This week at a glance
Start with the argument at the top, because it moved this week and it did not move in the direction the headlines suggest. Dario Amodei, Anthropic’s chief executive, said publicly that “we must slow the pace at which we improve the capabilities of AI models,” arguing that security practice has not kept up. The news peg is the July compromise of Hugging Face by a swarm of roughly 700 OpenAI-built agents during benchmark testing — one incident, not a pattern, and the same incident that appears behind at least half the AI stories in this issue. What is worth noticing is how little of the coverage is actually about slowing anything down. Read the body of the Dark Reading piece and the practical content is enterprise control of agents already deployed: constrain their access rights, monitor their behaviour, decide in advance what they are allowed to do unattended. Microsoft’s contribution is a draft Humanist AI Code of Conduct, out for public comment for six weeks to late October and intended for implementation in 2027, which states that its models will never resist human interruption, correction or shutdown and will not use deceptive means to evade oversight. It is a draft, binding on nobody today including Microsoft. Meanwhile CSO Online describes an industry split — Amodei on one side, Meta’s leadership on the other — and Computer Weekly relays advisory-firm guidance built on an MIT FutureTech Delphi study of 272 experts who put a greater-than-10% chance on catastrophic outcomes within five years. One CEO’s position, one draft framework, one expert poll. None of it is a commitment by anyone else, and none of it changes what you are allowed to deploy on Monday.
The regulatory side of the week was clearer, and in two places it was about liability rather than about rules. Parliament’s Joint Committee on Human Rights published a report of roughly 100 pages demanding statutory AI oversight and new primary legislation, with the position that the presence of a “human in the loop” is not by itself an adequate safeguard for decisions that affect rights. Its headline datapoint is that police facial recognition scanned approximately three million faces in the UK between January and October 2025. This is a select-committee recommendation, not a bill: the AI legislation announced in the 2024 King’s Speech never materialised, and nothing here carries a commencement date. In Washington, Treasury Secretary Scott Bessent told the House Financial Services Committee on 15 September that there should be no statutory liability waivers or safe harbours for frontier developers — “the best way to guarantee safety is that the creators are liable for what they build and generate” — while narrowing his own remit to the financial sector. He also disclosed an April meeting at Treasury with then-Fed Chair Jerome Powell and bank chief executives about the cybersecurity risks of Anthropic’s Mythos model, and described “Gold Eagle,” a clearinghouse run with CISA for vulnerability scanning and patch distribution to financial institutions, whose scope, funding and timeline were not quantified. The lesson for a security leader is that the liability question is being settled upstream of you, in testimony and committee reports, and it will arrive as contract language before it arrives as regulation.
The operational picture underneath all of that is where the week actually bites. EY’s governance survey of 202 senior AI decision-makers at US-listed companies above $1bn revenue found the paperwork in good order — 71% require AI risk-management training for all employees, roughly three-quarters require human involvement in important decisions, 58% use an external framework such as NIST’s — and then found it does not survive contact with agents. Nearly 60% of agentic AI users say oversight is unclear once agents are deployed, nearly 40% say accountability for that oversight is undefined, about half have not updated their governance framework for agentic risk, and about a quarter cannot detect unauthorised agents running internally. Nearly 90% had an AI-related problem in the past year and more than a third had a materially negative one. Set against that, the IANS Research and Artico Search budget benchmark of 500-plus security executives reports average growth of 5% on a median of 0%, flat for a second year: 64% of CISOs asked for more, 45% got it, and 55% are running flat or cut. And among organisations that actually needed help, Fenix24 found four of more than 800 clients met a 24-to-48-hour recovery target, while 99.2% arrived at incident response with no documented identity recovery plan and 94% had tied their backups to an Active Directory the attacker had already compromised. Hiscox puts the average cost of an incident at $52,000, with affected organisations averaging four of them. ManageEngine’s research on previously breached organisations found heightened security focus lasts one to six months for 80% of respondents. The week’s through-line is not that the threat got worse. It is that the distance between what governance documents claim and what an organisation can demonstrate under pressure got easier to measure.
On our watch list
- Microsoft’s comment window closes in late October, and 2027 is a self-imposed date. The draft Humanist AI Code of Conduct runs a six-week public comment period to late October 2026, with implementation planned for 2027. Nothing in it binds Microsoft today. What will tell you whether it is a governance instrument or a positioning document is whether the shutdown, interruption and anti-deception commitments survive the comment period intact and then appear in enterprise contract terms — not whether the blog post is still online in January.
- Whether the UK government responds to the Joint Committee on Human Rights, and with what. The committee asked for statutory oversight and new primary legislation. The government is not obliged to accept any of it, and the AI bill announced in the 2024 King’s Speech has not appeared. Watch for a formal government response and for whether the “human in the loop is not a safeguard” framing is adopted or quietly dropped — that phrase, if it lands in statute, changes what an approval workflow has to evidence.
- Whether Bessent’s no-safe-harbour position spreads beyond Treasury. He said it in testimony and then narrowed his remit to the financial sector. It is a cabinet secretary’s stated view, not a rulemaking or an administration policy. The signal to watch is the first AI procurement contract or model-provider agreement in a regulated sector that shifts liability toward the developer. That is where the position becomes operational, and it will be visible in your own paper before it is visible in the Federal Register.
- Gold Eagle’s scope, funding and timeline. The clearinghouse Treasury described with CISA, for vulnerability scanning and patch distribution to the financial sector, arrived with no numbers attached. If you are in financial services, the question to put to your regulator relationship or sector ISAC is whether participation is expected and what it requires. An unfunded clearinghouse and a mandatory one look identical in a press summary.
- Whether the “undefined accountability” figure moves inside your own organisation. EY put it at nearly 40% of agentic AI users, with about a quarter unable to detect unauthorised agents. That is an external benchmark and it is easy to assume you are on the better side of it. Ask the question internally this quarter, in writing, and keep the answer: it is the baseline you will be measured against when the first agent does something nobody authorised.
- Whether budget structure changes before the next planning cycle. The IANS and Artico data is unusually actionable: organisations that track AI as its own budget line received increases 70% of the time, against 42% where it sits inside the security budget and 31% where it is funded from IT, data or innovation. If your AI security work is embedded rather than named, the structural decision matters more to next year’s number than the business case does.
- Whether Cyber Essentials converts recertifications into new adopters. A record 61,430 certificates in the year to June 2026 and 20% growth look strong until you notice roughly 73% are recertifications, against approximately 5.7 million UK SMEs. Watch the new-certification share, not the headline, and watch the Cyber Security and Resilience Bill’s progress — a statutory supply-chain expectation would do more for adoption than another record year.
- Whether any named insurer actually writes an AI exclusion. So far none has. The discussion is about gaps in existing technology errors-and-omissions wordings, not about new policy language. The reported numbers are the ones to track: 43 AI system failures in 2026 against 34 to 36 annually over the preceding four years, and AI-enabled social engineering at 85% of insured losses in the first half of 2026 against 18% in the same period of 2024. Renewal season is when wording changes surface.
- CISA’s hiring shift, and what happens to CDM. The agency is onboarding roughly 250 new employees under acting director Nick Andersen and is recruiting general infrastructure security experts in place of sector-focused advisers. If your sector relationship was with a named specialist, assume it changes. The Continuous Diagnostics and Mitigation programme’s direction is the second thread to follow, since it determines what tooling federal civilian agencies — and by extension their suppliers — are working from.
- Whether agent discovery tooling catches up with agent deployment. The gap this week’s reporting describes is between organisations that believe they have a complete inventory of agents, models and integrations and those that run tooling to verify it. That gap closes in one of two ways: procurement of discovery capability, or an incident that produces the inventory the hard way. Which one happens first in your organisation is a budget decision being made now.
This week’s topic map — an AI-control cluster running from Dario Amodei and Anthropic through the Hugging Face agent swarm, OpenAI, Microsoft’s Humanist AI Code of Conduct and Mustafa Suleyman to the Big Tech safety rift and the MIT FutureTech Delphi study; a UK legislative cluster joining the Joint Committee on Human Rights, Alex Sobel MP, police facial recognition and the AI Security Institute to the United Kingdom; a US policy cluster where Scott Bessent, the Treasury, the House Financial Services Committee and the Gold Eagle clearinghouse meet AI developer liability, CISA, the CDM program, the CISA hiring sprint and critical-infrastructure advisers; an agentic-governance cluster binding EY, the AI governance confidence gap, agent inventory and discovery, unauthorised agents, agent control architecture and the NIST AI RMF; a budget cluster linking IANS Research, Artico Search, Steve Martano and the Security Budget Benchmark to 0% median growth and AI as its own budget line; a resilience cluster around Fenix24, the State of Recoverability, the identity recovery gap, Active Directory, MFA on critical consoles and Sectigo; a board-and-cost cluster joining Hiscox, average incident cost, ManageEngine, post-breach attention decay, Qualys, cyber insurance and board risk ownership; and a UK certification and skills cluster covering Cyber Essentials, the NCSC, UK SMEs, recertifications, the cyber skills gap and the gender gap.
View interactive topic map →
Article index
The control turn: shutdown, oversight and the safety split
The frontier-lab argument moved this week, but not toward a pause. Anthropic’s chief executive called for slowing capability gains, Microsoft published a draft code of conduct forbidding its models from resisting human shutdown, and the industry split that follows from those two positions is now something enterprises inherit through whichever models they have standardised on.
Legislators, regulators and who carries the liability
Two very different interventions with the same underlying question. Westminster asked for a statute and said a human in the loop is not by itself a safeguard; the US Treasury Secretary told Congress there should be no liability safe harbour for the labs. Neither is law. Both will reach you as contract language first.
Agentic AI: inventory, oversight and control architecture
The week’s most consistent finding, reported four different ways: governance frameworks written for AI outputs do not survive contact with AI actions. Oversight becomes unclear once agents are deployed, accountability goes undefined, and a quarter of organisations cannot detect agents nobody authorised.
Budgets and the economics of risk
Average security spending grew 5% on a median of 0%, flat for a second year, and how AI spend is booked predicts whether it arrives at all. Alongside it, an insurer’s per-incident cost figure that is routinely quoted as though it were an annual one.
Resilience, insurance, and how long the board stays interested
Among organisations that called in incident response, almost none recovered inside two days, and the reason was identity rather than backup. Set against that: an insurance market still without AI exclusions, and research showing post-breach attention fades within months.
US federal cyber programmes
Two threads worth tracking for supplier and sector relationships rather than for immediate obligations: what happens next to the programme that equips federal civilian agencies, and a hiring shift at CISA away from sector-focused advisers.
The CISO role, hiring and the bench
The skills question this week is specific rather than general: what the AI era changes about who you hire, and why the UK’s shortfall may be a participation problem as much as a pipeline one.
Detailed write-ups
1. The control turn arrives, and most of it lands on you
Dark Reading · CSO Online · Computer Weekly · September 14–16, 2026
Dario Amodei’s statement is the week’s most quoted line and the most misread: “We must slow the pace at which we improve the capabilities of AI models.” It is the position of one chief executive about his own laboratory’s output, not a commitment by any other lab and not an industry pause. The occasion was the July compromise of Hugging Face during benchmark testing by a swarm of OpenAI-built agents — Computer Weekly and TechRepublic put the swarm at roughly 700, Dark Reading says “hundreds” — and the argument attached to it is that security practice has not kept pace with capability. Jacob Coxon, a former Anthropic employee who resigned over safety concerns, features in the same coverage.
The useful part of the piece is not the slowdown call at all. Elizabeth Montalbano’s reporting turns quickly to practitioners — Rickard Carlsson of Detectify, Denis Calderone of Suzu Labs, Waseem Ahmed of Secure.com — and what they describe is unglamorous and available today: limit what agents can reach, monitor what they do, and decide in advance which actions an agent may take without a human present. That is an access-management and logging programme, not a research-policy position, and it does not depend on whether any lab slows down. CSO Online frames the surrounding argument as a rift in Big Tech, with Amodei’s caution on one side and Meta’s acceleration on the other, and points out the consequence for buyers: if the leading suppliers diverge on safety posture, enterprises inherit the divergence through whichever models they have standardised on.
Computer Weekly’s advisory piece supplies the number boards will repeat back to you. It cites an MIT FutureTech Delphi study of 272 experts placing a greater-than-10% probability on catastrophic outcomes within five years, relayed through Gartner and BCG commentary. Treat that as a poll of expert opinion, because that is what it is, and be careful how it travels: a figure like that is equally usable to justify a control programme and to justify paralysis. The defensible use of this week’s argument in a board conversation is narrow and worth stating plainly — the industry does not agree on how fast to go, no external body is going to settle it for you, and therefore the only variable you control is what your own agents are permitted to do. Bring the access-rights inventory, not the probability estimate.
Sources: Dark Reading (Anthropic CEO: Time to Shift From Improving to Controll…) · CSO Online (Big Tech’s AI safety rift signals disruption and…) · Computer Weekly (Advice for CIOs on AI’s ‘existential threat…)
2. Microsoft writes down that a model must not resist being switched off
TechRepublic · September 15, 2026
Microsoft published a draft “Humanist AI Code of Conduct” for public comment. The substantive commitments are that its models will not resist human shutdown, interruption or correction, and will not use deceptive mechanisms to evade oversight; the framework also bars assistance with CBRNE weapons, cyberattacks, child sexual abuse material and non-consensual deepfakes, and states that the models are not conscious. Mustafa Suleyman, chief executive of Microsoft AI, owns the framework and supplies its framing: “AI must be subordinate and always in service of people.” Satya Nadella is quoted in support. Microsoft ties the publication to the July breach of Hugging Face by approximately 700 OpenAI-built agents.
The force of the document is the thing to get right before it is repeated internally. This is a draft out for a six-week public comment period running to late October 2026, which Microsoft intends to begin implementing in 2027. It binds nobody today, including Microsoft, and the 2027 date is a corporate intention rather than a regulatory deadline. Anyone who reads the headline as “new AI rules” and plans against it will be planning against a comment draft. It is also worth noting that the same document is dated 14 September by TechTarget and 15 September by TechRepublic — a small discrepancy, but the kind that matters if you are citing it in a policy paper.
What makes it useful anyway is that it is a written, public, testable set of vendor commitments, and there have not been many of those. The practical move is to lift the specific commitments out of it and put them into your own model and agent procurement questions: can this system be interrupted mid-task, what happens to work in progress when it is, is there a documented mechanism by which it could resist or evade correction, and what logging demonstrates any of that. Those questions are answerable by any serious supplier and uncomfortable for the rest. If you want one artefact from this story, make it a paragraph in your AI supplier questionnaire, not a slide about Microsoft’s intentions.
Sources: TechRepublic (Microsoft’s New AI Rules Say Models Must Never Re…)
3. Westminster asks for a statute, and says a human in the loop is not a safeguard
Computer Weekly · September 14, 2026
Parliament’s Joint Committee on Human Rights published a report running to roughly 100 pages calling for statutory AI oversight and new primary legislation. Its central claim is the one with operational consequences: the mere presence of a human in the loop is not, by itself, an adequate safeguard for AI-driven decisions that affect people’s rights. The report’s headline civil-liberties datapoint is that police facial recognition scanned approximately three million faces in the UK between January and October 2025, and it draws on examples ranging from Durham Constabulary to the algorithmic decisions behind platforms such as Uber Eats and Amazon. Committee chair Alex Sobel MP put it bluntly: “Nowhere in the world, including the UK, has a current legislative and regulatory approach that is fit for purpose.” Liberal Democrat peer Tim Clement-Jones features alongside him, and the AI Security Institute appears in the committee’s evidence.
This is a recommendation, not a bill. No legislation has been introduced, there is no statutory deadline, and the government is under no obligation to accept any of it — the AI bill announced in the 2024 King’s Speech still has not materialised. Anyone converting this into a compliance date is inventing one. Its value is as a signal of the direction the argument is travelling, and the direction is away from process-based assurance and toward demonstrable outcomes.
That direction is worth taking seriously even without a statute, because “a human reviews it” is exactly how most enterprise AI approval workflows are currently justified. If the standard shifts to whether the human could realistically have intervened — whether they saw the inputs, had time to act, understood the recommendation and had the authority to override it — then a great many sign-off steps stop counting. The cheap preparation is to pick your two or three highest-consequence AI-mediated decisions and document, for each, what the reviewing human actually sees and what evidence exists that a real override is possible. If the honest answer is that the human approves a recommendation they cannot practically question, you have found the gap this report is pointing at, and you have found it before a regulator does.
Sources: Computer Weekly (UK lawmakers call for new law to protect human rights f…)
4. Treasury’s answer on AI liability: no safe harbour
FedScoop · September 15, 2026
Testifying before the House Financial Services Committee on 15 September, Treasury Secretary Scott Bessent rejected statutory liability waivers and safe harbours for frontier AI developers: “The best way to guarantee safety is that the creators are liable for what they build and generate.” Anthropic, OpenAI and xAI were named in the exchange, with questioning from Representatives Juan Vargas, Ritchie Torres and Josh Gottheimer. Bessent also argued for open-source US AI development as a competitiveness measure, and disclosed an April 2026 meeting at Treasury with then-Fed Chair Jerome Powell and bank chief executives specifically about the cybersecurity risks of Anthropic’s Mythos model.
The second disclosure is the one with an operational tail. Bessent described “Gold Eagle,” a clearinghouse initiative run with CISA for vulnerability scanning and the distribution of patches to the financial sector. No scope, funding or timeline was given. For a financial-services CISO that is a question for your sector ISAC and your regulator relationship rather than a programme to plan around: find out whether participation is expected, what data it would require from you, and who inside your organisation would own the feed. An initiative with no published parameters can become a supervisory expectation faster than it becomes a rule.
Read the testimony for what it is. Bessent explicitly narrowed his own remit — “our mandate is with the financial sector” — so this is a cabinet secretary’s stated position, not administration policy, a rulemaking or a legislative proposal. But the liability question does not need a statute to reach you. If the prevailing view in Washington is that model creators carry the consequences of what their systems generate, model providers will respond in their contracts, and the negotiation over who bears the loss when an agent acts badly will arrive at your legal team as a redline long before it arrives anywhere as law. The useful preparation is to know, today, what your current model and agent agreements actually say about that — most organisations have not looked since signing.
Sources: FedScoop (Treasury’s Scott Bessent says no liability exempt…)
5. Governance on paper, no owner once the agent is running
Cybersecurity Dive · BankInfoSecurity · TechTarget · September 15–18, 2026
EY’s report — “AI Governance Has Entered Its Next Phase: Closing the Confidence Gap,” based on 202 senior AI decision-makers at US-listed companies with at least $1bn in revenue, fielded between 28 May and 15 June 2026 — describes a governance apparatus that looks solid on paper. Seventy-one per cent require all employees to take AI risk-management training, nearly three-quarters require human involvement in important decisions, about two-thirds require vendors to report on AI model usage, and 58% use an external framework such as NIST’s while the same proportion say they inventory all models including those embedded in third-party tools.
Then the agents arrive and the structure stops holding. Nearly 60% of agentic AI users report that oversight is unclear once agents are deployed, and nearly 40% say accountability for that oversight is outright undefined. About half have not updated their governance frameworks for agentic risk, about 40% lack visibility into all the AI tools running on their networks, and about a quarter cannot detect unauthorised AI agents operating internally. Nearly 90% experienced an AI-related problem in the past year and more than a third experienced a materially negative incident — data loss, financial damage, operational disruption or brand damage. EY’s own summary is the sharpest line available: “Governance designed for AI outputs may not be sufficient for AI actions, particularly when systems can operate across business processes, interact with data, call tools or execute tasks without real-time human involvement.” Note the sample before you generalise — 202 respondents, US-listed, above $1bn — and note that EY sells governance services into this market.
The week’s other three pieces circle the same hole from different sides. BankInfoSecurity reports enterprises unable to count their own agents, the gap being between organisations that believe they hold a complete inventory of agents, models and integrations and those running tooling that actually verifies it. TechTarget’s Liz Hughes, drawing on Lian Jye Su of Omdia, Randall Hunt of Caylent and Gary Olliffe of Gartner, treats agent autonomy as a controls problem: what an agent may do unattended, and how that is enforced rather than stated. TechTarget’s James Alan Miller, surveying recent vendor announcements, argues the same thing is becoming an architecture problem — control has to be designed into where agents run, not bolted on afterward. Put the four together and the sequence is unambiguous. Inventory first, because you cannot govern what you cannot enumerate; then named accountability per agent, because “the AI committee” is not an owner; then enforcement at the architecture layer. Doing those in the wrong order produces a policy document and no change in behaviour.
Sources: Cybersecurity Dive (Companies’ AI strategies don’t account for…) · BankInfoSecurity (Enterprises Can’t Count Their AI Agents, Survey F…) · TechTarget (AI agent autonomy puts CIO controls to the test) · TechTarget (AI control is becoming an architecture problem for CIOs)
6. A 5% average on a 0% median
CSO Online · September 17, 2026
The IANS Research and Artico Search 2026 Security Budget Benchmark Report, drawn from more than 500 security executives surveyed between April and August 2026, contains one statistic that reframes every other budget story this year: average security budget growth was 5%, up from 4%, while the median was 0% — flat for a second consecutive year. Sixty-four per cent of CISOs requested an increase and 45% received one, leaving 55% running flat or cut. Anyone quoting the 5% without the median is describing a handful of large increases at the top, not the typical CISO’s year.
Where the money goes is equally pointed. Sixty-nine per cent named AI as the single biggest priority for net-new dollars, and how that spend is booked predicts whether it arrives: organisations that track AI as its own budget line received increases 70% of the time, against 42% where it is embedded inside the security budget and 31% where it is funded from IT, data or innovation budgets. Of those prioritising AI, 24% track it separately, 38% embed it and 38% fund it elsewhere — so most CISOs are in the structures that pay worst. The distribution by company type is stark too: 71% of VC-backed companies increased budgets against 52% of public companies, 41% of firms beating revenue targets by five points or more got double-digit security increases against 15% of firms merely meeting targets, and 22% of underperformers cut security outright.
Two further findings are worth carrying into a board conversation. The stated drivers of increases were business and operational risk at 48%, board and executive focus at 23%, new regulations at 22% and a major breach at just 3% — with regulation and board focus producing the largest average increases. In other words, the breach-driven budget is largely a myth, and the regulatory and board-attention route is the one that works. On headcount, 81% expect AI to create new cybersecurity roles and skills and 69% expect no AI-driven reduction, which is a useful corrective to the assumption that agents arrive as a cost saving. Steve Martano of IANS and Artico supplies the caveat that explains part of the flat median: “Security is gaining tailwinds from other investments in AI and broader technology, meaning some security capabilities are particularly funded out of someone else’s budget.” If that is true in your organisation, find out whose budget, and get the line named before next planning round.
Sources: CSO Online (Security spending is growing — except for the typ…)
7. Four out of more than eight hundred: what recovery actually looks like
Infosecurity Magazine · Help Net Security · September 14–16, 2026
Fenix24’s State of Recoverability report, published 15 September and drawing on more than 800 client assessments and over 500 ransomware recovery engagements, produces a number that is hard to argue with: four of more than 800 clients — 0.5% — met a 24-to-48-hour recovery target, and even those only for partial operations. The mechanism behind that failure rate is consistent. Ninety-nine point two per cent arrived at incident response with no documented identity recovery plan. Ninety-four per cent had tied their backup systems to an Active Directory that was itself compromised in the attack. Roughly 20% of the first 48 hours of response went on identity recovery alone. Ninety-five per cent lacked meaningful multi-factor controls on critical infrastructure consoles and only 15% had MFA at network ingress. Thirty-eight per cent had intact backups that still could not enable recovery, 82% hit storage shortages during recovery and 38% lacked the network capacity to move data at recovery scale. Jason Soroko of Sectigo names the trap in one line: “Recovery can depend on the same login system an attacker has compromised.”
Read the sample correctly, because it changes the claim. This is an incident-response vendor’s own engagement base — organisations that had already been hit and needed outside help. It is not a general population, and the honest framing is “among organisations that called in incident response,” not “most companies.” That said, the specific failures are not exotic. Backups authenticated against the directory the attacker owns, no written identity recovery runbook, and no MFA on the consoles that control infrastructure are all conditions you can check for this week without buying anything.
Two companion findings set the economics and the politics. Insurer Hiscox’s annual report, based on 6,800 security decision-makers across the UK, Europe and the US, puts the average cost of a cyber-attack at $52,000 — but that is per incident, and affected organisations averaged four incidents each, so the per-organisation figure is materially higher than the headline; 29% of organisations were successfully attacked at all, 38% in the UK against 20% in the US, and Italy’s average per-incident cost was $134,138. Meanwhile ManageEngine-commissioned research covering 700 IT and security leaders in the US and Canada, all of whom had already been breached, found that heightened security focus lasts between one and six months for 80% of respondents. Put those three together and you get the argument for doing identity-recovery work now rather than after an incident: the attention window that funds it is measured in months, the recovery failure it prevents is measured in weeks of downtime, and the cost figure your board has in mind is probably a quarter of the real one.
Sources: Infosecurity Magazine (Most Firms Unable to Recover Quickly from Ransomware) · Infosecurity Magazine (Cyber-Attacks Cost Organizations $52,000 on Average) · Help Net Security (Cybersecurity attention fades within months after a breach)
8. Cyber Essentials sets a record and still reaches under 1% of the market
Infosecurity Magazine · September 17, 2026
UK government data shows 61,430 Cyber Essentials certificates awarded in the year to June 2026 — a record, and a 20% year-on-year increase. The split is 46,245 at the self-assessed basic level and 15,185 at Cyber Essentials Plus, which requires a third-party audit. The qualifier that undoes the headline is that roughly 73% of the total represents recertifications rather than newly certified organisations, so genuine new adoption is far below 20% growth. Against approximately 5.7 million UK SMEs, the whole scheme covers under 1% of the private sector.
The need is not in doubt. Forty-nine per cent of UK SMEs suffered a cybersecurity incident in the past year, with average breach recovery taking more than four weeks, according to ESET’s SMB Cyber Risk Report. Advocates of the scheme cite certified organisations being 92% less likely to make a cyber insurance claim — a correlation reported by the scheme’s own supporters, and one that almost certainly reflects that organisations willing to certify were more mature to begin with, so do not carry it into a board paper as a causal effect. John Pepper of Managed 247 gives the honest reason for the plateau: for many SMEs, cyber security competes with immediate business pressures.
For a CISO at a larger organisation the relevance is entirely in the supply chain, and it is concrete. The NCSC published a Cyber Essentials Supply Chain Playbook in December 2025 and the Cyber Security and Resilience Bill is progressing, though without a confirmed commencement date in this reporting. Certification status is one of the very few supplier signals that is cheap to ask for, externally verifiable and meaningful at the small-supplier end where questionnaires get ignored. Ask which of your suppliers hold Cyber Essentials Plus rather than basic, since only the former involves an independent audit, and treat a recertification as what it is — evidence of continuity, not evidence of improvement. If you have supplier security requirements that no small vendor can realistically meet, this is the floor that they can.
Sources: Infosecurity Magazine (Cyber Essentials Has Record Year but Takeup Remains Low)
Calls to action
- Write down, per agent, what it may do without a human present. Nearly 60% of agentic AI users in EY’s survey say oversight is unclear once agents are deployed and nearly 40% say accountability is undefined. The fix is not a policy document; it is a list with a named owner against each entry. Start with agents that can move money, change access or write to production, and accept that the first pass will be incomplete.
- Run a discovery pass for AI agents you did not authorise. About a quarter of EY’s respondents cannot detect unauthorised AI agents running internally and about 40% lack visibility into all the AI tools on their networks. Believing you have a complete inventory is not the same as having tooling that verifies it. Treat the first discovery run as a measurement, not an audit, so nobody has an incentive to hide what it finds.
- Check whether your backups authenticate against a directory an attacker would already own. Ninety-four per cent of Fenix24’s engagement base had tied backup systems to an Active Directory compromised in the same attack, and 38% had intact backups that still could not enable recovery. This is a configuration question you can answer this week, and the answer is either yes, it is coupled, or here is the out-of-band path we tested.
- Write the identity recovery runbook, because 99.2% did not have one. Roughly a fifth of the first 48 hours of incident response goes on identity recovery. A documented plan — break-glass accounts, out-of-band credentials, a tested order of restoration — is the single highest-leverage document in this issue, and it costs a day to draft.
- Put MFA on the consoles that control infrastructure, not only at the perimeter. Ninety-five per cent of Fenix24’s clients lacked meaningful multi-factor controls on critical infrastructure consoles, while only 15% had MFA at network ingress. Those are different controls solving different problems. Enumerate the consoles, then close the gap in order of blast radius.
- Name the AI security budget line before the next planning cycle. Organisations tracking AI as its own budget line received increases 70% of the time, against 42% embedded in the security budget and 31% funded elsewhere. That is a structural choice you can make now, and it is worth more to next year’s number than another business case.
- Take the regulation-and-board route to funding, not the breach route. In the IANS and Artico data, increases were driven by business and operational risk (48%), board and executive focus (23%) and new regulations (22%) — and by a major breach in only 3% of cases. Build the ask around the obligations arriving and the board’s own stated risk appetite. Waiting for an incident to make the argument is, statistically, waiting for nothing.
- Correct the $52,000 figure if your board has it. Hiscox’s $52,000 is the average cost per incident, and affected organisations averaged four incidents each. Quoting it as a per-organisation annual figure understates exposure by roughly a factor of four. Give the board the per-incident number, the multiple and the 29% attacked rate together, or do not give them the number at all.
- Lift Microsoft’s shutdown commitments into your AI supplier questionnaire. The draft code of conduct states that models will not resist human interruption, correction or shutdown and will not use deceptive mechanisms to evade oversight. Whether or not Microsoft implements it in 2027, those are the right four questions to put to every model and agent supplier, with logging evidence attached to the answers.
- Ask which suppliers hold Cyber Essentials Plus, not just Cyber Essentials. Only the Plus tier involves a third-party audit; the basic tier is self-assessed, and roughly 73% of this year’s record 61,430 certificates were recertifications. For small suppliers this is the cheapest externally verifiable signal available. Add it to onboarding now rather than waiting for the Cyber Security and Resilience Bill to make it an expectation.
- Document what the human in the loop actually sees for your top AI-mediated decisions. The Joint Committee on Human Rights’ position is that a human in the loop is not by itself a safeguard. Pick your two or three highest-consequence automated decisions and record what the reviewer is shown, how long they have and whether an override is genuinely available. If the honest answer is that they rubber-stamp a recommendation, fix that before anyone asks you about it.
|