Explainer
Clear, accessible articles that explain cyber security concepts, technologies and services, helping organisations build understanding and make informed security decisions.
-

What Are the Cyber Essentials Requirements?
Read more: What Are the Cyber Essentials Requirements?EXPLAINER What Are the Cyber Essentials Requirements? READ Cyber Essentials requires an organisation to define its assessment scope and meet five technical controls across the devices, software, networks and cloud services within it. The controls cover firewalls, secure configuration, security update management, user access control and malware protection. The scheme is the UK Government’s recommended…
-

ISO 27001 Requirements and How to Meet Them
Read more: ISO 27001 Requirements and How to Meet ThemEXPLAINER ISO 27001 Requirements and How to Meet Them READ ISO/IEC 27001 requires an organisation to establish, operate, review and continually improve an information security management system. The standard does not prescribe one fixed set of technologies. It requires a risk-based system that can show how information security decisions are made, implemented and checked. That…
-

What is IMPEX?
Read more: What is IMPEX?EXPLAINER What is IMPEX? READ Organisations working across defence, government and other high-assurance environments often need to move information between systems that have been deliberately separated. One network may be internet-connected, another may be isolated, and a third may operate under different security rules or at a different classification. The separation protects the more sensitive…
-

Why ISO certifications matter in cyber security
Read more: Why ISO certifications matter in cyber securityISO standards provide internationally recognised frameworks that help organisations manage important aspects of their operations in a consistent, repeatable and continually improving way.
-

Communicating via the RLI
Read more: Communicating via the RLIThe Restricted LAN Interconnect (RLI) is a connectivity capability used to enable authorised organisations to communicate and exchange information with the UK Ministry of Defence (MOD) as part of specific programmes and contracts.
-

What is endpoint management in secure collaboration?
Read more: What is endpoint management in secure collaboration?Endpoint management is the process of centrally configuring, securing, monitoring and maintaining the laptops, desktops and mobile devices that users rely on to access organisational systems and information.
-

What is secure collaboration?
Read more: What is secure collaboration?Secure collaboration is the combination of people, processes and technology that enables organisations to share information, communicate and work together while maintaining appropriate security controls.
-

SOC in cyber security explained
Read more: SOC in cyber security explainedA SOC, or Security Operations Centre, is the team, process and technology used to monitor an organisation for cyber security events, detect suspicious activity, analyse alerts and coordinate response to incidents.
-

How does SIEM help in detecting security threats?
Read more: How does SIEM help in detecting security threats?SIEM helps detect security threats by collecting security data from systems, applications, networks, cloud services and security tools, then presenting it as actionable information through a central interface.
-

The biggest threat to cyber security
Read more: The biggest threat to cyber securityThe biggest threat to cyber security depends on the organisation, but ransomware remains one of the most acute and disruptive threats for UK organisations. For many businesses, the deeper issue is poor readiness: weak identity controls, unpatched vulnerabilities, limited visibility, poor recovery planning and unclear incident response.
-

What should I look for when choosing a cyber security consulting firm?
Read more: What should I look for when choosing a cyber security consulting firm?When choosing a cybersecurity consulting firm, look for relevant sector experience, proven technical depth, recognised assurance, clear delivery methods, independent judgement, evidence-led reporting and the ability to explain cyber risk in business terms.

