May 2026 Newsletter

Posted By: Mark Tuesday 30th June 2026 Tags: , , , , , , , , , , , , , ,

This month: ISO Certification, the latest phishing attack updates, the risks of insider threats, more bad news for passwords – plus the latest LaneSystems news.

Newsletter image: ISO Certification

Why ISO Certification Matters: Helping Businesses Turn Standards Into Real-World Improvement

When many businesses hear the word ISO, they immediately think of policies, audits and certificates on the wall. And that is often where the misunderstanding begins.

Understanding the Real Purpose of ISO Certification

The businesses that gain the most value from ISO rarely see it as a paperwork exercise. Instead, they use it as a framework that helps the business operate more effectively.

Every business faces similar day-to-day challenges. Questions start appearing such as: Who owns this? Has anyone reviewed that? Where is the latest version? Has this happened before? Are we actually improving?

As businesses grow, information naturally starts spreading across emails, spreadsheets, systems and different departments. Over time, it becomes harder to see what is happening across the organisation, which can lead to duplicated effort, delays and uncertainty.

This is where a properly implemented management system can make a real difference.

How ISO Certification Creates a Connected, Visible Management System

Rather than introducing extra administration, a good ISO framework brings existing activities together into one connected structure. Risks, actions, incidents, supplier reviews, objectives and performance measures stop operating separately and begin supporting each other.

That creates something many businesses struggle with: visibility. Business owners gain a clearer picture of what is happening across the organisation. They can quickly see where actions are overdue, whether objectives are being achieved, which risks require attention and where recurring issues may be developing.

The result is better decision-making because information becomes easier to find and easier to trust.

The benefits are not just theoretical either. Organisations that have implemented ISO properly have reported fewer security incidents, reduced downtime, faster responses to customer due diligence requests and stronger competitive positioning. One engineering organisation reported a 72% reduction in security incidents after integrating information security into wider business operations and risk management processes.

How ISO Certification Helps SMEs Work Smarter, Not Harder

For many businesses, however, the biggest benefit is often much simpler. Less chasing. Less duplication. Less time spent preparing for audits or searching for information.

Instead of gathering evidence at the last minute before an audit or customer review, the evidence already exists because it has been created naturally through everyday activities.

Most SMEs are already carrying out much of what ISO requires. They are onboarding staff, managing suppliers, resolving issues and continuously improving services. The challenge is often not doing the work itself. It is connecting the work together in a structured way.

At LaneSystems, we believe management systems should become part of the normal rhythm of the business rather than a collection of documents sitting in folders and only being opened during audit season.

Because the strongest ISO implementations do not simply help businesses achieve certification. They help businesses run better.

If you’re a business in the north-east of England, contact us today to find out more about how we can help you get your ISO certifications and how it can help your business work more effectively.


Newsletter image: LaneSystems Team Anniversary & Charity News

LaneSystems News

Charity News

We’re continuing our focus on cyber awareness for our clients and the wider community. This month’s charitable donation is further support of one of our hospice partners, with £300 of phishing awareness training to help Willow Burn Hospice strengthen their defences against the same cyber threats affecting businesses throughout the region.

Phishing & Vishing Training: Strengthening Your First Line of Defence

Phishing and vishing attacks remain one of the most effective ways criminals breach organisations — not by breaking systems, but by manipulating people. Even well-trained, experienced staff can be caught off guard by messages or calls that appear completely legitimate. Attackers use urgency, authority, and familiarity to create pressure, and as highlighted in last month’s article, a single successful attempt can lead to credential theft, financial loss, or unauthorised access deep inside a business’s systems .

That’s why structured phishing and vishing training is no longer a “nice to have” — it’s a critical layer of cyber protection. Real-world simulations and guided awareness sessions help employees recognise the subtle cues that attackers rely on, giving them the confidence to pause, question, and report suspicious activity before damage occurs. Organisations that take this proactive approach significantly reduce the likelihood of successful attacks and strengthen their overall resilience .

LaneSystems provides tailored phishing and vishing training designed specifically for busy teams who need practical, actionable skills. Our sessions help staff understand how modern social-engineering attacks work, what red flags to look for, and how to respond safely under pressure. If your business wants to reduce risk, protect sensitive information, and build a more cyber-aware workforce, now is the ideal time to invest in this training.

Get in touch today to for more information about our phishing and vishing awareness training.


The Growing Threat of Phishing Attacks

Last month we wrote about Phishing and Vishing (and Smishing) attacks being ‘The Business Risk Hiding in Plain Sight‘.  This month, we are following up on that article by highlighting some of the phishing attack stories which made headlines during May.

UK Travel Firm Nearly Loses £500,000 to a Year-Long Vishing Scam

A major case highlighted in early May involved a UK travel and tourism company that almost transferred £500,000 after attackers spent 12 months researching a specific employee before placing highly convincing fraudulent phone calls. The attackers used detailed personal and organisational information to impersonate trusted contacts and pressure the employee into authorising a payment.

This case is particularly important because it shows:

  • Vishing attacks are becoming long-term, targeted, and highly researched.

  • Criminals are using voice calls instead of email, bypassing traditional email-based defences.

  • The attack relied entirely on human manipulation, not technical exploits.

The government’s Cyber Security Breaches Survey also noted that phishing accounts for 93% of all cyber crimes against UK businesses, with an estimated 5.13 million incidents in the past year.

New AI-Driven Phishing Campaigns Targeting UK Users

Security researchers reported a surge in AI-generated phishing emails impersonating HMRC, NHS Digital, banks, telecoms providers, and cloud platforms. These campaigns use:

  • Perfect grammar and branding

  • Fake Microsoft 365 login pages

  • QR-code phishing

  • Multi-channel attacks combining email, SMS (smishing), and phone calls (vishing)

The National Cyber Security Centre (NCSC) flagged a significant rise in credential-harvesting campaigns in early 2026, with attackers using AI to make scams far more convincing.

This is especially relevant to your training services because the old advice (“look for spelling mistakes”) is now obsolete, as AI has removed those tell-tale signs.

AI Voice-Clone Vishing Attacks Increasing Against UK SMEs

UK Finance’s fraud reporting shows that voice-based impersonation attacks are now the fastest-growing fraud vector for SMEs. Criminals are using AI-cloned voices of CEOs, directors, and finance managers to:

  • Authorise payments

  • Approve MFA prompts

  • Request sensitive information

Voice clones can be created from as little as 30 seconds of audio, often scraped from LinkedIn, YouTube, or podcasts.

This trend directly reinforces the need for vishing-awareness training as staff can no longer rely on “recognising the voice”.

Get in touch today for more information about our phishing and vishing awareness training.


When Employees Become the Threat: New Cifas Data Reveals A Growing Insider Risk

A new Cifas Workplace Fraud Trends report has revealed a worrying shift in employee attitudes toward cyber security. According to the findings, 1 in 8 UK workers say they have sold company login details or know someone who has, and 13 percent believe selling access is justifiable. For any organisation, that represents a significant insider-risk exposure.

Even more concerning is how this attitude increases with seniority. Cifas reports that 32% of managers, 36% of directors, and 43% of C‑suite executives believe selling their access could be acceptable. Among business owners, the figure rises to an astonishing 81%. These are individuals with the highest levels of system access — and therefore the greatest potential to cause harm.

The Human Factor: Why Insider Risk Is Rising

The motivations behind this behaviour range from financial pressure to a belief that it’s a victimless act. But the consequences are anything but harmless. Selling login credentials gives criminals a direct route into business systems, bypassing technical controls entirely. Once inside, attackers can steal data, manipulate payments, impersonate staff, or deploy ransomware — all without needing to break through firewalls or exploit software vulnerabilities.

This reinforces a critical truth: cyber security failures are often human failures. Whether it’s an employee selling access or a member of staff being manipulated by a convincing phishing email or vishing call, attackers rely on people making quick decisions under pressure.

That’s why phishing and vishing awareness training, and other cyber awareness training, is essential. When employees understand how criminals operate, and how easily trust, authority and urgency can be exploited, they are far less likely to fall for social-engineering attempts or misuse their own access. Training helps staff recognise red flags, report suspicious activity, and understand the real-world consequences of poor cyber hygiene.

For businesses looking to strengthen their defences, investing in structured cyber-awareness training is one of the most effective steps you can take. Technology protects systems, but only training can protect people.  If you’re a business in the north-east of England get in touch for a chat about our phishing and vishing training and other cyber awareness services.


More Bad News for Passwords

A new analysis from Kaspersky, published on World Password Day, highlights just how fragile traditional password security has become. Using a dataset of more than 231 million leaked passwords, researchers hashed them with MD5 and found that 60 percent could be cracked in under an hour, and nearly half in under 60 seconds, using a single Nvidia RTX 5090 GPU . Even attackers without high‑end hardware can simply rent GPU power cheaply from cloud providers, making large‑scale cracking accessible to anyone.

The core issue isn’t just MD5 itself — it’s password predictability. Kaspersky notes that common patterns in real‑world passwords allow attackers to optimise cracking algorithms, dramatically reducing the time needed to guess them . Worse still, passwords are becoming easier to crack over time, with the 2026 results slightly worse than the 2024 study.

Security experts quoted in the report stress that passwords alone are no longer enough. Even strong passwords can be undermined if the wider identity environment isn’t properly managed, and multi‑factor authentication — ideally biometric — is now considered essential.

Passkeys are the way forward

This aligns directly with the NCSC’s updated guidance, which we covered in last month’s newsletter: organisations should adopt passkeys wherever possible, as they eliminate password‑based attacks and reduce the risk of credential theft.

With attackers able to crack weak hashes in seconds and social‑engineering attacks continuing to target staff, the message is clear: password‑only security is no longer defensible. Moving to passkeys — and strengthening phishing awareness — is now one of the most effective steps businesses can take to protect their systems and people.


Need Cyber Security?

If you’re a business in the North East of England and looking for professional and reliable cyber security services, IT consultation, and general IT services to keep your company cyber secure, get in touch. Cybersecurity is a continuous process, and staying proactive is key to safeguarding digital assets.

Recent Posts