Security Roundup September 2026

Security Watch

Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants.

BH Consulting launch BH Haven – a new service for SMEs

We are delighted to announce the launch of BH Haven, a new service from BH Consulting providing straightforward cybersecurity solutions designed for SMEs.

Cybersecurity, data protection, AI and regulatory requirements are becoming increasingly complex, but managing them doesn’t have to be.

BH Haven makes it simpler.

Designed with SMEs in mind, BH Haven brings together practical cybersecurity expertise and AI-enabled support to help businesses manage cyber risk, protect their data, navigate compliance requirements and build greater resilience.

Backed by the expertise of BH Consulting, BH Haven gives SMEs access to trusted support without the complexity of building specialist capabilities in-house.

Straightforward cybersecurity. Expert support. Built for SMEs.

Discover BH Haven here: https://bhhaven.com/

Is your cyber resilience plan ready for the real world?

Embedding resilience is about more than checking that backups work. One of the best ways to test recovery plans is to carry out tabletop exercises that make the experience of a cybersecurity incident or a data breach real for leaders and senior management. Use them to establish roles and responsibilities, and uncover any possible gaps in information gathering, decision making, or in stakeholder communication. The worst time to plan for a crisis is when you’re in one. Be sure you’re ready, across the organisation. For more details, call +353 1 440 4065 or email info@bhconsulting.ie.

SANS updates incident response to adapt to changing circumstances

SANS Institute has published a practical framework for security teams managing real-world incidents. “Dynamic Incident Response” is an update to its incident response process, intended as a replacement for earlier models like ‘prepare, identify, contain, eradicate, recover’ that were built for simpler times. Joshua Wright, one of the authors, argues the updated framework is needed because “new findings, shifting priorities, and active attackers make response anything but linear”. For example, an incident response team might be working on containing a breach on a single host, when evidence emerges that multiple systems are compromised, affecting several business units.

The update introduces DAIR, a model built around verification, triage, and iterative scoping steps, that allows responders to adapt as new evidence emerges “instead of forcing an incident into a sequence it never agreed to follow”. It includes contributions on ransomware, cloud, and operational technology, along with AI-accelerated response, MCP and agentic workflows. Weighing in at a hefty 720 pages, it’s free to read, share, and adapt. Download a copy here.

Data Protection and privacy roundup: Google GDPR fine; DPC dives into AI; health wearables not so smart with privacy 

The Data Protection Commission (DPC) has fined Google Ireland €403 million for breaches of European information privacy laws related to the tech giant’s processing of its users’ location history and data. In a statement, DPC deputy commissioner Graham Doyle said Google users may have been “unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data.” The alleged infringements happened between May 2018 and February 2020. The regulator has given Google six months to comply; some reports suggest the company may appeal elements of the decision.

Separately, the regulator has also published an AI Insights Report (PDF), garnered from its supervision of AI products and services from 2021 to 2025. It’s intended as both a guideline for data controllers and a record of the DPC’s actions in regulating emerging technologies.

In international news, the Electronic Frontier Foundation has found various fitness trackers and health monitoring devices lack privacy protections. As many as 40 per cent of US citizens have at least one such smart device, but “few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health data,” the group said. The BBC carried a good report of how one app’s settings affected women’s privacy in particular.

France has taken a tough stance, with a new law that bans unsolicited telemarketing calls. Now, businesses must have consumers’ consent before contacting them. In the UK, 52 per cent of children would try to bypass any age verification checks when accessing online services, and 41 per cent have tried to get around parental monitoring controls. The results come from a survey of over 4,000 children and their parents by the UK Information Commissioner’s Office.

NCSC produces guidelines on compliance with EU Cyber Resilience Act

The National Cyber Security Centre (NCSC) has officially launched new national guidelines to support manufacturers in complying with the EU Cyber Resilience Act (CRA). The guidance coincided with the mandatory reporting obligations under Article 14 which began on 11 September, more than a year ahead of full technical product compliance rules that take effect on 11 December next year. The CRA is often described as the ‘CE mark’ for cybersecurity hardware and software, and is intended to enforce secure-by-design principles.

Under the CRA, manufacturers of products with digital elements, including connected hardware and software, will be obliged to report actively exploited vulnerabilities and severe security incidents. The NCSC’s supports outline practical details on reporting thresholds, required documentation, and notification procedures. The website is accessible at NCSC: Cyber Resilience Act – Reporting Obligations and it includes links to European Commission and ENISA resources, along with the NCSC’s own guidance on CRA reporting obligations.

Links we liked

“Bet on people.” Securing AI is human work, argues SANS’ James Lyne. MORE

“The asbestos of IT.” Adrian Sanabria’s great description for old protocols. MORE

How cyber decoys can strengthen detection and response. MORE

The wide geographical spread of Irish cybersecurity companies. MORE

Assessing security vendors at this year’s Black Hat conference. MORE

TrendAI maps the cybercrime economy targeting critical infrastructure. MORE

Glassbox checks how identifiable your web browser is to outside trackers. MORE

Inside a scam factory: the latest podcast from cybercrime reporter Geoff White. MORE

The BBC’s Joe Tidy takes us inside the fallout from the FBI’s data breach. MORE

As attacks on OT escalate, the UK NCSC steps in with guidance. MORE

Have you signed up to our monthly newsletter? Every month we send out the latest cybersecurity and data protection news, trends and advice from around the globe.

Sign up here

Why get in touch with BH Consulting

BH Consulting is a trusted, independent cybersecurity and data protection consultancy with over 20 years of experience. Whether you need expert guidance on compliance, risk management, or security strategy, our team delivers practical, vendor-neutral advice tailored to your needs.

Let’s start a conversation about securing your business.

Respect in Security Pledge logo

Areas of interest*