Cyber_Radar_17_August_to_23_August_2026

Weekly Cyber Radar

17th August - 23rd August 2026

Each week, Cyber Radar brings together the latest cyber security, resilience and regulatory developments, with clear insight into what they mean for organisations.

This week's stories centre on access that was granted and never reviewed, exposure arriving through a supplier's supplier, and regulators asking organisations to evidence their controls rather than describe them.

Subscribe to receive the weekly highlights and scroll down to explore this week's stories.

Subscribe to Cyber Radar

NCSC Issues Interim AI Agent Guidance

Screenshot 2026-07-07 at 11.35.34
What happened

Organisations running AI agents are told to sandbox, monitor and retain the ability to shut them down.

Insider Intel

Four-level maturity model, from unrestricted network access to none at all.

What to do now

Map where AI agents already hold access before extending their autonomy.

ICO Publishes Police Facial Recognition Findings

Screenshot 2026-08-24 at 11.58.32
What happened

Audits of five police forces found gaps in senior oversight, record keeping and staff training.

Insider Intel

107 recommendations issued, all accepted or partially accepted.

What to do now

Check your high-risk data processing has named owners and current training records.

Premier League Mandates Club Cyber Standards

Screenshot 2026-08-24 at 12.00.23
What happened

Clubs face fines up to £100,000 under rules covering backups, incident response and recovery.

Insider Intel

Phased from April 2027, with an annual January assessment.

What to do now

Start evidencing backup and recovery capability now, not at the first assessment.

US Bank Cites Fourth-Party Breach

Bank
What happened

A ransomware leak-site listing was traced to an event outside the bank's own environment.

Insider Intel

LockBit set a 3 September publication deadline.

What to do now

Agree in advance who speaks if a supplier's supplier is breached.

Exposed Cloud Keys Remain Active

typing-on-laptop-keyboard-with-illuminated-keys-2026-03-18-14-53-48-utc
What happened

Over 9,300 publicly leaked cloud access keys still authenticate, some with full admin rights.

Insider Intel

526 were company root keys; only 13.7% had ever been rotated.

What to do now

Inventory long-lived access keys, remove root credentials and rotate anything made public.

Three priorities for leaders

Give every machine identity an owner

Automated agents, service accounts and access keys should each carry a named owner, a defined scope and a review date, in the same way that staff accounts already do.

Map one supplier layer deeper

Your exposure includes the organisations your suppliers depend on, so extend dependency mapping beyond direct contracts and agree how you would verify a claim involving them.

Evidence controls, don't describe them

Regulators and sector bodies increasingly ask for records, training completion and tested recovery, so build that evidence trail now rather than assembling it under pressure.

The Cyber Security Compliance Experts

RightCue has delivered cyber security compliance and assurance since 2009. We are an NCSC Assured Service Provider, CREST accredited, and a Government Commercial Agency supplier.  We work across Defence, Healthcare, Financial Services and Technology, helping organisations meet today’s regulatory requirements and prepare for what comes next.

Stay informed beyond the Cyber Radar briefing

How The UK’s Recent Cabinet Changes Could Impact Cybersecurity

RightCue named one of a small group of UK firms assured under NCSC’s Audit and Review scheme

RightCue has become an Assured Service Provider under the National Cyber Security Centre’s (NCSC) Assured Cyber Security Consultancy (ACSC) scheme, in the Audit and Review offering, starting 17th August 2026.

 

Wexstminster

What the UK’s Cabinet Reshuffle Means for Cybersecurity Leaders

Yogesh Agarwal, CEO at RightCue, has been vocal about the risk this creates. Commenting on the changes, he noted that the government has “effectively split up a well-formed function into three separate departments” and that this matters because AI and cyber are so closely linked.