Give every machine identity an owner
Automated agents, service accounts and access keys should each carry a named owner, a defined scope and a review date, in the same way that staff accounts already do.

17th August - 23rd August 2026
Each week, Cyber Radar brings together the latest cyber security, resilience and regulatory developments, with clear insight into what they mean for organisations.
This week's stories centre on access that was granted and never reviewed, exposure arriving through a supplier's supplier, and regulators asking organisations to evidence their controls rather than describe them.
Subscribe to receive the weekly highlights and scroll down to explore this week's stories.
Give every machine identity an owner
Automated agents, service accounts and access keys should each carry a named owner, a defined scope and a review date, in the same way that staff accounts already do.
Map one supplier layer deeper
Your exposure includes the organisations your suppliers depend on, so extend dependency mapping beyond direct contracts and agree how you would verify a claim involving them.
Evidence controls, don't describe them
Regulators and sector bodies increasingly ask for records, training completion and tested recovery, so build that evidence trail now rather than assembling it under pressure.
RightCue has delivered cyber security compliance and assurance since 2009. We are an NCSC Assured Service Provider, CREST accredited, and a Government Commercial Agency supplier. We work across Defence, Healthcare, Financial Services and Technology, helping organisations meet today’s regulatory requirements and prepare for what comes next.

.png?width=1000&height=1000&name=headshot_3_branded%20(1).png)
%20Act%202025.jpg?width=1924&height=1012&name=Data%20(Use%20and%20Access)%20Act%202025.jpg)
RightCue has become an Assured Service Provider under the National Cyber Security Centre’s (NCSC) Assured Cyber Security Consultancy (ACSC) scheme, in the Audit and Review offering, starting 17th August 2026.

Yogesh Agarwal, CEO at RightCue, has been vocal about the risk this creates. Commenting on the changes, he noted that the government has “effectively split up a well-formed function into three separate departments” and that this matters because AI and cyber are so closely linked.