MITRE-Lite has two versions. You're reading the plain English edition — written for business owners, no technical knowledge needed. MITRE ATT&CK is the gold standard framework used by cybersecurity professionals worldwide. It's also highly technical by design. We built both versions so everyone in your business can act on the same intelligence. View Technical Version →
MITRE-Lite Plain English Edition ● Updated This Week

Who is targeting your business right now — and what do they want?

This page translates real, active cyber threat intelligence into plain English for UK business owners. No acronyms. No jargon. Just what you need to know and what you should do about it.

What is MITRE ATT&CK — and why does it matter to you?

MITRE is an American non-profit research organisation that works with governments and security agencies worldwide. Their ATT&CK framework is a constantly updated library of every known attack technique used by criminal groups and state-sponsored hackers — built from real incident data, not theory.

Think of it as a documented playbook of everything attackers do. When a criminal group successfully breaks into a bank, a hospital, or a business like yours, their methods get analysed and added to this library. Security professionals use it to understand what they're up against.

MITRE-Lite takes that intelligence and cuts it down to what actually matters for UK SMEs. You don't need to read a 500-page framework. You need to know who is active this week, what they're doing, and whether your business is at risk.

Last updated: 21 July 2026  ·  Week 30 / 2026  ·  Next update: 28 July 2026

Current Status

What is the threat level for UK businesses like yours?

Every week we assess the overall risk level for UK small businesses in financial services — insurance brokers, financial advisers, mortgage intermediaries, and professional services firms. This is based on real intelligence from the UK's National Cyber Security Centre (NCSC), US cyber agencies, and industry reporting.

█ Threat Level: High

This is one of the busiest weeks for confirmed cyber attacks on UK business software in 2026

Seven confirmed vulnerabilities in software used by UK businesses were added to the US government's active exploitation list this week alone. That is the highest weekly count since January. The affected software includes Microsoft SharePoint, Microsoft's identity management system, Fortinet security equipment, and — strikingly — a piece of Cisco networking software with a vulnerability first identified in 2008 that is only now being actively exploited by criminals. This week's threat level is raised to High. If your business has not reviewed its patching and access controls recently, this week is the week to do it.

What do the three levels mean?
Normal — background level of threat activity, no significant increase in targeting of your sector.
Elevated — active campaigns confirmed against UK businesses in your sector. Increased vigilance recommended.
High — significant coordinated threat activity. Specific sectors or business types being actively targeted at scale.
Most Urgent This Week

The most important thing your staff need to know right now

Each week we identify the single highest-risk attack technique that is seeing a spike in use against UK businesses. This week:

► Highest Risk This Week — Week 30 / 2026 █ THREAT LEVEL HIGH

Microsoft's identity system has a new vulnerability — and it could give attackers keys to everything

If your business uses Microsoft 365 — and the majority of UK businesses do — your organisation almost certainly uses something called Active Directory Federation Services, or ADFS. It is the layer that manages who is allowed to log in, what they can access, and how different Microsoft systems recognise each other. It is, in effect, the keymaster for your entire Microsoft environment.

This week, a confirmed vulnerability in ADFS (CVE-2026-56155) was added to the US government's actively-exploited list. The vulnerability allows an attacker who already has a standard user account — perhaps obtained through a phishing email or a previous breach — to elevate their privileges to administrator level. Once at administrator level, they can access everything: email, SharePoint, Teams, your file storage, your backup systems.

At the same time, Microsoft SharePoint has received its third confirmed vulnerability in four weeks. This one (CVE-2026-56164) requires no login at all — an unauthenticated attacker on your network can use it to elevate their privileges directly. The pattern of repeated SharePoint vulnerabilities in consecutive weeks is unusual and worth taking seriously.

And in an editorial detail that tells you something important about how cyber attacks work: a Cisco networking vulnerability first discovered in 2008 — eighteen years ago — was added to the active exploitation list this week. Criminal groups are scanning for and successfully exploiting vulnerabilities in equipment that businesses installed years ago and have never patched.

What to do right now: Contact your IT provider and ask three questions: (1) Has the Microsoft ADFS patch for CVE-2026-56155 been applied? (2) Are all SharePoint patches from July 2026 up to date? (3) Do we have any Cisco networking equipment running IOS 12.4 — if so, is it patched or due for replacement? If your IT provider manages your Microsoft 365 environment, these should all be confirmable within the day.
Also this week — Fortinet equipment is still under active attack: Two new Fortinet FortiSandbox vulnerabilities were added to the confirmed-exploited list this week, both allowing unauthenticated attackers to run commands on affected systems. FortiSandbox is enterprise security analysis equipment rather than the FortiGate firewalls targeted in the FortiBleed campaign — but the pattern is consistent: Fortinet products across the range are being actively targeted. If your business uses any Fortinet equipment, confirm with your IT provider that all firmware is current and that no management interfaces are exposed to the internet.
Also this week — the NCSC is offering free hands-on cyber help to small businesses: The National Cyber Security Centre announced a free hands-on cyber consultancy programme for UK small businesses. This is a direct resource your business can access — not a government leaflet but actual consultancy support. If you have been putting off a security review because of cost, this is worth looking at. The link is on the NCSC website: ncsc.gov.uk. Search for "helping small businesses cyber consultancy."
1
Ask your IT provider to confirm all July Microsoft patches have been applied — specifically ADFS and SharePoint

Microsoft releases security patches on the second Tuesday of each month — this is known as Patch Tuesday, and July's round included fixes for the ADFS and SharePoint vulnerabilities confirmed exploited this week. If your IT provider manages your Microsoft environment, they should have applied these automatically. But "should have" and "has been" are not the same thing. Contact them today and ask specifically: have the July 2026 Microsoft security patches been applied, and in particular the patches for Active Directory Federation Services (CVE-2026-56155) and SharePoint (CVE-2026-56164 and CVE-2026-58644)? You do not need to understand what those reference numbers mean — the question is enough. A well-run IT provider will confirm within hours.

Why now: Both vulnerabilities were added to CISA's active exploitation list on 14–16 July 2026. They are being used in real attacks on real organisations right now. The patches exist — the risk is entirely in whether they have been applied.

2
Check whether your business has any old Cisco networking equipment — and whether it is still receiving security updates

Cisco IOS 12.4 — a version of Cisco's networking software released in the mid-2000s — has just had an 18-year-old vulnerability added to the active exploitation list. This means criminals are scanning for and successfully attacking networking equipment running software that has not been updated since before the iPhone existed. If your office has Cisco switches, routers, or other networking equipment, ask your IT provider: what version of software is it running, and is it still receiving security updates from Cisco? Equipment running end-of-support software will never receive patches for new vulnerabilities. The only solution for truly end-of-life equipment is replacement. If cost is a concern, prioritise any equipment that faces the internet — switches inside the office are lower risk than routers and firewalls that connect to the outside world.

Why now: CVE-2008-4128 — an 18-year-old vulnerability in Cisco IOS — was added to CISA's active exploitation list on 13 July 2026. Legacy networking equipment is a live attack surface today, not a theoretical future risk.

3
Look into the NCSC's free cyber consultancy for small businesses — and pass it on to clients who need it

The National Cyber Security Centre this week announced a free hands-on cyber consultancy programme specifically for UK small businesses. This is not a generic government guidance document — it is practical consultancy support. For businesses that have been deferring a security review because of cost, this removes the cost barrier. Visit ncsc.gov.uk and search for the small business consultancy programme. If you work with clients, suppliers, or professional contacts who you know have not addressed their cyber security posture, forwarding them this resource is a genuinely useful thing to do. It also positions you as someone who is across the current landscape — which is exactly the kind of trust-building that matters in financial services relationships.

Why now: NCSC published this programme on 15 July 2026. Free, government-backed, hands-on. Cost is one of the most common barriers small businesses cite for not addressing cyber security — this removes it.

Want to know how exposed your business actually is?

A GET-IT resilience scan maps your current defences against the active threat techniques on this page and tells you exactly where your gaps are — in plain English, with costs to fix them.

Book a Free Resilience Scan → View Technical Version
Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, FCA ScamSmart, and the MITRE ATT&CK framework (CC BY 4.0). All figures are sourced from published industry data and government reporting — see the technical version for full source references. This page is updated every Monday. GET-IT Solutions Ltd is not responsible for inaccuracies in third-party source data. Nothing on this page constitutes legal or regulatory advice.