risk management

cyber due diligence mergers acquisitions a magnifying glass on plinth

Cyber Due Diligence in M&A: Essential Guide to Avoid Risk

Financial diligence values the earnings and legal diligence values the contracts, but neither tells a buyer whether the target has been quietly compromised for eight months. This guide sets out proportionate cyber due diligence on a real transaction: what the exercise actually covers, the four ways weak review destroys deal value, the five phases from scoping to costed reporting, the data room evidence list and what its absence proves, the red flags that justify repricing, how deal size and sector change the scope, the mapping from findings to price adjustments, warranties, indemnities and conditions, the first hundred days after completion, who should run the exercise and what it costs, and the mistakes that keep repeating.

Read more
iso 27001 readiness assessment checklist a shield tick hexagonal plinth

ISO 27001 Readiness Assessment: Essential Risk Checklist

An ISO 27001 readiness assessment is the honest audit you run on yourself before a certification body runs one on you. This checklist walks through the mandatory requirements of Clauses 4 to 10, scores the 93 Annex A controls across the four 2022 themes, sets out the documented information an auditor asks for by name, and names the seven gaps that turn up in almost every first assessment. It covers a maturity scoring method that produces a remediation plan rather than a dashboard, realistic remediation timescales per gap type, the difference between doing the assessment in-house, consultant-led or platform-led, and the single biggest predictor of failing Stage 2.

Read more
cyber essentials plus vs iso 27001 comparison a three shields stepped plinth

Cyber Essentials Plus vs ISO 27001: Smart, Proven Choice

Cyber Essentials, Cyber Essentials Plus and ISO 27001 are treated as three rungs on one ladder, and that is the first mistake. Two of them certify a fixed set of five technical controls; the third certifies the management system that decides which controls you need at all. This guide sets the three side by side on assessment method, cost, elapsed time, scope, renewal and buyer recognition. It walks through the five Cyber Essentials controls under version 3.3 of the Requirements for IT Infrastructure, the five test cases behind a Cyber Essentials Plus audit, and the mandatory clauses and 93 Annex A controls that ISO 27001 adds on top. It closes with a decision path based on who is actually asking, the evidence overlap if you end up holding both, and the sequencing that keeps the combined bill down.

Read more
cyber essentials failure reasons how to avoid a shield five panels plinth

Cyber Essentials Failure Reasons: Proven Fixes to Avoid

Cyber Essentials failure is rarely caused by a sophisticated security gap. It is caused by an end-of-life laptop nobody logged, a cloud service quietly left outside the scope statement, or a director who has been reading email from an administrator account for four years. This guide works through the reasons organisations actually fail against version 3.3 of the Requirements for IT Infrastructure: scope boundaries that exclude what they cannot, unsupported software as an automatic fail, the 14-day patching deadline and its CVSS trigger, administrator account separation, mandatory MFA on cloud services, home working and BYOD traps, undocumented firewall rules, and the five Cyber Essentials Plus test cases where paper answers meet a live scan. It closes with a 60-day readiness plan and what to do inside the two-working-day correction window if a result has already come back non-compliant.

Read more
iso 42001 implementation cost controls certification a glowing seal above layered cube core

ISO 42001 Implementation: Essential Cost and Risk Guide

A realistic ISO 42001 implementation lands between roughly £15,000 and £90,000 in the first year, and almost none of that sits on a single invoice. This guide splits the number into certification body audit fees, external support, tooling and internal staff time, maps all 38 Annex A controls you will have to evidence, explains how the AI impact assessment differs from a risk assessment, sets out a realistic six to fifteen month timeline from gap analysis to certificate, and lists nine levers that genuinely reduce spend without weakening the certificate.

Read more
iso 27001 certification cost uk smes a certificate seal on stacked coin discs

ISO 27001 Certification Cost: The Smart, Essential UK SME Guide

The realistic ISO 27001 certification cost for a UK SME lands between roughly £6,000 and £48,000 in the first year, and almost none of that sits on a single invoice. This guide splits the number into certification body audit fees, external support, tooling and internal staff time, benchmarks each by headcount, explains how audit days are calculated, sets out a realistic six to twelve month timeline from gap analysis to certificate, and lists nine levers that genuinely reduce spend without putting the audit outcome at risk.

Read more
cyber security and resilience bill a glossy shield ringed by network nodes

Cyber Security and Resilience Bill: Essential Risk Guide

The Cyber Security and Resilience Bill brings managed service providers, data centres and designated critical suppliers into cyber regulation for the first time. Even businesses that are never regulated directly will feel it, because their IT supplier acquires a regulator, a 24-hour incident reporting clock and turnover-based fines. This guide covers where the Bill has reached in Parliament, the four-part managed service provider test, the customer notification duty most buyers miss, the two penalty bands, and the five questions worth putting to your provider before your next renewal.

Read more
IT security compliance frameworks for small law firms shown with a key on a laptop for confidential client data protection

IT Security Compliance Frameworks: 7 Best Law Firm Picks

Small law firms handle confidential client files, payment records, litigation material, discovery data, tax information, contracts, and sensitive communications. These seven IT security compliance frameworks help firms build a practical security roadmap without copying an enterprise program that is too heavy to maintain.

Read more
CHAT