Posts

Showing posts from March, 2026

What the UK Cyber Security & Resilience Bill Means for Security Practitioners

Image
The UK Cyber Security & Resilience Bill is progressing through Parliament Royal Assent expected later in 2026. The UK's Cyber Security and Resilience Bill is working its way through Parliament, and if you haven't started paying serious attention yet, now is the time. Introduced to the House of Commons in November 2025, the Bill represents the most significant overhaul of UK cyber regulation since the NIS Regulations in 2018, and its implications for security practitioners are immediate and practical. What's Actually Changing At its core, the Bill expands the existing Network and Information Systems regulatory framework. It brings more organisations into scope, imposes stricter incident notification requirements, and hands regulators substantially more enforcement power. Secondary legislation and statutory Codes of Practice will follow, but the primary architecture of what you'll be working within is already taking shape. One of the most significant shifts for prac...

The True Cost of Cyber Downtime: A UK Board-Level Briefing

Image
Written by Sean Tilley, Senior Sales Director EMEA at  11:11 Systems   Cyber downtime carries measurable financial consequences, and those consequences are becoming clearer with each major incident.  Research from 11:11 Systems  shows that 78% of European organisations report losses of up to $500,000 per hour following a cyber-related outage, while 6% face costs exceeding £1 million per hour. When recovery extends beyond containment, the disruption begins to register in revenue performance, contractual exposure, and customer stability rather than remaining confined to the technology function. For UK leadership teams, the issue centres on continuity of income, fulfilment of obligations, and the strength of customer relationships under strain.   Recovery delays compound risk Half of organisations surveyed require between one and two weeks to fully recover from a cyber incident. Over that period, cost exposure builds in ways that are rarely reflected in early estim...

When insider risk is a wellbeing issue, not just a disciplinary one

Image
Written by Katie Barnett, Director of Cyber Security at Toro Solutions Insider risk is still often framed around intent, with the focus placed on malicious employees, disgruntled contractors, or deliberate misuse of access for personal gain. Those cases exist and they matter, but they are rarely where risk first begins, and they do not reflect how most insider-related incidents actually develop. In reality, many cases take shape slowly and quietly. They are shaped by pressure, fatigue, disengagement, coercion, manipulation or personal strain rather than hostility. The behaviour that later causes harm is often preceded by long periods of stress, isolation, being influenced or unresolved workplace issues. By the time someone is formally labelled an insider threat,the opportunity for early, proportionate support has usually passed, and the organisation is left with far fewer options. This is why treating insider risk purely as a disciplinary or compliance issue consistently falls short. ...

Building Trust in AI SOC Analyst Solutions: A UK and EU CISO Perspective

Image
By Brett Candon, VP International at Dropzone AI Trust has always been critical in security operations, but in the UK and Europe it carries significant regulatory weight. GDPR, NIS2 and similar related data‑protection frameworks shape far more than legal risk, they directly influence architectural decisions, supplier selection, and how security data can be accessed, processed and reviewed. That becomes more pronounced as autonomous AI systems move from proof‑of‑concept to daily SOC tooling.  The appeal is undeniable. Faster investigations, more consistent outcomes, and the ability to scale Tier‑1 response are all compelling. However, without clear answers on data flows, access and accountability, AI introduces risk as easily as it removes it. And speed alone does not result in trust. Against this backdrop, AI‑native approaches to SOC operations are gaining traction, grounded in the idea that autonomy, transparency, and repeatability must be foundational design principles rather tha...

AI Is Moving Faster Than Security Controls

Image
AI is entering organisations faster than the security controls designed to govern it. Artificial intelligence is rapidly becoming embedded across organisations. AI assistants are now writing code, summarising documents, analysing data, and supporting operational decisions. What began as experimentation is quickly becoming operational dependency. For security teams, the challenge is not simply adopting AI. The real challenge is understanding how AI changes the way cybersecurity controls need to be validated. In many organisations, AI tools are already interacting with corporate data, internal systems, and operational workflows. Yet when security leaders ask a simple question “How do we know these AI systems are operating within our control boundaries?” …the answer is often less clear than expected. Why AI Security Controls Are Different Traditional software behaves in predictable ways. Security teams can audit ...

NCSC Warns UK Organisations to Prepare for Potential Iran-Linked Cyber Activity

Image
Geopolitical conflict rarely stays confined to physical battlefields. Increasingly, it spills into the digital domain. The latest escalation of tensions in the Middle East has prompted the UK’s National Cyber Security Centre (NCSC) to issue a warning to organisations  to review their cyber security posture and prepare for possible cyber activity linked to Iran. While the NCSC has stressed that there is currently no confirmed significant increase in direct cyber threats to the UK, it has warned that the situation is fast-moving and organisations should remain alert. Rising Tensions and Cyber Spillover The warning follows a sharp escalation in the regional conflict involving Iran, the United States and Israel. Military developments have been accompanied by cyber activity targeting digital infrastructure and online services in the region, highlighting how modern conflicts now run across both physical and digital fronts. In response, the NCSC has advised UK organisations to review the...