Security Roundup August 2026

Security Watch

Curated advice, guidance, learning and trends in cybersecurity and privacy, as chosen by our consultants.

Sound the AI-larm

This summer, thermometers weren’t the only thing soaring: levels of hype and fearmongering around AI and cybercrime similarly set temperatures rising. In July, AI agents operating with OpenAI cyber models broke out of a training environment to hack Hugging Face, an open-source AI platform for testing and sharing software tools. Cue industry figures sounding the alarm, even if the reality is more complicated, as Computer Weekly reported. Add this to Anthropic’s launch of Mythos earlier this year and it seemed like all those dire warnings were coming true.

But a new paper on AI and ransomware from the Royal United Services Institute casts doubt on whether cybercriminals will deploy AI at scale to unleash a ‘vulnageddon’ as some have speculated. Will Lyne and Jamie MacColl argue that industry predictions fail to take account of how cybercriminals think. They write: “The history of modern cybercrime demonstrates two things. First, that cybercriminal behaviour has been driven more by innovation in business models than technical capabilities. Second, that cybercriminals tend to innovate when they have to, not simply because a new kind of technology becomes available.” Or to sum it up more crudely: “if it ain’t broke, don’t fix it”. In a similar vein, Prof Ciaran Martin argues in the Economist (paywall) that fears of an AI armageddon are “overdone”. BH Consulting CEO Brian Honan’s op-ed for Help Net Security notes that the biggest risk for boards and security leaders is being distracted by scary headlines. “They should not confuse automation with accountability, nor allow the excitement surrounding AI to distract them from building resilient organisations based on proven cybersecurity fundamentals,” he writes.

Meanwhile Ireland’s National Cyber Security Centre is providing resources to support the secure use of AI in the public sector. NCSC: Secure AI brings together existing guidance with practical control sets, aligned to the Cyber Fundamentals (CyFun) framework. The resources include an AI cybersecurity risk assessment and guidelines, with CyFun mapping and a project tool due for launch soon.

MEET DPO OBLIGATIONS WITHOUT THE OVERHEADS

Many organisations need to appoint a full-time independent data protection officer (DPO) to meet their GDPR obligations. But it’s the classic Catch-22: that individual needs to have broad experience and expertise, and those qualities are difficult and expensive to recruit and retain. Many groups struggle to fill the post from in-house resources. An outsourced DPO from BH Consulting offers subject matter expertise, provided on demand, so it’s cost-effective and tailored to your needs. Talk to us today.

Data protection and privacy roundup: omnibus obligations, cookie crunch

The EU’s AI Omnibus came into force on 27 July, featuring changes aimed at simplifying the EU AI Act and giving organisations more time to get ready for parts of the full regime. The following week, transparency obligations under Article 50 of the Act took effect. As Euro News noted, these obligations apply to everyday users, not just big tech companies. Providers must now inform individuals when they are interacting directly with an AI system. AI-generated or manipulated content must also be marked in a machine-readable format. For example, Anthropic said its future Claude models will include a watermark signifying AI-generated text, in line with the AI Act. There are also disclosure obligations for providers around deepfakes, emotion-recognition and biometric-categorisation systems, and AI-generated material on matters of public interest.

Meanwhile efforts to reduce cookie banners have hit the buffers amid competing interests of consumers, publishers and privacy advocates. Germany’s data regulator issued six recommendations including replacing cookie banners with a centralised European system.

The European Data Protection Board has called for a clear legal basis for sharing confidential information efficiently between regulators operating in different areas of EU law. Interesting side note: the board said the issue is more pressing due to complex complaints, including those driven by AI. That harks back to a theme of the DPC’s annual report where AI emerged as a cause of rising numbers of cases. Separately, the board also published draft guidelines on anonymisation for public consultation, with feedback open until 30 October. It’s the first guidance on the issue in over ten years.

Former Data Protection Commissioner Helen Dixon has spoken to the Law Society Gazette about her time at the regulator and how meetings with EU partners sometimes became “politicised”.

Two-thirds of Irish businesses suffered a cyber attack in the last year

Two-thirds of Irish businesses experienced at least one cyber attack in the past 12 months. Three out of 10 companies had to pay legal costs as a result, while over one in five (22 per cent) incurred fines from regulators. Nearly a third lost revenue following a security incident (29 per cent), and almost one-third (32 per cent) were unable to serve customers due to downtime that followed.

The data comes from a poll of 250 businesses in Ireland, carried out by the Centre for Economics and Business Research with Gallagher, an insurance brokerage. The findings reflect a significant escalation in cyber threats facing Irish firms, said Michael Cunningham, Head of Financial Lines at Gallagher. “The frequency, severity and intensity of cyber attacks has increased in recent years and our research reflects that.”

Links we liked

SANS’ cheat sheet for building LLMs to use in red team exercises. MORE

Test your skills with a quiz to hack an AI agent using prompt injections. MORE

Cheap evaluations could distort risk decisions, UK AI Security Institute warns. MORE

Microsoft lifts the lid on Windows updates, aka ‘Patch Tuesday’. MORE

Reading between the lines of a cyber insurance policy MORE

Jane Frankland checks assumptions about cyber insurance. MORE

How thieves broke into a data centre for a multi-million heist. MORE

One single text message led to a stolen digital life. MORE

Have your say on the certification of managed services in the EU. MORE

Paolo Balboni’s podcast looks at data flows and AI cybersecurity. MORE

Have you signed up to our monthly newsletter? Every month we send out the latest cybersecurity and data protection news, trends and advice from around the globe.

Sign up here

Why get in touch with BH Consulting

BH Consulting is a trusted, independent cybersecurity and data protection consultancy with over 20 years of experience. Whether you need expert guidance on compliance, risk management, or security strategy, our team delivers practical, vendor-neutral advice tailored to your needs.

Let’s start a conversation about securing your business.

Respect in Security Pledge logo

Areas of interest*