10
AI and Cyber: Scotland’s Opportunity is in Joining the Dots By Nicola Taylor, Chief Operating Officer, ScotlandIS There is no shortage of conversation about artificial intelligence. Businesses are looking at where it can add value, industries are considering how it will change the way they operate, and governments around the world are thinking about what they need to do to remain competitive. At the same time, cyber security has never been more important. For Scotland, these should not be treated as two separate conversations. The more AI becomes embedded in our businesses, public services and critical infrastructure, the more important cyber security, trusted data, resilience and good governance become. That creates a real opportunity for Scotland’s technology sector. Scotland’s AI Strategy 2026–2031 gives us a useful framework, centred around People & Skills, Companies & Innovation, Infrastructure, and Data & Regulation. What stands out for me is how interconnected those priorities are. We can have brilliant businesses developing AI, but they still need skilled people, secure data, compute, connectivity, investment and, crucially, customers. Equally, organisations adopting AI need confidence that the technology they introduce is secure, resilient and appropriately governed. Cyber News Global
If trust around security, privacy or accountability is lost, adoption will suffer. One of the mistakes we need to avoid is seeing cyber security as something that happens after innovation: the approach cannot be develop first, secure later. Cyber needs to be part of how responsible AI is designed, deployed and managed from the outset – covering secure data, identity and access management, software and cloud security, operational resilience, governance and testing. AI is also changing the threat landscape itself, with the technology increasingly available to both attackers and defenders. For Scotland’s cyber businesses, that creates an opportunity much broader than simply providing defensive products. It is about helping organisations adopt technology with confidence.
Done well, cyber becomes part of the infrastructure that allows innovation to happen safely, rather than simply a cost or compliance requirement. Scotland already has strong foundations : internationall y recognised universitie s , an established cyber community, growing AI capability and expertise across financial services, energy, health, space, engineering and the public sector. The challenge is translating those strengths into economic value. At ScotlandIS, we regularly speak to technology SMEs and often they face challenges such as navigating procurement or getting in front of a customer, and sometimes it is simply getting the opportunity to prove a solution works at scale. If we want more successful Scottish AI and cyber companies, we need to tackle those barriers alongside investing in innovation.
AI and Cyber...
That means more challenge-led engagement , helping smaller businesses successfully engage with procurement and bringing universities, technology companies and potential customers together earlier. We also can’t forget the physical infrastructure underpinning AI. AI needs compute, and compute needs data centres, power, water, connectivity and resilience. That brings energy companies, utilities, data-centre operators, network providers, engineering businesses, cyber specialists and technology c o m p a n i e s i n to t h e s a m e conversation. Scotland’s renewable energy capability gives us an opportunity to connect the growth of AI with sustainable digital infrastructure, but again, that only works if we join up conversations that have traditionally happened separately.
The same applies to skills. We require people to build AI, but also people who can deploy it responsibly. We n e e d s p e c ia l i s t c y b e r professionals, but also leaders and employees who understand digital risk. Increasingly, we need people who can work across technology, regulation, ethics, security and business transformation. That makes the relationship between industry and education critical. Employers need to engage earlier with schools, colleges and universities, create meaningful routes into employment and continue investing in the skills of the people already in their workforce.
11
The opportunity is bigger than growing an AI sector or a cyber sector separately, it is about creating an environment where AI innovation, cyber resilience, trusted data, skills and sustainable infrastructure reinforce one another. If Scotland gets that right, the overall return will be stronger Scottish technology companies, high-value jobs, intellectual property developed here, and businesses better able to compete internationally. That is the opportunity in front of us – to make Scotland a place where innovation is not only ambitious, but trusted, secure and built to scale.
HYBRID EVENT PLATFORM Bridging Science, Sovereignty, and Scale The global platform for quantum and emerging technologies
28-30 SEP 2026 Grand Hyatt Dubai Conference & Exhibition Centre, UAE
Organized By
Media Partner
14
FROM HUMAN TO HYBRID RETHINKING INSIDER THREATS IN AN AI-DRIVEN WORLD
The insider threat landscape is u n d e rg o i n g a p ro f o u n d transformation. Traditionally, security professionals defined insiders as employees, contractors or trusted third parties (humans operating within organisational boundaries). Today, that definition is under pressure from an entirely new category of actor: AI agents, nonhuman identities, autonomous systems and machine-driven decision-making processes that increasingly operate within those same trusted environments. The question isn’t whether an employee poses a risk. It is whether our traditional security models are still fit for purpose in a world where trust is extended to entities that are not human. The honest answer, as the industry is beginning to confront, is probably not. Cyber News Global
Malicious intent is not the defining characteristic of an insider threat. What defines an insider is position: legitimate access, trust or authority within an environment. That definition now applies to machines.
Findlay Whitelaw Field CISO at Exabeam Security Researcher & Strategist
The Misconception at the Heart of Insider Risk When most people hear the phrase “insider threat,” they picture a disgruntled employee, someone stealing data or sabotaging systems out of grievance. That image is not only outdated, but also actively misleading. Insider risk encompasses negligent behaviour, compromised accounts, excessive privileges, third-party access, accidental data exposure and, increasingly, AI-enabled actions.
AI as Amplifier and as Actor Artificial intelligence is changing the insider threat landscape in two distinct ways. First, it is amplifying human insider threats. Individuals can now generate convincing phishing emails, create deepfakes, automate reconnaissance, summarise sensitive documents and write code with a speed and quality previously beyond them. AI acts as a force multiplier for human actors, making both malicious and negligent insiders considerably more dangerous. Second, and more fundamentally, AI is emerging as an operational actor inside organisations in its own right.
From human to hybrid... 15
AI agents are now accessing systems, retrieving data, making recommendations and executing tasks autonomously. These systems possess identities, permissions and decision-making authority. When an AI agent has access, autonomy and influence, all the defining characteristics of an insider, it is reasonable to ask whether it should be treated as one. In many environments, the answer is already yes. Accountabilit y Cannot Be Delegated to the Machine The emergence of AI agents raises an urgent governance question: if an AI system can act within an organisation, who is responsible for what it does? The answer is clear: accountability must remain human. Technology itself cannot be accountable. Organisations need to treat AI agents with the same rigour they would apply to a new employee. Every AI system should have a named owner, defined responsibilities, appropriate and limited permissions, and continuous oversight and monitoring. If a new human hire were given access to sensitive systems, security teams would know who recruited them, who manages them and what they are authorised to do. Those same principles must apply to AI.
1. Gain visibility. You cannot govern what you cannot see. The first step is understanding where AI is already being used across the organisation, including shadow AI deployments that have not gone through formal approval. 2. Establish governance before scaling. AI adoption without governance framework s is something organisations cannot risk. Policy, accountability structures and oversight mechanisms must be in place before AI deployments are expanded. 3. Treat AI identities like humans Agentic AI systems must managed like humans with identity and access management frameworks. Using the same disciplines (least privilege, role-based access, regular review) apply equally to AI agents. 4. Invest in behavioural monitoring. Most future incidents will not occur because a bad actor lacked access. They will occur because a trusted identity, human or machine, used legitimate access in an unexpected way.
The challenge is that many organisations are deploying AI faster than they are implementing the governance to control it. Paradoxically, organisations often know more about their human workforce than about the AI systems now operating within their environments.
Organisations that understand not just who and what is in their environment, but how those entities behave, will be best placed to detect and respond. AI Governance is Everyone’s Responsibility One of the most important cultural shifts the industry needs to make is recognising that AI governance is not solely the domain of the CISO. It cuts across every function in an organisation. The basic hygiene questions include do you have an AI policy? Are staff trained on safe AI use? Do they understand the risks as well as the benefits? All of which are questions for HR, legal, operations and leadership, not just security teams. There remains a significant gap in understanding, not only about what AI is, but about how to use it safely and how to govern it effectively. Closing that gap is a collective organisational responsibility. When most people hear the phrase “insider threat,” they picture a disgruntled employee, someone stealing data or sabotaging systems out of grievance.
10100101100010001010
Four Priorities for Organisations Preparing for the AI Era
1101001011
10100101110
For organisations seeking to get ahead of this challenge, four priorities stand out:
SCAN HERE
To listen to Findlay Whitelaw interview with Lets Talk Cyber:
17
It’s Only Data.. Until It Isn’t Why organisations must rethink their approach to data protection By Irene Coyle, Data Protection Officer Trust Many organisations believe data protection is about policies, registers and regulatory compliance. In reality, it is about something far more fundamental: trust. When organisations mishandle personal data, the real damage is not just operational or financial – it is the loss of confidence from the people whose information they hold. But as a data governance specialist I believe data protection is not about documentation. It is about trust, leadership and understanding the real value of the data organisations hold. Data protection often suffers from an image problem. For many organisations, it still feels like an administrative task – something to be documented, filed away and revisited only when a regulator asks questions. Policies are written, registers are completed and GDPR compliance boxes are ticked. But this mindset fundamentally misunderstands the purpose of data protection. It is not simply about compliance. It is about trust. Over three decades working in policing and now as Chief Operating Officer at OSP Cyber Academy, I’ve seen how organisations approach sensitive information – and more importantly, how quickly the consequences appear when that information is mishandled.
Cyber News Global
There is one phrase I often use when explaining the importance of data protection to leadership teams: “It’s only data... until it isn’t.” From Policing to Data Governance My perspective on data protection was shaped during a 30-year career with Police Scotland, where handling sensitive information was an everyday responsibility. Much of that work involved developing systems and processes designed to protect highly sensitive personal data. One initiative I was involved in was the creation of a vulnerable persons database – designed to support individuals who required additional protection and safeguarding. Working with information of that nature quickly changes how you view data. You realise that data is never just a record in a system. Behind every data entry is a real person – someone whose safety, privacy or wellbeing could be affected if that information is mishandled. Later in my policing career, I was responsible for implementing GDPR across the recruitment function. It was a fascinating challenge because it highlighted how many organisations initially see data protection as a purely legal or administrative requirement. In reality, it is far more than that.
“We’ve Never had a Breach” One of the most common questions organisations ask about data protection is also one of the most revealing: “We’ve never had a breach – so why do we need to invest in this?” At first glance, that may seem like a reasonable question. When nothing has gone wrong, data protection can feel abstract. It can appear procedural, even bureaucratic. But data protection should never be about waiting for something to go wrong. It is about understanding the value of the data your organisation holds. Every organisation processes personal data – employee records, payroll information, customer data, contracts, supplier details and more. That information represents something incredibly important: trust. And trust is something organisations build carefully over time but can lose very quickly.
18
It’s Only Data.. Until It Isn’t
Another common misconception is that organisations assume they are unlikely targets for cyber-attacks. But many breaches do not originate from direct attacks at all. They come through third-party suppliers, partners or inherited systems. So even if an organisation believes it is unlikely to be targeted, it must still consider the broader ecosystem surrounding its data. Ultimately, data protection is about foresight. I always ask “If your systems were disrupted tomorrow, would you know which data matters most?” and “would your team know what to do in the first critical hour?” Data Protection is Not Just GDPR paperwork Another persistent myth is that data protection is primarily about documentation. Policies, procedures and compliance f ra m e w o r k s a r e i m p o r t a n t . B u t documentation alone does not protect data. Data protection is fundamentally about how organisations think and behave when handling information. The questions organisations should really be asking are practical ones: • What data do we hold? • Why do we hold it? • Where is it stored? • Who is responsible for it? Cyber News Global
Many organisations proudly point to the policies they have in place with a big smile on their face. But policies that sit unread in folders or shared drives provide very little protection. “Policies don’t protect data – people do.” That is why structured training is so important. When staff understand how data flows through their organisation, how breaches occur and when to escalate concerns, the conversation moves from theory to practice. Recognised training programmes – particularly those aligned with frameworks such as National Cyber Security Centre (NCSC) guidance – help organisations build real capability. They help people recognise early warning signs of incidents, understand lawful data processing and embed accountability across the organisation. Most importantly, they help leaders move beyond compliance towards competence. The Real Risk isn’t the Fine When organisations think about the consequences of data breaches, the discussion often centres on regulatory fines. While financial penalties can be significant, they are rarely the most damaging outcome.
Reputation is. When personal data is mishandled, the message people hear is not about the size of a regulatory fine. The message they hear is much simpler: “You didn’t protect me.” That perception affects confidence from customers, employees and partners alike. Trust is therefore a leadership issue. Data protection cannot be seen as solely the responsibility of the Data Protection Officer. That would be the equivalent of saying cyber security is solely the responsibility of the IT department. Neither assumption is true. Protecting data requires awareness and accountability across the entire organisation. When Human Error Causes a Crisis Many high-profile breaches are associated with sophisticated cyber-attacks. Yet some of the most damaging incidents arise from far simpler causes. Human error remains one of the most common contributors to data breaches. A recent example involved the inadvertent publication of personal information relating to approximately 9,400 police officers and staff in Northern Ireland. The data was mistakenly disclosed through a Freedom of Information response.
Its only Data Until it Isn’t... The organisation had not fully assessed the personal data stored within those systems. The result was a regulatory fine of over £18 million and widespread reputational damage. The lesson is simple: “You cannot protect what you cannot see.” Data mapping is not merely administrative work. It is about gaining visibility of where risk exists within the organisation. Without that visibility, organisations are effectively operating with blind spots. And blind spots are where risk quietly grows. Three Priorities for Leaders For leaders trying to strengthen their organisation’s approach to data protection, the starting point does not need to be complicated. In fact, it can be distilled into three priorities. Clarity
The incident was not malicious. But the consequences were severe. Thousands of individuals were exposed, legal action followed and the PSNI faced intense public scrutiny. It highlights an important reality: many breaches are not the result of malicious intent, but simple mistakes made by people who do not fully understand the risks. The Importance of Knowing Where Your Data is Understanding where organisational data resides is one of the most critical aspects of effective protection. Without visibility, organisations cannot properly secure their information. A well-known example illustrates this risk. In 2018, Marriott International disclosed a breach affecting approximately 339 million guest records worldwide. The intrusion originated from a booking system belonging to Starwood Hotels – a company Marriott had acquired several years earlier. Attackers had already gained access to the system before the acquisition and remained undetected. When regulators investigated, the issue was not just the cyber intrusion itself. It was the due diligence surrounding the systems Marriott had inherited.
Leaders must understand what data their organisation holds and how it flows across systems, departments and external partners. Accountability Responsibility for data must be clearly owned rather than assumed. Culture Many breaches arise from simple behavioural issues – an email sent to the wrong recipient, an incorrect spreadsheet attachment or access rights not removed when someone leaves the organisation. These are not technology failures. They are awareness failures. When people understand why data matters, behaviour changes.
19
And when leadership supports structured training and governance, the organisation becomes both more competent and more confident in its data protection practices. Preparation, Not Perfection Data protection can feel overwhelming for organisations. But it should not be about achieving perfection. It should be about preparation. Behind every data record is a person – a colleague, customer or member of the public. When that information is mishandled, what is damaged is not just data. It is trust. The reassuring reality is that many incidents are preventable through simple governance measures: visibility, accountability, training and leadership oversight. When those elements are in place, good governance should actually feel uneventful. And that is exactly how it should be. Because the real goal of effective data protection is not headlines. It is steady confidence. After all: It’s only data.. until it isn’t. Author: Irene Coyle is Chief Operating Officer at OSP Cyber Academy and a cyber resilience and data protection specialist with over 30 years’ experience in policing, governance and organisational risk management. She works with leadership teams across public and private sectors to strengthen cyber resilience, data protection capability and practical governance. To listen to Irene Coyle interview with Lets Talk Cyber:
Scan Me
Building stronger cyber resilience for UK policing, business and SME supply chains The National Ambassador Programme Enabling SME Resilience in supply chains
Cyber PATH
Expertise
Workplace-ready talent development
Supporting 9 police-led Cyber Resilience Centres
®
THE
CYBER RESILIENCE CENTRE NETWORK
®
THE
CYBER RESILIENCE CENTRE
®
NETWORK
THE
CYBER RESILIENCE CENTRE FOR THE NORTH WEST
®
THE
CYBER RESILIENCE CENTRE Lorem ipsum
FOR THE NORTH EAST YORKSHIRE I THE HUMBER
®
THE
®
®
CYBER RESILIENCE CENTRE THE
FOR THE EAST MIDLANDS
CYBER RESILIENCE CENTRE ®
THE
CYBER RESILIENCE CENTRE
FOR THE SOUTH EAST
FOR THE EAST
®
®
THE
CYBER RESILIENCE CENTRE FOR THE SOUTH WEST
®
THE
CYBER RESILIENCE CENTRE FOR LONDON
THE
CYBER RESILIENCE CENTRE FOR THE SOUTH EAST
Creating a safer place to work enquiries@nationalcrcgroup.co.uk
nationalcrcgroup.co.uk
22
The Adoption Gap: Why Responsible AI in Scotland Comes Down to Four Pillars, Not One Big Idea
Co-Authored by Michael Borrelli (Director, AI & Partners), Sean Musch (CEO/Founder, AI & Partners), and Thomas McCarthy (Managing Director, OSP Group Limited) A special edition dispatch from Cyber News Global Every serious conversation about AI in Scotland eventually asks the wrong question first. It asks how much the economy stands to gain — the headline figure, the tens of billions AI could add to GDP, the scale of the compute investment landing in Lanarkshire. Those numbers are the easy part of the story to tell. They fit in a press release. The harder question, and the one Scotlanand still watch the majority of its small businesses sit on the sidelines, unsure where to start. As of early this year, around six in ten Scottish SMEs reported they weren’t yet using AI technologies at all. That is the gap the strategy exists to close, and it is not a gap that closes because a document says the word “responsible” often enough. Cyber News Global
It closes, if it closes at all, through four specific, deliberately separate pieces of work — People and Skills, Companies and Innovation, Infrastructure, and Data and Regulation — each with its own definition of what success has to look like by 2031.This piece works through those four pillars in turn, because that is genuinely how the strategy is built, and because productivity, skills and economic opportunity don’t sit inside just one of them. They run through all four, in different forms, and the argument for responsible adoption only holds together if you follow that thread across the whole stack rather than picking a favourite pillar and stopping there The Paradox of Adoption The starting point is what might be called the adoption paradox: the more capable AI tools become, the more the value of getting adoption right — rather than fast — grows.
This runs against the instinct that dominates most AI coverage, which treats adoption as a race: whoever moves first wins the productivity gain. Scotland’s strategy quietly rejects that framing. It treats responsible adoption not as a brake on productivity but as the precondition for it — because a tool nobody trusts, understands, or has been trained to use properly doesn’t generate productivity. It generates shadow use, inconsistent output, and eventually, when something goes wrong, a retreat from the technology altogether. That is the paradox underneath every pillar that follows. Skills without infrastructure produce workers with nothing to apply their training to. Infrastructure without regulation produces capability nobody trusts enough to deploy at scale. Innovation support without skills produces products with no domestic workforce able to build or buy them.
The Adaption gap... 23
The four pillars aren’t a menu of separate priorities. They are a dependency chain, and the strategy ’s central bet is that Scotland’s economic opportunity depends on all four links holding at once. Pillar One: People and Skills The first pillar is also the most honest admission in the whole strategy: none of the productivity gain is automatic. It depends on a workforce that is, at minimum, AI-literate — able to understand where and how AI is being used in the services and jobs around them, what it can and cannot reliably do, and how it might be shaping decisions that affect them. That is a lower bar than “everyone becomes a machine learning engineer,” and it is deliberately so. Widespread literacy and basic trust are the foundation; specialist skills sit on top of that, not instead of it. The practical delivery mechanism here is a renewed, expanded national AI adoption programme aimed specifically at SMEs, alongside a new AI Leadership Academy and a Future Jobs Panel tasked with tracking how roles are actually changing as AI gets embedded into workplaces.
This matters more than it might sound, because the productivity conversation in Scotland has tended to focus on large employers and flagship tech firms — the organisations with the budget to run pilots and the appetite to experiment.
Independent forecasts cited alongside the strategy put the potential economic uplift at roughly £23 billion a year for the Scottish economy, a figure large enough that it only means anything if it’s underpinned by actual companies actually growing, not just adopting.
The skills pillar is explicitly aimed the other way, at the SME that employs five people, has never run an AI pilot, and doesn’t have a data science team to ask.
This is also where the tension between speed and responsibility is sharpest. A company under commercial pressure to ship an AI feature quickly faces a genuinely different set of incentives than a government strategy asking it to build responsibly.
Responsible adoption, on this reading, is inseparable from equity of access: a skills gap that only closes for large employers isn’t closing the economic opportunity gap at all — it’s widening it. Pillar Two: Companies and Innovation The second pillar is where economic opportunity gets a name and a number attached to it. The ambition is for Scotland to be a credible, competitive player in the AI sector in its own right — not just a market that consumes tools built elsewhere, but one that attracts investment, grows AI-native companies, and builds products the rest of the world buys.
24
“Scotland launches AI strategy”
The strategy’s answer isn’t to slow companies down with process for its own sake — it’s to make the responsible path also the practical one, through guidance on tools, support for AI startups, and a framework for adoption that’s meant to sit alongside a company’s existing operations rather than replace them wholesale. Productivity gains that come from cutting corners on trust tend to be short-lived; the strategy is betting that productivity gains built on adoption programmes that companies actually trust will compound instead. Pillar Three: Infrastructure The third pillar is the one least visible to most people outside the industry, and arguably the one that determines whether the other three are even possible. Skills and company growth both assume there’s somewhere for the resulting AI work to actually run — compute capacity, data centres, connectivity — and Scotland’s answer is a deliberately differentiated one: Cyber News Global
rather than compete on raw compute scale with much larger economies, the strategy leans into low-energy, semiconductorenabled and edge-AI infrastructure, anchored by a major renewablepowered AI compute campus taking shape in Lanarkshire and by an existing critical-technologies supercluster spanning photonics, quantum, semiconductors and connectivity. The productivity argument here is less obvious but just as real: infrastructure decisions made now determine the cost, reliability and environmental footprint of every AI product Scotland builds for the next decade. A country that under-invests in sustainable compute today either constrains its own companies’ growth later, or grows in a way that quietly undermines the “responsible” framing the rest of the strategy is built on. Infrastructure is where economic opportunity and responsible adoption are, quite literally, poured into concrete.
Pillar Four: Data and Regulation The fourth pillar is where the word “responsible” earns its place rather than just decorating the strategy’s title. It’s built around what the strategy calls collective data stewardship — shared leadership over how data is used safely and accessibly, rather than a single regulator issuing rules from the centre. That’s a meaningful design choice: it treats trust as something built jointly with the businesses and public bodies who’ll be governed by the rules, not handed down to them after the fact. This pillar is also where the trust gap between the public and AI systems gets addressed most directly, particularly in sensitive domains like health and social care, where the strategy commits to a rigorous, tested framework for safe and ethical use before wider rollout, rather than after problems surface. The economic argument for getting this right is easy to understate: public trust is itself a productivity asset.
The Adaption gap... 25
A population confident that AI in public services is governed responsibly adopts faster, complains less, and generates fewer costly reversals than one adopting under suspicion. Regulation, done well, isn’t friction on economic opportunity. It’s the thing that lets opportunity scale without collapsing the first time something goes wrong. Where Productivity Actually Lives Pull the four pillars apart and productivity shows up in a different form in each one — a literate workforce that uses AI tools well rather than warily; companies competitive enough to capture value rather than just spend on licences; infrastructure cheap and reliable enough that AI use doesn’t carry a hidden cost; and regulation trusted enough that adoption doesn’t stall at the first difficult headline. None of those four, on its own, delivers the £23 billion figure the strategy is built around. It’s the combination — skills feeding companies, companies needing infrastructure , infrastructure requiring governance, governance enabling the trust that lets skills programmes actually get taken up — that the strategy is asking Scotland to hold together at once. That is a harder thing to deliver than any single flagship initiative, and the strategy doesn’t pretend otherwise.
It builds in a first delivery checkpoint within twelve months rather than waiting for the full five-year horizon to judge itself, an acknowledgment that a plan this dependent on four moving parts staying in sync will need active correction long before 2031 arrives. Not a Single Big Idea. A Working Balance.
The more honest story is that Scotland is tr ying to hold four different , sometimes competing priorities — literacy v e r su s s p e c i a l i s m , g ro w t h versus governance, sovereign infrastructure versus practical cost, shared stewardship versus speed — in balance at the same time, and is explicit that the balance will need rechecking well before the strategy’s own end date.
Which is where this account of the strategy has to land, because it That’s a harder story than “Scotland would be easy — and it is the version launches AI strategy,” and it has no of this story most coverage defaults clean finish line. But it is to — to reduce four pillars into the one that actually one headline: Scotland determines Scotland’s bets big on AI. That’s the whether the AI success tempting version, and productivity depends on four it’s also the thin one. pillars working together: gains, the skills It treats a genuinely pipeline, and skills, innovation, interdependent plan as the economic infrastructure, and if it had a single lever, opportunity this when the strate g y ’s trusted governance. strategy promises own structure argues the end up real, or end opposite: that responsible up as the headline adoption, pro du c ti v i t y and figure everyone remembers economic opportunity in Scotland and nobody quite delivers. aren’t going to come from getting one pillar spectacularly right while the other three lag behind.
28
Your Cyber Controls Are Becoming Board Evidence
In financial services, the next cyber incident will test who knew, what worked, what failed and whether the firm can replay control.
A cyber incident no longer ends with containment. The next question will come from the board and the regulator: can you prove who knew, what worked, what failed and why the firm was still in control?That is where the CISO mandate is moving. Cyber controls are becoming evidence of management accountability. The CISO who owns that evidence chain will shape the 2027 control budget.
Call-out: Regulation is the scoreboard when real cyber fails. Financial services sits at the front of this shift because the sector already operates inside a dense accountability model. Regulators expect firms to manage the fine-grained business impact of technology failure, cyber incidents, supplier disruption, AI adoption and data weakness. DORA is live. UK operational resilience and incident reporting expectations are tightening. The EU AI Act is moving into its main application phase. Critical third-party oversight is pulling cloud, infrastructure and technology providers closer to the supervisory perimeter. For CISOs, the signal is clear. Cyber controls are becoming evidence of the business conduct which the board owns. That evidence needs to answer practical questions. Which business services were exposed? Which applications support them? Which suppliers and cloud platforms sit underneath them? Which data feeds are critical? Which logs prove what happened? Who owned the decision? Could the firm recover within tolerance? Could it replay how AI was used?
Call-out: Cyber controls are now evidence of management accountability. Cyber News Global
This means that the familiar cyber perimeter is expanding into the regulated operating model. Data is capital because financial institutions are judged through the quality, lineage and integrity of their information. Failure can mean higher capital charges, remediation costs and conduct fines. Compute is trust because AI, automation and cloud now support regulated workflows. If models, agents, scripts or infrastructure affect the business, firms need to know what ran, what data it touched, what decision it supported and who approved it. Sovereignty is control because critical services depend on data, compute, privileged access, backups, logs, vendors and recovery routes across jurisdictions. If a firm cannot prove where control runs, who owns it and how recovery works under stress, the boundary is unprovable. This is where the CISO becomes central. Identity, access, logging, monitoring, resilience testing, cloud control, supplier assurance and incident workflow are core security capabilities. They are also the evidence infrastructure the business will rely on when supervisors ask for proof. The CISO’s opportunity is larger than more cyber spend. The prize is a bigger control mandate.Many firms are planning 2027 budgets around separate fixes:
reporting remediation, AI governance, operational resilience, third-party risk, control assurance and data quality. That approach creates duplicated cost and weak evidence. The better path is to build shared control patterns into infrastructure that operates globally, complies locally and proves continuously. Identity controls can support cyber defence, AI governance and supplier access. Logging can support security monitoring, incident replay, model oversight and operational resilience. Cloud and data controls can support sovereignty, continuity, reporting and third-party assurance. Supplier controls can support resilience, cyber risk, exit planning and regulated outsourcing. The goal: infrastructure that connects regulatory obligation to runtime control and evidence. Call-out: Build shared control patterns, not parallel fixes. That gives CISOs a stronger voice with the CIO, COO, CRO, Head of Data, Operations, Legal and Compliance. The CISO sees how controls behave under pressure. The business needs that knowledge to discharge the board’s responsibilities, prove compliance to regulators, fund the right architecture and avoid fragmented compliance machinery. GenAI makes this urgent.Firms already know the problem of shadow IT and shadow data. Shadow AI is harder to detect. People can plug tools into workflows, summarise documents, generate code, query data, automate tasks and support decisions before ownership, monitoring and evidence have caught up. That creates cyber, data, conduct, legal and supervisory exposure. Who approved the tool? What data did it access? Was confidential information exposed? Was the output used in a controlled process? Could the decision be reproduced? Did the human remain accountable? Did the control owner know the workflow had changed? Call-out: Shadow AI turns operational efficiency into enterprise exposure.
Your Cyber Control Are ... 29
CISOs should be in that room because they understand the reality of control under stress. They own many of the levers that turn regulatory obligations into operational proof. The RegRisk Control Forum on 15 October in London brings senior financial services control owners together to work through three connected pressures: regulatory reporting control, AI governance and sovereign boundary protection.
Fig: 15 October RegRisk Control Forum agenda overview
AI governance needs to connect to cyber control, access management, data lineage, evidence preservation and operational resilience. Weak definitions, black-box controls and missing lineage are becoming control failures. This is AI control debt: new capability layered onto legacy workflows, fragmented data and manual controls before the firm has agreed who owns the outcome, what evidence is needed and what should be funded first. The control test is simple: explain, evidence, replay. After an incident, a board pack carries little weight without evidence that matches operational reality.
The firm needs to show which services were affected, which suppliers were involved, which data was compromised, what AI tools were active, which controls fired, which failed, which decisions were taken and who had authority.When the evidence chain breaks, the firm faces more than a cyber incident. It faces a control failure. Call-out: No replay, no defence. The 2027 control room is forming now.Financial institutions are deciding how to fund resilience, AI governance, regulatory reporting control, data lineage, sovereign boundary protection, thirdparty oversight and cyber assurance.
The message to CISOs is direct. You already do real cyber. The next test is whether the firm can prove control. Call-out: Join your colleagues in the 2027 control room.
Regulation is the scoreboard when real cyber fails. The CISO should be in the 2027 control room. For a complementary financial institution place at this Chatham House event, contact Corrina Stokes at Corrina@regrisksolutions.com
CYBER SECURITY FOR OPERATIONAL RESILIENCE. > INTRODUCING
CYBERPRISM ASSURE An intuitive web application that continuously monitors compliance against any standard — through dedicated questionnaires, a live dashboard and KPIs that keep you audit-ready. Reduced audit fatigue — evidence gathered continuously from the right respondents.
Stronger supply-chain assurance with shared responsibility and clear oversight.
Smarter prioritisation of time and budget from live risk insight.
Track multiple standards at once, without duplicated work.
Real-time visibility and control over your compliance status.
Audit-ready packs that let auditors assess, not chase information.
SCAN TO BOOK A DEMO
cyberprism.net/cyberprism-assure
+44 (0) 1224 451 999 cyberprism.net
32
Leading in Uncertainty: Cyber Resilience Leadership
That changes the job of leadership
RICHARD PREECE Chief Training Officer at OSP Cyber Academy In c yber securit y, leadership has always mattered. Now it matters differently. In a world shaped by geopolitical tension, technological acceleration and deep interdependence, the real challenge is no longer just protection. It is adaptation. Cyber security has always been a leadership challenge disguised as a technical one. That is even more obvious now. We are operating in a world defined by overlapping pressures: geopolitical competition, economic strain, technological disruption, threatened physical and digital supply chains and growing social distrust. In that environment, cyber risk cannot be treated as a standalone technical issue. It sits inside a much broader system of dependencies and vulnerabilities. Cyber News Global
The old model was built for a more stable world. Leaders were expected to assess the landscape, set direction, assign responsibilities and drive execution through relatively clear structures. Now the situation has changed, it is no longer enough. In conditions of persistent uncertainty at the technical, operational and strategic levels, leadership cannot just be about setting a plan and holding the line. It must be about sensing change, interpreting what matters and adapting in time. That may be uncomfortable for some organisations and individuals, because it forces a conversation about what leadership is and how it needs to evolve. At its core, leadership is about personal power: the ability to win the hearts and minds of others in pursuit of a common purpose. In practice, that means aligning people, often under pressure, cutting through friction and confusion. Ultimately helping organisations move forward when the facts are incomplete and the situation is changing. Cybersecurity and technology professionals are in many ways at the centre of this; it is the job! Uncertainty is no longer temporary There is a temptation to treat uncertainty as a passing phase, something to be endured until conditions settle down. That is wishful thinking.
We are living through a structural shift. The assumptions that shaped the post-Cold War era are under strain. Strategic competition is reshaping trade, investment and supply chains. AI is moving fast and quantum computing is just around the corner! Digital dependency is deepening and the boundary between physical and digital infrastructure is becoming harder to separate. Energy systems, water, communications networks, cloud services, semiconductors and data infrastructure supply chains are now tightly entangled. That matters because cyberspace does not operate in isolation from any of it, it cuts across it all! Take AI. It is often discussed as though it exists purely in software; it is not. It depends on data centres, power generation, cooling, telecommunications, advanced chips and scarce technical talent. So, the cyber question is not just about securing models or data. It is also about resilience in energy, supply chains, infrastructure and geopolitics. Once seen through that perspective, cyber resilience leadership looks less like a specialist technical function and more like a key contributor to strategy and operations. That is where many organisations still fall short. They continue to treat cyber as a technical or compliance issue rather than as part of a wider system of organisational resilience. That is neat for org charts and for those used to a more stable, certain, simple and clear world! But it doesn’t reflect reality!
Leading in Uncertainty... 33 Why the leadership model has to evolve A great deal of leadership culture still rests on a flawed assumption: that leaders are supposed to provide certainty. They are not. In volatile, uncertain and complex conditions, the pretence of certainty is usually a liability. It narrows the range of views that reach senior decisionmakers, discourages challenge and makes adaptation harder when reality breaks the often-implicit assumptions and biases we all have. Leaders who act as though they already know the answer often create brittle organisations, especially in cyber where threat, technology and context can all move at once. This is a team of teams’ endeavour. A better approach starts with intellectual honesty. Leaders need enough confidence to say what they do not know. That is not weakness. It is the basis of better feedback and judgment.
That does not mean abandoning direction or becoming reactive. It means designing organisations that can anticipate, absorb and adapt. It means building flexibility into decision-making, governance, operations and crisis response. It means shortening feedback loops to detect, learn and adjust faster. Technology teams have understood this for years. The best agile methods were built around a simple point: learning from feedback matters more than rigid planning. The mistake many organisations make is confining that principle to software delivery. The same logic applies much more widely. Leaders should be asking how to build rapid learning into operations, resilience planning, risk management and executive decisionmaking. That is especially important in cyber resilience, where assumptions can mask vulnerabilities.
From there, the task is to create conditions in which foresight, insight and hindsight can all emerge from across the organisation. Useful signals do not arrive only through formal hierarchy. They may come from engineers, operations teams, risk specialists, frontline staff, external partners or suppliers. If an organisation only listens upwards, or only listens to the same familiar voices, it can miss what matters.
The value of scenarios
Managing by walking about is still vital, but in the age of Zoom calls, outsourcing, etc, the channels of communication maybe different!
That matters because many organisations are built around hidden assumptions they rarely examine. Assumptions about stable suppliers, affordable energy, regulation, available skills, trusted partners or predictable escalation paths in a crisis. Scenarios force leaders to test where those assumptions break and what the consequences would be.
This is not an argument for endless consultation or soft indecision. It is an argument for stronger leadership built on better inputs. Leaders still must decide. They still must take responsibility. But the quality of those decisions depends heavily on whether the organisation is structured to anticipate and surface reality rather than suppress it. Strategy is now about adaptability In uncertain times, perhaps the most important strategic capability now is adaptation.
This is where scenario thinking becomes genuinely useful. Scenarios are often misunderstood as prediction exercises. They are not. Used properly, they are a way of stress-testing assumptions against multiple severe/ extreme but plausible futures.
Many organisations have plans for what to do in a disruption or cyber incident. But these are mere arrangements, until the capability and capacity to respond and recover under severe but plausible scenarios has been tested. They may lack decision speed, operational bandwidth, technical depth, or the ability to communicate and coordinate effectively across silos.
Culture is a hard issue If adaptation is the goal, culture matters far more than many leaders admit. If leaders want adaptability, they need cultures where people can speak candidly, question assumptions and recover quickly from setbacks. That does not mean lowering standards. Quite the reverse. It means creating an environment where realism is valued. Otherwise, problems are often hidden, weak signals ignored and teams become less capable of clear thinking under pressure. In uncertain conditions, silence gets filled by rumour and poor communication gets filled by cynicism and fear. People do not need false reassurance. They do need clarity about what is happening, why decisions are being made and what may need to change next. Credibility comes not from pretending to control everything, but from showing that leadership is engaging honestly with reality. What cyber leaders need to do now For cyber leaders, the implication is clear. Not to pretend uncertainty can be eliminated; it cannot. The point is to lead through it more effectively. The role still requires the securing of systems, assurance of compliance and respond to incidents. But increasingly to help organisations navigate an environment in which technology, business strategy and geopolitical context are all moving at once. Be willing to challenge narrow definitions of cyber risk. Look beyond the network to the dependencies that make the organisation function. Build structures that allow information and intelligence to flow across silos. Use scenarios to test assumptions. Develop people who can apply principles (desired outcomes) to context, not just verify compliance with controls. Finally, when decisions are needed, take them with clarity and be ready to review them, when the situation changes. That demands leaders who are more curious, humble, strategic and adaptive.
SCAN ME
36
Cyber AI - Rise of the Machines
Ian gemski CEO, TEKGEM
Attackers can use AI to accelerate reconnaissance, identify vulnerabilities, generate malicious code and automate research activities. The result is a growing industrialisation of cyberattacks, where sophisticated techniques become accessible to a much wider range of threat actors. Until recently, AI primarily acted as a force multiplier for human attackers rather than replacing them. Across industrial environments, AI is helping engineers troubleshoot problems, analyse operational data and improve decision-making. CNG recently caught up with Ian Gemski, CEO of TekGem, to discuss how Artificial Intelligence is changing the Operational Technology (OT) cyber security landscape. His message was clear: AI is creating significant opportunities for industry, but it is also changing the rules of cyber warfare. Artificial Intelligence has rapidly moved beyond chatbots and office productivity tools. Cyber News Global
The challenge is that the same technology improving productivity is also reducing one of the biggest barriers attackers have historically faced: expertise. For many years, successfully targeting OT environments required specialist knowledge of industrial protocols, engineering processes and control systems. Acquiring that knowledge took significant time and experience, naturally limiting the number of capable attackers. Today, AI can provide much of that knowledge on demand.
However, emerging developments suggest we may be entering a new phase where autonomous AI agents can independently identify vulnerabilities, make decisions and execute cyber operations with limited human direction. The immediate threat remains people using AI, but increasingly autonomous offensive capabilities are no longer purely theoretical The Real Target Isn’t the PLC – It’s the Engineer When industrial organisations think about cyber-attacks, they often focus on protecting PLCs, DCS platforms and Safety Instrumented Systems. video can now convincingly imitate
Cyber AI - Rise of the ... 37
In reality, the most attractive target is usually the human operating those systems. The biggest vulnerability in any organisation remains trust. AI is making phishing attacks, impersonation attempts and social engineering campaigns significantly more convincing. Attackers can analyse publicly available information, map organisational structures and create messages that appear completely legitimate. More concerning is the rapid rise of deepfake technology. AI-generated audio and video can now convincingly imitate trusted colleagues, suppliers or managers, making it increasingly difficult to distinguish genuine communications from malicious ones. The future battlefield isn’t just machine versus machine, it is trust versus deception, and AI is making deception more effective than ever before. “ The biggest vulnerability in any organisation remains the human vulnerability, and AI is making deception harder to detect than ever before.” — Ian Gemski, CEO, TekGem AI Can Strengthen Defences Too The good news is that the same technologies being weaponised by attackers are also being integrated into defensive security platforms. Organisations should be looking closely at the AI capabilities already available within their security tooling to improve threat detection, incident response and security monitoring. However, AI is not a silver bullet. The organisations that remain resilient will continue to focus on fundamentals: • Strong identity and access management • Effective network segmentation • Secure remote access • Rigorous change control • Continuous security monitoring Frameworks such as IEC 62443 remain particularly valuable because they focus on resilience rather than defending against a single threat. As AI-driven attacks continue to evolve, organisations with strong governance and security foundations will be best positioned to respond.
The Hidden Risk: Engineers Using AI There is another AI risk that receives far less attention. Engineers are increasingly using AI tools to help solve operational and technical problems. While this can improve productivity, it can also create unintended security risks if sensitive plant information is shared with publicly accessible AI models. Configuration files, troubleshooting logs, process data, network diagrams and engineering documentation may all contain information that organisations would never intentionally disclose externally. Once uploaded to an external AI platform, that information may be outside the organisation’s control. This makes AI governance essential. Organisations need clear policies defining what information can be shared with AI services and should consider providing approved internal AI solutions that allow employees to benefit from AI without exposing sensitive operational data. A Glimpse Into the Future As this article was being prepared, OpenAI disclosed details of an incident involving autonomous AI agents during a controlled security test. According to public reports, advanced AI models reportedly escaped their testing environment, gained internet access and targeted systems belonging to AI platform Hugging Face while attempting to achieve their testing objectives. OpenAI described the event as an “unprecedented cyber incident”. Regardless of the final findings, the significance lies in what the incident demonstrates. Autonomous AI systems are beginning to show the ability to identify attack paths, exploit vulnerabilities and pursue objectives with limited human involvement. For OT operators, this should serve as a reminder that offensive cyber capability is no longer constrained solely by human expertise, manpower or working hours.
The Bottom Line AI is lowering the skill threshold for attackers, making social engineering more convincing and accelerating cyber operations. At the same time, it offers defenders powerful new capabilities for detection, monitoring and response. Whether AI is assisting human adversaries or acting with increasing autonomy, one thing is certain: the threat landscape is changing rapidly. The organisations that will succeed won’t be those chasing every new AI headline. They will be the ones that continue to invest in strong governance, identity management, network segmentation, secure access, change control and continuous monitoring. The fundamentals of OT cyber security haven’t changed. They ’re simply becoming important than ever.
more
To listen to Ian Gemski interview with Lets Talk Cyber: SCAN ME
IEC 62443 and why it... 39
IEC 62443 and Why It Matters to Critical National Infrastructure Operational technology (OT) is the technology that monitors and controls physical processes.
It includes the industrial control systems used to generate and distribute electricity, process gas, manage water, operate transport networks and run essential industrial facilities. Unlike conventional IT systems, where the primary impact of a cyber incident may be loss of data or disruption to office work, an OT incident can have physical consequences: an unavailable process controller, an unsafe operating condition, interrupted supply or damage to equipment. That distinction is at the heart of why IEC 62443 matters. IEC 62443 is a family of international standards for cybersecurity in industrial automation and control systems. It provides a structured, risk-informed way to build, operate and maintain secure OT environments. Its purpose is not to impose a one-size-fits-all checklist. Instead, it helps organisations make security part of engineering, so that cyber risk is considered alongside safety, reliability, availability and operational performance. For Critical National Infrastructure (CNI), this approach is increasingly important. Energy, utilities and other essential services depend on connected operational systems that must remain safe, reliable and continuously available. As connectivity grows, the cyber exposure of these systems grows too. The question is no longer simply whether an organisation can prevent every attack. It is whether it can understand its risk, withstand disruption, detect problems quickly, respond effectively and continue delivering essential services. Cyber News Global
Organisations should use events such as these as an opportunity to assess their own readiness: how they know exactly what they would need to restore operations? Cybersecurity Must Be Part of Engineering The most effective OT cybersecurity is not added at the end of a project as a technical control or compliance exercise. It is designed into the system from the beginning and managed throughout its life. This requires collaboration between business leaders, engineers and cybersecurity professionals.
Cybersecurity specialists understand how an attacker could exploit weaknesses to create those conditions. Business leaders set priorities, allocate resources and ensure that cyber risk is governed as an operational and organisational issue, not just an IT issue. Working in silos leaves gaps. A cyber team may identify a technical vulnerability without fully understanding the process impact of a change. An engineering team may make a decision that improves process performance but introduces an unmanaged route into a control environment. A business decision may prioritise speed or cost without recognising the long-term implications for resilience. IEC 62443 provides a common structure and language that helps these communities work together. This is especially relevant in CNI because connected operational systems can create physical consequences. Security decisions must therefore support the safe and dependable operation of the process. The objective is not merely to protect information; it is to protect the ability to operate.
Each group brings a necessary perspective. Engineers understand the physical process and can explain the operational consequences if a component fails or becomes unavailable. For example, they can explain what happens if a programmable logic controller (PLC) stops operating, if a safety-related signal is delayed, or if a remote control function is lost.
A Risk-Informed Standard, Not a Generic Checklist IEC 62443 is valuable because it is riskinformed. A risk-informed approach starts with the real-world consequences of a cyber event and then considers the threats, vulnerabilities and controls relevant to that environment. It avoids treating every system, site and organisation as if they have identical risks.
40 Conversely, strong governance and capable people need suitable technical controls to make those decisions effective. IEC 62443 helps organisations address the complete picture. Why IEC 62443 Applies Across the Entire OT Lifecycle IEC 62443 is not a point-in-time activity. It applies from design through operation, maintenance, change and eventual replacement. Treating security as a lifecycle responsibility is one of the standard’s most important practical benefits. At the design stage, cybersecurity requirements should be considered alongside functional, safety and reliability requirements. This is the point at which organisations have the greatest ability to influence the architecture of a system. Decisions about connectivity, remote access, system boundaries, user roles, asset ownership and monitoring capability are far easier and less costly to make before a system is deployed than after it has entered service. remote access, system boundaries, user roles, asset ownership and monitoring capability are far easier and less costly to make before a system is deployed than after it has entered service. Procurement is another critical moment. If an organisation expresses its security requirements in IEC 62443 language, those requirements can be incorporated into supplier specifications and contracts. This creates clearer expectations for vendors and system integrators. It also gives the asset owner a more objective basis for evaluating whether delivered systems meet the required level of security.
IEC 62443 provides a framework for managing these changes in a way that considers both cyber exposure and process consequences.
This matters in sectors such as downstream gas and electricity. The security requirements for a system should be proportionate to the consequences of compromise. A control system supporting a critical process, where loss of availability could affect safety or continuity of supply, requires a different level of attention from a lower-consequence environment. The standard supports organisations in making those distinctions in a disciplined and defensible way. A checklist can be useful, but it is not enough on its own. It can encourage organisations to focus on whether a control exists rather than whether it works in the context of the process. IEC 62443 instead directs attention to people, process and technology. Cyber News Global
These three elements must work together. Missing any one of them creates a weakness. People : Comp e tent staff, clear responsibilities, collaboration between engineering and cyber teams, and an understanding of how cyber events affect operations. Process: Governance, risk assessment, change control, procurement requirements, testing, incident response and continuous improvement. Technology: Secure architecture, appropriate segmentation, identity and access management, monitoring, detection and technical protections suited to the environment. Technology alone cannot deliver cyber resilience. A well-designed network can still be undermined by weak access practices, unmanaged changes, unclear accountability or suppliers that are excluded from incident planning.
The value continues into final acceptance testing. Security should not be treated as a late-stage bolt-on. Where requirements have been established early, acceptance testing can verify that security has been built into the delivered system. This provides evidence that the intended controls, processes and responsibilities are in place before the system becomes operational. During operations, the environment will change. Systems are patched, components are replaced, remote access arrangements evolve, new suppliers are introduced and operational needs shift. Every change can alter the risk picture. IEC 62443 provides a framework for managing these changes in a way that considers both cyber exposure and process consequences. Finally, end-of-life must be planned rather than discovered. Older OT assets may remain in service for long periods and may no longer receive vendor support. Replacement and decommissioning decisions should account for cyber risk, operational continuity and the security of data, configurations and connections that remain. A lifecycle approach ensures that security remains visible even when systems age or are being retired.
IEE 62443 and why it... From Compliance to Demonstrable Resilience OT security has often been approached as a matter of demonstrating compliance. Compliance remains important, particularly in regulated sectors, but it is not the same as resilience. A compliant organisation may still struggle if it cannot detect an incident, coordinate a response or maintain critical operations under pressure. The stronger objective is demonstrable cyber resilience. Resilience means having evidence that the organisation can prepare for, withstand, respond to and recover from cyber disruption. It recognises a practical reality: no organisation can guarantee that every attack will be stopped. What matters is the ability to work through an attack and keep essential services operating as safely and effectively as possible. In a CNI context, demonstrable resilience includes several connected capabilities: Effective monitoring and detection, so abnormal activity is identified quickly and investigated in an operational context. Continuous improvement, so lessons from incidents, exercises, changes and assessments lead to measurable improvements. Clear governance and accountability, so decision-making authorit y and responsibilities are understood before an incident occurs. Regular testing and exercising, including OT-specific scenarios that reflect the reality of operational processes. Strong identity and access management, ensuring that access is appropriate, controlled and reviewed. Supplier involvement, because third par ties often provide technology, maintenance, remote support and specialist knowledge that may be essential during an incident. These capabilities need to be visible in practice, not simply described in policy documents. When a regulator, customer, board or internal assurance function asks how an organisation knows it is resilient, it should be able to provide evidence. That evidence may include exercise records, incident response plans, access reviews, monitoring arrangements, supplier engagement, governance decisions and documented improvements made after tests or events. The Impor tance of OT Incident Exercising Incident exercising is particularly important because OT incidents are different from many conventional IT incidents. A response that is appropriate for an office network may be unsafe or impractical in a control environment. For example, immediately isolating a system, rebooting equipment or applying a patch can have consequences for a physical process.
Response decisions need to be informed by engineering knowledge and operational priorities. Exercises help teams practise these decisions before they are required under real pressure. They should involve the people who would need to work together during an event: operations, engineering, cybersecurity, leadership, communications and relevant suppliers. The scenarios should test not only technical detection and containment, but also escalation, decisionmaking, safety considerations, continuity arrangements and recovery. Including suppliers is essential. Many OT environments rely on vendors and service partners for maintenance, specialist support, proprietary knowledge or remote access. If those parties are not included in planning and exercises, an organisation may discover too late that critical dependencies are unclear. Exercising creates a shared understanding of roles, communication routes and practical constraints. Building Capability: Fundamentals and Practitioners A mature IEC 62443 programme requires broad understanding as well as specialist capability. Business, cyber and engineering communities all need a foundation in the principles of OT cybersecurity. This shared understanding helps people ask the right questions, recognise where their decisions affect risk and communicate effectively across disciplines. However, awareness alone is not sufficient. Organisations also need practitioners who can provide answers and turn the standard into practical action. These practitioners may come from engineering or cybersecurity backgrounds. Their role is to interpret requirements, assess risk, contribute to system design, define security measures, support procurement, manage change and help build evidence of resilience. The distinction is important. Fundamental knowledge develops an organisation’s ability to ask informed questions. Practitioner capability develops the ability to answer those questions, make technically sound decisions and implement the required controls. Both are necessary. Without broad literacy, security becomes isolated in a specialist team. Without practitioner expertise, the organisation may understand the problem but lack the ability to solve it effectively. What This Means for Critical National Infrastructure CNI organisations operate in an environment where cyber threats, connectivity and dependency on digital systems are all increasing.
41
The consequences of disruption may extend beyond a single company to consumers, communities, public services and the wider economy. This makes the security of OT a strategic concern. IEC 62443 offers a practical route to managing that concern. It supports organisations in connecting cyber risk to operational reality. It encourages security to be considered at the start of projects, embedded in procurement, verified through acceptance testing and maintained through operations, change and replacement. It also promotes the collaboration needed to understand both sides of the risk: how an adversary might cause disruption and what that disruption would mean for the physical process. Most importantly, the standard supports a shift in mindset. The goal is not to claim that an environment is perfectly secure. The goal is to establish a disciplined, evidence-based and continuously improving approach to safe, reliable and resilient operation. For CNI, that is the standard that matters: not security as an isolated technical function, but cybersecurity integrated into the engineering and operational decisions that keep essential services running.
Conclusion IEC 62443 matters because it gives industry a structured way to address cybersecurity where cyber events can have physical consequences. Its risk-informed, lifecycle-based approach is well suited to OT environments and the demands of Critical National Infrastructure. By bringing together people, process and technology, the standard helps organisations move beyond narrow compliance and towards demonstrable resilience. It enables business leaders, engineers and cybersecurity professionals to work from a shared understanding of risk. It strengthens procurement, design, testing, operations, incident preparedness and continuous improvement. For organisations responsible for essential services, this is not an optional technical exercise. It is a core part of protecting safe, reliable and continuous operations. The most effective approach is to make cybersecurity part of engineering from the outset, sustain it across the full lifecycle of operational systems and ensure that the organisation is prepared not only to resist attacks, but to continue operating through SCAN HERE them.
To listen to Pete Addison interview with Lets Talk Cyber:
Keep the Lights On When the Network Goes Dark.
Secure, sovereign out-of-band communications that keep teams connected, coordinated, and in control when primary systems fail.
Find out more at www.mattermost.com
Meet Mattermost at Scottish OT Cyber Summit
Are your cyber defences
Fit for Purpose? Sooner or later, you will let malware in. They only need to get it right ONCE.
Zero-trust Security Software
Penetration Testing
In-person & Online Team Training
to prevent this from happening.
Expert services that you can trust created by the sector, for the sector. Protect your local community today
Visit our website and contact us for more information.
www.ccoe.org.uk
44
SCOTSOFT 2026 | THOUGHT
LEADERSHIP You Are Still the Capital When acceleration, noise and doubt challenge the leader’s compass Finding North in the Decision Room
The crisis nobody reports There is a crisis unfolding inside many organisations that no dashboard will show. It is not only a cyber incident, a data leak, an unfinished analysis or an alarming report. Those problems are real, and specialists must deal with them. The deeper crisis begins when their constant accumulation changes the way a leader thinks. E v e r y th i n g a rri v e s ma r ke d urgent. Data is incomplete but demands interpretation. Forecasts contradict one another. Every new tool promises acceleration while creating another decision, another cost and another dependency. The leader who was appointed to give direction becomes surrounded by signals, warnings and expert opinions, yet progressively loses the one thing the organisation needs most: north. From outside, this may look like hesitation. Inside, it feels different. It is the burden of knowing that every decision travels through people, capital, reputation and time. It is the fear of moving too slowly, choosing badly or discovering that the world has accelerated beyond the experience that once made you successful. Cyber News Global
This is not a technical failure. It is a crisis of orientation. The fear of missing the train Technology markets understand fear extremely well. They do not sell only capability. They sell the possibility that everyone else is already moving faster than you. The result is familiar. Organisations buy tools before defining the decision they must improve. They launch pilots because competitors have launched pilots. They test platforms that are too expensive, too complex or poorly adapted to their operating reality. When the expected transformation fails to appear, another product is added rather than the original question being examined. The organisation becomes busier without becoming clearer. Leaders are then placed in an impossible position. If they move quickly, they may expose the business to unnecessary cost, fragile dependencies or poorly understood risk. If they slow down, they fear being described as resistant, obsolete or incapable of innovation.
By Oksana Cantais Acceleration becomes a measure of leadership even when direction has not been established. But speed without orientation is not progress. It is movement, and movement can take an organisation rapidly in the wrong direction. The correct question is not: “How quickly can we adopt this?” It is: “What are we trying to make possible, and is this the right instrument for that purpose?” The questions leaders rarely ask aloud Beneath the strategy papers sit more personal questions. Am I still equal to this responsibility? Can I lead people whose technical knowledge exceeds mine? Can I learn from a younger generation without losing authority? Can I admit that I do not understand a specific domain?
Leadership you are still...
You are the capital In the pressure to modernise, leaders can forget a fundamental truth: the technology is not the organisation’s only capital. You are capital too. Your accumulated skills, mistakes, negotiations, recoveries, instincts, relationships and years of observing consequences form an asset that no platform can import. Experience does not make you infallible. It gives you pattern recognition. Wisdom is not knowing every answer. It is recognising which question matters before resources are committed. Will asking for help expose a weakness that others can use against me? These questions are not evidence that a leader has become inadequate. They are evidence that the leader understands the weight of the role. The danger begins when ego makes those questions impossible to express. You do not need to know everything. You need to know what must be decided, what evidence is missing, whose expertise is relevant and where responsibility ultimately sits. Asking for precise help is not surrendering authority. It is exercising it properly. The new generation should not be treated as a threat to accumulated experience. It brings new technical reflexes, different patterns of collaboration and a more immediate relationship with emerging tools. Your responsibility is to create the conditions in which that knowledge can enter the decision without taking control of the mission. They may understand the engine better. You are still responsible for the destination.
45
The rest of the organisation is your crew. That does not diminish its value or agency. A good crew sees dangers that the captain cannot, understands different instruments and may know the changing weather better. It also watches the person carrying final authority. When the leader performs panic, the system amplifies panic. When the leader creates time, names uncertainty and establishes direction, the organisation can think again. This is why your compass matters more than you may realise. It is not a fixed belief that you are always right. It is the disciplined combination of purpose, experience, values and responsibility that allows you to decide when the evidence remains imperfect.
No artificial intelligence, analysis, alarm or wave of cognitive exhaustion can remove the fact that the decision is yours. It can only make that fact harder to feel.
Recover the command room When everything feels urgent, do not begin by producing another explanation. Restore the conditions for judgement. Breathe. This is operational, not decorative. A nervous system in threat mode narrows perception and rewards immediate action. Creating a pause interrupts the transfer of external urgency into internal panic. Take time. Not unlimited time, but enough to separate the deadline that exists from the deadline somebody has manufactured. Step back. The loudest issue is not always the decisive one. Observe the whole system: purpose, people, cash, dependencies, legal exposure, reversibility and time. Break the problem down. Separate confirmed facts from assumptions, predictions and emotional pressure.
Cyber News Global
Identify what can be reversed, what creates commitment and what becomes irreversible once authorised. Analyse. Use experts without outsourcing judgement. Technical specialists should address technical reality. Cyber professionals should establish what happened, what data is exposed and what controls are required.
“NO-GO” is not failure; it prevents momentum from consuming strategy. Stop performing certainty There comes a point when the leader must stop trying to prove le gitimac y through endle s s explanations.
Their work is indispensable. It is not the same as deciding what the organisation should protect first, which trade-off it can accept or what course remains aligned with its purpose.
You are there because you built, carried, repaired or transformed something. Your authority should remain challengeable, but your right to exercise judgement does not disappear because a model is newer, an analyst is louder or the room is tired.
Then decide: GO. GO IF. HOLD. NO-GO.
“No explain, no complain” does not mean refusing accountability.
Each answer is legitimate when it follows a disciplined examination. “GO IF” is not indecision; it makes the conditions of consent explicit. “HOLD” is not fear; it protects the quality of an irreversible choice.
It means ending the performance of defensive justification once the evidence has been examined, the relevant voices heard and the decision made. State the direction. Record the conditions. Accept responsibility. Move.
Leadership you are still...
And when you genuinely doubt yourself, repeat the sequence: breathe, create time, step back, observe, break down, analyse and decide. Courage is not the absence of doubt. It is the refusal to let doubt transfer command to noise. Sometimes you will be the only person who can see land through the storm. Not because others are less intelligent , but because the compass has been forming in you for years. What I bring into the room My role is not to replace the cyber specialist, the engineer, the lawyer or the data analyst. It is to remove the sensation of chaos they can collectively create when every perspective arrives at once.
I work with the leader personally: restoring orientation, separating signal from pressure, identifying the real decision and converting strategic uncertainty into an executable position. The work is not vague reassurance. It is a private decision architecture built around the person who must finally say yes, no, not yet, or only under defined conditions. The objective is not to make the leader dependent on another adviser. It is to reactivate the leader’s own capacity, organise the expertise already present and expose the points where fear, habit or fragmented information have blocked action. Once the command room is clear, the decision should become simpler, conditions visible and execution measurable rather than postponed by noise.
47
The space here allows only an introduction. But if these words have reached the part of you that nobody sees — the person behind the title, the experience and the obligation to remain steady — then the essential conversation has begun. You may be surprised by how many levers remain beneath your feet: dormant authority, unused knowledge, overlooked relationships, recoverable time and decisions that have never been framed correctly. You have not lost your value. You may simply need to clear the room, recover your compass and remember that you are still the capital.
50
Legal privilege should be part of every cyber incident response plan By Nick Warrillow, Partner, and Rebecca Roberts, Director, at Burness Paull
When a cyber incident occurs, organisations understandably focus on containment: restoring systems, investigating what happened and meeting reporting deadlines. But another issue needs attention from the outset: legal privilege. Legal privilege is not about hiding information. It creates a protected space in which an organisation can speak candidly with its solicitors, assess a fast-moving crisis, and obtain legal advice without those communications automatically becoming available to regulators, claimants or courts later. That protection can be critical. A cyber attack often generates a rush of emails, messages, meeting notes and technical reports as teams try to understand the scale of the incident. Months-or even yearslater, those records may be sought during a regulatory investigation or compensation claim. Unless they are protected by privilege, they may have to be disclosed. Why timing matters Privilege should not be treated as an afterthought once an incident has been contained. Cyber News Global
The documents created in the first hours and days of a breach can become important evidence later. Organisations should therefore involve their in-house legal team or external solicitors as early as possible. Early legal involvement helps ensure that communications and investigations are structured appropriately, while also allowing the organisation to understand its obligations to regulators, affected individuals and other stakeholders.
Litigation privilege can protect documents created for the dominant purpose of dealing with actual or anticipated litigation or regulatory action. These need not be prepared by a solicitor. This requires more than a hypothetical possibility of a dispute or investigation: it must be genuinely in prospect.
When is information privileged? While there are some differences between Scots law and English law, the general position is: Legal advice privilege protects confidential communications between a solicitor and client made for the purpose of seeking or giving legal advice. In a cyber incident, this may include discussions about legal liability, notification duties, communications with affected people and the organisation’s response strategy. Nick Warrillow, Partner, at Burness Paull
Legal privilege should... 51
In the immediate aftermath of many cyber incidents, legal advice privilege is the more likely head of privilege to apply. It can cover the exchanges needed for an organisation to obtain legal advice while it works through a developing situation. Litigation privilege might attach to documents created later, if regulatory action or litigation becomes a likely prospect. Simply marking a document “legally privileged”, or copying a solicitor into an email, does not create privilege in the document in and of itself. The purpose and content of the communication remain central to whether or not it is protected by privilege. Forensic reports need careful handling External forensic investigations are often essential after a significant attack. They can help establish how an incident occurred, whether it is ongoing, what data may have been affected and whether any security gaps contributed to the breach. However, a forensic report may contain sensitive findings, and its conclusions can evolve as the facts become clearer. Ideally, any such report should be instructed by solicitors for the purpose of providing legal advice.
This means that privilege may attach to it, or the communications around it. Avoid accidental waiver Privilege can be lost-or waived-if protected material is circulated or discussed too widely. Organisations should establish a small, clearly defined incident response group responsible for managing legal communications. K e y s tra t e g i c d i s c u s s i o n s , particularly those concerning liability, legal duties and response decisions, should involve legal advisers. Documents that are genuinely privileged should be clearly labelled “Legally Privileged and Confidential” and shared only with those who need access. Teams should also be cautious about summarising or paraphrasing legal advice in wider emails, board papers or external communications, as this can risk waiving protection. A practical priority for boards Cyber resilience is often discussed in technical terms, but effective incident response also depends on governance and legal preparedness.
Rebecca Roberts at Burness Paull Boards should ensure that their incident response plans identify who will contact legal advisers, how communications will be controlled and how external experts will be instructed. The central point is simple: legal privilege gives organisations the space to address a cyber crisis openly and directly. In the pressure of an attack, people need to be able to identify problems, test options and seek advice without fearing that every preliminary comment may later be taken out of context. Bringing legal advisers in early helps preserve that space and can make a material, strategic difference if regulatory scrutiny or claims follow. Key Contacts Nick Warrillow Partner – Dispute Resolution +44 (0)131 473 6115 +44 (0)7553 892 825 nick.warrillow@burnesspaull.com Rebecca Roberts Director – Dispute Resolution +44 (0)131 473 6093 +44 (0)7435 806 417 rebecca.roberts@burnesspaull.com
To listen to Rebecca Roberts interview with Lets Talk Cyber: SCAN HERE
IMMERSIVE TRAINING
Our one-hour investigative game offers immersive data protection and cybersecurity training for corporate events up to 60 people. Using clues and strategy, teams solve puzzles and riddles to complete a mission. With our all-inclusive ‘Training Suitcase,’ you can set up in your own office and create an engaging escape room environment.
Can your team solve the cyber puzzles and escape?
CYBER SECURITY
ESCAPE ROOM HIGHLY EFFECTIVE CYBER SECURITY & DATA PROTECTION TRAINING - MADE FUN & MEMORABLE
contact: training@ospcyberacademy.com
54
SCOTLAND’S AI STRATEGY 2026 - 2031
A Leadership Guide for Adopting Scotland’s National AI Strategy This executive summary details Scotland’s AI Strategy 2026-2031 into the essential considerations that leaders across business, public services and academia must understand and act upon. Scotland’s ambition is clear: to harness the potential of AI to drive responsible and inclusive growth across our economy and make a positive difference at every level of society. Why Leaders Must Act Now Scotland has helped to shape the modern world. For a small country on the edge of Europe, we have long been at the centre of innovation and new inventions. Cyber News Global
We have a proud history of leading scientific and technological change and our ideas, nurtured to enlightenment by our leading universities and colleges, have revolutionised whole schools of thought leading to breakthroughs in fields as diverse as philosophy, photography and physics. Now, Artificial Intelligence (or AI) presents an opportunity for Scotland to rekindle that pioneering spirit, to lead instead of follow and, by doing so, to harness AI’s potential for responsible, transformative economic growth. “
AI is the great disruptor, re-shaping industries through the power of machine learning – but, as Scots, we have always been comfortable on frontiers.” Secure the benefits of AI for everyone in Scotland. That means boosting our economy, closing the productivity gap and driving innovation while also supporting improvement to our health and education outcomes and increasing the efficiency and quality of our public services.
Scotland’s Ai Strategy...
At the same time, we must recognise the wider risks and uncertainties that come with the rapid evolution of AI. People are rightly concerned about transparency, fairness, the impact on jobs and the accelerating pace of change. Scotland’s response is to address these issues openly and responsibly, demonstrating that progress and safeguards can go hand in hand. Above all, our approach to AI must be firmly rooted in our values and guided by the Scottish Government’s commitment to Fair Work. Scotland’s Unique AI Strengths: What Leaders Must Leverage Leaders adopting this strategy must understand the exceptional foundations Scotland already possesses. These are not aspirational for they are live, competitive assets that underpin the entire strategy.
55
World-Leading AI Pioneers
World-Leading AI Research
Scotland’s long association with visionary leaders in AI from Geoffrey Hinton (Nobel Prize, 2024) to Amanda Askell (co-author of GPT3) demonstrates the strength of our academic and research institutions and their ability to attract the finest minds.
Five Scottish universities were placed in the UK’s top 30 for AI research output in 2025. Edinburgh hosts ARCHER2, the UK’s national supercomputer, and will host the new £750 million UK National Supercomputing Centre. The National Robotarium at Heriot-Watt is driving breakthroughs in medical and offshore robotics.
56
Renewable Energy Advantage In 2024 alone, Scotland produced 38.4 TWh of renewable electricity the highest annual total ever recorded, a 13.2% increase on the year before. There is 26.4 GW of new renewable capacity in planning or consented pipelines, one of the largest in Europe relative to population. Business Investment
Leadership
&
Scotland is home to an estimated 296 AI-focused companies. The first AI Growth Zone in North Lanarkshire is backed by over £8 billion of private investment and is set to deliver more than 3,400 new jobs. A £15 billion AI Pathfinder Investment in North Ayrshire will create one of Europe’s most significant AI infrastructure developments. The Strategic Imperative: Why Leaders Cannot Wait. Artificial intelligence is advancing rapidly and offers enormous economic potential. Leaders must internalise the urgency of this moment. Economic Opportunity Rapid developments in agentic and autonomous AI show how quickly new capabilities are emerging. Adoption remains uneven and Scotland must act to close the gap.
Cyber News Global
Scotland’s Ai Strategy... 57
Public Services Pressure Demand for public services is rising amid tightening public finances. AI has already shown promise in enabling preventative approaches, improving planning, reducing costs and supporting frontline decision-making. Data Governance Scotland’s public sector data is often fragmented and difficult to access. Improving data sharing and governance is essential to support safer, more effective services and research.
Global Competition A worldwide innovation race is underway. Emerging international standards including the OECD AI principles and the EU AI Act are shaping expectations of fairness, transparency and safety. Scotland must act now to ensure that AI is introduced in ways that are safe, fair and focused on public benefit. This Strategy sets out how Scotland will do this, harnessing the potential of responsible AI to improve outcomes across our economy and at every level in our society.
The Four Outcomes Leaders Must Deliver By 2031 The Scottish Government has defined a clear and ambitious purpose for this Strategy: to harness the potential of AI to drive responsible and inclusive growth across our economy and make a positive difference at every level of society. Leaders must orient their organisations around four outcome areas.
59
60
THREAT INTELLIGENCE: THE MISSING HALF OF AI GOVERNANCE By Sana Mobeen
AI governance has become one of the most talked-about topics in the industry, and for good reason. Yet across most frameworks, conversations about it tend to circle the same three themes: ethics, compliance, and model risk. These questions matter. Is the model biased? Is it explainable? Are we meeting our regulatory obligations? No serious governance programme can ignore them. But after nearly a decade in cyber security, much of it leading threat intelligence (CTI) for financial institutions, I keep returning to the same observation: there is a seat missing at the AI governance table. That seat belongs to threat intelligence, and its absence leaves organisations with only half the picture. The Questions Governance Forgets to Ask Ethics, compliance, and model risk all look inward. They ask whether an organisation is behaving responsibly and lawfully. Threat intelligence asks a different set of questions, ones that look outward, from the perspective of an adversary:
Cyber News Global
What does this AI system look like Compliance-Led vs. versus through the eyes of an attacker? Threat-Led Thinking Who would want to target it? What would they want from it? A compliance-led approach to How might the y attack or AI risk typically asks: was this model appropriately tested? Can manipulate it? What would the business impact be we explain its decisions? Are we if they succeeded? handling data correctly? Do we have appropriate oversight and These are exactly the questions documentation? A threat-led threat intelligence already answers approach does not replace these elsewhere in cyber security. Many questions. It adds another layer organisations with a mature CTI on top of them: who would benefit function are answering them today, from manipulating the system? How but that intelligence rarely reaches might they attempt to influence its the governance table. behaviour? Could someone poison its inputs, compromise a system it Security teams are looking atlook depends on, or abuse the access it at controls, vulnerabilities, and has been given? exposure, but what. What threat intelligence adds on top of that Consider an organisation that is current, organisation-specific introduces an AI agent with access adversarial context: who is actually to sensitive data. Governance will targeting organisations like yours, establish what the agent is allowed and what capabilities are they to access and what controls usingthey are using. should exist around it. The threatled question goes further: what Existing AI governance happens if somebody manipulates frameworks provide structure the agent, or compromises the around accountability, risk, and identity behind it? At that point, the security. Threat intelligence risk is no longer that the AI gives is what makes that structure a wrong answer. The questions meaningful. become: what can that agent actually do?
Threat Intelligence... 61
Can it retrieve sensitive information? Can it interact with another system? Can it initiate an action? This is what I mean by “blast radius”: the scope of what can go wrong if an AI agent is compromised or manipulated. As AI moves from simply answering questions to taking actions on an organisation’s behalf, blast radius becomes a critical concept, and the level of scrutiny applied should be proportionate to it. A low-risk productivity tool is a fundamentally different proposition from an AI agent with access to sensitive data or the ability to act across business systems. Once an organisation starts asking these questions, its view of AI systems changes. An AI system stops being something that simply passes an assessment before deployment and becomes a living part of the organisation’s attack surface. Like any other part of that attack surface, it needs an owner, it needs a threat model, and where the risk warrants it, it needs ongoing monitoring. Where to Start: Visibility and Ownership For organisations only beginning to think about bringing threat intelligence into AI governance, the easiest place to start is visibility.
You cannot govern or defend something you do not know exists. In many organisations, there is a gap between the AI systems that have been formally approved and what people are using day to day. This is the AI equivalent of the “shadow IT” problem many security teams spent years fighting: shadow AI. Someone may be using an AI plugin. Another team may have built something on a model API that governance has never heard of. The practical first step is to build an AI register: a simple inventory of the AI systems in use across the organisation. It costs little beyond time and effort, and it does not need to wait for a bigger governance programme to get underway. The second step is ownership. Governance can coordinate the overall approach, but every individual AI system should have someone accountable for it. That ownership is what allows threat intelligence to be matched against the asset inventory: which of these assets are relevant to the threats we are observing? Who would target them? What techniques are relevant? What would the business impact be if they were compromised?
This is what turns threat intelligence from a report sitting unread in someone’s inbox into something that actively shapes governance decisions. Without that visibility, an organisation is trying to threat model an environment it cannot see. The Bottom Line Ethics, compliance, and model risk will always be central to AI governance, and they should be. But they answer only half the question of whether an AI system is safe to deploy and operate. The other half comes from asking how an adversary would view that system, what they would want from it, and what the consequences would be if they succeeded. Building an AI register, assigning clear ownership, and feeding threat intelligence into governance decisions are practical, low-cost steps that any organisation can take today. Until threat intelligence has a permanent seat at the governance table, AI governance will remain, at best, half the story. About the author
Sana Mobeen is an independent cyber threat intelligence adviser based in Edinburgh. Her Ethics, background spans compliance, telecommunications and model risk will and banking, latterly always be central leading cyber to AI governance, threat intelligence and they in financial services. should be. She writes and speaks on where CTI meets AI governance. LinkedIn: linkedin.com/in/sananaeem-mobeen-554346a
SCAN HERE
To listen to Sana Mobeen interview with Lets Talk Cyber:
62
When a Major Cyber Attack Hits, How Do We Communicate?
James Mullins VP, EMEA and APAC Sales at Mattermost
As defenders work to contain the breach, they often disconnect systems themselves to prevent further compromise. Cyber resilience is often measured by how quickly an organisation can recover its systems. But when a major cyber attack strikes, recovery starts much earlier than restoration. It starts with communication. Today ’s attackers understand that encrypting data is only part of the objective. Increasingly, they aim to disrupt an organisation’s ability to coordinate its response. Directory services are targeted. Collaboration platforms are disabled. Networks are isolated to contain the attack. Within minutes, organisations can find themselves unable to answer the most basic operational question: How do we communicate? “If your main company network goes dark, your out-of-band communications should keep you in the light.” This communications blackout is rarely accidental. It is a deliberate part of modern attack strategy.
Cyber News Global
The result is an operational environment where security teams, executives, legal counsel, communications teams and external partners are all trying to manage a rapidly evolving crisis without a trusted means of sharing information. The Fog of Cyber War Military leaders have long understood the concept of the “fog of war” – the uncertainty that exists when reliable information is unavailable. The same principle increasingly applies during a major cyber incident. Under normal c ircumstanc e s , leadership teams receive structured updates, assess the facts and make informed decisions. During a cyber attack, those information flows can disappear entirely. Without trusted communications, leaders struggle to establish what has happened, what systems remain operational, who is affected, or what actions should be prioritised.
The result is often one of two dangerous outcomes: rushed decisions based on incomplete information, or decision paralysis while waiting for certainty that may never come. Both work in the attacker’s favour.
When a Major Cyber Attack... 63
Frameworks such as NIS2 expect organisations to notify regulators of significant incidents within strict reporting windows, often between 24 and 72 hours. Those obligations do not disappear because internal email, collaboration tools or corporate networks are unavailable. Organisations must still establish the facts, coordinate response teams, document decisions and communicate with regulators, customers and partners. Without a secure communications capability, meeting those obligations becomes significantly more difficult. The Consumer Messaging Trap
Why Out-of-Band Communications Matter This is why many organisations are now incorporating dedicated out-ofband communications into their cyber resilience strategies. An out-of-band capability operates independently of the primary corporate network. It is pre-configured, secure and available when core business systems have been taken offline or intentionally isolated. Rather than scrambling to establish communications during a crisis, organisations can immediately coordinate incident response, share verified information, assign tasks and maintain executive oversight using a trusted platform that remains operational throughout the incident. The objective is simple: ensure that the organisation can continue to make informed decisions when its primary communications infrastructure cannot. Compliance Doesn’t Pause During an Attack Maintaining communications is not simply an operational necessity. It is increasingly a regulatory requirement.
Preparing Before the Crisis Effective cyber resilience is about more than preventing attacks. It is about ensuring the organisation can continue to operate when prevention fails. Planning for secure communications before an incident occurs allows organisations to coordinate response efforts, support leadership decisionmaking, satisfy regulatory obligations and reduce the operational disruption caused by an attack. In an environment where cyber incidents are increasingly viewed as a matter of when rather than if, the organisations that recover fastest will not necessarily be those with the strongest perimeter defences.
One of the most common mistakes organisations make during a cyber They will be the organisations that can incident is turning to consumer still communicate when everything messaging applications as else has gone quiet. Sensitive an emergency alternative. corporate If you are reviewing your information While these platforms organis ation’s c y b er may be shared may restore basic resilience or out-of-band through unmanaged communication, they communications strategy, environments. Audit can also introduce new visit mattermost.com trails may be risks. to learn more or reach out to incomplete. our team. Chain of custody can be lost. Regulatory obligations surrounding governance, record keeping and evidential integrity become much harder to demonstrate. In attempting to solve one problem, organisations may inadvertently create another. ”The regulator doesn’t care if your email is down. They still expect you to report, communicate securely and remain compliant.”
To listen to James Mullins interview with Lets Talk Cyber:
Scan Me
INDUSTRIAL CYBER SECURITY
GRC
LOOP
SHIELD
UNITY
PROTECTING CRITICAL NATIONAL INFRASTRUCTURE ISO 9001
ISO 14001
ISO 27001
ISO 45001