惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
人人都是产品经理
人人都是产品经理
WordPress大学
WordPress大学
博客园 - Franky
小众软件
小众软件
酷 壳 – CoolShell
酷 壳 – CoolShell
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
IT之家
IT之家
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog
S
SegmentFault 最新的问题
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
有赞技术团队
有赞技术团队
B
Blog RSS Feed
Last Week in AI
Last Week in AI
Jina AI
Jina AI
博客园 - 司徒正美
The Cloudflare Blog
博客园_首页
博客园 - 聂微东
宝玉的分享
宝玉的分享
大猫的无限游戏
大猫的无限游戏

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Infosecurity Europe: CyCOS Project Expands to Support UK ...
Kevin Poireault · 2026-05-29 · via www.infosecurity-magazine.com

In the UK, a small initiative aimed at helping small and medium enterprises (SMEs) tackle cybersecurity problems is scaling up as it prepares for a bigger future.

The Cybersecurity Communities of Support (CyCOS) is a UK research-driven pilot launched by academics from the University of Nottingham, Queen Mary University of London and the University of Kent to test a new, peer-led model of cyber support for small and micro businesses.

The project began in late 2023 as an investigation into gaps in SME cyber guidance and grew into a practical pilot that established two professional communities – one focused on micro businesses and the other on small and medium enterprises.

Each community is intentionally small and manageable and is supported by volunteer cyber practitioners so members can build trust, share experiences and get timely, practical help.

Speaking to Infosecurity, Steven Furnell, professor of cybersecurity at the University of Nottingham, noted: “We've got two or three experts and eight or nine organizations within each community, which keeps groups large enough to be useful but small enough to be personal.”

CyCOS operates with a mix of synchronous and asynchronous support designed to fit SME schedules:

  • Regular thematic webinars and occasional in-person meetings
  • Plenary sessions that bring communities together for broader briefings and cross-community discussion
  • Live ‘Ask Me Anything’ sessions where volunteer cyber experts field members’ questions in real time
  • A support-broker online platform hosting community threads, polls, session recordings and ad-hoc Q&A so members can keep the conversation going between events
  • Recordings and shared resources so members who can’t attend live still benefit

After over two years of academics running the project, CyCOS is now about to enter a new phase, with a planned expansion and a winding down of the academics’ leadership, Furnell told Infosecurity.

CyCOS Expands to Seven Communities Ahead of CIISec Handover

The announced expansion will add five new communities, bringing the pilot cohort from two to seven.

The move comes as the academic funding phase nears its end and the project prepares for a handover to the Chartered Institute of Information Security (CIISec), a professional body for cybersecurity practitioners, which is already a CyCOS partner.

“CyCOS as a concept of cybersecurity communities of support will still exist but will be promoted within CIISec. As for us academics, we’ll still be around too, just not running the projects like we used to,” Furnell said.

Speaking to Infosecurity, Amanda Finch, CEO at CIISec, said the organization is “proud to be involved” in the development of CyCOS.

“As security professionals, we all have a duty of care to help smaller organizations improve their cyber resilience. The current communities of support are already doing excellent work in this area, so very glad that more are being established,” she added.

Furnell was unable to give more information about the five new communities at this early stage. However, he explained that they were all founded by SMEs that “feel they can attract a suitable number of other SMEs to join a community” and volunteered to act as facilitators, as “beacons within those communities.”

The new CyCOS communities can be built around a geographical location, a sector or even a supply chain.

Leading SMEs have been provided with a “Community Toolkit” that they can follow to recruit members, establish a community and operationalize it. This document also ensures groups can replicate the model as responsibility transitions to CIISec.

SMEs Know the Risks, But Lack Direction on How to Respond

Cyber threats to SMEs have evolved and grown as citizens and threat actors alike have realized they are “a crucial part of everyone’s life and activities,” Furnell said.

“Particularly, we have seen major cyber incidents that have had impact on the supply chain, and thus involved SMEs,” he added.

In this challenging environment, he said awareness of cybersecurity guidance and government programs is still limited within UK-based SME leaders – and the smaller the company, the less aware they are.

This trend is particularly prominent with Cyber Essentials, the UK government-endorsed scheme to certify the level of cyber hygiene of UK-based organizations.

According to the latest edition of the UK Cyber Security Breaches survey, a point of reference for Furnell and CyCOS, 64% of large businesses and 56% of medium businesses were aware of the program, compared to 25% of small businesses and 14% of micro businesses.

However, after over two years working on the CyCOS project, Furnell believes the main problem for SMEs is not necessarily awareness that cyber hygiene is important, but where to find resources and expertise to implement cybersecurity.

“In many cases, people we’re speaking to recognize the issues but don’t feel empowered to do something about it,” Furnell explained.

Speaking to Infosecurity, Helen Barge, principal and head of digital resilience services at Howden and volunteer within the Federation of Small Businesses (FSB), brushed off the lack of budget as being the main reason behind some SMEs lagging in cybersecurity.

“I get tired of that excuse, because some of the controls that you can put in place, like multifactor authentication (MFA) actually don’t cost any money,” she highlighted.

“Something like patching may cost a lot of money, but budget is definitely not the only restrictor,” she added.

She emphasized the accessibility of what she described as “brilliant guidance” released by the UK government, including the National Cyber Security Centre’s (NCSC) Cyber Action Toolkit, released in 2025.

One thing Barge said was key for SMEs, who do not necessarily have enough staff dedicated to cyber, is choosing the right IT and cybersecurity providers.

She criticized some cybersecurity providers for questionable practices, especially when dealing with SMEs.

“I was working with a client earlier this week and their IT provider charges extra for patching within 14 days – which is a requirement to obtain the Cyber Essentials certificate in the UK. That’s not acceptable: a cleaner doesn’t charge me extra for a buying a bottle of bleach, that’s part of the service,” she said.

However, Barge noted: “I don’t want to tar everybody with the same brush: it’s important to say not all SMEs are rubbish at [cybersecurity]. Within CyCOS and the FSB, we’re working with some that are doing amazing things, that are standing out in their cyber hygiene.”

Steven Furnell, Amanda Finch and Helen Barge will speak on a panel session titled “Communities of Support: Scaling Practical Cyber Help for SMEs”, held on the keynote stage of Infosecurity Europe 2026 on Thursday, June 4 (11:50 to 12:30). Steven Furnell will also be running cyber gamified activities at Infosec Sidequest. You will also be able to find CIISec at Booths #F155 and #F157. Register for Infosecurity Europe here.