August 2026 - Page 22 of 44

cyber due diligence mergers acquisitions a magnifying glass on plinth

Cyber Due Diligence in M&A: Essential Guide to Avoid Risk

Financial diligence values the earnings and legal diligence values the contracts, but neither tells a buyer whether the target has been quietly compromised for eight months. This guide sets out proportionate cyber due diligence on a real transaction: what the exercise actually covers, the four ways weak review destroys deal value, the five phases from scoping to costed reporting, the data room evidence list and what its absence proves, the red flags that justify repricing, how deal size and sector change the scope, the mapping from findings to price adjustments, warranties, indemnities and conditions, the first hundred days after completion, who should run the exercise and what it costs, and the mistakes that keep repeating.

Read more
passkeys vs mfa replace business passwords a hexagonal shield fingerprint

Passkeys vs MFA: Proven Guide to Stop Password Risk

Adversary-in-the-middle phishing kits now defeat one-time codes and push approvals routinely, which is why the multi-factor authentication you deployed in 2020 is no longer doing the job you think it is. This guide compares passkeys and traditional MFA by the attacks each one actually stops, explains how origin binding makes a passkey unphishable, sets out the parts of a typical application estate that cannot accept a passkey yet, costs the migration in service desk time and hardware, and gives a staged rollout plan that ends with weak factors switched off rather than left as a fallback.

Read more
immutable backup 3 2 1 1 0 strategy a sealed vault cube plinth

Immutable Backup: Essential 3-2-1-1-0 Strategy to Cut Risk

Ransomware crews delete the backups before they encrypt anything, which is why the old 3-2-1 rule quietly stopped being enough. This guide explains what an immutable backup genuinely is at the storage layer, how each digit of the 3-2-1-1-0 backup strategy is proved rather than claimed, the difference between governance and compliance mode, how long the lock window needs to be against realistic dwell time, what the storage overhead actually costs, the restore verification that the final zero demands, and a 90-day plan to get there.

Read more
business email compromise playbook a branching decision tree monument

Business Email Compromise Playbook: Essential Risk Guide

The document itself, not the product underneath it — how to write a business email compromise playbook that removes decisions from the moment of the incident: the five roles to name in advance, three severity tiers that stop every alert becoming a crisis, the first-hour containment order that preserves evidence before it destroys it, the bank recall clock, pre-written message templates for staff, customers and the bank, the 72-hour regulatory and insurance obligations, and the rehearsal that turns a file into a reflex.

Read more
managed detection and response vs edr antivirus soc a shield orbited by hex nodes

Managed Detection and Response vs EDR: Smart Proven Guide

Antivirus, EDR, MDR and a SOC are sold as competing purchases when three of them are tools and one of them is people. This guide separates the four properly: what managed detection and response actually includes beyond the licence, what antivirus still stops and where it goes blind, why unmonitored EDR is an expensive flight recorder, what a 24/7 in-house SOC really costs to staff, a side-by-side comparison of coverage, cost, response authority and out-of-hours cover, the detection-speed gap that decides most incidents, how to choose by company size and sector, the questions to ask a provider before signing, and the mistakes that waste the budget.

Read more
supplier cyber-risk assessment - supplier cyber risk assessment checklist a concentric cube rings plinth

Supplier Cyber-Risk Assessment: Essential Safe Checklist

Most supplier assurance programmes send a spreadsheet, receive a spreadsheet and file it — producing documentation rather than assessment. This guide sets out a working supplier cyber-risk assessment checklist as a seven-step programme: building an honest supplier inventory from four independent sources, scoring inherent risk before you contact anyone, tiering the base so effort follows exposure, the ten control domains the checklist must cover, choosing an assessment method that matches the tier, demanding the evidence artefact behind every claim, converting answers into residual risk and a dated decision, handling concentration and fourth-party risk, turning findings into remediation with deadlines and consequences, monitoring continuously between reviews, and closing the loop properly at offboarding.

Read more
third-party cybersecurity questionnaire - third party cybersecurity questionnaire template a central hub six satellite nodes plinth

Third-Party Cybersecurity Questionnaire: Proven Risk Guide

Most supplier security questionnaires are inherited spreadsheets that produce documented false assurance rather than real risk reduction. This guide provides a working third-party cybersecurity questionnaire template: the eight domains it must cover, the full 47-question Tier 1 set written as closed questions, a three-tier model so you stop sending 180 rows to low-risk suppliers, a four-outcome scoring rubric that produces decisions instead of percentages, the evidence artefact to demand behind every claim, the red flags that separate a filed document from a real finding, a mapping to Cyber Essentials, ISO 27001 and NIS2 Article 21, and the contract clauses that turn questionnaire answers into enforceable obligations.

Read more
nis2 compliance uk businesses eu customers a shield padlock hexring plinth

NIS2 Compliance for UK Suppliers: Essential Risk Guide

NIS2 compliance reaches UK businesses along two routes, and the second catches far more of them than the first. This guide explains which UK companies fall directly under Directive (EU) 2022/2555 and must appoint an EU representative, how the Article 21 supply chain clause pulls every other UK supplier in through customer contracts, what the ten security measures actually require, how the 24-hour, 72-hour and one-month reporting clocks work when you are the supplier rather than the reporting entity, how the regime compares with the UK NIS Regulations 2018 and the Cyber Security and Resilience Bill, what fines and management liability look like, and a 90-day programme that gets a UK supplier to a defensible position.

Read more
iso 27001 readiness assessment checklist a shield tick hexagonal plinth

ISO 27001 Readiness Assessment: Essential Risk Checklist

An ISO 27001 readiness assessment is the honest audit you run on yourself before a certification body runs one on you. This checklist walks through the mandatory requirements of Clauses 4 to 10, scores the 93 Annex A controls across the four 2022 themes, sets out the documented information an auditor asks for by name, and names the seven gaps that turn up in almost every first assessment. It covers a maturity scoring method that produces a remediation plan rather than a dashboard, realistic remediation timescales per gap type, the difference between doing the assessment in-house, consultant-led or platform-led, and the single biggest predictor of failing Stage 2.

Read more
cyber essentials plus vs iso 27001 comparison a three shields stepped plinth

Cyber Essentials Plus vs ISO 27001: Smart, Proven Choice

Cyber Essentials, Cyber Essentials Plus and ISO 27001 are treated as three rungs on one ladder, and that is the first mistake. Two of them certify a fixed set of five technical controls; the third certifies the management system that decides which controls you need at all. This guide sets the three side by side on assessment method, cost, elapsed time, scope, renewal and buyer recognition. It walks through the five Cyber Essentials controls under version 3.3 of the Requirements for IT Infrastructure, the five test cases behind a Cyber Essentials Plus audit, and the mandatory clauses and 93 Annex A controls that ISO 27001 adds on top. It closes with a decision path based on who is actually asking, the evidence overlap if you end up holding both, and the sequencing that keeps the combined bill down.

Read more
CHAT