News
Seven years after its predecessor came to market, the Marshall Stockwell III is here — and wow, what a beauty.
From the moment I unboxed the Stockwell III, I was struck by its quality. Its striking amp-inspired aesthetic, complimented by luxurious PU leather, golden detailing, and a red velvet-infused handle made it likeable from the off. But could its sound live up to its enticing looks?
Well, I’ve spent hours upon hours listening to music and messing around with various features on Marshall’s new speaker, and I’ve got a fair few thoughts. So here’s whether it can compare with some of the best Bluetooth speakers around.
Let’s start with sound quality, an area where the Stockwell III is aiming to make quite the leap from its predecessor. Under the hood, you’ll find one three-inch woofer with 65W class D amplification alongside two 1.75-inch wide-band drivers, which both have 31W of class D amplification. This means that the Stockwell III is incredibly mighty for a speaker of its size, and offers considerably meatier audio than its predecessor could.
The Stockwell III’s impressive power really shines through in its performance — it displays a striking level of confidence with regimented, intent-filled bass, driven mids, and expressive highs that make it an incredibly enjoyable speaker to use.
(Image credit: Future)In Home Meeting by Sadao Watanabe, I was impressed with the fluent and colorful leading sax, which played alongside substantial and weighty funky bass and accurate, precise drums in the treble range. As the track built towards its climax, the Stockwell III managed the swathe of instruments with ease, and backing vocals, guitars, horns, and bass all came together in a cohesive yet nuanced ensemble.
With a deeper track, like Vision of Love by Lewis Taylor, the Stockwell III proved that its power goes a long way. Pumping deep bass pounded through our music testing room with intensity, yet remained controlled and clean. Energetic drums high up in the frequency range also came through with plenty of bite, although neither end of the spectrum overshadowed the finer electronic details in the mid-range.
The Stockwell III can extend down to 54Hz, and although it wasn’t capable of the most full-sounding, consuming sub-bass, I still found that it coped decently with ultra-low frequencies. More generally, the speaker does have a bit of a bass preference, and although this may not be to everyone’s taste, a swift turn of the bass dial can easily get you the sound you’re after.
One thing I will say is that although vocals come through clearly on the Stanmore III, they perhaps lack the warmth and texture that you’ll find from some other premium speakers. To be clear, I still found that vocal-focused tracks sounded great on the Stockwell III, but audiophiles may wish for a bit more detail and depth.
As you’d expect with a recent Marshall release, there's USB-C audio onboard for lossless playback, and the speaker sounds great with a wired connection. There’s also a 3.5mm port if you’d prefer. Unfortunately though, there’s no LDAC for higher-res Bluetooth playback — something we recently saw on the Marshall Acton IV and Marshall Stanmore IV — which would’ve been nice to see.
But a couple of features really help the Stockwell III perform at an excellent level. For example, Dynamic Loudness helps the speaker maintain clarity, even at higher volumes, and I found that the Stockwell III still sounded excellent even when pushing volume up to 90% and beyond. Marshall has also implemented its True Stereophonic 360 sound, intended to make sure it sounds excellent from every angle, and this felt effective to me, resulting in the speaker having no true ‘sweet spot’ — ideal for a party situation, say.
One final thing worth pointing out about sound, is that the Stockwell III technically outputs in stereo. However, the stereo effects aren’t particularly convincing — in part due to the Stockwell III’s limited confines.
(Image credit: Future)So the Stockwell III is a hit in the sound quality department. But how does it fare elsewhere?
Well, when it comes to features, there are quite a few options to uncover. For the moment, the Stockwell III is using the older Marshall Bluetooth app, unlike the newer Marshall software harnessed by the Acton IV, Stanmore IV, and Heston soundbars. This means that you only get a five-band EQ, though this still works well — and the speaker does sound great out of the box.
The app also enables you to use a soundstage mode to reduce or expand the width of sound, you can toggle on Source Mix to play media via wired and Bluetooth connections simultaneously, and you can map a specific EQ configuration to the speaker’s M button. In addition, there’s a placement compensation feature that genuinely makes a difference, as well as USB-C port configuration settings (you can make it charge other devices, play media, or both), and battery preservation options.
Speaking of battery, the Stockwell III is capable of providing 40 hours of playback — double what its predecessor could manage. That’s a phenomenal amount of playtime for a speaker of this size, and a seismic technological advancement, proving that Marshall are still one of the leading audio manufacturers when it comes to battery life.
I’ve spoken a bit about design already, but the Stockwell III is a true joy to behold. It’s also a lot lighter than Marshall’s alternate mid-weight speaker, the Marshall Middleton II, making it feel way more portable. It's also got more amplification power than the Middleton II and in my view, looks more premium — it’s the better mid-weight option overall in my view.
However, this does come at the expense of weaker waterproofing — the Middleton II is IP67 rated, whereas the Stockwell III is only IP55. That's still an improvement on its IPX4-rated predecessor and keeps it protected against splashes and dust ingress, but a lot of competitors shield their devices against full underwater submersion.
But let’s wrap up now. At $249.99 / £199.99 / AU$379, the Stockwell III isn’t the cheapest option on the market, but for its power, and its sound and build quality, it's an excellent value for money choice. At launch, the Stockwell II was priced the same as this new model in the US, but it's actually cheaper in the UK and Australia than its predecessor was at the point of release. With the improvements in acoustics, build, and waterproofing, that’s amazing to see.
Although the Stockwell III leaves out LDAC and is using the older Marshall Bluetooth app at the moment, I still think it’s a brilliant speaker. With confident yet elegant sound, amazing looks, and a fantastic feature-set, it's the best mid-weight Marshall speaker you can buy, and stands as a stellar upgrade over the Stockwell II.
(Image credit: Future)Marshall Stockwell III review: price & release date- Priced at $249.99 / £199.99 / AU$379
- Released in August 2026
The Marshall Stockwell III was released in August 2026, seven years after the Marshall Stockwell II came to market. It's priced at $249.99 / £199.99 / AU$379, meaning that in the US it costs the same as the Stockwell II did at launch, and it's actually cheaper in the UK and Australia. Considering the vast improvements it provides, that makes it a phenomenal value for money option. It’s available in Black and Brass or in Cream.
Marshall Stockwell III review: specsWeight
2.9 lbs / 1.3kg
Dimensions
17.1 x 5.9 x 2.8 inches / 181 x 150 x 72mm
Connectivity
Bluetooth 5.3, 3.5mm, USB-C
Battery life
40 hours
Speaker drivers
1x 3-inch woofer with 65W class D amplification, 2x 1.75-inch wide-band drivers with 31W class D amplification
Waterproofing
IP55
(Image credit: Future)Should I buy the Marshall Stockwell III?Attribute
Notes
Score
Features
Great connectivity options, feature-rich app, but still using the old version, great battery life.
4.5/5
Performance
Excellent bass, clear mids, and clean highs.
4.5/5
Design
Gorgeous looks, a more portable than the Middleton, but waterproofing not as good.
4.5/5
Value
Same price as predecessor with meaningful improvements, great price for the power and quality on offer.
5/5
Buy it if…You want a super-stylish speaker
The Stockwell III is a gorgeous speaker with enticing PU leather, golden detailing, and a stylish handle. If you want style that matches substance, this is a great option.
You want a powerful yet portable speaker
The Stockwell III is crammed with plenty of amplification power, but it's still highly portable and relatively lightweight. That’s the main reason I’d pick it over a model like the Marshall Middleton II.
You want a speaker with higher-res Bluetooth codecs
Although the Stockwell III features USB-C audio and a 3.5mm input, it skips on aptX and LDAC. The latter has been seen on a few of Marshall’s recent releases, so it would’ve been great to see on the Stockwell III.
You want the ultimate waterproof speaker
The Stockwell III is protected from dust ingress and water splashes, but there are rivals with even better waterproofing on the market. For instance, the Bang & Olufsen Beosound A1 3rd Gen has an IP67 rating, meaning it can be submerged under a meter of water for up to 30 minutes.
Marshall Stockwell III
Bang & Olufsen Beosound A1 3rd Gen
JBL Charge 6
Price
$249.99 / £199.99 / AU$379
$349 / £299 / AU$639
$149 / £129 / AU$229.95
Weight
2.9 lbs / 1.3kg
1.27 lbs / 576g
3 lbs / 1.4kg
Dimensions
17.1 x 5.9 x 2.8 inches / 181 x 150 x 72mm
5.2 x 1.8 x 5.2 inches133 x 46 x 133mm
9 x 3.9 x 3.7 inches / 229 x 99 x 94mm
Connectivity
Bluetooth 5.3, 3.5mm, USB-C
Bluetooth 5.1, USB-C
Bluetooth 5.4, USB-C
Battery life
40 hours
24 hours
24 hours (28 hours with PlayTime Boost)
Speaker drivers
1x 3-inch woofer with 65W class D amplification, 2x 1.75-inch wide-band drivers with 31W class D amplification
1 x 0.6-inch tweeter; 1 x 3.25-inch woofer, each with 1 x 30W Class D amplification
53 x 93 mm mid/bass 'racetrack' driver, 20mm tweeter
Waterproofing
IP55
IP67
IP68
Bang & Olufsen Beosound A1 3rd Gen
This luxurious speaker sounds absolutely spectacular, and it's one of the best-looking models I’ve tested. It’s pricey, but for the quality you get back in return — both sonically and in terms of build — it's well worth checking out. Read our full Bang & Olufsen Beosound A1 3rd Gen review.
JBL Charge 6
With mighty sound, impeccable waterproofing, and a swath of features, the JBL Charge 6 was fully deserving of the five stars that we awarded it last year. If you want something a little cheaper, albeit slightly less premium-looking, this is my top recommendation. Read our full JBL Charge 6 review.
- Tested over a week-long period
- Mainly streamed tracks over Tidal
- Predominantly made use of Bluetooth and USB-C connectivity
I tested the Marshall Stockwell III over the course of a week, spending hours listening to music and exhausting its various features. I mainly had it connected to my Xiaomi 17 phone, where I streamed tunes over Tidal — predominantly using Bluetooth and USB-C connectivity.
When listening to music, I made sure to play tracks from a wide variety of genres — both from the TechRadar reference playlist and from my own personal library.
More generally, I’ve spent years testing audio gear here at TechRadar, where I serve as our in-house Senior Reviews Writer. I’ve tested all kinds of gadgets, from premium wireless headphones like the Sony 1000X The Collexion through to Dolby Atmos soundbars like the LG Sound Suite Immersive Suite 7 Pro. I’ve also reviewed countless Marshall speakers, including its recent Homeline releases, so I know exactly what to look for when putting the audio specialist’s tech to the test.
- Read TechRadar’s reviews guarantee
- First reviewed: August 2026
Artificial intelligence is entering a new phase, one defined not by experimentation, but by operational deployment in environments where the stakes are high and the margin for error is narrow.
Nowhere is this shift more visible than in critical services such as healthcare, where organizations are beginning to rely on AI not just for efficiency gains, but for decisions that directly affect lives, outcomes and public trust.
As a result, the conversation around AI capability is expanding, and there’s a real need for AI systems to be sovereign, trusted and aligned to the legal, ethical and operational frameworks of the jurisdictions they serve.
Sovereign AI is emerging as a response to this need.
It is not a marketing term or a technical preference; it is a structural requirement for organizations that operate under strict regulatory oversight and handle sensitive citizen data.
For these sectors, sovereignty is the mechanism that ensures AI systems remain under the control of the people and institutions accountable for their outcomes.
Data residencyThe distinction between data residency and true sovereignty is central to this shift. Data residency simply describes where data is stored or processed. It is a geographical statement, not a legal one. Data sovereignty, by contrast, defines who controls the data, who can access it and which laws apply. It is a statement of legal authority and operational control.
Sovereign AI goes further still. A sovereign by design AI system ensures that every stage of the AI lifecycle, from training and fine tuning to inference, deployment and monitoring, sits entirely within the sovereign perimeter. This includes the IT infrastructure, the data pipelines, the model governance processes and the personnel who operate and maintain the system. Nothing crosses borders, and nothing falls under the jurisdiction of external authorities.
For critical services such as national healthcare systems, this level of assurance is not optional. These organizations must protect patient confidentiality, maintain public trust and comply with regulatory frameworks that are among the most stringent in the world. They cannot rely on AI systems whose training data is opaque, whose operational footprint spans multiple jurisdictions or whose governance structures are not aligned to local laws.
They need systems that are transparent, explainable and auditable, systems that can demonstrate not only what they do, but how and why they do it.
Regulated sectorsThis is one of the reasons why organizations in regulated sectors are increasingly looking beyond general purpose AI models. These models have driven much of the recent excitement around AI, but they are not always suitable for environments where accuracy, safety and accountability are paramount.
Their training data is broad and often scraped from the open internet. Their provenance is difficult to verify. Their operational controls vary widely. And their governance frameworks are not always designed with regulatory compliance in mind. In contrast, domain specific AI models built on trusted, curated datasets offer a level of precision and contextual understanding that general purpose models struggle to match.
They can be aligned to clinical workflows, diagnostic pathways and sector specific terminology. They can be governed with the level of transparency and auditability that regulators increasingly expect. And when built within a sovereign architecture, they can operate entirely within the legal and ethical boundaries required by critical services.
The rise of sovereign AI signals a broader transformation in how regulated sectors will adopt and govern AI over the next decade. AI architectures will become more localized, with sovereign cloud regions, isolated compute environments and jurisdiction specific MLOps pipelines becoming the norm. Governance will become as important as model performance, with explainability, auditability and lifecycle control treated as first class requirements.
Regulators will demand greater transparency around model provenance, training data lineage and operational controls. And AI supply chains, from data ingestion to model deployment, will be scrutinized with the same rigor applied to other critical infrastructure.
What this future looks likeHealthcare offers a clear illustration of what this future looks like. When deployed responsibly, sovereign AI can automate clinical workflows while maintaining strict data protection, support diagnostic decision making with transparent and explainable models, improve patient flow through predictive analytics and optimize resource allocation across hospitals and care pathways.
By reducing administrative burden and helping ensure patients are directed to the most appropriate care pathway more efficiently, it also has the potential to improve productivity and support better use of constrained healthcare resources.
It can also enable population level insights without compromising privacy, allowing healthcare systems to plan more effectively and respond more rapidly to emerging challenges. These benefits are only achievable when the underlying AI systems are trusted, transparent and sovereign.
Sovereign AI represents a turning point in how critical services approach digital transformation. It acknowledges that trust, governance and domain expertise are just as important as model capability.
It recognizes that AI must be built to serve the needs, values and legal frameworks of the communities it supports. And it reflects a broader truth: as AI becomes more deeply embedded in essential services, sovereignty will not be a niche requirement. It will be the standard.
Check out our list of the best cloud backup services.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
The reality for many organizations is that their employees are already being deceived. So, probably are their customers, their investors, and their board.
For years, the warnings have focused on the impact of deepfakes, such as fake CEOs on video calls, cloned voices authorizing payments, and fraudulent emails.
The tactics themselves are not new, but over the past few years, AI has made them cheaper to produce, harder to spot, and far more convincing within the ordinary flow of business.
It’s this trend that means that the principle of Zero Trust is becoming as relevant to how information is treated as it has been to access.
In cybersecurity, Zero Trust starts from a simple assumption: no user, device, application or request should be trusted by default.
In the age of AI-generated misinformation, businesses need to apply that same mindset to the information that moves throughout their organization.
The new trust crisisEmployees, customers, investors and partners are all making decisions based on what they see, read and hear. If that information is false, manipulated or stripped of context, the consequences can move quickly from confusion to commercial damage. Which is why misinformation, disinformation, and malinformation need to be treated as business risks.
Misinformation – the false content that spreads without deliberate intent – has always been an issue. Disinformation, constructed specifically to deceive, is now easier to manufacture at scale than ever before. And malinformation – true information, often deliberately stripped of context and weaponized – might be the most insidious of the three. A competitor, a criminal group, or an activist campaign no longer needs to breach a network to cause serious damage. They can influence those associated and concerned with an organization simply by shaping what those people see and believe.
What makes this particularly difficult for businesses is that it mirrors something individuals are already struggling with. In an environment saturated with AI-generated content, the habits that people must employ to protect themselves – pause before reacting, questioning the source, verifying before acting – are the same habits that organizations must build into how they operate.
Essentially, the instinct to trust has become a vulnerability. And addressing that requires something closer to a structural response than an awareness campaign.
The importance of verified trustThis is where Zero Trust becomes the strategy. Traditionally, organizations have thought about Zero Trust through the lens of least privilege, ensuring that the right users have access to the right applications, and nothing more. But in an AI-driven information environment, that principle needs to evolve. Businesses can no longer focus just on who is requesting access. They also need to interrogate what information is being used, what action is being taken, and whether the intent behind the action can be trusted.
The next stage is going beyond authentication and investigating authenticity, and asking questions such as “Is this information verified?”, “Is this image real or AI-generated?”, and “Has this content been edited?”. Zero Trust gives businesses a framework for answering those questions. It forces organizations to verify before they act, limit exposure where they can, and reduce the risk of false, manipulated, or decontextualised information moving unchecked through the business.
Standards bodies such as the C2PA (Coalition for Content Provenance and Authenticity) show the direction that this is heading: a future where provenance and integrity are embedded in digital content itself, the same way a padlock in a browser indicates that the connection is secure. Essentially trust won’t be something that businesses need to check for, rather it will be something that travels with the information as provenance feeds verifications. Every piece of content therefore becomes a signal in a continuous trust decision.
Developing Trust in the agentic eraThe need to trust intent has become even more pressing as AI agents enter the workplace. These agents will increasingly operate like another person working alongside us, mirroring our behaviors, such as reading documents, interpreting data, making decisions, and acting. The difference, however, is that these non-human identities are moving at machine speed, where human-speed verification has no hope of keeping up.
That means AI agents must be governed through a Zero Trust model from the outset. An agent should not be trusted just because it sits inside the enterprise, has been approved by a user, or is connected to corporate systems. Its identity, permissions, behavior and outputs all need to be continuously validated. Just as importantly, agents should be governed by least privilege, the principle of least information, and least function, granting only the minimum access, data, and capability required for a specific task.
However, these agents create a trust challenge that identity management alone can’t solve. Businesses will need to know whether they are dealing with a human or a machine, whether an agent is behaving responsibly, and whether its actions reflect an organization’s values and boundaries. Effectively, businesses will need to adopt an operating constitution that agents are continuously measured against.
And in this AI era, enterprises must interrogate information, content, intent, behavior, and action in realtime and continuously as identity is generally just checked as front door access. However, given the scale of the task at hand, it will take AI to audit, flag, and govern as needed and keep the chain of trust intact.
Engineering trust into the businessThe organizations that succeed will be those that treat trust as something to be engineered, rather than assumed. Misinformation, disinformation, malinformation are security, resilience, and leadership challenges, and AI is making them harder to ignore.
As technology continues to shape how information is created, shared, and acted upon, businesses need to build the same discipline around authenticity that they’ve always applied to access. That means verifying content, questioning intent, and limiting what AI systems can do to what they actually need to do.
Trust can no longer be the default setting. Instead, in today’s operating environment, it must be a decision that’s made continuously, at machine speed, across information, intent, behavior, and action. The good news is that the framework already exists in Zero Trust. What needs to change however is how organizations apply it, broadening the scope to include information, intent, behavior, and action.
We've reviewed, rated, and ranked the best internet security suites.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
- UK workers could unlock more than three weeks of unproductive time a year by embracing flexible working
- However many say they aren't confident in their mobile networks
- Boosting connectivity could lead to a potential £115 billion productivity boost to the UK economy
Embracing flexible working could help give the British economy a major boost, and unlock productivity across the nation, new research has claimed.
A report from VodafoneThree says boosting "connectivity confidence" to work on the go could help unlock more than three weeks of unproductive time a year, leading to a potential £115 billion productivity boost to the UK economy.
However, the report noted this all depends on being more confident in such mobile working, which can only happen if the UK's mobile networks are resilient and reliable enough.
No more wasted timeThe study, which surveyed 2,000 adults across the UK, found a third of Brits feel they are unable to leave their home or office Wi-Fi to get things done on-the-go, while almost half (46%) spend most of their working day at a desk.
Nearly half (43%) of those with a job said they would prioritise working on the move if they felt more confident in the quality of the UK’s mobile networks, with accessing and collaborating on work documents, taking calls on commutes and joining remote NHS consultations from phones all named as big tame savers.
British workers said they wasted almost two hours a week being unproductive on the commute, and over an hour sitting in waiting rooms and waiting to pick up children or dependents - wasted time which totals more than 10 hours a week, more than France, Germany, Spain, Australia, Singapore, Hungary and South Korea.
The lack of flexibility even extend into the weekend, as more than a third (34%) said their weekend to do list would be shorter if they could be more productive on the go, with booking all GP appointments through apps or their phones (23%), pay utility bills (27%) and book tickets on-the-go (16%) also named as tasks which could benefit from better connectivity.
“Boosting the UK’s productivity doesn’t have to mean spending more hours behind our desks," noted Andrea Donà, Chief Network Officer at VodafoneThree. "But to change the way the nation works, we need mobile networks that keep us connected to colleagues, technology and essential services on the move."
“The UK Government is rightly taking this issue seriously. With improvements to the planning system and regulations fit for the digital economy, our networks can help to make public services more accessible, close digital divides and lay the foundations for growth.”
The survey comes as VodafoneThree looks to continue its rollout of a UK-wide £11 billion investment programme to help raise the speed and quality of connectivity across the country following its merger with Three in 2025.
The company hopes this expansion will bring 5G Standalone coverage to 99% of the UK population by 2030, and 99.96% by 2034, helping millions of people to work, shop and access public services seamlessly.
The prospect of bringing more of Britain's critical national infrastructure into public ownership has prompted plenty of debate about investment, governance and accountability.
Far less attention has been paid to what it could mean for cybersecurity.
Regardless of where you stand politically, one thing is clear. Public ownership does not make cyber risk disappear.
If anything, it raises expectations that essential services will be more resilient, more coordinated and better prepared to withstand disruption.
That expectation reflects the reality of the threat landscape. Energy providers, water companies, transport operators and healthcare organizations all sit at the center of complex digital ecosystems. Their ability to deliver essential services depends on thousands of suppliers, technology vendors and third parties.
When one organization is compromised, the effects can spread well beyond its own network. Resilience therefore depends on far more than protecting individual organizations. It depends on understanding and managing the relationships between them.
If the government is serious about strengthening national infrastructure, cybersecurity must become part of that conversation from day one. That means moving beyond isolated security programs and towards a model where organizations share intelligence, understand common risks and coordinate their response before disruption spreads.
Critical infrastructure extends beyond organizational boundariesSome of the defining cyber attacks of recent years have demonstrated that attackers are rarely interested in a single target. They look for opportunities to compromise one organization in order to reach many others.
The SolarWinds attack remains one of the clearest examples. By compromising trusted software updates, attackers gained access to thousands of organizations around the world. More recently, the ransomware attack on Synnovis disrupted pathology services across several NHS trusts, leading to cancelled operations, delayed appointments and widespread disruption to patient care.
Neither incident remained confined to the organization that was initially compromised. Both exposed the reality that critical infrastructure now depends on interconnected supply chains as much as physical assets.
That presents a challenge for every operator of critical national infrastructure. Security can no longer be viewed solely through the lens of protecting your own estate. Organizations also need visibility into the threats affecting suppliers, partners and the wider ecosystem. A vulnerability within a software provider or outsourced service can quickly become a problem for every organization that depends on it.
This is where many existing security programs begin to show their limitations. Organizations have invested heavily in detection technologies, vulnerability management platforms and threat intelligence feeds. They are collecting more information than ever before. Yet many still struggle to translate that information into confident operational decisions.
Better decisions start with better intelligenceThe cybersecurity industry has spent years focusing on visibility. The assumption has been that if organizations can discover every vulnerability, identify every asset and collect every threat feed, they will naturally become more secure.
The evidence suggests otherwise.
Filigran's recent State of Threat Management report found that organizations consume an average of fourteen different threat intelligence feeds, yet fewer than half have fully operationalized that intelligence across their security programs.
At the same time, 84% of respondents said the attacks they experience exploit risks that were already known but had not been prioritized. Almost every organization surveyed also reported difficulty determining whether identified exposures were genuinely exploitable.
Those findings illustrate a wider industry problem. The challenge is no longer discovering risk. It is deciding which risks deserve immediate attention.
Security teams are surrounded by alerts, vulnerability reports and intelligence updates. Every tool claims to identify another critical issue demanding urgent action. Without context, everything starts to look important. Analysts spend valuable time investigating vulnerabilities that may never be exploited while genuinely dangerous attack paths remain hidden among the noise.
That has consequences beyond operational efficiency. Every hour spent investigating a low priority issue is an hour that cannot be spent reducing real business risk. Organizations are not simply overwhelmed by the volume of information. They are overwhelmed by the number of decisions they are expected to make every day.
Threat intelligence should shape decisions long before an incidentOne reason this happens is that threat intelligence is still too often treated as a function of the Security Operations Centre. Intelligence is gathered, analyzed and used to help detect or investigate malicious activity once attackers have already reached the network.
Yet, threat intelligence has far greater value when it informs decisions much earlier in the security lifecycle.
Used effectively, it should help organizations understand which vulnerabilities are actively being targeted, which attack paths present the greatest business risk and which remediation activities will deliver the greatest reduction in exposure. Rather than treating every vulnerability as equally urgent, security teams can focus on the threats that genuinely matter to their environment.
This is also where Continuous Threat Exposure Management, or CTEM, has an important role to play. CTEM should not be viewed as another technology category or another security acronym. It provides a structured framework for connecting threat intelligence, exposure management, validation and remediation into a continuous process. Instead of relying on assumptions or theoretical risk scores, organizations can validate whether a vulnerability is genuinely exploitable before committing time and resources to fixing it.
Perhaps the biggest obstacle is not technical at all. Many organizations still operate with threat intelligence, vulnerability management, penetration testing and governance teams working independently, each with different priorities, processes and tooling. Breaking down those silos often delivers greater improvements than introducing another security platform.
Building a national capabilityIf critical infrastructure is expected to become more resilient, collaboration has to become part of everyday operations rather than something that only happens during a major incident. That thinking is already beginning to take shape.
Earlier this month, the National Cyber Security Centre and GCHQ issued a call for industry, academia and critical infrastructure operators to help define Cyber Shield, a proposed national cyber defense capability designed to combine AI, shared intelligence and coordinated defense at national scale.
Significantly, the initiative recognizes that the government cannot build this capability alone. It will depend on close collaboration with the organizations responsible for protecting the UK's essential services.
Additionally, the Cyber Security and Resilience Bill provides an opportunity to strengthen that approach by encouraging greater consistency across essential sectors. Frameworks such as the National Cyber Security Centre's Cyber Assessment Framework already give organizations a common language for measuring resilience.
They become even more valuable when they encourage organizations to learn from one another instead of tackling similar challenges in isolation.
Open standards have an important role to play as well. The Dutch National Cyber Security Centre recently made STIX and TAXII 2.1 the mandatory standard for sharing cyber threat intelligence across government.
While technical on the surface, the decision reflects a broader principle. When organizations exchange intelligence using common standards, they remove friction from collaboration and can respond to threats more quickly.
Technology alone will not deliver that outcome. Artificial intelligence, automation and modern security platforms can help organizations process more information and reduce manual effort, but they still depend on good intelligence, sound governance and trusted relationships.
For the simple reason that fast decisions only become good decisions when they are supported by the right context.
Resilience is a shared responsibilityWhether more of Britain's critical national infrastructure ultimately moves into public ownership is only part of the story. Cyber attackers do not distinguish between public and private organizations. They target weak links, trusted suppliers and interconnected systems wherever they find them.
The organizations that will be best prepared for the years ahead will be those that treat resilience as a collective responsibility. They will operationalize threat intelligence before incidents occur, validate real-world risk rather than relying on assumptions, and collaborate across organizational boundaries as readily as attackers do.
Protecting critical infrastructure has never been solely about defending individual organizations. It is about strengthening the entire ecosystem that keeps essential services running. If the UK wants to build genuinely resilient national infrastructure, that is where the conversation needs to begin.
We've listed the best path management software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
As global supply chains remain exposed to geopolitical and climate uncertainty, retail and consumer packaged goods (CPG) businesses face challenges of fluctuating prices and demand. In the United Kingdom, supply chain volatility is adding to uncertainty in raw material and packaging costs to impact CPG companies’ production economics.
Research has found that a huge majority of British retailers were not confident of scaling up their supply chain operations to meet the expected increase in consumer demand. In fact, 43% of retail leaders ranked supply chain issues among their top three business challenges in 2025, highlighting widespread concern over operational capacity in the face of rising demand and cost uncertainty.
Retail and CPG businesses can address these problems by modernizing fragmented and often inflexible systems to improve data visibility, analysis and automation across their supply chains.
Artificial Intelligence (AI) and Machine Learning (ML) technologies are imperative to this agenda: packing powerful capabilities - including data integration, automation, demand sensing and intelligence - AI and ML are redefining retail and CPG operations by enabling seamless, autonomous ecosystems.
Connected platform to satisfied customerConnected supply chains provide transparency to allow organizations to manage operations and inventories in real-time to improve stock allocation and ordering efficiency.
Intelligent algorithms also analyze vast and varied data – from historical sales and seasonality to weather, social media trends and local events – to accurately forecast demand, preparing supply chains for changing ordering patterns.
Forewarned, businesses can rapidly adapt production and distribution strategies in case of a surge in demand or supply disruption. AI and ML automate a variety of supply chain tasks to speed up processes, reduce errors and save costs. Ensuring product availability at all times, retailers and CPG companies in the U.K. can look forward to greater customer satisfaction and loyalty.
Real-time, for responsiveness and resilienceReal-time insights are critical to supply chain operations. Live data from Point of Sale systems, ecommerce platforms, etc. provide up-to-date insights into customer preferences and behaviors to improve demand forecasting and also allow companies to dynamically adjust stock levels across warehouses and stores to meet sudden demand.
Real-time analytics solutions highlight product performance by region, channel and even outlet, enabling retailers to optimize assortments and launch targeted promotions. By providing continuous visibility into the supply chain, AI allows CPG companies to anticipate demand shifts and disruptions to curtail risk and maintain supply chain resilience.
Precise prediction drives product fulfilmentAI and ML platforms have superior predictive capabilities: they go beyond general demand forecasting to predict exactly what customers want, and when, and can even proactively trigger replenishment orders before stocks run out. Algorithms are not only more efficient at spotting patterns and making projections than traditional analysis, but are even capable of adjusting forecasts based on micro-trends.
By enabling CPG and retail companies to ensure that the right product is at the right place at the right time, AI and ML mitigate loss of sales due to stockout; save labor, warehousing and other costs; and improve product availability across physical and digital channels, leading to superior customer experience.
The future is autonomousAgentic AI-powered autonomous supply chains are taking operational efficiency and customer engagement to new heights by anticipating demand, optimizing inventory, and orchestrating various tasks with little or no human intervention.
Autonomous systems meet the digital consumer’s expectation of frictionless, enjoyable experiences by personalizing product and delivery options and continuously optimizing logistics and transportation routes to allow faster/ on-time delivery.
Upon anticipating a delay, AI agents can take proactive measures – rerouting a shipment or suggesting an alternative supplier, and updating customers about the status of their orders to avoid frustration. By enabling full traceability to allow customers to track their orders any time, autonomous supply chains build trust and engagement.
Last but not least, by optimizing inventory and logistics operations, autonomous supply chains reduce waste and energy consumption, and support ethical sourcing through clear visibility. Agile, proactive, and sustainable – that is what the future of retail and CPG supply chains looks like.
We've featured the best AI tool.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
- We've heard countless rumors about camera-toting AirPods
- Now, a leaked video reportedly from MacOS build shows how they'd work
- Public opinion on this kind of tech is poor, and getting worse
We've been hearing countless rumors that Apple is working on AirPods with cameras — last news was that they could come in 2027 — and now we have an idea as to how they could work.
Website MacRumors has uncovered a video found in pre-release code for MacOS Tahoe 26.7, an upcoming update to Macs' operating system.
The video shows an AirPods-wearing man pick up a book and look at it, while a female voice says: "With visual intelligence, your world becomes saveable. See something you like? Just ask me to save it for later."
Here is your first look at AirPods with Cameras in action using Visual Intelligence.This video file came from macOS 26.7 RC pic.twitter.com/yo7RI4MCeuAugust 18, 2026
Finally, we have a way to remember things! How has humanity got to this point without that...
Visual Intelligence is an Apple feature, which uses an iPhone camera to see what's going on around you. And apparently, it's coming to AirPods, when they get cameras.
This video doesn't look like leaked marketing material for the new AirPods; the production value doesn't match other Apple material. It looks like it was shot on an iPhone, with exposure that's all over the place. But it could be a placeholder, or perhaps an internal video.
It's also unlikely that the AirPods used in the video are the new camera-toting ones; again, these are probably just placeholder buds. Instead, this news shows us what Apple thinks these new buds will do: act as extensions of AI tools like Visual Intelligence. And that might be their downfall.
A bad time for all-seeing tech(Image credit: Future)Some journalists have written that always-watching smart tech, especially smart glasses, are facing a reckoning. That's no longer quite true: they've faced said reckoning, the great privacy revolt has reached its conclusion, and opinion now couldn't be sourer on this kind of surveillance gadget.
In the UK, smart glasses have been banned from courts, restaurants, theaters, and even the pub chain Wetherspoons (there's nowhere lower to go than being kicked out of a 'Spoons'). Their disparaging moniker, "pervert glasses", is now used more commonly than their actual name, and they're frowned upon even more in the court of social opinion than in actual courts.
Okay I hate to be that guy but… who’s asking for thisAugust 18, 2026
The reason for this low public opinion — well, one of many — is smart glasses' use of cameras. Since the user could be recording video or taking pictures, without anyone else knowing, they're a privacy nightmare. And since legislation can take an age to come into effect, it's easier just to socially ostracise people who might be recording you without your knowledge.
And so, AirPods coming with cameras would be a truly awful look, as it'd get them lumped in with smart glasses. Even if the buds don't actually let you capture footage, and only use their cameras for object recognition, the very presence of visible cameras will get them lumped in with smart glasses: "pervert earbuds".
And that's notwithstanding the real chance — as has been demonstrated with those glasses — of Apple's earbuds being appropriated by tech-savvy individuals, to somehow get the cameras working (despite the buds' presumed low-res quality that Apple doesn't mean for video capture).
As I've written in the past, these things aren't designed to take pictures. They are for analyzing your surroundings. https://t.co/r7IFNmsoE4 https://t.co/tjmS7w8tlJAugust 18, 2026
Disregarding the scant use cases of camera-toting smart glasses, camera-toting AirPods would launch amid a storm of negative attitudes to this kind of tech. It's a risk and could even be seen as a potential lose-lose situation for Apple: either release a product that's dead on arrival, or one that is popular but helps to distribute and normalize "pervert" tech.
Maybe the sentiment one X user posted, "I hate to be that guy but… who's asking for this?" sums it up nicely. It could be that at this point, we don't need these AirPods, guys. And perhaps Apple could instead put its R&D efforts towards earbuds with a competitive battery life…
- Sony CEO Hiroko Totoki says a release date for the PS6 has yet to be decided
- The global component shortage and trade wars have impacted Sony's decision-making
- Totoki says, "We need to take some action. Otherwise, we cannot survive in this landscape"
Sony CEO Hiroko Totoki has confirmed that the PlayStation 6 release date remains undecided due to the ongoing manufacturing component crisis and trade wars.
During an interview with The Wall Street Journal (via VGC), in which Totoki primarily discussed the company's television and movie business, the CEO briefly touched on the PS6 and the challenges of developing the next-generation PlayStation console.
Namely, the global RAM crisis, driven primarily by the rapid demand for AI data centers and seeing prices skyrocket, and the ongoing trade wars.
"Considering that importance, we need to take some action. Otherwise, we cannot survive in this landscape," Totoki said.
Analysts have previously predicted that the PS6 could launch in 2027, which The Wall Street Journal also mentioned in its interview; however, due to the component shortage, Sony hasn't decided the launch date internally.
"Totoki said the company still hasn’t fixed a date for PS6’s launch," The Wall Street Journal states.
Totoki last spoke about the PS6 in May but was hesitant to share anything about the console, saying that the current circumstances regarding the RAM crisis, "memory price is also expected to be very high [in] FY 2027."
"We have not yet decided on at what timing we will launch the new console, or at what prices," Totoki said at the time. "So we would like to really observe and follow the situation.
"Looking at the current circumstances, the memory price is also expected to be very high [in] FY 2027, because there will still be a shortage of supply. So under that assumption, we must think carefully what we will do."
There have also been numerous claims from industry insiders, such as Moore's Law is Dead, who have suggested a 2027 launch date as well, and even claimed that Sony will launch its next-generation PlayStation with three devices in 2027, including two consoles and a companion handheld.
Recent comments from Sony Interactive Entertainment CEO Hideaki Nishino also seem to suggest that the next-generation PlayStation console could be a handheld.
However, Following Sony's announcement that it will end the production of physical game discs in January 2028, analysts have determined that the next-gen PS6 console will launch in 2028.
According to Ampere analyst Piers Harding-Rolls, the all-digital plan telegraphs Sony's upcoming plans, and the "current expectation is that the console will launch at the end of 2028."
The analyst also suggested that "at a minimum," the standard version of the PS6 won't have a physical media disc drive since Sony will be looking for ways to reduce the cost of its next-gen hardware, and "this is an easy win."
For years, cybersecurity has become increasingly measurable. Security leaders can often tell you how long it takes to detect an intrusion, contain an attack and restore normal operation. Those figures have given boards a straightforward way to judge progress, offering reassurance that investment in security is delivering real improvements.
Metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) have earned their place at the table. They both provide a clear picture of how effectively security teams perform when something goes wrong and have helped drive better incident response across the industry.
The problem is not that these metrics are wrong. They were designed for a different era, when technology changed more slowly, attack methods evolved over longer timescales and AI wasn't yet part of the equation.
Today's businesses are introducing new technologies at an extraordinary pace. AI is becoming embedded across organizations, cloud environments continue to expand and businesses are more interconnected than ever before. At the same time, attackers are constantly adapting their own techniques, taking advantage of new tactics and tools almost as quickly as they emerge.
CISO’s and boards need to dynamically review the changing threat landscape and risk posture and ask themselves whether the metrics relied on for years still tell us everything we need to know.
Mind the gapEvery business wants to detect attacks sooner, contain them faster and recover with minimal disruption. That’s why MTTD and MTTR remain valuable operational measures. They tell us how effectively a security team performed once an incident was underway.
What they don't tell us is whether the business is becoming better prepared for what comes next, more resilient, more agile in recovery. That matters because cyber risk continues to evolve long after an incident has been contained.
The UK Government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses experienced a cyber breach or attack during the previous year.
This reinforces how security teams are operating in an environment where incidents are a regular reality, whether it's in their own environment, or that of one of their supply chain. Responding well is important, but resilience is shaped by everything that happens before incidents.
A business may recover quickly from an attack but still take months to review its security policies, reassess supplier risk or strengthen controls in response to what it has learned. By the time those changes are made, the threat landscape will have moved on.
Traditional metrics tell us how quickly a business responds to an incident. They don't tell us how quickly it learns from one, or how quickly it adapts.
Closing the gapIf we're going to close that gap of preparedness, our metrics need to evolve as well. Resilience is no longer defined solely by how well a business responds to isolated incidents, but by how quickly it keeps pace with continuous change.
I believe organizations should start thinking about another benchmark alongside the ones we already know: Mean Time to Adapt (MTTA).
MTTA considers how long it takes to recognize a meaningful change in the threat landscape and turn that knowledge into action.
Sometimes that action will be technical. It could mean updating the rules security tools used to detect emerging attack techniques. Or it might involve tightening access to critical systems after a serious vulnerability is discovered. It may also be a proactive lessons learned view of an attack on another organization or sector to understand how vulnerable the organization would be.
In other cases, the response will be organizational rather than technical. It may involve reviewing governance, changing how cyber risk is reported to the board or refreshing employee awareness programs to reflect the latest tactics being used by attackers.
Either way, resilience depends on both. The strongest security programs combine technical improvements with organizational change, ensuring businesses can recognize change and act on it quickly.
That’s why closing this gap is not only a technology challenge. It relies on decision-making, leadership and a willingness to keep questioning whether existing assumptions still hold true. Businesses that adapt well rarely assume their current security program is finished. They expect it to evolve because the environment around them is evolving too.
That thinking is increasingly reflected across the wider industry. For example, the National Cyber Security Centre's Cyber Assessment Framework places governance, risk management and continual improvement at the heart of cyber resilience. It recognizes that security is an ongoing organizational capability, not a one-time achievement.
A different conversation in the boardroomIf preparedness and adaptation becomes a more meaningful measure of resilience, it will change the conversations taking place in the boardroom.
Most directors already receive regular updates covering incidents, phishing activity and response times. Those reports remain important, but they won’t always show how well the business is responding to change itself.
The discussion must now move beyond operational reporting and give greater prominence to MTTA. This would give boards a way to measure how quickly an organization responds to change, rather than simply how efficiently it handles incidents.
In practice, that means asking a different set of questions. How quickly does the business reassess risk when a significant new threat emerges? How long does it take for new intelligence to shape security policies? Have lessons from recent attacks fundamentally changed the way the organization operates, or have they simply been recorded and filed away?
By measuring adaptation, rather than response alone, organizations can answer these questions with greater confidence and build a broader picture of resilience.
And this isn't solely a question for security teams. It depends on leadership, governance and how prepared the wider business is to make decisions as risks continue to evolve.
Measuring what mattersMTTD and MTTR will remain valuable measures of operational performance. But if organizations want to understand how resilient they really are, they also need to know how quickly they adapt.
MTTA fills that gap. It won't replace today's cyber metrics, but it will enhance them by measuring a capability that is becoming increasingly important as technology, AI and cyber threats continue to evolve.
It’s now MTTA time to shine.
We've featured the best endpoint protection software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
- Pokémon Center UK orders disrupted after CEVA Logistics cyberattack on July 30 2026
- Customer names, addresses, emails, and order details likely exposed, but accounts and payments safe
- Around a dozen organizations confirmed affected; no group has claimed responsibility yet
Customers who recently ordered their favorite Pikachu toy from Pokémon Center might have to do it all over again, since the company suffered a third-party cyberattack which disrupted its operations.
The official store for Pokémon merchandise in the UK has reached out to its customers via email to warn them about a recent cyberattack and its consequences.
According to BleepingComputer, which has seen a copy of the email, the company told its customers they had to “cancel your recent order due to an unforeseen fulfilment issue”.
Threat Exposure Platform: at NordStellar
Use code TECHRADAR10 for 10% off
NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.
Use coupon code TECHRADAR10 for an additional 10% off.View Deal
CEVA LogisticsThe company’s website is also showing a notification saying the company is “currently experiencing delays affecting some orders for our UK customers.”
“These orders may take longer than usual to process, dispatch, and deliver. We apologize for the inconvenience and appreciate your patience.”
The company said the attack struck its logistics provider, CEVA Logistics.
"CEVA Logistics, the vendor Pokémon Center utilizes to ship products from PokemonCenter.com for customers in the United Kingdom and Germany, has informed us that unfortunately they were a victim of a cyber attack commencing on 30 July, 2026."
Last week, one of the biggest shipping and logistics companies in the world disclosed an incident that forced it to shut down parts of its IT infrastructure and affected eight warehouses. At the time, a handful of its customers reported being affected by the breach, including Dutch retailers Bol and De Bijenkorf, and PC gaming powerhouse Valve.
Pokémon Center said the data most likely exposed in this incident includes people’s full names, mailing addresses, phone numbers, email addresses, and details about what they previously ordered on the site. User accounts are apparently safe, and so are payment details.
So far, around a dozen organizations are confirmed as having been affected. No threat actors have claimed responsibility yet.
Software security was built around human development.
People wrote, reviewed and deployed code. Now machines are taking over.
In a recent paper, Anthropic reports that more than 80% of the code merged into its production codebase is authored by their AI model, Claude.
The same capabilities that make developers more productive are changing the economics of cyberattacks.
While adversaries still define the objective, machines can generate the payloads, test variants, adapt code to different environments and repeat the process at a velocity that security programs can’t match.
Speed is Marginalizing Security ControlsMost enterprise software security workflows assume there is time for review. Code is written, scanned, tested, approved and deployed. If something suspicious happens later, security teams investigate and respond.
That model breaks down when software moves from prompt to execution in minutes.
AI-generated code can become a script, dependency, automation job or infrastructure change almost immediately. While development agents can modify files, resolve packages and run commands.
Human reviewers are no longer in the loop.
Attackers can use the same mechanics to generate exploits, test evasion techniques and adjust payload behavior for different targets. This creates more variation with fewer stable indicators for defenders to recognize.
While AI-assisted analysis can improve triage, it still often produces probability, not policy. At machine speed, “probably suspicious” is not good enough.
Machines Change The Attack ModelHuman attackers are not disappearing. But more of the attack chain is becoming machine-executed.
AI can automate reconnaissance, accelerate vulnerability discovery, generate exploit code, rewrite payloads and adapt command sequences to the target environment. But most defensive measures are designed around human constraints: reused infrastructure, shortcuts and trackable patterns. These don’t apply to machine attacks.
A machine-generated payload may not match a known signature or have an established reputation. It may be created, used briefly and discarded. But AI malware must still interact with the target environment to achieve its objective. Its behavior cannot conceal its intent, since it must access resources and change the environment in ways that advance the attack.
What malicious code is capable of doing is the more durable security signal.
Security Needs to Ask A Different QuestionSoftware supply chain security has improved, but much of it still validates the artifact’s properties before execution rather than governing execution itself.
SBOMs, signing and provenance give security teams greater confidence in a code's composition, origin and build history. But knowing where software came from does not reveal what it will do when it runs.
Software can pass each of those checks and still create risk. Even an artifact produced through a legitimate build process may violate policy at runtime, while an AI-generated script may complete its intended task in a way that exposes data or systems. As a result, a clean dependency list is not proof of safe behavior.
Post-Execution Detection Is Too LateDetection and response remain essential, but they intervene after risk has entered the environment. By the time suspicious behavior is visible, software may have accessed secrets, changed system state, opened network connections or created persistence.
AI compresses that window. Code can be generated, modified and deployed faster than humans can review it. Waiting for post-execution evidence gives attackers too much room to operate.
We need to shift the decision point left. Instead of asking, “Can we contain this software if it behaves badly?” the question should be, “Should this behavior be permitted to execute in the first place?”
That does not mean replacing existing controls, but rather changing where the decisive security gate sits.
Zero Trust for CodeZero Trust changed enterprise security by rejecting implicit trust. Users, devices, sessions and access requests are not trusted simply because they appear familiar. They must be verified against policy.
Software execution needs the same level of verification.
Code should not be trusted solely because it came from a known repository, was signed by a recognized publisher, passed through a build pipeline or has not been seen exhibiting malicious behavior before. Those are useful indicators, but they are not conclusive.
Zero Trust for Code addresses this problem. Before software runs, its expected behavior should be evaluated against policy. If the behavior is acceptable, execution can proceed. If not, the artifact should be blocked, restricted, isolated or escalated for review.
Organizations can start by mapping every path through which code enters the environment or executes with meaningful privilege. This includes formal development channels such as repositories, open-source packages, containers and CI/CD pipelines, as well as email attachments, downloaded files, macros, browser extensions, endpoint installers, third-party integrations and scripts introduced through AI or automation tools.
Then identify where those paths rely on inherited trust. If execution is allowed because software came from an approved source, was signed, passed through a build process or has no malicious history, the control is incomplete. Behavior still has to be evaluated before the artifact is allowed to run.
As AI takes on more of the work of creating legitimate and malicious code, enterprises can no longer assume that code which clears existing checks should be allowed to run. Execution must become a deliberate security decision.
We've listed the best internet security suites for PCs, Macs and mobile devices.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit
- Chinese government moves ahead with Windows 10 replacement
- Heavily customized Windows edition will be replaced by domestic alternative
- Windows 10 official end of life was October 14, 2024
The Chinese government has revealed plans to finally remove Windows 10 from its systems as it looks to move towards home-made alternatives.
A report from Bloomberg claims the Chinese Ministry of State Security has told some state-linked entities to start uninstalling the software as part of a multi-year plan to remove dependence on Western technology.
The version of Windows 10 is developed by C&M Information Technologies Co (CMIT) which was formed in 2016 as a joint venture between Microsoft and the state-owned China Electronics Technology Group Corp in a bid to make sure Windows 10 was compliant with the government's security requirements.
A welcome change?There's no official confirmation as to why the decision has been made now, with CMIT reportedly planning to retire the software in February 2027, in line with a government campaign to curb the use of foreign technology.
Bloomberg notes the move comes just weeks before US President Donald Trump is set to meet with Chinese premier Xi Jinping, where security concerns will no doubt be high.
“Microsoft is not aware of a security incident affecting this product, which continues to receive regular security updates,” a spokesperson for the US company told Bloomberg. “We have nothing further to share.”
Windows 10 famously saw its end of life in October 2024, as Microsoft retired the software in order to focus on newer editions.
However some users were initially able to get extra support until 2026, a deadline which was surprisingly extended even further recently, with Microsoft's Extended Security Updates (ESU) scheme now indicating support will run through to October 2027.
The move was slow to catch on, as a study in July 2026 found one in six PCs still ran the older software as opposed to 78.8% for Windows 11 - with healthcare and pharmaceuticals (23%), consumer and retails (23%) and manufacturing (18%) among the industries most likely to still be running Windows 10, with SMBs (21.4%) more likely to be running the outgoing OS compared with enterprises (16.6%).
This is especially concerning as the average Windows 10 device has around three times as many active CVEs (1,903) as a Windows 11 devices (652).


