
Unapproved AI use is outpacing policy inside UK workplaces today. Studio Graphene’s research suggests many organisations remain exposed on governance, communication, and oversight as employees adopt unsanctioned AI tools faster than leadership teams respond.

SonicWall says SMB cyber gaps remain painfully predictable in 2026. Its new report recasts annual threat research around protection outcomes, arguing that preventable operational failures still drive most small business exposure.

Paper records remain a stubborn data protection risk for employers. Officeology says thousands of paperwork-related breaches have been reported in recent years, with employee data regularly caught up in late-reported offline incidents.

Drata has unveiled agentic AI for enterprise trust workflows today. The release targets third-party risk, security questionnaires, and Trust Centre creation with more automated workflow ownership.

Check Point has launched a control layer for enterprise AI. The new AI Defense Plane is designed to govern employee AI use, AI applications, and agentic systems from one security architecture.

Sectigo has launched a platform to scale certificate services globally. The company is targeting channel partners with a multi-tenant system designed to turn certificate lifecycle management into a recurring managed service.

Infosecurity Europe is tying cyber risk to geopolitical instability directly. The event’s 2026 keynote programme will examine cyber conflict, resilience, and European cooperation as organisers report rising concern about how international tensions are reshaping security collaboration.

The cyber weak point increasingly sits beyond the core stack. Fresh warnings on messaging app targeting, botnets built from neglected devices, and the resilience of threat actors after takedowns all point to the same problem: organisations still struggle more with behaviour, asset visibility, authentication, and third-party control than with encryption itself.

EU cyber rules force faster vulnerability reporting and operational change. Sylvain Cortes, VP Strategy at Hackuity, says organisations will need real-time visibility across software supply chains, stronger data consolidation, and faster remediation processes to meet the Cyber Resilience Act’s 24-hour reporting requirement.

Meta incident spotlights fresh risks from autonomous workplace AI tools. RAIDS AI says the episode shows how trust in agent output can become a security weakness even without privileged system access.