Back to News

Ransomware Attacks Hit a 2026 High in July — and AI Agents Are Already in the Mix

Ransomware Attacks Hit a 2026 High in July — and AI Agents Are Already in the Mix

Ransomware volumes in July 2026 reached their highest point of the year so far. Cyber security firm NCC Group, which tracks publicly claimed ransomware incidents month by month, recorded almost 900 attacks over the course of July — more than any other month in 2026, and enough to put the year back on the trajectory that the industry had cautiously hoped was flattening out. The figure still sits below the all-time monthly record of 1,099 attacks set in February 2025, but the direction of travel matters more than the gap. Twenty-nine per cent of those July victims were organisations in Europe.

The number that should hold a British business owner’s attention, though, is not 900. It is one. In the same month, NCC recorded the emergence of a threat actor it calls Jadepuffer, which it describes as an agentic actor capable of executing a successful, end-to-end ransomware intrusion entirely autonomously — reconnaissance through to encryption, without a human operator steering it. To date it appears to have been used as a proof of concept rather than for financial gain. That distinction is real, and it is also temporary. Today, 27 August 2026, the practical question for a UK small or medium-sized business is no longer whether attackers have access to automation that compresses an intrusion from weeks into hours. It is whether the controls in your own environment were designed for an attacker moving at human speed, and what happens to them when that assumption stops holding.

~900
ransomware attacks recorded by NCC Group in July 2026 — the highest monthly total of the year so far
29%
of July’s victims were organisations based in Europe; 41% were in North America
15%
of all July attacks were claimed by The Gentlemen, a Qilin splinter group barely a year old
1,099
the standing monthly record, set in February 2025 — July 2026 came close but did not beat it

What NCC Group actually reported

NCC Group’s monthly threat intelligence reporting counts ransomware attacks that have been publicly claimed — typically posted to a leak site by the group responsible, or otherwise disclosed. July 2026’s tally of almost 900 makes it the busiest month of the year to date. That is a meaningful high-water mark for 2026, and it arrives after a period in which several months had suggested the ecosystem might be consolidating rather than expanding. It has not consolidated. It has redistributed.

The regional split is the first thing worth reading properly. Forty-one per cent of July’s victims were in North America and 29% were in Europe. For a UK business, the European figure is the one that lands closest to home: close to three in ten publicly claimed ransomware victims last month were operating under broadly similar regulatory obligations, insurance markets and supply-chain structures to your own. This is not a distant American phenomenon reported at one remove. The gap between the North American and European shares has narrowed considerably from where it sat a few years ago, and the practical reading is that European organisations — including mid-market and smaller UK firms that would not describe themselves as obvious targets — are now a routine part of the target set rather than an occasional one.

The second finding concerns who is doing the attacking. The single largest contributor to July’s volume was a group calling itself The Gentlemen, which accounted for 15% of all attacks recorded in the month. The Gentlemen is a splinter from Qilin, one of the more established ransomware-as-a-service operations, and it reportedly formed after a dispute over a ransom payment. Since then it has scaled faster than any other group NCC tracks, claiming more than 300 victims in a year. That growth curve is the story in miniature: a group that did not meaningfully exist eighteen months ago is now responsible for roughly one in seven publicly claimed ransomware incidents worldwide. The barrier to standing up a competent, high-volume ransomware operation is not a technical one. It is organisational, and the ecosystem has become very good at solving organisational problems quickly.

The third finding is a caution against reading claim counts too literally. A newer group, CRPxO, claimed 36 attacks in July, but NCC assessed the group as only “partially verified” — meaning some of those victim claims could not be substantiated. NCC’s reading is that a proportion may have been exaggerated to make the group appear more threatening than its actual capability warrants. This is a familiar pattern. Leak-site posts are marketing as much as they are disclosure, and a new entrant with an inflated victim list is trying to recruit affiliates, not just extort victims. For defenders, the lesson is that headline group rankings should be treated as a directional signal about where the ecosystem’s energy is going, not as an audited ledger.

And then there is Jadepuffer. NCC describes it as an agentic threat actor: not a tool that assists a human operator, but a system capable of executing a successful ransomware intrusion end to end, autonomously, without human oversight at each step. NCC’s assessment is that it has so far been used as a proof of concept rather than for financial gain — a demonstration, in other words, that the thing works. Matt Hull, NCC Group’s vice president of cyber intelligence and response, framed the broader trend plainly: AI is “changing the speed and scale of cyber attacks”, letting attackers automate more of their operations and generate far more convincing phishing and social engineering content than they could before.

Why an autonomous intrusion changes your arithmetic

Most SME security postures rely, whether or not anyone has said so out loud, on the attacker being slow. Someone reviews alerts in the morning. Patches get applied at the next maintenance window. The backup is checked when there is time. Those cadences work because a human-operated intrusion typically takes days or weeks between initial access and encryption, which leaves a window in which a slow defender can still win. An agentic actor collapses that window. Reconnaissance, credential harvesting, lateral movement and deployment can run continuously, without fatigue, at machine pace, across every exposed asset simultaneously. Jadepuffer is currently a proof of concept. The controls that would have stopped it — enforced multi-factor authentication, least-privilege access, prompt patching of internet-facing systems, and immutable offline backups — take months to put in place properly. Those months need to start before the proof of concept becomes a product.

How July 2026 got here: a timeline

Ransomware volume does not spike randomly. July’s figure is the output of a set of structural shifts that have been accumulating for roughly eighteen months — the fragmentation of established ransomware brands into faster-moving splinters, the arrival of generative AI in the attacker’s toolkit, and a UK policy environment that has been in flux. The chronology below sets out the reference points that matter for reading the July number in context.

February 2025 — The record month
NCC Group records 1,099 publicly claimed ransomware attacks in a single month, still the highest monthly total the firm has logged. It becomes the benchmark against which every subsequent month is measured, including July 2026’s near-900.
Mid-2025 — Qilin fractures
A dispute over a ransom payment inside the Qilin ransomware-as-a-service operation leads to a breakaway. The splinter takes the name The Gentlemen and begins recruiting affiliates independently. Splits of this kind used to slow the ecosystem down; increasingly they accelerate it, because both halves keep operating.
Late 2025 to early 2026 — The Gentlemen scale
The new group scales faster than any other operation NCC tracks, moving from nothing to a sustained, high-volume claim rate. Over the course of roughly a year it claims more than 300 victims — an average approaching six a week, sustained.
Through 2026 — AI enters the intrusion chain
Generative tooling moves from writing phishing copy to supporting reconnaissance, target triage and payload preparation. Hull’s assessment is that AI is changing the speed and scale of attacks and producing markedly more convincing social engineering — removing the spelling and register errors that used to give a fraudulent email away.
Mid-2026 — A UK change of prime minister
NCC’s report flags the UK’s recent change of prime minister as a period of policy transition that can extend opportunities for threat actors. Personnel and process changes create fresh targets for reconnaissance and social engineering: new names, new reporting lines, new approval routes that nobody in the organisation has yet learned to recognise as normal or abnormal.
July 2026 — The 2026 high-water mark
Almost 900 publicly claimed attacks, the highest monthly total of the year. Forty-one per cent of victims in North America, 29% in Europe. The volume is broad-based rather than driven by a single mass-exploitation event.
July 2026 — The Gentlemen take 15%
The Qilin splinter accounts for 15% of all attacks recorded in the month, making it the single largest identified contributor to the total and confirming that its growth curve has not levelled off.
July 2026 — CRPxO claims 36, partially verified
A newer group posts 36 victim claims. NCC assesses it as only partially verified, noting that some claims may be exaggerated to make the group look more capable than it is — a reminder that leak-site output is a recruitment channel as well as an extortion one.
July 2026 — Jadepuffer emerges
NCC records an agentic threat actor capable of running a successful ransomware intrusion end to end without human oversight. Apparently deployed as a proof of concept rather than for financial gain — the capability demonstrated before it is monetised.
27 August 2026 — Where that leaves UK businesses
The report lands into a UK market where Cyber Essentials remains the baseline control set for most SMEs, and where a significant proportion of firms still treat backup verification, MFA enforcement and privileged-access review as annual rather than continuous activities.

Reading the 900: region, group and the limits of the data

A single monthly total is a blunt instrument. What makes July’s figure useful is that it can be cut two ways from the same reporting: by where the victims were, and by who claimed them. The chart below does both against the same base of roughly 900 attacks. The first three bars split the month by victim region. The remaining four split the same month by the group doing the claiming. They are two views of one dataset, not a single ranking, and they are read separately.

North America (victim region)
41%
Rest of world (victim region, residual)
30%
Europe (victim region)
29%
All other tracked groups (claiming group, residual)
81%
The Gentlemen (claiming group)
15%
CRPxO (claiming group, partially verified)
4%
Jadepuffer (agentic, proof of concept)
<1%

The two residual bars — “rest of world” at 30% and “all other tracked groups” at 81% — are arithmetic rather than reported figures, derived from the published shares. They are included because they carry the more important message in each view. In the regional cut, the residual tells you that ransomware is not concentrated in two continents; roughly three in ten victims sat outside both North America and Europe. In the group cut, the residual tells you that even the fastest-growing operation in the ecosystem accounts for only about one in seven incidents. There is no single group to defend against. Removing The Gentlemen from the picture entirely would still leave more than 750 attacks in July.

That is the strategic point that gets lost when reporting focuses on named groups. Law-enforcement takedowns and brand disruptions are worth doing, and they have had real effect, but the ecosystem’s response has consistently been redistribution rather than reduction. Qilin fractured and produced The Gentlemen, which now claims a larger share of monthly volume than most of the brands that preceded it. The defensive implication is that your control set should be indifferent to attribution. Enforced multi-factor authentication does not care which group is trying the credential. An immutable backup does not care whose encryptor ran. Attribution matters for insurers, regulators and law enforcement; it should not shape an SME’s roadmap.

Twenty-nine per cent: the number that makes this a UK story

Of every hundred publicly claimed ransomware victims in July 2026, twenty-nine were European. That is the figure a UK business should be planning against, because it is the one that reflects a target population operating under conditions much like your own: UK GDPR and the ICO’s 72-hour breach notification expectations, a hardening cyber insurance market that increasingly asks for evidence of controls rather than assertions, and supply chains dense with small suppliers who hold client data and system access disproportionate to their headcount.

29%
Share of July 2026’s ransomware victims based in Europe (NCC Group)

There is a second reason the UK reading is sharper than the raw European share suggests, and NCC flags it directly in the report: the country’s recent change of prime minister creates a period of policy transition, and policy transitions extend opportunities for threat actors. That is not a comment about any government’s security competence. It is a structural observation about what happens when personnel and processes change. New ministers bring new special advisers and new private offices. Departments reorganise. Suppliers get new points of contact. Approval chains are rewritten, and for a period nobody in the organisation has a reliable instinct for what a normal instruction from a new name looks like.

For attackers, that period is reconnaissance gold. Social engineering works by exploiting the gap between what an organisation formally requires and what its people actually recognise as routine. When the roster changes, that gap widens for everyone in the chain — not just central government, but every supplier, contractor and professional-services firm that touches it. A UK accountancy practice, IT reseller or facilities contractor sitting three tiers down a public-sector supply chain will see the same effect: emails from unfamiliar names, referencing genuine reorganisations, arriving at plausible moments. Combine that with Hull’s point about AI producing more convincing phishing content and the traditional detection heuristics — odd phrasing, poor grammar, wrong register — stop earning their keep.

Where UK SMEs are actually exposed

Volume figures describe the weather. The table below describes the building. These are the control gaps we see most often when assessing UK small and medium-sized businesses, rated by how frequently they turn out to be the weak point that matters in a ransomware scenario. The ratings are Cloudswitched’s assessment based on assessment and remediation work with UK SMEs, not NCC Group data — but each maps directly to one of the fundamentals Hull identified as still mattering most.

Common UK SME ransomware exposure, by how often it is the decisive gap
Multi-factor authentication enabled but not enforced for every account High
Backups exist but restoration has never been tested end to end High
Internet-facing appliances (VPN, firewall, RMM) patched on an ad-hoc cycle High
Former staff and dormant service accounts still active in the directory High
Local administrator rights granted broadly to make support easier Medium
No central logging, so an intrusion leaves no reconstructable trail Medium
Phishing training delivered annually and never updated for AI-generated lures Medium
Incident response plan exists as a document nobody has rehearsed Lower

The pattern in that list is worth naming. Almost none of these are exotic. There is no zero-day on it, no nation-state capability, nothing that requires a large budget to address. They are the fundamentals, and they are exactly the fundamentals Hull pointed to: strong identity and access controls, good vulnerability management, visibility across the IT environment, and the ability to detect and respond quickly when something goes wrong — alongside staff training that has actually been updated for the era of AI-generated social engineering.

The reason they persist is not ignorance. It is that each one is individually easy to defer. Enforcing MFA on the last eleven accounts means dealing with the four people who will complain. Testing the restore means booking a day nobody has. Decommissioning the dormant service account means finding out what it does first, and the person who set it up left in 2023. Every one of these is a small piece of organisational friction, and ransomware readiness is mostly the discipline of clearing small friction before it compounds. An agentic attacker does not need a sophisticated exploit if a valid credential without MFA is available.

What ransomware readiness costs a UK business

The most common objection to any of this is budget, so it is worth being concrete about the order of magnitude. The bands below are indicative annual figures for UK SMEs, covering managed security fundamentals rather than a full enterprise programme — identity hardening and MFA enforcement, patch and vulnerability management for endpoints and internet-facing systems, immutable backup with tested restores, centralised logging with monitoring, and Cyber Essentials certification. They are planning ranges, not quotations; the actual figure depends on estate complexity, compliance obligations and how much remediation is needed before a steady state is reached.

Business size Typical estate Indicative annual spend Realistic first-year focus
Micro (1–9 staff) Microsoft 365, a handful of laptops, one cloud line-of-business app £1,200 – £3,500 MFA enforced on every account, managed endpoint protection, backup with a verified restore, Cyber Essentials self-assessment
Small (10–49 staff) Mixed cloud and on-premises, a file server, VPN or remote access, one or two SaaS platforms £4,000 – £12,000 The above plus patch management for internet-facing systems, privileged access review, centralised logging, quarterly restore tests
Medium (50–149 staff) Multiple sites or hybrid working, line-of-business servers, supplier integrations, some regulated data £14,000 – £40,000 The above plus monitored detection and response, immutable and offsite backup tiers, supplier access review, rehearsed incident response
Upper mid-market (150–250 staff) Complex estate, compliance obligations, meaningful downstream supply chain £45,000 – £110,000 The above plus continuous vulnerability management, segmentation, Cyber Essentials Plus, tabletop exercises with named decision-makers

Set those figures against the alternative. A ransomware incident at a small UK business rarely costs only the ransom, and in many cases the ransom is never paid. The cost is the downtime — days or weeks of no order processing, no invoicing, no client access — plus incident response fees, legal advice, ICO engagement if personal data was involved, notification, credit monitoring, insurance excess, premium increases at renewal, and the contract losses that follow when a client asks how it happened and does not like the answer. For most SMEs, a fortnight of operational paralysis costs multiples of a year’s security budget before a single specialist invoice arrives.

Reactive versus proactive: the same budget, spent at different times

The difference between businesses that survive a ransomware incident well and those that do not is rarely the size of the security budget. It is when the money was spent. The comparison below sets out the two postures as we encounter them.

Reactive posture

What a great many UK SMEs run today

  • MFA is switched on in the tenant but exceptions were granted for convenience and never revisited
  • Backups run nightly; nobody has attempted a full restore since the system was installed
  • Firewall and VPN firmware is updated when something breaks or a vendor advisory makes the news
  • Leavers are removed from payroll promptly and from the directory eventually
  • Logs sit on individual devices and are overwritten within days, so an incident cannot be reconstructed
  • Security awareness training is an annual video, unchanged since before AI-generated phishing was convincing
  • The incident response plan is a document; nobody has read it aloud in a room with the people named in it
  • Cyber insurance is held, and its control warranties have never been checked against reality

Proactive posture

Where Cloudswitched takes you

  • MFA enforced by conditional access on every account with no standing exceptions, reviewed monthly
  • Immutable backups with scheduled restore tests and a documented, timed recovery objective
  • Internet-facing systems on a managed patch cycle with an emergency route for critical advisories
  • Joiner, mover and leaver process tied to the directory, with dormant and service accounts reviewed quarterly
  • Centralised log retention across identity, endpoint and network, so an intrusion leaves a readable trail
  • Training refreshed against current lures, including AI-generated business email compromise and voice pretexting
  • Incident response rehearsed with named decision-makers, out-of-band contacts and pre-agreed authority to act
  • Cyber Essentials certification maintained, with evidence that satisfies insurers and procurement questionnaires

Neither column is a maturity fantasy. The right-hand column is achievable inside a year for most UK SMEs at the budgets in the table above. What separates the two is not spend but sequence: the proactive posture pays for controls before an incident, when the work can be scheduled, scoped and negotiated. The reactive posture pays for the same controls afterwards, at emergency rates, while the business is not trading, and with an insurer and possibly a regulator watching. The controls end up in place either way.

34
Cloudswitched readiness estimate: typical UK SME score against the fundamentals Hull identified, out of 100

That score is our own editorial assessment rather than a figure from NCC’s report, and it is deliberately assembled from the four fundamentals Hull named — identity and access control, vulnerability management, environment visibility, and detection and response — plus the fifth he added, staff training refreshed for AI-generated social engineering. A typical UK SME scores reasonably on the first (MFA is usually deployed, if imperfectly enforced) and poorly on the third and fourth, because visibility and response capability are the two that cost real money and produce nothing visible until the day they are needed. Thirty-four out of a hundred is not a crisis. It is a normal starting position, and it is fixable in a planned sequence.

The single most useful thing to do this week

Test a restore. Not a file-level restore — a full recovery of one business-critical system to a point in time, performed by the person who would actually have to do it under pressure, timed from start to finish. It is the one exercise that validates several controls at once: that the backups are complete, that they are not reachable from a compromised domain account, that the restore media and credentials exist somewhere the ransomware cannot reach, and that the recovery time objective written in your continuity plan bears some relationship to reality. Businesses are routinely surprised by the result, and it is far better to be surprised on a Tuesday afternoon than at 3am with an encrypted estate and a countdown on a leak site.

At a glance: the July 2026 ransomware picture

Item Detail
Attacks recorded, July 2026 Almost 900 publicly claimed ransomware attacks — the highest monthly total of 2026 so far
Standing monthly record 1,099 attacks, set in February 2025; July 2026 approached but did not exceed it
Source of the data NCC Group monthly threat intelligence reporting
Victims in North America 41% of July’s total
Victims in Europe 29% of July’s total — the figure most relevant to UK businesses
Largest single group The Gentlemen, at 15% of all July attacks
The Gentlemen’s origin A splinter from the Qilin operation, reportedly formed after a dispute over a ransom payment
The Gentlemen’s growth More than 300 victims claimed in a year; scaled faster than any other group NCC tracks
CRPxO 36 attacks claimed in July; assessed by NCC as only “partially verified”, with some claims possibly exaggerated
Jadepuffer Agentic threat actor able to execute an end-to-end ransomware intrusion autonomously; apparently a proof of concept rather than financially motivated
NCC on AI Matt Hull: AI is “changing the speed and scale of cyber attacks”, enabling automation and more convincing phishing and social engineering
NCC on defence The fundamentals still matter most: identity and access controls, vulnerability management, environment visibility, fast detection and response, plus training for AI-generated social engineering
UK policy factor The recent change of prime minister creates a transition period; personnel and process change generates new reconnaissance and social engineering targets
UK SME baseline control set Cyber Essentials, covering firewalls, secure configuration, user access control, malware protection and patch management
Indicative annual security spend From roughly £1,200 for a micro business to £110,000 at the top of the SME range

Related coverage

This report sits alongside several threads we have followed over recent weeks. The autonomous-intrusion angle connects directly to our coverage of the Sleepwalker Windows backdoor, where persistence rather than encryption was the objective, and to the Microsoft Entra ID maximum-severity flaw, which showed how quickly an identity-layer weakness becomes an estate-wide one — precisely the failure mode an agentic attacker is built to exploit. On the infrastructure side, the PSTN switch-off deadline is forcing migrations that put alarms, payment terminals and emergency lines onto IP networks, expanding the attack surface many SMEs are now defending, while the Gamma Communications takeover reshapes the UK supplier landscape those migrations depend on. And for a view of how enforcement is changing the compliance calculus more broadly, our report on the HMRC crypto tax crackdown covers the same underlying shift: data-driven authorities, shorter grace periods, and less tolerance for organisations that cannot evidence what they did and when.

Get the fundamentals certified, not just intended

Cyber Essentials covers the five control areas that stop the overwhelming majority of ransomware intrusions before they start — and certification forces you to evidence them rather than assume them. Cloudswitched takes UK businesses through assessment, remediation and certification, then keeps the controls in place year-round.

Talk to us about Cyber Essentials Certification

Frequently asked questions

Almost 900 attacks in a month sounds enormous. Does that number represent every ransomware incident?
No, and the gap matters. NCC Group’s monthly figures count attacks that have been publicly claimed — usually posted to a group’s leak site, or otherwise disclosed. Incidents where the victim paid quietly, where the group chose not to publish, or where the attack was contained before extortion began do not appear. The real total is higher than 900, by an amount nobody can measure precisely. The published figure is best read as a consistent index of ecosystem activity over time rather than a census. Its value is comparative: July 2026 is the busiest month of the year to date, measured the same way as every month before it.
Why does 29% in Europe matter more to a UK business than 41% in North America?
Because it describes a population you resemble. European victims operate under regulatory regimes broadly comparable to UK GDPR, with similar breach-notification expectations, similar cyber insurance market conditions and similar supply-chain structures — large numbers of small suppliers holding disproportionate access to client systems and data. North American volume tells you the ecosystem is busy; European volume tells you the ecosystem is busy with organisations shaped like yours. Close to three in ten publicly claimed victims last month fell into that category, which makes the risk a planning assumption rather than a distant statistic.
What is an “agentic threat actor”, and how is Jadepuffer different from attackers using AI tools?
Most AI-assisted attacks still have a human in the loop: an operator uses a model to draft a phishing email, summarise reconnaissance or generate a script, then decides what happens next. NCC describes Jadepuffer differently — as capable of executing a successful, end-to-end ransomware intrusion entirely autonomously, without human oversight at each step. That means initial access, discovery, lateral movement and deployment run as a continuous automated process rather than a sequence of human decisions. NCC assesses it as a proof of concept so far, used to demonstrate the capability rather than to make money. The significance is not the damage it has done. It is the demonstration that the approach works.
Does an autonomous attacker mean our existing defences are obsolete?
No — and this is the most important point in the whole report. Hull’s assessment is that the fundamentals still matter most: strong identity and access controls, good vulnerability management, visibility across the IT environment, and the ability to detect and respond quickly. An automated intrusion still needs a way in, and the ways in have not changed: an unpatched internet-facing appliance, a valid credential without multi-factor authentication, or a user persuaded to authorise something. What changes is the time budget. Automation shortens the interval between initial access and encryption, which means controls that depend on someone noticing during office hours are the ones that degrade first. Fix the fundamentals; then shorten your detection and response times.
Who are The Gentlemen, and should we be defending against them specifically?
The Gentlemen are a splinter group from the Qilin ransomware operation, reportedly formed after a dispute over a ransom payment. In roughly a year they have claimed more than 300 victims and scaled faster than any other group NCC tracks, accounting for 15% of all attacks recorded in July 2026. But no, you should not build a group-specific defence. Fifteen per cent means the other 85% of July’s attacks came from someone else — more than 750 incidents. Attribution is useful to insurers, law enforcement and regulators. For an SME, it should not shape the roadmap: enforced MFA, patched perimeters and tested immutable backups are indifferent to which brand is on the ransom note.
NCC called CRPxO “partially verified”. Why would a criminal group inflate its own victim list?
Because leak sites serve two audiences. The obvious one is the victim, pressured into paying. The less obvious one is the affiliate market: ransomware-as-a-service operations compete to recruit the people who actually carry out intrusions, and affiliates go where the operation looks successful and well-run. A long victim list is a recruitment advertisement. NCC recorded 36 claims from CRPxO in July but assessed the group as only partially verified, suggesting some claims may be exaggerated to make it appear more threatening than its real capability warrants. The practical lesson for defenders is to treat group rankings as a directional signal about ecosystem energy, not as an audited ledger.
What does the change of prime minister have to do with our security?
NCC’s report flags the UK’s recent change of prime minister as a period of policy transition, which can extend opportunities for threat actors because personnel and process changes create new targets for reconnaissance and social engineering. The mechanism is straightforward: when names, reporting lines and approval routes change, people temporarily lose their instinct for what a normal request looks like. That effect travels down supply chains. If your business supplies, subcontracts to, or serves organisations touched by a reorganisation, expect a period in which unfamiliar names making plausible requests are genuinely common — which is exactly the cover a social engineer needs. Verify payment and access changes out of band, always, and especially now.
Our staff have had phishing training. Is that still enough against AI-generated lures?
Only if the training has been updated. Most awareness programmes teach people to spot spelling mistakes, awkward phrasing, generic greetings and the wrong tone — and generative AI removes all of those tells. Hull specifically identified training staff to spot AI-generated social engineering as part of the defensive picture. Updated training moves the emphasis from how a message reads to what it asks for: any request to change bank details, approve an unusual payment, bypass a process, install software or re-authenticate should trigger out-of-band verification regardless of how convincing it looks. Teach the process trigger, not the linguistic tell. Annual video training that has not been rewritten in two years is no longer doing the job.
Does Cyber Essentials actually help against ransomware, or is it just a procurement badge?
It helps, because its five control areas map closely onto how ransomware intrusions actually begin: boundary firewalls, secure configuration, user access control, malware protection and patch management. Enforced access control and current patching between them close the two most common initial-access routes. Certification also has a second-order benefit that businesses underrate — it forces evidence. Assertions that MFA is on and patching is current survive indefinitely until someone has to demonstrate them. That said, Cyber Essentials is a baseline, not a ceiling. It does not require centralised logging, monitored detection and response, or tested immutable backups, and those are what determine how a fast-moving intrusion ends.
If we were hit tomorrow, what would determine whether we recover in days rather than weeks?
Backups, almost entirely — specifically whether they are immutable, whether they are reachable from a compromised domain account, and whether anyone has performed a full timed restore. Attackers routinely target backup infrastructure before deploying an encryptor, because a business with working backups does not need to negotiate. After that, it is whether you have logs. Without centralised retention across identity, endpoint and network, an incident response team spends its first days establishing what happened instead of remediating, and you cannot tell a client or the ICO what was accessed. Third is whether the response plan has been rehearsed by the people named in it, with out-of-band contact details and pre-agreed authority to disconnect systems without waiting for a meeting.

The window is the point

Almost 900 attacks in July, 29% of them in Europe, a year-old splinter group taking 15% of the total, and a first documented case of an autonomous agent running an intrusion from end to end. Read together, those figures describe an ecosystem that is getting faster, more distributed and less dependent on skilled human operators. None of them describe a new class of vulnerability. The way in is still an unpatched edge device, an unenforced authentication policy or a person persuaded to do something reasonable-sounding.

That is genuinely good news, because it means the defensive work is known, bounded and affordable. It is also the reason delay is expensive. The controls that stop an agentic intrusion are the same ones that stop a human one — they simply have to be in place beforehand, because there will be less time to improvise. Jadepuffer is a proof of concept today. The interval between proof of concept and commodity tooling in this ecosystem has historically been measured in months, and enforcing MFA properly, getting internet-facing systems onto a managed patch cycle and proving a restore works takes about the same amount of time. Starting now means those two clocks run in parallel rather than one behind the other.

Make July 2026 the month you stopped deferring the fundamentals

Cloudswitched works with UK businesses on exactly the controls NCC Group identifies as still mattering most — enforced identity and access management, managed vulnerability and patch cycles, visibility across the estate, and tested immutable backups — with Cyber Essentials certification as the evidenced baseline that satisfies clients, insurers and procurement.

Talk to us about Cyber Essentials Certification
Tags:Cyber EssentialsIT SupportNetwork AdminCloud Backup
CloudSwitched

London-based managed IT services provider offering support, cloud solutions and cybersecurity for SMEs.

CloudSwitched Service

Cyber Essentials Certification

End-to-end Cyber Essentials Plus certification and ongoing security services for UK businesses

Learn More

Technology Stack

Powered by industry-leading technologies including SolarWinds, Cloudflare, BitDefender, AWS, Microsoft Azure, and Cisco Meraki to deliver secure, scalable, and reliable IT solutions.

SolarWinds
Cloudflare
BitDefender
AWS
Hono
Opus
Office 365
Microsoft
Cisco Meraki
Microsoft Azure

Latest Articles

9
  • Google Ads & PPC

Google Ads Attribution: A UK Business Guide to Understanding Which Campaigns Actually Drive Sales in 2026

9 Sep, 2026

Every UK business running paid search eventually has the same meeting. Someone opens the Google Ads interface, sorts the campaign list by conversions, points...

Read more
8
  • SEO

Technical SEO Audit: A UK Business Guide to Finding and Fixing the Issues Killing Your Rankings in 2026

8 Sep, 2026

There is a particular kind of frustration that shows up in UK marketing meetings about eighteen months into a content programme. The blog is publishing...

Read more
7
  • Web Development

Website Accessibility Compliance: A UK Business Guide to Meeting WCAG 2.2 and Avoiding Legal Risk in 2026

7 Sep, 2026

Most UK businesses discover the state of their website accessibility in one of three ways: a customer complaint, a procurement questionnaire they cannot answer...

Read more

Enquiry Received!

Thank you for getting in touch. A member of our team will review your enquiry and get back to you within 24 hours.