Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

G7 cyber exercise ends without readout

1 min read
16:08UTC

A GOV.UK update records the G7 Cyber Expert Group's 2026 Cross-Border Coordination Exercise as concluded on or before 31 July. No readout has been published.

TechnologyDeveloping
Key takeaway

The exercise closed with no published scenario, participants or findings.

The G7 Cyber Expert Group's 2026 Cross-Border Coordination Exercise concluded on or before 31 July, according to a GOV.UK update 1. The group brings member states' authorities together to coordinate response to cyber incidents that cross national borders, and the exercise is its rehearsal of that coordination. No participant list, no scenario description and no findings have been published.

Silence of this kind is ordinary practice for exercises of this type, since the scenario often models attacks on named sectors and publishing it advertises what the participants believe they cannot yet handle. It does leave the record thin. Cross-border work of the operational kind produces visible results when it lands, as Europol's Operation Saffron did in May by pulling 33 servers out of the infrastructure of at least 25 gangs . An operator in one of the sectors a cross-border scenario would cover has no way to learn which coordination failures the exercise surfaced, or whether the arrangements it depends on in a real incident were tested at all.

Deep Analysis

In plain English

The G7 Cyber Expert Group is a working group where officials from the G7 countries, the US, UK, Canada, France, Germany, Italy and Japan, practise coordinating their response to a major cross-border cyberattack before a real one happens. A government update confirmed their 2026 exercise wrapped up by 31 July, but no summary of what happened during it, or what they learned, has been published. That means there's currently no public detail on what scenario the exercise covered, who took part beyond the group's usual membership, or what gaps it may have found in how these countries would work together during a real incident.

What could happen next?
  • Meaning

    Without a published readout, the exercise's findings cannot inform public assessment of G7 cross-border incident-response readiness; a future release, if one comes, is the thing to watch.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

GOV.UK· 3 Aug 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.