Menu

Digital Fortress: Half year cyber threat update

Posted on 22 July 2026

Watching time 34 minutes
Read the full transcript

Joe Hancock, Partner (non-lawyer)

Welcome to our, uh, another Digital Fortress session for 2026.  And today we're going to be looking at a cyber threat update for kind of H1 of this year, intended to be a high-level view of the big changes at a kind of operational and strategic level for anyone involved in their wider cybersecurity or in fact kind of security posture within their organisation.  First, just some housekeeping.  If you have any questions, please put them in the Q&A function and we'll try and address them at the end.  If there's anything pressing, we'll try and deal with them as we go along bit by bit.  If you have any technical difficulties, stick them in the chat function, one of the team can help and if you want to get in contact with myself or Francisco or any other member of the team, please do feel able to do that directly.  If you click on the resources tab down below, you'll be taken to our bios and contact details so all kind of questions welcome, and there will be a recording of the session for everyone who signed up, whether you attended or not, which will be sent out in about 48 hours' time.

So thank you for joining us, and we look forward to an engaging and informative session.  So anyone who's attended one of these before knows I'm Joe Hancock.  I'm the partner and head of cyber risk and complex investigations at Mishcon, and I am joined by Francisco Sanchez.  Francisco, do you want to introduce yourself to everyone?

Francisco Sanches, Cyber Risk Director (non-lawyer)

Sure, I'm Mishcon’s Cyber Risk Director and I lead our digital forensics and incidents practise. Pleasure to be here today.

Joe Hancock, Partner (non-lawyer)

Thanks, Francisco.  Um, for Francisco and I, this is, uh, in certain degree a kind of businessman's holiday.  We spend a lot of time talking about threats, what's occurring out there, um, both because it kind of crosses our professional desk a lot, but also we kind of have a real, real deep interest.  So we're going to cover kind of four kind of key topics today, uh, and again, plenty of time for questions.  So let's talk about kind of cybercrime and ransomware to start with. What changed in the ransomware landscape in the first half of the year?  So I mean, why don't I kick off, Francisco, and then see what you think by reply.  So at the moment, our real kind of takeaway is we're seeing kind of much more shifts to kind of, frankly, extortion only.  We do see kind of encryption and destructive type attacks.  Most of the incidents we've dealt with, I'd say going on to the last year, 18 months have been very much extortion only.  So data theft, exfiltration, and then extortion off the back of a threat to leak or a perception of that.  We do see instances where the attackers will claim to have taken the data and try to extort a target.

We see less payments, which is positive, but those payments are for higher amounts.  Um, and then the big news for me really has been the law enforcement activity that's taken place in the last 6 months and then more broadly.  I mean, you'll have seen this week 2 individuals as part of the Scattered Spider group, both sentenced to over 5 years in prison, which is really positive for law enforcement.  That kind of means that more ransomware groups really are now kind of consolidating.  In essence, what law enforcement has managed to do is create a smaller but kind of stronger set of groups who've survived.  Those are groups who are perhaps beyond the reach of law enforcement geographically or just where they have a slightly different model.  That means that we've seen seeing kind of the affiliate groups really kind of get kind of smashed and some of the other groups be quite strong.  What's the kind of takeaway from that?  Probably that ransomware isn't going anywhere.  It's going to continue to be sophisticated and we'll continue to see more of it, but we might see some of the kind of more low-level opportunistic stuff disappearing.  Francisco, what do you think?

Francisco Sanches, Cyber Risk Director (non-lawyer)

I would highlight the move to data theft on extortion itself because we traditionally, the key control against ransomware is either the prevention to be able to detect and stop it from happening, or on the other end, after it happens, to have proper backups in place so we're not at the hands of the attacker about recovering our data.  Now, the move to data theft only extortion will put the focus back on companies needing to have a negotiation strategy in place to help them engage if they need, because the data is out there, it's a threat to probably publicating it or making it very well known in the news spaces.  And that, and this would really benefit from having both negotiation strategies and communication plans for those events prepared ahead of it.  That's where I see the move to data theft or extortion, putting the focus on.

Joe Hancock, Partner (non-lawyer)

No, I think, I think very good advice.  On the destructive attack side of things, I mean, we, we do see these, and again, the attack is now very much focused on actively targeting backup infrastructure, identity services, your kind of cloud and virtualisation management plan and we'll talk a bit about this further.  We’ll talk about identity attacks later on.  Um, and we now see this kind of being codified in the kind of defensive language as well.  So MITRE ATT&CK updated October last year, kind of codified actively disabling defences over kind of hiding type issues, which I thought was quite interesting because it now kind of codifies this recovery denial, backup destruction type issue, um, the kind of trend we see.  So I think from a kind of technical perspective, to me the takeaway is very much the kind of technical control opportunity is backups, identity, and virtualisation, not just trying to do more things with, with an endpoint, not looking at AV and EDR.  And to your point, very much agree.  If you're in data theft only territory, it's how do you communicate?  How do you kind of negotiate?  So I think unfortunately every threat briefing for the last 10 years and the next 10 years is going to include ransomware.

Um, why don't we talk about kind of moving beyond the money of it into kind of some of the more destructive and geopolitically driven kind of incidents?  Do you want to talk about some of the kind of perhaps the mass device wiping things we've seen?  And I could talk then a bit more about some of the geopolitics side of things, Francisco.

Francisco Sanches, Cyber Risk Director (non-lawyer)

Sure.  Well, one is not disconnected from the other so we talk about the recent mass device wiping campaign.  Uh, what we have there is no ransom, no negotiation so it's an incident with no ransom note, no negotiation channel, no decryptor to be had.  So the commercial and the planning logic that normally shapes a ransomware response is entirely absent.  Recovery was effectively the only option in that case.  Now I'm talking about the target that was Stryker.  It's one of the world's largest medical technology companies and an Iran-linked group turned the company's own administrative infrastructure into a weapon.  So the result was employees across 79 countries powering on their devices to find blank screens.  Corporate laptops wiped, bring your own device enrolled personal phones factory reset.  That means, you know, the personal photos, personal authenticator apps in the process, all gone and there was no malware.  The attackers in this case used Intune's built-in remote wipe capability against every enrolled device.  Now from the security stack, every command looked like a legitimate administrative action.  EDR had nothing to flag.  Now the group stated the attack was retaliation for ongoing US and Israeli military strikes on Iran.  This is activism with the potential motive, with the political motive.

Now the question you should take away of this would, if your backup strategy would actually be allow you to survive an attack of this kind?  Or do we need to rethink how we protect against them when attacks like this type of damaging, destructive wiper attacks come into play?  And I think that's a good wake-up call for most organisations.  Sorry, Joe.

Joe Hancock, Partner (non-lawyer)

No, no, I think that's really interesting so I remember the kind of the response to the Shamoon attacks, which again were Iranian-linked wiper attacks, again with a bit more of a traditional here's some malware that does the damage.  The using our own tools against us type piece is very interesting, again, using that Intune remote wipe piece, we want that for good data protection reasons, but then someone with privileged access can then use that against us.  I think that's fascinating.  I mean, you, you mentioned that the two being linked.  I mean, I come at this from the view of kind of, you know, we're now living very much in an era of conflict after what kind of felt like perhaps a decade of kind of safety and so I think for me, it kind of started with the war in Ukraine, then the, you know, the terrorist attacks on Israel.  We've now then got kind of, as you said, the US-Israeli strikes on Iran.  We've got wider conflict in Sudan and Africa. The world just feels instinctively like a slightly less safe place and maybe that was false safety, I don't know.  But what that means really is hostile states are still hostile.

They always kind of have been, as of there aligned groups.  I mean, you know, if you look at just some of the kind of National Cybersecurity Centre numbers, there's now more incidents affecting CNI, there's more significant incidents overall affecting kind of UK Plc and so I think that kind of in some way kind of goes to back up the fact we see more of these kind of state-level issues.  And again, and the other kind of key concept again is prepositioning, some of these attacks being done to kind of get a foothold in adversary infrastructure by kind of if there is a future problem.  We'll talk a bit more about prepositioning in a bit, but it's, prepositioning isn't a new concept, it was part of the kind of Cold War doctrine.  We've always had this idea of trying to gain this strategic foothold so you can then do something if you need to at a later date.  For me, the interesting area that comes, spins off the back of this though, is kind of these state-aligned actors or kind of hacktivism and I've, I've had a love-hate relationship with the term hacktivism for decades, because I think it's kind of, it's quite overblown and we used to have it there in the risk register as kind of hacktivism/cyberterrorism and what that really meant in practise was someone was going to deface someone's website.  Yet we had to, that we had to have it right there at the top of the risk register.  But I think we really are now seeing what that actually means and so for me, hacktivism is, or cyberactivism we call it, is it's the grey zone type issues we see.  It's synthetic media and propaganda.  It's some of these wider campaigns.  It's things like the kind of Stryker attack that are kind of state-related, or at least kind of conflict-related, but maybe on the traditional kind of cyber espionage campaigns we've seen.  Francisco, are there thoughts?

 

Francisco Sanches, Cyber Risk Director (non-lawyer)

Yeah, one of the things I like to highlight is when I look at the attacks we've seen out there, typically they're motivated, or most of them are motivated by money.  They were not motivated by money when we talk about nation-state sponsored attacks, they're typically against CNI infrastructures, to stop it.

Joe Hancock, Partner (non-lawyer)

Mm-hmm.

Francisco Sanches, Cyber Risk Director (non-lawyer)

This case is nation-sponsored activism against a private corporation, uh, company, and with the intention to destroy and with the wide effect in this case the number of affected machines was quite extensive.  And that in its own way, it's new.  It's not where the market was going from an attacker's perspective.  So a wide destructive wiper attack really needs a motivation behind it and we did when it's nation-sponsored, potentially that really changes the rules of the game against a private company, not a CNI from our perspective.

Joe Hancock, Partner (non-lawyer)

I think for me, another takeaway here is that if you look at the kind of grey zone piece, is that cyber now really needs to take on insider and kind of counterintelligence type threats in a way it never has done before.  There's a, you know, if you look in the history of kind of like cybersecurity education and how the kind of the disciplines developed, very much focused on there's a bad guy on the outside doing something that we need to protect against.  And you know, don't get wrong, like you look at ransomware, that often is the case but I think, you know, insider and the kind of wider geopolitical risk is not well, I think, understood.  So for example, you know, what happens to you as an organisation if you run foul of the US government and they order Microsoft to not provide you services?  You know, what happens in that scenario? What happens if you are part of a supply chain that provides services into a conflict zone, even if those are humanitarian services?  What happens if you are a widget manufacturer and your widget is deep, deep, deep down in the supply chain for a fighter jet, you know, you provide washers and nuts, those kind of things.

That, that starts to have a level of impact on you.  Don't get wrong, there's going to be a large chunk of organisations, you know, your kind of non-international organisations where this stuff still does not apply.  You are very much happy with your kind of geopolitical exposure and borders, but I'm not entirely sure many organisations have done that assessment yet.  And I think we're seeing this also.  Go on, Francesco, sorry.

Francisco Sanches, Cyber Risk Director (non-lawyer)

No, I was going to point something that I think we're going to see more and more also, the national cybersecurity centres of different countries issuing, uh, the joint advisory types like we've seen recently in July, early July.  So we had a national cybersecurity advisory issued alongside 18 security intelligence agencies across 12 allied nations.  And this was a major joint advisory warning about ongoing widespread targeting of network edge devices and this specific activity was attributed to Russia's FSB Centre 16, also known as Berserk Bear, Dragonfly, or, or Ghost Blizzard.  They are targeting sectors like communications, energy, healthcare, defence, financial services, and government.

Joe Hancock, Partner (non-lawyer)

Mm-hmm.

Francisco Sanches, Cyber Risk Director (non-lawyer)

Uh, the thing I'd like to, to point out on one hand is the joint advisory by allied nations, and I expect this will be increasingly in the future because that's the type of response that is required. Secondly, this is not about, although it's a nation-sponsored attack, it's not about anything deploying high-cost exploits.  No, we're talking about, in this case, the attackers relied on automated scanning for weak management configurations.  We're talking about basic network, network hygiene failures that are then exploited to gain initial access and quiet persistence. Their goal was getting initial foothold into organisations at the edge, what we call the edge hardware.

This would be things like unpatched Cisco devices and other type of network devices.  And that's from where they take, they get in, they stay there, they monitor because they're, they're nation sponsored.  They have politically motivated reasons to do this type of attacks and this is what we're seeing and both the response from joint actions.  Now when I look at both of those, this and Stryker, it's like two ends of the same spectrum.  Stryker shows you what happens when a management place is turned, sorry, the management plane, the control plane, in this case Intune, is turned against you.  The National Cybersecurity Joint Advisory shows how our adversaries are quietly prepositioning themselves in the infrastructure, waiting for a reason to act.  And now the motivation can vary, but our resilience needs to be constant to prevent against that.

Joe Hancock, Partner (non-lawyer)

Thank you. I like it and that kind of, you mentioned automation, which brings us on to the kind of elephant in the room.  We probably need to talk about AI, um, which unfortunately feels like, again, a bit like ransomware every threat briefing at the moment.  But I like how you, as soon as you said edge device, you mentioned Cisco routers.  I think that kind of betrays both of our backgrounds and kind of, and ages in this space is that that used to be very much the idea that you'd have some customer premises equipment and it was a router.  Now, sorry, router even, router would be a different thing.  Now, um, though, that kind of edge has a myriad of stuff and those things can be appliances in the cloud.  They aren't just bits of hardware, but there's also a whole chunk of stuff just sat on the edge of our control that often is highly vulnerable.  I mean, we've seen this multiple times.  I mean, Fortinet have had a few issues where they've released kind of major vulnerabilities in their appliances, for example.  You know, are we moving back to the bad old days of having to have two firewalls back to back because you can't trust what's in them and those kind of things?  I don't know, maybe we'll leave that one there.  So, AI and cyberattacks.  So, what's actually happening?  I mean, a couple of comments from me perhaps, and I'll come to you, Francisco.  I mean, I would be really happy to never see a headline that says, "AI writes malware that is super virus," ever again. I mean, I just don't think it's helpful. What we are seeing AI be used for, I put into two categories.  There's 1%, which is like writing better language, so, you know, foreign language attackers attacking English language organisations frankly can write better phishing emails, but we've seen that since the days of kind of Grammarly and others.  Um, that, you know, is always there in the background.  But actually what we are kind of seeing really is orchestration.  We're seeing, you know, agentic AI tools being used as a lot of people are using them.  Um, and we saw some really interesting research from Anthropic who, you know, looked across 830-something kind of bad accounts to see what those accounts were doing, and those accounts were carrying out relatively benign, kind of low technical capability, um, attacks, but were just very well organised.  I don't think that really should be surprising, because, you know, attackers will use AI to remove the time-consuming and low-value bits of the job, right?

That's the dream for all of us.  We want to spend more time on the bits that really require kind of the human kind of brain but I think that's kind of interesting that we see that orchestration.  Also, it kind of reminds me of the, of the idea that, you know, what's it, amateurs taught tactics, professionals taught logistics, that actually behind any kind of cyber campaign or attack, frankly, it's the logistics and operations that are the bit that kind of people struggle to get right, not finding actually a problem to exploit.  I don’t know what your kind of view of the AI landscape is?

Francisco Sanches, Cyber Risk Director (non-lawyer)

I'll broadly agree with you, and then a couple of things.  Now in my opinion, and sometimes it can be polemic, but AI has not yet produced a step change in the number of successful attacks. Now, what I mean by this is that the breach volumes, the initial access factor, the root causes behind the bulk of the attacks look broadly like they did 3 years ago.  Uh, you can take Google's Threat Intelligence Group latest report in their February 2026 tracker.  They have not yet observed any advanced persistent threat or APT or any other information operations across, sorry, information operations actors achieving breakthrough capabilities that fundamentally alter the threat landscape.  So why do we keep talking about it?  Well, because the shape of what attackers can do is changing as you mentioned.  I would summarise in 3 points.  Now, the first you mentioned, it's automation of the boring parts.  Now attackers are using LLMs to compress the labour-intensive phases, recognition, target profiling, translation.  There is a shift towards AI-augmented phishing enablement, you know, where the speed and accuracy of the LLMs removes the manual labour traditionally required for victim profiling.

Joe Hancock, Partner (non-lawyer)

Is this effectively the kind of uplift concept?  So, you know, an attacker being able to do something more complex than they otherwise would've been able to do with the help of AI?

Francisco Sanches, Cyber Risk Director (non-lawyer)

In this case, I would also say that it's not necessarily a new capability, but it's the same attack, but cheaper and faster because the LLMs can do these attacks and build the, the list, the, of the victims and send the attacks to them.  The second is, as you mentioned, the capability uplift for basic operators and this is the one I would flag to, you know, senior members on board is that AI raises the floor.  You know, a low skill actor who previously couldn't write a convincing English language pretext or couldn't read obfuscated code, couldn't chain an exploit to get where he needs to, now can, to some degree.  This means that the commodity end of the market has moved up, it's now a higher end.  There is now a functioning criminal marketplace focusing on AI-enabled tooling.  And the last one, and this is for me, the third one is the genuinely new development that I like to keep an eye on, is what we're watching, early autonomy.  We're starting to see AI embedded inside malicious code rather than sitting beside the operator.  By integrating LLMs into malware operations, attackers enable payloads to act autonomously, interact with the victim environments, synthesising system state, executing commands without human supervision.  And we're starting to have reported cases of end-to-end attacks conducted by LLMs and this is still early but the direction of travel is clear.  Now, why with all of this do I not believe that the threat landscape has significantly changed or increased? Now, my read of it is that the constraint on most offensive scale has never been the tooling.  It's the skilled operators running an intrusion end-to-end, knowing what to do, when you are inside, reading an unfamiliar environment, deciding when to move, when to sit still, staying quiet, or is judgement work.  That's the point and AI is currently very good at the parts either side of it, reconnaissance before, content generation, code scaffolding.  It is not yet reliably good at being the operator.  That's the gap that for now I believe it's holding the line.  The thing to watch then, for me, it's not the phishing volume, it's whether this agentic tooling starts to close that operator gap, because that's the variable that I believe would you know, make a group of 10 good people run like a group of 100, and that would scale and create the problem over there.

Joe Hancock, Partner (non-lawyer)

It's interesting you mentioned that kind of inside view.  Very often we find ourselves in this kind of like, I call it kind of a fishbowl, where we're looking into the environment and we can see where we're full visibility, we know where everything is and we could see what the attacker, um, was doing.  And often, you know, you do see lower skill attackers kind of flailing around a bit, you know, trying to work out what's out there, sometimes missing things that are kind of really obvious, sometimes finding things that are really interesting, you know, um, not being relatively sophisticated with their kind of tooling.  And again, something that could do a better job for an attacker of that internal enumeration, I think, yeah, would be quite interesting.  It's kind of a very, I guess it's a boring bit of the job again, right?  It's that kind of everyone's focused on the interesting bit, which is the how do I get in, how do I phish someone?  How do I keep my kind of, you know, command and control covert, all that stuff but actually the, how do I enumerate this environment on the inside and work out where everything is when I don't understand the naming convention, don't understand how a network's set up, all that kind of stuff would be, would be really interesting.

And just on that kind of insider point, one, one thing for me there is very much that, that kind of, you know, an issue I see is that it can have a very forward-looking risk you know, is now your own AI agents then as kind of insiders, you know, enterprise controls, you, you, we build them for conventional software, we build them for conventional users, but when you have an AI tool that runs as a user that has access to everything they have access to, um, that kind of starts to feel like a kind of data breach issue waiting to happen and it's not, um, we haven't entirely got our arms around that one yet.  But that brings me quite nicely onto our kind of final topic, which is identity because again, you know, an agent only acting as, as an individual.  So I mean, to me, this topic is really, is really simple on one level.  Social engineering is back.  Um, uh, not that it ever went away, um, and it works.  I mean, so, you know, we've seen help desk targeting with the M&S instance, JLR.  We see help desk targeting incoming ourselves.  We see it in various clients.  But then, you know, I, I have social engineering kind of recordings from call centres going back 10 or 15 years ago trying to, um, elicit information from people, not necessarily a new set of tactics, but perhaps being used against helpdesk a bit more, a bit more novel.  And you know that this, this isn't, this isn't software, this is persuasion over malware, as I saw it nicely kind of described recently.  And I do think though that there is a kind of a layer below that when we talk about identity though.  Um, we do, we do see attacks focused on the identity service, reconfiguring entry once someone's got access, adding a second MFA token. Um, we see them in the cloud management layer where, you know, monitoring is kind of incomplete or kind of poorly understood and that's a little bit complicated because trying to deal with, you know, an attacker that might have either compromised your help desk infrastructure or has then compromised those management tools feels like a struggle.  A lot of security operations teams we see, or even IR teams, very, very focused on what happens on an endpoint, what happens on an account, don't really know how to deal with an attack that really only touched Azure, for example, or another cloud plane.  I mean, any thoughts about what's happening in this wider identity space now?

Francisco Sanches, Cyber Risk Director (non-lawyer)

Well, two things come to mind.  One of them is the use of physical attacks to compromise or override identity controls.  So we've seen reported a number of increased compromises to physical security.  That could be either by getting you to hire an employee that is not who he pretends to be and getting him inside the organisation with valid credentials behind the identity already because you were tricked into hiring the wrong person.  And the other one is people hired in the physical world to get close to your computer and try to physically get access to it or deploy something straightforward in there, uh, again bypassing traditional identity controls.  Uh, the last thing I would mention in this space is that I think companies need to reassess, um, carefully is about what's normally called, you know, privileged MFI phishing resistance.  So what we mean is talking about physical FIDO2 and passkeys.  Now, I don't suggest that this should be deployed for all the users, that's a big step and can be quite disruptive.  But I do need, I do need to suggest organisations think about your global admins, your Intune admins, your high-privileged users probably move their authentication into that space to make it really resilient and really strong because those are the accounts that if compromised would be used to bring your organisation down.

Joe Hancock, Partner (non-lawyer)

Yeah, I think that's a really good takeaway, especially if you think about kind of, you know, the destructive attack we talked about with Stryker and Intune, remote wipe, those kind of things, having that kind of physical token or an additional layer around kind of your privileged accounts. MFA, so multi-factor authentication, um, you know, being seen as the kind of perhaps the panacea for all of these account takeover type attacks, but in itself has its own kind of weaknesses and isn't kind of used against everything.  I think also for me, it's not just detecting things statically, not just looking, you know, there's some really good detections there for, okay, we see this bad thing, we do this, but having to move to something more behavioural.  Is this admin account actually doing what we think it should be doing?  Should this admin account actually be wiping all of our devices, it normally wipes one device a month.  Why is it, you know, why is it wiping 100?  Those kind of things again with as an idea.  Um, difficult to do though in the kind of tooling at the moment.  Just aware of time, we're coming to our half hour.  These always been quite a rapid session.  Um, if there's any questions, feel free to drop them into the Q&A and we will endeavour to pick one, answer it now.  Again, if you have any, any you'd like to send through, please do. We'll just give it a couple of minutes for that.

Um, Francisco, if there's one kind of prediction, let me, let me ask my kind of favourite question, what prediction you had for the next 6 months, fast forward into us both being sat here in January 2027, um, what do you think is going to change?

Francisco Sanches, Cyber Risk Director (non-lawyer)

I think, I think we'll be going into the debate about the Fable-level AIs and the impact they have on the security space because Fable from Anthropic was the first commercially really sounded name that we had out there that really raised the discussion.  But now we have other LLMs raised to the same level, provide, proving, providing the same level of challenges from a security space.  And we're still waiting to see both on the commercial, how does that model work?  How can we get access to those level of LLMs without causing a problem with security? And the what problem will they bring to the security space?  I think that will be a very interesting topic and that will only grow in the future.

Joe Hancock, Partner (non-lawyer)

We've had one question through, um, around have we seen an increase in private client support in cyber incidents or an increased awareness of personal cyber threats?  Go on, do you want to do 30 seconds of that and I can perhaps chip in as well?

Francisco Sanches, Cyber Risk Director (non-lawyer)

Sorry, about the private client?

Joe Hancock, Partner (non-lawyer)

Yeah, effectively, you know, have we seen more on the private client side of our business?

Francisco Sanches, Cyber Risk Director (non-lawyer)

The, we have seen, the challenge with the private client is what their ability to get support into reacting and addressing the threats that are coming.  Now, typically the ones that will get wide support will have to be highly impacted to be balanced between what the effort of fighting it versus, uh, uh, a corporation that has the means and security tools to bring it.  I don't think the common Joe, pardon the pun, out there is not typically the focus of these attacks.  It is more and more high net worth individuals and these would be, uh, would do well to rethink how they're using their IT environment and the cybersecurity that they benefit from and how they can protect ahead of any potential attacks.

Joe Hancock, Partner (non-lawyer)

Yeah, I think it's interesting because if we look over the kind of private client cyber attacks we've dealt with, I'd say in the last 2 years, for me, the, whilst that, that there have been cyber issues that have affected those organisations on, and, you know, around those individuals, they've not felt targeted.  To me, they felt, um, uh, kind of opportunistic, or people didn't really know what they were targeting.  The, the issue we have seen is more targeted snatching of high-value items or burglaries and again, which now seem to have a certain level of cyber enablement to them.  If the plans for your house, your property, everything is online, if it's really obvious who your staff are and where they're going and those kind of things, that particular issue seems to occur quite a bit.  Um, and also on the awareness point of view, I think there is a general increased level of awareness across the population more broadly around fraud and scams.  In my experience, following kind of demographics, you tend to find that people who are more digital native, perhaps towards the younger end of the spectrum, tend to be a bit more aware than perhaps I look at my parents, for example, who are less digital native, but still now very aware.  We don't see necessarily a major kind of change being driven by that though.  I think at the moment, private clients more worried about physical safety issues off the back of the conflicts we've talked about in geopolitics than cyber at the moment.

Francisco Sanches, Cyber Risk Director (non-lawyer)

Yeah, they also benefit, sorry, just to wrap it up, they also benefit from an improvement on the default configuration of most SaaS services, iCloud being the most obvious one.  They've really stepped up their protections to minimise or diminish the number of issues with the security of that space.  So I think that has helped out significantly in bringing down the Private clients.

Joe Hancock, Partner (non-lawyer)

Yeah.  Which makes your other job as running our digital forensics offering even more frustrating.  And with that, so just to close again, we're just slightly over time.  Thank you very much, Francisco, as always, um, good to have one of our kind of threat coffee chats a bit more live, we should do this again.  And thank you for everyone that joined us today.  Any outstanding questions, I can see a couple, we'll tackle those by email and there'll be a recording sent to all those who signed up and our contact details.  If you want to get in touch directly, as always, um, if you click on the resources tab down below, you'll be taken to our bios and contact details.  Do please feel free to reach out.  Thank you.

Drawing on recent cyber incident response engagements and in-house threat intelligence activity, we explored the key threats shaping the cyber risk landscape in 2026 and the implications for organisations responsible for governance, compliance and resilience. 

Our key insights include: 

  • Ransomware is still the number one cyber crime issue. Data theft has overtaken encryption as the most common extortion tactic. Organisations should be considering their response, communications and regulatory strategies to deal with data leaks as well as backups and recovery. 
  • Geopolitical cyber risk is no longer confined to critical infrastructure. We are in a more exposed world with state-aligned and destructive attacks increasingly affecting private sector organisations. We recommend understanding the impacts geopolitical shifts will have on technology, security and business reputations.  
  • AI is helping threat actors operate faster and at greater scale. This occurs particularly through enhanced reconnaissance, phishing and operational automation, but there is a lot of hype. 
  • Identity has become a primary attack surface, with attackers increasingly targeting helpdesks, privileged accounts and cloud management platforms rather than endpoints themselves. We recommend understanding how social engineering attacks target your people, or how your Cloud and Technology environments are secured, beyond adding more security tools. 

Speakers

How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else