Close the access routes you forgot
List every integration, admin key and external account created for a reason that no longer applies, then close each one or bring it under multi-factor authentication.

31st August - 6th September 2026
Five stories about exposure that was already in place: retired logins, single suppliers, and patching that cannot keep pace with AI-scale discovery.
Subscribe to receive the weekly highlights and scroll down to explore this week's stories.
Refusing to pay did not stop publication: half a terabyte on 8.7 million airport customers is now public.
Entry is claimed to have come via admin keys left in public website code.
Check what customer data your public-facing booking and parking services hold, and who can reach it.
The regulator says AI is finding flaws faster than firms can fix them, straining remediation teams.
Watch for low-rated flaws being chained into a single workable route in.
Ask whether your patching pipeline could absorb a step change in volume without breaking change control.
165 of 213 English NHS trusts connect to a US hyperscaler, and 132 route email through Microsoft 365.
162 of 213 trusts sit across UK and US-held services at the same time.
Map the suppliers carrying your email, identity and core operations, and plan for a day without each.
A retired Lenovo sign-in route let attackers into about 5,000 Dropbox accounts, none using two-step login.
The access ran from 4 to 21 August before anyone spotted it.
Retire dormant sign-in integrations and make multi-factor authentication the default on shared storage.
France's regulator fined a private hospital 500,000 euros after data on 727,000 people was taken.
External clinicians could reach patient records with no extra checks at all.
Confirm external and third-party accounts require multi-factor authentication, and that access is logged.
Close the access routes you forgot
List every integration, admin key and external account created for a reason that no longer applies, then close each one or bring it under multi-factor authentication.
Know which suppliers you cannot lose
Identify the few providers carrying your email, identity and core operations, and write down what the business actually does on a day without each of them.
Fix by impact, not by severity score
Prioritise remediation using exploitable paths and business service impact, and test whether your change process could absorb a sudden surge in urgent patching.
RightCue has delivered cyber security compliance and assurance since 2009. We are an NCSC Assured Service Provider, CREST accredited, and a Government Commercial Agency supplier. We work across Defence, Healthcare, Financial Services and Technology, helping organisations meet today’s regulatory requirements and prepare for what comes next.

.png?width=1000&height=1000&name=headshot_3_branded%20(1).png)
%20Act%202025.jpg?width=1924&height=1012&name=Data%20(Use%20and%20Access)%20Act%202025.jpg)
RightCue has become an Assured Service Provider under the National Cyber Security Centre’s (NCSC) Assured Cyber Security Consultancy (ACSC) scheme, in the Audit and Review offering, starting 17th August 2026.

RightCue's sales and operations director, Jenny Leah, features in SC Media UK's coverage of International Women in Cyber Day, alongside senior women from across the industry. The piece examines why women still hold just 17% of UK cyber security roles, and why the harder question is not how many women join the profession, but how many feel able to stay.