Cyber security threats are becoming increasingly difficult for UK businesses to ignore.
September 2026 highlighted just how quickly a cyber incident can move from a technical problem to a serious operational disruption.
From attacks affecting NHS supply chains to critical vulnerabilities being exploited within hours of patches being released, last month provided some important lessons for businesses of every size.
For organisations relying on cloud platforms, third-party suppliers, remote access and connected technology, cyber security can no longer be treated as something that sits solely with the IT team. It is a business continuity issue.
Here are some of the key cyber security developments from September 2026 and what UK businesses can learn from them.
1. Cyber Attacks Can Disrupt Businesses That Were Never Directly Attacked
One of the most significant incidents involved medical technology manufacturer Boston Scientific.
A cyber attack disrupted the company's internal systems, manufacturing, order processing and global distribution. The disruption subsequently affected NHS Supply Chain deliveries of medical products and required special arrangements for urgent procedures. Manufacturing and distribution were largely restored by 11 September.
The important lesson is that your organisation does not necessarily need to be the target of a cyber attack to experience disruption.
If a critical supplier suffers an outage, your own operations could quickly be affected.
What can businesses do?
Start by identifying your critical suppliers and understanding the technology and services your business depends on.
Ask yourself:
- Which suppliers are essential to our day-to-day operations?
- What would happen if one of them was unavailable for several days?
- Do we have alternative suppliers or workarounds?
- Have we tested our business continuity plans?
Cyber security and business continuity need to work together.
2. Your Third-Party Applications Could Become a Route Into Your Business
Another incident highlighted the risks associated with third-party software integrations.
Attackers compromised credentials belonging to two third-party BigCommerce applications and used them to access customer information across several online retailers. UK retailer Master of Malt confirmed that customer names, email addresses, phone numbers and delivery addresses were exposed. BigCommerce itself was not breached.
This demonstrates an important point: your security perimeter extends beyond the systems you directly control.
Businesses increasingly connect applications to platforms such as Microsoft 365, CRM systems, ecommerce platforms and other cloud services.
Every integration potentially creates another access point that needs to be secured.
What can businesses do?
Review the applications and integrations connected to your key business systems.
Remove applications that are no longer required and regularly review the permissions granted to those that remain.
Third-party applications should receive the same security scrutiny as internal user accounts.
3. Critical Vulnerabilities Are Being Exploited Incredibly Quickly
September also demonstrated the growing importance of rapid patch management.
A critical WordPress vulnerability, CVE-2026-87902, was followed by malicious activity less than five hours after the fix was released. The vulnerability had a CVSS score of 9.2 and could allow an unauthenticated attacker to execute code remotely in certain configurations.
The message for businesses is clear: installing security updates cannot simply be a monthly task that gets added to the IT team's to-do list.
Some vulnerabilities need to be addressed immediately.
For organisations running websites, applications or other internet-facing systems, the time between a vulnerability being disclosed and attackers attempting to exploit it can be extremely short.
4. Microsoft Addressed 966 Vulnerabilities in September
Microsoft's September Patch Tuesday addressed 966 vulnerabilities, including 105 rated Critical.
Two zero-day vulnerabilities were already being actively exploited, while more than 250 vulnerabilities could enable remote code execution.
For businesses, this highlights the scale of modern vulnerability management.
It is not always practical to treat every security update in exactly the same way. Organisations need to understand which vulnerabilities present the greatest risk and prioritise accordingly.
Effective patch management should consider:
- Whether a vulnerability is actively being exploited
- Whether the affected system is exposed to the internet
- The importance of the system to your business
- The potential impact of exploitation
- How quickly a patch can safely be deployed
The goal should be to move from simply installing updates to actively managing cyber risk.
5. Operational Technology Is Becoming a Bigger Target
The UK's National Cyber Security Centre (NCSC) also warned of increased targeting of operational technology (OT).
Operational technology includes systems used to control physical processes and production. The NCSC highlighted internet-exposed systems, legacy connections, weak credentials and poorly secured edge devices as areas of concern.
This matters because an attack against OT can have consequences that go far beyond stolen data.
A successful attack could potentially disrupt physical processes, production environments or essential services.
Businesses therefore need to understand exactly what technology is connected to their networks and whether any systems are unnecessarily exposed to the internet.
Businesses should consider:
- Identifying internet-facing OT systems
- Removing unnecessary direct exposure
- Changing default or weak credentials
- Segmenting networks
- Backing up critical configurations
- Monitoring systems for suspicious activity
You cannot protect technology that you do not know exists.
6. Zero-Day Vulnerabilities Remain a Major Concern
September also saw the exploitation of a critical vulnerability in Cisco Identity Services Engine (ISE).
CVE-2026-76460 was rated CVSS 10 and was being exploited as a zero-day before patches were available. The authentication bypass could allow an unauthenticated attacker to gain access to the appliance.
VMware vCenter was another example of how quickly vulnerabilities can escalate.
A critical vulnerability highlighted in August moved from advanced persistent threat exploitation to ransomware activity. The vulnerability was exploited within days of a patch being released, and hundreds of internet-facing vCenter servers remained exposed.
For businesses, the lesson is that patching alone is not always enough.
If a vulnerable system has already been compromised, organisations need to investigate for signs of malicious activity as well as applying the appropriate security update.
7. UK Cyber Security Regulation Is Continuing to Evolve
Cyber security is not only changing from a threat perspective. Regulation is evolving too.
The Cyber Security and Resilience Bill completed its House of Lords Committee stage in September. The proposals include expanding regulation across essential services and additional technology providers, alongside strengthened incident reporting and government intervention powers.
Current proposals include an initial incident notification within 24 hours followed by a more detailed report within 72 hours.
For affected organisations and their suppliers, this could mean greater responsibilities around cyber resilience, governance and incident reporting.
Businesses should therefore understand whether the legislation could apply to them or to critical suppliers within their supply chain and begin considering what a practical compliance roadmap could look like.
What Should UK Businesses Do Now?
The cyber security events of September provide a useful opportunity for businesses to review their own security posture.
Ask yourself:
Do you know what systems are exposed to the internet?
Make sure you have visibility of your infrastructure, devices, applications and management interfaces.
How quickly can you deploy critical security updates?
A vulnerability that is actively being exploited cannot necessarily wait for your next scheduled maintenance window.
Do you investigate after a critical vulnerability is patched?
If exploitation may have already started, patching the vulnerability is only part of the response.
What happens if a critical supplier suffers a cyber attack?
Review your business continuity and disaster recovery plans and consider how long your organisation could continue operating without key suppliers.
Which third-party applications have access to your systems?
Regularly review integrations and permissions across platforms such as Microsoft 365, CRM and ecommerce systems.
Have you tested your incident response plan?
Having a document that explains what you should do during a cyber attack is very different from having a plan that has actually been tested.
Cyber Security Needs to Be Proactive
September 2026 demonstrated that cyber security threats are moving quickly.
Attacks can spread through supply chains. Third-party applications can expose customer information. Critical vulnerabilities can be exploited within hours, while attacks against operational technology can potentially cause real-world disruption.
For UK businesses, the answer is not simply to buy more security tools.
It is about understanding your technology, identifying vulnerabilities, controlling access, keeping systems updated and having a clear plan for responding when something goes wrong.
A proactive cyber security strategy helps organisations reduce risk, improve resilience and minimise disruption when incidents occur.
How V4One Can Help
At V4One, we help businesses take a proactive approach to managed IT and cyber security.
From protecting your systems and users to monitoring your infrastructure and helping you respond to emerging threats, our experienced team can help you build a more resilient technology environment.
If your organisation wants to improve its cyber security posture, strengthen business continuity planning and reduce exposure to growing threats, we're here to help.
Want to understand how secure your business really is?
Talk to the V4One team about your Managed IT and Cyber Security requirements and discover where your organisation could strengthen its cyber resilience.
Technology Solutions. Experienced People. Personal Service.




