Connect with us

Business & Technology

UK cyber survey shows stagnant breach preparedness

Published

on



SHANNON WILLIAMS

News Editor

The UK Government has released its Cyber Security Breaches Survey 2026, prompting criticism from security specialists and legal experts who say progress remains limited.

The annual survey tracks the frequency and impact of cyber incidents across organisations of different sizes and sectors. It also examines how businesses and charities approach risk management, staff training and supply chain security.

Initial industry reaction points to what many describe as stagnation in key measures of preparedness, with phishing, supplier vulnerabilities and the position of smaller firms emerging as particular concerns.

Tom Kidwell, co-founder of security firm Ecliptic Dynamics and a former British Army and UK Government intelligence specialist, said the 2026 results suggest too few lessons have been learned from recent attacks on well-known consumer brands.

“After years of headline-grabbing cyber attacks, this survey feels depressingly familiar. Breach levels haven’t shifted, preparedness hasn’t improved, and despite all the noise around breaches causing serious damage to major brands like Marks and Spencer and the Co-Op, too many organisations are still failing to act. Talking about cyber security clearly isn’t the same as doing anything meaningful about it. Too many companies are still in the mindset that ‘it won’t happen to me.'”

Phishing remains the most commonly reported form of attack in the government study. Security practitioners argue that attackers are using increasingly sophisticated and targeted methods, often supported by artificial intelligence tools.

For Kidwell, the survey exposes a disconnect between the scale of the phishing threat and current investment in staff awareness programmes.

“What really stands out is phishing. It continues to dominate, and it’s becoming smarter, more targeted and more damaging thanks to advances in AI, yet the Government’s Cyber Security Breaches Survey shows that staff training levels remain considerably low. When fewer than one in five organisations train their people, it’s no surprise attackers keep walking straight through the front door,” he said.

Experts also single out supply chain exposure. The survey shows relatively low levels of structured risk assessment of immediate suppliers, despite a series of high-profile disruptions.

“The same applies to supply chain attacks. Despite Jaguar Land Rover hitting the headlines last year with one of the most significant supply chain attacks, amounting to almost £500m in losses, a measly 15% of companies review risks associated with their immediate suppliers. This is creating a glaring blind spot, one that attackers are increasingly exploiting,” Kidwell said.

Smaller organisations appear to be under particular pressure. The latest figures suggest some modest gains in basic security practices recorded in previous years have not been sustained.

“Small businesses are the biggest concern. Last year’s modest improvements in basic cyber hygiene have gone into reverse, with fewer risk assessments, fewer policies and weaker continuity planning. Companies appear to be abandoning the bare minimum required to keep their businesses secure,” Kidwell said.

Government awareness efforts receive some recognition from specialists, but they argue that publicity and campaigns have yet to translate into sustained improvements in resilience.

“Government campaigns such as the Cyber Aware campaign are being recognised a little more, which is encouraging, but awareness alone is clearly not building resilience. Until cyber risk is treated as a practical business issue, and not a compliance tick-box exercise, these numbers in the annual Cyber Breaches Survey won’t change,” Kidwell said.

He also questioned the wider response from law enforcement and government agencies to rising levels of cyber crime, arguing that better organisational defences must be matched by stronger efforts to disrupt the groups behind attacks.

“While awareness is clearly important and businesses need to play their role, a question to ask is how is the Government tackling this wave of crime? With such prevalence of the activity, what is being done to disrupt the actors conducting it? Defensive and preventative actions can only go so far, upstream disruption is required alongside this,” Kidwell said.

Legal specialists view the survey as further evidence of a gap between the severity of cyber risk and the way many boards approach the issue. They also point to nation-state threats and the complexity of global vendor networks as added pressures on governance.

Ross McKean, co-chair of the UK Data Protection and Cyber Response Practise at DLA Piper, said:

“While some welcome progress has been made, today’s figures show a persistent gap between the potential existential nature of cyber threats and board-level engagement, especially across smaller businesses. With nation state threat actors increasingly targeting Western organisations and global supply chains becoming ever more interconnected, there is a pressing urgency to close this gap, including by ensuring businesses consistently identify, assess and prepare for vulnerabilities across their third-party vendor networks and take steps to defend against new technologies such as AI which potentially render current vulnerability patching practices redundant.”

McKean argued that boards should incorporate cyber considerations into broader resilience planning and crisis management, with clear priorities for keeping critical functions running after an incident.

“As a first step, all organisations, no matter their size, should have a clear picture of their ‘minimum viable business’ and urgently establish tested and effective workarounds that allow them to keep going should primary systems be offline. Fundamentally cyber risk is a business resilience, board level consideration,” McKean said.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business & Technology

Network Rail will not reopen Botley Road early despite completion

Published

on



Gas network company SGN confirmed it had repaired three minor gas leaks and left the site on Monday, August 3, six days earlier than expected.

The leaks were discovered during excavation works last month and contributed to the pushing back of the road’s reopening date, yet again, to September 20.

The completion of the gas mains replacement marked a significant step forward in the wider Oxford Station improvement project, which was originally budgeted at £161 million but is now expected to cost at least £237 million.

The development prompted hopes that Botley Road, closed beneath the rail bridge since April 2023, could reopen earlier than planned.

However, Network Rail has moved to manage expectations, saying the project remains on course to meet its existing target date rather than finish ahead of schedule.

A Network Rail spokesperson said: “We’re pleased that SGN has completed its gas mains replacement work.

“While this is an important milestone, it doesn’t necessarily mean the overall project will finish early as some remaining work is dependent on access to the railway, which we have had to rearrange to enable the replacement of the gas main.

“Our focus remains on meeting our planned deadline of 20 September for reopening Botley Road to traffic.”

While the completion of the gas works removes one of the most recent obstacles facing the scheme, Network Rail says further work under the bridge and around the station is still needed before the route can reopen to traffic.





Source link

Continue Reading

Business & Technology

40-year-old Oxfordshire gymnastics club at risk of closure due to heat

Published

on


The club is currently struggling in the summer heat, and has launched a new fundraiser to keep its gymnasts safe.

The club, which is based at Grove House Barn near Warkworth in Banbury, launched the fundraiser so it could buy and install four air conditioning units to keep its space cool.

Currently, the club hopes to raise £7,000 through the appeal so it can buy four 10kW air conditioning units and cover all the installation costs.

So far, the club has raised £380.

Karl Wade, director of Wade Gymnastics, said the club has become “increasingly warm” during the summer months due to the rising temperatures.

READ MORE: Thames Water leakage targets are ‘not realistic’ says boss after pay rise

Wade Gymnastics at Grove House Barn in BanburyWade Gymnastics at Grove House Barn in Banbury (Image: Google Maps)

“Despite our best efforts to keep doorways and shutters open, it becomes very uncomfortable for gymnasts to play and train,” Mr Wade said.

He added: “The safety of our gymnasts and coaches is always our utmost priority.

“Unfortunately, the risk of having to close the business during these hot spells is increasing and we need to have more effective ways of keeping everyone cool.

“An air conditioning system would allow the business to stay open during those extreme hot conditions and continue to provide classes for everyone who attends.”

The gym currently delivers classes seven days a week for around 900 people, which range from toddlers to athletes competing at national level.

The gym club was founded more than four decades ago by Ruth Wade and, for the past 20 years it has been based at its current facility.





Source link

Continue Reading

Business & Technology

Solihull Council appoints ICS.AI for AI discovery phase

Published

on



SOFIAH NICHOLE SALIVIO

News Editor

Solihull Council has appointed ICS.AI to deliver the first phase of an AI Transformation Discovery programme to examine how artificial intelligence could be used across several resident-facing services.

The 24-week programme will review opportunities in Adult Social Care, Children’s Services, Economy & Infrastructure, and Public Health. It is intended to help the council decide where AI could be used and where future spending should be directed.

In this first phase, ICS.AI will assess the council’s readiness for AI and identify use cases across the four service areas. The programme is expected to produce a prioritised shortlist of about 200 use cases, including 50 validated from a finance perspective, alongside a longer-term AI Transformation Roadmap.

The work is intended to create an evidence base before any wider implementation decisions are taken. Ethics, privacy, and safeguarding will be considered throughout the assessment process.

Discovery phase

ICS.AI will use its AI Target Operating Model framework to review Solihull’s current position across five dimensions before ranking opportunities. The outputs will be based on council-owned baseline data and reviewed by public sector specialists.

The approach reflects a broader pattern among local authorities exploring AI in service delivery while facing pressure to justify spending and manage risks around data use and public accountability. Councils have also been seeking clearer business cases before committing to larger technology programmes.

Solihull said the discovery exercise would support a measured approach to service modernisation. The authority wants to identify where AI could improve services for residents while also demonstrating value for money.

“We are committed to taking a well-considered and planned approach to modernising the services we provide. By building a strong evidence base for future decisions, this programme will help us understand where the greatest AI opportunities exist. We will then be able to prioritise those improvements that will deliver the greatest benefit for residents, while ensuring full value for the council,” said Councillor Dave Pinwell, Cabinet Portfolio Holder for Resources, Solihull Council.

Public sector focus

ICS.AI said the Solihull engagement builds on work it has carried out with more than 20 public sector organisations using its AI transformation and discovery assessments. Those organisations include Derby City Council.

The company focuses on AI projects for the public sector, where interest has increased as authorities look for ways to manage demand pressures in social care, public health, and other frontline services. At the same time, councils are under scrutiny to show that new technology investments are proportionate and supported by practical evidence.

Dwayne Johnson, Chief Local Government Officer at ICS.AI, said local authorities need stronger justification before committing funds. “Local authorities need confidence that every investment is backed by robust evidence and long-term value for residents. Solihull Council is taking the right approach by starting with a structured discovery programme that builds a clear understanding of priorities before decisions are made. By developing finance-validated business cases and a practical roadmap, the council can be more proactive in the decisions it makes,” he said.

The programme’s initial outputs are expected to give Solihull a ranked view of where AI could be applied across services, the level of organisational readiness, and which projects may warrant further consideration. This first phase is focused on identifying options rather than moving directly into deployment.

For local government leaders, that distinction is becoming increasingly important as councils test AI in areas that affect vulnerable residents and essential public services. In Solihull’s case, the work spans some of the authority’s most visible functions, including care services, children’s provision, public health activity, and parts of local infrastructure planning.

The council aims to use the findings to inform later investment decisions through finance-validated business cases and a practical roadmap for future priorities.



Source link

Continue Reading

Trending