Business & Technology
UK cyber survey criticised over AI threat blindness
The Department for Science, Innovation and Technology has published the latest Cyber Security Breaches Survey 2025/2026. Security specialists have questioned whether the government’s approach and business responses match the scale of AI-driven threats.
The annual survey tracks how UK businesses and charities experience and manage cyber incidents. It reports relatively stable headline breach numbers, persistent phishing threats, and a continued emphasis on policy documents, training, and certification.
Several industry figures argue that this apparent stability masks a decline in real-world resilience. They highlight AI’s growing role in both attacks and defence, and point to gaps in funding, incident response, and day-to-day security practice, particularly among smaller organisations.
Merlin Gillespie, Chief Technology Officer at Cybanetix, argued that the survey framework no longer reflects the threat landscape.
“The Cyber Security Breaches Survey is fundamentally flawed because the government is measuring the wrong things. Why? Because it props up a cyber policy that doesn’t fund resilience. The survey shows the same information every year because the policy shaping it hasn’t changed in line with the problem. Attacks are getting cheaper, faster, and more sophisticated, in no small part because they’re AI-assisted. Defences aren’t keeping pace because businesses are being asked to build them voluntarily, without funding, while outcomes are measured through paperwork rather than real-world results. Cyber security is being treated as a private-sector hygiene issue rather than a nationwide public risk. CISOs are exhausted, not because they don’t know what to do technically, but because they’re overwhelmed by risk, compliance, the audit treadmill, and supplier questionnaires.”
“UK cyber policy has turned CISOs into paperwork administrators, and they’re in a doom spiral. Until the government moves from policy to incentives, and recognises technical changes that can move the dial rather than mandating compliance documents that bury teams, every successive survey will show defences eroding. Every year the government’s answer is to encourage more certifications, more training, and more awareness. Microsoft says AI is being used at every stage of the cyber kill chain, but the survey barely mentions it. The attack surface is changing beneath our feet, and everyone is trying to catch up with last year’s paperwork while worrying about the latest novel attack that the average CISO probably has no coverage against and no detections to identify. Phishing remains a top attack, not because defenders are lazy, but because attackers are evolving it faster than policy can adapt. OSINT-driven, multi-channel attacks using email, WhatsApp, and voice are growing.”
“AI-generated content can capture and repurpose real voice and video so instructions appear to come from a real colleague. Meanwhile, we’re being asked to combat it with questionnaires and multiple-choice tests. Incident response should be the headline of the survey, yet it is traditionally buried near the bottom. It consistently shows that most UK businesses have no incident response plan and little guidance on when to escalate an incident externally. As a result, the typical UK business is improvising mid-breach. And in the minority of cases where businesses do take action, it is through training, which doesn’t appear to be working. This is like trying to address a disease when a preventative vaccine would be more efficient. We need to use fiscal levers and provide solutions that work, foster the economy, and strengthen UK businesses, rather than drowning them in overheads and hindsight. The UK government spends £30 million supporting SMEs, which means those businesses are effectively fighting digital terrorists with enough money to buy a bag of chips.”
“The UK cyber sector generated £13.2 billion in revenue last year but attracted under £200 million in venture investment. By comparison, Israeli tech raised $12.2 billion in 2024, up 31% from the year before, with investment heavily concentrated in cyber and backed by stackable R&D grants worth up to $3.3 million per startup and a preferred corporation tax rate of 7.5% versus the UK’s 25%. If we underfund the buyer, starve the sellers, and bury businesses in paperwork with limited demonstrable impact, is it any wonder we have no answer to attackers using Mythos-class game-changing technology? If the government is serious about digital sovereignty and protecting its citizens, it needs fiscal incentives at both ends of the loop: tax credits for UK businesses investing in genuine cyber defence, and R&D grants and preferred tax treatment for UK cyber firms that build and retain their IP in the UK while serving UK citizens.”
Jon Fielding, Managing Director for EMEA at Apricorn, focused on how smaller organisations implement basic controls. He pointed to persistent weaknesses in staff education, device security, and backup strategies.
“Staff training continues to be a low priority among SMEs, with a third carrying out sessions compared with 84% of large organisations. As a result, the user remains the weakest link, and those users are becoming even more vulnerable as attacks are crafted and refined by AI. Phishing and social engineering attacks are now far more sophisticated and harder to spot, making it vital that employees know how to report suspicious communications. They also need guidance on how to report rogue AI. The syntactic nature of AI means it can change and morph over time, and that could make it the ultimate insider threat,” said Fielding.
“There is still a consistent failure to secure mobile technology, even when it belongs to the business. While 61% insist on on-device security, the needle has barely moved over the past five years. That keeps risk unnecessarily high in a world where mobile and hybrid working are now commonplace. These devices are much easier to compromise outside the office, so businesses should secure everything from mobile phones to laptops and portable storage media,” he added.
“Cyber criminals are increasingly targeting not the data itself but the backups. They know backups contain sensitive data, and by compromising them they can block recovery and hamstring the business, giving them maximum leverage. Another problem revealed by the survey is that wholesale backup of data to the cloud has created a single dependency. Only 48% are backing up data by other means, down from 55% in 2024, and that decline means fewer options when, not if, a business is attacked. The long-standing advice was to keep multiple backups on different media and in different locations, but that has since evolved. Best practice is now the 3-2-1-1-0 rule: three copies of data on two different media, one stored encrypted and offline, at least one backup immutable, and recovery regularly tested to ensure zero errors. Testing recovery is crucial because close to a third of businesses have previously reported that they could not fully recover their data,” Fielding said.
“There continues to be a grey area between corporate and personal device security when it comes to acceptable use. While 84% set rules for how staff can use business-issued devices, only 58% cover personal device use. Yet the vast majority of hybrid workers routinely use personal devices for work, and in our own annual survey the majority, 61%, said they expect those workers to put them at risk of a data breach. So even though remote or mobile working is now routinely included in security policies, there is little follow-through in how it is implemented and enforced. A key example is the use of removable storage such as USBs, which this section of the workforce is highly likely to use. The survey found only 64% stipulate what can be stored on such devices, which suggests that almost half of the mobile workforce is free to move data around on any type of USB stick. That is why policies must set out where and how data can be stored, and why it is sensible to specify the level of on-device security these storage devices should have,” he said.
“UK businesses continue to lag in their approach to cyber security. There is a tendency to put all their eggs in one basket, whether that basket is the cloud or a backup solution, and that increases risk. By taking a more distributed approach, businesses can dilute that risk. At the same time, organisations need to be more prescriptive about what they expect employees to do. Guidance on reporting suspicious communications, using on-device security, and backing up data is badly needed because the hybrid workforce remains largely adrift and is being circled by AI. The picture is further complicated by new threats on the horizon. For instance, digital twinning, where AI adopts the working practices of a human user and performs actions on their behalf, adds another layer between the user and the data. While such advances may increase productivity, they are also likely to make it much harder to safeguard users and corporate data,” Fielding added.
Dan Lattimer, Vice President for EMEA at Semperis, highlighted the gap between preventive controls and structured response.
“Stability in breach numbers should not be mistaken for resilience. The Cyber Security Breaches Survey 2025/2026 highlights a growing gap between prevention and preparedness. While organisations invest in controls such as restricted admin rights (73%) and backups (88%), far fewer have plans to recover their identity infrastructure after a breach. Only 25% of businesses and 19% of charities had a formal incident response plan, and only a minority had actually tested those plans. With phishing still the most disruptive threat and incident response planning still limited, organisations need to assume identity compromise will happen and prepare accordingly. Investing in identity monitoring and recovery alongside prevention is essential to reducing downtime, repeat incidents, and long-term business damage. Incident response without identity recovery is incomplete. The survey shows many organisations still have no plans to restore trust after a breach. That correlates with the increase in businesses reporting that a breach or attack led to loss of revenue or share value, because that is where the real damage begins,” Lattimer said.
Business & Technology
Ecommpay shortlisted in seven Payments Awards categories
SOFIAH NICHOLE SALIVIO
News Editor
Ecommpay has been shortlisted in seven categories at the Payments Awards, including two individual Women in PayTech honours.
Its Head of Regulatory Compliance, Alpa Jotangia, and Chief Marketing Officer, Miranda McLean, are finalists for the Women in PayTech award. Ecommpay is also in contention for Best Online Payments Solution, Best Merchant Acquirer or Processor, Cross-Border Payments Solution of the Year, AI-Driven Fraud Prevention Platform of the Year, and Best Use of AI and Data in Payments.
The shortlist spans both corporate and individual categories in an awards programme that recognises businesses and executives across the payments sector.
Ecommpay operates a full-stack payments platform for merchants, with cross-border commerce at the centre of its offer. Merchants can access global and local acquiring, payment processing, and orchestration through a single API, alongside more than 100 payment methods.
Fraud prevention was one of the areas highlighted by the shortlist. Ecommpay cited its in-house Graph Analysis system as part of its response to payment fraud, a growing issue in digital commerce.
The individual nominations reflect different parts of the business. Jotangia was recognised for her work in regulatory compliance and for building a compliance culture within organisations.
McLean’s nomination centres on her marketing career and her work on inclusion, accessibility, and diversity in financial technology. Financial inclusivity sits at the heart of Ecommpay’s wider mission and shapes how it supports merchants seeking to improve accessibility for end customers.
AI focus
Artificial intelligence features prominently in the company’s awards showing. Alongside the AI-Driven Fraud Prevention Platform of the Year category, Ecommpay was shortlisted for Best Use of AI and Data in Payments, reflecting its use of machine learning and data analysis in payment processing.
Ecommpay has invested in artificial intelligence to analyse payment declines and fraud patterns. That work forms part of a broader push to improve checkout performance and payment acceptance rates for merchants.
McLean commented on the recognition in a statement.
“At Ecommpay, we are on a mission to push checkout performance to its absolute limit. As well as committing to increasing accessibility and inclusivity across our platform, adding to our suite of available payment methods and using the latest tech to fight fraud, we have invested in artificial intelligence to analyse payment declines and transform FinTech performance. To have our people, our innovations and our successes recognised with no less than seven Payments Awards shortlistings is incredible,” said Miranda McLean, Chief Marketing Officer, Ecommpay.
Company profile
Founded in 2012 and based in London, Ecommpay serves merchants looking to manage domestic and international payments through a single provider. Its platform includes open banking, recurring billing, and direct debits, which it builds directly into its system rather than relying on third-party products.
The business is authorised by the Financial Conduct Authority under the Payment Services Regulations to provide payment services. It is also a principal member of Mastercard and Visa, according to the company.
The seven shortlistings give Ecommpay visibility across some of the most competitive parts of the payments market, including online payments, merchant acquiring, cross-border transactions, fraud prevention, and the use of artificial intelligence in payment operations.
These categories highlight where payments groups are under pressure to differentiate, particularly as merchants seek fewer providers, broader geographic reach, and stronger fraud controls.
Ecommpay said ultimate financial inclusivity is its company mission, with a focus on helping merchants improve accessibility for customers.
Business & Technology
Thames Water’s £7.5bn reservoir near Abingdon ‘critical’
Leonie Dubois, Head of Engagement, Land and Consents at Thames Water, said: “The South East is designated as seriously water stressed and as we enter the fourth heatwave of the summer it’s clear climate change is already having an impact.
“It’s therefore critical that we continue to progress our plans for White Horse Reservoir.
“It would act as drought insurance policy for the region, securing water supplies for 15 million people, including Thames Water, Affinity Water and Southern Water customers.”
The White Horse Reservoir, near Abingdon, will provide water for 15 million people across the south east.
The project has been labelled a “vital piece of national water infrastructure” by Thames Water.
But, in a statement action group ‘Group Against Reservoir Development’ called the reservoir the wrong solution in the wrong place.
The massive reservoir, which will cover an area the size of Gatwick Airport, has always been a topic of debate.
Only Kielder Water in Northumberland, at 200 billion litres, is bigger.
READ MORE: Rain to reverse Oxfordshire drought won’t arrive till October
Map of Abingdon reservoir location. (Image: Google Maps)
Two groups, Countryside charity CPRE Oxfordshire and Safer Waters, even sought a judicial review at the High Court.
However, their judicial review was dismissed.
Thames Water revealed that costs for the controversial proposed Abingdon Reservoir soared from £2.2 billion to between £5.5 billion and £7.5 billion, a tripling of the original figure
This will be borne by customers of Thames Water, Affinity Water, and Southern Water.
The plan is to tackle an anticipated shortfall of more than a billion litres of water per day in the next 50 years, according to Thames Water.
This projection considers the effects of population growth and climate change.
Thames Water predicts that a severe drought could cost London’s economy alone as much as £500m a day.
Currently, hosepipe bans are already a common occurrence.
The Abingdon Reservoir, also known as the South East Strategic Reservoir Option (SESRO), is expected to be the second largest reservoir in the UK, with a capacity of 150 billion litres.
Only Kielder Water in Northumberland, at 200 billion litres, is bigger.
The site is located three miles southwest of Abingdon.
It is close to the River Thames and features the right geology and ground conditions for a reservoir.
Thames Water has had to plan for more than just the reservoir itself.
The project will include a pumping station, a conveyance tunnel to transfer flows to and from the River Thames near Culham, and infrastructure to link the reservoir to the River Thames for emergency drawdown.
An access road into the site, a temporary rail siding for freight train deliveries, and a compensatory floodplain are also part of the plan.
Local streams will be diverted, and the Steventon–Hanney road will be shifted to the south.
Business & Technology
Cambridge Tech Week names five startup pitching finalists
Cambridge Tech Week has named five startups as finalists in its 2026 pitching competition after judges selected them from a shortlist of 20 companies.
The finalists are HotHouse Therapeutics, HutanBio, Lambda Energy, Myonerv and Xplore Intelligence. They span biotechnology, sustainable energy, agritech, medtech and artificial intelligence, reflecting the breadth of the wider shortlist.
HotHouse Therapeutics emerged from Professor Anne Osbourn’s laboratory at the John Innes Centre. The company is developing a drug discovery approach based on transient plant expression, using living plants to produce new medicines through an artificial intelligence-led platform.
HutanBio is focused on algae-based fuel production. It has identified a new class of algae, called Sphaerica, that produces oil at much higher rates than existing leading strains and can be cultivated in seawater on non-agricultural coastal land using sunlight and CO2.
Lambda Energy operates in agritech with a greenhouse additive called GloGro. The product is designed to increase crop yields by about 20%, and the company has secured pilot manufacturing and grower trials for high-value crops in the UK.
Myonerv has developed a wearable neurostimulator designed to monitor and treat stroke-induced paralysis remotely. Its system uses reusable electrode arrays and has already demonstrated remote control of hand movement between Cambridge and Greece.
Edinburgh-based Xplore Intelligence is building software to train and evaluate AI agents. Its Forge platform is designed to simulate operational environments so businesses can test full AI agent systems before deployment. The company has also won its first contract, worth more than GBP £1 million.
Judging panels
An independent panel drawn from finance, venture capital and industry reviewed the initial shortlist. It included Paul Hughes, Managing Director – Life Sciences & Technology, BDO; Jamie Bignal, Director, HSBC Innovation Banking; Mayank Shah, Co-founder and Chief Executive Officer, Grow Beyond Borders; Anne Dobree, Investment Director, Parkwalk Advisors; Isabelle O’Keeffe, Venture Partner, Twin Path Ventures; and the Chief Technology Officer for His Majesty’s Government Communications Centre, whose identity was withheld for security reasons.
A separate panel will choose the overall winner in the live final. It includes Zickie Lim, Partner and Head of VC & Investments, Mills & Reeve; Marilena Ioannidou, Director, Metaxi Catalyst Ventures; Richard Lewis, Managing Director, Foresight Group; and Emmi Nicholl, Chief Executive Officer, Cambridge Angels.
The competition forms part of Startup to Scaleup Day, one of the business-focused strands of Cambridge Tech Week. Organisers have positioned it as a showcase for younger technology businesses seeking investor, customer and market attention as they move beyond the early stage.
The finalists also highlight where UK startup activity remains concentrated. Drug development, climate and energy technologies, digital health, food production and AI infrastructure continue to attract commercial and investor interest, particularly when linked to research institutions or clear industrial use cases.
Cambridge has long been one of the UK’s leading centres for venture-backed science and technology businesses, with strong links between academia, investors and corporate partners. The inclusion of companies from outside the city, including Xplore Intelligence, suggests the competition is intended to reflect a broader national technology base rather than the local cluster alone.
The pitching competition is sponsored by Mills & Reeve, PwC and Julius & Clark. Professional services and law firms have become regular backers of startup competitions as they seek closer ties with high-growth businesses and their investors.
Lead judge Zickie Lim commented on the selection process.
“The standard of this year’s competition has been exceptionally high from the start, which will make the final selection process incredibly challenging. As sponsors of the Pitching Competition, Mills & Reeve is delighted to support a platform that shines a spotlight on the next generation of innovative businesses, and we are looking forward very much to seeing the finalists pitch live at Cambridge Tech Week,” Lim said.
PwC also highlighted the strength of the field.
“This year’s finalists demonstrate the extraordinary depth of innovation emerging from the UK’s technology ecosystem, and are among the strongest we’ve seen. They all represent the kind of ambitious, globally relevant businesses that have the potential to create real impact. PwC is proud to support entrepreneurs at this critical stage of their growth journey,” de Young said.
-
Business & Technology3 weeks agoHSBC UK & Visa test AI shopping with live payments
-
Business & Technology3 weeks agoValarian lands USD $50 million backing for sovereign AI
-
Business & Technology4 weeks agoMouser warns against viral hacks to cool overheating phones
-
Oxford News4 weeks agoNew romantasy bookshop attracts queues of customers
-
Business & Technology4 weeks agoSNP & Palantir launch AI tools for SAP transformations
-
Business & Technology4 weeks agoKane tops England influencer rankings after Mexico win
-
Traffic & Transport4 weeks ago‘I felt my spine and body split’: the woman who was hit by a child on a Lime bike – and denied compensation | Ebikes
-
Oxford united FC3 weeks agoOxford United three players who be kept after transfer ban
