Securing the Cloud: Visibility, Control and Confidence

Cloud adoption without compromise Cloud platforms have transformed how global organisations deliver services, manage data and scale operations. However, whilst flexibility and speed have improved, visibility and control have often decreased. Many incidents reported to the NCSC over the past year have been linked to cloud misconfiguration or weak access controls, not platform flaws. The […]

From Simulation to Response: Turning Exercises into Real Capability

Running a cyber incident exercise is an excellent way to test response readiness, but too many stop at the simulation itself. The real value lies in what happens afterwards. Every drill, tabletop or technical run-through should end with clear evidence of progress, not a list that disappears into an inbox. Why most exercises fall short […]

The Ransomware Reality Check: Preparing for the UK’s New Direction

Over the past few years, the UK has seen a clear rise in both the frequency and impact of cyber extortion attempts. As the Government moves towards tighter rules on ransom payments, boards and IT leaders need to ask themselves a difficult question: could we recover if paying a ransom was no longer an option? […]

Surviving Peak Season: Cyber Resilience for Retail and eCommerce

For most UK retailers, the final quarter determines the success of the year. Whilst sales teams prepare for record-breaking volumes, threat actors are quietly doing the same. Every promotion, flash sale or Black Friday campaign is an invitation to test defences. The difference between a smooth season and a costly outage comes down to simply […]

Real Insight in Real Time: How AI is Changing the Way We Manage Cyber Risk

Across the tech-sphere it has become abundantly clear that Artificial Intelligence is now a driving force, even more-so across the cybersecurity landscape. With this great leap in technology, AI is being leveraged on both sides of the battle. But how? AI is now being used both as a tool for defence and, increasingly, as a […]

Pass the Audit; Fail the Breach – The Superficial Security Trap

In today’s compliance-driven landscape, IT audits and certifications are critical tools to display your organisation’s adherence to industry standards. With that, certifications such as Cyber Essentials and ISO27001 are no longer distinguishing factors for prospective clients and suppliers, they’ve instead become a minimum requirement. And with good reason: these certifications reflect your organisation’s commitment to […]

Bait and Switch – Are You Accidentally Recruiting Insider Threats?

Over the last couple of years, we have seen a marked increase in criminal groups infiltrating companies. Either using AI and stolen identities or fronting interviews with disposable candidates all the way through until the contract is signed, and then an alternative person shows up to start the job. In many cases once they have […]

Data Hygiene

Most organisation’s that are breached and compromised are done so not because they are lax with security, have poor patching, or are gambling that they will never be a victim; instead they usually suffer from poor data hygiene. Users store data on desktops, in shared folders, in online repositories (such as Jira, SharePoint, Confluence, etc.), […]

Passwords

NIST, like the NCSC have updated their password guidance. It is now no longer advisable to set them to be random strings of nonsensical letters, numbers and symbols. The focus is now on password length, by stringing together multiple words. Inclusion of uppercase, and symbols or numbers is still helpful, to make them even harder […]

Experiencing a security breach?
Contact the cyber security experts now