A cyber war is being waged and businesses need to batten down the hatches, says top tech expert
20th July 2026
Businesses need to be aware that the rising tempo of cyber attacks during the year so far means the UK is engaged in a full-blown cyber contest against hostile states, a leading technology expert has warned.
Roy Shelton, Group CEO of managed services provider Connectus Business Solutions, says organisations need to treat network security as a board-level concern and not just a risk to be managed.
The warning on increased activity was sounded by the CEO of the National Cyber Security Centre, Richard Horne, during the Royal United Services Institute Annual Security Lecture last month.
The NCSC handled more than 200 “nationally significant” incidents affecting critical UK infrastructure and its supporting ecosystem in the year to May 2026, more than double the 89 recorded the previous year.
Around 75% were believed to be linked to state actors, and significant attacks are estimated to cost the UK economy £14.7 billion, or around 0.5% of GDP.
The Cyber Monitoring Centre estimates that the cyber attack that crippled production at Jaguar Land Rover, which has been linked by some to Russian hackers, had an economic impact valued at £1.9 billion.
The JLR attack cascaded through 5,000 companies, while the combined attacks on M&S and the Co-op are estimated to have cost up to £440 million.
Mr Shelton says automated AI attacks have been driving the spike and that businesses have to regard attacks as an inevitability and not just a risk.
Regulation will be hardened by the government in the Cyber Security and Resilience Bill, which will be phased in over the next couple of years and will see fines for higher tier security lapses increase to £17 million or 4% of global turnover.
“The threat has changed shape this year. AI hasn’t invented new attacks, it has industrialised the old ones,” Mr Shelton said. “Work that used to take a criminal gang weeks now takes hours, and the gap between a flaw becoming public and someone exploiting it is closing fast.
“Too many business leaders still file this under IT. It isn’t an IT problem, it’s a board problem, and the boards that haven’t worked that out are the ones who will find out the hard way.
“Most breaches don’t begin with some dazzling piece of hacking. They begin with a phone call to a help desk, a supplier running weaker controls than yours, or an account that should have been closed years ago. Jaguar Land Rover was attacked once, and five thousand businesses felt it.
“If you can’t name the suppliers whose failure would stop you trading tomorrow, you don’t yet understand your own risk.”
He added: “Stop asking whether you’ll be hit and start asking how fast you can get back up.”
Mr Shelton’s advice to businesses:
- Rehearse the response, don’t just document it. Only about 25% of UK businesses have a formal incident response plan, and only 40% of the most disruptive breaches are reported externally.
- Harden identity and the help desk. Verified call-back or manager approval should be required for any credential or MFA reset; voice alone is no longer proof of identity.
- Map the third parties that can stop you trading. Know which supplier’s outage would halt your operations, and how long you can trade without them.
- Plan to recover without paying. Most UK victims already don’t pay, 57% recovered from backups. Test your restores.
- Get the first 72 hours right, and don’t over-claim. Resist the instinct to say no customer data was affected before you know, Co-op ended up confirming that data belonging to all 6.5 million members had been taken.