Four things from the past working week that a UK board should know about, in the order I would raise them with a chair over coffee on Monday morning. The theme this week is trust in the machinery — the regulatory clock, the patching pipeline, the endpoint agent, the governance framework — and in each case the machinery itself turned out to be the problem. I have left out the noise. What survives has a decision attached.

1. The EU’s vulnerability reporting clock started ticking on Friday

On 11 September, Article 14 of the EU Cyber Resilience Act became enforceable. From that date, any manufacturer of a product with digital elements placed on the EU single market must notify a national CSIRT and ENISA within 24 hours of becoming aware that a vulnerability in its product is being actively exploited. A fuller report follows at 72 hours. A final report is due within 14 days of a corrective measure becoming available.

The penalties reach €15 million or 2.5 per cent of global turnover. The obligation applies to products already on the market, not only those shipped after the date. And it catches British manufacturers that sell into the EU — which is most of the connected-hardware and embedded-software sector. I wrote about this in more detail on Thursday.

For boards. Ask your product and engineering leadership one question: do we have a process that can detect active exploitation of a vulnerability in our product and file an initial notification with a national CSIRT within 24 hours, including out of hours? If the answer is no, you are non-compliant as of Friday.

2. Microsoft shipped the largest Patch Tuesday on record

On Tuesday, Microsoft released fixes for 973 vulnerabilities, the largest single Patch Tuesday in the company’s history, with 113 rated critical. Two are confirmed under active exploitation.

CVE-2026-81963 is an elevation-of-privilege flaw in the Windows Update Stack — the mechanism your machines use to receive and install patches. A local attacker who exploits it gains SYSTEM privileges. It is the first Update Stack zero-day in five years, and the irony is precise: the system that delivers your defences is itself the vulnerability. CVE-2026-85880 is an elevation-of-privilege flaw in Windows ALPC, also exploited to gain SYSTEM. Both sit at CVSS 7.8. CISA has added both to the KEV catalogue with a federal remediation deadline of 22 September.

For boards. The number to ask for is not how many patches were applied, but how many days elapsed between Microsoft’s release and 95 per cent coverage of your estate. With a thousand CVEs in a single drop and a zero-day in the patching infrastructure itself, “we’ll get to it in the next cycle” is not an answer that ages well.

3. Your EDR just became an escalation path, and there is no patch

In early September a researcher publicly disclosed FalconFlank, a zero-day privilege escalation technique affecting CrowdStrike Falcon on Windows 11 25H2 and Windows Server 2025. A working proof of concept followed within days. As of Friday, CrowdStrike had not issued a patch.

The technique abuses Falcon’s own Office malicious macro remediation workflow: a low-privileged local user triggers the remediation behaviour and rides it to SYSTEM. The agent you deployed to detect and contain threats is the mechanism an attacker uses to escalate from a foothold to full control. CrowdStrike’s interim recommendation is to disable the “Microsoft Office file Suspicious Macro Removal” policy in the Falcon console. That removes the attack vector but also removes the protection the policy provides. It is a trade, not a fix.

For boards. This is not a patching question — there is nothing to patch. It is a trust question. Your endpoint detection platform is deeply privileged software running on every machine in the estate. When it becomes the escalation path, the usual answer — “our EDR will catch it” — is circular. Ask your security team whether the Falcon macro remediation policy has been disabled, and if not, what compensating detection they have for the specific escalation behaviour.

4. Parliament says no to personal director liability

Earlier this week, peers in the Lords Committee stage of the Cyber Security and Resilience Bill asked the government why the legislation does not impose personal liability on directors for failures of cyber governance. The government’s answer: corporate fines — up to £17 million or 4 per cent of global turnover — are sufficient to change behaviour. I wrote on Tuesday about why I think that answer is wrong.

The EU’s NIS2 directive takes the opposite view under Article 20, imposing explicit duties on management bodies including personal liability. The UK Bill will almost certainly reach Royal Assent this year without a personal liability provision. That does not make the question academic — it means the standard of care will be set by courts, by insurers, and by regulators, not by statute.

For boards. The absence of statutory personal liability does not reduce your exposure. It moves it from a defined penalty to an undefined one. If you sit on a board in scope of this Bill — and the scope now includes MSPs, data centres, and designated critical suppliers — the question is not whether the law names you. It is whether you can demonstrate that you governed the risk. That starts with being able to answer the questions in items 1, 2, and 3 above.

The thread that ties this together

Every item this week is about the machinery of defence, and every one found the machinery wanting. The CRA started a clock most UK product firms cannot yet hear. Microsoft patched nearly a thousand flaws, including one in the system that delivers patches. CrowdStrike’s own agent became the escalation vector, with no fix available. And Parliament decided that fines absorbed by the balance sheet will be enough to make boards care, while the rest of the week’s evidence suggests that boards still cannot answer basic questions about patch velocity, product vulnerability reporting, or endpoint trust.

The question to take into next week: of the four clocks that started or kept ticking this week — CRA reporting, Patch Tuesday remediation, FalconFlank mitigation, and Bill compliance planning — which one is your organisation actually tracking?