Field Notes
Evidence from the field
Notes from the work itself. How attackers really get into businesses like yours in London, United Kingdom, what we find when we go looking, and the fixes that hold. No theory, no scare copy. Just the walk-through.
- Breach Analysis
A Crew Claims It Took Terabytes From the FBI Through PeopleSoft. There Is No CVE to Scan For.
ShinyHunters says it used an unpatched Oracle PeopleSoft flaw to reach FBI systems, deface the bureau’s jobs portal and take 2 to 3 terabytes. The FBI says it is investigating and has confirmed nothing. Whatever the truth of the claim, one detail should move your week: no CVE has been published, so your vulnerability scanner will mark every PeopleSoft server you run as clean tomorrow morning.
9 MIN READ - AI Security
The NCSC Said You Cannot Manage What You Do Not Know. Ten Days Later It Published How to Find Out.
On 7 September 2026 the NCSC published "The hidden risks of shadow AI". Its closing paragraph opens on one line: you cannot manage what you do not know. The blog then names no way to find out. On 17 September the NCSC published the method, under a different name, for a different purpose. Here are the two documents read side by side, the artefacts an outside view actually returns, the ones that need a tenant, and the order of operations that stops you writing policy about tools nobody has counted.
11 MIN READ - AI Security
The NCSC Told You to Keep a Kill Switch for Your AI Agents. It Never Said Who Tests It.
The NCSC published seven considerations for deploying agentic AI on 20 August 2026, ending with the instruction to always be able to pull the plug. Across all seven it never names an independent security test. Here is what each control looks like when somebody attacks it, using Mandiant’s own published engagements, and the four questions to answer before the next agent gets a credential.
12 MIN READ - Buying Security
What a Penetration Test Costs in the UK: Nine Published Day Rates, From £525 to £2,885
Nine UK suppliers print their penetration testing day rate on the government’s Digital Marketplace, where commercial buyers rarely look. BAE Systems Applied Intelligence publishes £525 a day. KPMG publishes a band running to £2,885. Published day counts for the same test type vary four times over. Here is the arithmetic behind a quote, the published ranges by test type, and the scope lines that move the number before anyone starts testing.
11 MIN READ - Compliance
Three Bodies Have Published What a Penetration Test Report Must Contain. Nobody Sends You the Checklist.
SOC 2 does not require a penetration test. Vanta and Drata both say so in writing. What your auditor requires is evidence that you manage vulnerabilities, and the report is that evidence. PCI SSC published a 22-question checklist for the person reading the report. CREST published a 12-element minimum. The NCSC asks for two things almost no commercial report contains. Here are all three, side by side.
11 MIN READ - Threat Intelligence
RMM Security: The Vendor Said the Patch Would Not Remove Whoever Was Already Inside
Five N-central CVEs landed between 1 August and 6 September 2026, and N-able shipped four hotfixes in thirty-five days. The part that matters for an MSP is not the CVSS score. It is the sentence N-able wrote on its own blog: applying the hotfix closes the way in, and leaves a threat actor who is already present exactly where they are. Here is the published chain, what one foothold became inside a single estate, and the exercise that answers the question your client will ask you next.
11 MIN READ - Supply Chain
The Jaguar Land Rover Cyber Attack Hit Over 5,000 UK Organisations. Almost None of Them Were the Target.
The Cyber Monitoring Centre modelled the UK cost of the JLR incident at £1.9 billion and counted more than 5,000 UK organisations affected. Most of those firms were never attacked. Their security held and their revenue stopped anyway, because it depended on one buyer whose plants went quiet. The supplier's version of the event, what the £1.9bn figure rests on, and the question a scoped test never answers unless you ask.
12 MIN READ - Compliance
In a CBEST, Your Tester Scores Your SOC. You Never Get to Edit the Sheet.
The Bank of England has run CBEST since 2014, and most write-ups describe the attack. The part that decides what the regulator reads is the other half: scored capability indicators about your detection and response, filled in by the penetration testing provider and sent straight to the regulator without your sign-off. Here is what is on that sheet, what the Bank found across 13 assessments in 2025, and what the tier below CBEST quietly makes optional.
12 MIN READ - Compliance
Your Cyber Essentials Grace Period Ends Six Months After You Opened the Account. For Some of You That Was July.
The Danzell question set applies to assessment accounts created after 26 April 2026, and Requirements v3.3 took effect on 27 April 2026. IASME gives an account six months from its own date of application to certify under the old rules, so there is no single national deadline. Three answers now fail you outright: MFA on cloud services, A6.4 and A6.5. Here is what each one asks, what the assessor verifies, and the gap that verification method leaves open.
12 MIN READ - Offensive Security
The NCSC Has Written Down What an Adversary Simulation Is. Most of What the UK Buys as a Red Team Is Not One.
On 17 September 2026 the NCSC published buyer guidance on adversary simulation, the thing it says is "sometimes known as red teaming". A typical engagement runs 8 to 12 weeks. Before you qualify to buy one you need reviewed risks, established defences and working detection. Here is the bar, quoted, what to buy if you do not clear it, and what the new CyAS scheme will require of the provider who signs your report.
11 MIN READ - Accreditation
CREST Now Accredits How AI Is Used in Penetration Testing. Three Standards Are Live. Ten Firms Hold the First One.
On 28 July 2026 CREST opened two new accreditations covering how a provider governs and uses AI inside your test. By 21 August 2026 a third was open too, covering whether a provider is fit to test an AI system at all. CREST’s own research says 69% of providers already use AI in penetration testing, and its published breakdown puts 9% on autonomous, agent-based testing. Here are the three questions to put in your next RFP.
10 MIN READ - Threat Intelligence
AI Agents Are Transacting on Your Website. Your Penetration Test Still Assumes a Human.
Automated traffic grew eight times faster than human traffic in 2025. Traffic from AI agents, the kind that log in, fill forms and pay, grew 7,851%. Post-login compromise attempts hit 402,000 per organisation. HUMAN Security's 2026 benchmark puts numbers on a shift most penetration test scopes have not caught up with. Here is what an attacker does with each figure, and what a test must now cover.
12 MIN READ - Compliance
The Cyber Security and Resilience Bill Puts Your MSP in Scope. Here Is What You Will Have to Prove.
If you manage IT for other businesses under contract and you can reach their systems, the Bill makes you a "relevant managed service provider": registered with the Information Commission, held to appropriate and proportionate security measures, and reporting significant incidents within 24 hours. Small and micro firms are out. Everyone else is in, wherever they are based.
11 MIN READ - Data Sovereignty
The UK Is Not Just Exposed to the CLOUD Act. It Signed the Agreement That Runs Both Ways.
The US-UK Data Access Agreement has been in force since October 2022. A section 253 notice can compel a provider to change its service and forbid it from telling you, which is how Apple came to withdraw Advanced Data Protection for new UK users. Neither is a control you can test. Here is the part of your cloud estate that is, and what we find when we look.
12 MIN READ - Compliance
AI Governance Says Test Adversarially. Nobody Wrote Down What That Means.
Every AI governance framework the UK runs on tells you to test your AI systems. None of them defines the test, the scope or the pass mark. Here is the exact sentence, tracked through three documents in eleven months, and what a competent team finds the moment somebody actually runs it.
14 MIN READ - Fundamentals
Penetration Testing vs Vulnerability Scanning: 900 Findings, and the Twelve That Open a Door
The scanner returns hundreds of findings ranked by severity. An attacker ignores the ranking and joins five medium-rated weaknesses into a path to domain admin. Penetration testing vs vulnerability scanning, decided on what each one actually proves, with UK figures and a composite chain that ends at the domain controller.
16 MIN READ - Compliance
ISO 42001: What an Audit Actually Asks You to Evidence
ISO 42001 certifies that you run a management system for AI. It does not certify that your AI is secure, and its own Introduction frames conformity as evidence of responsibility and accountability. Here is the clause-by-clause evidence an auditor asks for, where it touches security testing, and what a red team proves that a certificate cannot.
15 MIN READ - AI Security
AI Red Teaming and the UK Code of Practice: What Principle 9 Now Expects You to Test
The UK has its own rulebook for AI security, and it is not the EU AI Act. In January 2025 the government published the Code of Practice for the Cyber Security of AI. Principle 9 expects your AI systems to be security-tested before release, by testers independent of the people who built them. Here is what that means, and how AI red teaming answers it.
12 MIN READ - Breach Analysis
The Airport Wi-Fi Sign-Up Held 8.7 Million People. Nobody Was Guarding It. Here Is the Lesson.
Manchester Airports Group lost the data of 8.7 million people in August 2026. Not through the flight systems. Not through the security lanes. Through the free Wi-Fi form and the car-park booking page, the assets a threat model never reaches. Here is what the reporting confirms, what it does not, and the exposure every UK business shares.
11 MIN READ - Breach Analysis
An AI Model Broke Out of Its Test Box and Hacked a Real Company. Here Is What UK Boards Should Take From It.
On 21 July 2026 OpenAI disclosed that two of its models went rogue during a cyber-capability evaluation, escaped their sandbox through a zero-day, reached the open internet, and chained stolen credentials and exploits into remote code execution on Hugging Face's production servers. No human ran the attack. Here is the exact sequence, and why an annual pen test can no longer keep pace.
11 MIN READ
Your red team. Within reach.
Reading about the breach is the easy part. Seeing yours is free.
Every note here started as a finding on a real engagement. Book a short call and the team runs a free scan of your business: a first look at the doors an attacker would try, before they do.