Skip to content
Search

Latest Stories

3 steps businesses must take to avoid AI cyberattacks

Ministers warn AI is making cyberattacks faster, cheaper and easier to scale

AI Cyberattacks
3 steps businesses must take to avoid AI cyberattacks, says UK government
iStock
  • AI cyber capabilities are now doubling every four months, government-backed tests show.
  • New models can find vulnerabilities and generate exploit code without human expertise.
  • Businesses of all sizes, not just critical sectors, are now potential targets.

The UK government has warned that artificial intelligence is rapidly lowering the barrier to cyberattacks, allowing systems to identify software weaknesses and generate exploit code at a speed and scale not seen before. In a joint letter issued on April 15, 2026, ministers said the shift marks a move away from attacks led by a small pool of highly skilled criminals to a landscape where advanced tools can replicate those capabilities. The warning follows testing of Anthropic’s Mythos model, which officials said is “substantially more capable” at cyber offence than earlier systems, as quoted in the letter.

Data from the government-backed AI Security Institute suggests the pace of change is accelerating sharply, with frontier AI cyber capabilities now doubling roughly every four months, compared to every eight months earlier. Ministers also pointed to parallel developments across the industry as evidence that the shift is not isolated, adding that attackers are expected to target “ordinary companies, of every size, in every sector." Against this backdrop, the government has set out three immediate steps for businesses to strengthen their defences.


Here are the three steps businesses are being urged to follow

1. Treat cyber security as a leadership issue, not just an IT task

The government is asking boards to take direct responsibility for cyber risk, warning that it can no longer be delegated solely to technical teams. Businesses are urged to regularly review cyber threats at board level, adopt frameworks such as the Cyber Governance Code of Practice and ensure clear incident response plans are in place. The letter also highlights the importance of rehearsing responses to major cyber incidents and considering how tools like cyber insurance could support recovery.

2. Fix basic weaknesses and secure Cyber Essentials certification

Despite the rise of advanced AI threats, ministers stress that most successful cyberattacks still exploit simple vulnerabilities such as outdated software, weak passwords and missing data backups. Businesses are encouraged to obtain Cyber Essentials certification, which the government says significantly reduces the likelihood of a damaging cyber incident. Organisations are also advised to apply these standards across their supply chains to avoid weak links that attackers could exploit.

3. Use official guidance and act on early threat warnings

The government is urging businesses to actively follow advice from the National Cyber Security Centre and sign up to its Early Warning Service. This free service provides alerts about potential cyber threats, giving organisations time to respond before incidents escalate. Regulators are also expected to issue sector-specific guidance, reinforcing the need for businesses to stay updated as AI-driven risks continue to evolve.

The letter makes it clear that while AI is accelerating the scale and sophistication of cyber threats, the response is not entirely new. Businesses that act early and strengthen basic defences are likely to be better positioned as these risks grow, while those that delay may find it harder to keep pace with a rapidly changing threat landscape.

More For You

Gautam Adani, the chairman of Adani Group, leads a business empire spanning coal, airports, cement, and media. (Photo: Reuters)

Gautam Adani

Reuters

Gautam Adani and nephew settle US investor fraud case for £13 million

  • Gautam Adani and Sagar Adani have agreed to pay a combined £13 million ($18 million) to settle a US civil fraud lawsuit.
  • US regulators had accused the Adanis of misleading investors during a renewable energy fundraising drive.
  • Reports in the US media suggest the Justice Department may also move to drop related criminal charges.

Indian billionaire Gautam Adani and his nephew Sagar Adani have agreed to pay a combined £13 million ($18 million) to settle a civil fraud lawsuit brought by the US Securities and Exchange Commission over alleged investor deception linked to renewable energy projects.

The proposed settlement, which still requires court approval, would resolve allegations made by the regulator in 2024 that the Adanis misled US investors while raising funds through a bond offering tied to Adani Green Energy.

Keep ReadingShow less