MITRE-Lite has two versions. You're reading the plain English edition — written for business owners, no technical knowledge needed. MITRE ATT&CK is the gold standard framework used by cybersecurity professionals worldwide. It's also highly technical by design. We built both versions so everyone in your business can act on the same intelligence. View Technical Version →
MITRE-Lite Plain English Edition ● Updated This Month

Who is targeting your business right now — and what do they want?

This page translates real, active cyber threat intelligence into plain English for UK business owners. No acronyms. No jargon. Just what you need to know and what you should do about it.

What is MITRE ATT&CK — and why does it matter to you?

MITRE is an American non-profit research organisation that works with governments and security agencies worldwide. Their ATT&CK framework is a constantly updated library of every known attack technique used by criminal groups and state-sponsored hackers — built from real incident data, not theory.

Think of it as a documented playbook of everything attackers do. When a criminal group successfully breaks into a bank, a hospital, or a business like yours, their methods get analysed and added to this library. Security professionals use it to understand what they're up against.

MITRE-Lite takes that intelligence and cuts it down to what actually matters for UK SMEs. You don't need to read a 500-page framework. You need to know who is active this month, what they're doing, and whether your business is at risk.

Last updated: 28 September 2026  ·  September 2026 Edition  ·  Next update: October 2026

Current Status

What is the threat level for UK businesses like yours?

Every month we assess the overall risk level for UK small businesses in financial services — insurance brokers, financial advisers, mortgage intermediaries, and professional services firms. This is based on real intelligence from the UK's National Cyber Security Centre (NCSC), US cyber agencies, and industry reporting.

⚠
█ Threat Level: Elevated

Attacks on UK financial services businesses remain above normal levels this month

Seven criminal and state-sponsored groups continue running active operations targeting UK businesses in your sector. This month brought the highest number of confirmed, actively-exploited vulnerabilities MITRE-Lite has tracked in a single month — seventeen in total — concentrated in the software that connects your business to the internet: VPN and remote-access appliances from Citrix, Cisco and F5, plus fresh confirmed exploits in WordPress and Microsoft SharePoint, and two separate zero-day flaws in the Chrome/Edge browser engine. The UK's National Cyber Security Centre had already flagged this exact pattern in late August, warning specifically about the risk from internet-exposed systems and edge devices.

What do the three levels mean?
Normal — background level of threat activity, no significant increase in targeting of your sector.
Elevated — active campaigns confirmed against UK businesses in your sector. Increased vigilance recommended.
High — significant coordinated threat activity. Specific sectors or business types being actively targeted at scale.
Most Urgent This Month

The most important thing your staff need to know right now

Each week we identify the single highest-risk attack technique that is seeing a spike in use against UK businesses. This week:

► Highest Risk This Month — September 2026 Edition

The software that connects your business to the internet — your VPN, your website, your remote-access tools — had a very bad month

Seventeen separate security flaws were confirmed as actively being used in real attacks this month — the highest number MITRE-Lite has tracked in a single month since we started this dashboard. Most of them share one thing in common: they're in the equipment and software that sits at the edge of your network, connecting your business to the internet.

Citrix NetScaler — a piece of equipment many businesses use to let staff connect to office systems remotely, especially since the shift to hybrid working — had two separate flaws confirmed exploited in the same week. One of them lets an attacker with no username or password run commands on the device directly. Cisco had three separate confirmed exploits across its network security and email filtering products, including one that hands an attacker full administrator-level access. If your business uses any of this equipment — usually set up and managed by your IT provider rather than something you'd interact with day to day — it needs checking urgently.

Separately, WordPress — the software behind a very large share of small business websites in the UK — had a serious flaw confirmed exploited that can let an attacker take over the server your website runs on. If your website was built on WordPress, this is worth raising with whoever hosts or maintains it. And Microsoft SharePoint picked up its fifth confirmed exploit of the year, continuing a pattern we've flagged in previous editions — if your business stores documents or runs an intranet on SharePoint, confirm this month's patches have been applied.

Finally, and this one affects literally everyone: Google confirmed two separate serious flaws in the technology that powers Chrome, Microsoft Edge, and Opera — the browsers most UK businesses use every day. Both let an attacker take control of your computer just by getting you to visit a malicious web page, no download required.

What to do right now: Ask your IT provider three specific questions this week: (1) do we have any Citrix, Cisco, or F5 remote-access equipment, and has it been patched against this month's confirmed exploits; (2) is our website built on WordPress, and has it been updated; and (3) are all our staff browsers (Chrome, Edge) set to update automatically, and can you confirm they're on the latest version. All three are checkable within a day and don't require any downtime.
Also this month — NCSC published three further pieces on AI risk, and confirmed Iranian state spyware activity: Building on last month's first-ever guidance on AI agents, NCSC published scheme documents for testing your defences against simulated attacks, a piece on defending against AI-driven threats, and a warning about employees using AI tools without permission ("shadow AI"). Separately, NCSC and allied agencies confirmed that Iranian state-linked actors have been running spyware campaigns against UK-based activists and journalists — a reminder that state-level targeting, while not usually aimed at ordinary SMEs, continues to escalate in sophistication.
Also this month — a fake takeover bid fraud case and a warning on money mule accounts: A UK man has pleaded guilty to fraud and forgery after fabricating a fake takeover approach for a listed company — a useful reminder that impersonation fraud isn't limited to email; it can extend to entire fabricated corporate approaches. Separately, the FCA reports that financial firms are shutting down record numbers of suspected "money mule" accounts used to launder stolen funds, but says more needs to be done. For insurance brokers and financial advisers, fraud awareness — for both your business and your clients — is worth an active conversation this quarter.
1
Ask your IT provider whether your business uses Citrix, Cisco, or F5 remote-access equipment — and get it checked this week

These are the pieces of equipment that let your staff connect to office systems from home, or that filter your email and protect your network perimeter. They're usually set up once by an IT provider and rarely thought about again — which is exactly why they're a target. This month, two separate flaws in Citrix NetScaler were confirmed exploited, one of which lets an attacker run commands without any login at all. Cisco had three separate confirmed exploits, including one that hands an attacker full administrator access. If you don't know whether your business uses this kind of equipment, that's the first question to ask your IT provider — many businesses use it without realising, bundled into their VPN or firewall setup.

Why now: Citrix NetScaler flaws confirmed exploited 27 September 2026 (CVE-2026-88771, CVE-2026-88772); Cisco flaws confirmed exploited 9–16 September 2026 (CVE-2026-76460, CVE-2026-76461, CVE-2026-20079). Several require no valid login to exploit.

2
If your business website runs WordPress, confirm it's been updated this month

WordPress powers a very large share of small business websites in the UK — if you're not sure whether yours does, ask whoever built or hosts it. A serious flaw confirmed this month allows an attacker to trick the site into loading a file of their choosing from outside its normal folders, which can lead to them taking full control of the server your website runs on. Most reputable hosts and developers will patch this automatically, but it's worth a direct check — especially if your site uses older plugins or a developer you haven't heard from in a while.

Why now: CVE-2026-87902 confirmed exploited 25 September 2026. The flaw requires no login and can lead to complete server takeover.

3
Make sure every computer's web browser is set to update automatically

Google confirmed two separate serious flaws this month in the underlying technology that powers Chrome, Microsoft Edge, and Opera. Both allow an attacker to take control of a computer simply by getting someone to visit a malicious web page — no download or file needed. Browsers usually update themselves in the background, but the update often only takes effect once the browser is fully restarted, and staff frequently leave dozens of tabs open for weeks without restarting. Encourage staff to fully close and reopen their browser every few days, and check with your IT provider that automatic updates haven't been disabled anywhere.

Why now: CVE-2026-87491 confirmed exploited 9 September 2026; CVE-2026-85046 confirmed exploited 4 September 2026. Both are actively exploited sandbox-escape flaws affecting nearly every UK business's browser.

Want to know how exposed your business actually is?

A GET-IT resilience scan maps your current defences against the active threat techniques on this page and tells you exactly where your gaps are — in plain English, with costs to fix them.

Book a Free Resilience Scan → View Technical Version
Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, FCA ScamSmart, and the MITRE ATT&CK framework (CC BY 4.0). All figures are sourced from published industry data and government reporting — see the technical version for full source references. This page is updated monthly. GET-IT Solutions Ltd is not responsible for inaccuracies in third-party source data. Nothing on this page constitutes legal or regulatory advice.