Live National Cyber Helpline · 0300 123 2040
Assured Cyber Protection Cyber & insurance briefing

News

Cyber Security News: July 2026

By the Assured Cyber Protection team · Updated 2026 · Reviewed

The back half of July brought two ransomware reports that shift where the risk actually sits, a free hands-on offer from the NCSC aimed at smaller firms, and a jump in the cover on offer to SMEs. Here is what happened between roughly 15 and 24 July, and what it means if you run a small business, buy cyber cover or hold Cyber Essentials.

Stolen logins now start most ransomware attacks

Sophos published its State of Ransomware 2026 report, and for the first time in four years the leading way in was not an unpatched software flaw but a stolen or guessed login. Compromised credentials started 79% of the attacks studied, and, tellingly, 97% of the affected organisations already had multi-factor authentication in place, so attackers found ways around it through phishing, session theft and fatigue. For a small business the read is that patching alone no longer covers you: the front door is now your staff accounts. Turning on phishing-resistant MFA, killing shared and dormant logins, and using long unique passwords are the cheap wins here, and they map straight onto what a Cyber Essentials assessment checks. Our password strength and crack-time calculator shows how quickly a weak one falls, and our guide to Cyber Essentials certification sets out the controls insurers expect. Reported by Dark Reading.

Proofpoint says AI is making ransomware land more often

On 22 July, Proofpoint released its 2026 AI-Era Ransomware Report, in which nearly two-thirds of organisations hit by ransomware (65%) said AI had made the attack more effective. The practical effect is sharper, more convincing phishing and faster movement once an attacker is inside, which shortens the window a small team has to spot and stop an incident. None of this changes the fundamentals, but it does raise the cost of a slow response, which is exactly what an incident-response retainer and a tested backup are for. Our cyber insurance readiness checklist is a quick way to see whether those basics are in place, and our guide to what cyber insurance covers and its exclusions helps you check your policy pays for the response, not just the loss. Details from Proofpoint.

NCSC offers small firms a free 30-minute cyber consultation

The NCSC published a blog on 15 July promoting free, no-strings 30-minute consultations from its assured Cyber Advisors, aimed at smaller businesses that want to get started with Cyber Essentials but find the subject daunting. A Cyber Advisor is an NCSC-assured practitioner who translates the official guidance into practical steps for a firm without an in-house security team, and you book one directly through the IASME directory. If cyber has sat on your to-do list because you did not know where to begin, this is a genuinely low-cost way in, and getting to Cyber Essentials both lowers your risk and widens the insurers willing to quote you. Our Cyber Essentials certification guide covers what the standard asks for. Read the announcement at the NCSC.

SME cyber cover limits keep climbing as the market stays soft

Underwriter Pen Underwriting has doubled its cyber cover limit to £10 million for UK small and mid-sized businesses with revenue up to £600 million, effective from the start of July, and moved claims handling in-house to speed up payouts. It is another sign of a competitive, buyer-friendly market: capacity and limits are rising while pricing stays soft. For buyers that means it is worth shopping around and asking for a higher limit than last year, but the deciding factor is still what the policy actually does, because response support and third-party liability vary widely. Our note on first-party versus third-party cover explains the split, and our cover level calculator helps you size the limit you need. Reported by The Insurer.

The Threat Brief

A calm, plain-English security update. Once a week.

New scams, breach lessons, and cyber insurance changes that affect UK businesses, explained without the jargon. No alarmism, no vendor spin.

Unsubscribe anytime. We never share your address.