This Week's Cyber Radar
Most exposure now sits with the things an organisation has already granted access to, automated software, long-lived credentials and suppliers it never contracted with directly. Here's what happened this week, and what it means for you.
1. NCSC sets ground rules for AI agents
The NCSC has published interim guidance for organisations running AI agents, covering sandboxing, monitoring and the ability to shut an agent down mid-task. It sets out four levels of network control, from unrestricted access at level one to no external access at all at level four. Practically, this means deciding how much autonomy an agent needs before it is given any.
Read the source →2. ICO presses police on facial recognition
The Information Commissioner's Office has published audit outcomes covering five police forces' use of facial recognition, calling for significant improvements in oversight, record keeping and training. It issued 107 recommendations, all of which were accepted or partially accepted. Notably, the findings turn on whether controls can be evidenced, not whether they are documented.
Read the source →3. Premier League makes cyber rules mandatory
The Premier League's 20 clubs have approved a cyber compliance regime carrying fines of up to £100,000, phased in from April 2027 and covering backups, incident response and recovery. Research by Darktrace found 80% of the sports organisations it works with had a cyber incident in the past year. In short, sector bodies are now setting requirements ahead of regulators, not behind them.
Read the source →4. US Bank points to a fourth party
US Bank has been listed on the LockBit leak site, with the group threatening to publish data on 3 September. The bank says the available evidence indicates a fourth-party event outside its own environment. Even so, its name is attached to the incident — which is why dependency mapping needs to reach past your direct contracts.
Read the source →5. Exposed cloud keys still work
Researchers found that more than 9,300 cloud access keys leaked publicly since 2022 still authenticate, including 526 company root keys with full administrative rights. Only 13.7% of the keys with recorded creation dates had ever been replaced, and the median age was around five years. Therefore, an inventory of long-lived keys is a small task with a considerable payoff.
Read the source →None of this week's stories needed a clever attack.
Each one traces back to an agent, a supplier or a key that nobody was reviewing.
Full story details & sources →Knowledge Hub
To see how we work with clients, ensuring data privacy compliance for their specific industries read our useful articles, guides and customer success stories





