Business Leaders Cyber Briefing

Cool Waters Cyber

A short summary of the latest cyber security news and trends, from the perspective of business leaders and owners.  Hosts Trish and Tom provide plain English explanations along with practical advice to keep your business safe and secure from cyber crime and disruption. For cyber security help and advice, speak to Cool Waters Cyber: www.cool-waters.co.uk 

  1. OCT 21

    NCSC Annual Review 2025: Crisis in the Boardroom, AI driven threats and Supply Chain Resilience Roadmap

    Trish and Tom take a deep dive into the NCSC Annual Review for 2025 and unpack practical tips for business leaders. We're tearing open the most critical report of the year: the NCSC Annual Review 2025. The message from GCHQ is crystal clear: Cyber risk is no longer just an IT issue—it’s a boardroom priority. Forget those old assumptions—the threats are escalating at an alarming rate. Recent high-profile attacks on household names like M&S, Co-op, and JLR show that cyber incidents now cause operational standstills, affecting real lives and costing millions (like the £32.7 million loss following an attack on a pathology provider). We’re diving into why the NCSC CEO says the risk facing the nation is "widely underestimated", the dramatic 50% rise in highly significant incidents, and what leaders need to do now to embrace resilience.  We unpack the impact AI is having on cyber security and how the bad guys are using it to target UK organisations more effectively And we round off with a conversation about the radical shift in how organisations need to tackle cyber security in their supply chain - it's not all about data security anymore! Tune in—the window for preparation is narrowing ========== To learn more about the Cyber Swift platform mention in this podcast, sign up for the upcoming webinar on 28th October here: https://www.cool-waters.co.uk/events/how-to-build-a-cyber-secure-supply-chain-turning-awareness-into-action  Need help with Cyber Security? Speak to Cool Waters Cyber - NCSC assured Cyber Advisors and Cyber Essentials experts - www.cool-waters.co.uk

    33 min
  2. JUL 18

    Dramatic changes in UK Supply Chain Security

    This episode dives deep into UK Supply Chain Cyber Security, a critical and often overlooked area in today's digital world. So, what exactly is it? It's about securing the entire network of external partners, suppliers, and third-party services that your business relies on. Imagine your company as only as strong as its weakest link. In the UK, this is more urgent than ever: supply chain cyberattacks surged by a staggering 431% between 2021 and 2023. Despite this growing threat, shockingly few UK businesses formally review risks from their immediate suppliers (only 14%) or their wider supply chain (just 7%). The financial impact is immense, costing the UK economy an estimated £27 billion annually. Our understanding of supply chain cyber security has evolved significantly beyond mere data protection. While preventing data breaches remains vital, the new reality focuses on operational resilience. This means ensuring your suppliers remain functional and can continue delivering critical services, even if they suffer a cyberattack themselves. Recent high-profile incidents, like the 2024 Synnovis ransomware attack which disrupted NHS services, starkly illustrate how a supplier's compromise can halt critical operations, affecting everything from pension payments to patient care. The goal is no longer just to avoid losing data, but to guarantee your ability to operate smoothly. The easiest and most effective way for firms to manage this complex supply chain security is by asking for certifications from their suppliers. Cyber Essentials has emerged as the cornerstone of the UK's strategy, a government-backed scheme defining five fundamental technical controls that protect against the majority of common cyberattacks. It's not just a recommendation; it's rapidly becoming a critical business requirement, with major UK banks like Barclays and Lloyds Banking Group now expanding Cyber Essentials requirements across their supply chains. This streamlines due diligence, raises minimum standards across the economy, and has been proven to work: one firm, St. James's Place, saw an 80% reduction in cyber incidents after requiring 2,800 suppliers to achieve Cyber Essentials Plus. Need help with Cyber Security? Speak to Cool Waters Cyber - NCSC assured Cyber Advisors and Cyber Essentials experts - www.cool-waters.co.uk

    11 min
  3. JUN 3

    2025 UK Cyber Breaches Survey: What need to know - What you need to do

    Business Leaders Cyber Briefing - Episode 12: Key TakeawaysWhat You'll Learn from This Episode Trish and Tom from Cool Waters Cyber break down the 2025 Cyber Security Breaches Survey findings to help UK financial services leaders understand their current risk landscape and improve their cyber defenses. Critical Insights for Business Leaders Your Risk Profile is Higher Than You Think 74% of large businesses and 67% of medium businesses experienced cyber incidentsFinance and digitally intensive sectors face elevated risksRansomware attacks have doubled, now affecting 1% of all businesses (19,000 organizations)Phishing Remains Your Biggest Threat 85% of breached businesses were hit by phishing attacksEven failed attempts drain significant staff timeAI-enhanced scams are making phishing more sophisticated and harder to detectFinancial Impact Can Be Severe Average breach costs range from £1,600 to £8,260 depending on severityCyber-facilitated fraud averages £5,900 per incidentRepeat attacks are common—affected businesses face an average of 30 incidents annuallyKey Action Items Strengthen Board Accountability Only 27% of businesses have a board member explicitly responsible for cyber securityFinance sector performs better (57%) but still has room for improvementMake cyber security a standing board agenda itemImprove Incident Response Preparedness Just 23% of all businesses have formal incident response plansOnly 39% of affected businesses report incidents externallyDevelop and regularly test your incident response proceduresImplement Proven Frameworks Use the UK Cyber Governance Code of Practice's five principles as your foundationConsider IASME Cyber Assurance for comprehensive governance alignmentStart with Cyber Essentials for essential technical controlsBottom Line The episode demonstrates that while cyber threats are intensifying, businesses with structured governance and incident response capabilities are better positioned to minimize impact. The key is moving from reactive to proactive cyber security management through proven frameworks and clear board-level accountability. Next Steps: Assess your current cyber governance against the five principles, ensure you have formal incident response plans, and consider certification standards like Cyber Essentials or IASME Cyber Assurance to systematically strengthen your defences. Need help with Cyber Security? Speak to Cool Waters Cyber - NCSC assured Cyber Advisors and Cyber Essentials experts - www.cool-waters.co.uk

    20 min
  4. MAY 8

    How to fast-track the UK Cyber Governance Code of Practice using IASME Cyber Assurance

    Implementing the UK Cyber Governance Code of Practice with IASME Cyber Assurance In this episode, we discuss the crucial topic of cyber governance for business leaders. With 74% of large businesses and 70% of medium businesses in the UK experiencing a cyber breach in the past year, boards are now clearly expected to lead on cyber risk. In response, the UK government (via DSIT and NCSC) has introduced the voluntary Cyber Governance Code of Practice to guide boards and directors. The Code distils five key principles for effective cyber governance: Risk Management, Strategy, People, Incident Planning & Response, and Assurance & Oversight. However, implementing these practices can be a challenge. Our deep dive focuses on a pragmatic roadmap to implement the Code: the IASME Cyber Assurance standard. Formerly known as "IASME Governance", this government-backed standard is comprehensive yet accessible, developed with UK government support as an alternative to more complex standards like ISO/IEC 27001.  Using IASME Cyber Assurance to implement the Code offers several benefits: • Integrated Approach: It delivers both the Cyber Governance Code's requirements and the technical controls of Cyber Essentials in one unified effort, avoiding duplicate work. • Structured Guidance: IASME provides detailed guidance, templates, and a structured question set to lead you through implementing controls, so you don't have to "reinvent the wheel". • Comprehensive Coverage: The standard covers technical controls, risk management, data protection (like GDPR), and regulatory compliance. • External Assurance: It culminates in an independent certification, providing tangible proof to stakeholders that your cyber governance meets a national standard. Learn how following a structured roadmap using IASME can help organisations achieve significant cyber maturity relatively quickly, often within ~3–6 months to certification. Implementing these steps can be challenging, which is why partnering with an NCSC-accredited Cyber Advisor can be invaluable. Advisors, like our sponsor Cool Waters Cyber, provide expert gap analysis, hands-on remediation support, plain-English communication, project management, and certification liaison. They offer a clear, pragmatic roadmap and help streamline the process, ensuring you meet the standards effectively. Cool Waters Cyber offers a comprehensive service to help boards implement the Cyber Governance Code of Practice. They provide tailored support backed by real-world experience and plain-English advice. Ready to strengthen your cyber governance? Cool Waters Cyber can help your firm implement the new code. Need help with Cyber Security? Speak to Cool Waters Cyber - NCSC assured Cyber Advisors and Cyber Essentials experts - www.cool-waters.co.uk

    20 min
  5. APR 28

    Unpacking the UK Cyber Governance Code of Practice

    Tune into this episode for a deep dive into the UK government's Cyber Governance Code of Practice. This Code is a crucial resource designed specifically for boards and directors. Understanding it can significantly benefit your organisation. By listening, you will gain insights into: • Why cyber governance is essential for modern businesses and organisations. Digital technologies are deeply embedded in most businesses, and critical operations often rely on them. Cyber risk is a material risk for almost all organisations. • The critical role of boards and directors in managing digital risks and protecting their organisations from cyber attacks. Governing cyber risk requires strong engagement and action at a leadership level. • How the Code helps protect your organisation's financial viability. Effective management of cyber risks is crucial, and building cyber resilience is key to recovering from harm caused by cyber events. • What the Cyber Governance Code of Practice is and how it sets out the most critical governance actions that directors are responsible for. It shows how boards and directors can build resilience to a wide range of cyber risks. • Who should use the Code: It's tailor-made for boards and directors of both public-sector and private organisations, especially medium and large ones. While not specifically for small organisations, they play a critical role in UK economic resilience and should seek to implement the Code's principles. • How the Code helps manage cyber risks effectively and reduce the likelihood and impact of cyber attacks. Cyber incidents can lead to major impacts like loss of income, damage to customer trust, or costly remedial action. • How the Code fits into a wider government support package. It is underpinned by resources such as Cyber Governance Training and the Cyber Security Toolkit for Boards, which help strengthen understanding and support implementation. • The key areas covered by the Code, including Risk Management, Strategy, People, Incident Planning, Response and Recovery, and Assurance and Oversight, detailing specific actions for each area. • Understanding the minimum standards for managing cyber risk, especially when the Code is used alongside Cyber Essentials, a government-backed certification scheme. Understanding the principles and actions outlined in the Code of Practice is crucial for effective governance and protecting your organisation in today's digital landscape Need help with Cyber Security? Speak to Cool Waters Cyber - NCSC assured Cyber Advisors and Cyber Essentials experts - www.cool-waters.co.uk

    13 min
  6. MAR 19

    From Hard Hats to Firewalls: Why Cyber Safety is the Next Big Construction Risk

    🔹 Episode Overview: For decades, the construction industry has made physical safety a top priority. Over time, mental well-being has also been recognised as a critical part of workplace safety. But now, a new challenge is emerging—one that many construction businesses aren’t prepared for: Cyber Safety. In this episode, we discuss the findings of our latest white paper on the evolution of safety culture in construction, revealing how cyber risks are becoming just as important as traditional workplace hazards. We’ll unpack: ✅ How health and safety evolved from a compliance burden to a core business value. ✅ The growing link between mental well-being and job site safety—and how stress can increase the risk of accidents. ✅ Why cyber threats (like ransomware, phishing, and invoice fraud) are now a critical risk to construction firms. ✅ How construction companies can apply lessons from traditional safety culture to build a strong cyber safety mindset. We also introduce our 6-Point Cyber Safety Action Plan, a practical guide to help construction firms protect their people, projects, and profits from cyber threats. 🔹 Key Takeaways: ✔️ Cyber attacks are increasing in the construction industry, but most firms are unprepared. ✔️ Employees need to be trained to spot cyber threats just like they spot physical hazards. ✔️ Cyber safety should be integrated into daily briefings, safety reports, and leadership discussions. ✔️ The best way to avoid cyber attacks is to build a culture of cyber awareness. 🔹 Get the Full Report: Want the complete insights? Download the full white paper, which includes the 6-Point Cyber Safety Action Plan and real-world strategies for construction firms. 📥 [Download Your Copy Here] 🔹 Who Should Listen? 👷 Construction & engineering leaders 🛠️ Health & Safety professionals 💻 IT & Cybersecurity teams 🏗️ Contractors & site managers 📈 Business owners in the built environment 🚀 Tune in and learn how to future-proof your construction business with cyber safety! Need help with Cyber Security? Speak to Cool Waters Cyber - NCSC assured Cyber Advisors and Cyber Essentials experts - www.cool-waters.co.uk

    20 min

About

A short summary of the latest cyber security news and trends, from the perspective of business leaders and owners.  Hosts Trish and Tom provide plain English explanations along with practical advice to keep your business safe and secure from cyber crime and disruption. For cyber security help and advice, speak to Cool Waters Cyber: www.cool-waters.co.uk