All systems operational · Ormskirk, North West England

Government AI Cyber Threat Warning

What the letter says

On 15 April 2026, Liz Kendall, Secretary of State for Science, Innovation and Technology, and Dan Jarvis, Security Minister at the Cabinet Office and Home Office, issued a joint open letter to UK business leaders. The subject was direct: the threat your business faces in cyber space is changing, and the response must change with it.

For years, the most damaging cyber attacks needed a small number of highly skilled criminals. A new generation of AI models is changing that. These tools can now find weaknesses in software, write the code to exploit them, and do both at speed and scale that would have been impossible a year ago.

The letter names one model directly. Anthropic, the AI firm, announced a model called Mythos. The AI Security Institute at DSIT tested it and found it substantially more capable at cyber offence than any model assessed before. OpenAI has scaled up its Trusted Access for Cyber programme. Other companies are expected to follow.

One figure stands out. The AI Security Institute now assesses that frontier AI model capabilities are doubling every four months. The previous estimate was every eight months. That is the speed the ministers want every board to understand.

Why this matters for SMEs in the North West

The letter is blunt about who gets attacked. Criminals will not just target government systems and critical infrastructure. They will target ordinary companies, of every size, in every sector. Attackers go where defences are weakest.

For a business in Ormskirk, Liverpool, Manchester or anywhere across the North West, that is the line that matters. A construction firm, an accountancy practice, a manufacturer, a care provider. None of these businesses sit behind the defences of a bank or a government department. Most run on a mix of Microsoft 365, a few line-of-business applications, and whatever cyber hygiene has been put in place over the years.

AI-enabled attacks do not need a human operator to spend weeks on a single target. The economics of attacking a 20-person business have changed. That is the practical consequence of capabilities doubling every four months.

The three actions ministers are asking every business to take

The letter is clear that the steps to protect against AI-driven threats are the same cyber hygiene measures recommended for traditional cyber threats. Three actions are requested of every business leader.

1. Take cyber security seriously at the very top of your organisation

Cyber risk should be on the next board agenda, and then on every board agenda. It is not an issue to delegate to the IT team and forget. The government points boards to the Cyber Governance Code of Practice and points smaller businesses to the NCSC Cyber Action Toolkit. Plan and rehearse how the business would respond to a serious incident. Free cyber insurance is available to small organisations that hold Cyber Essentials.

2. Get the basics right with Cyber Essentials

Most successful cyber attacks exploit simple weaknesses. Outdated software. Weak passwords. Missing backups. Cyber Essentials is the government-backed certification scheme that protects against the most common attacks. Organisations that hold it are significantly less likely to suffer a damaging incident. The letter also asks larger firms to embed Cyber Essentials requirements across their supply chains.

3. Follow NCSC advice and sign up to the Early Warning Service

The National Cyber Security Centre publishes free, practical advice for organisations of every size. The Early Warning service is free and alerts organisations to potential cyber attacks, giving time to act before an incident escalates.

The core message, in the ministers’ own words

We are entering a period in which the pace of technological change may test every institution in the country. The businesses that act now, that treat cyber security as an essential part of running a modern company, not an optional extra, will be the ones best placed to thrive through it.

Attributed to The Rt Hon Liz Kendall MP and Dan Jarvis MBE MP, open letter to business leaders, 15 April 2026.

What this looks like in practice for a North West SME

The three government actions translate into a practical checklist any owner-managed business can start on this week.

Put cyber on the next board or directors’ meeting agenda

Ask three questions. What are our three most likely cyber incidents? What would we do in the first hour of each one? Who makes the decisions if the main point of contact is unavailable? If the answers are vague, that is the gap to close first.

Audit the basics before chasing the advanced

Multi-factor authentication on every account. Patching in place for Windows, Microsoft 365 and line-of-business software. Backups that are tested, not just running. An inventory of who has admin rights and why. These are the controls Cyber Essentials assesses.

Work out your Cyber Essentials route

Cyber Essentials is a certification, not a one-off exercise. For most SMEs it is achievable inside a short project with the right support. Cyber Essentials Plus adds an independent technical audit, which carries more weight with insurers and procurement teams. Blowfish Technology holds Cyber Essentials Plus.

Get signed up to NCSC Early Warning

Any organisation with a UK-registered domain can register. The alerts are specific to the domains and IPs you register. It is free and takes minutes.

Write down the incident response plan

Not a 40-page document. One or two pages that name who calls who, which systems get isolated first, which insurer is on the phone, and how staff are told what to do. Rehearse it once a year.

Where Blowfish Technology fits

Blowfish Technology works with SMEs across the North West on exactly this agenda. Managed IT, cyber security, Cyber Essentials and Cyber Essentials Plus certification, Microsoft 365 hardening, backup and disaster recovery planning. We hold ISO 9001, ISO 27001 and Cyber Essentials Plus, and we are a Microsoft Solutions Partner for Modern Work.

If the ministers’ letter has prompted a conversation at your next board meeting, and you need somewhere to start, a short scoping call is the quickest way to turn the three government actions into a plan for your business.

Under 15s
Average call waiting time
91%
Issues resolved same day
98%
Within SLA

Further reading

The full letter and linked government resources are available directly from gov.uk.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.