Analysis, Commentary & Case Studies
-
10 JUL 2026
NCSC's Cyber Essentials Pathways Pilot Wasn't Built for SMEs — But Two of Its Findings Are
NCSC's Cyber Essentials Pathways pilot is aimed at large, complex organisations proving alternative controls — not SMEs. But its evidence-over-self-attestation finding and its AI/patching warning land directly on the standard certification route too.
-
19 MAY 2026
FCA, Bank of England and Treasury Issue Joint Warning on Frontier AI Cyber Risk
A joint statement warns regulated firms that frontier AI is amplifying cyber threats at speed and scale — and GET-IT's own audit data shows exactly the gap they're pointing at.
-
CASE STUDY
The NHS WannaCry Crisis: When IT Became an A&E Emergency
How the 2017 WannaCry ransomware attack paralysed the NHS, cancelled 19,000 appointments, and exposed the cost of poor cyber hygiene.
-
CASE STUDY
The $250,000 "Evil Twin" Fraud
How a single character swap in an email domain cost a UK mortgage firm $250,000 — a forensic breakdown of Business Email Compromise.
Active UK Advisories
China-linked malicious actors called out by UK and international partners for targeting sensitive data globally
Read NCSC Advisory →Incident affecting ASOS customers
Read NCSC Advisory →Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
Read NCSC Advisory →One does not simply defend agentically
Read NCSC Advisory →Cyber Adversary Simulation (CyAS): scheme documents now available
Read NCSC Advisory →Adversary simulation: what you need to know
Read NCSC Advisory →Known Exploited Vulnerabilities — Active in the Wild
ISC BIND Vulnerability
ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
View CISA Advisory → CVE-2016-3081 — Apache | StrutsApache Struts Vulnerability
Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
View CISA Advisory → CVE-2023-22894 — Strapi | StrapiStrapi Strapi Vulnerability
Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution.
View CISA Advisory → CVE-2021-3199 — ONLYOFFICE | DocsONLYOFFICE Docs Vulnerability
ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
View CISA Advisory → CVE-2015-3306 — ProFTPD | ProFTPDProFTPD ProFTPD Vulnerability
ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
View CISA Advisory → CVE-2026-88779 — Citrix | NetScalerCitrix NetScaler Vulnerability
Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.
View CISA Advisory →Financial Fraud Warnings & Action Fraud Alerts
FCA secures money back for victims of crypto fraud
Victims of a £1.5m crypto investment fraud will recover lost funds after the FCA obtained confiscation orders against Raymondip Bedi and Patrick Mavanga. At a hearing at Southwark Crown Court on 28 September 2026, Raymo...
Read FCA Warning →InterestMe Financial Planning Limited (IMFP) and the appointed representative InterestMe Advisers Limited (IMA) enter administration
On 24 September 2026, IMFP and IMA entered administration. Robert Goodhew and Geoff Bouchier of Kroll Advisory Limited were appointed joint administrators for both firms. The joint administrators are responsible for man...
Read FCA Warning →Firms crack down on money mules but need to do more
Financial firms are shutting down hundreds of thousands of suspected money mule accounts, but organised criminal groups are still shifting dirty money through multiple bank accounts before cashing out. An FCA survey fou...
Read FCA Warning →Debt advice warning: spot the red flags
People seeking debt advice are being urged to watch out for red flags. Free debt advice is available to everyone. However, the FCA is concerned that some consumers are being steered towards fee-paying debt solutions tha...
Read FCA Warning →FCA takes Hunter Jones to High Court over alleged unauthorised activity
The FCA has begun High Court proceedings against Osborne Baldwin Limited, which trades as Hunter Jones and Hunter Jones Group. The FCA alleges that Hunter Jones, which sells loan notes, carries out regulated activity wi...
Read FCA Warning →ICO Enforcement Notices & Data Protection Penalties
ICO Enforcement Notices & Monetary Penalties
The ICO regularly issues fines and enforcement notices for data protection breaches under UK GDPR. View the full register of actions below.
View ICO Enforcement Register →Is Your Business Exposed?
Many of these vulnerabilities affect software used by UK SMEs every day. The Cyber Resilience Review tells you where you stand and what to prioritise.
Explore the Cyber Resilience Review →Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, the FCA ScamSmart programme, and the ICO Enforcement register. This page is updated automatically every 12 hours. For the most current advisories visit the source links directly. GET-IT Cyber Division curates this content for UK SME relevance but is not responsible for the accuracy of third-party source data.