SOC status:Duty analyst on shift

UK Cyber Defence

Sectors

Every sector has its ownadversaries. We report on them weekly.

Our SOC publishes a threat intelligence report for each of the sectors below every week — the same reports our clients receive, minus their estate-specific detail. Pick your sector to see the current picture and how we defend it.

Financial servicesLegalHealthcareMaritime and logisticsRetailDefence and government

Common ground

Different sectors, shared problems

Every sector has its own language, regulation and technology, but most of the ways in is the same. Our method is consistent — threat-led, intelligence-driven, engineering-focused — and the sector pages show how we apply it.

01

Cloud and identity

Entra ID, Microsoft 365 and SaaS access for staff, contractors and partners — the identity layer is where most 2026 intrusions begin.

02

Edge appliances

VPN concentrators, firewalls and remote-access gateways whose vulnerabilities are exploited within days of disclosure.

03

Email, phishing and BEC

Payment diversion, credential harvesting and AI-assisted pretexting aimed at the processes each sector runs on.

04

OT, IoT and operational systems

Industrial control, medical devices, vessel and warehouse automation that cannot simply be patched.

05

Ransomware and data extortion

Double extortion remains the dominant criminal business model; the aim is to make you a bad target and a fast recoverer.

06

Regulation and assurance

FCA, DORA, NIS, DSPT, DEF STAN, PCI DSS and Cyber Essentials — evidence that stands up to an auditor, produced as a by-product of doing the work.

This week

Latest sector threat intelligence

All insights →

Start a conversation

Not sure where you fit?

Many clients span several sectors or sit in a niche of their own. Tell us about your environment and we will map the right combination of monitoring, testing and advice.