Organisations need to have plans in place for cyber attack response, which should only be used infrequently but must be able to limit damage and speed recovery. The plan needs to be thoroughly analysed and rehearsed, involve stakeholders of increasing seniority, and should be built into existing structures. It should be regularly exercised to ensure it will function correctly in a crisis situation, and a senior manager should be accountable in its development and maintenance.

Ivanti VPN customers targeted via unrecognized RCE vulnerability (CVE-2025-22457)
A suspected Chinese advanced persistent threat (APT) group exploited CVE-2025-22457, a previously unexploitable buffer overflow bug, to compromise devices running Ivanti Connect Secure (ICS) and