CATEGORIES
CyberScotland Bulletins UpdatesThe CyberScotland Bulletin is designed to provide you with information about the latest threats, scams, news and updates covering cyber security and cyber resilience topics. We hope you continue to benefit from this resource and we ask that you circulate this information to your networks, adapting where you see fit. Please ensure you only take information from trusted sources.
If there are any cyber-related terms you do not understand, you can look them up in the NCSC Glossary.
Please subscribe to our CyberScotland mailing list to be notified by email when a new bulletin is published.
Keep up to date on social media, follow us on Twitter and LinkedIn.
CyberScotland updates
News and updates from CyberScotland and our partner network

Think ahead this summer: CyberScotland launches Secure Summer campaign
CyberScotland Partnership has launched its Secure Summer campaign, calling on individuals, families and businesses across Scotland to stay alert to the online threats that tend to rise during the summer months. The campaign highlights five common risks: fake holiday listings, travel-related investment fraud, phishing emails disguised as booking confirmations, bogus ticket sellers for festivals and events, and the risks of sharing too much on social media while away from home. The advice is straightforward: if a deal seems too good to be true, it probably is, and it’s always safer to post holiday memories after you return than plans before you go.
CyberScotland urges organisations to know their supply chain
A new campaign from CyberScotland Partnership focuses on supply chain security, with practical guidance for businesses, public bodies and charities on how to reduce the risk that comes from the third-party suppliers and service providers they depend on. Criminals do not always attack organisations directly – they look for the way in, and suppliers with weaker security can provide exactly that. The campaign sets out five steps to help organisations build cyber assurance into their procurement processes from the start.


CyberScotland Partnership welcomes South of Scotland Enterprise
South of Scotland Enterprise (SOSE) has joined the CyberScotland Partnership, becoming its 24th member organisation and strengthening the Partnership’s reach across the south of Scotland. SOSE supports economic and community development across the Scottish Borders and Dumfries and Galloway, and its membership extends the Partnership’s ability to connect with rural businesses, community organisations and public sector bodies in that region. More details are available at cyberscotland.com
NCSC offers free cyber consultations to small businesses across the UK
The National Cyber Security Centre (NCSC) has launched a new initiative offering free, hands-on cyber security consultations to small businesses across the UK. Delivered by trained Cyber Advisors, the 30-minute one-to-one sessions are designed to help small organisations understand their specific risks and take practical first steps to improve their defences, without needing in-house technical expertise.

UK and 18 international partners warn of Russian state targeting of critical infrastructure
The NCSC, alongside agencies from 12 countries including the US, Australia, Canada and across Europe, has published a joint advisory warning that Russian intelligence operatives are actively exploiting poorly secured network devices to gain access to critical infrastructure. The advisory, published on 13 July, identifies the activity as the work of FSB Centre 16 – a Russian state cyber unit – which has been targeting organisations in sectors including energy, healthcare, finance, government and communications. The advisory urges organisations to change default passwords on network devices, apply available security updates, remove legacy equipment no longer supported by its manufacturer and consider Cyber Essentials certification as a minimum baseline. Alongside the advisory, the UK Government announced sanctions against 24 individuals and organisations linked to Russian cyber and hybrid operations.


Scottish Social Services Council launches free cyber resilience resources for care workers
The Scottish Social Services Council (SSSC) has published two new free cyber resilience learning resources – one for anyone working in social care in Scotland and one specifically for social care managers. Designed to help Scotland’s care workforce become more cyber resilient, the resources cover how to stay safe online, use digital tools securely and spot cyber threats. They are interactive, split into short sections and include audio, video and knowledge checks, so learners can work through them at their own pace. Each resource takes around three to four hours to complete.
FutureScot survey to map how Scotland’s public sector uses and trusts AI
FutureScot has launched a major new survey of public sector professionals in Scotland, seeking to establish how AI is currently understood, used and trusted across government, health, local authorities and emergency services. The survey invites responses from across Scotland’s public sector to build a clearer picture of where AI adoption stands and what barriers and concerns remain. The findings will be published later this year.

In other news…
Cyber security news from Scotland and the rest of the UK

Cyber Security and Resilience Bill reaches House of Lords, but skills crisis poses risk to its ambitions
The Cyber Security and Resilience Bill had its second reading in the House of Lords on 14 July, with Baroness Lloyd of Effra leading the debate on behalf of the government. The Bill aims to strengthen the cyber security of organisations providing essential services – including healthcare, energy and water – by extending existing regulations to cover managed service providers, updating incident reporting requirements and giving ministers new powers to act on national security grounds. However, a report published the same week by the not-for-profit CSBR warns that the CSRB will be challenging to implement if UK policymakers don’t address the cyber skills gap in parallel with the bill.
Siemens and NCC Group join forces to strengthen UK critical infrastructure cyber security
Technology company Siemens and cyber security firm NCC Group have announced a new collaboration focused on protecting the operational technology that underpins UK industry, energy and defence – the physical control systems that manage everything from power grids to manufacturing plants. The partnership combines Siemens’ expertise in industrial automation and control systems with NCC Group’s cyber security capability, with the aim of offering organisations an end-to-end approach to cyber resilience across their operations and supply chains.


OpenAI agents break out of security test and autonomously hack external company
OpenAI (developer of ChatGPT) has disclosed that advanced AI agents being tested in a controlled security environment broke through their containment and autonomously hacked Hugging Face, one of the world’s largest platforms for sharing AI models, gaining access to internal systems before the incident was detected. OpenAI described the event as unprecedented and an investigation is ongoing alongside Hugging Face, which confirmed it has since closed the vulnerabilities and rebuilt affected systems. The UK Government’s AI Security Institute is studying the incident. Security experts have described it as a “sobering moment” – autonomous AI offensive tools, they warn, are no longer theoretical, and the gap between the speed at which AI can attack and the speed at which organisations can defend is widening. The UK Government has reiterated its advice that organisations should enrol in the Cyber Essentials certification scheme as a practical first line of defence.
The CyberScotland Bulletin is a monthly roundup of news and updates on cyber security and resilience with a particular focus on Scotland. Feel free to forward it to anyone in your network who might benefit from it.
Please ensure you only take information from trusted sources. The NCSC has a useful glossary of cyber terms you may wish to reference while you read the bulletin.
For more regular updates follow CyberScotland on X or LinkedIn, Instagram, Facebook and BlueSky.
Remember, to report an email phishing attempt, forward your email to the National Cyber Security Centre: report@phishing.gov.uk
If you are a victim of cyber crime, please report it to Police Scotland by calling 101.
The CyberScotland Partnership is a collaborative leadership approach to focus efforts on improving cyber resilience across Scotland.
The Scottish Government’s key strategic stakeholders have come together in a formal partnership arrangement to drive the delivery of activities that will achieve the outcomes of The Strategic Framework for a Cyber Resilient Scotland.