There is a pattern playing out inside businesses right now that security teams are only just beginning to grapple with. A business deploys Microsoft Copilot, ChatGPT, Claude or Gemini. The IT team follows the vendor’s setup guide, enables the licence, and rolls it out to users. Within weeks, executives are summarising emails, generating first drafts, and asking questions of their data in natural language. Productivity improves. The board is pleased.

What nobody has checked is what data these AI tools can actually reach.

Because these AI tools don’t create new access, they inherit existing permissions. If a user already had access to a shared drive containing board minutes, financial forecasts, HR records, or sensitive client data, these AI tools can now potentially surface all of it in response to a simple typed question. In many Microsoft 365 environments, permissions have accumulated over years: old shared folders never cleaned up, overly broad access granted to entire departments, files that were never meant to be widely visible sitting in locations that technically anyone with a company login can reach.

The AI tool hasn’t introduced a new vulnerability in the conventional sense. It has simply made the existing one dramatically easier to exploit.

Why This Is Happening Now

The pace of AI adoption inside organisations has outstripped the pace of governance. That isn’t a criticism, it is an observation about how enterprise technology typically evolves. When email was introduced, most organisations didn’t have an email security policy until something went wrong. When staff started using smartphones for work, mobile device management came later. When cloud storage arrived, data classification lagged behind.

AI is following a similar adoption curve, but faster and with higher stakes.

The difference this time is that AI tools don’t just store or transmit data, they actively reason over it, synthesise it, and present it in response to unstructured natural language queries. The implications of overpermissioning are therefore qualitatively different. A misconfigured shared folder in a pre-AI environment might go unnoticed indefinitely. The same misconfiguration in a Copilot-enabled environment for example, can be surfaced to anyone in the organisation within seconds.

Shadow AI adds a further dimension to this problem. While IT departments are managing official deployments, staff are independently signing up for ChatGPT, Claude, Gemini, and a growing range of AI-powered productivity tools. They are pasting customer data, internal documents, and commercially sensitive material into these tools without any visibility from the organisation’s security function. In many cases they don’t know they are doing anything wrong, the tools are freely available, the interface is intuitive, and nobody told them not to.

According to research by ISACA, only 31% of organisations have some form of formal governance in place when it comes to AI.  That means the majority of organisations are operating in a space where the rules haven’t been written, the risks haven’t been assessed, and the exposure hasn’t been mapped.

The Three Gaps at the Heart of the Problem

Understanding where the risk actually sits requires looking at three distinct but connected areas.

The data permissions gap. Before any AI tool can be safely deployed, the organisation needs to understand what its users can access and whether that access is appropriate. In most Microsoft 365 environments, this picture has never been properly mapped. Data has accumulated over years, access has been granted ad hoc, and the cumulative effect is a permissions landscape that nobody has a complete view of. AI tools surface this gap in a way that makes it impossible to ignore.

The governance gap. Most organisations don’t have policies that specifically address AI tool usage, data classification in the context of AI, or acceptable use boundaries for generative models. Without these policies, staff have no framework for deciding what is and isn’t appropriate and security teams have no baseline against which to measure behaviour or investigate incidents.

The visibility gap. Shadow AI is, by definition, invisible to the tools organisations use to monitor data flows. Conventional endpoint, network, and SIEM controls are designed to detect known threat patterns. They are not designed to identify when a member of staff pastes a client contract into a public AI tool. This isn’t a gap that can be closed with existing controls, it requires a different approach to monitoring and awareness.

The Questions Boards Are Starting to Ask

As AI governance has moved up the regulatory agenda, with the EU AI Act, FCA guidance on AI in financial services, and ICO attention on AI and personal data, boards and audit committees are beginning to ask questions that security and IT teams are struggling to answer.

What AI tools are currently operating within the business? What data can those tools access? Do we have a policy that governs AI usage? Have we assessed our exposure under relevant regulatory frameworks? How would we know if sensitive data had been processed by an unapproved AI tool?

For many organisations, the honest answer to most of these questions is currently “we don’t know.”

That isn’t a comfortable position to be in. It is, however, a fixable one, and the organisations that address it proactively will be in a fundamentally stronger position than those that wait for a regulatory inquiry or a data incident to force the issue.

When This Becomes Particularly Urgent

There are specific moments when the need for clarity around AI security becomes especially acute. Organisations that are actively rolling out Copilot or another enterprise AI tool are in the highest-risk window, the period between deployment and a proper security review is when exposure is greatest. The same is true when staff are using AI tools without explicit IT approval, when an insurance renewal or regulatory audit is approaching, when a board sign-off on AI investment is required, or when a new CIO, CISO, or CTO joins and needs to understand the existing landscape.

In each of these situations, operating without a clear view of AI security posture isn’t just a technical risk, it is a governance and accountability risk that sits at board level.

What a Structured Review Looks Like

So where should you start when looking at solving these problems with AI adoption in your business? At Cyberfort we encourage all businesses to undertake an AI Security Readiness review before any AI tool is fully deployed. From our experience understanding AI security exposure requires a methodical approach across four areas:

Step 1 — Scoping and Discovery. Establish the boundaries of the assessment: which AI tools are in scope, which parts of the estate will be reviewed, and which stakeholders need to be involved. This step also captures the organisation’s current understanding of its own AI usage, which is often the first point at which shadow AI usage becomes visible.

Step 2 — AI Usage and Exposure Review. Map the AI tools currently operating within the organisation, both sanctioned and unsanctioned. Assess data access permissions, identify overpermissioning in Microsoft 365 or other AI-adjacent environments, and establish a baseline picture of where sensitive data could be reached by AI tools.

Step 3 — Security and Governance Assessment. Evaluate the organisation’s current policies, controls, and monitoring capabilities against the specific requirements of an AI-enabled environment. Identify gaps in policy, monitoring, data classification, and incident response that are specific to AI risk.

Step 4 — Findings, Scorecard, and Roadmap. Produce a clear, executive-readable risk scorecard and a prioritised remediation roadmap. This gives the organisation both the board-level view and the technical detail needed to act.

What Good Looks Like

Organisations that have done this work properly typically come out of it with three things they didn’t have before.

First, a clear and accurate picture of what their AI tools can actually access, which is almost always different from what they assumed. Second, a governance framework that gives staff clarity on what is and isn’t acceptable, reducing the shadow AI risk significantly. Third, a documented security posture around AI that can be presented to insurers, regulators, boards, and enterprise customers when the question arises.

None of this requires stopping AI adoption. The goal isn’t to slow the business down, it is to make sure the speed of adoption doesn’t create a risk profile that leadership hasn’t had the opportunity to consider.

A certification that started life as a baseline has quietly become a commercial necessity

There was a time when Cyber Essentials was something organisations pursued because it seemed like a sensible thing to do. A government-backed certification. A signal to customers and partners that basic cyber hygiene was in order. Useful, perhaps. Reassuring, certainly. But optional.

That time has passed.

Cyber Essentials is now a requirement in a growing number of commercial and regulatory contexts. Public sector contracts, NHS supply chain agreements, central government procurement frameworks, all mandate it. An increasing number of insurers require it as a condition of cyber cover. Enterprise and large corporate buyers are writing it into supplier questionnaires as a minimum threshold. Organisations that lack it are discovering not that it would be nice to have, but that they cannot bid, renew contracts, or proceed without it.

This shift in the market has changed the nature of the question. It is no longer “should we  have Cyber Essentials?” It is “why haven’t we got it yet, and what’s stopping us?”

The answer to that second question is more instructive than most organisations expect.

What Cyber Essentials Actually Assesses

Before understanding why organisations get stuck in unlocking the business value of this security certification, it helps to understand what the scheme is actually testing. Cyber Essentials, and its more rigorous variant, Cyber Essentials Plus covers five technical control areas. These are not exotic or advanced. They represent the foundational layer of cyber hygiene that every organisation with an internet-connected environment should have in place.

The five areas are: boundary firewalls and internet gateways; secure configuration of devices and software; access control and administrative privilege management; malware protection; and patch management.

None of these are unusual. Most organisations believe they have them covered. And in many cases, they do, but not in the structured, evidenced, and consistently applied way the scheme requires.

That gap between “we have that” and “we can demonstrate that” is precisely where organisations stall.

The Three Reasons Organisations Get Stuck

From our experience at Cyberfort we see organisations attempting Cyber Essentials certification running into one of three structural problems (or all three at once) before they engage with a specialist MSSP who really understands the certification standard.

The first is the absence of a structured readiness process. Most organisations approach certification the way they might approach any compliance task: they read the requirements, make a judgement about how well they comply, and submit. What they don’t do is conduct a systematic gap analysis first. The result is that surprises emerge during the assessment itself, configurations that don’t meet the standard, devices that aren’t managed in the way assumed, or policy documents that exist in draft but have never been formally adopted. By the time these surface, the certification window is often compromised.

The second is remediation drag. Even when gaps are identified in advance, fixing them takes longer than anticipated. A device configuration change needs sign-off. A patch deployment waits for a change control window. A policy update requires review by a legal or compliance team. These are not failures of intent they are the natural friction of operating a real organisation with real governance processes. But without a structured plan that accounts for this friction, remediation spreads across weeks or months and the certification timeline slips.

The third is ownership ambiguity. In many businesses, the answer to “who is responsible for Cyber Essentials?” is genuinely unclear. It might sit with IT, a compliance function, a part-time fractional CISO, or with no one in particular. Without a clear owner who understands both the technical requirements and the business context, progress stalls at the points where decisions need to be made.

These three problems are not signs of bad security. They are signs of normal organisational complexity applied to a process that demands unusual clarity and structure.

Why the consequences of delay are increasingly material

For many years, the cost of not having Cyber Essentials was relatively abstract. You might lose out on some public sector work. You might look less credible to a prospective customer. These were real costs, but they were often speculative or hard to attribute directly.

The consequences are now considerably more material.

Research suggests that more than half of organisations seeking public sector contracts have lost or been excluded from an opportunity specifically because of the absence of Cyber Essentials certification. More than a third of UK organisations have faced questions about certification during insurance renewal processes, with some facing premium increases or coverage refusals where it was absent. And as supply chain security requirements tighten, partly driven by legislation, partly by enterprise procurement practices, the volume of organisations requiring certification from their suppliers continues to grow.

There is also a compounding effect. Cyber Essentials Plus, the independently verified variant, requires the underlying Cyber Essentials to be current and in good standing. Organisations that allow their certification to lapse, (which is common), as it must be renewed annually, find themselves having to restart from the basic level before they can progress to Cyber Essentials Plus. The longer the lapse, the more has changed in the environment, and the more work the renewal requires.

The organisations that manage this most smoothly are not the ones with the most sophisticated security environments. They are the ones with a repeatable, structured process for maintaining certification as part of their normal security operations.

What Good Looks Like: A Framework for Getting It Right

There is a clear pattern among organisations that move through Cyber Essentials certification efficiently and without disruption. It involves four logical stages, each building on the last.

The first stage is scoping and discovery. Before any gap analysis or remediation work begins, the organisation needs clarity on what is in scope. What devices, systems, and networks will the certification cover? This is not always as simple as it sounds. Cloud environments, remote working infrastructure, BYOD policies, and third-party managed services all introduce complexity. Getting scope right at the start prevents the most expensive kind of surprise: discovering mid-assessment that something was missed.

The second stage is gap analysis. With scope established, a structured review of the five control areas identifies where the current environment meets the standard and where it does not. A good gap analysis does not just flag what is missing, it produces a prioritised remediation plan that distinguishes between quick wins, items requiring planned change windows, and anything that needs a policy or governance decision before the technical fix can proceed.

The third stage is guided remediation. This is where most organisations benefit most from external support. Working through a prioritised remediation plan with a structured approach, and with advisors who have done this many times across many different environments, is materially faster than attempting it internally without that reference point. Common remediations are well understood. The sequence in which they should be addressed is known. The points of friction that typically cause delay are predictable and can be managed proactively.

The fourth stage is certification support. The final assessment and submission process has its own requirements, timelines, and common failure points. Having support through this stage, including review of self-assessment responses before submission significantly improves first-time pass rates.

Who This Matters To, and When

Cyber Essentials is relevant to virtually every UK organisation, but the urgency varies significantly depending on context. There are a number of situations where the need to act becomes pressing rather than merely prudent. The most common situations include:

  • Organisations responding to a public sector tender with a certification requirement that they cannot currently meet.

  • Businesses approaching an insurance renewal where cyber cover is under review.

  • Suppliers who have received a questionnaire from a major customer asking for certification evidence.

  • Organisations that failed a previous certification attempt and need to understand what went wrong and how to fix it.

  • Businesses that have recently changed their IT environment, through a cloud migration, an acquisition, or a change in IT provider and are no longer confident that their previous certification is still reflective of current practice.

  • Organisations that have had a team change and no longer have a clear internal owner for the process.

In each of these situations, the question is not whether to pursue certification, that has usually already been answered by an external event. The question is how to move through it as quickly and cleanly as possible.

The threat your controls were never designed to see

There is a fraud technique spreading rapidly across every sector that has nothing to do with malware, phishing links, or compromised credentials. It does not trigger your SIEM. It bypasses your email gateway. It has no payload for your endpoint agent to detect. And in 40%+ of organisations that have experienced it, it has succeeded.

The technique is AI-powered deepfake executive impersonation. Understanding how it works, why it works, and what actually stops it is one of the most important things a security, finance leader or board member can do right now.

How the attack landscape has changed

Executive impersonation is not new. Fraudsters have long posed as C-Level executives in emails, invoking urgency and authority to push through unauthorised payments. What has changed, fundamentally and recently, is the cost and complexity of doing it convincingly.

Until very recently, cloning a voice or generating a synthetic video required significant technical expertise, specialist equipment, and considerable time. It was a capability largely confined to well-resourced criminal groups and nation-state actors. That barrier has gone.

Today, generative AI tools that can clone a voice from a few minutes of audio are freely available online. The same technology that powers legitimate productivity tools including voice synthesis, video generation, and natural language models, is being repurposed by fraudsters who need no technical expertise to use them. The result is a 1,500% increase in deepfake attacks since 2023 (UK Gov 2025 Study), and an average financial impact of a successful attack being estimated to be over £210,000.

The democratisation of this capability is the critical shift. Attacks that previously required sophisticated criminal infrastructure can now be launched by individuals. The volume of attempts is increasing not because more sophisticated actors have emerged, but because the barrier to entry has effectively collapsed.

Why human judgement is the target and why that is hard to defend

To understand why this threat is so difficult to defend against, it helps to understand what it is actually attacking.

Most organisational fraud controls assume that the weakest link is the technology, that if you can secure the perimeter, filter the email, and lock down the endpoint, you have addressed the risk. Deepfake impersonation attacks do not target the technology. They target the trust that people place in the voices and faces of their colleagues and leaders.

Consider the typical high-value payment authorisation process. A finance director receives a call from someone who sounds exactly like the CEO, requesting an urgent transfer ahead of a deal closing. The voice, the tone, the vocabulary, and the sense of urgency are all consistent with the genuine article. The finance director has no reason to doubt what they are hearing, and every reason to act quickly.

The verification mechanism in that scenario is human judgement. And human judgement is precisely what AI-powered impersonation is engineered to defeat.

This is not a failure of intelligence or awareness on the part of the individual. It is a structural vulnerability in how organisations communicate and authorise actions, one that has existed for years but that has only recently become practically exploitable at scale.

The exposure organisations are not measuring

One of the most significant and underappreciated aspects of this threat is how much publicly available material already exists that could be used to construct a convincing impersonation.

For most organisations with any public profile, and for most executives who are active in their industry, the raw material needed to train an impersonation model is already out there. LinkedIn videos, Keynote recordings, Investor calls, Press interviews, Webinars, Podcast appearances. Every piece of public audio and video content featuring a senior leader is, from an attacker’s perspective, training data.

Most organisations have no idea how extensive that exposure is. They have never mapped it, or quantified it, and therefore cannot make informed decisions about how to manage it. The exposure assessment, understanding what is publicly accessible and what risk it creates, is the first and most important step in addressing this threat, because it moves the organisation from assumption to evidence.

Why existing controls have a structural blind spot

It is worth being direct about why conventional security investments do not address this risk, not as a criticism of those investments, but because understanding the gap is necessary to filling it.

Email security controls are designed to analyse digital artefacts: headers, links, attachments, sender reputation. A deepfake attack that arrives as a phone call or a WhatsApp voice note has none of these characteristics. There is nothing to scan.

SIEM and endpoint detection tools look for anomalous system behaviour, indicators of compromise, and known attack signatures. A fraudulent phone call does not generate system events. There is no log entry to correlate.

DLP tools monitor data moving across systems. A payment authorised verbally following a fraudulent instruction does not cross a data loss boundary the tool was designed to detect.

This is not a technology problem that more technology will solve, at least not primarily. The attack surface here is the communication channel and the human trust it carries, and the defence requires interventions that operate at that level.

What effective defence actually looks like

Understanding this threat clearly points toward what effective defence requires. From our experience at Cyberfort there are four interconnected components which need to be in place to defend against a deepfake attack:

Exposure mapping. Before any organisation can make informed decisions about its risk, it needs to understand what material already exists publicly and which individuals carry the greatest impersonation risk. A structured exposure review produces that picture and identifies where reduction is possible.

Risk assessment. Not all scenarios carry equal risk. The combination of who could be impersonated, which communication channels are most vulnerable, and which teams are most likely to act on impersonated instructions creates a specific risk profile that varies by organisation. Understanding that profile lets you prioritise your response.

Scenario-based testing. Awareness training that tells people deepfakes exist is not sufficient preparation. What prepares people is working through realistic simulations: hearing what a cloned voice actually sounds like, experiencing the psychology of an authority-and-urgency scenario, and practising the verification instincts needed to slow down and challenge. Organisations that have been through this consistently report it as the single most impactful element of their preparation.

Procedural controls. The most durable defence is embedding out-of-band verification into high-risk processes, making it structurally normal, rather than exceptional, to pause and confirm through a secondary channel before acting on a significant instruction. This does not slow organisations down in practice; it removes the friction that fraudsters rely on.

When this risk becomes particularly acute

While every organisation with any public profile carries some exposure, certain situations materially increase the risk or the consequences of a successful attack.

Executives who are active on LinkedIn, YouTube, or in industry media carry higher impersonation risk simply by virtue of the volume of publicly available material. Organisations going through mergers, acquisitions, or leadership changes create a period of uncertainty and unfamiliar communication patterns that fraudsters actively exploit, staff may be less sure what normal looks like, and more inclined to defer to authority. Publicly listed companies face particular scrutiny because their leadership and financial processes are more visible.

Organisations with large or frequent payment authorisation processes, particularly where those processes involve a small number of decision-makers acting on verbal instruction, carry concentrated exposure. Recent near-misses or suspected fraud attempts are a signal that the organisation may already be on a target list. And insurance renewals and regulatory audits increasingly ask direct questions about this threat, which means the question of whether you have addressed it is coming regardless.

 Five key questions organisations should be asking when it comes to deepfake and execution impersonation attacks

For any security or risk leader thinking through their organisation’s position on this threat, five questions are worth asking:

1. How much publicly available audio and video material exists featuring your senior leaders, and have you ever assessed it as an attack surface?

2. Do your finance, HR, and executive assistant teams have specific, practised protocols for verifying the identity of a caller or video sender before acting on a sensitive instruction?

3. Have your high-risk teams ever experienced a realistic impersonation simulation,  not been told it exists, but actually worked through one

4. Could you articulate to your board, in concrete terms, what your current exposure to this risk is and what controls are in place to manage it?

5. If a successful attack occurred tomorrow, would your incident response procedures cover this scenario?

If the honest answer to any of these is no, or not sure, that is the gap which needs to be addressed through training, policy updates and staff awareness of Deepfake and Executive impersonation attacks.

How quickly do you need to act and what’s involved

One of the useful things about this threat is that addressing it does not require a lengthy programme. The core work – exposure mapping, risk assessment, scenario testing, procedural control design can be completed in a focused engagement that does not consume significant internal resource or disrupt day-to-day operations. The output is a clear picture of exposure, a tested and trained team, and a set of practical controls embedded in process.

So, What does this look like?

As mentioned earlier in the article addressing this threat requires more than awareness. It requires a structured assessment of your actual exposure, a tested understanding of how your people respond under realistic conditions, and practical controls that embed durable resilience.

For example, at Cyberfort we have built a Deepfake & Executive Impersonation Defence service to help organisations prepare themselves against this type of attack effectively.

It begins with an Executive Exposure Review – a systematic mapping of the publicly available material that could be used to impersonate your key individuals. Most organisations are genuinely surprised by what this surfaces. Understanding your exposure is the essential first step.

Step 2 involves a structured Deepfake Risk Assessment that identifies your highest-risk scenarios, communication channels, and roles. Not every part of your organisation carries the same level of risk. Knowing where to focus is what makes the response proportionate and effective.

Step 3 puts your people through realistic Fraud Scenario Testing – AI-powered impersonation simulations that replicate the conditions of a real attack. This is where organisations learn the difference between theoretical awareness and genuine resilience. It is also where the specific gaps in your human controls become visible, in a controlled environment, before an attacker finds them for you.

Step 4 combines targeted AI Awareness Training with the delivery of an Executive Protection Playbook: practical verification protocols, out-of-band confirmation procedures, escalation paths, and governance processes that your teams can use immediately and sustain over time.

The outcome is not just a report. It is an organisation that has moved from unknown exposure to active, measurable resilience, with the board-level evidence of due diligence that regulators, insurers, and investors increasingly expect.

From our experience at Cyberfort, the organisations that are best placed to mitigate the risks against this type of attack are not necessarily the most technologically sophisticated. They are the ones that have looked at this honestly, understood where their exposure lies, and put the right human controls in place. That is an achievable position for any organisation, and it is a significantly better one than discovering the gap through a successful attack.

The attack that starts next door

When security teams map their risks, they tend to focus on what they can see and control: their own infrastructure, endpoints, and perimeter. That instinct is understandable. It is also increasingly misaligned with how the most significant breaches of the last two years have happened.

The pattern is consistent. An organisation with mature security controls, a hardened perimeter, and a well-resourced IT team is compromised, not through their own systems, but through a supplier. A managed service provider with access to their network, a software vendor whose update mechanism became a delivery vehicle for malicious code, a cloud platform partner whose credentials were harvested and used to move laterally into the customer’s environment.

The attacker did not knock on the front door. They walked in through a side entrance that the target organisation had never fully audited, and in many cases, did not even know existed.

This is the defining characteristic of modern supply chain cyber risk. It does not respect the perimeter you have built. It exploits the trust relationships you have extended, often necessarily, often legitimately, to the network of third parties your organisation depends on to function.

The scale of the problem is structural, not incidental

It would be reassuring to treat high-profile supply chain attacks as edge cases: sophisticated operations carried out by well-resourced nation-state actors against strategically significant targets. The data does not support that reassurance.

According to the Verizon Data Breach Investigations Report 2025, more than 30% of data breaches now involve a third-party element. Blackberry’s 2024 survey of IT decision-makers found that more than 75% of software supply chains had been exposed to a cyber attack in the preceding twelve months. And the UK Government’s Cyber Security Breaches Survey 2025 found that only 14% of organisations had undertaken a formal security review of their supply chain in the last year.

Read those three figures together and the picture becomes clear. Third-party attacks are not rare. They are not declining. And the vast majority of organisations have not formally assessed the risk they carry through their supplier relationships.

This is not primarily a technology problem. It is a governance and visibility problem. Most organisations have grown their supplier base organically over years or decades, extending access and data-sharing relationships as the business required them, without building a proportionate framework for assessing and managing the security posture of those suppliers over time.

The result is a risk landscape that is both significant and largely invisible.

Why traditional approaches fall short

The conventional response to supply chain risk tends to rely on one of two mechanisms: contractual protections, or certification-based assurance. Both have genuine value. Neither is sufficient on its own.

A supplier’s ISO 27001 certificate, or their signed GDPR data processing agreement, tells you about their intent and their documented processes at the point the certificate was issued. It does not tell you about the controls that are actually operating today, in the specific parts of their business that touch your data and your systems. Certification can be narrowly scoped, out of date, or simply not reflective of the real-world security posture of an organisation at a given moment.

Supplier questionnaires suffer from a different but related problem. They are typically completed once, reviewed once, filed, and then largely forgotten, while the risk environment continues to evolve. A supplier that passed your assessment two years ago may have undergone significant organisational change, technology change, or personnel change since then. The questionnaire response that gave you comfort at the time has not been updated to reflect any of it.

The deeper issue is one of volume and capacity. A typical mid-sized organisation has dozens, sometimes hundreds of suppliers with some form of digital access or data-sharing relationship. Applying consistent, meaningful scrutiny to every one of those relationships, at the depth required to form a genuine view of security posture, is not feasible without a structured, risk-prioritised approach that distinguishes between the suppliers that represent real exposure and those that do not.

The five gaps that create real exposure

Through our work with organisations across financial services, professional services, engineering, and critical infrastructure, five specific gaps appear with consistent regularity.

The first is the absence of a consolidated supplier inventory. Most organisations cannot produce, without significant effort, a complete list of which third parties have access to their systems, what level of access they hold, and what data they can reach. That baseline simply does not exist in a structured, maintained form.

The second is the reliance on static risk pictures in a dynamic environment. Supplier relationships change. Personnel change. Technology changes. A risk assessment that does not have a defined refresh cycle is a record of how things were, not how they are.

The third is the gap between contractual assurance and operational reality. Contracts establish obligations. They do not verify compliance. The difference between what a supplier is contractually required to do and what their security controls actually look like in practice can be significant, and that gap is rarely visible without independent assessment.

The fourth is the absence of incident response planning that accounts for supplier failure. Most organisations have internal incident response plans. Far fewer have pre-agreed response playbooks that cover the specific scenario where a supplier is compromised and the organisation needs to contain, investigate, and communicate about that compromise quickly. When a supplier incident occurs, the organisations that respond well are those that had already mapped their exposure in advance.

The fifth is the growing commercial and regulatory pressure that makes this governance gap increasingly visible. Insurers are asking harder questions about third-party risk management as a condition of coverage. Regulated sectors face specific obligations around supply chain oversight. Enterprise customers are requesting evidence of third-party assurance as part of procurement processes. The organisations that cannot answer these questions clearly are finding that the absence of a supply chain risk framework carries direct commercial consequences.

The right approach: structured, risk-prioritised, proportionate

Effective supply chain risk management does not mean applying the same level of scrutiny to every supplier relationship. It means having a clear, defensible basis for understanding which supplier relationships represent the greatest exposure and directing your assurance effort accordingly.

That starts with building and maintaining a structured view of your supplier landscape: who has access, at what level, to what data and systems. It continues with a risk-prioritised approach to assessment that distinguishes between critical suppliers, significant suppliers, and low-risk relationships, and applies proportionate scrutiny to each tier. It is sustained through embedding supply chain security assessment into procurement and vendor management processes so that new relationships are evaluated consistently before access is granted, not retrospectively.

The output of this kind of programme is not just reduced risk. It is the documented evidence of due diligence that regulators, insurers, and enterprise customers are increasingly requiring and that boards need to be able to point to when the question of third-party risk management is raised.

When does this typically become urgent?

Supply chain cyber risk tends to crystallise as a priority at specific moments. Organisations approaching an insurance renewal are often asked to demonstrate their third-party risk management practices for the first time. Those going through merger or acquisition activity find that supply chain security is a growing focus of technical due diligence. Those onboarding a new critical supplier, a managed service provider, a cloud infrastructure partner, a key software vendor, recognise that they are extending significant trust and need to verify that it is warranted.

Public sector organisations facing procurement requirements, professional services firms whose clients are asking for evidence of supply chain assurance, and businesses that have recently experienced an incident (however contained) that involved a third-party element also consistently find that this becomes a priority quickly.

In each case, the trigger is different. The underlying question is the same: do we have genuine visibility of the risk we carry through our supplier relationships, and can we demonstrate that we are managing it?

Cyber threats don’t stand still. Neither do the standards designed to stop them. If your organisation holds Cyber Essentials a Cyber Essentials Plus (CE+) certification, or has been thinking about this certification, there’s something important you need to know: the standard has been updated, and the bar has been raised.

This isn’t a minor tweak. The refreshed Cyber Essentials Plus framework reflects the reality of how businesses operate today, cloud-first environments, remote workforces, mobile devices, and an attack surface that looks nothing like it did when the original standard was written.

The good news? If you act now, you can get ahead of it. Here’s everything you need to know.

Why Cyber Essentials Plus Matters More Than Ever

Let’s start with the basics. Cyber Essentials is the UK government-backed certification scheme designed to help organisations protect themselves against the most common cyber-attacks – phishing, malware, ransomware, and unauthorised access. Cyber Essentials Plus takes that a step further: rather than a self-assessed questionnaire, it involves independent technical verification. An assessor actually tests your systems to confirm your controls work in practice, not just on paper.

For your customers, that distinction matters enormously.

In a landscape where supply chain attacks are increasingly common, your clients, partners, and procurement teams aren’t just asking whether you have a security policy, they’re asking whether you can prove it. CE+ is that proof. It tells the world that your defences have been independently tested and verified, not self-declared. For organisations bidding on government contracts, working in regulated sectors, or handling sensitive customer data, CE+ isn’t a nice-to-have. It’s increasingly a commercial prerequisite.

Beyond the contractual angle, there’s the practical one. Cyber Essentials Plus certification gives your leadership team confidence that the five core technical controls – firewalls, secure configuration, user access control, malware protection, and patch management are genuinely in place and functioning. That confidence has real value when a board is assessing risk, when an insurer is pricing a cyber policy, or when a customer is deciding whether to trust you with their data.

The updated standard makes that assurance even more meaningful, because it’s been designed for the way businesses actually work in 2026 and beyond.

What’s Changed: Old Standard vs New

The original Cyber Essentials framework was built for a world of on-premise infrastructure, desktop computers, and relatively contained network perimeters. That world has largely gone. The updated standard acknowledges this and closes the gaps that the old version left open.

Cloud services are now firmly in scope – Under the previous standard, cloud-hosted services occupied a grey area. Many organisations assumed that if a service was managed by a third-party provider, it fell outside the scope of their assessment. The updated framework makes clear that cloud services including Software as a Service (SaaS) platforms are in scope where your organisation controls the configuration. If your staff are using Microsoft 365, Google Workspace, or any other cloud platform, the way those environments are configured now counts. That’s a significant shift for organisations that have migrated heavily to the cloud and assumed their provider was handling security on their behalf.

Home and hybrid working environments are addressed directly – The old standard was written before remote working became the norm for millions of UK employees. The updated version explicitly addresses devices used outside the corporate network – including home broadband routers and personal devices used for work. If your staff are connecting from home, those endpoints and the networks they sit on are now part of the picture. For many organisations, this will require a fresh look at device management, VPN policies, and the controls applied to personally-owned devices used for work purposes.

Thin clients and virtual desktops are included – As more organisations move to virtual desktop infrastructure (VDI) and thin-client environments, the updated standard provides clearer guidance on how these are assessed. The previous version left room for ambiguity; the new one closes it.

Firmware and router security – The updated standard tightens requirements around routers and firewalls, including the firmware running on them. Default credentials, unpatched firmware, and misconfigured boundary devices have been a consistent entry point for attackers, the revised standard makes it harder to overlook these.

Stronger password and authentication requirements – The bar on credential security has been raised. The updated standard aligns more closely with current NCSC guidance on password policies, multi-factor authentication, and account management. If your organisation is still relying on password complexity rules alone, without MFA on internet-facing services, you’ll need to address that before you can certify.

Malware protection scope expanded – The updated framework takes a broader view of malware protection, including application allow-listing as an accepted control and providing clearer guidance on what’s required for different device types. Organisations that have relied on traditional antivirus alone may find they need to review their approach.

Taken together, these changes mean that organisations which previously held CE+ certification cannot assume they’ll pass under the new standard without a fresh assessment of their controls. The scope is wider, the requirements are more precise, and the technical verification is more thorough.

Why you need to ‘Act Now’ and how Cyberfort can help

At Cyberfort, we’ve been working with the Cyber Essentials framework since its inception. We’re an IASME-accredited Certification Body, which means we can take you through the full CE+ process,  from readiness assessment through to certification, with a team that understands both the technical requirements and the commercial pressures you’re working under.

Our approach to CE+ is built around three things: preparation, verification, and remediation.

Preparation – Before we put your organisation through the formal assessment, we work with you to understand your current environment, your devices, your cloud services, your remote working setup, your boundary controls. We identify the gaps against the new standard and give you a clear, prioritised action plan. No surprises on assessment day.

Verification – Our technical assessors carry out the hands-on testing that CE+ requires including scanning your external-facing systems, testing your internal controls, and verifying that what you’ve documented is what’s actually in place. This is where CE+ earns its credibility, and it’s where our experience makes a real difference. We’ve assessed organisations who have different IT estate sizes and complexity, and we know what the assessors look for.

Remediation support – If gaps are found and in our experience, they usually are, particularly under the updated standard, we don’t just flag them and walk away. Our technical team can help you close them, whether that’s configuring MFA across your cloud platforms, tightening your patch management process, or reviewing your device management policies. We see the assessment and the remediation as part of the same engagement, not two separate conversations.

The reason to act now is straightforward: the updated standard is in effect, and the window to prepare is shorter than most organisations realise. If your current certification is due for renewal, you’ll be assessed against the new requirements. If you’re pursuing CE+ for the first time, you’re starting under the new standard from day one. Either way, the organisations that begin their preparation earliest are the ones that certify fastest and the ones that avoid the costly scramble of last-minute remediation.

Why Cyberfort for CE+?

There’s no shortage of organisations offering Cyber Essentials assessments. So why does it matter who you choose?

Because certification is only part of the story. What matters is what happens before the assessment and what you’re left with afterwards.

Cyberfort brings together accredited certification, deep technical expertise, and a genuine understanding of the threat landscape. Our assessors aren’t ticking boxes; they’re experienced security professionals who understand how attackers think and where defences typically fail. That means our pre-assessment work is sharper, our gap analysis is more accurate, and our remediation guidance is practical rather than theoretical.

We also bring continuity. Many of our customers come to us for CE+ and stay with us for broader security services including penetration testing, managed detection and response, and security awareness training. That’s not a sales pitch; it’s a reflection of how security works in practice. Cyber Essentials Plus is a foundation, not a finish line, and having a partner who can support you beyond certification means you’re building on solid ground rather than starting from scratch every year.

Glen Williams, CEO of Cyberfort, recently joined Guy Clapperton on The Near Futurist Podcast to discuss how cyber security has moved far beyond basic antivirus and controls. In this two-part interview series, they explore how the threat landscape is evolving, what hasn’t changed and where businesses need to invest to be protected in the future against a changing cyber-attack landscape.

In part 2 Glen and Guy cover:

  • Why certifications are not enough to keep your business secure 
  • Communicating key cyber security messages across an organisation
  • The importance of a cyber resilience mindset and culture
  • Evaluating a cyber security services provider for your business
  • The UK Cyber Resilience Act and how it will impact businesses

Glen Williams, CEO of Cyberfort, recently joined Guy Clapperton on The Near Futurist Podcast to discuss how cyber security has moved far beyond basic antivirus and controls. In this two-part interview series, they explore how the threat landscape is evolving, what hasn’t changed and where businesses need to invest to be protected in the future against a changing cyber-attack landscape.

In part 1 they explore:

  • Why cyber security needs to be taken as seriously as physical security 
  • The ‘tooling and compliance’ misconception trap many businesses have fallen into
  • The importance of creating a cyber security culture in a business and not just relying on the IT team
  • Why deepfake attacks are on the rise and what steps organisations can take to mitigate this type of attack
  • Why certifications are important, but regular security testing holds the key to becoming resilient against attack

With fast-paced changes in technologies, evolving regulations, and changing growth expectations many organisations are finding their risk environments becoming time consuming to manage and difficult to keep under control. Without a structured approach to managing these risks, even the most innovative organisations can face costly disruptions, security incidents, and compliance missteps.

According to Vanta’s latest State of Trust Report, nearly 72% of organisations find their overall risk at an all-time high, while 56% report a recent vendor breach, all highlighting the constant risk to  operations, reputation, and bottom line.

Risk management software offers an efficient way to stay on top of your organisation’s risk landscape and mitigate detected threats. In recent months at Cyberfort we have been reviewing the business use cases for risk management software from a number of providers and how the right risk management tooling can reduce the admin burden of routine risk management tasks, but that is only one part of the equation. We have discovered the Vanta suite offers a lot more than merely time savings when it comes to risk and compliance management.

In this article, I explore the value risk management software brings and provide guidance on choosing the solution that works best for your organisation.

So let’s get started!

What is risk management software?

Risk management software helps organisations streamline risk assessments, tracking, and mitigation with capabilities spanning:

  • Risk identification and prioritisation
  • Ongoing risk tracking and management
  • Reporting and compliance
  • Visualisation and decision-making support

Ideally, the software enables organisations to move beyond reactive point-in-time checks to a real-time overview of their risk landscape, allowing for faster response times.

Risk management software plays a key role in demonstrating compliance with popular frameworks and standards, including ISO 27001 and SOC 2, and streamlining audit preparation. Some tools can automatically consolidate real-time data to generate gap analyses, which can be useful to both internal and external auditors.

ROI potential of risk management software

Robust risk management software can also unlock significant savings in the long run. When fully integrated, these solutions scale with your organisation, reducing the need for investment in additional resources and tools as risks evolve.

While the software is valuable for all industries, its ROI may be higher for companies in heavily regulated sectors, such as government, finance, healthcare, and technology, where emerging risks and increased scrutiny make manual tracking impractical and costly. Ineffective risk management can also potentially lead to missed business opportunities in these sectors.

Similarly, many companies begin exploring these tools when scaling initiatives, such as international expansion or mergers and acquisitions, introduce new complexity and increase risk exposure. In these cases, manual processes become too time-consuming and error-prone, ultimately hurting ROI.

Benefits of risk management software

Integrating risk management software into your GRC program also brings various tangible benefits, including:

Enhanced vendor oversight: Gain visibility into third-party risks by linking security review findings to various risk scenarios

Improved efficiency: Automate core risk management processes and assessments, reducing manual workloads and freeing up team capacity 

Demonstrable transparency: Centralise all risk data into a unified risk register, giving stakeholders a clear overview of your organisation’s risk landscape

Informed decision making: Collect risk information from disparate systems, enabling data-driven decisions and optimised resource allocation for impactful mitigation efforts

Proactive risk management: With real-time monitoring and automated alerts, security and IT teams can identify and address risks proactively, strengthening resilience

Vanta’s Most Valuable Risk Management Features for CISO’s and IT Leaders

For UK CISOs navigating a landscape shaped by UK GDPR, the ICO’s enforcement appetite, and the Cyber Essentials Plus scheme, Vanta’s platform offers several features that stand out as genuinely high value.

Continuous Controls Monitoring is arguably the most impactful. Rather than relying on point-in-time audits, Vanta moves organisations beyond point-in-time assessments with continuous monitoring, real-time alerts, and integrated risk management. For a CISO at a UK financial services firm subject to FCA oversight, this means risks are surfaced and evidenced in real time rather than discovered during an annual audit.

Vendor Risk Management (VRM) is increasingly critical given the supply chain incidents we have witnessed over the past 12 months across a wide range of industry sectors. Vanta’s VRM replaces static point-in-time assessments with continuous, AI-driven risk intelligence, monitoring for vendor changes and delivering real-time alerts with context, severity, and mitigation guidance.

Enterprise Risk Reporting Rollups address a key boardroom challenge all senior cyber security and IT leaders face. Multiple Risk Registers allow organisations to structure risk management around business units, with Enterprise Risk Rollups consolidating those into a unified, real-time dashboard for executive-level visibility,  exactly what a CISO/IT Director presenting to a UK board needs.

Finally, Privacy Automation, covering ROPA management, data inventories, and DPIAs is particularly relevant under UK GDPR. Centralising these into the broader compliance environment provides a real-time, audit-ready view of how personal data is governed across the entire organisation.

Together, these features shift the cyber security and IT team from reactive firefighting to proactive, board-ready risk governance.

5 tips for choosing your risk management software

Based on my recent discussions with a number of customers across a range of sectors, here are my top 5 tips when it comes to selecting a risk management software platform and why I believe Vanta is the best choice on the market today.

1. Determine your organisation’s risk management priorities

Start by defining the categories of risk your organisation must manage, such as operational, compliance, and vendor risks, and how they shape your risk monitoring and mitigation needs.

For example:

  • If you handle sensitive data, you may need a solution that supports regulatory compliance and data protection
  • If rapid company growth and emerging threats have made manual processes inefficient, you must prioritise automation-enabled solutions
  • If you’re working with distributed or remote teams, you may want software that promotes workflow visibility

Consider scalability and long-term alignment from the start if you don’t want to worry about constant add-ons or software replacements down the line.

2. Evaluate technical usability and request demos

Your next step is to evaluate solutions that align with your priorities. Some risk management platforms are versatile and serve multiple industries, while others only support limited sectors, such as healthcare or government contracting.

Besides looking into risk management features, also consider these technical usability factors:

  • AI and automation maturity: Check whether the solution uses AI to reliably automate risk and compliance management workflows or predict risk trends
  • Deployment method: See if your team better aligns with cloud-based or on-premise solutions, as the latter demands deeper in-house technical expertise
  • Regular updates and proper patch governance: Determine if the software receives updates regularly and how visible the patch governance is

Request demos to help you validate these usability aspects and plan a structured adoption process.

3. Assess the software’s integration capabilities

The software’s integration capabilities play a crucial role in its effectiveness. A tool that can integrate easily into your existing system architecture will likely provide a more complete and up-to-date view of organisational risks by consolidating data from multiple sources.

Key systems and processes your risk management software should connect with include:

  • Cloud infrastructure
  • Identity providers
  • Human resources information systems (HRIS)
  • Version control
  • Vulnerability scanner
  • Ticketing tools
  • Mobile device management (MDM)

Weaker integrations aren’t necessarily a dealbreaker, but you’ll have to rely more on manual workarounds, which can impact overall efficiency and the speed of adoption.

4. Determine the cost-to-feature ratio

Implementing risk management software is a long-term investment, so it’s important to weigh the cost-to-feature ratio carefully and flag potential extra costs associated with sustained usage.

Before you choose a solution:

  • Identify must-have features based on existing needs to avoid paying for unused capabilities
  • When calculating the total cost of the software, include factors such as maintenance, setup complexity, training costs, as well as pricing tiers and bundling options

Paying a high upfront price for a capable risk management solution may be worth it in high-risk, heavily scrutinised landscapes, or if your organisation needs to aggressively build customer trust.

5. Assess monitoring and reporting capabilities

Real-time monitoring and alerting are non-negotiable features of any strong risk management software. While nearly all existing solutions offer some form of reporting, you’ll have to focus more on whether you’re getting enough data for decision-making support.

The right solution will provide options for customisation and variety, allowing you to tailor insights to different internal teams, leadership, and even external auditors. For instance, modern risk management tools like Vanta offer numerous risk visibility options, such as: 

  • Automated risk registers
  • Colour-coded risk matrices based on custom risk scores
  • Risk assessment reports with visual aids and mitigation prompts 
  • Risk snapshots that can record your posture at a particular point in time and serve as a historical report for auditors

Overall, a granular monitoring and reporting setup can help teams turn risk management into a strategic advantage, supporting decisions that are a clear win for security and growth.

Best practices for implementing your risk management software solution

Follow these best practices to make the adoption of risk management software smoother:

  • Prepare systems and processes: Configure your systems and processes ahead of time to make the implementation process smoother. Proactive preparation can help uncover gaps, such as unmapped data processes or conflicting access rights, which can cause friction during rollout.
  • Conduct stakeholder training: Train your stakeholders on the new software so they can use it independently. Address potential adoption errors via written or video tutorials.
  • Document the effectiveness of the tool: Track the long-term impact of your risk management solution using relevant metrics so you can demonstrate the effectiveness of the solution to leadership.
  • Review and update the risk management software: Regularly assess your software to see if it holds up against evolving risk management needs. Check if the tool provides alerts for missing patches or if you should get the IT team involved to configure updates.

Why Vanta is the best risk management software on the market today

As discussed earlier in the article, I have evaluated several risk management software tools in previous months alongside customers in different industry sectors. One thing is clear from both mine and the customers I have talked to – Vanta is the leading risk management and agentic trust platform that offers one of the most comprehensive and scalable feature sets, complete with built-in resources and automation-enabled workflows. Some of the key features the Vanta platform includes:

  • Automated risk assessments, reviews, and approval through 400+ integrations
  • Automated risk scoring and prioritization
  • Risk ownership for better accountability tracking
  • A pre-built risk library with 100+ scenarios and suggested control mappings
  • Continuous risk monitoring for real-time alerts
  • Risk snapshots for better demonstrability during audits
  • A dynamic risk register and integrated control recommendations
  • A centralised dashboard for seamless accessibility

Cyberfort and Vanta can also work with you to enable third-party risk management workflows and conduct context-rich staff training.

What questions should you ask when evaluating software risk management tools

The key questions to focus on related to your organisation’s tech and risk profile, should include:

  • What types of data and systems does your solution support for risk monitoring?
  • What workflows are automated, and what will be the level of human intervention?
  • What kind of support is available during software adoption?
  • How does your risk management software help with compliance?

The EU AI Act which came into force on the 1st August 2024 introduced the first comprehensive, harmonised regulatory framework for managing AI systems ethically and responsibly. Before the Act, the closest robust guidelines in existence was ISO 42001, which has a similar overarching goal.

If your organisation has already implemented ISO 42001, you might have a head start in achieving EU AI Act compliance. In this article, we explain why this is the case by covering:

  • The purpose and scope of the EU AI Act and ISO 42001
  • The complementary and harmonious relationship between the two frameworks
  • Steps and strategies to approach compliance with both standards

EU AI Act and ISO 42001: Similarities and differences

The EU AI Act and ISO 42001 aim to ensure safe and responsible development, implementation, and use of AI systems. Still, they approach this goal differently.

The EU AI Act is a mandatory regulation that applies to all EU-based organisations and those that provide services in the EU. Meanwhile, ISO 42001 is an international, voluntary standard with recommended best practices for building a comprehensive AI management system (AIMS).

Another considerable difference is the certification type:

  • ISO 42001 is a certifiable standard, and an obtained certificate is valid for three years
  • The EU AI Act requires only self-attestation, with re-attestation needed only if significant changes are made to the AI system

Even though ISO 42001 is a certifiable standard, this certification is voluntary and organisations are not mandated to achieve it. By contrast, the EU AI Act carries considerable legal weight, so non-compliance can lead to substantial fines and penalties.

Despite these differences, the shared goal of the EU AI Act and ISO 42001 results in notable overlaps between these frameworks.

The relationship between the EU AI Act and ISO 42001

The EU AI Act and ISO 42001 have around 40%–50% overlap in high-level requirements. Both frameworks cover several important aspects of responsible AI system development and implementation, such as:

Data governance: Article 10 of the EU AI Act outlines various data governance requirements regarding data categorisation and bias detection. Similarly, ISO 42001 also focuses on bias detection and mitigation and calls for clear roles to be defined in charge of AIMS oversight, which should encompass effective data governance.

Risk management: The main pillar of the EU AI Act is the classification of risks into four categories (unacceptable, high, limited, and minimal) and the different treatment of AI systems depending on their risk level. ISO 42001 offers a clear framework for effective risk assessment, which helps categorise different AI system risks and manage them accordingly.

Human oversight: As per Article 14 of the EU AI Act, AI systems should be developed to enable ongoing human oversight, with specific measures corresponding with the risk level. ISO 42001 aligns with this requirement, mainly by recommending the detailed documentation of AI processes for increased transparency and easier oversight.

Ethical implications: Both the EU AI Act and ISO 42001 emphasise the importance of ethical use of AI systems, which includes fairness in decision-making, bias mitigation, and other measures that prevent harmful effects of AI implementation.

High-risk AI systems: ISO 42001 provides practical guidelines for detecting and discontinuing AI systems that breach EU AI Act prohibitions, including untargeted facial recognition or biased decision-making algorithms.

These overlaps allow your team to reuse the existing controls you might have put into place while pursuing ISO 42001 certification to simplify compliance with the EU AI Act.

How to approach compliance with ISO 42001 and the EU AI Act

If you’ve already obtained an ISO 42001 certificate, the first step toward EU AI Act compliance is to cross-reference your existing controls with the Act’s requirements. You can then identify all compliance gaps that require remediation to ensure adherence to the Act.

If you haven’t achieved ISO 42001 compliance, you can choose whether to implement it first or focus on the EU AI Act directly. Since the Act is comprehensive and mandatory, prioritising it might be the more practical option.

This doesn’t mean you should skip ISO 42001 compliance altogether, becoming certified lets you build a robust AIMS that helps future-proof your AI-related operations. It can also give you a notable competitive advantage because it shows commitment to responsible AI use beyond the mandatory regulations. Keeping this in mind, combining ISO 42001 certification with EU AI Act compliance is the most comprehensive way to develop and implement AI responsibly. To help, we’ll go over the high-level processes of complying with both standards.

How to obtain an ISO 42001 certificate

To become ISO 42001-certified, it is advised organisations undertake the following steps:

Understand the principles and requirements: ISO 42001 has 10 clauses, six of which outline the specific requirements you must meet to get certified. It also includes four annexes with detailed prescriptive guidance you can use to implement the necessary controls.

Conduct a gap analysis: Analyse your current or prospective AI system to see how it aligns with ISO 42001 requirements. Some of the key aspects you’ll need to review include roles and responsibilities, data and resources used to build the system, and the impact of AI systems on stakeholders and your broader environment. Use the findings to develop a strategy for closing the gaps and achieving compliance.

Build your AIMS: Go through the ISO requirements to develop the policies, procedures, and practices that will be encompassed by your AIMS to ensure ongoing compliance with the prescribed standards.

Document your processes: Document the implementation of the relevant controls to ensure transparency and clear oversight of your AI processes.

Continuously monitor and improve: Continuously monitor and review your AIMS to identify opportunities for the improvement of its suitability, adequacy, and effectiveness.

How to achieve EU AI Act compliance

While the specific steps to achieving EU AI Act compliance depend on the current state of your AI systems, the general process consists of the following steps:

Assess the Act’s impact on your organisation: Use an EU AI Act Compliance Checker or specialist GRC partner to precisely determine how the Act affects your organisation.

Review and document your AI practices: Perform a comprehensive assessment of your current AI systems, documenting the related policies and practices to make the relevant information readily available to auditing bodies.

Perform a conformity assessment: If your AI system is classified as high-risk, conduct a conformity assessment to bridge any compliance gaps related to transparency, risk management, record-keeping, and other relevant requirements.

Submit your EU Declaration of Conformity: After ensuring EU AI Act compliance, submit an EU Declaration of Conformity in physical or electronic form.

Conduct post-market monitoring and reassessment: Develop a system for continuously monitoring and reporting your AI system’s performance and adherence to the EU AI Actace to recover your system should the worst happen might be the key to keeping your organisation functional during a cyber security incident – without them your organisation may be unable to fully recover.

Within all modern organisations there is a technical supply chain which underpins how that organisation not only functions, but also how it protects itself. Recognising the importance of IT supply chains and minimising disruptions and vulnerabilities should be an ongoing focus for all organisations. Protection of IT supply chains is becoming increasingly important for small and medium-sized enterprises (SME’s) which are increasingly becoming targeted for supply chain attacks due to their less rigorous security risk-management measures.

The EU ICT supply chain security toolbox seeks to provide member states with a common and structured approach to securing their supply chains. Its key objectives are:

  • Create and foster a common understanding of supply chain security risks
  • Identify potential threats, vulnerabilities and risks within the supply chain through a scenario-based methodology
  • Provide recommendations to secure the ICT supply chain

The ultimate objective of the EU supply chain toolbox is to provide guidance on effective measures for managing security risks at each stage of the services lifecycle across hardware, software and managed security services. The IT supply chain toolbox is technology agnostic and aims to focus on the assessment of supply chain risk rather than targeting specific technologies.

This toolbox aims to not only educate organisations around how they can better manage their security risk and technology but to provide them with the examples to empower them to manage their security.

Three things the toolbox does

1. It makes risk scenarios real and actionable

Abstract risk language can be confusing when it comes to effective security governance. Telling a board that ‘supply chain threats are increasing’ generates concern but without the right business context – how it will affect business KPI’s, and KBI’s it rarely generates action. The EU ICT Supply Chain Security Toolbox aims to replace theoretical risk with real quantifiable risk aligned to an organisation’s goals and objectives.

It identifies risk scenarios across three categories:

  • Deliberate threats such as ransomware attacks against managed service providers and the insertion of counterfeit hardware components
  • Unintended threats including faulty software updates cascading across dependent systems
  • External events such as supplier lock-in and geopolitical disruptions that could constrain an organisation’s ability to operate with a vendor they have relied upon for years

These scenarios are not hypothetical. They are drawn from documented incident patterns, ENISA threat intelligence, and the collective experience of national cyber security authorities. For IT teams, they provide a structured way for assessing supply chain exposure, not in the abstract, but against specific, realistic threat pathways.

2. It gives organisations a structured mitigation framework

The toolbox does not stop at identifying risks. It provides seven recommendations grouped across four strategic pillars, giving organisations a clear action framework rather than a list of concerns.

The first pillar demands a robust framework for ICT supply chain risk management, moving beyond point-in-time assessments to establish structured, repeatable processes that cover the full supplier ecosystem, including the tier-two and tier-three dependencies that most organisations currently have limited visibility into.

The second pillar addresses supply chain resilience through diversity, the toolbox highlights that single-vendor dependency is a strategic vulnerability, and that multi-vendor strategies are not just commercially sensible but a security ‘must have’.

When it comes to the third pillar it focuses on situational awareness and operational cooperation, the kind of structured information sharing between organisations and sectors that transforms isolated security teams into a networked defence community.

The fourth pillar looks to the longer term – building a resilient, trusted, and transparent industrial base through standards alignment, security certification, and an interoperable ecosystem where Software Bills of Materials (SBOMs) and cryptographic attestation become baseline procurement expectations.

Each of these pillars has immediate operational implications for IT teams. They are not aspirational; they are the measures against which your supply chain security programme will increasingly be assessed.

3. Extended scope to critical sectors through dedicated risk assessments

The toolbox is accompanied by two Union-level coordinated risk assessments that signal where the EU considers the supply chain threat to be most acute right now.

The first focuses on connected and automated vehicles, a sector where the convergence of hardware complexity, software dependency, and remote update capability creates a large supply chain attack surface. The NIS Cooperation Group recommends that the Commission and Member States identify proportionate measures to de-risk EU supply chains from high-risk suppliers, particularly in processing and decision-making systems and vehicle control components capable of receiving remote updates.

The second focuses on detection equipment used at borders and customs, infrastructure that sits at the intersection of physical and digital security, and where supply chain compromise could have consequences that extend well beyond the cyber domain.

For IT teams operating in or as part of these sectors, these assessments are not background reading. They are a direct signal of where regulatory scrutiny will intensify.

The competitive dimension IT Departments are missing

From our discussions with several customers over recent months at Cyberfort we know that supply chain security conversations are not happening in enough boardrooms. Instead of supply chain security being seen as another compliance task to complete it should be treated as a competitive differentiator.

Organisations that can demonstrate structured, auditable supply chain risk management will increasingly win procurement decisions, particularly in public sector and regulated industries where NIS2 and DORA compliance is a requirement for suppliers. Organisations that cannot demonstrate this will find themselves excluded from opportunities, regardless of how competitive their core offering is.

The EU ICT Supply Chain Security Toolbox provides the framework to build that capability credibly and systematically. IT teams who engage with it proactively, embedding its risk scenarios into their vendor assessment processes, aligning their procurement governance with its recommendations, and investing in the information sharing infrastructure it calls for, will be ahead of the curve when national authorities begin enforcement.

Those who wait for enforcement to begin will be playing catch-up in a regulatory environment that has less tolerance for delay.

So what does this look like in practice?

An example scenario for an organisation to consider from the EU ICT supply chain toolbox which would apply to most organisations is;

A Cloud service provider has a datacentre outage due to human error which prevents access to millions of domains including your organisations. This disruption to your web application has its root cause traced back to an air vent being mistakenly closed in the datacentre which although simple to remediate has left many organisations’ online services down or working at limited capacity after they failed services over to other datacentres. This extended period of downtime raises concerns around the resilience of hosting vital organisational infrastructure in the cloud.

How would the analysis of this look?

Type of incident: Service outage

Root cause: Human error

Supply chain: Cloud computing provider, organisational users of the cloud computing provider

Threat actor who could use this scenario to their advantage: Advanced persistent threats, Organised crime groups, Insiders in the supply chain

Vulnerability: Poor practices by cloud computing provider, poor supply chain management by the end user organisation

Impact: Reputational damage, service disruptions (availability and integrity)

For organisations these types of incidents and risks should be considered as part of their operations. They need to consider how they would they recover if something like this were to happen and do they have any measures in place to minimise the damage it would cause to their operations.

Without a business continuity/disaster recovery plan in place an organisation may struggle how to prioritise remediation and get their operations up and running again.

Where to start with developing a business continuity plan

Firstly, identify your most critical and time sensitive operations and the impact that disruption to any of these operations would have. Measure the impact and likelihood of these operations being disrupted and attribute a timescale as to how long your organisation would continue with these services deprecated.

Plan your response strategy – having processes in place to not only identify issues as they arise, but also how technical support are contacted in case of an emergency and what the roles look like for the involved teams will be a first step in bringing the organisation back to its full operations.

Consider the recovery – define the steps which would be required in a variety of scenarios which would need to be completed in order to recover these critical services. That could be server failover to a new region or removal of malware from a server depending on which risks you have defined. Create a team which know how to start recovery and who know where to find the necessary materials to begin the recovery process

Train around your key risk scenarios – you may have plans written but do you know these plans work in practice, consider running tabletop exercises to train staff around how they might work in a  real-world situation. This will identify key areas of weakness which can be considered and remediated before a real-world situation occurs.

Ensure communication channels are detailed within the organisation – In case of X happening this is the go-to team and people we need to help resolve it should be defined in the business continuity plan. Understanding who needs to be involved will speed up the time to recover rather than having people searching for the right teams when they’re under high time pressure.

Disaster could strike at any time day or night and the last thing you want is to be trying to work out who you need to call at 3am. Have plans for any regulatory or external comms you might need to make in case of a breach in GDPR or cases where your organisations attack is one with wide external consequences. This might be informing your suppliers, the ICO, customers or industry of what has happened and the steps you are taking to remediate.

Four top recommendations for effective incident response include:

  • Partners – know your supporting partners and contact details/process – Cyber Incident Response (CIR), Insurance, Legal
  • Decision process – Board responsibilities – have clear and known Board level decision and escalation processes
  • Empowering decision makers – rehearse and engage with Board stakeholders, educate any that are not Cyber aware
  • Exercising and planning, prioritise information sharing (reporting) etc

Disaster recovery planning

Disaster recovery plans go into greater depth than the business continuity plan defining the recovery objectives and how systems and data needs to be protected during an outage. The recovery time objective determines the maximum acceptable time the system or component can be down before it starts causing unacceptable damage to the organisation. This will be individual to the specific component of the organisation and will be based around the result of the business impact assessment (BIA).

As part of this process there will also be the need to define a recovery point objective (RPO) to answer the question. How much data can we afford to lose in case of a disaster? If the answer to the question is we cannot afford to lose any of this data – you may need to consider how you can improve your security posture to best protect this data as any and all systems can be compromised.

For data which your organisation feels they could afford to lose, build your disaster recovery plans accordingly.

How do business continuity and disaster recovery plans benefit the organisations who have invested in them?

Reduced downtime – keeping any security incident based downtime to a minimum is key to maintaining a good relationship with stakeholders. If your organisation find itself unable to recover previous customers may start to move to competitors who have been able to maintain operations during any cyber attacks or incidents.

Lower financial risk – the average cost of a data breach has been increasing year on year up until last year where it fell by 9% to $4.4 million due to improved speed of identification and containment as organisations have become more aware of their general risk landscape. 

Reduction in penalty risk – having a plan to mitigate data loss will reduce the overall security risk around your organisations data. Without appropriate measures in place to start data or system recovery the organisation can be left open to high penalties for losing sensitive customer information. This is most prevalent in healthcare, finance and government environments. Having plans and steps in place to recover your system should the worst happen might be the key to keeping your organisation functional during a cyber security incident – without them your organisation may be unable to fully recover.

Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.