Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

G7 cyber exercise ends without readout

1 min read
16:08UTC

A GOV.UK update records the G7 Cyber Expert Group's 2026 Cross-Border Coordination Exercise as concluded on or before 31 July. No readout has been published.

TechnologyDeveloping
Key takeaway

The exercise closed with no published scenario, participants or findings.

The G7 Cyber Expert Group's 2026 Cross-Border Coordination Exercise concluded on or before 31 July, according to a GOV.UK update 1. The group brings member states' authorities together to coordinate response to cyber incidents that cross national borders, and the exercise is its rehearsal of that coordination. No participant list, no scenario description and no findings have been published.

Silence of this kind is ordinary practice for exercises of this type, since the scenario often models attacks on named sectors and publishing it advertises what the participants believe they cannot yet handle. It does leave the record thin. Cross-border work of the operational kind produces visible results when it lands, as Europol's Operation Saffron did in May by pulling 33 servers out of the infrastructure of at least 25 gangs . An operator in one of the sectors a cross-border scenario would cover has no way to learn which coordination failures the exercise surfaced, or whether the arrangements it depends on in a real incident were tested at all.

Deep Analysis

In plain English

The G7 Cyber Expert Group is a working group where officials from the G7 countries, the US, UK, Canada, France, Germany, Italy and Japan, practise coordinating their response to a major cross-border cyberattack before a real one happens. A government update confirmed their 2026 exercise wrapped up by 31 July, but no summary of what happened during it, or what they learned, has been published. That means there's currently no public detail on what scenario the exercise covered, who took part beyond the group's usual membership, or what gaps it may have found in how these countries would work together during a real incident.

What could happen next?
  • Meaning

    Without a published readout, the exercise's findings cannot inform public assessment of G7 cross-border incident-response readiness; a future release, if one comes, is the thing to watch.

First Reported In

Update #12 · KEV deadlines fell from 14 days to three

GOV.UK· 3 Aug 2026
Read original
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.