What shipped, and when did you know: the Cyber Resilience Act's clock starts tomorrow
From 11 September 2026, anyone selling software or connected hardware into the EU has 24 hours from the moment they know a flaw is being exploited to tell a national CSIRT. What that means, what it does not yet mean, and why it reaches British firms that never signed up to it.
Read full article →No personal liability, no change: the Cyber Security and Resilience Bill misses the one lever that works
Peers asked why the Cyber Security and Resilience Bill lets executives off the personal liability hook. The Government said corporate fines are enough. Thirty years of watching boards tells me they are not, and here is why.
Trezor, ShipMonk, and the deletion that never happened
Trezor's shipping partner was breached through a Metabase zero-day in August. This week the count reached 81,000, because 67,000 records came from 2019 to 2021 orders ShipMonk had confirmed in writing were deleted. A timeline, and what it teaches about supplier assurances.
The unmarkable exam: the child-safety law no one is allowed to grade
The Children's Commissioner told a Lords committee that children say the Online Safety Act has made "absolutely no difference" — and that she can't judge it, because Ofcom won't release the platforms' risk assessments. A law built to be unmarkable has already told you something.
The week in cyber — 31 August to 4 September 2026
Parliament writes a 24-hour clock into law while attackers work through the appliances at your network edge — four things from the week, each with a decision attached.
The consent nobody sought: Britain says no to the keys
Someone finally asked the public — and across every party, Britain said it would not trust the state with the keys to its private life. A sidebar to the series that goes to the foundation the whole age-verification project rests on: a consent never sought, and never given.
The UK threat landscape: August 2026
The first of a monthly series. In August, 8.7 million airport customers, more than a thousand charities and a national police database lost data through exposed keys and open portals rather than exploits; a small power generator went dark; and the patch window shrank to days.
The honeypot changes address
Part 11: Meta settles the US child-safety case for up to $18bn and the UN comes out against outright bans — the week the ban model lost the argument. But the age check just moved from the platform to the app store, and the identity honeypot moved with it.
AI-generated harm against children in 2026
Revisiting the September 2024 post on deepfakes and children. UK law has criminalised creation of intimate deepfakes of minors. Schools have policies. The IWF reports massive growth in AI-generated CSAM. Voice clone fraud is mature. What has actually changed and what to do.
Struck down before the start: France's court reads the argument back
Part 10: eighteen days before launch, France's Constitutional Council struck the under-15 ban down — on the grounds this series pressed: disproportion, and age verification with no guarantees for private life. A reprieve, but the redraft is already commissioned.
Gaming and online communities in 2026: what changed
Revisiting the 2023 post on gaming, voice chat, and the communities that look least like social media. Three years of platform safety overhauls, AI moderation, AI voice in games, and the new financial and AI-companion risks that did not exist last time.
The first hour
Part 3: a child has just told you they are being extorted over an image. What to do, in what order, in the hour that follows. Why not to pay, why not to block before you capture, what Report Remove actually does, and why the image is not the emergency.
The first message is always kind
Part 2: how contact with a child actually starts. Not a stranger saying something obviously wrong, but attention, aimed at a child having a bad week. The pattern, the four things that stop them telling you, and the sentence to say before anything happens.
The week in cyber — 20 to 24 July 2026
A zero-click Russian email campaign, a SharePoint patch trailing its own exploitation, an AI agent that escaped its sandbox, and a council insider nobody was watching — four containment failures and the board questions they leave behind.
They were never on the dark web
Part 1 of a new series. Europol has just referred 4,340 URLs tied to The Com, a network that grooms and coerces children on the platforms they already use. Why the dark-web mental model fails parents, what the numbers say, and what follows.
The trapdoor under the safe harbour
A pornography company and a speed-camera app have just cost the internet its hosting defence. The Court of Justice says algorithmic ranking is control — and the protection against being made to monitor everything may go with it. Why the ruling I wanted worries me.
The experiment comes home: Britain bans under-16s
Part 10: the experiment comes home. Britain will ban under-16s from social media by spring 2027 — the ban the Commons rejected in March, revived by regulation in June. Held to the same standard as France and Australia, including the objection the government made itself.
Four days, 490 records: the insider breach nobody budgets for
A new council worker opened ~490 sensitive safeguarding records and downloaded 94 over four days — then got a suspended sentence. The sentence is the least interesting part. Why insider snooping is the breach nobody budgets for, and why you can't rely on prosecution to stop it.
The experiment goes live: France bans under-15s
Part 9: France becomes the first country in Europe to ban under-15s from social media — and the first to make everyone verify their age. Braver than Australia's version, and it builds the identity honeypot at national scale. Scoring the law against the argument.
An AI broke containment and hacked Hugging Face to cheat a test
An autonomous AI agent broke into Hugging Face's production systems — thousands of actions, stolen credentials, lateral movement. OpenAI admitted it was theirs: models in a cyber eval escaped their sandbox and hacked a real company to cheat the test. Not malice — optimisation.
Buying the breach: cyber due diligence, a board read
In a deal you don't just buy revenue — you buy the unpatched servers, the undisclosed incidents, and whoever is already inside the network. A board read on cyber due diligence: what's at stake, what to ask before signing, and why a court just put a PE sponsor on the hook.