Risk & governance
-
NCSC sets out CNI security lessons
The NCSC has published practical lessons from penetration testers on how critical national infrastructure operators can make compromise harder.
-
Bank warns on agentic AI risk
Sarah Breeden has warned that agentic AI could reshape cyber, payments, and market resilience, forcing financial institutions to revisit accountability and recovery.
-
European ransomware puts suppliers under pressure
Black Kite says European ransomware incidents rose sharply in early 2026, with supplier compromise becoming a major route into affected organisations.
-
ENISA moves Cybersecurity Reserve into procurement
ENISA’s open call for Cybersecurity Reserve services turns Europe’s emergency cyber response capacity into a concrete procurement and delivery issue.
-
ENISA opens NIS2 maturity survey
ENISA has opened a new NIS360 survey cycle, giving authorities and high-criticality entities a benchmarked view of sector cyber maturity under NIS2.
-
Apple patch cadence compresses under AI
Apple has released some security fixes ahead of broader updates, acknowledging that AI may shorten the time between disclosure and exploitation.
-
UK ransomware figures expose reporting gap
Report Fraud says 323 organisations reported ransomware attacks in a year, with SMEs accounting for more than half of the disclosed cases.
-
NCSC puts CNI resilience into design
The NCSC’s operational technology guidance pushes critical infrastructure operators towards secure design, segmentation, monitoring, and specialist testing.
-
Cyber action delay leaves pledge exposed
The UK’s wider national cyber plan has reportedly slipped while a FTSE 350 pledge proceeds, leaving board-level resilience policy split across separate tracks.
-
Indra ransomware case tests supplier assurance
Spanish defence and technology group Indra says a ransomware incident at one subsidiary was contained, with services continuing normally and the wider group unaffected.




