Analysis, Commentary & Case Studies
-
10 JUL 2026
NCSC's Cyber Essentials Pathways Pilot Wasn't Built for SMEs — But Two of Its Findings Are
NCSC's Cyber Essentials Pathways pilot is aimed at large, complex organisations proving alternative controls — not SMEs. But its evidence-over-self-attestation finding and its AI/patching warning land directly on the standard certification route too.
-
19 MAY 2026
FCA, Bank of England and Treasury Issue Joint Warning on Frontier AI Cyber Risk
A joint statement warns regulated firms that frontier AI is amplifying cyber threats at speed and scale — and GET-IT's own audit data shows exactly the gap they're pointing at.
-
CASE STUDY
The NHS WannaCry Crisis: When IT Became an A&E Emergency
How the 2017 WannaCry ransomware attack paralysed the NHS, cancelled 19,000 appointments, and exposed the cost of poor cyber hygiene.
-
CASE STUDY
The $250,000 "Evil Twin" Fraud
How a single character swap in an email domain cost a UK mortgage firm $250,000 — a forensic breakdown of Business Email Compromise.
Active UK Advisories
Managing the cyber risk of agentic AI
Read NCSC Advisory →How BitLocker PINs help protect your data and devices
Read NCSC Advisory →Help shape the future of resilient private 5G
Read NCSC Advisory →Water sector example added to the NCSC’s Secure connectivity principles
Read NCSC Advisory →NCSC statement in response to recent incidents resulting from frontier AI evaluations
Read NCSC Advisory →Making forensic observability the norm for network devices
Read NCSC Advisory →Known Exploited Vulnerabilities — Active in the Wild
Ajax.NET Professional Ajax.NET Professional Vulnerability
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
View CISA Advisory → CVE-2015-3246 — Red Hat | LibuserRed Hat Libuser Vulnerability
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
View CISA Advisory → CVE-2015-5287 — Red Hat | Automatic Bug Reporting ToolRed Hat Automatic Bug Reporting Tool Vulnerability
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
View CISA Advisory → CVE-2022-0995 — Linux | KernelLinux Kernel Vulnerability
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
View CISA Advisory → CVE-2026-8452 — Citrix | NetScaler ADC and NetScaler GatewayCitrix NetScaler ADC and NetScaler Gateway Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
View CISA Advisory → CVE-2019-1068 — Microsoft | SQL ServerMicrosoft SQL Server Vulnerability
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
View CISA Advisory →Financial Fraud Warnings & Action Fraud Alerts
EGR Wealth Limited enters administration
On 24 August 2026, EGR Wealth Limited (EGR Wealth) entered administration. Robert Goodhew and Geoff Bouchier of Kroll Advisory Limited were appointed joint administrators. The joint administrators are responsible for ma...
Read FCA Warning →Consumers warned to beware of risky mini-bonds and loan notes
The FCA is warning consumers about the risks of investing in loan notes and mini-bonds issued by unregulated companies, after continuing to see people lose money in these high-risk investments. The recent failure of Woo...
Read FCA Warning →Unregulated loan notes and mini-bonds: don't risk your savings on promises of high returns
These high-risk investments should not usually be advertised widely to the public. We banned the marketing of speculative mini-bonds and loan notes to ordinary retail investors from 1 January 2021.We did this because th...
Read FCA Warning →Trial date set for individual charged with illegal promotions
On 30 July 2026, Lucy Beck attended Southwark Crown Court for a hearing in relation to unauthorised promotions on social media. Ms Beck entered a not guilty plea and the date of her trial has been set as 12 June 2028.It...
Read FCA Warning →Blue Motor Finance Limited enters administration
On 30 July 2026, Blue Motor Finance Limited (BMFL) was placed into administration. Simon Edel, Richard Barker and Alan Michael Hudson of Ernst & Young LLP were appointed as joint administrators. BMFL (firm reference...
Read FCA Warning →ICO Enforcement Notices & Data Protection Penalties
ICO Enforcement Notices & Monetary Penalties
The ICO regularly issues fines and enforcement notices for data protection breaches under UK GDPR. View the full register of actions below.
View ICO Enforcement Register →Is Your Business Exposed?
Many of these vulnerabilities affect software used by UK SMEs every day. A GET-IT threat intelligence scan will tell you exactly where your perimeter stands.
Book a Resilience Scan →Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, the FCA ScamSmart programme, and the ICO Enforcement register. This page is updated automatically every 12 hours. For the most current advisories visit the source links directly. GET-IT Cyber Division curates this content for UK SME relevance but is not responsible for the accuracy of third-party source data.