Company Check : HP Fined Over Government Tender Rigging

HP India has been fined almost 1.39 billion Indian rupees (around £12 million) by India’s Competition Commission after a lengthy investigation concluded that it coordinated with resellers to manipulate bidding in government technology procurement, in one of the most significant competition law cases involving the IT sector in recent years.

What Happened?

The penalties arise from two separate investigations covering personal computing equipment and printer consumables sold through India’s Government e-Marketplace (GeM), the country’s central online procurement platform for public sector purchasing. India’s regulator concluded that HP and a number of authorised resellers worked together in ways that undermined genuine competition during public tenders, resulting in combined penalties of approximately 1.3885 billion rupees.

What Did The Investigation Find?

The larger of the two cases focused on laptops, desktops, workstations, notebooks, point-of-sale systems and related accessories supplied through GeM. The Competition Commission began investigating after HP itself applied for leniency under India’s competition laws, admitting that anti-competitive arrangements had taken place and providing evidence to investigators.

Investigators examined dozens of government tenders before identifying seven major procurements where they found evidence that HP and selected resellers had coordinated their activities. According to the Commission, this coordination included deciding which reseller should have the strongest chance of winning particular contracts, arranging “cover bids” from other partners to create the appearance of competition, influencing bid prices and controlling which resellers received the Manufacturer’s Authorisation Forms (MAFs) needed to participate in tenders.

The Commission concluded that HP was not simply responding to requests from resellers but had become actively involved in facilitating these arrangements.

As the order states: “The coordination amongst HP India’s reseller was accordingly designed to ensure that at least one HP reseller remained present in the final round.”

Evidence relied upon by investigators included internal emails, witness statements, WhatsApp conversations and other communications exchanged between HP employees and reseller organisations.

Why Did It Happen?

The Commission’s findings essentially reveal that the behaviour developed during the transition from India’s older government procurement arrangements to the newer GeM platform.

For example, before GeM was introduced, many resellers had built long-standing relationships with particular government departments. Under the new system, suppliers across India could compete much more easily for the same contracts, increasing price competition and making it harder for established partners to protect their existing business.

According to HP’s own submissions, resellers asked the company to help preserve these legacy customer relationships by limiting competition between HP partners. The requests included restricting which resellers received Manufacturer’s Authorisation Forms (MAFs), allocating particular accounts to preferred partners and facilitating support bids where other resellers would deliberately submit non-competitive quotations.

HP argued that it was attempting to manage commercial pressures created by the new procurement system and that competition from other manufacturers such as Dell, Acer and Lenovo remained strong. It also maintained that any coordination only affected competition between HP resellers rather than competition across the wider market. However, clearly, the Competition Commission wasn’t persuaded by HP’s arguments.

The Second Investigation

Going from bad to worse for HP, alongside the personal systems case, the Commission also investigated HP’s sale of printer consumables, including ink cartridges and toner supplies.

Investigators concluded that similar anti-competitive practices had taken place in government tenders for printing supplies, leading to a further penalty of approximately 119.8 million rupees (about £923,000). Together, the two decisions resulted in total penalties approaching 1.39 billion rupees (about £10.7 million), with additional fines imposed on participating reseller companies and several individuals involved in the conduct.

Although HP received substantial reductions under India’s leniency programme because it voluntarily disclosed the conduct and cooperated throughout the investigation, the regulator still considered the company’s role sufficiently serious to justify one of the largest competition penalties imposed on an IT manufacturer in India.

Why This Matters Beyond India

While the case concerns India’s procurement system, the underlying issues are very relevant to manufacturers and channel partners worldwide.

For example, most technology vendors rely on networks of distributors and authorised resellers. Those relationships naturally involve discussions about pricing, product availability, technical specifications and manufacturer approvals. None of those activities are inherently problematic.

However, the risk arises when those conversations begin influencing who should bid, what prices should be quoted or which partners should deliberately avoid competing. At that point, legitimate channel management can cross into anti-competitive behaviour.

One particularly interesting aspect of the case involves Manufacturer’s Authorisation Forms. These documents exist for good reasons, helping purchasers verify that products are genuine and supported by the manufacturer. However, the Commission found that selectively issuing or withholding those authorisations became one mechanism for controlling competition between resellers rather than simply protecting customers from counterfeit products.

What Does This Mean For Your Business?

For organisations buying technology, the decision serves as a reminder that procurement platforms alone can’t guarantee competitive markets if suppliers coordinate behind the scenes.

For technology manufacturers, distributors and resellers, the message is even clearer. Competition authorities are increasingly willing to examine communications between channel partners in detail, looking beyond formal contracts to understand how bidding decisions are actually made.

Internal emails, messaging platforms and routine commercial discussions can all become evidence if they reveal attempts to coordinate pricing, allocate customers or influence tender outcomes.

Businesses operating partner programmes should therefore ensure that their competition law compliance extends beyond formal policies. Sales teams, account managers and channel partners all need clear guidance on where legitimate commercial co-operation ends and unlawful co-ordination begins, because, as this case demonstrates, the financial and reputational consequences of crossing that line can be substantial.

Tech News : Poland’s Tech Sovereignty Test For Government AI Purchases

Poland will introduce a new “sovereignty test” for major government technology purchases as Prime Minister Donald Tusk warns that growing dependence on foreign digital infrastructure and AI providers has become a strategic national concern.

What Has Been Announced?

Speaking at the European Financial Congress in Sopot, Tusk said Poland would begin assessing significant public-sector technology procurements through a sovereignty lens, while also publishing annual reports tracking the country’s progress towards greater IT independence.

Although the full details of the test have not yet been released, the policy is expected to examine issues such as vendor dependence, control over critical systems, access to data, and the strategic risks associated with relying heavily on a small number of technology suppliers.

Explaining the reasoning behind the move, Tusk said: “At this point, the scale of this dependency, and I’m referring here to the relationship between the state and the digital sphere, has reached such proportions that it must prompt serious economic, institutional, and organisational decisions.”

The announcement represents one of the clearest examples yet of a European government moving beyond discussions about digital sovereignty and beginning to embed those concerns directly into procurement policy.

Why Poland Is Concerned

The policy reflects growing concern across Europe that critical public services increasingly depend on technology platforms, cloud infrastructure, AI systems, and digital services controlled by a relatively small number of foreign companies.

Tusk argued that technological sovereignty should become a strategic objective for Poland, not because the country wants to isolate itself from global technology markets, but because governments need meaningful choice rather than dependence.

According to figures cited by the Polish government, the country’s digital trade deficit has grown from approximately PLN 9 billion in 2016 to around PLN 45 billion in 2025, highlighting the increasing flow of technology spending towards foreign providers.

At the same time, artificial intelligence is creating new forms of dependency. Governments increasingly rely on cloud platforms, AI models, cybersecurity tools, data infrastructure, and software ecosystems that are often developed and controlled outside their own borders.

As AI becomes embedded in healthcare, public administration, education, defence, transport, and critical infrastructure, questions about who owns, controls, and maintains those systems are becoming more politically significant.

Part Of A Wider European Debate

Poland’s announcement reflects a wider debate taking place across Europe about digital sovereignty. For example, for several years, European policymakers have expressed concerns about dependence on both American technology giants and Chinese hardware suppliers. However, the rapid emergence of generative AI has added fresh urgency to those discussions.

Many European leaders now worry that regulation alone may not be enough if the most advanced AI systems, cloud platforms, and digital infrastructure remain concentrated in the hands of a small number of overseas providers.

The challenge is particularly evident in AI, where the most advanced models currently come largely from companies based in the United States. European governments and businesses increasingly face difficult decisions about balancing access to the best available technology against concerns around strategic dependence.

Poland has already taken steps in this direction. For example, earlier this year, the government restricted certain Chinese technologies from sensitive military environments and has increased support for domestic AI initiatives, including the development of Polish-language AI models.

What Could The Sovereignty Test Mean In Practice?

Although the final framework remains unclear, the test is unlikely to operate as a simple ban on foreign technology suppliers.

Instead, it appears more likely that government departments will be required to assess whether major procurements create excessive dependence on a single vendor or introduce risks around control, resilience, security, or long-term flexibility.

For example, authorities may need to consider whether critical systems can be migrated elsewhere if required, whether data remains under appropriate control, and whether alternative suppliers exist.

Such considerations are already becoming common in discussions around cloud computing, cybersecurity platforms, AI systems, telecommunications infrastructure, and public-sector software procurement.

The broader objective appears to be ensuring that Poland retains meaningful strategic choice rather than finding itself locked into technologies that become difficult or impossible to replace.

What Does This Mean For Your Business?

For businesses, Poland’s announcement highlights how technology procurement is increasingly becoming a strategic and geopolitical issue rather than simply a commercial one.

Cost, functionality, and performance remain important, but governments and organisations are paying growing attention to questions of control, resilience, supplier concentration, and long-term dependency.

The policy also reflects a wider change in how AI is being viewed. Rather than treating AI purely as a productivity tool, governments are increasingly seeing access to AI infrastructure and capabilities as a matter of economic competitiveness and national security.

Whether other countries follow Poland’s lead remains to be seen. However, the introduction of a sovereignty test suggests that future technology purchasing decisions may increasingly involve questions about who controls the technology, where it is hosted, and how dependent organisations become on the companies that provide it.

Featured Article : UK Government Offers Free AI Training for All UK Adults

UK adults are being offered free, government-benchmarked AI training for work as part of a national programme to upskill 10 million people by 2030 and address low confidence and adoption of artificial intelligence across the economy.

UK Government Expands Free AI Training Programme

The UK government has announced a major expansion of its national AI skills programme, making free AI training available to every adult in the country through the AI Skills Boost initiative. Led by the Department for Science, Innovation and Technology in partnership with Skills England, the programme is being positioned as a response to growing concerns about workforce readiness as artificial intelligence becomes more widely embedded across workplaces.

10 Million People By 2030

The expansion builds on a commitment made in June 2025, when government and industry partners first set out plans to train 7.5 million workers in AI-related skills. The latest announcement increases that ambition to 10 million people by the end of the decade, equivalent to nearly a third of the UK workforce, and frames the initiative as the largest targeted training programme since the creation of the Open University.

Who Can Access The Training And How?

The training is open to all UK adults and is delivered online through the government’s AI Skills Hub, a free platform where users can create a learning profile and follow a structured learning journey. No prior technical knowledge is required, and the courses are designed to be accessible alongside existing work or caring commitments.

Courses vary in length, with some taking under 20 minutes to complete, while others run for several hours. Participation is voluntary, and learners can choose which courses to take based on their role, interests or level of confidence with digital tools. The government has said that NHS staff and local government employees will be among the first groups actively encouraged to take part, supported by their employers and representative bodies.

What Do The Courses Teach?

The focus of the training is on practical workplace use rather than technical development of AI systems. For example, courses concentrate on helping workers use commonly available AI tools safely and effectively as part of everyday tasks.

This includes learning how to write and refine prompts for generative AI tools, use AI to draft text and create content, automate routine administrative processes, and interpret simple AI dashboards to identify trends. The training also covers responsible use, including understanding the risks, limitations and potential consequences of using AI at work.

All approved courses have been assessed against Skills England’s AI foundation skills for work benchmark, which sets out a nationally defined baseline for AI literacy in the workplace. Anyone who completes a course that meets the benchmark receives a government-backed virtual AI foundations badge, which can be used on CVs and professional profiles to demonstrate recognised skills.

Why The Government Is Prioritising AI Skills

The expansion of AI training reflects evidence that AI adoption in the UK remains uneven and that confidence among workers is low. For example, research published alongside the announcement found that only 21 per cent of UK workers currently feel confident using AI in their jobs. Business adoption data suggests that as of mid-2025 only around one in six UK businesses were using AI at all, with much lower uptake among small and micro businesses.

Government analysis suggests that improving adoption and confidence could deliver significant productivity gains. Ministers estimate that wider use of AI could unlock up to £140 billion in additional annual economic output by reducing time spent on routine tasks and enabling workers to focus on higher value activity.

Technology Secretary Liz Kendall highlighted how the training is intended to ensure the benefits of AI are widely shared, saying, “We want AI to work for Britain, and that means ensuring Britons can work with AI,” adding that, “Change is inevitable, but the consequences of change are not. We will protect people from the risks of AI while ensuring everyone can share in its benefits.”

The Role Of Industry And Public Sector Partners

Delivery of the programme relies on a large partnership between government, industry and public sector organisations. For example, founding partners including Accenture, Amazon, Google, IBM, Microsoft, Salesforce, Sage and SAS have been joined by a wider group that now includes the NHS, British Chambers of Commerce, Federation of Small Businesses, Institute of Directors, Local Government Association, Cisco, Cognizant, Multiverse, Pax8 and techUK.

Industry partners are responsible for developing many of the courses hosted on the AI Skills Hub, while representative organisations are expected to promote the training to their members and workforces. The involvement of the NHS, the UK’s largest employer, is intended to support large scale uptake in the public sector and reinforce the relevance of AI skills beyond technology focused roles.

Phil Smith, Chair of Skills England, has said the benchmark was designed to provide clarity for both learners and employers about what AI skills are needed for work. He said the digital badges awarded on completion would provide clear recognition of learning and help set consistent standards for AI upskilling across the economy.

Funding And Wider Skills Measures

The training offer forms part of a broader package of measures aimed at preparing the UK workforce for AI-driven change. For example, the government has announced £27 million in funding for a new TechLocal scheme, part of the wider £187 million TechFirst programme, which will support local employers and education providers to develop AI-related jobs, professional practice courses, graduate traineeships and work experience opportunities.

Alongside this, the government has launched applications for the Spärck AI Scholarship, which will fund up to 100 master’s students in AI and STEM subjects at nine UK universities. The scholarships will cover tuition and living costs while providing access to industry placements and mentoring.

A new AI and the Future of Work Unit has also been established to monitor the economic and labour market impact of AI. Supported by an expert panel drawn from business, academia and trade unions, the unit is intended to provide evidence-based advice on when policy interventions may be needed to support workers and communities as roles and skills evolve.

The Implications For Employers And Businesses

For employers, particularly small and medium-sized enterprises, the programme offers a low-cost route to building basic AI capability across teams. Business groups including the Federation of Small Businesses and the British Chambers of Commerce have welcomed the initiative, citing uncertainty among employers about what AI skills staff need and how to support responsible adoption.

Large employers involved in the programme have pointed to their own experience of rolling out AI tools internally, noting that productivity gains depend heavily on shared understanding and confidence rather than access to technology alone. The government argues that a nationally recognised benchmark will help employers set clearer expectations and reduce the risk of misuse or unrealistic assumptions about AI.

Criticisms And Questions

Despite broad support, the initiative has attracted criticism from some policy groups and professional bodies. For example, the Institute for Public Policy Research has warned that short, tool-focused courses risk oversimplifying what it means to be prepared for AI-enabled work. Critics argue that effective adaptation also requires judgement, critical thinking, leadership and organisational change, which cannot be delivered through brief online modules alone.

There are also questions about how impact will be measured over time. For example, while the government has committed to reaching 10 million workers by 2030, it has not yet set out detailed plans for tracking completion rates, long-term skills retention or productivity outcomes across different sectors. Concerns have also been raised about the mix of free and subsidised courses on the AI Skills Hub and whether this could cause confusion about access.

The government has said the AI Skills Boost programme will continue to evolve, with new courses, partners and benchmarks added as workplace use of AI develops and expectations around skills mature.

What Does This Mean For Your Business?

The expansion of free AI training marks a clear attempt by government to address one of the most persistent barriers to AI adoption in the UK, which is a lack of confidence and shared understanding rather than access to technology itself. By setting a national benchmark and backing it with widely accessible courses, the programme establishes a common baseline for what it means to use AI responsibly at work, something many employers and workers have so far lacked.

For UK businesses, particularly small and medium-sized firms, the initiative could lower the practical and financial threshold for experimenting with AI tools in everyday operations. A clearer definition of core skills may help employers move beyond uncertainty and begin integrating AI in measured, realistic ways, while also supporting better internal governance and expectations around use. Larger organisations and public sector bodies may benefit from a more consistent skills foundation across teams, reducing fragmentation and uneven uptake.

For workers, the availability of short, recognised courses offers a route to building confidence without committing to formal retraining or specialist qualifications. The emphasis on practical use, risk awareness and responsible adoption reflects an acknowledgement that AI will increasingly sit alongside existing roles rather than replace them outright in the near term.

At a national level, the programme aligns skills policy more closely with the government’s wider ambitions on productivity, economic growth and technological adoption. Whether it delivers lasting impact will depend on uptake, the quality of training, and how effectively it connects to broader workforce development and organisational change. The creation of the AI and the Future of Work Unit suggests an awareness that skills alone will not resolve all challenges, but it also places responsibility on government, employers and industry partners to ensure the transition is managed in a way that supports workers and delivers tangible economic benefit.

Featured Article : Government Plans Major Expansion Of Facial Recognition

The government has set out plans to expand the use of facial recognition and other biometrics across UK policing, describing it as the biggest breakthrough for catching criminals since DNA matching.

A National Strategy For Biometrics

The Home Office has launched a ten week consultation to establish a new legal framework covering all police use of facial recognition and biometric technologies. This would replace the current mix of case law and guidance with a single, structured system that applies consistently across forces.

The plan includes creating a dedicated regulator overseeing facial recognition, fingerprints and emerging biometric tools. The Home Office says a single body would provide clarity and help forces apply safeguards more confidently. It also proposes a national facial matching service, allowing officers to run searches against millions of custody images through one central system.

Breakthrough

Launching the consultation, Crime and Policing Minister Sarah Jones said, “Facial recognition is the biggest breakthrough for catching criminals since DNA matching,” adding, “We will expand its use so that forces can put more criminals behind bars and tackle crime in their communities.” Her view reflects the government’s belief that existing deployments have already demonstrated clear operational value, particularly in identifying violent offenders.

Why Now?

The push for expansion comes as police forces face increasing pressure to track offenders across regions and to manage high volumes of video supplied by retailers, businesses and members of the public. Also, recent cases of prisoners being released in error, or disappearing before arrest, have highlighted the difficulty of locating suspects quickly without technological support.

Public Tolerance For Certain Uses

Government research published alongside the consultation appears to suggest high public tolerance for certain uses. For example, according to the government’s figures, 97 per cent of respondents said retrospective facial recognition is at least sometimes acceptable, while 88 per cent said the same about live facial recognition for locating suspects. Ministers may see this as support for building a clearer framework, although rights groups argue that acceptability is dependent on strict safeguards and transparency.

The Need For Oversight

That said, independent accuracy testing has reinforced the need for stronger oversight. For example, the National Physical Laboratory found that earlier systems used in UK policing produced significantly higher false alert rates for Black and Asian people. The Home Office now acknowledges these disparities, noting that updated systems and reviews have since been introduced. Even so, the findings have shaped calls for clearer legal boundaries before expansion proceeds.

When These Changes Might Take Effect

The consultation runs through early 2026, after which ministers will draft legislation for parliamentary scrutiny. The Home Office estimates that introducing a new legal regime, establishing the regulator and deploying the national facial matching service will take around two years. During that period, existing deployments will continue under current guidance.

Police forces already using live facial recognition, including the Metropolitan Police and South Wales Police, will continue targeted deployments. Trials using mobile facial recognition vans across multiple forces are also expected to continue, and the national facial matching service is scheduled for testing in 2026.

How The Technology Works Across UK Forces Today

Police currently rely on three distinct facial recognition tools, each supporting different operational needs, which are:

1. Retrospective facial recognition. Used during investigations, this compares still images from CCTV, doorbell cameras, mobile footage or social media against custody images. It is the most widely used form, and police say it speeds up identification in cases where investigators have a clear image but no confirmed identity.

2. Live facial recognition. These systems scan faces in real time as people pass a camera. The software compares each face to a watchlist of individuals wanted for specific offences or subject to court conditions. When a possible match arises, officers decide whether to stop the person. Deployments are usually short, targeted and focused on high footfall areas.

3. Operator initiated facial recognition. This mobile app allows officers to check identity during encounters by comparing a photo to custody images, avoiding unnecessary trips to a station solely for identification.

Police leaders say these tools allow forces to locate wanted individuals more efficiently. Lindsey Chiswick, the National Police Chiefs’ Council lead for facial recognition, says the technology “makes officers more effective and delivers more arrests than would otherwise be possible”, adding that “public trust is vital, and we want to build on that by listening to people’s views”.

Legal And Ethical Issues

Legal concerns have followed facial recognition since its earliest deployments, and several landmark rulings continue to shape how police use the technology. For example, back in 2020, a Court of Appeal ruling in the Ed Bridges case remains the most significant legal challenge to date. In this case, the court found that South Wales Police’s early use of live facial recognition breached privacy rights because of inadequate safeguards, incomplete assessments and insufficient checks on whether the system discriminated against particular groups.

Also, the Equality and Human Rights Commission has criticised aspects of earlier Metropolitan Police deployments, saying forces must demonstrate necessity and proportionality each time. The Information Commissioner’s Office has also warned forces to ensure accuracy and justify the retention of custody images belonging to people never convicted of an offence.

Accuracy Problems

Accuracy remains central to the ethical debate. For example, the National Physical Laboratory found that in one system previously used operationally, Asian faces were wrongly flagged around four per cent of the time and Black faces around five and a half per cent, compared with around 0.04 per cent for white faces. For Black women, false alerts rose to nearly ten per cent. These figures show how demographic disparities can emerge in real deployments and highlight the importance of system configuration.

Rights groups warn that these issues could lead to wrongful stops or reinforce existing inequalities. They also argue that routine scanning in public spaces risks creating a sense of constant surveillance that may influence how people move or gather. Liberty has said it is “disappointed” that expansion is being planned before the risks are fully resolved, while Big Brother Watch has urged a pause during the consultation.

Support Strong From Police

It’s worth noting here that, perhaps not surprisingly, support within policing remains strong. For example, former counter terror policing lead Neil Basu says live facial recognition is “a massive step forward for law enforcement, a digital 21st century step change in the tradition of fingerprint and DNA technology”, while noting that it “will still require proper legal safeguards and oversight by the surveillance commissioner”. Police forces repeatedly stress that every alert is reviewed by an officer rather than acted on automatically.

Industry Supports Structured Rollout

Industry organisations also appear to support a structured rollout. For example, Sue Daley, Director of Tech and Innovation at techUK, says “regulation clarity, certainty and consistency on how this technology will be used will be paramount to establish trust and long term public support”. The technology sector argues that clear rules will help build confidence both inside and outside policing.

Charities

Charities focused on vulnerable people have also highlighted some potential benefits. For example, Susannah Drury of Missing People says facial recognition “could help to ensure more missing people are found, protecting people from serious harm”, though she also stresses the need to examine ethical implications before expanding use.

That said, civil liberties groups continue to call for stronger limits, arguing that wider deployment risks normalising biometric scanning in everyday spaces unless strict rules are imposed regarding watchlists, retention and operational necessity.

Areas For Further Debate

The proposals raise questions that will remain live throughout the consultation period. For example, these include how forces will define and maintain watchlists, how the new regulator will enforce safeguards, what thresholds will apply before live facial recognition can be deployed, and how demographic accuracy will be monitored over time. Businesses that operate high footfall environments, such as shopping centres and transport hubs, are also likely to face questions about how their video systems might interact with police requests as adoption increases.

What Does This Mean For Your Business?

It seems that, following this announcement from the government, policymakers now face a moment where practical policing needs, public confidence and legal safeguards must be aligned in a way that has not been achieved before. The consultation sets out an ambition for national consistency and clearer rules, although the evidence presented across this debate shows that accuracy, oversight and transparency will determine whether expansion strengthens trust or undermines it. The range of views from policing, civil liberties groups, industry and charities illustrates how differently this technology is experienced, and why the government will need to resolve issues that sit well beyond technical capability alone.

The implications extend into policing culture, investigative practice and public space management, which will all look different if facial recognition becomes a mainstream tool. Forces anticipate faster identifications, clearer procedures and more reliable ways to locate individuals who pose a genuine risk. Civil society groups, by contrast, point to the potential for overreach unless firm limits are embedded in law. These competing priorities will shape how the regulator operates and how the Home Office interprets proportionality in real deployments.

Businesses also sit at the centre of this discussion because they capture and provide a significant volume of the video footage used in retrospective searches. Retailers, transport hubs and major venues may face new expectations about how they store, secure and share images, and these responsibilities may grow as facial matching becomes more accurate and more widely used. Clearer rules could help organisations understand how to cooperate with investigations without exposing themselves to unnecessary compliance risks, particularly around data protection and equality duties.

The wider public interest lies in how these decisions affect everyday life. Public attitudes will depend on whether safeguards are visible, whether wrongful identifications are prevented, and whether live deployments remain tightly focused rather than becoming a routine feature of public spaces. A national framework could provide that reassurance if it genuinely addresses the concerns raised during testing and legal review. The coming months will show how far the government is prepared to go in defining those boundaries and whether the final model satisfies the mix of operational urgency and ethical caution that has defined this debate so far.

News : Government to CEOs: “Print Backups Of Cyber Plans”

The UK government has written to chief executives across the country urging them to keep physical, offline copies of their cyber contingency and business continuity plans, as the number of severe cyber attacks continues to rise.

Why The Government Is Acting Now

The move follows a sharp increase in what officials call “nationally significant” cyber incidents. In its latest annual review, the National Cyber Security Centre (NCSC) reported handling 429 cyber incidents over the past year, of which 204 were classed as nationally significant, more than double the previous year’s total of 89. Eighteen of those were categorised as “highly significant”, marking a 50 per cent rise.

These figures highlight a growing problem for UK organisations. Attacks on major companies have recently disrupted production lines, logistics operations, and supply chains. The government says this shows how cyber threats now pose not only a security risk but also a direct threat to jobs and the wider economy.

Cyber Resilience Should Be A Board Level Priority

Technology Secretary Liz Kendall, Chancellor Rachel Reeves, Business Secretary Peter Kyle, Security Minister Dan Jarvis, and the heads of both the NCSC and the National Crime Agency have jointly signed letters to business leaders, including all FTSE 350 companies. The message is that cyber resilience must become a board-level priority, and organisations must be ready to operate without IT systems for extended periods if necessary.

What The Letter Tells CEOs To Do

The letter from the government essentially makes three key points/recommendations to company leaders, which are:

1. It says they should treat cyber resilience as a governance issue and align with the government’s new Cyber Governance Code of Practice.

2. It recommends that all organisations sign up to the NCSC’s Early Warning service, which alerts firms to potential vulnerabilities or active threats.

3. It advises implementing the Cyber Essentials scheme, both within their own operations and throughout their supply chains.

Crucially, the letter also stresses the importance of keeping copies of critical plans “accessible offline or in hard copy”, including details of how to communicate and coordinate during an IT failure. This is actually part of a wider government effort to embed what the NCSC calls “resilience engineering”, which can basically be described as an approach that focuses on anticipating, absorbing, recovering from, and adapting to cyber attacks.

The Logic Behind Paper Copies

Although it may sound strange in what is increasingly a digital world, the advice to hold printed plans is intended to be a practical response to one of the key realities of modern cyber incidents. For example, when ransomware or destructive malware locks or wipes digital systems, even backups stored in the cloud can become inaccessible. In those situations, an organisation needs something it can rely on immediately, i.e., contact lists, instructions, and decision trees that are available without power, network access, or authentication.

The NCSC’s annual review explains that organisations should have “plans for how they would continue to operate without their IT, and rebuild that IT at pace, were an attack to get through.” Storing that information offline ensures that teams can still coordinate a response even if email, messaging, or identity systems have been taken down.

From Prevention To Resilience

The government’s letter reflects a wider change in strategy from simply preventing attacks to building the ability to withstand them. For example, the NCSC now encourages what it calls resilience engineering, i.e., designing systems and processes that can recover quickly after disruption.

That includes maintaining immutable backups that cannot be encrypted or tampered with, segmenting networks to prevent attacks spreading, testing recovery procedures, and running scenario exercises that simulate complete loss of IT. This approach assumes that no organisation can be completely immune to attack, so readiness and rapid recovery become essential.

Warnings From The NCSC

In its latest report, the NCSC said cyber security had become “a matter of business survival and national resilience.” The agency noted that half the incidents it managed in the past year met the top three severity categories, which cover impacts to government, essential services, or large sections of the public and economy.

The NCSC is urging organisations to make themselves as hard a target as possible, warning that hesitation in improving resilience leaves them exposed. It is also promoting its Cyber Action Toolkit for smaller firms, which provides simple step-by-step measures to improve security and response capabilities.

Support From The Security Industry

Cybersecurity professionals appear to have broadly supported the government’s message, saying it reflects lessons learned from recent incidents where businesses lost access to key systems for weeks. Industry experts have described the advice as practical rather than symbolic, noting that while printed plans may seem old-fashioned, they can be vital when digital tools fail.

The concept of treating cyber security like health and safety, something every employee understands as part of everyday working life, has gained traction in recent years. The government’s call reinforces this by urging boards to build resilience into core operations rather than treating it as an optional add-on.

Preparation

For larger companies, the message essentially means that cyber risk must now be reported and discussed at board level, with directors accountable for ensuring readiness. That includes confirming who would take charge in an emergency, how to communicate without email, and where physical copies of key documents are stored.

For smaller firms, the focus is more on preparation. For example, the NCSC’s free services, including the Early Warning system and Cyber Essentials certification, are designed to reduce the burden of building basic protection. Having physical backup plans does not replace digital defences, but it ensures that even in the worst-case scenario, there is a clear process for keeping the business running.

The government also highlights the benefits of requiring suppliers to meet similar standards, as supply chain weaknesses can often be exploited by attackers. Making resilience part of procurement policies helps reduce the risk of disruption spreading between organisations.

The Advantage of Offline Contingency Plans

A key advantage of offline contingency plans is that they allow teams to act immediately when systems go down. For example, staff can access emergency contacts, escalate issues, and follow recovery steps without waiting for IT access to return. In critical industries, such as healthcare, manufacturing, and logistics, those minutes or hours can make the difference between a temporary disruption and a complete operational shutdown.

Organisations that follow the NCSC’s guidance can also expect tangible benefits. The agency notes that companies meeting Cyber Essentials standards are significantly less likely to make cyber insurance claims. Better planning also tends to reduce recovery times and financial losses.

Challenges And Concerns

Although there is broad support for the government’s recommendations, there are (inevitably) some practical and logistical challenges. For example, paper copies need to be updated regularly to reflect new systems and staff changes, and they must be stored securely to prevent sensitive information from being accessed or lost. Some companies have also expressed concern about the administrative burden of maintaining both digital and physical documentation.

Others question whether a focus on manual fallbacks could distract from investment in prevention. However, security experts argue that resilience and defence are complementary, i.e., both are necessary, and neither alone is sufficient.

For small and medium-sized enterprises, limited resources remain a concern. Even with free government tools, implementing and maintaining robust resilience measures can take time and expertise. Nonetheless, the government’s stance is that preparedness is no longer optional, given the rising frequency and severity of attacks.

The Bigger Picture

Ministers have said that further steps will follow, including continued promotion of the Cyber Governance Code of Practice and potential new requirements under the forthcoming Cyber Security and Resilience Bill.

The letters sent this month highlight a clear change in tone, to one where cyber resilience is no longer being treated as an IT issue, but as a matter of national and economic security. For UK businesses, the message is simply that if the screens go dark, the organisation should still be able to function, and that begins with having the right plans on paper.

What Does This Mean For Your Business?

The government’s intervention could be said to mark a notable moment in how cyber risk is now being framed, i.e., as a question of continuity and national resilience rather than purely technical defence. The decision to write directly to company chiefs shows the extent to which cyber attacks have moved from the IT department to the boardroom, becoming an operational, financial, and reputational issue that demands visible leadership. The emphasis on hardcopy plans might appear unusual in a digital economy, yet it underlines an uncomfortable truth, which is that digital systems are not invincible and that planning for their failure is now a core part of responsible management.

For UK businesses, this change could prove both challenging and beneficial. For example, it requires time, training, and discipline to maintain offline contingency plans and rehearse manual processes, but it also forces a clearer understanding of dependencies and critical operations. Those already investing in resilience may find themselves better protected from both financial losses and prolonged service disruption. Smaller firms, meanwhile, stand to gain from the free support and practical guidance now being promoted by the NCSC, which aims to bring consistent standards across the economy.

The wider implications reach beyond business. For government and regulators, the campaign is part of a long-term effort to build systemic strength in the face of increasingly complex attacks. For insurers and investors, it offers a signal that resilience planning is becoming a measurable component of good governance. For the public, it reinforces the expectation that essential services, from food distribution to healthcare, should be able to keep operating even when technology fails.

The government’s advice accepts that no cyber defence is perfect, but that preparedness can dramatically limit the impact. By putting resilience on paper as well as on screen, the UK’s leadership is attempting to bridge the gap between digital ambition and practical survivability. If businesses take that message seriously, the result may be a more stable and dependable digital economy, and one that can withstand not just the next attack, but the inevitable disruptions still to come.

Tech Insight : Government Trial Shows No CoPilot Productivity Boost

A three-month evaluation of Microsoft’s M365 Copilot AI assistant in a key UK department found mixed results and few measurable efficiency gains.

Mixed Results From Promising Tech

The UK Department for Business and Trade (DBT) has published the results of a detailed trial of Microsoft’s M365 Copilot AI assistant, revealing no definitive evidence that the tool leads to higher productivity. Despite users reporting moderate satisfaction and perceived time savings, the trial concluded that the AI often performed inconsistently across tasks, and in some cases, reduced output quality.

The trial, which ran from October to December 2024, involved 1,000 Copilot licences distributed across the department, with roughly 300 participants consenting to monitored usage. The pilot aimed to assess the AI’s real-world impact on common digital tasks using Microsoft 365 apps such as Word, Outlook, Teams, Excel and PowerPoint.

Microsoft markets Copilot as an AI productivity enhancer that can summarise meetings, draft emails, generate slides, analyse data, and more. However, the DBT report suggests the real-world impact was far more nuanced than the promotional material might suggest.

Where Copilot Worked And Where It Didn’t

The government study found that users were most satisfied when using Copilot to perform simpler, text-based tasks, e.g., summarising meetings, writing emails, and condensing written communications.

In the trial, these tasks consistently showed time savings and improved clarity when compared with work from non-Copilot users. Email writing was slightly faster and judged higher in quality and accuracy.

However, performance in more complex tasks was notably weaker. For example, data analysis in Excel and visual content creation in PowerPoint suffered, with AI-generated outputs often requiring correction or falling short of expectations. PowerPoint slide creation was seven minutes faster on average, but to a lower standard of quality. In Excel, AI users took longer and produced less accurate results than their non-AI counterparts.

The report concluded: “We did not find robust evidence to suggest that time savings are leading to improved productivity. However, this was not a key aim of the evaluation, and therefore, limited data was collected to identify if time savings have led to productivity gains.”

Light Usage of Copilot

The study also revealed relatively light usage patterns. According to the M365 Copilot dashboard, the average user triggered just 1.14 Copilot actions per working day across the 63-day pilot.

Word, Outlook and Teams saw the highest engagement, but more specialised tools such as Excel, PowerPoint, Loop and OneNote saw very low uptake, i.e., less than 7 percent of users activated Copilot in Excel or PowerPoint on any given day. Loop and OneNote usage was negligible.

These numbers raise questions about whether the value justifies the cost. For example, UK commercial Copilot licences currently range from £4.90 to £18.10 per user per month. For large departments or enterprises, these costs could escalate rapidly, especially if many users engage with the tool only sporadically.

User Attitudes and AI Limitations

While 72 percent of participants were “satisfied or very satisfied” with Copilot, it seems that qualitative interviews suggested that much of this enthusiasm came from the novelty or perceived time saved on repetitive admin tasks. In some cases, staff used their saved time to take training courses or enjoy longer breaks, rather than focusing on higher-value work.

Interestingly, a significant number of participants (22 percent) reported witnessing hallucinations (AI-generated inaccuracies or fabrications). Another 11 percent were unsure, highlighting the still-fragile trust in GenAI tools in professional settings.

Adoption also varied across teams, often influenced by management attitudes. Some line managers actively encouraged use, while others created a “frosty” culture around AI assistance, which in turn impacted engagement.

Microsoft and Its Competitors

For Microsoft, the report is clearly a mixed result. The company has heavily invested in integrating Copilot across its core product suite and has made productivity gains a central part of its pitch. But in the DBT trial, the return on investment appears questionable.

Critics say that the AI’s strengths in low-complexity tasks are well documented, but the promise of broad-based productivity enhancement still feels premature.

A recent MIT survey cited in the DBT report found that 95 percent of companies investing in generative AI tools (including M365 Copilot) had little tangible benefit to show for it. With corporate spending on GenAI already topping $40 billion, pressure is growing for vendors to demonstrate real ROI.

The findings may also embolden competitors such as Google, Zoho, or even open-source productivity platforms. For now, Copilot’s core strength appears to lie in routine, text-heavy admin support. In more complex tasks requiring judgement or accuracy, it remains inconsistent.

As DBT continues to analyse the environmental and cost impacts of Copilot, Microsoft may need to further refine how its AI interacts with different apps and workflows, or risk a broader slowdown in enterprise adoption.

What Does This Mean For Your Business?

The DBT trial showed that M365 Copilot could save time on routine admin, but may not provide any meaningful productivity gains across a department. For UK businesses considering using the tool (or using it already), this raises some serious questions about cost-effectiveness, especially where licences are purchased at scale but only lightly used. With Microsoft positioning Copilot as a flagship product, the pressure to deliver clear, measurable value will only grow.

Usage data from the trial suggests that even in a controlled, well-supported environment, AI tools are far from being embedded into daily workflows. Inconsistent performance in more complex tasks, combined with ongoing concerns about hallucinations, points to a maturity gap that will be difficult to ignore. Competitors offering simpler or more focused AI products may now find space to challenge Microsoft’s all-in-one approach, particularly in areas where users need speed and accuracy over generalised support.

Company Check – New UK Law Could Hit IT Firms With £100K-a-Day Fines

The UK government has unveiled sweeping new cyber legislation that could see organisations hit with fines of up to £100,000 (per day!) if they fail to respond to threats in time – a move that dramatically raises the stakes for IT providers, critical service operators, plus their supply chains.

Tough New Rules Aimed at Critical Infrastructure and the Tech Supply Chain

The draft Cyber Security and Resilience (CSR) Bill, formally outlined this week by technology secretary Peter Kyle, seems to be setting out a more aggressive approach to cyber regulation in response to what ministers describe as “unprecedented threats” to the UK’s digital and physical infrastructure.

Crucially, the bill expands the scope of current regulations and will bring managed service providers (MSPs), IT suppliers, and potentially datacentre operators into the same regulatory framework as public utilities and emergency services. This means that for the first time, commercial tech firms (up to 1,000 of them by current estimates) could be legally obliged to meet strict cybersecurity standards or face financial penalties.

“Economic growth is the cornerstone of our Plan for Change,” said Kyle, “And ensuring the security of the vital services which will deliver that growth is non-negotiable.”

Three Core Pillars – and a Sharp Set of Teeth!

The new bill is built on three pillars. First, widening the scope of the UK’s existing Network and Information Systems (NIS) regulations to include more types of organisations. Second, giving regulators stronger powers to enforce those rules and third, allowing government to rapidly update the rules in response to new and emerging cyber threats.

What’s new (and raising a few eyebrows) is the addition of discretionary government powers to issue binding cyber directives in real-time. For example, if an in-scope organisation receives a formal order to patch a vulnerability or improve cyber defences in response to an active threat and fails to comply, it could face daily fines of up to £100,000, or 10% of turnover, whichever is higher.

The message, therefore, appears to be that falling short isn’t just risky but could be ruinously expensive.

Why Supply Chain Security Is Now Front and Centre

The bill changes how cyber risk is perceived at the national level. For example, instead of focusing solely on headline-grabbing ransomware events or attacks on high-profile utilities, the government now appears to be turning its attention to the digital supply chain, i.e. the vast network of IT support firms, software providers, and cloud service operators that underpin the UK economy.

For example, the Cloud Hopper espionage campaign, which targeted MSPs to indirectly infiltrate governments and corporations, is a cautionary tale of how supply chain vulnerabilities can be weaponised at scale. Likewise, the recent breach of the Ministry of Defence’s payroll system showed how even indirect routes into sensitive data can have real-world consequences.

The UK’s National Cyber Security Centre (NCSC) is backing the approach, and as NCSC CEO Richard Horne says: “The Cyber Security and Resilience Bill is a landmark moment,” adding that “It will improve the cyber defences of the critical services on which we rely every day, such as water, power and healthcare.”

Datacentres and the Next Phase of CNI Regulation

The government is also strongly considering bringing datacentre operators into the bill’s remit, a step it hinted at last year when these facilities were designated as critical national infrastructure (CNI).

If passed, this could affect more than 180 UK-based datacentres and over 60 operators, according to industry figures. While exact compliance requirements haven’t yet been defined, it’s expected that these facilities will be subject to the same incident reporting rules and real-time intervention powers as other in-scope entities.

What’s more, ministers are exploring the use of AI tools to help detect and respond to threats inside these physical and virtual infrastructure hubs.

Mandatory Incident Reporting Tightens Timelines

Another key change is a tightening of mandatory reporting timelines. Organisations in scope of the CSR Bill will need to notify regulators and the NCSC of significant incidents within 24 hours – faster than the 72-hour window required by both the EU’s NIS2 directive and the US’s CIRCIA.

A full report must follow within 72 hours, creating a dual-stage reporting process that places UK organisations under one of the most stringent regulatory regimes in the world.

As technology secretary Peter Kyle says: “This is not just red tape,” but rather “It’s about making sure we know, quickly, when something serious is happening – and being able to act fast.”

Why This Isn’t a ‘One and Done’ Job

Legal experts and cyber risk consultants are warning that the scale of the challenge posed by the new rules is significant, i.e. not just in terms of cost, but also the time and effort required. For example, even well-resourced organisations could find the process of aligning legacy infrastructure with modern cyber resilience standards a long and complex task.

The key point that many are making is that cyber security is not something that can be addressed once and then forgotten. With threats constantly evolving, businesses will need to build ongoing investment and regular system upgrades into their operations. The burden, therefore, isn’t going to be just technical, but will also demand sustained leadership focus and cultural change across entire workforces. In other words, achieving compliance in this case is going to be a continuous journey.

Statutory Powers and Strategic Priorities

As well as giving regulators sharper enforcement tools, the bill proposes that the government publish a unified Statement of Strategic Priorities (updated every three to five years) to guide the approach of different regulators. This aims to bring consistency and clarity to enforcement across sectors, ensuring that energy, healthcare, and IT providers all face comparable expectations.

The government would also be granted the power to issue emergency directions to organisations where needed. This could prove vital in responding to fast-moving attacks, such as zero-day exploits or geopolitical cyber events.

Rising Threats, Rising Costs

The need for faster, tougher intervention isn’t theoretical. In 2023, attacks on UK utility firms surged by 586 per cent, according to reinsurance firm Chaucer. The NCSC dealt with 89 nationally significant incidents (up from 62 the previous year) including 12 so serious they required COBR (Cabinet Office Briefing Rooms) meetings.

Notably, one of the most damaging incidents of last year (i.e. the ransomware attack on NHS blood testing partner Synnovis) cost the NHS an estimated £32 million! Analysts have suggested that a well-coordinated attack on the energy grid in southeast England could cost the UK economy up to £49 billion!

In light of this, the CSR Bill is not just about compliance, but is also about protecting national prosperity.

What Does This Mean For Your Business?

The details of the Cyber Security and Resilience Bill seem to show that the intention is to move things from reactive firefighting to proactive, enforceable standards. For UK businesses, particularly those in the technology supply chain, the message is that cybersecurity isn’t simply optional, nor is it simply an IT issue. It is now a board-level priority with legal and financial consequences attached.

While some organisations, especially larger providers, may already have mature systems in place, many will find that aligning with the new expectations demands more than just a policy refresh. Compliance will mean revisiting internal processes, investing in tools and training, and developing the ability to respond quickly and transparently to incidents. Smaller IT firms, regional MSPs, and niche datacentre operators, who may not have considered themselves part of critical national infrastructure until now, are likely to face the steepest learning curve.

The government’s aim appears to be to ensure the resilience of the UK’s digital backbone, and it is using both carrot and stick to get there. On one hand, businesses are being offered access to NCSC resources and support frameworks like Cyber Essentials. On the other, they face heavy penalties if they fail to take action when directed. Regulators, too, will be expected to step up, with clearer powers and more tools to enforce consistent, effective oversight across all sectors.

For regulators, IT service providers, and businesses that rely on outsourced digital infrastructure, the implications are far-reaching. In the short term, there may be uncertainty over exactly how these rules will be applied and interpreted, especially as the list of in-scope organisations grows. But in the long term, the bill signals a new era in which resilience and responsiveness are the benchmark for doing business in a connected economy.

The stakes are high but, looking on the positive side, so is the opportunity to build a more secure, digitally confident UK. With attacks becoming more frequent, more sophisticated, and more costly, the government is hoping that strong, enforceable rules are the best way to safeguard both national infrastructure and future economic growth. For those now falling under the scope of this legislation, the clock has started ticking.

Security Stop-Press: UK Government Proposes Ransomware Payment Ban

The UK government is consulting on plans to ban ransomware payments by public sector bodies and critical national infrastructure (CNI) to disrupt the financial model underpinning cybercrime.

The proposals also include mandatory reporting of ransomware attacks and measures to block payments to criminal groups, aiming to reduce the threat and support law enforcement investigations.

Ransomware is the most serious cybercrime threat to the UK, with attacks on organisations like the NHS and Royal Mail causing widespread disruption and recovery costs. Security Minister Dan Jarvis highlighted the urgency of action, noting $1 billion was paid globally to ransomware groups in 2023.

Banning payments would make public organisations less attractive targets, while mandatory reporting would provide intelligence to help disrupt criminal networks. Penalties for non-compliance, such as fines or leadership bans, are also being considered to ensure adherence.

This initiative is part of a wider strategy to strengthen the UK’s cyber resilience, complementing global efforts like the disruption of the LockBit network and sanctions against major ransomware groups.

Businesses are advised to adopt strong cybersecurity measures, including frameworks like Cyber Essentials, regular data backups, and tested incident response plans, to mitigate the risk and impact of ransomware attacks.