Connect with us

Business & Technology

UK cyber survey exposes gaps in basic security controls

Published

on


The UK government has published the 2025/26 Cyber Security Breaches Survey for businesses and charities. Security experts say the findings expose persistent gaps in basic controls, supply chain oversight, and incident reporting.

The latest annual survey points to continued exposure to cyber incidents across UK organisations, alongside uneven adoption of recognised security standards and controls. It is based on research carried out for the Department for Science, Innovation and Technology and the National Cyber Security Centre.

Chris Newton-Smith, Chief Executive Officer at IO, said the findings on formal security frameworks highlighted a structural weakness in many organisations.

“Today’s Cyber Security Breaches Survey has once again revealed some stark and urgent findings about the state of the UK cyber security landscape.”

“The continued low uptake of recognised standards, with only 5% of businesses reporting adherence to Cyber Essentials, signals a missed opportunity to build structured resilience. Frameworks should not be seen as a compliance overhead. They provide proven, repeatable security practices and can reduce reliance on fragmented external advice. Organisations that depend heavily on consultants instead of frameworks risk inconsistent controls and a lack of internal capability. Frameworks such as Cyber Essentials can help turn good intentions into operational discipline.”


“The survey shows some encouraging improvements in baseline hygiene, for example in risk assessments, policies, and insurance. But despite progress in several hygiene practices, small businesses returned to 2023/24 levels. This creates a false sense of security. Organisations are doing visible things, but not necessarily the things that are most effective. Cyber hygiene is improving, but resilience requires depth, not just breadth.”

“This is compounded by the very low level of supplier risk reviews, with only 15% reviewing the risks posed by their immediate suppliers. That highlights a significant systemic vulnerability. It is particularly critical in light of increasing regulatory pressure, especially from rules such as DORA and NIS2, which place strong emphasis on supply chain resilience and third-party risk management. Many organisations are strengthening their internal defences while leaving a critical gap in how they assess and manage supply chain risk, effectively reinforcing the front door while leaving the back door open.”

“Cyber security maturity is not defined by how many tools an organisation deploys, but by how consistently it applies governance, manages risk, and aligns to recognised standards. The organisations that close that gap and achieve true resilience will be the ones that turn cyber security into a genuine competitive advantage.”

Newton-Smith highlighted supplier oversight as a particular concern, given growing regulatory pressure such as the EU’s Digital Operational Resilience Act and updated Network and Information Systems rules. Those regimes place greater scrutiny on third-party risk and operational continuity across digital supply chains.

The survey also reports relatively low adoption of multi-factor authentication across UK companies, despite official guidance treating it as a basic control. The findings suggest many firms still rely on passwords as the primary safeguard for access to systems and cloud services.

Michael Downs, Vice President at SecurEnvoy, said many organisations continue to delay adopting multi-factor authentication despite its role in blocking common attacks.

“The 2026 Cyber Security Breaches Survey still shows surprising figures on how few businesses have implemented multi-factor authentication as a standard security control. Only 47% of businesses have adopted it, meaning a significant proportion of organisations are leaving the door wide open to cybercriminals.”

“MFA is one of the most straightforward controls available and does not require a lengthy procurement process or specialist hire. If an attacker gets hold of a password through phishing or a credential leak, MFA adds another layer of protection. Given that stolen credentials feature in the majority of breaches, there is no excuse not to offer it to employees, contractors, and customers.”

“Businesses also need to be aware that the NCSC’s Cyber Essentials scheme is being updated this year to require MFA on all cloud services, so it will no longer be a nice-to-have. For the many organisations still holding out, implementing MFA is the most direct step they can take to improve their security posture today.”

Regulation features heavily in expert reactions to the survey. Specialist providers see forthcoming rules as a catalyst for more rigorous preparation, especially around detection, response, and reporting.

Richard Groome, OT Cybersecurity Specialist at e2e-assure, said current breach notification levels remain well below the standards set in upcoming legislation.

“Only 50% of businesses surveyed say they currently inform regulators about breaches. Incident reporting is about to become much more important because, under the Cyber Security Resilience Bill, organisations deemed critical will be required to report significant cyber incidents within 24 hours, with a full report due within 72 hours. That is a completely different standard from what most businesses currently operate to, and the gap between today’s practice and tomorrow’s requirement is significant.”

“It is worth noting that regulators can designate any supplier, including SMEs and non-UK entities, as critical if their failure could disrupt essential services. The potential scope is therefore massive and not limited to large organisations.”

“Meeting those reporting deadlines requires mature SOC processes, 24/7 monitoring, and automated detection capabilities that many smaller organisations simply do not have in place today. Most will also need to identify and notify affected customers within that same window, which demands granular visibility into systems and workloads that few have yet built.”

“Organisations should be assessing their incident detection and reporting workflows now, mapping their IT ecosystem, and ensuring they have the monitoring capability to identify a breach quickly enough to meet the new thresholds.”

“The survey shows that senior management are being informed when breaches occur. The CSRB will extend that accountability outward, and businesses need to be ready for it.”

Groome also pointed to the financial impact of serious incidents, which he said often exceeds the direct costs cited by respondents.

“For organisations that experienced a breach in the past 12 months, the average perceived cost is just £940, but this rises to £20,000 at the 95th percentile. These costs might sound manageable, but the reality for those at the more severe end of the spectrum is anything but.”

“The Jaguar Land Rover attack was estimated to cost the business around £5 million per day in lost profits, with the wider economic impact running into billions across the supply chain. The M&S ransomware attack resulted in losses of £300 million.”

“A large part of these costs is due to the downtime caused by attacks. With this in mind, we need to be acutely aware that our Critical National Infrastructure is particularly vulnerable to shutdowns, and the knock-on costs of downtime will have an even greater impact on the organisations we all depend on to live: power, water, and food.”

“Attackers know this. Modern ransomware attacks go beyond encrypting data. Attackers understand that months of downtime, and the financial damage that comes with it, are a lucrative bargaining chip in ransom negotiations.”

“UK businesses need to invest in continuous monitoring, faster detection, and tested incident response. That not only reduces the likelihood of a breach but also directly limits the financial exposure when one occurs.”



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business & Technology

Muscle Food at risk of closing after entering administration

Published

on



Muscle Food has offered customers “quality” meat, high-protein meals, supplements, and more for 13 years (founded in 2013).

The brand has built its reputation on offering “macro-friendly” meal options, calorie-controlled bundles, and nutritional transparency, aiming to support customers’ health and fitness goals.

Its website explains: “Muscle Food brings together high-protein meats, curated hampers, supplements, snacks and functional drinks to support every goal.

“From lean, macro-friendly cuts to calorie-packed bulking options, our range is built to fuel performance, recovery and everyday healthy living.

“We focus on quality, clear nutrition and products that help you stay consistent, and we are always expanding to support your journey!

“Every order is carefully packed for freshness and delivered straight to you, making it easy to stay stocked with the food that powers your progress.

“With dependable delivery and consistent quality, MuscleFood fits seamlessly into your routine so you can focus on your goals.”

Muscle Food falls into administration

After 13 years, Muscle Food has now confirmed it has fallen into administration.

Stuart Kelly and Claire Harsley from Mackay Goodwin Limited were appointed joint administrators on July 21, according to The Gazette.



Despite its financial trouble, the company’s website remains online, along with a notice stating the joint administrators are now managing the business and its assets.

Muscle Food said: “The affairs, business and property are managed by the Joint Administrators, who act as agents of Muscle Foods Limited (In Administration) and without personal liability.”

Customers “very distressed” as Muscle Food at risk of closing

Muscle Food has built up a loyal customer base over the past 13 years, maintaining a 3.7-star rating on Trustpilot.

One long-time customer said: “Brilliant service, from delivery to the quality of the meats bought. My family and I have been using Muscle Food since their start-up.

“I first started buying for my family, and now my daughters have grown and have children of their own and now use Muscle Food too.

“I was VERY distressed to hear that they had gone into administration.

“Keep going Guys. There are thousands of us who appreciate you.”

Other UK companies that have closed or entered administration/liquidation in 2026

It has been a tough year for the UK high street, with several other retailers entering administration or liquidation and others announcing widespread store closures.

Major high street brands LK Bennett, Claire’s, and Quiz have been forced to close all their remaining stores after falling into administration.

UK fashion retailer Leading Labels is also set to close its remaining 15 stores after falling into liquidation.

Whitbread recently confirmed it will be closing all its UK restaurants in September:

  • Brewers Fayre (89 locations) – September 7
  • Beefeater (106) – September 10
  • Bar + Block – September 3
  • Table Table – September 3
  • Cookhouse + Pub – September 3

TG Jones and the British Heart Foundation will also both be closing around 150 stores across the UK.

Other retailers have been forced to close stores this year, including:



Several UK travel companies have also ceased trading or entered administration in 2026:

Meanwhile, four UK airlines have fallen into administration or liquidation:



UK delivery company Yodel is set to be phased out after being acquired by InPost.

It’s also been reported that Morrisons is looking to sell some of its in-store pharmacies as it continues to cut costs.

It hasn’t all been bad news for the UK high street, with several major brands announcing new store openings for 2026, including Aldi, M&S, and Superdrug.

Plus-size clothing brand Evans also returned to the UK high street recently after closing all its stores and concessions in December 2020.

Bodycare has also returned to the UK high street in 2026 after closing all its stores last year, having fallen into administration.

Do you use Muscle Food? Let us know in the poll above or in the comments below.





Source link

Continue Reading

Business & Technology

Ecommpay shortlisted in seven Payments Awards categories

Published

on



SOFIAH NICHOLE SALIVIO

News Editor

Ecommpay has been shortlisted in seven categories at the Payments Awards, including two individual Women in PayTech honours.

Its Head of Regulatory Compliance, Alpa Jotangia, and Chief Marketing Officer, Miranda McLean, are finalists for the Women in PayTech award. Ecommpay is also in contention for Best Online Payments Solution, Best Merchant Acquirer or Processor, Cross-Border Payments Solution of the Year, AI-Driven Fraud Prevention Platform of the Year, and Best Use of AI and Data in Payments.

The shortlist spans both corporate and individual categories in an awards programme that recognises businesses and executives across the payments sector.

Ecommpay operates a full-stack payments platform for merchants, with cross-border commerce at the centre of its offer. Merchants can access global and local acquiring, payment processing, and orchestration through a single API, alongside more than 100 payment methods.

Fraud prevention was one of the areas highlighted by the shortlist. Ecommpay cited its in-house Graph Analysis system as part of its response to payment fraud, a growing issue in digital commerce.

The individual nominations reflect different parts of the business. Jotangia was recognised for her work in regulatory compliance and for building a compliance culture within organisations.

McLean’s nomination centres on her marketing career and her work on inclusion, accessibility, and diversity in financial technology. Financial inclusivity sits at the heart of Ecommpay’s wider mission and shapes how it supports merchants seeking to improve accessibility for end customers.

AI focus

Artificial intelligence features prominently in the company’s awards showing. Alongside the AI-Driven Fraud Prevention Platform of the Year category, Ecommpay was shortlisted for Best Use of AI and Data in Payments, reflecting its use of machine learning and data analysis in payment processing.

Ecommpay has invested in artificial intelligence to analyse payment declines and fraud patterns. That work forms part of a broader push to improve checkout performance and payment acceptance rates for merchants.

McLean commented on the recognition in a statement.

“At Ecommpay, we are on a mission to push checkout performance to its absolute limit. As well as committing to increasing accessibility and inclusivity across our platform, adding to our suite of available payment methods and using the latest tech to fight fraud, we have invested in artificial intelligence to analyse payment declines and transform FinTech performance. To have our people, our innovations and our successes recognised with no less than seven Payments Awards shortlistings is incredible,” said Miranda McLean, Chief Marketing Officer, Ecommpay.

Company profile

Founded in 2012 and based in London, Ecommpay serves merchants looking to manage domestic and international payments through a single provider. Its platform includes open banking, recurring billing, and direct debits, which it builds directly into its system rather than relying on third-party products.

The business is authorised by the Financial Conduct Authority under the Payment Services Regulations to provide payment services. It is also a principal member of Mastercard and Visa, according to the company.

The seven shortlistings give Ecommpay visibility across some of the most competitive parts of the payments market, including online payments, merchant acquiring, cross-border transactions, fraud prevention, and the use of artificial intelligence in payment operations.

These categories highlight where payments groups are under pressure to differentiate, particularly as merchants seek fewer providers, broader geographic reach, and stronger fraud controls.

Ecommpay said ultimate financial inclusivity is its company mission, with a focus on helping merchants improve accessibility for customers.



Source link

Continue Reading

Business & Technology

Thames Water’s £7.5bn reservoir near Abingdon ‘critical’

Published

on


Leonie Dubois, Head of Engagement, Land and Consents at Thames Water, said: “The South East is designated as seriously water stressed and as we enter the fourth heatwave of the summer it’s clear climate change is already having an impact.

“It’s therefore critical that we continue to progress our plans for White Horse Reservoir.

“It would act as drought insurance policy for the region, securing water supplies for 15 million people, including Thames Water, Affinity Water and Southern Water customers.”

The White Horse Reservoir, near Abingdon, will provide water for 15 million people across the south east.

The project has been labelled a “vital piece of national water infrastructure” by Thames Water.

But, in a statement action group ‘Group Against Reservoir Development’ called the reservoir the wrong solution in the wrong place.

The massive reservoir, which will cover an area the size of Gatwick Airport, has always been a topic of debate.

Only Kielder Water in Northumberland, at 200 billion litres, is bigger.

READ MORE: Rain to reverse Oxfordshire drought won’t arrive till October

Map of Abingdon reservoir location.Map of Abingdon reservoir location. (Image: Google Maps)

Two groups, Countryside charity CPRE Oxfordshire and Safer Waters, even sought a judicial review at the High Court.

However, their judicial review was dismissed.

 Thames Water revealed that costs for the controversial proposed Abingdon Reservoir soared from £2.2 billion to between £5.5 billion and £7.5 billion, a tripling of the original figure

This will be borne by customers of Thames Water, Affinity Water, and Southern Water.

The plan is to tackle an anticipated shortfall of more than a billion litres of water per day in the next 50 years, according to Thames Water.

This projection considers the effects of population growth and climate change.

Thames Water predicts that a severe drought could cost London’s economy alone as much as £500m a day.

Currently, hosepipe bans are already a common occurrence.

The Abingdon Reservoir, also known as the South East Strategic Reservoir Option (SESRO), is expected to be the second largest reservoir in the UK, with a capacity of 150 billion litres.

Only Kielder Water in Northumberland, at 200 billion litres, is bigger.

The site is located three miles southwest of Abingdon.

It is close to the River Thames and features the right geology and ground conditions for a reservoir.

Thames Water has had to plan for more than just the reservoir itself.

The project will include a pumping station, a conveyance tunnel to transfer flows to and from the River Thames near Culham, and infrastructure to link the reservoir to the River Thames for emergency drawdown.

An access road into the site, a temporary rail siding for freight train deliveries, and a compensatory floodplain are also part of the plan.

Local streams will be diverted, and the Steventon–Hanney road will be shifted to the south.





Source link

Continue Reading

Trending