Episode one, live on Tuesday 29 September 2026, examines how attackers are using AI today and how they are getting past multi-factor authentication
Haywards Heath, West Sussex, September 2026
Nebulogiq, the Haywards Heath managed IT and cyber security provider, has announced the first episode of The Threat Is Out There, a free live webinar series for UK business leaders and the people who look after their technology. Episode one runs on Tuesday 29 September 2026 at 10.30am, and it takes on two questions that come up in almost every client conversation the company is having at the moment. How are attackers actually using artificial intelligence today? And how are they getting past multi-factor authentication?
The session brings together Darren Senadhira, Managing Director of Nebulogiq, Craig Florence, the company’s Technical Director, and Sasha Roshan, Senior Sales Engineer at threat detection platform Huntress. The format is a working conversation about what the three of them are seeing in the field rather than a product demonstration, followed by an open question and answer session. Everyone who takes part in the Q&A is offered a complimentary security audit.
The numbers behind the invitation
The case for making time on a Tuesday morning is in the official statistics. The Cyber Security Breaches Survey 2025/2026, published by the Department for Science, Innovation and Technology, found that 43 per cent of UK businesses identified a cyber breach or attack in the previous twelve months. Scaled up, that is around 612,000 businesses. Phishing accounts for the overwhelming majority of it: 38 per cent of all businesses experienced a phishing attempt, and the survey describes phishing as the most prevalent type of breach or attack by far. Nineteen per cent of businesses, roughly 267,000, were victims of cybercrime.
The national picture has moved in the same direction. In its most recent Annual Review, covering 1 September 2024 to 31 August 2025, the National Cyber Security Centre reported handling 204 nationally significant cyber incidents, up from 89 the year before. That is a rise of around 129 per cent, and it works out at roughly four nationally significant attacks every week. Eighteen were classified as highly significant, the third consecutive annual increase in that category. Dr Richard Horne, Chief Executive of the NCSC, put it plainly in the review: “Cyber security is now a matter of business survival and national resilience.”
Why multi-factor authentication is no longer the finish line
The same government survey found that fewer than half of UK businesses, 47 per cent, have two-factor authentication in place at all. That gap matters. But there is a second, quieter problem waiting for the businesses that have already made the investment, and it is one of the reasons Nebulogiq chose MFA bypass as a topic for the first episode.
Attackers have adapted. Adversary in the middle phishing kits now sit between the user and the genuine login page, relay the one time code straight through in real time, and capture the session token that is issued once the login succeeds. From the user’s side, nothing looks wrong. They signed in, the code worked, the page loaded. Meanwhile the attacker is holding a valid session and can walk in behind them. Multi-factor authentication remains essential, and no business should be without it, but treating it as the finish line is now a risk in itself.
Craig Florence, Technical Director at Nebulogiq, said:
“Multi-factor authentication is amazing, and it does genuinely stop almost 99% of all account takeover attacks. But this widespread trust and certainty that MFA is enabled, therefore you are safe and impervious to hackers can be a detriment in its own right. These hackers spend enormous resource and time trying to trick you into bypassing MFA for them. It’s rather like people at train stations waiting for your paid-for ticket to open the barrier, and then they slide right in behind you, or they manage to steal your ticket before you get to use it. As users become complacent that MFA is doing all the heavy lifting, they can stop being vigilant for these kinds of attacks. They might click on that invoice linked in the email, that requires their login credentials in order to view it… or pick up the phone to the ‘IT Department’ and let the hacker in, thinking they were just proving their own identity. That’s why we put precautions in place to make sure MFA is being used, for that 99% protection, but then we target the psychology of the staff to make them your next greatest line of defence. “
The AI dimension
The National Cyber Security Centre’s assessment of the impact of AI on cyber threat to 2027 is measured but firm. It judges that “AI will almost certainly continue to make elements of cyber intrusion operations more effective and efficient, leading to an increase in frequency and intensity of cyber threats.” It also warns of “a digital divide between systems keeping pace with AI-enabled threats and a large proportion that are more vulnerable.”
Businesses are adopting AI considerably faster than they are securing it. The Cyber Security Breaches Survey found 31 per cent of businesses are using, adopting or considering AI, while only 24 per cent have any cyber security practices or processes covering AI related risk.
Darren Senadhira, Managing Director of Nebulogiq, said:
“Attackers are advancing more quickly than many businesses can adapt. AI is now employed to craft more convincing phishing emails, automate reconnaissance efforts, and identify vulnerabilities at a scale previously unattainable. Meanwhile, there are increasingly sophisticated methods aimed at bypassing multi-factor authentication, which many organisations still consider their primary defence.
For regulated industries like legal, healthcare, and financial services, the risks are greater. A breach not only results in financial loss but also damages client trust and may lead to regulatory penalties.
That’s why we’ve partnered with Huntress for this webinar. They see these threats play out across thousands of businesses, and we aimed to bring that frontline knowledge directly to the business owners and leaders we serve. Cybersecurity is no longer just about ticking boxes; businesses must understand the real dangers they face and strengthen their defences appropriately.”
Stuart Humphrey, Managing Director of Phoenix Marketing, added: “I sit outside the security industry, which is perhaps why I find these figures so hard to look away from. Forty three per cent is not a fringe risk, it is closer to a coin toss, and the businesses in that number are ordinary ones handling client data, payment details and supplier relationships every day. We hold client information at our agency. Our suppliers hold ours. Take it seriously is not a slogan for a webinar; it is simply what it now costs to be a responsible business. An hour on a Tuesday morning is a very small price for finding out what you do not know.”
Who should attend
The webinar is aimed at business owners, finance and operations leaders, office managers and internal IT staff at UK organisations of any size. No technical background is assumed. Businesses across Sussex, Surrey, Kent and the wider South East are particularly welcome, though the session is open to attendees anywhere in the UK.
Webinar details
- The Threat Is Out There, Episode 1
- Tuesday 29 September 2026, 10.30am
- Live online via Microsoft Teams
- Free to attend, registration required
- Speakers: Darren Senadhira (Managing Director, Nebulogiq), Craig Florence (Technical Director, Nebulogiq), Sasha Roshan (Senior Sales Engineer, Huntress)
- Register at www.nebulogiq.com/webinar/the-threat-is-out-there
- Attendees who take part in the live Q&A are offered a complimentary security audit
About Nebulogiq
Nebulogiq is a UK managed IT and cyber security provider based in Haywards Heath, West Sussex. The company is Cyber Essentials certified and supports businesses with managed IT support, cyber security, cloud services and security monitoring. Nebulogiq can be found at Delta House, 16 Bridge Road, Haywards Heath RH16 1UA.



