Don’t Expect Cybersecurity to Work in Firms Where Nothing Does

You cannot expect the CISO on their own, bottom-up, to reverse widespread business dynamics, where short-termism prevails everywhere across the business. I have written at length about the difficulties many large organizations encounter with cybersecurity, and their endemic execution problems when it comes to protecting themselves from cyber threats. While the diagnostic is relatively clear in my view, there […]
How Organisations Can Master Incident Reporting Obligations Under NIS2

The new NIS2 directive is designed to strengthen the cyber resilience of over 160,000 companies that operate in the EU – either directly or indirectly. Coming into force by 17th October, NIS2 regulations will outline how these essential entities can combat increasingly sophisticated and frequent cyber attacks. Notwithstanding delays in the implementation of local legislation, the […]
Is your business ready for the inevitable cyberattack?

Today, it’s not a matter of if your business will be hacked, but when. The 2024 UK Government Cybersecurity Breaches Survey revealed a startling statistic: 50% of UK businesses suffered a cyberattack or security breach in the previous 12 months, up from 39% in 2022. The average cost of a data breach in 2023 was $4.45 million. For […]
Framing the Role of the Board around Cybersecurity is No Longer about Risk

Business protection from cyber threats must be rooted in the reality of the world we live in The role of the Board with regards to cybersecurity is a topic that keeps coming back and is often addressed in simplistic terms in my view. I don’t think it makes sense to look for “one-size-fits-all” answers to […]
Tracing the destructive path of ransomware’s evolution

The year is 1989. “Rain Man” wins the Academy Award for Best Picture. Motorola releases the world’s smallest and lightest phone. The Berlin Wall falls. Taylor Swift was born. It also begins the dawn of a new era of cyber extortion. The AIDS Trojan arrived innocuously, distributed via floppy disk to public health professionals. But it harbored […]
Large Enterprises Can’t Cope With More Cybersecurity Tools

It should be central to the role of the CISO to build a vision and a product strategy, and drive the decluttering of cybersecurity landscapes Every year, as we approach conference season, I can’t help but being amazed by the monumental number of cybersecurity products, services and vendors. I have written at length about this […]
Legal consequences for victims of cyberattacks are piling up

Falling victim to a cyberattack is bad enough, but there’s a chance that it also leaves companies open to lawsuits should they be found to have failed to adequately protect private data or disrupted other businesses. Several pharmacy groups and healthcare providers in the USA have filed a class action lawsuit against the payments service […]
Putting individuals back in charge of their own identities

From letting hotels keep copies of our passports to handing over IDs for car hire or air travel, we seldom think twice about the implications of physically sharing our identity documents. By now, we’ve gotten accustomed to exchanging personal information in return for a product or service we value – but we need to be […]
Paris 2024 Could Set A New World Record, But Not By The Athletes

Paris 2024 expected to see “eight to ten times more” cyberattacks than Japan’s 450 million With Paris 2024 now finished, security teams were braced against the heightened threat of cyberattacks facing this year’s Games. Previous Games, and any large sporting event for that matter, have seen threat actors increase their activity looking to monetise their […]
Three ways firms can protect themselves from AI cybersecurity risks

Across the world, we are seeing a rise in the number of cyber-attacks, with research finding an 8% spike in global cyber-attacks in the second quarter of this year – the most significant increase in the last two years. Accelerated digitalisation across our professional and personal lives, increasingly sophisticated attack techniques used by cybercriminals as […]