Cyber Security Insights August 2025

Cyber Security Insights August 2025

Written by Bryan Altimas

As you enjoy your summer holiday we provide a sizzling edition of Cyber Security Insights to keep entertained. This month we are looking at:

  • AI generated voice and video deep fakes. 2 cases in the UK and Canada stole $35 million.
  • We look at how cybersecurity architecture is changing: Zero trust, AI and adaptive defences.
  • Forthcoming UK and EU regulations that could influence your cyber security strategy

Deepfakes – The AI Threat That Isn’t Fiction Anymore

1754491459145

Check Point Research’s “AI Security Report 2025” details that in just one high‑profile incident in the UK, over £20 million was lost to a real‑time deepfake video scam. Whilst pre-recorded deepfake video scams in the UK have resulted in 6,000 victims and £27 million losses.

  • British engineering firm Arup suffered a £20 million fraud when cybercriminals impersonated senior executives on a live video call persuading a Hong Kong based employee to transfer £20 million to fraudulent bank accounts in 5 transactions.
  • The CEO of WPP was targeted in an unsuccessful fraud attempt. Fraudsters created a WhatsApp account with a publicly available image of CEO Mark Read and used it to set up a Microsoft Teams meeting that appeared to be with him and another senior WPP executive. During the meeting, the impostors deployed a voice clone of the executive as well as YouTube footage of them. The scammers impersonated Read off-camera using the meeting’s chat window. The targeted executive was asked to set up a new business in an attempt to solicit money and personal details.
  • Recorded deep fake videos of high profile public people, such as Martin Lewis, Zoe Ball and Ben Fogle, have been used in fraudulent cryptocurrency scams. There are 6,000 reported victims and losses of £27 million.
  • Smaller cases, such as Canadian victims losing C$373,000 in a multi-target scam show these are not only “big corporate” risks.
  • Broader risk: Better Business Bureau estimates $12 billion global deepfake-related fraud losses, forecast to triple in three years.

Why it matters: Deepfake-as-a-service is now available on underground markets for as little as $200. Legitimate tools like ElevenLabs can create a believable voice clone from less than 10 minutes of audio.

What to do:

  • Use out of band authentication for high‑risk transactions.
  • Embed deepfake detection and awareness training for all staff.
  • Audit any “urgent” requests from senior leaders, especially those via video

You and your team could be seconds away from being socially engineered on a live call. Let’s run a deepfake resilience simulation for your executives and you’ll see exactly how easily this threat can bypass standard processes and how to harden them. DM me the word "Deep".

Zero Trust, AI and Adaptive Defences

1754498069787

The cybersecurity landscape is demanding a strategic shift. Enterprises are moving towards Zero Trust, AI-powered detection, and resilience planning. Here is why they should be your top priorities this year.

1. Zero Trust Architecture

Cyber attacks now use user access credentials to gain initial access to their victim organisations. Identity management and validation has long been an issue wit IT and cybersecurity teams.

Gartner says 60% of enterprises will move away from remote access VPNs in favour of Zero Trust Network Access systems over the coming years. This means every request, internal or external, is continuously authenticated and authorised.

By 2027, 40% of large enterprises will support fully location-agnostic Zero Trust network access (ZTNA), up sharply from under 10% in 2024.

Organisations with mature Zero Trust deployments have reduced breach costs by an average of US $1.76 million per incident, compared to those without Zero Trust according to the IBM Cost of a Data Breach Report 2025.

2. AI-Powered Detection & Response

  • According to IBM’s 2025 Cost of a Data Breach Report, UK companies using AI and automation extensively averaged £3.11 million in breach costs versus £3.78 million for those without, saving over £600,000 per incident.
  • The IBM report also identified the Mean Time to Identify (MTTI) and Mean Time To Contain (MTTC) improved drastically when companies used AI detection and response. MTTI fell to 148 days from 168, and MTTC improved to 42 days from 64.
  • Globally, organisations using AI report breach lifecycle reductions of up to 80 days and cost savings of US $1.9 million on average.
  • Without proper governance, 13% of firms suffered breaches involving AI models, and 97% of those lacked access controls, driving up operational disruption and data loss.

AI is becoming both the weapon of attackers and the shield for defenders. AI is becoming mandatory in a strategic security posture.

3. Resilience as Strategy

There is no such thing as being 100% secure. Our objective is to make you secure enough most threat actors find it too difficult to get in. The longer it takes a threat actor to breach the higher the risk they will be detected. Resilience is essential to prevent long recovery times.

Immutable backups, micro-segmented recovery zones, and tested failover workflows reduce the fallout and downtime when breaches happen.

Today’s fast-moving threat environment demands not only prevention, but rapid detection and recovery.

Summary: Why You Need These Three Pillars

Article content

Let’s schedule a Zero Trust & AI readiness review. We’ll assess:

  • Your identity and access policies
  • Current AI security controls and shadow AI risk
  • Detection & containment capability
  • Resilience gaps (backups, segmentation, incident response testing)

You’ll receive a business-aligned roadmap, prioritised by ROI and impact. That’s the difference between ticking boxes and being secure for scale. DM me the word 'Resilience".

Regulatory Watch – UK & EU Cyber Laws That Will Shape Your Strategy

Compliance v contract loss

The regulatory landscape is shifting fast. In both the EU and UK there are a number of new regulations that are already in force or will be in force very shortly. Here, we are just looking at cybersecurity regulations and not AI regulations. These aren’t “tick‑box” exercises, non‑compliance now means fines, reputational damage, and contractual loss.

EU NIS2 Directive – In force from 18 October 2024, transposed into national law across EU Member States.

  • Expands the scope of the original NIS Directive to cover more sectors, including healthcare, technology, manufacturing, food, waste management, space, and public administration.
  • Introduces stricter incident reporting requirements, significant incidents must be reported within 24 hours, with a final report due within 72 hours.
  • Imposes higher fines: up to €10 million or 2% of global turnover, whichever is higher.
  • Requires supply chain risk management, organisations are responsible for the resilience of their critical suppliers.

NIS2 is about sector-wide operational resilience, not just your own security posture.

EU Digital Operational Resilience Act (DORA) – Live from 17 January 2025.

  • Applies to financial institutions and ICT providers.
  • Requires ICT risk management frameworks, resilience testing, incident classification & reporting, and third‑party ICT oversight.
  • Penalties: up to 2% annual turnover for critical breaches or repeated non-compliance.

EU Cyber Resilience Act (CRA) – Applies from December 2027.

  • Mandates “secure by design” for connected devices and software.
  • Requires manufacturers to patch vulnerabilities and disclose incidents promptly.
  • Non‑compliance can mean fines up to €15 million or 2.5% of turnover.

UK Cyber Security & Resilience Bill (CS&R) – Expected first half 2026.

  • Aligns with the EU NIS2.
  • Expanding the definition of critical infrastructure and essential services
  • Mandating incident reporting, resilience planning, and cyber audits
  • Requiring organisations to proactively secure their digital supply chains
  • Empowering regulators to enforce penalties, issue improvement notices, and conduct investigations

The scope is intentionally wide. The Cyber Security and Resilience Bill UK isn’t just for traditional critical infrastructure like power grids or water suppliers. It is about digital resilience across all essential sectors, including organisations that provide services considered vital to economic security, public safety, or the national digital ecosystem, or those that support them.

What you should do now:

  • Map regulatory applicability – Which rules apply to your sector, clients, and suppliers.
  • Tighten supplier due diligence – NIS2 and DORA make you responsible for third‑party resilience.
  • Implement rapid incident reporting – Build workflows to meet NIS2’s 24-hour and 72-hour windows.
  • Start secure‑by‑design projects – Don’t wait until CRA’s 2027 enforcement.
  • Prepare for CS&R changes – Upgrade authentication and prepare for cyber audits.

Book a regulatory readiness workshop. We will assess your exposure to NIS2, DORA, CRA, and UK CS&R and produce a prioritised compliance roadmap that protects revenue, wins client trust, and avoids costly fines. DM me the word "Regulation".


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right