Analysis, Commentary & Case Studies
-
10 JUL 2026
NCSC's Cyber Essentials Pathways Pilot Wasn't Built for SMEs — But Two of Its Findings Are
NCSC's Cyber Essentials Pathways pilot is aimed at large, complex organisations proving alternative controls — not SMEs. But its evidence-over-self-attestation finding and its AI/patching warning land directly on the standard certification route too.
-
19 MAY 2026
FCA, Bank of England and Treasury Issue Joint Warning on Frontier AI Cyber Risk
A joint statement warns regulated firms that frontier AI is amplifying cyber threats at speed and scale — and GET-IT's own audit data shows exactly the gap they're pointing at.
-
CASE STUDY
The NHS WannaCry Crisis: When IT Became an A&E Emergency
How the 2017 WannaCry ransomware attack paralysed the NHS, cancelled 19,000 appointments, and exposed the cost of poor cyber hygiene.
-
CASE STUDY
The $250,000 "Evil Twin" Fraud
How a single character swap in an email domain cost a UK mortgage firm $250,000 — a forensic breakdown of Business Email Compromise.
Active UK Advisories
One does not simply defend agentically
Read NCSC Advisory →Adversary simulation: what you need to know
Read NCSC Advisory →Cyber Adversary Simulation (CyAS): scheme documents now available
Read NCSC Advisory →Iranian cyber targeting of dissidents, activists and journalists
Read NCSC Advisory →UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
Read NCSC Advisory →The hidden risks of shadow AI
Read NCSC Advisory →Known Exploited Vulnerabilities — Active in the Wild
Arista VeloCloud Orchestrator Vulnerability
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
View CISA Advisory → CVE-2026-94127 — F5 | BIG-IP APMF5 BIG-IP APM Vulnerability
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
View CISA Advisory → CVE-2026-93616 — Check Point | Multiple ProductsCheck Point Multiple Products Vulnerability
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
View CISA Advisory → CVE-2026-85102 — Check Point | Multiple ProductsCheck Point Multiple Products Vulnerability
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
View CISA Advisory → CVE-2026-7273 — Zyxel | GS1900 Series SwitchesZyxel GS1900 Series Switches Vulnerability
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
View CISA Advisory → CVE-2025-39964 — Linux | KernelLinux Kernel Vulnerability
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
View CISA Advisory →Financial Fraud Warnings & Action Fraud Alerts
Debt advice warning: spot the red flags
People seeking debt advice are being urged to watch out for red flags. Free debt advice is available to everyone. However, the FCA is concerned that some consumers are being steered towards fee-paying debt solutions tha...
Read FCA Warning →FCA takes Hunter Jones to High Court over alleged unauthorised activity
The FCA has begun High Court proceedings against Osborne Baldwin Limited, which trades as Hunter Jones and Hunter Jones Group. The FCA alleges that Hunter Jones, which sells loan notes, carries out regulated activity wi...
Read FCA Warning →Building a stronger UK investment culture
Speech by Lucy Castledine, director of consumer investments, at the 2026 Investor Summit. Speaker: Lucy Castledine, director, consumer investmentsEvent: Investor Summit 2026, LondonDelivered: 18 September 2026Note: This...
Read FCA Warning →Financial crime: protecting the hive
Speech by Steve Smart, executive director of enforcement and market oversight, at the Law Society Economic Crime Conference 2026. IntroductionA few weeks ago, I visited the Bank of England Museum to see a new exhibition...
Read FCA Warning →Upper Tribunal upholds Crispin Odey ban
Crispin Odey’s ban from the financial services industry has been upheld by the Upper Tribunal, which found he lacked integrity. Mr Odey was the founder and majority owner of Odey Asset Management (OAM). He faced an inte...
Read FCA Warning →Man pleads guilty to fraud and forgery offences relating to fake takeover approach
Christopher Woolcott has pleaded guilty to 4 counts of fraud and forgery after creating a fake takeover bid for Touchstone Exploration Inc. Mr Woolcott held shares in Touchstone Exploration Inc and stood to benefit fina...
Read FCA Warning →ICO Enforcement Notices & Data Protection Penalties
ICO Enforcement Notices & Monetary Penalties
The ICO regularly issues fines and enforcement notices for data protection breaches under UK GDPR. View the full register of actions below.
View ICO Enforcement Register →Is Your Business Exposed?
Many of these vulnerabilities affect software used by UK SMEs every day. A GET-IT threat intelligence scan will tell you exactly where your perimeter stands.
Book a Resilience Scan →Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, the FCA ScamSmart programme, and the ICO Enforcement register. This page is updated automatically every 12 hours. For the most current advisories visit the source links directly. GET-IT Cyber Division curates this content for UK SME relevance but is not responsible for the accuracy of third-party source data.