Review what former suppliers still hold
Ask each current and former supplier what customer data it keeps, why and for how long, and build deletion terms into every contract exit.

21st September - 27th September 2026
Each week, Cyber Radar brings together the latest cyber security, resilience and regulatory developments, with clear insight into what they mean for organisations.
Exposure this week sat with former suppliers, trusted sign-in steps and slow warnings. Five stories on where to look and what to check.
Subscribe to receive the weekly highlights and scroll down to explore this week's stories.
A second incident this month: a former supplier lost old Revolut customer data it kept for regulatory reasons.
Social engineering reached records kept only to meet regulatory duties.
List what former suppliers still hold on your customers and agree when it will be deleted.
Dyfed-Powys Police has restored contact channels after a 14 September attack but cannot yet rule out staff data loss.
Who got in, how, and whether ransomware was involved all remain unknown.
Make sure your incident plan covers staff and HR data, not only customer records.
Microsoft and the Met disrupted EvilTokens, which used a genuine Microsoft sign-in step to get past multi-factor checks.
97.5% of hijacked accounts were business ones, and the UK was fourth most targeted.
Ask IT to confirm device code sign-in is switched off in Microsoft 365 wherever it is not needed.
File transfer provider Kiteworks urged a nine-hour precautionary shutdown after a warning from federal authorities.
Suppliers may now ask for downtime on a warning alone, before any breach is proven.
Decide now who can approve an emergency shutdown of a supplier's system and what stops if you do.
Australia set up a taskforce after an OpenAI agent got past blocks on a Medicare portal and reached non-public files.
The agent got in on 18 June, but the government was only told 84 days later.
Set clear rules for any AI agent you run: what it may access, and how fast incidents get reported.
Review what former suppliers still hold
Ask each current and former supplier what customer data it keeps, why and for how long, and build deletion terms into every contract exit.
Close the sign-in routes nobody uses
Switch off legacy and device sign-in options where they are not needed, and add a second check before finance teams change any payment details.
Agree how warnings will reach you
Set out how suppliers will contact you during an incident, who receives that call, and who can approve switching a service off at short notice.
RightCue has delivered cyber security compliance and assurance since 2009. We are an NCSC Assured Service Provider, CREST accredited, and a Government Commercial Agency supplier. We work across Defence, Healthcare, Financial Services and Technology, helping organisations meet today’s regulatory requirements and prepare for what comes next.

.png?width=1000&height=1000&name=headshot_3_branded%20(1).png)

RightCue was delighted to speak to the Ministry of Defence about hardening cyber security Defence's supply chain. This follows the company being accredited by IASME as a Certifying Body across all four levels of the Defence Cyber Certification (DCC) - Levels 0 to 3 - under MOD governance. You can read the whole piece here.

RightCue's sales and operations director, Jenny Leah, features in SC Media UK's coverage of International Women in Cyber Day, alongside senior women from across the industry. The piece examines why women still hold just 17% of UK cyber security roles, and why the harder question is not how many women join the profession, but how many feel able to stay.