grc-scanSecurity & governance
Data & privacy

Cyber security and governance checks in plain English — grc-scan

Latest briefings

updated 14 Sept 2026 · next Wednesday
PATCH14 Sept 2026· 11 to patch

What to patch now

This week's list is dominated by the tools working behind the scenes on your behalf — remote-support and IT-management software, firewalls and routers, developer platforms — rather than anything you'd notice yourself. - Ask your IT provider or help desk whether they use N-able N-central or ConnectWise ScreenConnect, and whether it's patched. - Running a Citrix, Fortinet or Cisco firewall/VPN, or a MikroTik router? Several fix-by dates have already passed — check today. - If a developer runs GitLab or Artifactory for you, ask when it was last updated — Artifactory's now three weeks running.

  1. 01Adobe Commerce and Magento — a booby-trapped page template can run an attacker's code (CVE-2026-75650)
  2. 02Microsoft Windows — two bugs that hand an attacker who's already in your PC full control (CVE-2026-81963, CVE-2026-85880)
  3. 03N-able N-central — a flaw in the software many IT providers use to manage your computers, no login required (CVE-2026-86218)
read the briefing· 8 more inside
NEWS11 Sept 2026· 9 stories

Cybersecurity news

Nearly everything attacked this week was the management layer — the console, the router, the remote-support tool — and in most cases the patch had existed for weeks or months before criminals started using it. - Ask your IT provider, in writing, what remote-management software they run and when they last updated it. - Inventory every internet-facing device you own with its firmware version and last update date; fill in the blanks. - Install security updates on a schedule, not in response to headlines — and confirm the reboot actually happened.

  1. 01The Software Your IT Provider Uses to Manage Your Computers Was Broken Into Before the Fix Existed
  2. 02A Firewall Management Flaw Disclosed in March Is Now Being Used in Real Attacks
  3. 03A Second Old Flaw Was Quietly Added to the "Actively Exploited" List the Same Week
read the briefing· 6 more inside
FINES9 Sept 2026· 2 cases

ICO fines & breaches

A breach does the most damage weeks after it happens, when the stolen data is finally published and the people in it start getting messages that quote real details back at them. - Keep your own copy of your customer contact list, so you can warn people when a supplier's system is the thing that failed. - Publish one line saying what you will never ask for by email or phone, and brief whoever answers the phone. - Ask your web developer to confirm in writing that no keys or tokens sit in your front-end code.

  1. 01Manchester Airports Group data is now public — 8.8 million people's records published after the ransom was refused
  2. 02Beacon CRM: the whole charity database was taken, and the likely cause was a cloud key left in the website's JavaScript
read the briefing

Reading about a breach — could it happen to you?

Most of these stories start with something visible from the outside — an exposed service, a spoofable domain, weak TLS. Check your own domain in about a minute. Free, nothing intrusive.

run the posture scan