Analysis, Commentary & Case Studies
-
10 JUL 2026
NCSC's Cyber Essentials Pathways Pilot Wasn't Built for SMEs — But Two of Its Findings Are
NCSC's Cyber Essentials Pathways pilot is aimed at large, complex organisations proving alternative controls — not SMEs. But its evidence-over-self-attestation finding and its AI/patching warning land directly on the standard certification route too.
-
19 MAY 2026
FCA, Bank of England and Treasury Issue Joint Warning on Frontier AI Cyber Risk
A joint statement warns regulated firms that frontier AI is amplifying cyber threats at speed and scale — and GET-IT's own audit data shows exactly the gap they're pointing at.
-
CASE STUDY
The NHS WannaCry Crisis: When IT Became an A&E Emergency
How the 2017 WannaCry ransomware attack paralysed the NHS, cancelled 19,000 appointments, and exposed the cost of poor cyber hygiene.
-
CASE STUDY
The $250,000 "Evil Twin" Fraud
How a single character swap in an email domain cost a UK mortgage firm $250,000 — a forensic breakdown of Business Email Compromise.
Active UK Advisories
NCSC statement in response to recent incidents resulting from frontier AI evaluations
Read NCSC Advisory →Making forensic observability the norm for network devices
Read NCSC Advisory →When cyber attacks happen: helping organisations recover
Read NCSC Advisory →UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations
Read NCSC Advisory →Post-quantum cryptography (PQC) migration workshop report
Read NCSC Advisory →Helping small businesses with free, hands-on cyber consultancy
Read NCSC Advisory →Known Exploited Vulnerabilities — Active in the Wild
N-able N-central Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
View CISA Advisory → CVE-2026-34486 — Apache | TomcatApache Tomcat Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
View CISA Advisory → CVE-2026-9198 — IBM | LangflowIBM Langflow Vulnerability
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
View CISA Advisory → CVE-2026-18577 — N-able | N-centralN-able N-central Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
View CISA Advisory → CVE-2026-20316 — Cisco | Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center (FMC) Vulnerability
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
View CISA Advisory → CVE-2025-68686 — Fortinet | FortiOSFortinet FortiOS Vulnerability
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.
View CISA Advisory →Financial Fraud Warnings & Action Fraud Alerts
Trial date set for individual charged with illegal promotions
On 30 July 2026, Lucy Beck attended Southwark Crown Court for a hearing in relation to unauthorised promotions on social media. Ms Beck entered a not guilty plea and the date of her trial has been set as 12 June 2028.It...
Read FCA Warning →Blue Motor Finance Limited enters administration
On 30 July 2026, Blue Motor Finance Limited (BMFL) was placed into administration. Simon Edel, Richard Barker and Alan Michael Hudson of Ernst & Young LLP were appointed as joint administrators. BMFL (firm reference...
Read FCA Warning →Strengthening resilience across an increasingly interconnected financial system
Think of the last time you made a payment, transferred money, used a banking app or logged on to online financial services. Did you give much thought to the infrastructure that makes those essential everyday transactions...
Read FCA Warning →FCA secures majority of victims’ money back from convicted fraudster
Victims of convicted fraudster John Burford are set to recover the majority of the money they invested after the FCA obtained a confiscation order against him. In September 2025 Mr Burford, 86, was sentenced to 2 years...
Read FCA Warning →FCA decides to ban father and son following fraud and misuse of client money
The FCA has decided to ban a father and son from UK financial services after the High Court found that they had engaged in fraud and misused client money.
Read FCA Warning →Anthropic to support FCA’s Supercharged Sandbox
Anthropic will support the second group of firms in the FCA's Supercharged Sandbox. The Sandbox is a controlled environment where firms can safely experiment with advanced AI.Anthropic will provide access to Claude for...
Read FCA Warning →ICO Enforcement Notices & Data Protection Penalties
ICO Enforcement Notices & Monetary Penalties
The ICO regularly issues fines and enforcement notices for data protection breaches under UK GDPR. View the full register of actions below.
View ICO Enforcement Register →Is Your Business Exposed?
Many of these vulnerabilities affect software used by UK SMEs every day. A GET-IT threat intelligence scan will tell you exactly where your perimeter stands.
Book a Resilience Scan →Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, the FCA ScamSmart programme, and the ICO Enforcement register. This page is updated automatically every 12 hours. For the most current advisories visit the source links directly. GET-IT Cyber Division curates this content for UK SME relevance but is not responsible for the accuracy of third-party source data.