This week in IT and cyber security: 17–24 July 2026
It has been a busy week on the System Force blog, covering fresh legislation, active cyber threats, and some practical thinking on how smaller businesses can get more from their IT.
New UK Data Law Is Live: What Your Business Must Do
The Data Use and Access Act 2026 came into force this week, replacing key parts of the UK GDPR framework and introducing new obligations for businesses of all sizes. Our post breaks down what has actually changed, what to review in your privacy notices and data-sharing agreements, and the steps you should take now to stay compliant. If you have not looked at your data governance recently, this is the week to do it.
wp2shell: Why Patching WordPress Just Became Urgent
A newly disclosed WordPress vulnerability, dubbed wp2shell, is being actively exploited in the wild and gives attackers the ability to run commands directly on your web server. If your business runs a WordPress site and has not applied the latest update, it is at immediate risk. We explain what the flaw is, how attacks are unfolding, and the steps to take right now to lock things down.
NCSC and Global Allies Expose Russian FSB Router Attacks: What UK Businesses Need to Do Now
The NCSC, alongside allied agencies, published a joint advisory warning that Russian FSB-linked actors are actively compromising routers to spy on businesses and government bodies across the UK and beyond. The advisory confirms that default credentials, unpatched firmware, and poor network segmentation are the most common entry points. We cover the key mitigations and explain why router security should be on every SMB’s checklist, not just large enterprise IT teams.
Fractional IT Management: What It Is and Why SMEs Need It
Not every business needs a full-time IT director, but many would benefit greatly from having one. Fractional IT management gives you the strategic oversight of a senior IT professional on a part-time or as-needed basis, at a fraction of the cost of a full hire. Our post explains how the model works, who it suits, and the results SMEs are already seeing when they bring proper IT leadership into the business.
Data Sovereignty: What It Is and Why Your Business Should Care
Data sovereignty is the principle that your data is subject to the laws of the country where it is stored or processed, and it matters more than ever as businesses move further into the cloud. For UK SMBs, this has real implications for where you host data, which cloud providers you use, and whether your current setup exposes you to overseas legal regimes. Our post cuts through the jargon and explains what to think about when reviewing your cloud arrangements.
Want to find out how any of this applies to your business? Get in touch with the System Force team and we will be happy to help.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


