Friday, 9 October 2026
GoCardless
Section

Cybersecurity

Threats, regulation and the leaders responsible for resilience.

VETTDD cybersecurity section card
Column

The NCSC has told MSSPs what an ‘autonomous SOC’ is really worth

Dave Chismon, writing on the NCSC’s website, says defenders cannot use AI as attackers do and that people, not machines, must act on what the machines find. For MSSPs that is a pricing model, not a warning

Editor · 21 Sept 2026

Kevin Hanes, chief executive of Quorum Cyber
The Brief

Quorum Cyber agrees to buy Ontinue from EQT in Microsoft MDR deal

Both providers build their managed security services on Microsoft's tools. The combined business would put AI agents at the center of its security operations, aiming at customers in North America, the UK and German-speaking Europe

Kevin Hanes, Quorum Cyber · 16 Sept 2026

Ian Brown, executive chairman of Integrity360
Column

Identity, not the SOC, is where the next MSSP premium sits

Integrity360 has bought its way across three continents in nine months, but the CyberIAM deal is the first about capability rather than geography. A UK MSSP without an identity practice will now be priced on its SOC alone

Editor · 27 Aug 2026

VETTDD cybersecurity section card
Column

Beacon breach shows what supplier questionnaires miss

Beacon CRM says the probable cause of its breach was a cloud key potentially exposed in public code. But for the charities that bought it, the harder lesson is about what they handed over

Editor · 13 Aug 2026

The Cytix logo on a blue and green textured background
The Brief

Cytix raises $7m to govern the risk in AI-era software changes

The Manchester startup is betting that security teams need to judge the risk in every code change, not just scan for flaws, as AI-assisted development speeds up release cycles

Ben Armstrong, Cytix · 12 Aug 2026

VETTDD cybersecurity section card
Column

The gap between two suppliers is where breaches live

The ICO’s reprimand of ACRO describes an MSP that patched the servers, a developer contracted to patch the website and nobody tasked with watching for updates or reading the alerts. The regulator now reads the contract before the logs

Editor · 12 Aug 2026

VETTDD cybersecurity section card
Column

Free Cyber Advisor sessions work, but too few small firms know to ask

Roughly one in five small organizations that approached the NCSC’s free Cyber Advisor scheme have since certified, on the agency’s figures. But a scheme that waits to be asked will reach few of the UK’s 5.64 million small businesses

Editor · 16 Jul 2026

VETTDD cybersecurity section card
The Brief

Half of surveyed security providers refer to UK security codes

Government-commissioned research maps a supply side made up mostly of micro and small firms, where penetration testing dominates and services for securing AI after deployment are still patchy

Editor · 10 Jul 2026

VETTDD cybersecurity section card
The Brief

UK organizations now need a data protection complaints process

The last parts of the Data (Use and Access) Act are in force. The regulator says its focus is on helping firms comply, but many still think the change passes them by

Emily Keaney, Information Commissioner’s Office · 23 Jun 2026

Illustration of a laptop and tablet with red alert symbols
Column

FortiBleed shows the VPN password is still the weakest door

The NCSC has told FortiGate users to check whether their VPN credentials were leaked in a global campaign. But the real fix is one more than half of UK businesses have yet to make: two-factor login

Editor · 20 Jun 2026

Baroness Lloyd of Effra, cyber security minister
Analysis

UK cyber sector reaches £14.7bn, but its biggest SME rival is ‘do nothing’

Government figures show more suppliers, higher revenue and investors backing smaller firms. Yet services hiring has stalled, and the SME customers many providers depend on still buy mostly what contracts demand

Baroness Lloyd of Effra, Department for Science, Innovation and Technology · 12 May 2026

VETTDD cybersecurity section card
Analysis

Small firms slip on cyber basics as phishing tightens its grip

The government’s annual breach survey finds attack rates flat and micro firms improving. But small businesses have lost last year’s gains in planning, just as officials warn AI is speeding up attackers

Editor · 30 Apr 2026