Company Check: Anthropic Releases AI Once Deemed Too Dangerous

Anthropic has released a public version of the same AI technology that it previously restricted because of concerns about its cyber security capabilities, only for access to be suspended days after an intervention by the US government.

What Is Claude Fable 5?

Claude Fable 5 is a public version of Anthropic’s Mythos-class AI, a highly capable model originally developed for cyber security and vulnerability discovery work.

According to Anthropic, Claude Fable 5 and Claude Mythos 5 are “the same underlying model”, with the main difference being that Fable 5 includes additional safeguards designed to prevent misuse in areas such as cyber security, biology, chemistry, and model extraction. Mythos 5, by contrast, has some of those restrictions removed for approved users.

Anthropic originally developed Mythos-class models as part of Project Glasswing, a programme aimed at helping cyber defenders and critical infrastructure providers identify serious software vulnerabilities before attackers could exploit them.

When the first Mythos model was launched in April, Anthropic limited access to a small group of carefully vetted organisations because it believed the system’s cyber capabilities presented significant risks if made widely available.

Those concerns were not entirely theoretical. According to Anthropic, organisations using Mythos-class models have already identified “more than ten thousand high- or critical-severity vulnerabilities across the most systemically important software in the world”.

Why Anthropic Decided To Release It

Anthropic says it spent several months developing safeguards that would allow Mythos-level capabilities to be released more broadly while reducing the risk of misuse.

The result was Claude Fable 5, which the company described as “a Mythos-class model that we’ve made safe for general use”.

According to Anthropic, Claude Fable 5 delivers capabilities that were previously available only to a small group of approved organisations using Mythos. The company said: “Fable 5’s capabilities exceed those of any model we’ve ever made generally available.”

The model reportedly demonstrates state-of-the-art performance across software engineering, scientific research, vision tasks, analytical reasoning, and long-running autonomous work. Anthropic said it can “work autonomously for longer than any previous Claude models”, enabling it to tackle more complex tasks with less human supervision.

To reduce the risks associated with releasing such a powerful model, Anthropic introduced new safety systems that automatically redirect certain high-risk requests to a less capable model, Claude Opus 4.8.

According to the company, those safeguards were deliberately configured conservatively because “releasing a model this capable comes with risks”.

Suspended

However, just days after launch, Anthropic announced that access to both Fable 5 and Mythos 5 was being suspended.

The company said the US government had issued an export-control directive requiring it to disable access for foreign nationals, whether inside or outside the United States. Anthropic stated that the government believed it had become aware of a method for bypassing, or “jailbreaking”, Fable 5’s safeguards. A jailbreak is a technique designed to trick an AI system into ignoring or circumventing its built-in restrictions.

Challenged By Anthropic

However, Anthropic strongly challenged the significance of the alleged vulnerability. The company said it had reviewed the reported technique and found that it was capable of identifying only “a small number of previously known, minor vulnerabilities”. It also argued that comparable results could already be achieved using other publicly available frontier AI models.

Anthropic further stated: “We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people.”

The company warned that applying the same standard across the industry could effectively prevent the release of future frontier AI models.

A New Kind Of National Security Debate

The dispute highlights a broader change taking place in how governments are approaching advanced AI. For example, historically, software products were largely regulated after release if problems emerged. Frontier AI models are increasingly being treated differently because of concerns that they may create new risks in areas such as cyber security, biotechnology, critical infrastructure, defence, and intelligence.

Anthropic itself appears to recognise that reality, and the company has repeatedly argued that governments should have the ability to intervene when genuinely dangerous models emerge. However, it also insists that such decisions should be transparent and supported by clear technical evidence.

In its response to the suspension order, Anthropic stated that governments should be able to block unsafe deployments “as part of a statutory process that is transparent, fair, clear, and grounded in technical facts”.

The disagreement therefore appears to be less about whether oversight is needed and more about where the threshold for intervention should sit.

Why This Matters

The release and subsequent suspension of Fable 5 suggests that AI developers are now reaching capability levels where some models may be viewed as strategic assets rather than ordinary software products.

That raises some difficult questions for regulators, governments, technology companies, and investors alike. If advanced AI models can genuinely accelerate vulnerability discovery, scientific research, software development, and other high-value activities, restricting access could slow innovation. However, if those same capabilities can be misused, governments may feel increasing pressure to intervene.

Anthropic appears to believe that tension will become increasingly common as frontier AI systems become more capable. The company has argued that governments should have powers to intervene where genuine risks exist, while also warning that overly broad restrictions could hinder beneficial uses of the technology.

The dispute over Fable 5 therefore highlights a growing challenge facing policymakers: deciding when an AI model should be treated as a normal commercial product and when it should be treated as a potential national security concern.

What Does This Mean For Your Business?

For businesses, the story highlights how rapidly the AI landscape is evolving beyond questions of productivity and automation.

Many organisations are still deciding which AI tools to adopt, yet policymakers are already debating whether some frontier models should be treated as potential national security concerns. That represents a notable change in how AI is viewed by governments.

The wider lesson is that future AI adoption may be influenced not only by technological progress but also by regulation, export controls, safety requirements, and geopolitical considerations. As AI systems become more capable, businesses may find that access to certain models, features, or services depends as much on policy decisions as on technical innovation.

The dispute over Fable 5 may ultimately be remembered as an early example of a much larger challenge: how to make increasingly powerful AI systems broadly available while still managing the risks that come with them.

Tech Insight : Magnetic Tape Proves Its Value In The AI Storage Era

Magnetic tape is experiencing a resurgence in 2025 as AI-driven data growth, cyber security pressures and new material innovations push organisations back towards a technology first introduced more than seventy years ago.

What Magnetic Tape Is And How It Works

Magnetic tape stores data on a long, narrow strip of plastic film coated with a magnetic layer. The tape is wound inside a cartridge and passed across a read and write head inside the drive. Since the tape must move sequentially, it is not designed for fast, random access in the way a hard disk or SSD is. It is instead designed for efficient, bulk writing and long-term storage.

Tape libraries, used by larger organisations, combine hundreds or thousands of cartridges in robotic cabinets that load tapes automatically. These libraries act as vast, energy-efficient archives for data that needs to be kept but not constantly accessed. Typical use cases include regulatory records, scientific and medical datasets, media archives, analytics data, CCTV footage and full system backups. Tape has been used for these roles since the 1950s and, despite the emergence of disks, flash and cloud storage, it has never disappeared from enterprise environments.

Why Tape Remains In Everyday Workloads

Several characteristics have kept tape relevant. For example, it offers the lowest cost per terabyte of any mainstream storage medium, making it attractive for multi-petabyte archives. Also, cartridges can remain readable for decades when stored correctly, making them suitable for compliance regimes and research datasets that must be preserved far beyond the lifespan of typical disk systems.

Tape also has exceptionally low error rates. For example, modern Linear Tape-Open (LTO) technology uses powerful error-correction algorithms that protect data as it is written. LTO has been the dominant open tape standard since the late 1990s, evolving through successive generations with higher capacities, stronger encryption and support for features such as write-once, read-many modes.

Alternatives

The main alternatives for large-scale storage are traditional disks, flash arrays and cloud archives. Disks and SSDs provide fast access for operational workloads, while cloud storage offers virtually limitless scale without on-premises hardware. However, cost becomes a challenge once organisations begin keeping years of unstructured data. Tape avoids ongoing energy costs, avoids data-egress fees, and consumes no power when cartridges sit idle in a library.

Why Tape Is Back In Demand

It seems that demand for tape is currently being driven by the rapid rise of unstructured data. For example, organisations now produce and collect logs, video, images, sensor feeds and documents at a scale that was unusual a decade ago. The emergence of generative AI has turned this unstructured data into a strategic resource. Many enterprises now view their archives as training material for future AI models or as datasets that can be mined for insights.

Record

In 2023, the LTO consortium reported that 152.9 exabytes of compressed tape capacity were shipped worldwide, a record at the time. Shipment volumes broke that record again in mid-2024 with 176.5 exabytes shipped. In fact, this was the fourth consecutive year of growth. Vendors attribute this momentum to AI, compliance requirements and the rising cost of keeping large datasets online.

Economically Viable Medium

Analysts continue to describe tape as the only economically viable medium for archives that will grow into the multi-petabyte range. The LTO consortium, the group that develops and oversees the LTO tape standard, has previously highlighted potential total cost of ownership reductions of up to 86 per cent when compared with equivalent disk-based solutions across a ten-year period, with substantial savings also reported when compared with cloud archives over the same timeframe.

The New 40 TB LTO-10 Cartridge

One of the most significant developments in the tape market this year is the release of the new 40 TB LTO-10 cartridge specification. This represents a major capacity boost over the existing 30 TB LTO-10 cartridges, and crucially, the increase does not require new tape drives.

The capacity uplift is enabled by a new base film material known as Aramid. This material allows manufacturers to produce thinner and smoother tape, enabling a longer tape length within the same cartridge housing. The result is an additional 10 TB of native capacity, offering organisations a way to store larger datasets without expanding their library footprint.

HPE’s Stephen Bacon described the new cartridge as a response to AI-scale storage demands, noting that “AI has turned archives into strategic assets” and highlighting the role of tape in consolidating petabytes, improving cyber resilience through offline air-gapping and keeping long-term retention affordable.

Organisations will soon be able to choose between 30 TB and 40 TB LTO-10 media depending on their cost and density needs, giving enterprise teams more flexibility in how they scale.

How Tape Supports AI-Scale Archives

AI workloads require very large training datasets, often consisting of structured and unstructured data accumulated over many years. While a small proportion of this data must be kept on fast disk or cloud storage for active use, much of it can sit on a colder, cheaper tier until it is needed again. Tape seems to fill this role effectively.

When a dataset is required for training a new model or running a new analysis, organisations can restore only the relevant portion to a disk-based environment. This keeps primary systems fast while allowing the business to retain historic data without excessive cost. Examples include:

– Media companies storing decades of raw video footage for future AI processing.

– Healthcare providers archiving medical imagery for research or diagnostics.

– Research institutions holding large scientific datasets that may later be used to train AI models.

– Financial firms retaining historical transactions that can be analysed for fraud models.

Tape and Sustainability

The sustainability angle is also relevant here. For example, tape consumes no energy when cartridges are idle, which is increasingly important as data retention requirements grow faster than most organisations’ environmental budgets.

Why Cyber Security Is Driving Tape’s Revival

Ransomware has fundamentally changed the way enterprises think about backup. For example, when attackers can encrypt or delete connected storage, offline copies become critical. Tape provides a kind of physical air gap, as a tape cartridge removed from a library cannot be reached across the network.

Many organisations now follow the 3-2-1 or 3-2-1-1 backup strategy, which requires one offline copy stored on a different medium. Tape remains the simplest and most established way to achieve this. It is also highly portable, meaning offline copies can be stored off-site, which provides protection against physical disasters.

Some organisations also use write-once, read-many tape media for critical records, preventing accidental or malicious changes and strengthening their overall cyber resilience.

The Roadmap Ahead

The LTO consortium recently updated its roadmap and confirmed plans for LTO-11 through to LTO-14. Native capacities will continue to rise, with the roadmap peaking at a projected 913 TB for LTO-14. The revised roadmap places more emphasis on achievable density gains, reliability and cost efficiency, aligning future products with enterprise demand for high-capacity, long-lived archives suited to AI and analytics workloads.

The roadmap also seeks to ensure that tape libraries can continue scaling into the exabyte range, giving organisations confidence that their archive strategy will remain technically and economically viable over the next decade.

Challenges, Objections And Criticisms

Perhaps not surprisingly, tape does still face some criticism. The biggest concern is access speed. For example, because tape is sequential, retrieving a specific file can be pretty slow, especially when the data is buried deep within a long cartridge. This is why tape is rarely used for operational workloads where rapid, repeated access is required.

There is also the practical side to consider. For example, tape libraries require careful handling, environmental controls and periodic testing. Skills are another issue. Many younger IT teams have grown up working only with cloud and flash systems, leaving fewer staff familiar with tape management. Migrating data between LTO generations can be time-consuming, and organisations must plan for these cycles to avoid being left with unsupported formats.

Also, some businesses prefer cloud archives because they offer global access, integration with cloud analytics tools and managed durability. Others simply feel tape requires more up-front investment than cloud subscriptions or deep-archive tiers. Perception also plays a part. Tape is sometimes viewed as outdated, even when the economics point strongly in its favour.

Even so, most analysts note that modern storage strategies are multi-tiered. Tape does not replace disk, flash or cloud, it complements them. Its role is to keep very large datasets safe, affordable and durable while faster environments deal with day-to-day workloads. As organisations continue to accumulate huge troves of data for AI and analytics, that role appears to be becoming more important, not less.

What Does This Mean For Your Business?

Tape’s renewed momentum shows that long-term storage decisions are changing as organisations weigh cost, risk and the growing importance of historical data. AI is accelerating that shift because archives that were once seen as routine compliance obligations are now being treated as potential training material and sources of future insight. This gives tape a clearer strategic role than it has had for many years. It offers a stable way to retain data at scale without placing pressure on budgets or energy targets, and it helps organisations withstand ransomware incidents by providing offline copies that cannot be tampered with remotely.

UK businesses in particular may find that tape fits naturally into multi-tier storage plans. Many rely heavily on cloud platforms for operational workloads, but long-term retention remains expensive when kept online. Tape provides a way to control those costs while meeting regulatory expectations around record keeping and resilience. It also offers a reliable route to building deeper AI datasets without needing to expand cloud storage indefinitely. These practical benefits explain why more IT teams are revisiting tape not as legacy infrastructure but as an essential pressure valve for growing digital estates.

Vendors and analysts expect this direction to continue as the roadmap evolves and capacities rise. However, the challenges identified in the article remain relevant. For example, access speed is still a limitation and operational expertise is still required, especially where organisations run large libraries across multiple generations. Misconceptions about tape’s relevance also persist, even as the technology improves. The reality is that these barriers tend to matter less once businesses focus on what tape is designed to do rather than what it is not. Long-term archives do not depend on millisecond retrieval, they depend on affordability, longevity and resilience, which are exactly the traits tape continues to offer.

Stakeholders across the wider ecosystem are responding to the same pressures. For example, cloud providers are investing in colder, slower archive tiers, compliance teams are tightening retention requirements, and security teams are prioritising offline backups. All of these shifts align with tape’s strengths. As AI models become larger and more data hungry, and as cyber threats continue to evolve, it seems likely that tape will remain a practical part of the storage mix for many years, especially for organisations that need to store vast volumes of information safely, predictably and at a manageable cost.

Wi-Fi Warning: Staying Safe on Holiday

Business travel can expose individuals to serious cyber threats when connecting to hotel or airport Wi-Fi, so here we explain how to stay secure using practical precautions such as VPNs and mobile tethering.

Why Public Wi-Fi Is a Hidden Risk for Travellers

Public Wi-Fi is one of the most widely used digital conveniences among UK business travellers. Whether in airports, hotels, cafés or train stations, free internet access is often seen as a quick and easy way to stay productive while on the move. But security experts are warning that many of these networks are poorly protected or actively targeted by cyber criminals looking to intercept data or install malware.

A Norton survey found that 60 per cent of travellers were already connecting to public Wi-Fi at least once a week in 2023, with nearly half admitting they’d used unsecured networks to check work emails or log in to sensitive accounts. More recently, a 2024 analysis by cybersecurity firm Inflection Point confirmed that around 70 per cent of business travellers had encountered some form of cyber threat while away from their usual workplace.

For UK businesses in 2025, the operational risk is even greater. Remote access to corporate tools is now standard, while business travel has rebounded strongly across Europe and beyond. Insecure public networks can easily be exploited to steal credentials, compromise cloud accounts or gain backdoor access to business systems. The threat is no longer limited to high-risk environments, it’s embedded in everyday travel routines.

How Criminals Target Public Wi-Fi Users

The main security risk with public Wi-Fi is that it often lacks encryption. This means that the data sent between your device and the router can be intercepted by third parties using basic equipment. One of the most common tactics is known as a man-in-the-middle attack, where a hacker places themselves between you and the network to eavesdrop on your activity or harvest personal and company data.

Rogue Wi-Fi Hotspots

Another growing tactic is the use of so-called “evil twin” networks. These are rogue Wi-Fi hotspots set up to mimic a legitimate service, often with names like “Hotel_WiFi_Guest” or “Free_Airport_WiFi”. Once connected, users may be redirected to phishing pages or silently monitored. According to a recent report from US-based WatchGuard Technologies, it takes as little as £400 worth of off-the-shelf kit to create one of these fake hotspots.

Even genuine Wi-Fi networks can be a risk. For example, hotel systems are often shared across hundreds of users and rarely updated or segmented, making them soft targets. Airports are also ideal hunting grounds for criminals, thanks to the large volume of fast-moving, distracted users and international visitors unfamiliar with local security risks.

What Experts Recommend for Safer Connections

Security experts agree that the safest approach is to avoid public Wi-Fi altogether where possible. However, when access is essential, there are some practical steps that can significantly reduce the risk.

VPNs

The most important measure is to use a virtual private network (VPN). A VPN encrypts your internet traffic, so even if someone intercepts the connection, they won’t be able to read or tamper with your data. As Paul Bischoff, consumer privacy advocate at Comparitech, explains: “A VPN creates a secure tunnel that protects your traffic from snoopers on unsecured networks. For travellers, it’s an essential layer of defence.”

There are dozens of business-grade VPN providers on the market, with options like NordVPN, Surfshark and ExpressVPN all offering apps compatible with laptops and mobile devices. However, not all VPNs are equally secure. Free versions, in particular, may collect data or lack proper encryption protocols.

Tethering

Another option is mobile tethering, which involves connecting a laptop or tablet to the internet via your phone’s 4G or 5G data rather than using Wi-Fi. This method uses your mobile provider’s encrypted network and is generally far safer than connecting to unknown hotspots. Most smartphones have built-in hotspot functionality, though business travellers should check their data limits before relying on this approach abroad.

In situations where public Wi-Fi must be used, it’s also wise to:

– Avoid online banking, file sharing and sensitive logins.

– Stick to websites using HTTPS (look for the padlock symbol in your browser).

– Turn off auto-connect and file sharing features.

– Set the connection type to ‘Public’ in your device settings.

– Keep all apps, browsers and antivirus software up to date.

How Mobile Habits Can Create Unintended Exposure

A recent study by the UK’s National Cyber Security Centre (NCSC) highlighted how user behaviour plays a key role in exposure to cyber threats. In their analysis of business travel patterns, they found that users often relax security habits when on the move, especially during summer holidays or while rushing through airports.

For example, many travellers leave their phones or laptops unlocked, or stay logged in to work systems and cloud services. Others fail to check the legitimacy of a network before connecting, relying on familiar-sounding names. These small lapses, while understandable, can make it much easier for attackers to gain access.

The NCSC advises that staff travelling for work should be briefed on digital hygiene protocols and given the tools needed to work safely while mobile. This might include rolling out managed VPN solutions or providing mobile data allowances specifically for tethering.

The Cloud

One other important aspect to consider is that businesses are now increasingly reliant on cloud-based tools and remote access platforms, from Microsoft 365 and Slack to enterprise CRM systems. This has brought major flexibility gains, but it has also raised the stakes when it comes to endpoint security. For example, a compromised login from a hotel room abroad could open the door to serious breaches back home.

The UK’s Information Commissioner’s Office (ICO) warns that data breaches involving personal or client information (even if caused by insecure Wi-Fi use) can lead to investigations and fines under the UK GDPR regime. For regulated sectors such as legal, healthcare and finance, this risk is even more acute.

Reputational Damage Risk

There’s also reputational damage to consider. In one documented incident investigated by FireEye, a consultant’s credentials were stolen via a compromised hotel Wi-Fi network linked to the Russian espionage group APT28 (also known as Fancy Bear). The attackers exploited hotel routers to harvest guest login details, and those credentials were later used to access corporate systems remotely. Although no malware was installed on the consultant’s device, the breach led to serious trust issues for the consultancy firm involved, who were forced to issue apologies to clients and implement stricter travel security protocols.

Simple Precautions That Reduce the Risk for Everyone

Despite the risks, public Wi-Fi use isn’t going away anytime soon, but business travellers can take control with a combination of awareness and simple protective tools. In addition to using a VPN or mobile tethering, businesses should ensure that staff understand how to recognise suspicious networks and what to do if they think a device has been compromised.

MFA

The NCSC also recommends that all business devices use multi-factor authentication (MFA) and endpoint security tools to minimise exposure. Organisations should also maintain clear reporting lines in the event of a suspected breach so that action can be taken quickly.

Whether on a short-haul trip to Brussels or checking emails from a hotel bar in Singapore, a few small changes in behaviour can significantly reduce the likelihood of an attack. With cyber criminals becoming more sophisticated each year, secure connectivity is now essential travel kit.

What Does This Mean For Your Business?

Cyber security on the move is no longer a niche concern for IT teams. As this summer’s travel season gathers pace, the reality is that every employee logging on from a hotel, airport or conference centre is a potential entry point for a wider breach. Public Wi-Fi remains widely used but poorly understood, and attackers continue to exploit that gap with tactics that are cheap to deploy but costly to recover from.

For UK businesses, the stakes are clear. A single compromised login can lead to regulatory consequences, reputational damage and financial loss. This is especially true in sectors where client confidentiality, personal data or financial systems are involved. Relying on convenience over security, particularly during travel, risks undermining all the investment made in other parts of the company’s digital infrastructure. However, as this article has shown, the tools to mitigate that risk already exist. VPNs, mobile tethering, MFA, and well-informed staff are not just best practice, they are now baseline requirements for secure hybrid working.

What matters next is awareness and consistency. Companies must ensure that secure connection policies are more than a tick-box exercise, especially as international travel becomes routine again.

Back 2 Cyber-School : Test Your Team

UK firms are using summer downtime to run cybersecurity quizzes that improve staff awareness, reduce phishing risks, support onboarding, and build a stronger security culture ahead of the September reset.

Why Summer Is the Time to Act

It may seem counterintuitive to launch a cybersecurity initiative during the holiday season, yet security professionals say this is exactly the right time to do it.

Staff returning from leave are often catching up on emails, resetting routines, and switching back into work mode. That makes them particularly vulnerable to phishing emails, credential theft, and misjudged clicks. For example, according to CybSafe, human error still accounts for 95 per cent of successful cyber attacks, with fatigue, distraction and complacency frequently involved.

A 2024 KnowBe4 report found that staff were 29 per cent more likely to click on phishing links in the first week after returning from time off. With many UK employees taking annual leave during July and August, the September return presents a high-risk window.

That is why many IT and compliance teams are opting to launch a light-touch but high-impact quiz or awareness campaign during summer, or just at the end of the holiday period. The aim is to create a timely reset, not a compliance burden. As CybSafe puts it, “It’s like sharpening the tools before we go back into the busy season.”

Back to Business and Back to Basics

The term “back to school” may be figurative, but the principle stands. September often marks a fresh start, Q4 planning begins, new projects launch, and there is an influx of new joiners or temporary staff.

That makes it a natural moment to remind employees of core cyber hygiene habits. Password security, phishing recognition, two-factor authentication, and safe use of cloud platforms are all common focus areas. Rather than relying on lengthy and formal training sessions, many businesses are shifting towards short and interactive formats that nudge behaviour and boost recall.

Awareness Quizzes

For example, firms including CybSafe, KnowBe4 and ESET now offer ready-made awareness quizzes tailored to workplace risks. These tools test employees’ understanding of phishing techniques, device hygiene, credential security, and social engineering tactics. Many offer features such as internal benchmarking, anonymised scoring by department, and follow-up resources based on quiz performance.

Quizzes typically include multiple choice or scenario-based questions, with questions such as, “You receive a Teams message from your manager with an urgent link to an invoice. What should you do?” Feedback is usually immediate, and correct answers are explained to reinforce good habits.

To be effective, questions need to reflect real-life risks. For example, a phishing section might include, “This email asks you to ‘urgently verify your payroll details’ using a link. What should you check first before clicking?” A password hygiene question could ask, “Which of these is the most secure password: Pa55word!, £S78qp*4, John1980, or MyCompany123?” Other useful topics include recognising suspicious attachments, safe use of public Wi-Fi, and what to do if you suspect your laptop has been compromised.

For remote or hybrid workers, practical scenarios can help highlight overlooked risks. One example might be, “You’re working from a café and need to join a video call. What is the safest way to connect?” By focusing on realistic decisions, these questions build familiarity with threats and give staff confidence to make better choices.

As CybSafe notes, “Security awareness doesn’t need to be dry. Gamification increases engagement by up to 60 per cent, and we see higher retention when people enjoy the format.”

New Staff, New Risks

Another reason why late summer is an ideal time for awareness activity is the volume of onboarding across many sectors. Whether it is school leavers entering the workforce or internal moves following the holiday period, new and transitioning employees are consistently shown to be more vulnerable.

Research cited by Keepnet Labs shows that new hires are 44 per cent more likely to click on phishing links, and 71 per cent more susceptible to social engineering tactics within their first three months. This is often due to unfamiliarity with tools, eagerness to make a good impression, and uncertainty around what constitutes suspicious behaviour.

Embedding a cyber quiz into induction materials or using it as part of a post-holiday reset can help mitigate this. According to Keepnet, “Embedding quizzes into everyday culture, not just annual training, helps build shared ownership of cyber hygiene. Awareness becomes a team asset, not an individual chore.”

Campaigns That Stick

Many UK firms are using seasonal branding and lighter messaging to increase participation. For example, naming the initiative “Back to Business: Cyber Reset” or “Security September” helps frame the content as helpful and timely, rather than bureaucratic.

Typical campaign assets include a short online quiz, accompanying infographics or posters on common threats, and a follow-up message sharing results or next steps. Some businesses use this moment to revisit hybrid working guidance or flag updates to bring-your-own-device (BYOD) policies.

The Cyber Security Breaches Survey 2025, published by the Department for Science, Innovation and Technology, highlights just how common incidents remain. 43 per cent of UK businesses reported a cyber breach or attack in the past 12 months, but among medium-sized businesses, that figure rose to 70 per cent, and for large organisations, to 90 per cent.

The same report found that businesses with regular staff training and awareness campaigns were more likely to detect and respond to threats promptly. That strengthens the case for low-friction, repeatable tools like quizzes, especially when timed around known periods of vulnerability.

Metrics That Matter

It seems that quizzes can also generate useful insights. For example, platforms such as CybSafe and KnowBe4 offer dashboards showing which questions are commonly missed, which teams or roles may need additional support, and how engagement varies over time. That helps IT, HR and compliance teams refine their approach and demonstrate value to leadership.

These insights can also support wider objectives. For companies pursuing Cyber Essentials or ISO 27001 certification, regular awareness campaigns count as demonstrable evidence of good cyber governance and staff engagement with security.

Crucially, quizzes offer an approachable format. For example, as CybSafe research shows, campaigns framed around positive reinforcement rather than fear or punishment consistently lead to better uptake, stronger recall and healthier behaviours across the organisation.

Real-World Findings Underscore the Risk

Recent UK data reinforces the need for continued staff education. In the Cyber Security Breaches Survey 2025, phishing was identified as the most common attack method by 85 per cent of affected businesses. 65 per cent said it was the most disruptive type of incident they faced.

In the SME sector, a study by GetApp UK found that 94 per cent of phishing attacks arrived via email, and more than two-thirds of businesses had faced multiple attempts in a short timeframe. The simplicity of phishing makes it hard to block completely through technical defences, placing the onus back on staff to spot and avoid traps.

Also, the risk is not limited to newcomers. For example, as a UK workplace study reported by Insurance Edge found, managers were twice as likely as junior staff to fall for phishing scams, despite being more familiar with systems and policies. That suggests even experienced employees benefit from regular and practical reminders.

Taken together, these findings reinforce why so many UK businesses are choosing to run fun, quiz-based cyber campaigns during the summer, to catch complacency before it becomes costly.

What Does This Mean For Your Business?

This approach is not about ticking boxes. It’s actually about creating a security culture that works with people, not against them. For example, quizzes seem to offer a simple, low-pressure way to reset expectations, surface knowledge gaps, and refocus attention on the behaviours that actually reduce risk. They are also easy to run and repeat, which gives organisations more flexibility than formal training cycles often allow.

For UK businesses, the benefits are both immediate and long-term. A short, well-timed quiz can reduce phishing risk, especially among returning staff and new joiners, while also demonstrating good governance to customers, insurers and auditors. When supported by the right follow-up and metrics, these tools become part of a wider risk management strategy, not a standalone event. In sectors where compliance, reputation or customer trust are central, that distinction matters.

The impact also extends beyond the IT team. HR departments, line managers and internal communications teams all have a role to play in making cyber awareness relatable and consistent. Using seasonal campaigns or friendly team challenges helps embed these habits across different parts of the business, rather than leaving them siloed. That shift is key if organisations want security awareness to feel like part of the culture, not just a requirement.

Suppliers, partners and clients also benefit from this raised awareness. In an interconnected economy, a weak link in one organisation can expose others to unnecessary risk. By encouraging regular, engaging training, UK firms not only protect their own operations, but also contribute to a more resilient digital environment across their wider supply chain.

The timing matters too. With rising attack volumes and continued pressure on internal resources, companies that take advantage of the quieter summer period to prepare for Q4 are putting themselves on the front foot. Awareness may not stop every attack, but it can make the difference between a quick recovery and a costly incident. That is why summer quizzes are gaining momentum, and why more organisations are choosing to turn a seasonal lull into a strategic advantage.

Out of Office, Not Out of Mind …

In this article, we look at various ways staff can stay cyber-secure while away, from setting safer out-of-office replies to avoiding phishing on the move and protecting devices abroad.

Out-of-Office Messages Can Put You at Risk

Most employees see out-of-office (OoO) replies as a harmless admin task. However, the wrong message can actually open the door to social engineering and impersonation attacks. It’s not the message itself that’s risky but what it reveals, and to whom.

For example, attackers actively scan for out-of-office responses which include return dates, job roles, colleague names, or even direct phone numbers. These details can be used to craft credible phishing emails that appear to come from someone inside your organisation or a known supplier.

To reduce the risk, the UK’s National Cyber Security Centre (NCSC) advises that organisations set clear rules for OoO replies. The most important steps include:

– Using different messages for internal and external recipients.

– Avoiding specific return dates or colleague names in external replies.

– Limiting details to a simple confirmation of unavailability.

For example, instead of “I’m in Spain until 15 August—please contact Lisa in Accounts,” a better external message would be: “I’m currently unavailable and will respond to your message on my return.”

Internally, it’s fine to include a bit more information, but it should still be concise if possible. The aim is to help colleagues, not advertise an absence to outsiders.

Phishing Attacks Are Timed to Catch You Off Guard

When staff are away from their usual routines, especially while travelling, they’re more likely to fall for phishing attempts. This is no coincidence and cyber criminals actively exploit periods like school holidays and summer breaks to increase attacks.

The UK Government’s Cyber Security Breaches Survey 2025 found that phishing remains the most common form of cyber attack, accounting for 85 per cent of incidents reported by businesses and 86 per cent by charities. The same survey estimated over 8.5 million cyber crimes against UK businesses in the past 12 months, of which more than 7.8 million were phishing-related.

These attacks often take the form of fake hotel confirmations, airline refund requests, or urgent security notifications that appear to come from well-known brands. A mobile phone notification while queuing at an airport (while distracted and in an unfamiliar environment) is far more likely to be clicked than an email during a typical office day.

To mitigate this, staff should be reminded before going away that:

– No reputable company will ask for login credentials by email or SMS.

– Links and attachments in unexpected travel-related messages should never be clicked without verifying the source.

– Suspicious messages can be reported to report@phishing.gov.uk or via text to 7726.

Tip: Pre-holiday reminders and short cyber awareness refreshers can make a significant difference, especially when phishing attempts are designed to catch people off guard.

Travel Exposes Devices to Extra Risks

It’s worth noting that business travellers face a different set of risks, especially if they’re logging into company systems abroad. For example, public Wi-Fi networks, hotel business centres, and even charging stations can all pose threats if used without care.

With this in mind, the NCSC recommends several precautions that should now be considered standard practice:

– Keep all software and security updates current before leaving.

– Use strong passwords and enable multi-factor authentication.

– Turn off Bluetooth and Wi-Fi auto-connect settings to avoid rogue connections.

– Only use secure, private Wi-Fi or a trusted mobile hotspot.

– Avoid public USB charging points, which can be used to extract data or install malware.

– Use a Virtual Private Network (VPN) when connecting to work resources remotely.

VPNs encrypt your internet traffic, reducing the risk of interception. Without one, using a free Wi-Fi network at an airport or hotel could expose email, login credentials or confidential files to anyone else on the same network.

Temporary Devices

Some organisations now go a step further, issuing temporary devices for international work trips. These are pre-configured with minimal data and set up to be wiped remotely in case of theft or compromise.

What Happens If a Device Is Lost or Stolen?

According to recent government data, over 2,000 official laptops, phones and tablets were reported lost or stolen in a single year. While most were encrypted, even a brief exposure could result in leaked credentials, compromised apps, or unauthorised access to systems if multi-factor authentication is not used.

In the private sector, the same risks apply. For example, if a staff member leaves a work phone in a taxi or hotel room, the consequences can range from inconvenience to data breach, particularly if no backup exists or if the device grants access to sensitive files without additional controls.

The most effective countermeasure is a layered one:

– Encrypted storage.

– Device lockout after inactivity.

– Remote tracking and wipe capability.

– Strict separation between personal and work accounts.

Employees should also know who to notify if a device is lost, and how quickly a compromise can escalate if not handled swiftly.

Oversharing on Social Media Can Be Just as Dangerous

Even without phishing or device theft, sharing too much about travel plans can lead to risk. A well-timed LinkedIn post saying “off to Greece for two weeks” may seem harmless, but it confirms a person’s absence to anyone watching, including cyber criminals looking to exploit out-of-office gaps.

Posting photos of boarding passes, passports or hotel locations on social media can also invite fraud. In recent cases, scammers have used partial passport information combined with leaked credentials to access travel accounts or generate fraudulent documents.

The safest approach is to wait until you’re home before sharing holiday updates publicly, or to keep posts strictly limited to private audiences.

Clear Expectations and Small Changes Make a Big Difference

While cyber threats grow more sophisticated each year, the most effective defences are still relatively simple:

– Don’t overshare in auto-replies.

– Watch for phishing while on the move.

– Keep devices locked down and updated.

– Avoid unnecessary risks abroad.

UK businesses can do more to embed these habits into everyday culture, especially during peak holiday months. Even if a full training session isn’t feasible, a short checklist or pre-departure reminder can reduce exposure significantly.

What Does This Mean For Your Business?

The risks outlined here are not theoretical. They reflect common oversights that continue to be exploited by attackers year after year. For UK businesses, especially those with remote or hybrid teams, these issues matter because they affect every department. A single out-of-office reply or a misjudged click while abroad can lead to reputational damage, operational disruption or financial loss.

The increase in phishing attacks during holiday periods shows how cyber criminals adapt their tactics to match human behaviour. The fact that over 85 per cent of cyber incidents reported by UK businesses now involve phishing should act as a clear warning. Routine travel or time off is not a reason to lower defences. In many cases, it is when organisations are most vulnerable.

All this creates a strong case for better awareness, firmer controls around device use while travelling and more consistent defaults for things like out-of-office replies and remote access. These measures are not expensive. In most cases, they come down to clear expectations, simple communications and a few minutes of preparation that can prevent much bigger problems later.

For individual employees, these risks are not always obvious, particularly for those in non-technical roles. That is why basic guidance on travel-related security should be part of the normal rhythm of work. Whether someone is attending an overseas meeting or switching off for a well-earned break, the same principles apply.

This also matters for HR, compliance and communications teams. The way cover is arranged, the wording of public messages and the tone of internal guidance all play a part in how securely staff behave while away. Responsibility for this does not sit with IT alone.

In the end, protecting an organisation during staff holidays is not about large-scale policy overhauls. It is about recognising that certain periods carry higher risk and planning accordingly. When simple habits like cautious messaging, phishing awareness and secure device use are embedded into daily working culture, the chances of a successful attack drop significantly. Also, in a landscape where cyber criminals only need one opening, those habits are what keep your business protected.

Tech Tip – How To Tighten Your Facebook Privacy in Just a Few Clicks

Your Facebook public profile info can be scraped for scams, impersonation or phishing, but with a few quick settings, you can lock things down and stay in control. Here’s how:

Limit Who Can See Your Posts:

– Go to ‘Settings & Privacy > Settings > Privacy’.

– Under ‘Your Activity’, set ‘Who can see your future posts?’ to ‘Friends’.

Review All Your Posts and Things You’re Tagged In:

– In Privacy Settings, click on ‘Limit Past Posts’ to change past public posts to friends only.

– Enable ‘Timeline Review’ and ‘Tag Review’ under ‘Profile and Tagging Settings’ to review posts you’re tagged in before they appear on your timeline.

Control Who Can Send You Friend Requests:

– Under ‘How People Find and Contact You’, set ‘Who can send you friend requests?’ to ‘Friends of friends’.

– Restrict Who Can Look You Up Using Your Email or Phone Number:

– Set ‘Who can look you up using the email address/phone number you provided?’ to ‘Friends’ or ‘Only me’.

Prevent Search Engines from Linking to Your Profile:

– Turn off ‘Do you want search engines outside of Facebook to link to your profile?’

Pro-Tip: Regularly review your privacy settings to ensure they reflect your current preferences. Facebook occasionally updates its settings, so it’s good practice to check them periodically.

Tech Insight : UK’s New Cyber Severity Scale

The UK’s Cyber Monitoring Centre (CMC) has now started categorising cyber events using a scale designed to assess the impact and severity of attacks (similar to the Richter scale for earthquakes).

What is the Cyber Monitoring Centre?

The Cyber Monitoring Centre (CMC) is an independent, non-profit organisation founded by the UK’s insurance industry to enhance trust in cyber insurance markets and improve national understanding of digital threats. Officially unveiled at a Royal United Services Institute (RUSI) event on 6 February 2025, the CMC has been operating behind the scenes for a year, refining its methodology before making its system publicly available.

How Does the Cyber Event Severity Scale Work?

The CMC has introduced a five-level categorisation system to rank cyber events based on their severity and financial impact. The scale ranges from one (least severe) to five (most severe), considering two key factors:

1. The proportion of UK-based organisations affected.

2. The overall financial impact of the event.

Only incidents with a potential financial impact exceeding £100 million, affecting multiple organisations, and with sufficient available data will be classified. The CMC will collect insights from polling, technical indicators, and other incident data, all reviewed by a Technical Committee of cyber security experts.

Once categorised, cyber events will be published along with detailed reports that outline the impact, methodology, and response strategies. This information will be freely available to businesses and individuals worldwide.

CMC CEO Will Mayes emphasised the importance of this classification system, stating: “The risk of major cyber events is greater now than at any time in the past as UK organisations have become increasingly reliant on technology. The CMC has the potential to help businesses and individuals better understand the implications of cyber events, mitigate their impact on people’s lives, and improve cyber resilience and response plans.”

The rating system initiative is being spearheaded by a team of cyber security experts and industry leaders, with former National Cyber Security Centre (NCSC) chief Ciaran Martin serving as Chair. Explaining the importance of the CMC’s work, Martin says: “Measuring the severity of incidents has proved very challenging. This could be a huge leap forward. I have no doubt the CMC will improve the way we tackle, learn from, and recover from cyber incidents. If we crack this, and I’m confident that we will, ultimately it could be a huge boost to cyber security efforts, not just here but internationally too.”

Why Is the UK Introducing a Cyber Severity Scale?

The new initiative has been launched in the UK to essentially help measure the severity of cyber threats, thereby (hopefully) bringing much-needed clarity to an ever-evolving digital battleground.

Cyber attacks have become increasingly frequent and damaging. In 2023 alone, the UK suffered over seven million cyber attacks, costing the economy an estimated £27 billion per year. From ransomware crippling hospitals to large-scale data breaches exposing personal and financial information, the need for an organised, systematic approach to assessing cyber threats has never been greater.

Martin has stressed that a standardised metric for cyber event severity has been long overdue, and has highlighted how: “If you get a major incident in a large organisation, the results can be absolutely devastating. Hospitals can be brought to their knees.”

Martin has also noted the fact that because international threat actors, including state-backed groups from Russia and China, are constantly evolving their tactics, the UK must now be better prepared.

How Will This Benefit UK Businesses?

For UK businesses, the introduction of the CMC’s cyber severity scale could be an important step in cyber risk management and its benefits could include:

– Clarity and consistency. Businesses will have an easily understood, objective framework to gauge the severity of cyber incidents and make informed decisions.

– Better risk assessment. Insurers, regulators, and industry leaders will be able to assess cyber risks more effectively, leading to better cyber insurance policies and risk management strategies.

– Faster response times. With categorised reports on cyber incidents, organisations can respond more quickly and appropriately to emerging threats.

– Improved cyber resilience. Detailed incident reports will help organisations refine their cyber security measures and prepare for future attacks.

CMC CEO Will Mayes has also highlighted how the CMC’s work will be supported by a broad range of global cyber security experts, saying: “I would also like to acknowledge the support from a wide range of world-leading experts who have contributed so much time and expertise to help establish the CMC, and continue to provide data and insights during events. Their ongoing support will be vital, and we look forward to adding further expertise to our growing cohort of partners in the months and years ahead.”

Potential Challenges and Drawbacks

Despite its promise, and although it’s still very early days, it should be acknowledged that the CMC’s classification system is not without potential challenges. These include:

– Accuracy and data availability. Since categorisation relies on accurate data collection, incomplete or delayed reporting could affect the reliability of classifications.

– Speed (or lack of it) of assessment. The CMC aims to classify events within 30 days, but in 2025 this timeline may take longer. Delays in categorisation could impact real-time responses.

– The threshold for categorisation. By focusing on incidents causing over £100 million in damage, smaller but still significant attacks may not be classified, potentially leaving some businesses without crucial insights.

– The potential for misinterpretation. While the scale is designed to simplify communication, businesses and the public may misinterpret severity rankings, leading to unnecessary alarm or complacency.

UK Not The First Country To Try It

The UK is not the first nation to attempt a structured approach to cyber threat classification, but the CMC’s initiative represents a more comprehensive framework than many existing models. The US, for instance, has the Cyber Incident Severity Schema, a classification system used by federal agencies, but it does not currently have the public-facing clarity or structured ranking system that the CMC intends to implement.

Other European nations have also been watching the CMC’s developments closely, with cyber security experts suggesting that if successful, this model could be replicated in the EU or even standardised internationally. According to industry insiders, discussions are already taking place regarding cross-border data sharing agreements to strengthen global cyber response strategies.

Some cyber security experts have noted how a universal classification that could be used by all countries would make for a better system and, as the CMC begins classifying real-world incidents, there is potential for the UK to take a leading role in shaping a globally recognised cyber threat severity scale. Such a scale would help both businesses and governments get the data needed to make informed, strategic decisions in the fight against digital threats.

What Does This Mean For Your Business?

The introduction of the CMC’s severity scale could offer a clearer, more structured approach to understanding and responding to cyber threats. As cyber attacks grow in frequency and complexity, businesses, insurers, and policymakers require reliable data to assess risk and improve resilience. The CMC’s initiative looks like it could provide just that, i.e. a structured, transparent framework that could transform how the UK, and potentially the wider world, categorises and responds to major cyber incidents.

However, while the system has some clear benefits, it’s not without its limitations. The reliance on accurate and timely data presents an ongoing challenge, particularly given the complex and often opaque nature of cyber incidents. The CMC’s approach of only classifying large-scale events, while logical for identifying major risks, may also leave some significant but smaller-scale attacks unaccounted for. Also, the speed at which classifications are made will determine how effective the system is in providing real-time insights for businesses and policymakers.

Despite these concerns, the CMC’s work has already garnered some strong backing from cyber security experts and industry leaders, who recognise its potential to standardise risk assessment in a sector where clear benchmarks have long been lacking. The fact that other nations are closely monitoring the UK’s efforts also suggests that this initiative could, in time, help shape a globally recognised classification system, which is something that could prove invaluable in the fight against international cyber threats.

The success of the CMC’s cyber event severity scale will depend on its ability to consistently deliver accurate, timely, and actionable insights. If it achieves this, it has the potential to improve cyber resilience not just for UK businesses but for organisations worldwide. With cyber threats showing no signs of slowing, initiatives like this are going to be increasingly necessary.

Security Stop-Press: GhostGPT AI Chatbot Threat

Cybercriminals are using an AI chatbot called GhostGPT to generate malware, craft phishing emails, and develop exploit code, according to a recent blog post by security firm Abnormal Security.

Unlike mainstream AI tools, GhostGPT has no ethical safeguards, making it a powerful tool for cybercrime.

Available as a Telegram bot, GhostGPT provides instant, uncensored responses and has a strict no-logs policy, making it easy for attackers to use while remaining anonymous. Despite being advertised for “cybersecurity,” it is openly sold on cybercrime forums, with subscriptions starting at $50 per week.

GhostGPT follows a growing trend of AI-powered cybercrime tools, including WormGPT and WolfGPT, which have made attacks more sophisticated and accessible. Security experts warn that by removing ethical restrictions, these chatbots allow criminals to create highly convincing phishing scams, develop malware that evades detection, and exploit software vulnerabilities with minimal effort.

With AI now being used to bypass traditional defences, businesses must adapt their security strategies. Implementing AI-driven threat detection, strengthening email security, and training employees to recognise phishing attempts are essential to mitigating the risks posed by tools like GhostGPT.

Security Stop-Press: TikTok Interference Annuls Romanian Elections

Romania’s Constitutional Court has annulled the first round of its presidential election due to allegations of Russian interference via TikTok.

Far-right candidate Călin Georgescu, a pro-Russian figure, had won with 23 per cent of the vote. Intelligence revealed a sophisticated influence operation involving over 25,000 TikTok accounts, which amplified Georgescu’s campaign, garnering 52 million video views in just four days. TikTok denies any preferential treatment but is under EU scrutiny to provide data on its algorithms and counter-disinformation measures.

Outgoing Prime Minister Marcel Ciolacu supported the annulment as vital for national security, while Georgescu called it a “formalised coup d’état.” The annulment leaves Romania in political limbo, with no set timeline for a new election.

This case highlights the risk of foreign interference via social media. Businesses should bolster cybersecurity, monitor for disinformation, and collaborate with platforms to counter coordinated inauthentic behaviour and protect digital integrity.