If your organisation has treated Cyber Essentials as a box-ticking exercise, it is time to reconsider the value of this certification standard. Insurers are already pricing cyber cover against it, some cover is being attached to it for free, and claims outcomes are diverging sharply between those who hold it and those who do not. In this blog article Cyberfort security experts look at why more insurers are mandating Cyber Essentials and Cyber Essentials Plus and where organisations should start with obtaining this certification.

Why are insurers demanding Cyber Essentials?

If your organisation does not hold Cyber Essentials, you are negotiating your cyber insurance from a position of weakness, and you may not even know it. Insurers are no longer treating the certification as a peripheral nice-to-have. They are using it as a baseline signal of risk, attaching real cover to it, and drawing a harder line at the point of claim between organisations that can demonstrate basic control and those that cannot.

This is not a future risk to plan for. It is already happening, and it is happening quietly, in premium calculations and underwriting criteria that most boards never see until a renewal comes in higher than expected, or a claim is challenged. The organisations that treat cyber essentials certification as a compliance formality, rather than as a live input into how their insurer prices and pays out on risk, are the ones who will be caught out first.

This matters more now than it did even two years ago, because the UK government has itself moved decisively. NCSC and the Department for Science, Innovation and Technology (DSIT) have both restated, throughout the past 12 months that Cyber Essentials is central to the UK’s approach to raising baseline cyber resilience across the economy, and the insurance market has followed that signal.

Insurers are already pricing on Cyber Essentials

Cyber insurance underwriting has always relied on some proxy for an applicant’s control maturity, because insurers cannot audit every policyholder’s network before every renewal. For years that proxy was a lengthy self-assessment questionnaire, inconsistently completed and inconsistently trusted. Cyber Essentials gives underwriters something better, an externally verified, government-backed certification against a fixed technical standard, refreshed annually, covering the five controls that NCSC’s own data shows would have prevented the overwhelming majority of the cyber incidents it investigates. 

That is precisely the kind of signal an underwriter wants. Independently assessed, standardised, and easy to verify. Several insurers operating in the UK market now explicitly reference Cyber Essentials in their underwriting criteria for small and medium-sized businesses, and a number offer a preferential rate or a more straightforward application route to certified applicants.

For a CFO or CEO reading a renewal quote, this means a decision made in the IT function – to pursue certification or let it lapse, now shows up as a line on the insurance budget. That is a governance point as much as a technical one. Control decisions taken below board level are already having a financial consequence at board level, whether or not anyone has connected the two.

Certification comes with quantifiable cover attached

The clearest evidence that insurers treat Cyber Essentials as a genuine risk signal, rather than a marketing checkbox, is that some of them are prepared to give away cover on the strength of it. NCSC’s own guidance confirms that organisations with a turnover under £20 million that achieve Cyber Essentials certification receive free cyber liability insurance cover of up to £25,000, automatically included as part of the certification process through NCSC’s delivery partner.

That is not a discount voucher or a marketing gesture. It is underwritten cover, provided because the insurer assessing the risk has concluded that an organisation meeting the Cyber Essentials standard is a materially better risk than one that has not been assessed at all. Insurers do not give away liability cover on organisations they consider high-risk; they price those organisations out or decline them. The fact that this cover is bundled automatically into certification tells you what the insurance market actually believes about the standard’s protective value, more clearly than any marketing statement from NCSC itself could.

For smaller and mid-sized businesses, this is close to a straightforward financial argument. The certification, which typically costs a fraction of a single cyber insurance premium, can bring with it cover that would otherwise need to be purchased separately. For larger organisations above that turnover threshold, the free cover does not apply directly, but the signal to their own insurers, that basic control hygiene is independently verified, still feeds into how their much larger cyber programmes are priced.

Certification changes what happens at the point of claim

The most consequential evidence sits in claims data, not in premiums. NCSC has published figures, drawn from its delivery partner’s own insurance claims experience, showing that organisations holding Cyber Essentials made 92% fewer claims than organisations without the certification. That is a large enough gap that it cannot be dismissed as noise, and it is precisely the kind of statistic that changes underwriting behaviour, because it demonstrates the certification’s protective effect in the real-world outcome insurers care about most, whether they end up paying out.

Beyond the headline number, certification also matters procedurally at the point of a claim being assessed. Insurers increasingly ask, as part of claims handling, whether basic controls were in place at the time of an incident, the same categories of control that Cyber Essentials tests. An organisation that can point to a current certification has a documented, independently verified answer to that question. An organisation that cannot is relying on its own account of its own security posture, offered after the fact, at precisely the moment an insurer has the least reason to take that account at face value. That difference can affect not just the speed of a claim, but its outcome.

The wider context – government is not treating this as optional

None of this is happening in isolation. The UK government has been explicit that Cyber Essentials sits at the centre of its strategy for raising baseline resilience across the economy, and it has backed that position with its own procurement rules. Certain categories of government contract have required Cyber Essentials for a number of years, and the government’s own Cyber Governance Code of Practice, along with its wider Cyber Resilience agenda through 2025 and 2026, continues to push board-level accountability for exactly the control areas the certification tests.

Put simply, the same standard that insurers are using to price risk is the standard government is using to gate contracts and expects boards to own. For a business operating in regulated sectors, supplying the public sector, or answering to increasingly cyber-literate customers and investors, Cyber Essentials is converging into a single reference point that touches procurement eligibility, insurance economics, and governance expectation at the same time. Treating it as three separate, unconnected compliance tasks, one for sales, one for finance, one for the board pack, is where most of the wasted effort and missed opportunity in this space actually sits.

What this means for the board

For senior leaders, the implication is not simply to renew the certificate and move on. It is that Cyber Essentials should be reviewed as a financial and risk instrument, not purely a technical one, and that review needs to happen where finance, risk and the insurance renewal cycle actually meet, which for most organisations is a boardroom conversation, not an IT one.

Three questions are worth putting directly to your executive team and your broker at the next renewal:

1. Does your current cyber insurance policy reference Cyber Essentials, or a comparable control standard, in its pricing or its claims conditions, and have you actually asked your insurer that question rather than assumed the answer?

2. If you hold certification, are you using it actively in renewal negotiations, or letting it sit as a badge on a website while the insurer prices you as an unknown quantity?

3. If you do not hold it, what is the quantifiable cost of that gap, in premium, in cover you cannot access, and in the leverage you do not have at the point of a claim?

None of these are IT questions. They are financial governance questions with a technical control standard sitting underneath them. Answering them properly requires the same kind of scrutiny a board would apply to any other instrument that affects the cost and reliability of risk transfer. Cyber Essentials has become one of those instruments, whether or not it was designed to be.

It’s over a year since DORA’s application date, this article opens our DORA insight series. It sets out the five capabilities every financial services firm needs to demonstrate under DORA. Over the forthcoming weeks Cyberfort security and compliance experts will explore each pillar in depth giving their insights, thoughts and recommendations for security professionals who are responsible for implementing and managing this regulatory standard in their organisation.

Most financial services firms are not starting their DORA journey from a position of weakness. They already have security teams, incident response processes, supplier oversight, testing programmes and governance forums. What DORA has done is expose the gap between having these capabilities and being able to demonstrate that they work consistently, under pressure, and with board-level accountability.

That distinction matters because DORA is not a technology regulation. It is an operational resilience regulation.

Regulators are not asking whether an organisation owns the right tools. They are asking whether it can prove it understands its ICT risks, responds effectively to disruption, manages third-party dependencies, tests resilience in a meaningful way, and contributes to the wider resilience of the financial services ecosystem.

Organisations that approach DORA as a compliance exercise will almost certainly produce an
unnecessary large quantity of documentation. Organisations that get the greatest value from it will use it as an opportunity to build lasting operational resilience capabilities.

Across all the conversations with financial services firms at Cyberfort over the past year, one consistent theme emerges. Success under DORA is not determined by individual controls or isolated projects. It is determined by five interconnected organisational capabilities.

Capability 1: ICT Risk Management

Everything starts with governance. Most firms can demonstrate strong operational security controls; vulnerability management, monitoring, asset inventories, incident response plans. What is often harder to demonstrate is how ICT risk is effectively governed, owned and managed at board level.

DORA places direct responsibility on senior leadership for the management of ICT risk. That means organisations need more than technical capability. They need a documented framework that explains:

  • How ICT risks are identified and assessed
  • How risk appetite is defined and approved
  • Who owns material risks
  • How mitigation activities are tracked
  • How the board receives and acts upon risk information

The key question is not “do we manage ICT risks?” It is “can we demonstrate how the organisation makes risk decisions, and prove those decisions align with documented and accepted business risk tolerances?” Without that foundation, every other DORA capability becomes significantly harder to sustain.

Capability 2: Incident Detection, Classification and Reporting

Most firms are relatively good at detecting incidents. The challenge is what happens next.

DORA’s requirements go beyond identifying suspicious activity or responding to technical events. Organisations must be able to classify incidents consistently, assess their severity accurately, determine cross-border and regulatory significance, and report major incidents against a genuinely tight clock – an initial notification within hours of classification, followed by further reports within days and weeks.

This is where many organisations discover that their existing incident processes were designed to support operational response rather than regulatory decision-making. An incident bridge call might successfully coordinate technical remediation, but can it determine severity using documented criteria, assess cross-border relevance, demonstrate why a classification decision was made, and produce an auditable record of root cause and remediation?

The difference between detection and classification is often where the greatest DORA related gap exists. Building a repeatable and defensible incident classification process is one of the most valuable investments financial services firms can make.

Capability 3: Operational Resilience Testing

Testing is not new. What DORA changes is the purpose of testing.

Traditional security testing often focuses on systems, applications or infrastructure. DORA shifts attention towards the resilience of critical and important business services. The key question becomes – can this service continue to operate during a realistic disruptive event?

Answering that requires more than vulnerability scans and penetration tests. Organisations must understand which systems support critical functions, which third parties those functions depend upon, how failures could propagate across services, and whether resilience assumptions have actually been validated under realistic scenarios.

For a sub-set of larger, designated organisations, this also means Threat-Led Penetration Testing. For every organisation in scope of DORA, it means moving beyond testing technology in isolation and towards testing business resilience as a whole. In many ways, testing is where assumptions become evidence.

Capability 4: Third-Party Risk Management

Few financial services organisations operate independently. Critical functions increasingly rely on cloud providers, managed service providers, software vendors and complex supply chains, and DORA recognises that operational resilience cannot exist if third-party dependencies remain poorly understood.

Most firms already have supplier management processes. The challenge is gaining visibility into critical supplier dependencies, concentration risk, fourth-party exposure, contractual obligations and exit readiness.

A supplier register can tell you who your providers are. A resilience-focused third-party risk programme tells you what happens if one of them fails. That distinction is becoming increasingly important as regulators place greater emphasis on systemic risk and concentration within the financial services technology ecosystem.

Capability 5: Information and Intelligence Sharing

The final capability is often the most misunderstood. Many organisations view threat intelligence as something they consume. DORA encourages organisations to view intelligence sharing as something they actively participate in – contributing to, and benefiting from, sector-wide resilience initiatives.

The rationale is straightforward. No individual financial services firm has complete visibility of the threat landscape. Attackers routinely target multiple organisations using similar techniques, dependencies and infrastructure. Sharing intelligence helps firms identify threats faster, improve detection capabilities and strengthen resilience across the sector.

The most mature organisations establish formal processes for consuming threat intelligence, feeding it into detection and testing activities, sharing appropriate indicators and insights, and maintaining audit trails of participation. The result is not simply compliance. It is a stronger collective defence capability.

Why these capabilities matter together

It is tempting to treat DORA’s pillars as separate workstreams. In reality, they are closely connected. A risk management framework informs incident classification. Incident data helps shape resilience testing. Testing identifies third-party dependencies. Third-party risks influence governance decisions. Threat intelligence improves every stage of the process.

The organisations making the greatest progress are not building five separate programmes. They are building one operational resilience capability that integrates and embeds governance, response, testing, supplier oversight and intelligence sharing into a single operating model.

By Dan Wood, Group CISO Cyberfort

As cyberthreats, regulatory requirements and third-party risks continue to evolve, organisations need a more continuous and connected approach to managing risk. Dan Wood, Group CISO at Cyberfort, explains why traditional risk management practices are no longer enough and how modern platforms can help security teams stay ahead.

Ask most CISOs how they manage risk day to day and the answer you will usually receive is ‘mostly on spreadsheets, bolted onto whatever GRC tool procurement or my predecessor has signed off on, we usually only use the tool once a year when the auditors arrive’. I say that without judgement, I’ve run programmes exactly like this as well. But I no longer think it’s defensible and I suspect most of us already know that is true.

Why traditional risk management doesn’t cut it anymore

The issue isn’t that risk teams don’t care. It’s that risk moves faster than the review cycle built to catch it. A vendor gets breached, a regulation shifts, a new system goes live and none of it waits politely for the next scheduled audit. By the time an exposure surfaces in a quarterly report, it has usually existed for months. Regulators such as the ICO and the FCA aren’t slowing down either and being caught relying on last quarter’s picture of risk is not a comfortable place for any CISO to stand.

Then there’s the sprawl. Most security and risk teams I speak to are juggling some mix of spreadsheets, a legacy GRC platform and manual reporting someone built to plug the gaps between them. Every extra tool adds another version of the truth and every version adds room for error.

Vendor risk is where this shows up hardest. An annual questionnaire tells you what a supplier’s posture looked like on the day they filled it in, not what it looks like now. A vendor can pass a review in January and quietly change its sub-processors, its access controls, or its own security posture by June and nobody finds out until it’s the vendor’s breach notification landing in your inbox. Given how many recent high-profile breaches have started with a third party in the last 12 months, treating vendor oversight as a once-a-year tick-box exercise feels closer to negligence than due diligence.

Data privacy adds another layer that’s easy to underestimate. Between UK GDPR obligations, DPIAs and the practical reality of tracking where personal data actually lives across an increasingly sprawling estate, privacy risk rarely gets the continuous attention it needs. It tends to live in a different spreadsheet, owned by a different team, reviewed on a different schedule, which means it’s often the last thing anyone notices has drifted out of control.

Then there’s the board. Cyber-risk is now a standing agenda item, which is progress, but it means CISOs are expected to translate technical and/or regulatory exposure into something a non-technical director can act on, on a schedule that leaves no room for a week of manual data-wrangling before every meeting. I’d rather spend that time on the risk itself than on the slide deck.

What good risk management software does

This is where the right risk management software earns its place. Not as another dashboard to check, but as the connective tissue between what’s happening across the estate and what gets reported upward. Done well, it should give continuous, real-time visibility rather than a point-in-time snapshot; it should replace static vendor questionnaires with ongoing monitoring that flags changes as they happen; it should hold risk data in one place rather than scattered across systems, so reporting to the board becomes an export rather than a project; and it should make the link between what you’re spending and what risk you’re removing, in language a CFO will accept.

Choosing the right platform

Choosing the right platform is less about the longest feature list and more about fit. I’d start by being honest about which categories of risk keep you up at night  – operational, regulatory or vendor –  because that should shape what you prioritise, rather than working backwards from a demo.

I’d then test how much of the workflow is genuinely automated versus how much is automation in name only, because plenty of tools promise intelligence and deliver another queue to manage. I’d look hard at integration: a platform that can’t pull from your identity provider, your cloud environment and your HR system will always be working from an incomplete picture, however polished its dashboard looks.

If you operate internationally, stress-test how it copes with multiple regulatory regimes at once – that’s usually where the cracks show first.

Cost matters too, but not in isolation. The sticker price rarely reflects the true cost of ownership once you’ve added training, setup and the internal resource needed to keep it configured properly. I’d rather pay more for a platform with strong support during adoption than save money upfront and spend the next year fighting the implementation. Ask what happens six months in, once the initial enthusiasm has worn off and the platform needs to run itself – that’s the question vendors are least keen to answer in a sales pitch.

Getting implementation right

Implementation is where good intentions often stall. The organisations that get the most from this software tend to do a few things consistently: they map their existing processes and access rights before switching anything on, rather than discovering the gaps live; they train people properly rather than assuming a new interface is self-explanatory; and they track outcomes deliberately, so there’s real evidence to show leadership rather than a vague sense that things feel better.

None of that is glamorous, but it’s the difference between a platform that gets used and one that quietly becomes shelfware within a year.

None of this replaces judgement. Software won’t decide your risk appetite for you, and it won’t have the difficult conversation with a business unit that’s ignoring a control gap. What it does is remove the excuse of not knowing – and in a landscape where regulators, boards and attackers are all moving faster than the traditional audit cycle, not knowing is no longer an option any of us can afford.

Read the article in Intelligent CISO here https://www.intelligentciso.com/2026/07/30/using-the-right-risk-management-software-to-build-resilience/

By Dan Wood, Group CISO Cyberfort

Dan Wood, Group CISO at Cyberfort, argues that resilience depends as much on people, governance, and live supply chain visibility as on security tooling.

Walk into any security conference this year and the conversation sounds the same wherever you stand. AI. Automation. Next-generation tooling. Every vendor stand promises the platform that will finally get you ahead of the threat. And I understand the appeal, I sit on the buying side of that conversation too, and these tools genuinely have value.

But I’ve sat in enough incident rooms at 2am to know that the breaches which do the most damage are rarely the ones a better tool would have stopped. They’re the ones where somebody clicked, somebody trusted, or somebody assumed a partner had it covered.

The next generation of cyber resilience won’t be defined by who has the shiniest stack. It will be defined by who takes people, governance and culture as seriously as they take technology.

The human element hasn’t gone away, it’s evolved

The Verizon 2026 Data Breach Investigations Report puts the human element in 62% of confirmed breaches. I’m not surprised by that number, and I don’t think anyone still working the floor of a SOC would be either.

What I do think is wrong is how the industry still talks about it. “Humans are the weakest link” needs to be retired for good. In my experience, the organisations that get breached hardest aren’t the ones with careless staff, they’re the ones where nobody made it easy, safe or rewarding for a person to say “something feels off about this.”

People are not a vulnerability to be fixed. They are the first line of defence, and often the only barrier a determined attacker needs to overcome. When organisations recognise people as a critical security control and invest in them with the same priority as any technical control, the effectiveness and resilience of the entire security programme changes dramatically.

Your supply chain is now your attack surface

Ernst & Young’s disclosure this year where an unauthorised party got in through a third-party IT support platform and walked out with client tax and investment documents, is the story I keep coming back to. Not because it’s unusual, but because it’s exactly the kind of access nobody puts on the risk register. Nobody runs a tabletop exercise on the support desk.

That’s the pattern I see again and again advising boards: enormous energy poured into hardening the front door, and a fire escape round the back that hasn’t been checked in two years because it belongs to somebody else’s IT estate, not yours.

Verizon’s data shows third-party involvement in breaches has roughly doubled in a single year, and honestly, having watched procurement and security teams operate in silo rather than together for most of my career, I’m more surprised it isn’t higher. A vendor risk register that gets updated once a year at renewal isn’t governance. It’s checkbox paperwork.

Point-in-time assurance is not resilience

This is where I think most organisations are still getting it wrong, and it’s the argument I find myself making most often in the boardroom. A clean audit report or a passed penetration test gives you a snapshot in time, not a state of ongoing health. Risk, control effectiveness and vendor exposure all shift week to week, sometimes day to day.

I’d rather have honest, continuous visibility of where I’m exposed right now than a polished report telling me I was fine three months ago. Resilience is a live picture, not a certificate on the wall.

Where I’d spend the next pound

If you’re a CISO staring at next year’s budget, here’s where I’d start, in order, and it’s a deliberately practical, pragmatic order.

First, continuous risk visibility. Build the capability to see control effectiveness and emerging exposure in near real time, not just at renewal or audit season.

Second, supply chain resilience. Continuous monitoring of third parties, cloud providers and technology partners needs its own budget line and its own named owner, not a clause in someone else’s contract review.

Third and this is the one I’d never cut, whatever the pressure on budget: your people. Security awareness has to graduate from an annual compliance module into a genuine culture, one where reporting a mistake is rewarded rather than punished, where security is everybody’s job, and where the board asks sharp questions instead of nodding along to a green dashboard.

Technology gives you capability. Governance gives you direction. But it’s people who create resilience. I’ve yet to see an organisation talk itself out of a breach with a tool it bought after the fact. I’ve seen plenty talk themselves out of one because someone on the front line trusted their instincts and picked up the phone.

Fund all three, in that order when budgets are tight, and you’ll be building resilience rather than shopping for it.

Read the article in Cyber Insider here https://cyberinsider.co.uk/stop-buying-resilience-start-building-it/

Cyber incidents often make headlines because of the disruption they cause, but they also reveal how organisations operate behind the scenes. The 2025 incident at Jaguar Land Rover (JLR) did exactly that, bringing into focus how closely its operations are connected to suppliers, shared systems and the wider manufacturing ecosystem.

What stood out wasn’t just the interruption itself, but the way it exposed the dependencies that keep a modern automotive operation moving. Supply chains in this sector are highly interconnected, and even a brief pause can surface links that usually sit quietly in the background. The JLR outage made some of those connections more visible and offered a practical reminder of how quickly operational pressures can ripple outward.

Seen through that lens, the incident becomes less about the disruption and more about what it revealed. It highlighted the level of interdependence built into today’s manufacturing environments and pointed to clear opportunities for organisations to strengthen their resilience. The lessons are practical, achievable and relevant far beyond the automotive sector.

A Quick Look at What Happened

When the cyber‑attack occurred, JLR paused parts of its UK production to contain the issue, restore affected systems and verify that operations could resume safely. What initially appeared to be a short interruption extended as teams completed recovery work and confirmed that core processes were stable.

The disruption affected several areas:

  • Manufacturing: some production lines paused and schedules were adjusted.
  • Supply chain: suppliers of all sizes experienced delays as orders and timings shifted.
  • Logistics: movements of parts and finished vehicles were rescheduled, creating knock‑on effects across transport networks.
  • Retail operations: downstream activity changed as production timelines moved.

Throughout the incident, JLR prioritised system stability and close coordination with partners. Production returned gradually, with a focus on safety and continuity across the manufacturing network.

The pause also offered a clearer view of how operational dependencies surface during unexpected events. It showed:

  • how quickly changes in one area can influence others
  • how reliant modern manufacturing is on shared digital processes
  • how important coordinated communication becomes when operations need to adjust at pace

This helps explain why the incident resonated beyond JLR itself. The effects were felt across a broad ecosystem of businesses, reinforcing the importance of understanding supply‑chain dependencies before they are tested.

Why This Was Really a Supply Chain Story

While the incident was centred on JLR, the wider context sits within the structure of automotive manufacturing. The sector relies on a broad network of suppliers, shared digital platforms and coordinated logistics processes, and any disruption naturally draws attention to how these elements interact in practice.

A few operational realities were highlighted during the pause:

  • Digital systems support day-to-day operations. Modern manufacturing uses a range of digital tools for ordering, scheduling, supplier coordination and logistics. When these systems are unavailable or slowed, it can influence how physical operations run.
  • Production processes are tightly timed. Automotive manufacturing typically follows structured, time-sensitive workflows. Even small changes to those workflows can create adjustments elsewhere, simply because the system is designed to move at a steady pace.
  • Suppliers notice changes quickly. When production activity shifts, suppliers often feel the effects early. Larger suppliers may have more capacity to absorb changes, but smaller businesses can be more exposed to sudden fluctuations.

Taken together, the incident illustrated how interconnected the automotive sector is. When a major manufacturer experiences a disruption, the effects can be felt across organisations of varying sizes and roles. It also provided a clearer view of where resilience measures can make a meaningful difference.

What Organisations Can Learn and Apply Right Now

Incidents like this are disruptive, but they also shine a light on where organisations can improve. The lessons aren’t limited to automotive manufacturing they apply to any business that relies on suppliers, partners or digital systems.

Here are the key takeaways.

Map Your Supply Chain

Most organisations have a list of suppliers. Very few have a clear picture of:

  • which suppliers rely on which systems
  • how data flows between them
  • where the single points of failure are
  • which suppliers are genuinely critical

A clear supply-chain map doesn’t need to be complicated but it does need to be accurate. And it’s an effective way to spot risks before they become problems.

This is especially important for organisations with complex operations. Without a clear map, it’s almost impossible to understand how a disruption in one area might affect another. JLR’s experience showed how quickly a single incident can ripple across an entire ecosystem.

Set Clear Security Expectations for Suppliers

Security requirements shouldn’t be vague or buried in contracts. They should be:

  • specific
  • measurable
  • regularly reviewed
  • aligned with your own risk appetite

If suppliers are part of your attack surface, and they are, they need to be part of your security strategy.

This doesn’t mean expecting every supplier to meet the same standards as a global manufacturer. It means setting expectations that are proportionate, realistic and clearly communicated. When suppliers know what’s expected of them, they’re far more likely to meet those expectations.

Limit Supplier Access to What’s Necessary

A common weakness in supply-chain breaches is overprivileged access. Suppliers often have:

  • more access than they need
  • access for longer than necessary
  • access that isn’t monitored

Follow the principle of least privilege:

If someone doesn’t need access today, they shouldn’t have it today.

This isn’t about mistrust; it’s about reducing the number of doors an attacker could potentially walk through. Access should be granted sparingly, monitored closely and removed promptly when no longer needed.

Build Segmentation into Your Architecture

Segmentation is an effective way to contain cyber incidents. If one system goes down, it shouldn’t take everything with it. In JLR’s case, the attack affected production systems across multiple factories a sign that segmentation could have reduced the blast radius.

Segmentation doesn’t eliminate risk, but it buys time. And in a cyber incident, time is everything.

It also helps organisations recover more quickly. When systems are segmented, it’s easier to isolate the affected areas, restore unaffected systems and bring operations back online in stages.

Test Your Response with Supplier Focused Scenarios

Most incident response exercises focus on internal failures. But real-world incidents often start elsewhere.

Useful scenarios include:

  • a key supplier going offline
  • a shared platform being compromised
  • a supplier’s credentials being used maliciously

These exercises don’t just test your technical response, they test communication, decision-making and the ability to keep the business running under pressure. They also help identify gaps that might not be obvious during day-to-day operations.

Strengthen Communication Channels with Suppliers

During a crisis, silence creates confusion. Clear, pre-agreed communication paths help everyone respond faster and more effectively.

This includes:

  • knowing who to contact
  • knowing how to escalate
  • knowing what information to share
  • knowing how to coordinate recovery

Good communication doesn’t fix the problem, but it makes sure that the people who need to know, do know. It also helps maintain trust both internally and externally.

When suppliers know what’s happening, they can take action to protect their own systems and support your recovery efforts. When they’re left in the dark, they can’t.

Build Contingency Plans for Critical Suppliers

If a supplier goes down, what’s your plan B? Or C? Or D?

Even a basic fallback plan can keep operations moving while the primary supplier recovers. It doesn’t need to be perfect it just needs to exist.

Contingency planning isn’t about expecting the worst. It’s about being prepared for the unexpected. And as JLR’s experience showed, the unexpected can happen quickly.

Glen Williams, CEO of Cyberfort Group discusses why UK boards must lead with resilience, beyond compliance, to prevent costly breaches.


Infrastructure-level attacks

Despite growing investment in cybersecurity, many UK businesses remain critically exposed to infrastructure-level attacks.

They are under siege; from state actors, criminal groups and opportunistic attackers exploiting any weakness.

Too many are operating under a concerning illusion of safety, believing being compliant means being secure.

But compliance is not resilience and ticking regulatory boxes is no defence strategy.

The biggest vulnerability is not always a firewall or an unpatched system.

Increasingly, it lies at the top. This is the boardroom blind spot – a disconnect between the perceived and actual state of cybersecurity in UK organisations.

Many underestimate the scale, sophistication and speed of cyber-threats.

The result? A slow drift toward crisis – costing money, reputations, operations and in some cases, the very survival of the business.

Leaders must ask the hard questions: If we were breached tomorrow, could we still operate? How fast could we recover – and at what cost?

From airports to automakers: The threat is escalating

Recent attacks on Jaguar Land Rover, major UK airport ransomware incidents and other critical infrastructure show no sector is immune.

Attackers are more organised, more aggressive and increasingly focused on large-scale disruption.

These breaches often succeed not because defences are absent, but because they are insufficient.  

Many businesses still assume cybersecurity is ‘being handled’ by internal IT or third-party providers – often generalists, not specialists.

But when facing organised crime groups or state-sponsored actors, general IT skills fall short.

The analogy holds: No one would trust a nurse to perform brain surgery – so why expect an IT generalist to protect the core of a business against elite cyber-threats?

The numbers speak for themselves. Of the 2.7 million registered UK businesses, only around 51,000 meet Cyber Essentials standards.

So basic cyber-hygiene is still being overlooked. With critical infrastructure now a prime target, the stakes are rising fast. Cybersecurity must be led from the top, by boards.

Why compliance does not equal resilience

Regulatory compliance frameworks such as ISO 27001, GDPR, the upcoming UK Cyber Resilience Act and Cyber Essentials serve a valuable purpose.

They set minimum standards and enforce accountability, but structure alone is not protection.

Compliance does not mean a business can detect, respond to or recover from an attack.

In fact, many companies seriously breached in recent years were fully compliant – on paper – but not operationally ready.

It is entirely possible to pass an audit and still be breached the very next day.

Worse, compliance is often used as a proxy for resilience – but it is often a lagging indicator of risk.

True resilience means having expert-led, scenario-tested, continuously evaluated strategies that are regularly refined and adapted to new threats.

Anything less leaves businesses dangerously exposed.

What real cyber-resilience looks like

Cyber-resilience is not a product you buy nor a policy you publish.

It is the organisation’s ability to absorb shocks and continue operating with minimal disruption – even when under attack.

Resilience starts at the board-level. This includes recognising cybersecurity as a core business risk as well as bringing in trusted partners, such as NCSC-assured consultancies who can help prepare organisations before, during and after an attack.

Resilient businesses invest in more than software; they invest in strategy.

They rehearse their response so that when a breach inevitably happens, teams avoid losing time or capability. 

Access to experts like virtual Chief Information Security Officers (CISOs) or specialist placements support stronger governance.

Resilience also means going beyond annual assessments to include regular threat modelling, red teaming and incident response drills.

Preparedness must extend across the entire organisation: Leadership, technical teams and non-technical staff alike.

At Cyberfort, resilience is defined not by how quickly companies recover, but by how little it loses in the process – whether that is trust, uptime, data integrity, capital or brand reputation.

Accountability cannot be outsourced

Cyber-risk is business risk – it impacts revenue, reputation, regulatory standing and long-term viability.

Yet this reality is recurringly not landing where it needs to: In the boardroom.

Too often, cybersecurity is viewed as technical – something IT should manage.

This mindset leads to underinvestment, poor response protocols and strategic blind spots in decision-making when it matters most.

Boards are responsible for resilience. Delegating without oversight or mistaking compliance for readiness, is a dereliction of that duty.

Leaders must ask the right questions, challenge assumptions and ensure cybersecurity is embedded in strategic planning.

When cyber is ignored at the top, the entire organisation is left vulnerable.

To close the boardroom blind spot, leaders must first make cybersecurity a standing board agenda item – not as an operational update, but a strategic risk discussion and treated with the same urgency as financial performance or operational risks.

Cybersecurity breaches can impact the balance sheet just as swiftly and severely as a major market event.

Second, boards must invest in education for directors.

While directors do not need to be technical experts, they must understand the business implications associated with cyber-threats.

Finally, success metrics must shift. Instead of measuring success by the absence of incidents, organisations should focus on the speed and effectiveness of detection, containment and recovery efforts.

Don’t wait for the crisis

The time of treating cybersecurity as an IT issue has long passed.

Cyber-risk now permeates every strategic decision – from M&A to supply chains.

The price of inaction is not theoretical – it is real and growing – just ask the companies that did not survive.

The fallout of recent breaches includes broken shareholder value, customer trust and long-term reputational damage that no insurance policy can undo.

Far too many businesses rely on generalist defences in a specialist threat environment.

Boards can no longer afford to sit on the side-lines.

Cybersecurity must be embedded into every strategic decision, not siloed as a compliance exercise.

The question is no longer if a breach will occur, but how well the organisation will be prepared to respond when it does.

Those who wait for the crisis to act will already be too late.

Nige Wilkinson – COO – Cyberfort


The introduction of the Cyber Resilience Bill marks a defining moment in the UK’s approach to digital security. For years, regulation has focused on the most visible parts of the critical national infrastructure, but the digital economy has become far more interconnected and far more dependent on the unseen operators that keep it running.

By widening the scope to include data centres, managed service providers and a new class of critical suppliers, the bill recognises that resilience is shaped not only by the organisations at the forefront of service delivery but also by those embedded deep within the national supply chain.

This shift is an important one. Data centres and managed service providers are now fundamental to how business is conducted. They host the information that fuels decision making, the platforms that support essential public services and the systems that underpin national productivity. Yet the bill’s current definition of a critical supplier remains broad and, at present, untested.

The absence of clear consultation with the industry on what constitutes criticality leaves room for uncertainty. A data centre hosting low risk workloads could be treated in the same way as one supporting essential public services. For operators and investors alike, such ambiguity could influence future development decisions and impose new requirements that are not aligned with the risk profile of their services.

While the details of classification require further refinement, the intention behind the legislation is sound. Cyber threats increasingly exploit the gaps that exist between interconnected partners rather than focusing solely on direct targets. As organisations have matured their own defences, attackers have looked outward to the suppliers and service providers that form the operational backbone of modern businesses. 

The bill acknowledges this reality. It places supply chain resilience at the forefront of regulatory attention and emphasises that security must be consistent from end to end if it is to be effective.

Training people is easy. Securing partners is harder

Employees are often highlighted as the main vulnerability within organisations, yet they are also the most addressable. People can be trained, educated and equipped to understand the nature of evolving threats. Supply chains, by contrast, are more complex. 

They are formed of partners who do not always adhere to the same standards and who may have very different levels of maturity in their own security practices. Without shared expectations and a unified framework, individual resilience will never translate into ecosystem resilience. The new provisions for faster incident reporting and enhanced enforcement powers are therefore meaningful steps towards creating a more transparent and accountable operating environment. They encourage collaboration, raise the collective bar and help ensure that weaknesses cannot be hidden within the less visible layers of the digital infrastructure.

Resilience requires more than regulation

However, true cyber resilience cannot be guaranteed by regulation alone. It must become embedded within organisational culture. Some businesses are still not fully compliant with GDPR despite its introduction seven years ago. Compliance, by itself, does not create resilience. 

It is the minimum threshold, not the desired state. The new bill risks becoming another set of obligations that organisations react to rather than a catalyst for genuine transformation. The success of the legislation will depend on whether businesses choose to act now to strengthen their security posture or wait until the obligation becomes unavoidable.

Cyber resilience is ultimately about safeguarding the data, systems, people and partnerships that underpin both economic stability and public trust. The bill sends a clear message that resilience is no longer a matter of choice but a shared responsibility. Those who begin preparing today will be best placed to thrive in a future where cybersecurity is not an operational consideration but a fundamental requirement for sustainable growth.

Automate compliance. Simplify security. Demonstrate trust. Vanta is the industry’s first Trust Management Platform. We automate GRC workflows and centralise security program management to give growing companies a fast, frictionless way to get compliant, stay secure, and earn and maintain the trust of vendors and customers alike.

Cyberfort
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.