Many organisations invest heavily in cyber security controls. They deploy endpoint protection, vulnerability management tools, firewalls, security monitoring platforms and incident response capabilities designed to reduce cyber risk. However, there is a fundamental question that is often overlooked. How can an organisation protect assets it does not know exist? As technology environments become increasingly complex, […]
Excessive permissions: the cyber security risk hiding in plain sight
When organisations think about cyber security risks, they often focus on external threats. Ransomware, phishing attacks, malware and sophisticated cybercriminals frequently dominate security discussions. While these threats remain significant, one of the most common causes of security incidents is often hiding in plain sight. Excessive permissions. Across many organisations, users, service accounts and applications have […]
Why SaaS sprawl is creating hidden cyber security risks
Software as a Service has transformed how organisations operate. From customer relationship management platforms and project management systems to file sharing solutions and collaboration tools, SaaS applications have become essential to modern business operations. They enable flexibility, improve productivity and allow organisations to adopt new technologies quickly without significant infrastructure investment. However, the rapid growth […]
Why passkeys are replacing passwords and what businesses need to know
For decades, passwords have been the primary method of securing online accounts. From email and cloud applications to financial systems and business platforms, organisations have relied on passwords as the first line of defence against cyber threats. However, passwords have also become one of the weakest links in modern cyber security. Password reuse, weak passwords, […]
Your SaaS stack is an attack surface. Treat it like one
Most organisations no longer rely on a single network, office location, or handful of business applications. Today’s businesses operate across dozens, sometimes hundreds, of SaaS apps that support communication, collaboration, finance, HR, customer management, development, and countless other functions. While SaaS platforms have transformed productivity and flexibility, they have also created a rapidly expanding attack […]
Mid-year cyber security statistics 2026: What UK businesses need to know
As we reach the halfway point of 2026, the latest figures from the UK Government and the National Cyber Security Centre (NCSC) reveal a cyber threat landscape that continues to challenge UK organisations. From ransomware attacks and phishing attacks to supply chain attacks and data loss, the statistics show that cyber criminals remain highly active […]
Why patch management alone is no longer enough
For years, patch management has been one of the most important cyber security disciplines. Applying software updates, deploying critical patches and maintaining patch compliance remain essential steps in protecting IT systems from known vulnerabilities. However, the threat landscape has changed. Today, many organisations face a constant stream of new vulnerabilities, publicly disclosed exploits and increasingly […]
Why identity security is becoming the new cyber security perimeter
For years, organisations built their cyber security strategies around a traditional security perimeter. Firewalls, network boundaries and endpoint protection formed the first line of defence against external threats. That approach made sense when most users worked from corporate offices, applications ran on premises systems, and network traffic largely remained within defined environments. Today, that world […]
What is a business continuity plan?
On a Wednesday afternoon, a ransomware group encrypts a regional law firm’s file servers. By 3 pm, staff cannot open client documents. By 5 pm, the managing partner is fielding calls from clients asking why their matters are on hold. Without a business continuity strategy in place, the firm has no answer to the most […]
What is Digital Forensics?
When a cyberattack hits a business or an employee is suspected of stealing data, the immediate question is: what actually happened? Which systems were affected? What was taken? Who was responsible, and when did it start? Answering those questions accurately, and in a way that holds up legally, is what digital forensics does. If you […]











