risk management

cloud security posture assessment checklist a upright shield on plinth

Cloud Security Posture: Essential Risk Assessment Checklist

Most cloud incidents do not start with a clever exploit. They start with a storage container someone made public for a demo, an access key committed to a repository years ago, or logging switched on in one region and never in the other three. A cloud security posture assessment is the structured way of finding all of that before somebody else does. This checklist walks the whole engagement in order: scoping and read-only access, the technical domains worth reviewing, how to score findings so the list is defensible, whether to use native tooling or a dedicated platform, and what the work realistically costs in money and elapsed time.

Read more
rto and rpo explained business calculator a single hourglass on plinth

RTO and RPO Explained: Simple Calculator to Avoid Risk

RTO and RPO are the two numbers that decide what a recovery plan is allowed to cost, and most organisations set them without ever pricing the alternatives. This guide explains what each number really measures, where the figures should come from, and then gives you a five-input business calculator that converts hourly downtime cost, hourly data loss cost and failure frequency into a total cost of risk for every recovery tier. It includes a blank worksheet, a fully worked example on a sixty-person firm, indicative UK costs for backup, pilot light, warm standby and active-active, and the testing discipline that turns a target into a fact.

Read more
AI vendor lock-in - ai vendor lock in exit strategy a featured upright key

AI Vendor Lock-In: Essential Exit Plan to Avoid Risk

AI vendor lock-in is the bill that arrives eighteen months after a successful pilot. This guide breaks dependency into five distinct types — model, data, workflow, integration and commercial — explains why AI switching costs behave differently from classic software migrations, sets out the contract clauses that cap your exposure at signature, covers the architecture decisions that keep switching cheap, and gives you a four-page exit plan you can write in a day and rehearse once a year.

Read more
ai acceptable use policy template employees a single blank paper sheet

AI Acceptable Use Policy: Essential Template to Avoid Risk

Your staff are already using AI at work; the only question is whether they are doing it inside rules you wrote. This guide gives you a complete AI acceptable use policy template for employees: the nine clauses that actually carry weight, model wording you can copy for scope, approved tools, data entry, human accountability, disclosure and breach handling, a three-tier approved and prohibited tool model, a data table showing what may never be pasted into a public chatbot, a rollout plan that gets the policy acknowledged, the mistakes that quietly kill enforcement, and the four numbers that tell you whether any of it is working.

Read more
iso 42001 certification cost timeline a blank octagonal seal disc

ISO 42001 Certification Cost and Timeline: Proven Smart Plan

ISO 42001 certification costs a UK organisation roughly £12,000 to £180,000 in year one and takes six to fifteen months, and neither range means anything until you know what moves it. This guide splits the cost into the four budgets hiding behind one number, shows how certification bodies calculate audit days under ISO/IEC 42006, sets out a month-by-month timeline from gap analysis to certificate decision, explains the five things that reliably push the date, models the three-year cost that matters more than year one, and lists six levers that cut spend and elapsed time without weakening the certificate.

Read more
penetration testing frequency a shield with magnifying glass

Penetration Testing Frequency: Proven Rules for Safer IT

Once a year is a floor, not a schedule. This guide sets out how often a business should conduct penetration testing and why the calendar date matters far less than what changed in the estate since the last report. It covers the twelve-month baseline and where it comes from, the seven change triggers that should force an unscheduled round, exactly what PCI DSS, ISO 27001, SOC 2, Cyber Essentials Plus and NIS2 actually require, where vulnerability scanning stops and human testing starts, indicative UK programme costs at every cadence, and how to build a calendar that survives a year of competing priorities.

Read more
cybersecurity risk register template smes a upright board of blank tiles

Cybersecurity Risk Register: Proven Template for Safe SMEs

Most cybersecurity risk register templates are built for banks and abandoned by small businesses within a fortnight. This guide strips the document back to the eleven fields that earn their place, gives likelihood and impact scales anchored to time and money rather than adjectives, and shows a worked register for a sixty-person firm with real rows, owners and treatment decisions. It also covers the four treatment options and how to use each one honestly, a two-afternoon build method, the review cadence and out-of-cycle triggers that stop the register rotting, and when a spreadsheet stops being enough.

Read more
incident response retainer cost and inclusions a shield lightning bolt plinth

Incident Response Retainer: Essential Costs to Avoid Risk

An incident response retainer is a contract you buy before anything has happened, to guarantee access to specialists who are otherwise fully booked the moment a large ransomware event hits the market. The cheapest and most expensive quotes can describe genuinely different products, and on a procurement spreadsheet they look interchangeable. This guide covers what you are actually buying: the standard reactive and proactive inclusions, the exclusions that destroy budgets, the three pricing models in common use, realistic UK cost bands for 2026 by organisation size, what response-time service levels genuinely promise, how prepaid hours are consumed and lost, and a scorecard for comparing providers before you sign.

Read more
cyber tabletop exercise how to run a shield rehearsal hexagons

Cyber Tabletop Exercise: Proven Steps to Avoid Costly Risk

An incident response plan that has never been tested is a document, not a capability. A cyber tabletop exercise is the cheapest way to find out whether your organisation can actually respond — who holds shutdown authority, when the regulatory clock starts, and whether anyone has drafted a holding statement before they needed one. This guide covers the full cycle: setting objectives and scope, choosing a scenario grounded in your real risk register, deciding who belongs in the room, building the four-document exercise pack, a three-hour run sheet, the facilitation techniques that keep the discussion honest, and the after-action reporting that converts findings into tracked and closed actions.

Read more
supplier contract security requirements a shield emblem on hexagonal plinth

Supplier Contract Security: Essential Clauses to Avoid Risk

Most contracts dispose of security in a single sentence promising “appropriate technical and organisational measures”, which gives you no notification deadline, no evidence rights and no route to terminate when the supplier is breached. This guide sets out the cybersecurity requirements worth writing into supplier agreements: the standards and certification scope to specify, the core control clauses, the UK GDPR processor terms that are statutory rather than optional, incident notification and cooperation, audit and evidence rights, subcontractor flow-down, exit and data return, liability and insurance, and the three-tier model that keeps the whole programme proportionate across a real supplier base.

Read more
CHAT