incident response

hotel cyber security checklist 20 controls uk a door hanger round hole

Hotel Cyber Security Checklist: 20 Controls Every UK Hotel Needs

Hotel cyber security fails in the joins. Not usually inside the property management system, not inside the payment terminal, but in the gaps between the reservation platform, the door-lock encoder, the guest network and the agency staff member who started on Friday night. A hotel runs more third-party systems per employee than almost any other […]

Read more
captive portal attacks hotel wifi captivecrunch a wireless gateway box two antenna rods

Hotel WiFi Cyber Attacks: What UK Hotels Can Learn From CaptiveCrunch

Captive portal pages are the most-clicked screens in British hospitality and the least-owned systems in the building. Every guest who joins the wireless network meets one, accepts whatever it says, and moves on. In 2026 a Russian state-linked operation turned that habit into a global intrusion campaign, and the lesson for UK hotels is uncomfortable: […]

Read more
incident response retainer cost and inclusions a shield lightning bolt plinth

Incident Response Retainer: Essential Costs to Avoid Risk

An incident response retainer is a contract you buy before anything has happened, to guarantee access to specialists who are otherwise fully booked the moment a large ransomware event hits the market. The cheapest and most expensive quotes can describe genuinely different products, and on a procurement spreadsheet they look interchangeable. This guide covers what you are actually buying: the standard reactive and proactive inclusions, the exclusions that destroy budgets, the three pricing models in common use, realistic UK cost bands for 2026 by organisation size, what response-time service levels genuinely promise, how prepaid hours are consumed and lost, and a scorecard for comparing providers before you sign.

Read more
cyber tabletop exercise how to run a shield rehearsal hexagons

Cyber Tabletop Exercise: Proven Steps to Avoid Costly Risk

An incident response plan that has never been tested is a document, not a capability. A cyber tabletop exercise is the cheapest way to find out whether your organisation can actually respond — who holds shutdown authority, when the regulatory clock starts, and whether anyone has drafted a holding statement before they needed one. This guide covers the full cycle: setting objectives and scope, choosing a scenario grounded in your real risk register, deciding who belongs in the room, building the four-document exercise pack, a three-hour run sheet, the facilitation techniques that keep the discussion honest, and the after-action reporting that converts findings into tracked and closed actions.

Read more
business email compromise playbook a branching decision tree monument

Business Email Compromise Playbook: Essential Risk Guide

The document itself, not the product underneath it — how to write a business email compromise playbook that removes decisions from the moment of the incident: the five roles to name in advance, three severity tiers that stop every alert becoming a crisis, the first-hour containment order that preserves evidence before it destroys it, the bank recall clock, pre-written message templates for staff, customers and the bank, the 72-hour regulatory and insurance obligations, and the rehearsal that turns a file into a reflex.

Read more
managed detection and response vs edr antivirus soc a shield orbited by hex nodes

Managed Detection and Response vs EDR: Smart Proven Guide

Antivirus, EDR, MDR and a SOC are sold as competing purchases when three of them are tools and one of them is people. This guide separates the four properly: what managed detection and response actually includes beyond the licence, what antivirus still stops and where it goes blind, why unmonitored EDR is an expensive flight recorder, what a 24/7 in-house SOC really costs to staff, a side-by-side comparison of coverage, cost, response authority and out-of-hours cover, the detection-speed gap that decides most incidents, how to choose by company size and sector, the questions to ask a provider before signing, and the mistakes that waste the budget.

Read more
nis2 compliance uk businesses eu customers a shield padlock hexring plinth

NIS2 Compliance for UK Suppliers: Essential Risk Guide

NIS2 compliance reaches UK businesses along two routes, and the second catches far more of them than the first. This guide explains which UK companies fall directly under Directive (EU) 2022/2555 and must appoint an EU representative, how the Article 21 supply chain clause pulls every other UK supplier in through customer contracts, what the ten security measures actually require, how the 24-hour, 72-hour and one-month reporting clocks work when you are the supplier rather than the reporting entity, how the regime compares with the UK NIS Regulations 2018 and the Cyber Security and Resilience Bill, what fines and management liability look like, and a 90-day programme that gets a UK supplier to a defensible position.

Read more
microsoft 365 business email compromise response plan a hijacked mailbox shield

Microsoft 365 Business Email Compromise: Proven Risk Plan

A working response plan for UK businesses on Business Premium, E3 or E5 — what to do in the first sixty minutes, why revoking sessions matters more than resetting the password, the evidence to export before you clean anything, how to investigate inbox rules, forwarding and OAuth grants, the bank and Action Fraud clock, UK GDPR notification, full tenant recovery, and the Conditional Access and phishing-resistant MFA controls that stop it happening again.

Read more
CHAT