惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
有赞技术团队
有赞技术团队
宝玉的分享
宝玉的分享
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
V
V2EX
大猫的无限游戏
大猫的无限游戏
博客园 - 司徒正美
D
Docker
T
The Blog of Author Tim Ferriss
罗磊的独立博客
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
Blog — PlanetScale
Blog — PlanetScale
月光博客
月光博客
J
Java Code Geeks
Jina AI
Jina AI
博客园 - 【当耐特】
C
Check Point Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
腾讯CDC
Last Week in AI
Last Week in AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty
JLR cyber bailout risks dangerous precedent, watchdog warns
Carly Page Carly Page · 2026-03-20 · via The Register - Security: Cyber-crime

Cyber-crime

Jaguar Land Rover's cyber bailout sets worrying precedent, watchdog warns

Lack of clear criteria risks encouraging firms to lean on state support instead of worrying about insurance

The UK's cyber watchdog has warned that the government's £1.5 billion bailout of Jaguar Land Rover (JLR) risks setting a troubling precedent for how Britain handles major cyber crises.

Speaking at an event marking the Cyber Monitoring Centre's (CMC) first operational year, Ciaran Martin, chair of the CMC's technical committee and a distinguished fellow at RUSI, said the government's response to the JLR cyberattack could create longer-term problems if repeated without a clear framework.

"I think the loan guarantee is an unfortunate precedent because the government intervened in a case-specific way... without clear criteria," Martin said. "Otherwise you'll just end up with a series of ad hoc precedents that will leave nobody any the wiser."

The warning comes as the country's Ministry of Defence on Friday confirmed that the British Army will retire its Land Rover fleet after more than 70 years of service, as it looks to replace thousands of vehicles with a modern successor.

It follows a year in which the CMC has tried to put hard numbers on the financial impact of major cyber incidents on the UK economy, including the JLR attack, which it estimates cost up to £1.9 billion. Separate attacks on retailers Marks & Spencer and the Co-op were pegged at a combined £355 million.

But beyond the headline figures, the discussion highlighted a deeper problem: the widening gap between the economic damage from cyberattacks and what the insurance market can realistically absorb.

Tracy Poole, chief communications officer at Pool Re, said the cyber insurance "protection gap" could be as high as 90 percent, meaning most losses from large-scale incidents are effectively uninsured. While insurance can cover individual companies, she warned it falls short when the damage spills into supply chains and local economies.

"They can insure a company, but they can't insure a community and the impact on the wider community," she said.

That mismatch helps explain why governments end up stepping in when things go wrong, but Martin warned that doing it without clear rules risks sending the wrong signal. Cybersecurity, he said, is driven by how companies assess risk, and if they think the state will ride to the rescue, they may be less inclined to invest in resilience.

"It would be better to have a framework... rather than a response to events," he said, suggesting options could include mandatory insurance, tax incentives, or some form of government-backed safety net.

Alongside the policy debate, the CMC used the event to show how its work is evolving. The organization said it is working with the Office for National Statistics to introduce post-incident business polling after widespread cyber events, and is preparing a white paper examining the UK's exposure to cloud-related risks.

It also confirmed plans to expand beyond the UK. "We're in the process of establishing a US cyber monitoring center," said CMC head of operations Ruth Goodwin. The effort will start with appointing a technical committee and setting up a US legal entity closely linked to the UK operation, with live incident categorizations potentially landing in 2027.

The move reflects growing demand for clearer, standardized ways of measuring cyber damage, something that remains patchy across the industry. Martin acknowledged that while disruptive ransomware attacks are relatively straightforward to cost, the financial impact of data breaches is far harder to pin down.

That uncertainty, combined with the scale of recent incidents, suggests the UK is only just getting to grips with the true economic fallout of cyberattacks. If the JLR case is anything to go by, the question of who ultimately foots the bill is still very much up for debate. ®