By Dan Wood, Group CISO Cyberfort

Two-thirds of CEOs want to be notified of a cyber attack within half an hour, with most expecting basic operations to be back up and running within a day. How can firms speed up their recovery?
The way an organization recovers from a cyber attack can be the difference between minimal disruption and going out of business. But while effective recovery can take time, business leaders are increasingly focusing on speed.

Recent data shows CEOs are placing huge demands on security professionals to be able to get back up and running quickly. Two-thirds of CEOs expect to be notified of a cyberattack within half an hour, according to research from Cohesity. While 19% of business leaders think they should be alerted to a breach within five minutes.Around 38% of CEOs expect basic operations to be back up and running within a day, with 14% saying this should happen in just one hour.

The UK government’s recent Cyber Security Breaches Survery shows most firms can recover within 24 hours. Is this really possible, and if so, how can firms harden defences so they are able to get back up and running swiftly?

Attack timelines

After a cyberattack hits, some businesses will descend into chaos. “Systems are down, normal tooling doesn’t work – and you may even be isolated from the internet,” says Ade Clewlow MBE, associate director and senior advisor at NCC Group.

Yet amid this complex and high-stakes environment, experts say the first few hours after discovering an incident are critical. “How companies react to a breach in the first few hours matters,” says Dennis Martin, cyber and crisis resilience specialist at Axians UK.

He explains how during a live ransomware attack for example, the call on whether to disconnect the network and shut down systems needs to be made quickly. “In practice, this means teams monitoring the network need clear pre-authorisation to shut it down if they suspect an attack. It also means there should be a plan on how to restore once the system has been taken down, for both false-positive cases and confirmed attacks.”

Among the steps required, victims need to rapidly establish what has happened, assess whether the threat actor is still active, and work out which systems are affected. They then need to identify the steps needed to minimize the attack’s impact. “Immediate priorities typically include containing the attack and engaging key stakeholders,” according to Adam Harrison, managing director in the cybersecurity practice at FTI Consulting.

Speed is important, but acting on incomplete or inaccurate information “can be just as damaging as acting too slowly”, Harrison warns. He says overreacting to a false positive, disconnecting systems in a manner that makes recovery more difficult, or causing unnecessary business disruption “can serve as a self-inflicted wound”.

Understanding the scope

Some steps can be taken straight after an attack, such as the initial containment. While this can often begin within the first hours, understanding the full scope of an incident may “take days or even weeks”, says Harrison.

Dan Wood, CISO at Cyberfort concurs. He believes recovering quickly and recovering well are “two very different things”.

“Everybody pats you on the back for getting operations restored in 24 hours after a cyber breach, but if you haven’t recovered well, recovering quickly is pointless,” he says.

Wood says he’s seen organizations seemingly back up and running within hours, but at a cost. “Then they suffer the same attack days later because compromised backups placed the vulnerability and the attacker’s back door straight back into live operation.”

The goal should be to have core services running in a clean environment, and to be able to prove this, Martin advises. “Otherwise, systems may be quickly compromised again, and, if a clean environment can’t be proven, partners won’t allow reactivation of vital interfaces.”

Yet at the same time, a slow response can be damaging. The impact of this will depend on the phase of the attack, according to Harrison. In the early stages, any delay gives an attacker more opportunity to achieve their objectives, he says. “They may access more systems, steal additional data, deploy ransomware, or establish persistence that makes later eradication significantly harder.”

Sluggish responses also increase business disruption. “Systems that could have been isolated early may instead require complete rebuilding,” says Harrison. “Recovery costs can also escalate and regulatory obligations will become more complex if additional data is compromised.”

In the latter stages of an incident, or after the adversary has already performed their ‘actions on objective’, the focus shifts from preventing compromise and limiting further damage to restoring operations safely and understanding the full extent of the impact, according to Harrison. “At that point, delays can prolong downtime and increase recovery costs.”

Recovery timelines

The pressure is on, and the initial response should be rapid. But CEOS must also be realistic about the possibility of recovering too quickly.

“The number of variables involved in an attack will always dictate the speed of recovery,” Clewlow says. “For example, the threat from AI is moving at pace, so a successful AI-enabled technical attack has the potential to be more damaging in a shorter time.”

However, an organization that experiences minor disruption, such as a website being defaced, can usually recover relatively quickly, says Clewlow.

“Although technically a cyber incident, this is at the less severe end of the sliding scale. The larger and more complex the network is, the more severe the incident is likely to be, and the longer it will take to return to business as usual.”

Meeting the 24-hour benchmark demands “genuine organizational rigour”, according to Tracey Hannan-Jones, consulting director in information security, UBDS Digital.

“This means documented and rehearsed response plans, clearly assigned roles, pre-approved communication templates, and recovery infrastructure that is tested regularly and never assumed to work.”

Some of the basics include foundational cyber hygiene and ensuring your network is adequately segmented, according to Clewlow.

It’s also key to know what the minimum viable operations are for the business and to understand the assets on the network, says Clewlow. He believes rehearsed response plans are a key factor.

“CISOs should work with colleagues to ensure business continuity plans are shared and verified against information security realities, and that priorities for restoring systems and services after an incident are clearly understood,” he said.

“Recovery from a cyberattack is a team effort, in which the CISO will play an integral role.”

Read the article in ITPro here https://www.itpro.com/security/cyber-attacks/24-hours-to-recover-from-a-cyber-attack

By Dan Wood, Group CISO Cyberfort

As cyberthreats, regulatory requirements and third-party risks continue to evolve, organisations need a more continuous and connected approach to managing risk. Dan Wood, Group CISO at Cyberfort, explains why traditional risk management practices are no longer enough and how modern platforms can help security teams stay ahead.

Ask most CISOs how they manage risk day to day and the answer you will usually receive is ‘mostly on spreadsheets, bolted onto whatever GRC tool procurement or my predecessor has signed off on, we usually only use the tool once a year when the auditors arrive’. I say that without judgement, I’ve run programmes exactly like this as well. But I no longer think it’s defensible and I suspect most of us already know that is true.

Why traditional risk management doesn’t cut it anymore

The issue isn’t that risk teams don’t care. It’s that risk moves faster than the review cycle built to catch it. A vendor gets breached, a regulation shifts, a new system goes live and none of it waits politely for the next scheduled audit. By the time an exposure surfaces in a quarterly report, it has usually existed for months. Regulators such as the ICO and the FCA aren’t slowing down either and being caught relying on last quarter’s picture of risk is not a comfortable place for any CISO to stand.

Then there’s the sprawl. Most security and risk teams I speak to are juggling some mix of spreadsheets, a legacy GRC platform and manual reporting someone built to plug the gaps between them. Every extra tool adds another version of the truth and every version adds room for error.

Vendor risk is where this shows up hardest. An annual questionnaire tells you what a supplier’s posture looked like on the day they filled it in, not what it looks like now. A vendor can pass a review in January and quietly change its sub-processors, its access controls, or its own security posture by June and nobody finds out until it’s the vendor’s breach notification landing in your inbox. Given how many recent high-profile breaches have started with a third party in the last 12 months, treating vendor oversight as a once-a-year tick-box exercise feels closer to negligence than due diligence.

Data privacy adds another layer that’s easy to underestimate. Between UK GDPR obligations, DPIAs and the practical reality of tracking where personal data actually lives across an increasingly sprawling estate, privacy risk rarely gets the continuous attention it needs. It tends to live in a different spreadsheet, owned by a different team, reviewed on a different schedule, which means it’s often the last thing anyone notices has drifted out of control.

Then there’s the board. Cyber-risk is now a standing agenda item, which is progress, but it means CISOs are expected to translate technical and/or regulatory exposure into something a non-technical director can act on, on a schedule that leaves no room for a week of manual data-wrangling before every meeting. I’d rather spend that time on the risk itself than on the slide deck.

What good risk management software does

This is where the right risk management software earns its place. Not as another dashboard to check, but as the connective tissue between what’s happening across the estate and what gets reported upward. Done well, it should give continuous, real-time visibility rather than a point-in-time snapshot; it should replace static vendor questionnaires with ongoing monitoring that flags changes as they happen; it should hold risk data in one place rather than scattered across systems, so reporting to the board becomes an export rather than a project; and it should make the link between what you’re spending and what risk you’re removing, in language a CFO will accept.

Choosing the right platform

Choosing the right platform is less about the longest feature list and more about fit. I’d start by being honest about which categories of risk keep you up at night  – operational, regulatory or vendor –  because that should shape what you prioritise, rather than working backwards from a demo.

I’d then test how much of the workflow is genuinely automated versus how much is automation in name only, because plenty of tools promise intelligence and deliver another queue to manage. I’d look hard at integration: a platform that can’t pull from your identity provider, your cloud environment and your HR system will always be working from an incomplete picture, however polished its dashboard looks.

If you operate internationally, stress-test how it copes with multiple regulatory regimes at once – that’s usually where the cracks show first.

Cost matters too, but not in isolation. The sticker price rarely reflects the true cost of ownership once you’ve added training, setup and the internal resource needed to keep it configured properly. I’d rather pay more for a platform with strong support during adoption than save money upfront and spend the next year fighting the implementation. Ask what happens six months in, once the initial enthusiasm has worn off and the platform needs to run itself – that’s the question vendors are least keen to answer in a sales pitch.

Getting implementation right

Implementation is where good intentions often stall. The organisations that get the most from this software tend to do a few things consistently: they map their existing processes and access rights before switching anything on, rather than discovering the gaps live; they train people properly rather than assuming a new interface is self-explanatory; and they track outcomes deliberately, so there’s real evidence to show leadership rather than a vague sense that things feel better.

None of that is glamorous, but it’s the difference between a platform that gets used and one that quietly becomes shelfware within a year.

None of this replaces judgement. Software won’t decide your risk appetite for you, and it won’t have the difficult conversation with a business unit that’s ignoring a control gap. What it does is remove the excuse of not knowing – and in a landscape where regulators, boards and attackers are all moving faster than the traditional audit cycle, not knowing is no longer an option any of us can afford.

Read the article in Intelligent CISO here https://www.intelligentciso.com/2026/07/30/using-the-right-risk-management-software-to-build-resilience/

By Dan Wood, Group CISO Cyberfort

Dan Wood, Group CISO at Cyberfort, argues that resilience depends as much on people, governance, and live supply chain visibility as on security tooling.

Walk into any security conference this year and the conversation sounds the same wherever you stand. AI. Automation. Next-generation tooling. Every vendor stand promises the platform that will finally get you ahead of the threat. And I understand the appeal, I sit on the buying side of that conversation too, and these tools genuinely have value.

But I’ve sat in enough incident rooms at 2am to know that the breaches which do the most damage are rarely the ones a better tool would have stopped. They’re the ones where somebody clicked, somebody trusted, or somebody assumed a partner had it covered.

The next generation of cyber resilience won’t be defined by who has the shiniest stack. It will be defined by who takes people, governance and culture as seriously as they take technology.

The human element hasn’t gone away, it’s evolved

The Verizon 2026 Data Breach Investigations Report puts the human element in 62% of confirmed breaches. I’m not surprised by that number, and I don’t think anyone still working the floor of a SOC would be either.

What I do think is wrong is how the industry still talks about it. “Humans are the weakest link” needs to be retired for good. In my experience, the organisations that get breached hardest aren’t the ones with careless staff, they’re the ones where nobody made it easy, safe or rewarding for a person to say “something feels off about this.”

People are not a vulnerability to be fixed. They are the first line of defence, and often the only barrier a determined attacker needs to overcome. When organisations recognise people as a critical security control and invest in them with the same priority as any technical control, the effectiveness and resilience of the entire security programme changes dramatically.

Your supply chain is now your attack surface

Ernst & Young’s disclosure this year where an unauthorised party got in through a third-party IT support platform and walked out with client tax and investment documents, is the story I keep coming back to. Not because it’s unusual, but because it’s exactly the kind of access nobody puts on the risk register. Nobody runs a tabletop exercise on the support desk.

That’s the pattern I see again and again advising boards: enormous energy poured into hardening the front door, and a fire escape round the back that hasn’t been checked in two years because it belongs to somebody else’s IT estate, not yours.

Verizon’s data shows third-party involvement in breaches has roughly doubled in a single year, and honestly, having watched procurement and security teams operate in silo rather than together for most of my career, I’m more surprised it isn’t higher. A vendor risk register that gets updated once a year at renewal isn’t governance. It’s checkbox paperwork.

Point-in-time assurance is not resilience

This is where I think most organisations are still getting it wrong, and it’s the argument I find myself making most often in the boardroom. A clean audit report or a passed penetration test gives you a snapshot in time, not a state of ongoing health. Risk, control effectiveness and vendor exposure all shift week to week, sometimes day to day.

I’d rather have honest, continuous visibility of where I’m exposed right now than a polished report telling me I was fine three months ago. Resilience is a live picture, not a certificate on the wall.

Where I’d spend the next pound

If you’re a CISO staring at next year’s budget, here’s where I’d start, in order, and it’s a deliberately practical, pragmatic order.

First, continuous risk visibility. Build the capability to see control effectiveness and emerging exposure in near real time, not just at renewal or audit season.

Second, supply chain resilience. Continuous monitoring of third parties, cloud providers and technology partners needs its own budget line and its own named owner, not a clause in someone else’s contract review.

Third and this is the one I’d never cut, whatever the pressure on budget: your people. Security awareness has to graduate from an annual compliance module into a genuine culture, one where reporting a mistake is rewarded rather than punished, where security is everybody’s job, and where the board asks sharp questions instead of nodding along to a green dashboard.

Technology gives you capability. Governance gives you direction. But it’s people who create resilience. I’ve yet to see an organisation talk itself out of a breach with a tool it bought after the fact. I’ve seen plenty talk themselves out of one because someone on the front line trusted their instincts and picked up the phone.

Fund all three, in that order when budgets are tight, and you’ll be building resilience rather than shopping for it.

Read the article in Cyber Insider here https://cyberinsider.co.uk/stop-buying-resilience-start-building-it/

By Nige Wilkinson, COO, Cyberfort

Recent high-profile cyber breaches have made uncomfortable reading for business leaders across every sector. Incidents in the last 12 months at Jaguar Land Rover and Marks & Spencer point to a widespread failure to treat the supply chain as a live attack surface.

Most organisations have invested heavily in their own cyber defences. But, the supply chain, by contrast doesn’t receive the attention it deserves with many organisations only completing a yearly questionnaire to pass a compliance audit and not taking real time actions to address potential vulnerabilities.

The attitude towards supply chain security needs to change if organisations are to move to becoming more secure and resilient both today and in the future. Supply chain security gaps can no longer be seen as minor oversights, they need to be treated as critical vulnerabilities.

According to the UK Government’s Cyber Security Breaches Survey 2025, just 14% of UK businesses reviewed the cyber risks posed by their immediate suppliers in the last 12 months. The number falls further still when you look beyond tier-one relationships into the wider supply ecosystem.

The real risk is not third parties. It is permanent access

The instinct is to frame supply chain security as a problem of third-party risk. But that framing misses something important. Organisations do not get breached simply because a supplier exists. They get breached because suppliers are over-trusted once they are onboarded, then quietly forgotten. Access is granted, rarely revisited, and almost never reduced.

What that creates is a population of accounts and access pathways that persist long after the justification for them has changed, or in some cases, disappeared entirely. When people leave a supplier organisation, those accounts do not always follow them out the door. When a supplier’s own controls weaken over time, nobody is checking. And when an adversary compromises a downstream supplier and begins traversing their way up the chain using perfectly legitimate credentials, the defences you have built around your own environment offer no meaningful resistance, because the attacker is coming in through an approved route.

The risk is not the third party. The risk is permanent access in a constantly changing environment.

You cannot manage what you cannot see

Suppliers accumulate in organisations without systematic oversight. Teams procure tools, services, and technical support independently. Contracts get signed and relationships begin without the knowledge of those responsible for managing supplier risk. By the time anyone attempts to map the full landscape, the picture is considerably more complex than the official supplier list suggests.

At an event last year, a CISO for a major airline described beginning a supply chain security programme not with assessment, but with mapping. He drew out the entire passenger journey and identified every third-party dependency at each stage. What emerged was a supply chain far broader than his organisation had previously recognised. You need to do the same: understand the full ecosystem, rank suppliers by criticality, and identify who has access to your systems. A one-person consultancy buried in tier three may carry more risk than a large, well-known provider, precisely because nobody is watching it.

Compliance is a baseline, not a guarantee

There is an understandable temptation to rely on certifications and questionnaires as a proxy for assurance. If a supplier holds ISO 27001 or has passed Cyber Essentials Plus, it is natural to assume that a meaningful level of control is in place.

The problem is that certifications confirm what an organisation looked like on a particular day. Cyber Essentials Plus is renewed annually, much like a car MOT. A supplier can be in excellent shape on the day of audit and in a significantly weaker position the following day if patching lapses, logs go unreviewed, or staff turnover leaves gaps in access management.

Sending a supplier a checklist asking whether policies exist and controls are in place provides something to point to if things go wrong, but it does not provide assurance that those controls are functioning. Active, independent assessment is a different exercise entirely, and for critical suppliers, it is the only approach that gives you genuine confidence.

What the regulatory landscape is telling you

It would be a mistake to view supply chain security purely through the lens of breach avoidance. NIS2, DORA, and the UK Cyber Resilience Act all place significant obligations on organisations to demonstrate active oversight of their supply chains, across financial services, regulated industries, and commercial supply chains alike. Organisations with documented criticality registers, evidence-based assessments, and clear remediation plans will be far better positioned to respond. Those still relying on periodic questionnaires will find themselves exposed, both operationally and in terms of regulatory standing.

Where to start

The priority is visibility. Map your supply chain before you attempt to manage it. Understand who is in your ecosystem, what access they hold, and what the impact would be if they were compromised or unavailable. Rank suppliers by criticality, not just by contract value or brand recognition.

From that foundation, build a management approach that is proportionate to the risk each supplier represents. Critical suppliers with system access require active, evidence-based assurance. Lower-risk suppliers require less intensive oversight. The approach should be calibrated, not uniform.

Supply chain security is no longer a background compliance task. For organisations that want to protect their operations, their customers, and their reputations, it is one of the most pressing operational priorities of the moment.

Read the article on IT In The Supply Chain here https://itsupplychain.com/your-supply-chain-is-not-a-peripheral-risk-it-is-your-greatest-vulnerability/

By Glen Williams, CEO, Cyberfort


What’s been your business high point of the last 12 months?

Without doubt, it’s the progress we’ve made in harnessing the power of AI across the business. While we’re still at a relatively early stage in that journey, what’s already clear is the significant impact it can have – from streamlining operations to enhancing how we deliver for clients. The potential we’re seeing gives us real confidence in where it can take us over the next few years and getting that foundation right has been a genuine highlight.

Name one thing your company is looking to achieve in 2026.

One of our key goals for 2026 is to firmly establish ourselves as the ‘Employer of Choice for Neurodiverse Employees’ and it’s something we’re genuinely passionate about. We’re actively working to build an environment where neurodivergent talent isn’t just welcomed, but truly valued and supported. We’ve already made significant progress in this area, from the way we recruit through to how we structure roles and support our people day-to-day. For us, this isn’t a box-ticking exercise – it’s about building a stronger, more diverse business that benefits everyone.

What keeps you awake at night as a partner leader?

Honestly, the question that sits with me most is: “How do you build an enduring company culture in a world of remote working?” It’s one of the defining challenges of modern leadership. Culture has always been the backbone of any successful business, but so much of it was built organically through shared spaces, chance conversations, and the everyday moments that happen when people are actually together. When your team is apart, you have to be far more intentional about creating that. Getting it right means people feel genuinely connected to the mission and to each other, regardless of where they’re logging in from. Get it wrong, and you risk ending up with a group of individuals rather than a team. It’s something I think about a lot.

Is AI being over-hyped?

In short, the answer is no. I genuinely believe AI is the most significant technology development of the past five years, and possibly much longer than that. Yes, there’s a lot of noise around it and not every claim lives up to scrutiny, but the underlying capability is real and it’s advancing fast. What we’re seeing isn’t a bubble – it’s a fundamental shift in how businesses operate, how problems get solved, and how value gets created. The organisations that treat it seriously now and invest in understanding how it applies to their world will be the ones with a real competitive edge. The hype may come and go, but the technology itself is here to stay.

What’s been your most successful internal AI project to date?

Our AI agent has genuinely been a gamechanger this year. We’ve deployed it across several areas of the business and the results have been really encouraging. Where it’s had the biggest impact is in reporting and data analysis – tasks that previously took considerable time and resource can now be done faster and with greater accuracy, which means our people can focus on the things that actually require human judgement. It’s also accelerated how quickly we can identify and implement process improvements, which in a fast-moving environment like ours makes a real difference. What makes it our most successful internal project is simple: it’s delivering tangible, visible results across the business, and we’re only scratching the surface of what it can do.

Can you share a surprising prediction about how UK IT channel partners or the UK IT channel will evolve over the next five years?

It may not be the most surprising prediction, but I think it’s one of the most important ones to pay attention to is that consolidation in the channel is going to continue and accelerate, particularly in the cyber partner space. The market is still quite fragmented, and as customer expectations rise, the complexity of what’s required to deliver genuine cyber security outcomes is increasing too. Smaller partners will find it harder to keep pace with the investment needed – in technology, in talent, and in compliance. That creates natural pressure toward consolidation, whether through acquisitions, mergers, or tighter partnerships. For those who get ahead of it and position themselves well, it represents a significant opportunity. For those who don’t, the next five years could be quite challenging.

Which tech gizmo could you not function without?

It has to be my iPhone. I know it’s probably the most common answer you’ll hear, but there’s a reason for that – it really has become indispensable. It’s not just a phone anymore, it’s essentially my mobile command centre. Whether I’m staying on top of emails on the move, jumping on a call, keeping across the news, or managing my day, it’s always in my hand. I genuinely think it’s changed the way we all work and not always in ways we notice until you imagine being without it. Take it away and I think most business leaders would feel the impact within the hour.

Which three famous people, dead or alive, would you invite to a dinner party?

Easy one for me – Ian Botham, Ben Stokes and Andrew Flintoff. Yes, I’m a cricket fan! But beyond the sport, what those three have in common is that they’re not just great cricketers – they’re genuine characters and winners. Each of them has that rare ability to change the mood of a room, lead from the front under real pressure, and carry people with them. I think the conversation would be anything but dull. You’d have Botham’s largerthan-life stories from a golden era, Flintoff’s humour and heart, and Stokes bringing that quiet intensity and modern leadership perspective. I think we’d have an incredible night and I’d share a beer or two with them.

If you had a warning label, what would it say?

Mine would probably read: “Warning: may deliver feedback with more directness than expected.” I’ve always believed that straight talking, done respectfully, is one of the most valuable things a leader can offer. People always know where they stand with me, and I think that builds trust over time even if it can catch people off guard initially.

Which tech figurehead has impressed you the most this year?

For me it has to be Mike Norris at Computacenter. What he’s achieved in building Computacenter into a FTSE 100 company is genuinely remarkable. This is a UK-founded, channel-focused technology business that has grown into one of the most respected names in the industry and that doesn’t happen by accident or overnight. It takes vision, consistency, and the ability to execute over a very long period of time.

Read the article on IT Channel Oxygen here https://giacom.com/it-channel-oxygen-partner-leaders-report/

By Glen Williams, CEO, Cyberfort


Cyber insurance has become one of the most heavily marketed business products of the last decade, and the reasons are easy to understand. Headlines are dominated by warnings of nation state actors, organised ransomware cartels and supply chain compromises that can bring entire sectors to a standstill.

Against this backdrop, boards across the world are under mounting pressure from brokers, regulators, and investors to purchase ever more comprehensive cover. Yet in an ironic twist, the most damaging security breach is rarely the one any insurance policy was designed to anticipate or cover.

The uncomfortable truth is that an intruder is far more likely to walk through the front door in a four pound high-vis jacket and a clipboard in hand than to tunnel through the firewall with a zero day exploit.

That is not a marketing line, it is an operational reality our consultants observe during physical and social engineering assessments. The person asking to read the meter, or holding the door while an employee swipes their pass, represents a far greater form of risk that no policy wording has yet managed to capture.

The pressure to insure against the wrong threat — Cyber insurance premiums have climbed steadily since 2021, and the questionnaires that accompany them have grown longer and more prescriptive with every renewal cycle.

Businesses are being asked to evidence multi factor authentication, endpoint detection, immutable backups, and further controls that stretch into dozens of line items. These are sensible measures and we would encourage any organisation to of course adopt them as standard practices.

The difficulty arises when leadership teams mistake the completion of an insurance schedule for a genuine programme of cyber resilience. A policy is a financial instrument that responds after an incident has occurred, and the payout, where it materialises at all, rarely covers reputational damage, regulatory consequence, or the loss of a customer who decides your organisation is no longer a safe pair of hands.

Treating insurance as the centre of strategy also distorts investment priorities, and we regularly see finance directors commit significant sums to premiums while the budget for staff awareness, access reviews, and physical security remains untouched from one year to the next.

Where risk actually lives

Risk does not reside exclusively in technology, and any assessment that treats it as such will miss the majority of the attack surface.

Risk lives in the new starter who has not been briefed on processes, in the third party supplier whose engineer has unsupervised access to your server room, in the printer that still holds a cached copy of last quarter’s board papers and in the leavers process that allows a departed contractor to retain working credentials for months after their engagement has ended.

The organisations that weather incidents most effectively are those that have mapped their genuine risk landscape across three dimensions, namely people, processes, and data. People covers the behaviours, training, and culture that determine how employees respond to the unexpected visitor or the unusual email. Processes covers everything from vendor management to visitor control and physical access through loading bays and back entrances.

Data addresses where information is held, who can reach it, and what would happen in commercial terms if it were exposed, altered, or held to ransom. When these dimensions are understood together, technology investment becomes far more effective because it is targeted at genuine exposure rather than at threats that happen to be fashionable.

Resilience is earned, not purchased

Cyber insurance has a legitimate role to play in any mature risk programme, and I am not suggesting for a moment that a responsible business should be without it. It should, however, be regarded as a backstop rather than a strategy, the equivalent of the business interruption cover that sits alongside a well run continuity plan rather than replacing it.

True resilience is earned through discipline, through honest assessment, and through a willingness to look beyond the firewall to the receptionist’s desk, the loading bay, and the coffee shop where a contractor is working on an unsecured network.

The £4 high-vis jacket will remain one of the most effective tools in an attacker’s inventory for as long as organisations spend more on insuring against the wrong threat than on understanding the one that is already walking, unchallenged, past the front desk.

Read the article on Business Quarter here https://businessquarter.co.uk/wp-content/uploads/2026/07/Business-Quarter-Issue-4-Q2-2026.pdf

By Glen Williams, CEO, Cyberfort


When the United States and Israel launched coordinated strikes against Iran on 28 February 2026, the response was not limited to missiles and military assets. According to CloudSEK, more than 60 Iranian aligned hacktivist groups activated on Telegram within hours. The company described it as the largest single event mobilisation of this ecosystem ever recorded.

The target was not military bases. Instead, it was infrastructure used by civilians.

CloudSEK reports that more than 40,000 US industrial control systems are reachable on the public internet, many protected by default or no credentials. Data from Forescout and Shodan in 2024 also counted over 40K exposed ICS devices in the United States. These systems help run water plants, electricity networks and fuel operations.

Is Cybercrime The New Warfare?

The report concluded, “The barrier to ICS disruption is no longer technical. It is motivational. And the events of 28 February 2026 have provided motivation to 60+ groups simultaneously.”

This raises the question: is the digital world becoming the modern day battlefield? The World Economic Forum spoke about this in a 2017 article and these words are still relevant today. They said, “Sure, cyberwar is better than a kinetic or physical war in many ways, but it could also make war worse. Unless it’s very carefully designed, a cyberattack could be a war crime.”

They continued, “Well, you could go the old fashioned way — call in some airstrikes or send troops to blow up the building — but this would be an open declaration of war, worsening tensions. It would also be a political disaster if your troops or even drones were captured.

“Now, there is another way: you could launch a cyberattack against the facility. This is more invisible and therefore less risky. It’d take too long to directly hack into the facility’s secure network, but you’ve already created an email virus that can knock out the town’s energy grid, which would take out the base.”

An interesting question and topic here. With the rest of the world moving digital, it would only make sense why this is being considered, and many say it has already been the case for decades.

Mike Maddison, CEO of Global Cybersecurity Company NCC Group:

Cyber activity in the Middle East

“The current conflict in the Middle East is proof that cyber operations have become fully integrated with military strategy. Israel and the US have combined cyber attacks with physical strikes to contribute to Iran’s communications blackout. Overall, the majority of cyber activity tied to the Israel–Iran conflict consists of DDoS attacks, website defacements, exaggerated breach claims, and widespread AI‑driven misinformation. This activity is high in volume but low in impact, rather than being materially disruptive.

“The breadth of global supply chains means that while Iran’s cyber capabilities are focused on Israel, the US and the Gulf-region, global companies still need to be vigilant. Supply chains and widely connected digital infrastructure face a realistic risk of disruption or being caught in an information war.”

GPS jamming

“The use of GPS jamming in the Middle East is a timely reminder of the fragility of our reliance on satellite navigation systems. All Global Navigation Satellite System (GNSS) platforms share a critical vulnerability – their signals are inherently weak and susceptible to targeted jamming. This situation underscores the urgent need for robust security investment to safeguard critical national infrastructure.

“The maritime sector remains a high value target due to the scale of disruption a successful attack can cause. As threats evolve, the industry must shift from reactive defence to proactive resilience strategies. Alternative technologies like Long Range Navigation (LORAN) or emerging quantum-based systems offer promise, but neither has yet been delivered at scale. Until then, resilience must come from layered defences and strategic foresight.”

Experts Share Their Thoughts On Cybercrime As The New Battlefield

More experts answer the question…

Our Experts:

  • Jorge Monteiro, CEO, Ethiack
  • Glen Williams, CEO, Cyberfort
  • Paulo Cardoso do Amara, Former CIO and NATO Scientific Advisor on Cybersecurity
  • Jack Alexander, Senior Threat Intelligence Analyst, Quorum Cyber
  • Joseph M. Saunders, Founder and CEO, RunSafe Security
  • Adam Darrah, VP of Intelligence, ZeroFox
  • Kaveh Ranjbar, Co-Founder & CEO, Whisper Security
  • Alexander Niejelow, CEO, Cyber Advisory, Hilco Global
  • Syed Asif Ali, Founder & Digital Media Strategist, Point Media
  • Brian Long, CEO and Co-founder, Adaptive Security
  • Cindy Murray, Chief Information Security Officer (CISO) & Systems Architect, Murray Digital

Jorge Monteiro, CEO, Ethiack

“A wide range of hackers, from cybercriminals to state actors, have fully weaponised AI. On the digital battlefield, threat actors no longer just use AI tools, but instead deploy fully autonomous malware that probes and exploits vulnerabilities in IT systems, even evolving its approach with minimal human input.

“The real-world impact of this AI-enabled cyber threat is an order of magnitude greater than anything seen before – as it can impact entire economies, not just individual organisations. In 2025, an attack on the British carmaker Jaguar Land Rover sent UK car production crashing to its lowest level in 70 years and knocked nearly 0.2% off the UK’s GDP.

“With conflict again raging in the Middle East, there is a risk of more such disruption in 2026: not just from data loss and extortion, but operational paralysis across entire industries.

“To keep pace, organisations must move away from periodic testing of their cyberdefences to adopt continuous, AI-driven security validation. Ethical, autonomous AI tools will become mainstream as enterprises realise they need the same automation and adaptability as that being used to attack them.

“Frameworks like DORA and NIS2 will accelerate this shift toward continuous assurance, and while AI will dominate the front line, human cybersecurity professionals won’t disappear. In our work, AI agents and ethical hackers routinely uncover different classes of vulnerabilities, and only together do they form a complete defence.

“2026 will see the fastest learners, who empower AI to help them find and fix weaknesses before criminals can exploit them, forge ahead. In a year defined by autonomous AI-led attacks, the greatest risk will be standing still.”

Glen Williams, CEO, Cyberfort

“Cyber conflict is no longer a future concern. It is already a core component of modern warfare. When geopolitical tensions rise, the digital domain is often the first-place retaliation appears. What we are seeing now is a clear example of that shift. Cyber operations can disrupt infrastructure, spread misinformation and undermine confidence without a single physical strike.”

“AI is accelerating this trend further. It lowers the barrier to entry for threat actors, automates reconnaissance and allows attacks to be launched at greater scale and speed. That means nation state groups and other threat actors can target energy networks, financial services, communications systems and government infrastructure more efficiently than ever before.”

“The question is not simply whether the US is prepared. It is whether any country is truly prepared for the pace and complexity of modern cyber conflict. The UK faces the same reality. As a highly connected digital economy with globally significant financial services, defence capability and critical infrastructure, the UK remains an attractive target for both state backed groups and opportunistic attackers. Defensive strategies built around traditional security controls are struggling to keep up with highly adaptive, AI assisted adversaries.”

“What this moment underlines is that cyber resilience must now be treated as national security infrastructure on both sides of the Atlantic. Governments and critical industries must assume that digital systems will be targeted during geopolitical crises. Preparation means stronger public private collaboration, continuous threat intelligence sharing and infrastructure designed with resilience at its core rather than as an afterthought.”

Paulo Cardoso do Amara, Former CIO and NATO Scientific Advisor on Cybersecurity

“The digital world grows in importance at the same pace as the dependence that both organisations and citizens place upon it. What once began, in the late 1980s, as a modest infrastructure for sending emails, sharing files, and participating in a few discussion forums has evolved into the nervous system of modern society.

“Interestingly, malware appeared almost as soon as the internet itself became useful. Since around 1988, malicious software has been a persistent reality of the digital ecosystem. In other words, vulnerability was born alongside connectivity and, today, the very dependence on digital systems has become a strategic attack surface.

“Yet it would be simplistic to claim that the digital world alone constitutes the modern battlefield. In reality, it is merely one dimension of a broader strategic landscape. The foundations of this multi-dimensional conflict can be traced back to the 1980s with the articulation of what analysts later called Fourth Generation Warfare.

“In this form of conflict, battles are not fought exclusively with tanks and missiles but across several arenas simultaneously, including economic pressure, intelligence operations, information influence, and political maneuvering. Conventional warfare still exists, of course, as the conflicts in Ukraine and tensions involving Iran clearly demonstrate. But these kinetic engagements now coexist with subtler forms of confrontation where perception, disruption, and influence become decisive.

“In this sense, cyberspace is not a replacement for traditional conflict. It is an extension of it.

“Technology, meanwhile, continues to evolve at a remarkable pace, transforming both offensive and defensive capabilities. Cyberwarfare illustrates this dynamic particularly well. In this context, AI has become a powerful accelerator, amplifying the effectiveness of both attack and defense. However, the decisive factor is not technology alone. As Sun Tzu famously argued “victory belongs to those who understand the terrain and the enemy”. In the digital domain, this terrain is made of code, networks, protocols, and data flows. Mastery therefore depends less on possessing technology and more on understanding it deeply.

“Therefore, those who know how to employ technology strategically are the ones who achieve their objectives.

“From this perspective, the United States occupies a particularly strong position. A significant portion of the digital infrastructure used globally originates from American technological ecosystems. Many of the foundational layers of the internet, from hardware architectures to operating systems and communication protocols, have been developed by U.S. companies and research institutions. This technological primacy creates not only economic advantage but also strategic leverage in pure tactical terms.

“The informational dimension reinforces this position even further. Major technology companies exercise enormous influence through the platforms that mediate global communication. Social networks, search engines, and digital services shape the information environment in which billions of people operate. While these platforms can be exploited by hostile actors, the underlying algorithms and infrastructures remain largely controlled by the companies that designed them.

“Artificial intelligence amplifies this phenomenon dramatically. AI systems can analyse vast volumes of unstructured information, generate persuasive narratives, and adapt content to specific audiences. In the realm of information warfare, this capability becomes a formidable instrument for shaping perceptions. Machiavelli would likely recognise the principle immediately because power often lies not merely in force but in the ability to shape what people believe.

“Thus, artificial intelligence is rapidly becoming one of the most potent weapons in the information domain, particularly in the hands of those who control the digital platforms through which narratives circulate.

“In the language of Clausewitz “war is the continuation of politics by other means”. In the digital age, those means increasingly include algorithms, networks, and data and the United States possesses substantial tactical capabilities in this environment. Whether these capabilities translate into strategic success ultimately depends on how effectively they are employed.

“Technology, after all, provides the weapons. Strategy determines victory.”

Jack Alexander, Senior Threat Intelligence Analyst, Quorum Cyber

Cyber in modern conflict:

“In modern conflict an immediate surge in hostile cyber aggression is to be expected. No longer are wars fought exclusively via the land, air and sea but also within cyberspace. This relatively new phenomenon is known as ‘hybrid warfare’ and is designed to weaken the opponent by directly targeting Critical National Infrastructure (CNI), but can also be used to achieve other strategic goals such as, sowing disinformation and disrupting civilian business continuity.

“This is not the first time that offensive cyber targeting has been used to impact CNI alongside traditional military activity. In 2022, Russian wiperware was deployed against the European Viasat network with the intended aim of impeding Ukrainian military communications, due to the heavy usage of the platform by Ukraine. This highlights the growing normalisation of CNI targeting during times of conflict as another means of disrupting your enemy.”

How AI can be used as a force multiplier:

“The time between vulnerability discovery/disclosure and active exploitation is now as little as 15 minutes via AI powered automated active scanning of networks. Actors are leveraging AI to automate routine tasks, including script generation, attack templating and consistent messaging during extortion efforts.

“Alongside this, social engineering is no longer just phishing with better grammar it is hyper personalised. Attackers can automate Open-Source Intelligence collection to profile targets and craft highly personalised lures that mirror their role, organisation and professional relationships.”

More from News

Joseph M. Saunders, Founder and CEO, RunSafe Security

“Cyber conflict rarely begins with a declaration of war. It unfolds in a persistent gray zone where nation-states and their proxies map networks, test defenses, and pre-position themselves inside critical infrastructure for future leverage. We’re seeing this play out in real time with Iran’s response to the US-Israel strikes.”

“AI has fundamentally changed the cost equation for attackers. Nation-state actors can now move faster, generate more convincing intrusion campaigns, and probe more targets simultaneously than ever before. When you combine that with pre-positioned access in critical infrastructure, like the persistent footholds we’ve seen from groups like Volt Typhoon, you have the ingredients for a very consequential attack.”

“Power grids, water systems, and communications networks are key targets for effects and to achieve outcomes of consequence, but much of this infrastructure was never built to absorb nation-state aggression. The US has world-class offensive cyber capabilities, but our defensive posture for industrial systems remains dangerously inconsistent. Every kinetic action, like the US-Israel strikes on Iran, now has an immediate digital echo. The digital world and the physical battlefield have merged, making cyber resilience the new deterrence.”

Adam Darrah, VP of Intelligence, ZeroFox

“Yes, and it has been since at least what is referred to as the “Arab Spring” or “Arab Awakening”. The digital battleground has encompassed and continues to include social media, mis- dis- and mal-information campaigns, offensive cyber operations that can shut down a country’s energy, military, or other systems. The digital space is where espionage, intelligence, marketing, civil society, shopping, politics, charity, convenience and war all converge. Adversaries do not see a sacred space that is off limits in war, peace, or intelligence collection.”

Is the US prepared?
“Yes. The United States has invested heavily in cyber defense capabilities and deterrence, and any actor considering cyber operations against US systems should assume there would be significant consequences. There is also a lot to unpack when discussing claims of a “surge” in Iranian-aligned cyber activity targeting US critical infrastructure, particularly when AI is described as a force multiplier for threat actors.

The US has adopted what is known as strategic ambiguity when it comes to what constitutes an act of war, probably to disincentivize adversaries to test red lines and ultimately deter conflict. Current administration officials have stated recently that any cyber attack against critical digital infrastructure could be considered an act of war.

When discussing “critical infrastructure”, it’s important to be precise. The US views as a matter of policy that any cyber-attacks against critical infrastructure such as water, sanitation, electricity and other critical systems could be considered precursors to an armed attack against the US homeland.”

Kaveh Ranjbar, Co-Founder & CEO, Whisper Security

“Calling this a “new battlefield” misses the point. Cyber has been the battlefield for years. The strikes make the news. The retaliation is already running.

“What’s happening now isn’t a surprise. Iranian-aligned groups have infrastructure ready to go: domains registered months ago, hosting relationships that predate any specific operation. Tension spikes, infrastructure activates. We’ve watched this pattern repeat since at least 2020.

“The real question isn’t whether the US is “prepared.” It’s whether anyone can see the infrastructure before it fires. Most attribution happens after the damage. By then you’re writing incident reports, not preventing incidents.

“AI makes both sides faster. Attackers spin up variants. Defenders try to map infrastructure at scale. Right now, offense is cheaper.”

Syed Asif Ali, Founder & Digital Media Strategist, Point Media

“Cyber conflict is increasingly becoming a parallel layer of modern geopolitical tension. It doesn’t replace traditional warfare, but it gives states and aligned groups a way to create disruption without the visibility or escalation of conventional military action.

“What makes this environment particularly challenging is how dependent modern economies are on digital infrastructure. Financial systems, logistics networks, cloud platforms, and communications all rely on software layers that can be probed or disrupted remotely. When those systems are targeted, the consequences can ripple far beyond the original point of attack.

“The growing role of AI also changes the equation. It allows threat actors to analyze systems faster, automate reconnaissance, and scale attacks more efficiently than before. That doesn’t mean AI creates entirely new risks, but it accelerates existing ones.

“Preparedness therefore becomes less about a single defensive tool and more about resilience. Governments and organisations need systems designed to detect anomalies early, isolate problems quickly, and recover operations without widespread disruption.

“In practical terms, cyber conflict has already become part of the strategic landscape. The question is less whether it will be a battlefield, and more whether institutions are building the resilience required to operate in that reality.”

Brian Long, CEO and Co-founder, Adaptive Security

“The digital world is absolutely becoming a modern battlefield. Governments and criminal groups now use cyber operations alongside traditional military activity because they can disrupt systems, gather intelligence, and influence public perception without firing a shot.

“We are already seeing the scale of this shift. The World Economic Forum has cited estimates that put the global cost of cybercrime at $10.5 trillion annually. That is the scale of a major global economy, and it shows why cyber conflict has become a serious part of modern geopolitical competition.

“Artificial intelligence is accelerating this trend. Attacks that once required specialised skills can now be launched with inexpensive tools and publicly available data. With just a few seconds of audio or a handful of public information, attackers can generate convincing voice clones, deepfake videos, or highly personalised phishing messages.

“These attacks are also expanding beyond email. Increasingly they happen through phone calls, text messages, and video meetings where people naturally trust what they hear and see. AI allows attackers to run these campaigns at enormous scale and target thousands of people at once.

“At the same time, critical infrastructure has become a major target. Energy systems, financial networks, and supply chains are attractive because disruptions there have immediate real-world consequences. Researchers at the Oxford Internet Institute found that, on one platform alone, more than 35,000 open-source deepfake generators had been downloaded nearly 15 million times since 2022. That shows how quickly these tools are spreading. We are also seeing deepfakes used to impersonate leaders and spread misinformation during moments of geopolitical tension.

“For organisations, cyber resilience is no longer just a technical problem. Most successful breaches still begin with social engineering, which means attackers are manipulating people, not just systems. Companies now need to prepare their workforce for AI-driven deception the same way they prepare their networks for malware.”

Cindy Murray, Chief Information Security Officer (CISO) & Systems Architect, Murray Digital

“Let’s just be honest about this. Cyber is not the new battlefield. It has been the only active warzone for a decade and the premise of the question is exactly why the US is losing. The recent strikes just proved our enemies know exactly how vulnerable our infrastructure is. The Iranian surge is simply a live stress test of a completely incompetent system.

“The problem is not the hackers. The problem is our own bloated architecture. We are protecting a twenty year old grid with bandaids. You can’t put a deadbolt on a screen door and call it secure. If you do not engineer your defense directly into the universal inference layer you are just asking for a breach.

“We are unprepared because Washington refuses to tear out their legacy sprawl. They are fighting an automated war using a bureaucratic checklist. A checklist is just a map for the enemy.”

Read the article on teiss here: https://techround.co.uk/news/experts-cyber-warfare-new-battlefield-modern-conflict/

By Glen Williams, CEO, Cyberfort


There is a phrase that should concern every board member and security leader operating in today’s threat landscape: “We’re covered.”

It sounds reassuring. It implies preparedness. In reality, it often signals the opposite.

Cyber-insurance has matured rapidly over the past decade into a legitimate and important component of organisational risk management. Policies now routinely cover business interruption losses, legal and regulatory costs, incident response support, ransom negotiations and reputational recovery. For organisations hit by a significant breach, that financial cushion can be genuinely significant.

But somewhere along the way, too many organisations began treating the policy as a proxy for the security strategy itself. Buying cyber-insurance cover became the endpoint rather than the backstop. And that confusion is now creating a dangerous gap between perceived protection and actual resilience.

Insurance covers the aftermath

A payout, however substantial, cannot restore trust with customers overnight. It cannot reverse reputational damage. It cannot undo the operational disruption of a manufacturing plant grinding to a halt, a logistics network going dark, or a hospital losing access to patient records. And it absolutely cannot stop an attacker who has already found their way in.

The financial mechanics of insurance have never been designed to do those things. They exist to absorb economic shock after an incident, not to reduce the likelihood of one occurring.

What drives likelihood is resilience. And resilience is something most insurance policies neither measure nor reward, at least not yet.

What insurers are actually asking for

The cyber-insurance market has changed significantly. A few years ago, insurance companies were issuing policies based on relatively lightweight questionnaires, broad assumptions about controls and limited scrutiny of what organisations had actually deployed. That era is closing.

Underwriters today want evidence. They want to see demonstrable incident response capability, not a document that has never been tested. They want visibility into backup maturity and recovery timelines. They want governance structures, identity and access management, third-party risk controls and, increasingly, proof of continuous monitoring and detection capability.

The question insurers are quietly beginning to ask is no longer simply “do you have controls in place?” It is “can you prove your environment is defensible and recoverable?” Those are meaningfully different questions, and many organisations are not yet equipped to answer the second one convincingly.

For businesses that cannot demonstrate genuine operational resilience, the implications are tangible; higher premiums, reduced coverage limits, more restrictive policy exclusions and in some cases, rejected claims where the insurer determines that basic controls were absent.

The compliance trap

Much of the problem stems from how organisations still approach cyber-security. The dominant mindset in many businesses remains compliance led. Have we achieved the relevant certifications? Have we filled in the annual questionnaire? Have we renewed the policy? Box ticked.

What that mindset consistently fails to ask is the more important operational question: could we continue functioning if we were attacked tomorrow?

Compliance and resilience are not the same thing. Passing an audit demonstrates that, at a point in time, documented controls existed. It says very little about whether those controls would hold under pressure, whether staff would know what to do in a crisis, or whether systems could be recovered at the speed the business actually requires.

The organisations that discover these gaps most painfully are those that find them during an incident rather than before.

The human layer remains the weakest point

One of the persistent realities of modern cyber-risk is that the most sophisticated technology stack in the world can be bypassed by remarkably simple means. Attackers do not always need advanced tooling. Sometimes they need someone to hold a door open, a member of staff to click a plausible-looking email, or a supplier with legitimate access and poor credential hygiene.

The human and operational layer of risk remains stubbornly underestimated. Tailgating, impersonation, social engineering, compromised third-party access, and weak verification processes. These are the vectors that continue to feature in significant incidents, not because they are new or sophisticated, but because they exploit trust, routine and the natural tendency of people to prioritise helpfulness over scepticism.

Insurance provides no meaningful protection against these vectors. Only operational rigour does.

Recovery is now a board-level question

The conversation in most boardrooms has shifted from whether a breach might happen to what would happen if it did. That shift in framing is healthy, but it demands a corresponding shift in investment and preparation.

Boards are now asking how quickly systems could be recovered, what a period of downtime would cost, which data and processes are genuinely critical and whether the business could continue trading through an incident. These are not questions that insurance answers. They are questions that resilience planning answers.

Cyber-resilience has become as much a business continuity issue as a technology issue. Recovery speed, containment capability, crisis communications, operational fallback: these capabilities need to be built, tested and embedded before an incident occurs, not assembled under pressure in the middle of one.

Confusing policies with protection

None of this is an argument against cyber-insurance. It remains an important layer of protection and a sensible component of any risk management programme. For businesses operating at scale, or in regulated sectors, it is increasingly non-negotiable.

But it should be understood clearly for what it is: a financial backstop, not a strategy. It is the last line of defence, not the first. It will solve some of your problems, but not all.

The organisations best positioned today are not those with the largest policies. They are the ones that have genuinely understood where their risk sits across people, processes and data; that have built demonstrable operational resilience; and that can show insurers, customers and regulators alike that they are materially harder to disrupt than their peers.

In a threat landscape where the question is no longer ‘if’ but ‘when’, the most dangerous words a business leader can say are still “We’re covered.”

Read the article on teiss here: https://www.teiss.co.uk/news/covered-but-not-protected

By Glen Williams, CEO, Cyberfort


Neurodiversity is no longer a niche workplace issue. It is part of the reality of modern teams, modern leadership and modern performance. For HR and business leaders, that presents a clear opportunity. Organisations that create environments where different thinking styles can do their best work, will have the ability to widen their talent pool, improve decision making and build more resilient teams. The outcome is not simply a more inclusive culture, but a more capable one.

The CIPD estimates that around one in five people are neurodivergent in some way. Many will never disclose a diagnosis to their employer. If hiring and management processes only work for people who fit a narrow, outdated definition of how a strong candidate should communicate, collaborate and perform under pressure, organisations risk missing exceptional talent. In a labour market where skills are scarce and competition is high, that becomes a commercial issue.

I lead a cybersecurity business, where complex problem solving, accuracy and judgement are critical. But this is not unique to technology or security. Any organisation that depends on analysis, creativity, sustained concentration or precision can benefit from neurodivergent talent, provided it designs work in a way that allows people to thrive. The focus should not be on labels. It should be on capability.

Understanding strengths without falling into stereotypes

It is important to approach neurodiversity carefully. It is not a single profile and it does not map neatly onto job roles. Even within the same diagnosis, there is huge variation. The aim is not to stereotype or assume strengths. The aim is to recognise that organisations perform better when they make room for different cognitive approaches rather than rewarding one narrow model of professionalism.

In high pressure and technical environments, certain strengths often emerge. Some people can sustain deep focus for extended periods when working on tasks that engage them. When supported properly, that can translate into exceptional output and consistency in complex work. Some individuals have outstanding attention to detail, which is invaluable in roles that depend on spotting patterns, anomalies or risks.

Another commonly overlooked strength is direct communication. Some neurodivergent individuals communicate literally and clearly. In the right environment, this can improve performance because ambiguity is reduced and assumptions are challenged early. What may be misinterpreted as bluntness is often precision. In organisations where unclear communication is a major cause of inefficiency, precision is an advantage.

Designing work for performance, not exceptions

Many organisations still approach neurodiversity through the lens of individual adjustment, making one off accommodations for a small group of people. While well intentioned, this can create friction. Managers can feel they are being asked to make special arrangements, and employees can feel singled out.

A more effective approach is to start with the workplace itself. Ask what great work requires and what gets in the way. Then design roles, expectations and workflows accordingly. This shifts the focus away from looking to “fix individuals” and towards creating an environment where different people can perform well.

For some roles, this means protecting time for deep work and reducing unnecessary interruptions. For others, it means clarity around priorities and outcomes. In some cases, it involves structuring work into defined packages with clear deliverables rather than expecting uniform output every day. Some people do their best work in intense periods of concentration followed by recovery time. If the only accepted model is steady daily output, high performers can be misjudged as inconsistent when the real issue is misaligned work design.

This is not indulgence. It is effective workforce planning. It also benefits everyone, not just neurodivergent employees.

Rethinking recruitment to avoid losing talent

Recruitment is one of the most common points at which organisations lose neurodivergent candidates, often without realising it. Exclusion is rarely intentional. More often, it happens through outdated hiring practices that prioritise performance in interviews over evidence of capability.

For example, interviews frequently reward confidence, speed and social cues. Those qualities are not reliable indicators of job performance. Small changes can significantly improve fairness and effectiveness. To make interview processes accessible for neurodivergent candidates  organisations should be explicit about what candidates can expect from the process, which can include sending interview questions to candidates in advance of any interview. Hiring managers should use clear, direct questions that invite evidence rather than hypothetical scenarios. The approach should be to treat interviews as structured conversations, not tests designed to catch people out.

Silence should be allowed. Some people need time to process and formulate strong responses. Eye contact and body language should not be treated as proxies for competence. Time should be used well. If a CV has already been reviewed, asking a candidate to repeat it adds little value.

Where possible, skills-based assessments should play a greater role. Practical exercises and work sample tests often provide a more accurate picture of capability and reduce the noise created by interview performance. They also tend to be fairer for all candidates, not just those who are neurodivergent.

Moving from disclosure to curiosity

One of the most powerful shifts organisations can make is moving away from disclosure led support towards curiosity led leadership. Rather than waiting for individuals to disclose a diagnosis, leaders should normalise asking a simple question such as: ‘how do you like to work at your best?’

This opens up conversations about communication preferences, working patterns, meeting styles and feedback without requiring labels. It also supports people who are undiagnosed, unsure or private. The result is a workplace that is better designed for everyone, not just those who feel able to speak up.

The cost of standing still

The business risk of failing to adapt is real. The National Autistic Society highlights that only around three in ten autistic adults are in work. That statistic points to a significant pool of untapped capability. It also highlights how much talent is filtered out by systems that were designed for a workforce of the past.

There is also a retention risk. As awareness grows, more people will articulate what they need to do their best work. If organisational culture treats reasonable adjustments as an inconvenience or advantage seeking, engagement will suffer and talent will leave. Often, leaders will never know what they lost, only that performance declined and hiring became harder.

Building workplaces that let different minds excel

Neurodiversity is often framed as a moral issue. It is that, but it is also a strategic one. Organisations that succeed in the coming years will be those that stop trying to standardise people and start designing work that allows different minds to excel.

This is not about policies or slogans. It is about building workplaces that think better, adapt faster and perform more consistently under pressure. For HR and business leaders, that is not a future aspiration. It is a present-day advantage.

Read the article on The HR Director here: https://www.thehrdirector.com/features/neurodiversity/neurodiversity-reshaping-attraction-retention/

Featuring Nige Wilkinson, COO, Cyberfort


Cybersecurity regulation is changing, driven by a need to be more robust in the face of increasingly sophisticated attacks. As 2026 kicks off, what are the key regulatory changes that will impact UK businesses?

Cyber Resilience Will Be Essential

One major legislation expected in the coming year is the Cyber Security and Resilience Bill, which brings with it a new set of resilience requirements. As the Bill enters Parliament, cyber resilience will “stop being a compliance checkbox “and “become a board-level operational performance test that recognises people, ways of working and the technology needed to succeed,” says Dan Jones, senior security advisor at Tanium.

“The UK government is making it clear that ‘reasonable steps’ and after-the-fact reporting won’t fly in a world where one weak supplier can knock out hospitals, councils or entire supply chains effecting the livelihoods of families and whole communities,” he says.

Over the next year, organisations that can’t prove continuous control of their environments will be “exposed to regulators, customers, and to reality,” he warns.

A key shift, which will not feature as one bill or regulation, is “the incorporation of demonstrable operational resilience into existing legal and regulatory frameworks,” adds Martin Davies, senior audit alliance manager at Drata. “Beyond having security policies in place, firms need systems and suppliers that can withstand disruption and recover within defined tolerances. This already exists as part of the Financial Services regulatory outlook (FCA’s Operational Resilience PS21/3) and is likely to become a facet of regulatory requirements in broader sectors.”

More Companies Will Find Themselves In Scope Of Key Regulation 

As the Cyber Security and Resilience Bill comes into force, it brings with it mandatory adoption of the Cyber Assessment Framework across critical sectors. The scope of regulation expands as the definition of Relevant Managed Service Providers (MSPs) is broadened, placing more of these firms “directly in the regulatory spotlight,” says Jamie Akhtar, CEO and co-founder of CyberSmart. “This change introduces new duties around incident reporting, baseline security controls and formal assurance, meaning that both service providers and their customers must operate with far greater transparency and discipline.”

Supply Chain Risk in The Spotlight

In 2026, regulation will put supply chain risk under the spotlight, experts predict. Supply chain risk has become “hard to ignore,” says Akhtar. High-profile interventions such as the FTSE 350 cyber letter and the latest CSM v4 requirements for defence suppliers have “pushed the issue into the mainstream,” he says.

Large organisations now expect their upstream suppliers, including SMEs, to show that they have implemented basic controls and can maintain resilience in a “consistent and certifiable way,” according to Akhtar. “The bottom line is that we will see the emergence of a market that values demonstrable, continuous cyber competence over declarations of intent.”

The Cyber Security and Resilience Bill will introduce “tougher scrutiny of supply-chain security,” adds Sam Peters, chief product officer at IO. “It will require organisations to standardise supplier due diligence, risk scoring and ongoing monitoring across departments to avoid fragmented processes. Businesses will also need to link supplier controls directly to the organisation’s risk register and resilience expectations, and maintain continuous assurance evidence for high-risk suppliers rather than relying on one-off questionnaires.”

In 2026, third and fourth-party cybersecurity will come under even greater scrutiny, says Mike Smith, partner – security at TXP. “Companies that fail to meet required security levels risk losing business over the coming months as the risk for their customers is simply too high.”

Security initiatives, such as red teaming and penetration testing, and developing robust processes around reporting, “will be crucial for suppliers, ensuring their security standards stand up to external scrutiny,” he adds.

Accountability Requirements Put CISOs “In The Firing Line”

In 2026, legislation such as the UK’s Cyber Security and Resilience Bill will “radically reshape accountability for cyber breaches,” by expanding the definition of critical infrastructure and introducing mandatory 24-hour breach reporting, with escalating fines for non-compliance, says Mark Jow, technical evangelist EMEA at Gigamon.

This legal shift puts CISOs “directly in the firing line,” says Jow.

Ultimately, the legislation moves cyber resilience “decisively into the boardroom,” says Nigel Wilkinson, COO at Cyberfort. “It will no longer be credible for senior leaders to say cyber is ‘owned by IT.’ Regulators will expect clear accountability, informed oversight and proof that cyber resilience is treated like any other critical business risk.”

High-Profile Attacks Will Give The Cyber Security And Resilience Bill A Political Boost

The attacks of 2025 — and the downtime as a result — will inevitably make the Cyber Security and Resilience Bill a key focus in 2026, says Mike Upton, director of partnerships and ecosystem, e2e-assure. “Historically the attitude among critical organisations has been to hold back budget and deal with issues post-breach, with little understanding of how harmful or expensive an approach that can be.”

The Bill promises to change this by making critical organisations implement risk management and improve their cyber posture, he says. “While there’s still aspects of to be finalised, the requirements as they currently stand could still see some stakeholders baulk at the spend required to ensure compliance. If that happens, there will inevitably be a few sacrificial scapegoats to encourage other entities to fall into line.”

UK Government Could Introduce Regulatory Sandboxes for AI

In 2026, it is likely there will be developments in the UK government’s plans to introduce regulatory sandboxes for AI, says Kate Densiton, tech regulation lawyer at Bird & Bird. “In its consultation document on the sandboxes, it said evidence from pilots could lead to regulatory reforms, enabling UK businesses to adopt trusted AI. Having launched a consultation in late 2025, some legislation will be needed over the coming year to give the mandate, budget and scope for the conduct of the AI sandboxes.”

In the UK, it is still unclear what specific regulation will be implemented by the government covering AI. With so many aspects unresolved, there’s “a clear risk that AI usage by UK industry will be impacted by uncertainty,” says Densiton.

In-house lawyers must keep up to date on developments and decide how best to advise the business within the current environment, she says. “We expect the UK government to implement an incremental, narrow regulatory framework for AI in the UK, but clarity might not come until late 2026.”

Read the article on SC Media UK here: https://insight.scmagazineuk.com/regulation-predictions-key-uk-legislation-changes-coming-in-2026

Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.