Weekly Briefings

Six sector briefings. Three land every Monday morning.

Two pages each, no filler — what actually moved in aviation cyber, UK construction cyber and compliance, counter-UAS, autonomous vehicles and international affairs, and what it means for the people who have to act on it.

Latest

Current briefings

6 briefings
Autonomous vehicles weekly · Edition 01 Week commencing 3 August 2026

London now has a licensed, human-supervised robotaxi on its streets — and the loudest response was a union warning, not a passenger queue.

On 5 August Transport for London issued the capital's first robotaxi private hire licences, to Uber and Wayve, for 15 supervised vehicles — three days after Baidu's Apollo Go began…

Aviation cyber weekly · Edition 01 Week commencing 3 August 2026

This week's confirmed exploits were not against edge boxes — they were against the consoles that manage them.

CISA confirmed active exploitation of a maximum-severity flaw in Arista's VeloCloud SD-WAN orchestrator and a hardcoded credential in Cisco's firewall management platform, both within three…

Cloud and AI platform briefing · Edition 01 Week commencing 3 August 2026

The EU AI Act's August deadline did not move for everyone — only the high-risk rules did.

Regulation (EU) 2026/1744 pushed the Annex III high-risk deadline from 2 August 2026 to 2 December 2027, but left Article 50's chatbot-disclosure and deepfake-labelling duties untouched.

Drone and counter-UAS weekly · Edition 01 Week commencing 3 August 2026

NATO just gave 32 nations a single route to buy counter-drone kit — nobody has confirmed it runs on an open interface.

Member states can now buy pre-qualified counter-UAS systems without running their own national procurement. That is a genuine speed gain.

International weekly · Edition 01 Week commencing 3 August 2026

China has, for the first time, put named European defence manufacturers on its rare-earth export blacklist.

Every previous round of Chinese export leverage targeted the civilian economy — electric vehicles, wind turbines, consumer electronics.

UK construction cyber and compliance weekly · Edition 01 Week commencing 3 August 2026

One hardcoded GitHub credential reportedly gave attackers seven months inside Arup's project data, including HS2 design files.

FulcrumSec's claimed breach of Arup Group traces to a personal access token left in a JavaScript file on a forgotten subdomain — a housekeeping failure, not a sophisticated exploit.

Want these in your inbox on Monday?

We can tailor a briefing to your sector, your estate and your risk appetite. Tell us what you need to watch.

Get in touch