Welcome to the latest edition of our quarterly Fraud and Cyber Newsletter.
As cyber threats continue to grow in scale and sophistication, this edition brings together expert analysis on the risks facing specific sectors, the latest regulatory enforcement and the broader trends shaping the UK's cyber resilience landscape.
We examine the increasing targeting of law firms by cybercriminals exploiting both technological vulnerabilities and human behaviours, and analyse the findings of the Cyber Security Breaches Survey 2026 which reveals persistent weaknesses in governance, board-level oversight and incident preparedness across organisations of all sizes.
We also explore the ICO's decision to fine South Staffordshire Water nearly £1 million following a cyber attack that exposed the personal data of more than 633,000 individuals, reinforcing the regulator's continued willingness to take enforcement action where fundamental security controls are lacking. In a related theme, we consider the lessons from the UK Biobank incident, highlighting that the erosion of public trust can be a more damaging consequence of data misuse than the loss of data itself, and that organisations must look beyond technical compliance to maintain confidence in their data governance.
Turning to the energy sector, we consider why the principle of 'security by design' is essential as the UK accelerates its energy transition, and how the Energy Sector Cyber Security Strategy seeks to embed cyber resilience into new infrastructure from the outset. We also examine the evolving fraud landscape, including the growing prevalence of fraud allegations in civil and commercial disputes and the strategic factors driving this trend, as litigants increasingly use fraud as a framework through which commercial disagreements are pursued and litigated. Finally, as the failure to prevent fraud offence approaches its first anniversary, we consider the early lessons from the Ultra Electronics Deferred Prosecution Agreement (or DPAs) and what it reveals about the likely trajectory of enforcement under the new regime.
In addition, we are pleased to share the second episode of our Tech Talks podcast, featuring a conversation with Matthew Evans of techUK on the role of technology across key sectors and the future of the UK tech industry.
If you have any suggestions or requests for future editions of the Trowers Fraud and Cyber Insight, please get in touch with one of the team.
Click the links below to view our latest insights.
Cyber Security Breaches Survey 2026
The Department for Science, Innovation and Technology's Cyber Security Breaches Survey 2026 suggests that while the overall level of cyber incidents has stabilised, the threat to organisations remains significant. More than four in ten businesses reported experiencing a cyber breach or attack in the past year, with the survey identifying persistent weaknesses in governance, board-level oversight and incident preparedness. Many organisations continue to operate without formal incident response plans, comprehensive risk assessments or cyber insurance, leaving them exposed when incidents occur. The findings reinforce the importance of treating cyber resilience as an organisation-wide responsibility, with greater focus required on governance, planning and supply chain risk management to address an increasingly complex threat environment.
Tech Talks - a conversation with Matthew Evans, techUK
In the second episode of our Tech Talks podcast, Partner Charlotte Clayson is joined by Matthew Evans, COO and Director of Markets at techUK, to discuss his perspective on the role of technology across key sectors, and his insights into the future of the UK tech industry. They explore what first sparked Matthew's interest in the tech sector and how his path led him to techUK, alongside the organisation's role in supporting businesses and driving growth across the UK technology ecosystem. Matthew also shares his insights on the importance of collaboration between industry, government and advisers, the skills future leaders will need to succeed, and the emerging trends shaping the future of technology.
Cyber threats facing law firms: a growing risk landscape
Law firms are increasingly becoming prime targets for cybercriminals due to the volume of highly sensitive client information they hold, and the trust placed in them as custodians of that data. Recent attacks on major international firms continues to demonstrate a shift away from traditional ransomware towards data extortion, with threat actors threatening to publish confidential client information rather than simply encrypting systems. The article highlights how cybercriminals are exploiting both technological vulnerabilities and human behaviour, with AI-enabled phishing attacks becoming increasingly sophisticated and difficult to detect. Against a backdrop of rising regulatory scrutiny and growing client expectations, the key message is that cyber security must be viewed as a core business risk rather than an IT issue, with organisations needing robust access controls, staff training, incident response planning and ongoing testing to remain resilient.
ICO fines South Staffordshire Water nearly £1 million following major cyber-attack
The ICO has fined South Staffordshire Water £963,900 following a significant cyber attack which ultimately resulted in more than 633,000 individuals' personal data being published on the dark web. The attack originated from a successful phishing email and remained undetected for an extended period, exposing shortcomings in security monitoring, vulnerability management, access controls and software maintenance. Although the regulator reduced the financial penalty to reflect the company's cooperation and remedial action, the decision underlines the ICO's continued willingness to take enforcement action where organisations fail to implement appropriate technical and organisational measures. The case serves as a timely reminder that fundamental cyber security controls, including least-privilege access, comprehensive monitoring, regular vulnerability scanning and staff awareness training, remain essential components of effective cyber resilience.
Building security: What ‘Security by Design’ means for the UK’s energy sector
As the UK accelerates its energy transition, this article first published in Energy Manager Magazine examines why cyber security must be embedded into new energy infrastructure from the outset rather than retrofitted after deployment. Drawing on the Energy Sector Cyber Security Strategy published by the Department for Energy Security & Net Zero, Ofgem, the NCSC and the National Energy System Operator, the article explains how the rapid shift towards a more digitised, diverse and interconnected energy system creates inherent vulnerabilities for threat actors to exploit. The Strategy sets out a phased approach, with proposals to introduce baseline cyber resilience requirements for all Ofgem licensees by 2027 and to designate critical suppliers under the Cyber Security and Resilience Bill by 2030. The article also highlights the cultural and structural challenges that must be addressed, including the need for cyber security to be treated as a board-level priority and the current skills gap in delivering a secure and resilient energy transition.
Trust is harder to rebuild than data: lessons from the UK Biobank incident
This article uses the UK Biobank incident, in which de-identified participant data was allegedly advertised for sale online after being misused by authorised users rather than stolen through an external cyberattack, to highlight that the greatest risk arising from data breaches is often the erosion of public trust rather than the loss of data itself. It argues that reassurance about anonymisation and technical compliance is not enough where sensitive health and genetic information is involved, because public confidence depends on the belief that robust safeguards will be maintained throughout a project's lifecycle. The article emphasises that organisations handling valuable personal data must focus not only on regulatory compliance but also on governance, access controls, monitoring and accountability, particularly as the UK moves towards a stricter cyber-resilience framework. The key lesson is that trust is a critical asset in data-driven initiatives and, once damaged, is far more difficult to restore than the data itself.
Why are there so many accusations of fraud in civil disputes?
In this article first published in the Law Society Gazette, we explore the context in which fraud accusations are rising. The article argues that the growing number of fraud allegations in civil litigation is not simply a reflection of rising fraud rates, but also of changing litigation behaviour. While increased fraud in society has made parties more suspicious of unexplained losses or unusual transactions, litigants are also increasingly characterising disputes as fraud claims because doing so can provide strategic advantages, such as access to freezing orders, search orders, broader disclosure and stronger settlement leverage. The article notes that fraud claims now make up a significantly larger proportion of civil disputes and judgments than in previous years, suggesting fraud has become a more common framework through which commercial disagreements are pursued and litigated.
Failure to Prevent Fraud: one year later
As the failure to prevent fraud offence approaches its first anniversary without a reported prosecution, this article examines the Ultra Electronics DPA, approved in May 2026 under the analogous failure to prevent bribery regime, as a practical lens through which the future of the FTPF offence can be understood. The Ultra case demonstrates that enforcement under the 'failure to prevent' model focuses on systemic weaknesses in governance and controls rather than the actions of senior individuals, with liability arising from inadequate procedures regardless of whether wrongdoing can be traced to leadership. The article considers the continued centrality of Deferred Prosecution Agreements as the primary resolution mechanism, the role of corporate cooperation and remediation in shaping enforcement outcomes, and the enduring risk posed by historical conduct in complex, long-running investigations. Taken together, the case offers a blueprint for how the FTPF regime is likely to develop, reinforcing the importance of embedding robust fraud prevention procedures as a core operational and strategic priority.