ICAEW.com works better with JavaScript enabled.

Cyber roundup: the risk of falling behind

Author: ICAEW Insights

Published: 30 Jul 2026

Cyber threats are evolving rapidly. July’s round-up explores how agentic AI, state-backed actors and quantum computing continue to raise the stakes for organisations.

Key takeaways:

  • OpenAI agent cyber incident: OpenAI tested the cyber capabilities of agents built on GPT 5.6 Sol, which broke free of their restrictions and hacked open-source AI company Hugging Face.
  • Quantum computing and post-quantum cryptography: As quantum computing advances in breaking standard RSA encryption, businesses must transition to post-quantum cryptography to protect long-term encrypted data.
  • Cyber Essentials certification guidance: The UK government is encouraging businesses of all sizes to use the Cyber Essentials framework to help protect themselves from cyber threat actors.

AI agents cause more trouble

In June 2026, we covered the release of Anthropic’s Claude Fable 5, a version of Mythos described as potentially the most powerful model ever developed. Just days later, it was withdrawn from public access following safety concerns about its ability to identify and exploit software vulnerabilities.

The White House has since intervened with another LLM release, this time asking OpenAI to slow the release of its new model amid safety concerns. As a result, OpenAI’s release of GPT 5.6 will only be shared with a small group of partners first.

These concerns are not unfounded. In July 2026, OpenAI revealed that during a security test designed to measure the cyber capabilities of agents using models, including GPT 5.6 Sol, the agents broke out of safeguards and launched an autonomous attack on Hugging Face, a large hub for sharing AI models.

While the testing is understood to have taken place in a security sandbox, the agents were able to attack the sandbox itself, identifying a vulnerability that allowed them to escape its restrictions.

OpenAI is investigating the incident and says it is strengthening protections for future training and evaluations. It also identified the need for model security and safety to keep pace with rapidly advancing capabilities. The company confirmed it will be focusing on enhancing containment and evaluation practices throughout model development.

This incident serves as a warning that organisations should review and strengthen their cyber security posture, while recognising that autonomous tools such as AI agents may not always behave as expected.

As agentic AI becomes more sophisticated and widely available, the guardrails governing its use must also evolve, with safeguards tailored to how AI interprets and acts on information, as covered in guidance published in May by cyber security agencies from countries including the UK.

AI is threatening national security

The threat from AI extends beyond organisations. AI is changing how cyber-attacks are carried out, increasing their scale, speed and risk at a national level. However, AI also provides opportunities for enhanced detection and prevention of cyber-attacks.

In response, GCHQ announced this month that the National Cyber Security Centre (NCSC) and the Department for Science, Innovation and Technology are developing Cyber Shield, a blueprint for national-scale, collaborative agentic cyber defence. Cyber Shield aims to use the most advanced AI technologies, including agentic AI, to identify, reduce and resolve national cyber risk.

This wider national security focus is also reflected in a new NCSC advisory urging critical infrastructure organisations to strengthen their defences against Russian intelligence-backed cyber activity

The advisory warns that cyber actors are exploiting vulnerable routers and opportunistically targeting critical national infrastructure networks globally. It follows new sanctions from the UK and EU against individuals and entities linked to destructive cyber operations, including bad actors based in Russia.

The NCSC has advised organisations operating in national infrastructure to obtain Cyber Essentials certification, a government-backed scheme. Organisations can also use the updated Cyber Assessment Framework to assess security maturity, address vulnerabilities and strengthen resilience against growing threats.

Quantum is a new future threat

A study published by a Google Quantum AI researcher in 2025 suggested that RSA encryption, a widely used standard for securing online data, could be cracked in under a week by a quantum computer. This would require fewer than one million qubits, or quantum bits, which are the fundamental units of information in quantum computing. This is 20 times fewer qubits than estimated in 2019, highlighting the need to reassess the urgency of deploying post-quantum cryptography (PQC).

PQC is the strongest mitigation against the threat that quantum computers pose to traditional encryption and cryptography. PQC algorithms are designed to replace today’s vulnerable cryptography algorithms.

In December 2025, the NCSC, along with others, hosted the first UK government and industry workshop on PQC migration. Three key themes emerged from the discussion, which were shared publicly in early July 2026:

  1. PQC should be treated as a business risk and resilience priority.
  2. Quantum readiness depends on the readiness of an organisation’s supply chain and suppliers.
  3. PQC migration is complex and requires expertise across a wide range of areas.

The NCSC is strongly encouraging anyone with the responsibility for cryptography and security in their organisations to continue planning for PQC migration.

Building cyber resilience

The Cyber Resilience Pledge launched early in July, with more than 60 signatories from a wide range of industries across the UK. The voluntary pledge is aimed at medium and large organisations but is open to all. It asks signatories to take three concrete steps to improve their cyber security:

  1. Making cyber security a board-level responsibility.
  2. Registering for the NCSC’s free Early Warning service.
  3. Taking a risk-based approach to requiring the government-backed Cyber Essentials certification across their supply chain.

The NCSC said that these three actions are practical steps that can improve organisational resilience and, if widely adopted, could strengthen resilience across the wider economy.

To further support a wider range of organisations, the NCSC has expanded Cyber Essentials with an alternative route for larger organisations with complex architectures. In those cases, a purely prescriptive approach may limit rather than improve security outcomes.

Cyber Essentials Pathways provides greater flexibility, allowing organisations that do not fit the standard Cyber Essentials model to demonstrate equivalent protection. The NCSC is now opening Pathways to more organisations and testing how it operates within the existing Cyber Essentials ecosystem.

For organisations with limited in-house expertise, NCSC-assured Cyber Advisors are offering free consultations to support small and medium-sized organisations looking to adopt Cyber Essentials.

AI workshop for practice

ICAEW is hosting a practical, interactive full-day event designed to help professionals in practice move beyond AI awareness and into real‑world application.

Middle-aged white man studying laptop screen and taking notes
Have something to share?

Get in touch with your cyber stories.

Latest technology insights

Recommended content

Resources
Keep up-to-date with tech issues and developments, including artificial intelligence (AI), blockchain, big data, and cyber security.
Technology

Keep up-to-date with tech issues and developments, including artificial intelligence (AI), blockchain, big data, and cyber security.

Read more
e-learning
 Promo image of laptop for Gen AI accelerator programme
GenAI Accelerator

Gain the skills to harness the power of GenAI with ICAEW's flexible, bite-sized online learning programme. Learn how to transform the way you work in a way that suits you.

Find out more Enrol
ICAEW support
A person holding  a tablet device displaying various graphs
Training and events

Browse upcoming and on-demand ICAEW events and webinars focused on making the most of the latest technologies.

Events and webinars CPD courses and more
Open AddCPD icon