Threat briefing4 May 2026Financial services threat intelligence report — 27 April – 3 May 2026During the reporting period the financial services threat picture continued to be dominated by ransomware and data-extortion crews, augmented by sustained credential-harvesting against retail and SME banking customers.Peter Bassill14 min read · 3 reads
Threat briefing4 May 2026Defence and government contractors threat intelligence report — 27 April – 3 May 2026The R&D and military-government-contractor threat picture for the reporting period is dominated by sustained state-sponsored activity.Peter Bassill16 min read · 3 reads
Insights26 March 2026The FCC Foreign Router Ban: Supply Chain Risk, State-Sponsored Threat Actors, and What UK Enterprise Security Teams Must Do NowThe FCC's ban on foreign-made routers has direct implications for UK and EU enterprise security posture. We examine the threat model, regulatory context, and strategic response.UK Cyber Defence Editorial Team7 min read · 2 reads
Insights17 February 2026What Should a Board Expect from a Modern SOC Provider?Cyber security has moved from the server room to the boardroom. Regulators, insurers, and shareholders now expect boards to demonstrate active oversight of cyber risk — and for most organisations, that means understanding what their Security Operations Centre provider is actually delivering. This article sets out the ten areas every board should scrutinise when evaluating a modern SOC provider, from detection engineering and threat intelligence to transparent reporting, compliance alignment, and measurable outcomes.Peter Bassill16 min read · 6 reads
Insights16 February 2026LockBit 5.0: New Version Targets Windows, Linux, and ESXi SystemsAn in-depth analysis of LockBit 5.0, the:w! latest evolution of the prolific ransomware family, now targeting Windows, Linux, and VMware ESXi environments with enhanced evasion, cross-platform payloads, and refined extortion tactics.Peter Bassill13 min read · 2 reads
Insights12 February 2026How SOC as a Service Supports FCA, DORA and NIS2 ComplianceThe regulatory environment for cyber security has undergone a fundamental shift. The FCA's PS21/3 operational resilience framework is now fully enforceable, DORA has been in effect since January 2025, and NIS2 transposition is reshaping obligations across the EU — with the UK's own Cyber Security and Resilience Bill following close behind. For organisations navigating these overlapping requirements, a well-structured SOC as a Service engagement is no longer a convenience. It is a compliance enabler. This article maps the specific requirements of each framework to the capabilities a modern managed SOC should deliver.Peter Bassill17 min read · 6 reads
Insights10 February 2026Integrating EDR, XDR and SIEM Within a Managed SOCA technical and strategic guide to understanding how EDR, XDR and SIEM technologies work together within a modern managed SOC — covering telemetry architecture, detection engineering, correlation strategies, response orchestration, and the practical reality of building unified visibility without vendor lock-in.Peter Bassill18 min read · 9 reads
Insights5 February 2026How Alert Fatigue Destroys Security Teams — and How Managed SOC Solves ItThe modern SOC is drowning. Industry research consistently reports that organisations receive thousands of security alerts per day, that the majority are false positives, and that analysts are leaving the profession faster than the industry can replace them. Alert fatigue is not a minor inconvenience — it is a structural vulnerability that attackers actively exploit. When every alert looks the same, none of them look important. This article examines the mechanics of alert fatigue, its quantifiable cost to organisations, and the specific practices a well-engineered managed SOC deploys to break the cycle — because the solution is not working harder, but building a fundamentally different operational model.Peter Bassill16 min read · 7 reads
Insights2 December 2025Hidden Google Play Adware Drains Devices and Disrupts Millions of UsersA major Android adware operation, now known asGhostAd, has been uncovered after spreading quietly through Google Play and affecting millions of users across East and Southeast Asia. Although the apps involved appeared benign at first glance, they concealed aggressive advertising engines that ran continuously in the background, degrading device performance, draining batteries, and causing widespread frustration for victims. The scale of this campaign, combined with the sophistication of its persistence mechanisms, marks it as one of the more impactful adware incidents seen on the platform in rePeter Bassill5 min read · 4 reads
Insights2 December 2025Over 2,000 Holiday-Themed Fake Stores Target Shoppers During Black Friday and Festive SalesThe holiday shopping season has become one of the most lucrative periods of the year for cybercriminals. Alongside legitimate Black Friday and Christmas offers, threat actors are now operating large, co-ordinated networks of fake online stores designed to steal payment card details and personal information at scale.Peter Bassill7 min read · 2 reads
Insights13 October 2025Why OWASP Matters: The Cornerstone of Modern Web Application SecurityExplore why OWASP is vital for web app security, offering tools, standards, and community-driven insights to combat modern cyber threats.Moises Salas Lopez2 min read · 2 reads
Insights3 October 2025What is a VPN? A Beginner’s Guide to Online PrivacyIn today’s digital world, online privacy and security have never been more important. Whether you’re browsing at home, working remotely, or connecting to free Wi-Fi at a café, your data can be exposed to hackers, advertisers, and even your internet service provider (ISP). This is where aVPN (Virtual Private Network)comes in.Moises Salas Lopez2 min read · 3 reads