What Happened
Between late 2025 and mid-2026, the UK faced a series of ransomware attacks on major enterprises like Marks & Spencer, Co-op, Harrods, and Jaguar Land Rover. These incidents disrupted operations and harmed the national economy. The Jaguar Land Rover breach was the most expensive cyberattack in UK history.
The National Cyber Security Center (NCSC) found that these attacks weren't due to sophisticated exploits but preventable control failures already documented in its Cyber Assessment Framework guidance.
In July 2026, the UK government launched two initiatives. The NCSC began developing Cyber Shield, an AI system to quickly address vulnerabilities in critical infrastructure. Concurrently, the government introduced the Cyber Resilience Pledge, with 60 organizations, including some breach victims, committing to specific security measures. Early signatories included Marks & Spencer, Accenture, Microsoft UK, Cloudflare, Deloitte, EY, London Stock Exchange Group, and Vodafone.
Timeline
Late 2025, Early 2026: High-profile ransomware incidents hit UK retailers and manufacturers, disrupting services at Marks & Spencer, Co-op, and Harrods.
Q1 2026: The Jaguar Land Rover breach occurs, marking the highest financial impact from a cyberattack in UK history.
Mid-2026: NCSC's analysis identifies widespread non-compliance with Cyber Assessment Framework guidance.
July 7, 2026: UK government announces Cyber Shield AI research program and the Cyber Resilience Pledge with commitments from 60 organizations.
Which Controls Failed or Were Missing
The NCSC's assessment highlighted three key control failures:
Outdated and unsupported systems in use. Organizations operated legacy infrastructure without vendor support, leaving known vulnerabilities unpatched. This violated basic asset management and system hardening practices.
Delays in applying security updates. Even when patches were available, organizations lacked rapid deployment processes. This delay allowed attackers to exploit known vulnerabilities.
Weak access controls enabled lateral movement. Insufficient network segmentation and overly permissive account privileges allowed attackers to escalate privileges and move through environments. This showed failures in Privileged Access Management and the Principle of Least Privilege.
Anne Keast-Butler, director of Government Communications Headquarters, stated that "many attacks still succeed because of basic vulnerabilities" that are "well-understood risks" but "remain widespread."
What the Relevant Standards Require
These failures directly relate to control requirements in frameworks that the affected organizations should have implemented:
ISO/IEC 27001 Annex A.8.8 (Management of Technical Vulnerabilities) requires timely information on vulnerabilities, evaluation of exposure, and appropriate measures. This includes patch management and avoiding unsupported software.
ISO/IEC 27002 Control 8.8 mandates maintaining an inventory of assets and their vulnerabilities, defining action timeframes, and prioritizing based on risk. Running unsupported systems without compensating controls violates this requirement.
ISO/IEC 27001 Annex A.8.2 (Privileged Access Rights) requires restricted and controlled allocation of privileged access rights. The breaches showed failures in access control implementation and monitoring.
NIST Cybersecurity Framework (CSF) 2.0 Identify function requires asset management (ID.AM) and vulnerability identification (ID.RA). The Protect function demands identity management and access control (PR.AA) and protective technology, including patching (PR.PT). The breaches revealed gaps across both functions.
CIS Critical Security Controls 3, 4, and 7 provide specific guidance. Control 7.3 requires automated operating system patch management, while 7.4 addresses automated software patch management. Control 4.1 mandates secure configurations, including decommissioning unsupported systems.
The NCSC's Cyber Assessment Framework, which was not widely implemented, covers these requirements with UK-specific context. The lack of compliance indicates either inadequate governance oversight or insufficient resource allocation to foundational controls.
Lessons and Action Items for Your Team
The UK breach wave and government response offer clear guidance for your compliance and security programs:
Conduct an unsupported systems audit this quarter. Inventory every operating system, application, database, and network device. Flag anything past end-of-life. You have three options: upgrade, replace, or implement compensating controls with documented risk acceptance.
Build a 72-hour patch deployment capability for critical vulnerabilities. The NCSC emphasizes "rapid patching" due to the short timeline between vulnerability disclosure and exploitation. Your patch management process should include automated scanning, risk-based prioritization, and expedited testing for high-severity updates. Document your target timeframes in your vulnerability management policy and track them as KPIs.
Implement Just-in-Time Access for privileged accounts. If you grant standing administrative access, you're replicating the lateral movement risk seen in these breaches. Move to time-bound, approval-gated privilege elevation. This aligns with ISO/IEC 27001 Annex A.8.2 and provides audit evidence of controlled privileged access.
Make cybersecurity a board agenda item with specific accountability. The Cyber Resilience Pledge requires board-level responsibility and director training on cyber governance. Your board should receive regular reports on patch compliance rates, unsupported system inventories, and access control metrics.
Map your controls to the NCSC Cyber Assessment Framework even if you're not UK-based. The framework provides outcome-focused guidance that complements ISO/IEC 27001 and NIST Cybersecurity Framework (CSF) 2.0 2.0. Use it as a gap analysis tool against your current program.
Prepare for AI-augmented attacks by understanding your vulnerability surface. The Cyber Shield initiative assumes that AI will soon automate attack chains. Your defense needs similar automation. Start with automated vulnerability scanning, SOAR playbooks for common incident types, and AI-assisted log analysis.
The UK government's response is a wake-up call. Your organization faces the same threat landscape. The question isn't whether you'll experience a similar attack, but whether you'll have the same control gaps when it arrives.





