never miss a thing
Sign up for news and upcoming events

Our monthly update bringing you the relevant, high-level policy and business news from across the cyber sector.
This month, we examine the King’s Speech and its implications for the cyber sector, explore the findings of the latest Cyber Breaches Survey, and follow up on the industry hype surrounding frontier AI models such as Claude Mythos.
If you have any questions about the content, or believe we should add to our coverage, please do not hesitate to get in touch.
never miss a thing

Photo credits: Getty Images
On Wednesday, the State Opening of Parliament took place, with the highly anticipated King’s Speech delivered in a fraught political environment, with ongoing speculation over potential leadership challenges to Sir Keir Starmer’s premiership. Broadly, the Speech set out a legislative agenda centred on building national resilience, improving public services, and strengthening the UK’s international partnerships.
On cyber specifically, the King stated that the Government will ‘introduce legislation to improve the country’s defences against cybersecurity threats’. This refers to the long anticipated Cyber Security and Resilience Bill currently before Parliament. As of today, the Bill has completed its committee stage and is awaiting dates for its report stage in the House of Commons.
The King’s Speech also trailed an upcoming Digital ID Bill, signalling the Government’s intention to introduce a Digital ID scheme in the UK. However, the announcement contained very little detail on the design, scope or implementation timeline of the scheme, and further clarity will only emerge as draft legislation and guidance are published.
In addition, the Government intends to bring forward a Regulatory Reform Bill aimed at streamlining regulation and reducing the burden on businesses, with the stated goal of ensuring that regulatory requirements don’t act as a barrier to innovation.
That said, given that the Cyber Security and Resilience Bill will strengthen the oversight of regulators, we do not expect that a new Regulatory Reform Bill would have a material impact on the new cyber incident reporting regimes, or the tightening of regulatory powers, mandated by the Cyber Security and Resilience Bill
We’ll continue to follow any updates on the government’s overarching cyber strategy and will be keeping members updated. If you have any questions about the King’s Speech, or the government’s cyber strategy, feel free to get in touch at finlay@cb-network.org.

The government’s 2026 Cyber Security Breaches Survey shows that cyber attacks remain a stubbornly high risk for organisations. According to the findings, 43% of UK businesses experienced at least one cyber breach or attack in 2025/26, unchanged from the previous year. This equates to approximately 612,000 businesses impacted in the last 12 months. This is down from the high of 50% recorded in 2023/24 but still representing a major and persistent threat landscape.
Phishing remains the most common type of incident, affecting 38% of businesses, the same level as in 2024/25. However, traditional phishing emails are now being compounded by voice‑phishing and other social engineering tactics, which attackers increasingly use to gain undue access to systems, steal credentials and install other forms of malicious software.
The survey highlights the growing problem of fraud directly enabled by cyber incidents. An estimated 3% of all businesses and 1% of all charities suffered fraud that resulted from a cyber breach or attack in the last year, equating to around 43,000 businesses, 3,000 charities and roughly 130,000 cyber‑facilitated fraud events.
Financial impacts to affected organisations vary widely. When including cases where organisations reported no direct financial loss, the median perceived cost was £110, with most falling between £0 and £2,000 and the top 10% reaching £12,000. Excluding zero‑cost cases, the median rises to £500, with most between £150 and £5,000 and the top 10% hitting £15,000.

Amidst growing threat from AI cyber capabilities, the government is urging businesses to sign the new Cyber Resilience Pledge, backed by £90 million in government investment as part of the government’s larger cyber resilience strategy. Baroness Liz Lloyd, Minister for Digital Economy, has warned that traditional cyber protections alone are not enough, with AI lowering the barrier for criminals to find vulnerabilities and launch attacks at a scale that would have been impossible even a year ago.
The Cyber Resilience Pledge sets out three steps to improve cyber security across organisations. Firstly, by mandating cyber security as a board-level responsibility. Secondly, signing up to the NCSC’s free Early Warning Service, and thirdly, mandating Cyber Essentials certifications across the organisation’s supply chains. Ministers have written directly to leading UK companies urging sign-up.
The announcement is accompanied by strong figures for the UK’s cyber sector. The government press release states that the sector at large grew 11% last year to £14.7 billion, with the number of firms rising 20% to 2,603 and 2,300 new jobs created.
Additionally, the number of UK firms offering cyber security products specifically for AI rose 68% in 2025, underlining the scale of emerging opportunity across the industry amid the ongoing cyber-AI discussion centering around the release of frontier AI models, such as Anthropic’s Claude Mythos.

Following the launch of the government’s Sovereign AI Unit on April 16th, which acts as a state-backed venture capital fund, the government has been announcing major investments, Technology Secretary Liz Kendall has warned that Britain must move decisively to cement its place in a new AI-driven era of global power, security and prosperity. In a speech at the Royal United Services Institute (RUSI) on the 28th April, Kendall argued that technology has become the ‘defining currency’ of the modern era.
Kendall stressed that AI sovereignty is about reducing over‑dependence and increasing resilience in key national priorities. To support this domestic ecosystem, she announced that the government will develop a UK AI Hardware Plan that will be released in June during London Tech Week; the fully funded access to the UK’s largest supercomputers for over 30 companies; and the £400m the Ministry of Defence has ringfenced to back British-built AI and innovative technologies.
Kendall highlighted the growing concentration of AI capability, noting that 70% of global AI compute is now controlled by just five companies. Control over where AI systems are built and how they operate is now ‘fundamental to economic security, energy security and defence security’. Kendall warned that failing to master AI risks ceding control over the future of the tech sector.

The UK’s AI Security Institute (AISI) has published new findings which show that frontier AI models, such as Anthropic’s Claude Mythos and GPT-5.5, are able to carry out increasingly complex cyberattacks autonomously, and the progress of their abilities are accelerating.
As a reminder, Anthropic announced their new Mythos model last month, which triggered an intense reaction across the cyber sector. The model has already shown itself to outperform many humans in finding and exploiting cyber vulnerabilities, and has uncovered thousands of previously unknown bugs.
AISI’s new research measures the time difference between an AI model and a human cyber expert in completing complex cyber tasks. Since late 2024, that figure has been doubling roughly every few months. In February 2026, the doubling rate was estimated at 4.7 months, already faster than the 8-month estimate from November 2025.
Most strikingly, Mythos became the first AI model to complete both of AISI’s ‘cyber range’ simulations, which are realistic multi-step attacks against small enterprise networks. One range was solved in 6 out of 10 attempts; the other, previously unsolved by any model, was completed in 3 out of 10.
As the capabilities of cyber AI models grow, boards should realise that the window to build strong security foundations is now. Frontier AI models are already helping defenders find vulnerabilities, but it’s important to remember that the same capabilities are available to attackers.n
On Monday, 11th May, CBN attended a briefing on the Government Cyber Action Plan, announced earlier this year, with Bella Powell, Government Chief Information Security Officer (CISO) and Director of the new Government Cyber Unit.
It was great to see engagement between government and industry on key issues of cyber resilience within the public sector. CBN is looking forward to continuing to engage with government and industry leaders to help strengthen UK cyber resilience.
Through recent briefings with CBN and DSIT on the upcoming National Cyber Action Plan, our January roundtable on the Cyber Security and Resilience Bill, and attending this briefing on the Government Cyber Action Plan, CBN is closely engaged with, and fully up to date on, the government’s evolving cyber strategy.
If you’d like to get involved with CBN’s work, feel free to get in contact at secretariat@cb-network.org.
The Cybersecurity Business Network is a coalition of leading UK-based organisations committed to strengthening the nation’s cyber resilience, fostering innovation and supporting economic growth. Through collaboration and knowledge sharing, we empower our members to drive growth and set standards for excellence across the UK cyber sector.
As a member-led network, our ambition is to serve as the unified voice of the UK cyber industry, championing its interests, amplifying its potential, advocating for greater engagement and support from government, media, and the wider business community.
If you are interested to hear more about CBN or want to become a member, then please reach out to secretariat@cb-network.org for more info.