
Cyber crises demand more than technical teams and technical fixes. Dan Potter of Immersive argues HR, legal, and communications must be drilled alongside security staff, with rehearsed handoffs and role-swap exercises helping organisations respond faster, and with greater cohesion, when incidents hit.

Basic security mistakes still dominate major cloud breaches, Wiz warns. New research says AI is widening the environments where known weaknesses appear, rather than creating entirely new classes of risk.

Unapproved AI use is outpacing policy inside UK workplaces today. Studio Graphene’s research suggests many organisations remain exposed on governance, communication, and oversight as employees adopt unsanctioned AI tools faster than leadership teams respond.

SonicWall says SMB cyber gaps remain painfully predictable in 2026. Its new report recasts annual threat research around protection outcomes, arguing that preventable operational failures still drive most small business exposure.

Paper records remain a stubborn data protection risk for employers. Officeology says thousands of paperwork-related breaches have been reported in recent years, with employee data regularly caught up in late-reported offline incidents.

Drata has unveiled agentic AI for enterprise trust workflows today. The release targets third-party risk, security questionnaires, and Trust Centre creation with more automated workflow ownership.

Check Point has launched a control layer for enterprise AI. The new AI Defense Plane is designed to govern employee AI use, AI applications, and agentic systems from one security architecture.

Sectigo has launched a platform to scale certificate services globally. The company is targeting channel partners with a multi-tenant system designed to turn certificate lifecycle management into a recurring managed service.

Infosecurity Europe is tying cyber risk to geopolitical instability directly. The event’s 2026 keynote programme will examine cyber conflict, resilience, and European cooperation as organisers report rising concern about how international tensions are reshaping security collaboration.

The cyber weak point increasingly sits beyond the core stack. Fresh warnings on messaging app targeting, botnets built from neglected devices, and the resilience of threat actors after takedowns all point to the same problem: organisations still struggle more with behaviour, asset visibility, authentication, and third-party control than with encryption itself.