Four things from the past working week that a UK board should know about, in the order I would raise them with a chair over coffee on Monday morning. The theme this week is speed, and who has it: Parliament spent Tuesday arguing over a 24-hour reporting clock, attackers spent the same days working through the security appliances that are supposed to keep them out, and Google shipped its sixth emergency browser fix of the year. I have left the noise out. What survives has a decision attached.
1. The Lords have started rewriting your supplier list
On Tuesday 1 September the Cyber Security and Resilience Bill entered Committee Stage in the House of Lords. This is the last substantive scrutiny before Royal Assent, expected later this year, and the shape is now settled: managed service providers and data centres regulated directly for the first time, a two-stage incident reporting duty of an initial notification within 24 hours and a full report within 72, and fines of up to £17 million or 4 per cent of global turnover. The Commons Library briefing remains the best plain-English summary.
What sharpened the week was the government's late additions. After The Telegraph revealed that Iran-linked attackers had forced a small UK energy generator offline for four days in July, ministers tabled amendments giving themselves powers to block critical-sector organisations from using technology suppliers deemed high risk. Note the mechanism: the state improving your resilience not by telling you to secure yourself, but by removing suppliers from your list.
For boards. Two questions, depending on which side of the fence you sit. If you buy: which of your suppliers could a minister plausibly strike off, and what is your exit plan for each? If you sell into energy, water, transport, health or their supply chains: you may be about to become a regulated entity, and the 24-hour notification duty is the part that takes longest to build. It has to work at 2am on a Sunday, triggered by an on-call engineer's judgement, without waiting a working day for legal sign-off. Start now; the secondary legislation will not give you the lead time you need.
2. Ten exploited flaws in three days, and most of them are plumbing
Between Monday and Wednesday CISA added ten vulnerabilities to its Known Exploited Vulnerabilities catalogue, all confirmed under attack. The pattern in the list is worth a moment. CVE-2026-83548 is a pre-authentication flaw in SonicWall SMA1000 remote-access appliances rated a maximum 10. Two PaperCut print-management flaws allow unauthenticated configuration changes. JFrog Artifactory, the system many firms use to store their software builds, has an authentication weakness handing out administrative access. And a flaw in LiteLLM, a popular AI gateway, has already been used in a supply chain attack that touched over 2,500 organisations.
Not one of these is a desktop or a laptop. They are the boxes at the edge of the network and the tooling behind the build pipeline — the infrastructure that runs quietly, is patched rarely, and holds credentials for everything else.
For boards. Ask for a one-page list of every internet-facing management interface in the estate: VPN appliances, print servers, artefact repositories, AI gateways. If nobody can produce that list within a day, that is the finding. The KEV catalogue is free, updated daily, and a perfectly good standing input to your risk reporting; if your security team is not measuring time-to-patch against it, ask why.
3. Chrome's sixth zero-day of the year, and a thousand-dollar thank-you
Late in the week Google shipped an emergency Chrome update for CVE-2026-85046, a type-confusion flaw in the V8 JavaScript engine that an exploit already existed for in the wild. A crafted web page is enough to run attacker code inside the browser. It is the sixth exploited Chrome zero-day of 2026. The researcher who found it was paid $1,000, which tells you something about the going rate for honesty when the grey market pays six figures for the same bug.
For boards. The browser is the most attacked piece of software your organisation runs, and six emergency fixes in eight months is the new normal, not a bad year. The question for your IT leadership is a single number: when Google ships an emergency update, how long until it reaches 95 per cent of your estate? If the answer is "when people restart their browsers", the honest answer is "unknown", and unknown is the wrong answer for the software that sits between your staff and the internet.
4. AI has found its way into the complaints inbox
The BBC reports that UK councils and other public bodies are being buried under AI-generated complaints — routine grievances about missed bins arriving as 20 to 30 page documents citing statutory duties and legal precedent, much of it fabricated. Staff are instructing lawyers to check citations that turn out not to exist, and the cost is landing on operational budgets rather than on anyone's risk register.
This is not a public-sector curiosity. Any organisation with a complaints function, a subject access process or a regulator to answer to should expect the same inflation: the cost of producing a plausible-looking 30-page letter has fallen to nothing, while the cost of responding to one has not moved.
For boards. Ask your operations and legal teams what happens to complaint-handling and DSAR service levels if average correspondence length rises tenfold. Then ask whether the response should also be AI-assisted, under proper oversight — because matching machine-generated volume with purely human effort is a losing trade, and your regulator will not extend the statutory deadlines to accommodate it.
The thread that ties this together
Every story this week is about clocks running at different speeds. Parliament is writing a 24-hour notification clock into law. Attackers turned newly disclosed appliance flaws into live exploitation inside days. Google patched a browser flaw the moment exploitation was confirmed. Meanwhile most organisations still run patch cycles measured in weeks and complaints processes measured in months, and the gap between those speeds is precisely where the losses happen.
The question to take into next week: if the Bill's 24-hour clock started ticking at 2am on Sunday, who in your organisation would hear it — and would they have the authority to act before Monday's coffee?