On 8 April 2025, Teiss Talk host Jonathan Craven was joined by Heather Lowrie, Independent Advisor, Earthgard Ltd; Raza Sadiq, Head of Enterprise Risk, MQube; Sandra Bell, Group Head of Organisational Resilience, Novuna; andGrant Caley, UK & Ireland Solutions Director, NetApp.
In September 2024, the UK Government announced the Cyber Security and Resilience Bill to address the challenges that cyber-attacks present, particularly for critical infrastructure. It is designed to protect essential digital services, update critical infrastructure and security frameworks, and make supply chains and energy services more secure. While markets are buoyant, there is less concern about these issues but once the economy is struggling and there is stress concentration, regulation becomes more relevant.
Although the current regulation has a critical infrastructure focus, it will drive wider social action. Regulation has also become more pertinent in the past couple of years due to a changing geopolitical situation. Labelling cloud infrastructure as critical is expected to put cloud services at the crosshairs of cyber criminals.
This legislation is happening in the UK as NIS2 is being implemented in the EU – an iteration of NIST, which hasn’t been effective in terms of imposing fines on noncompliant companies. The merit of NIS2 is that it starts to bring commonality of reporting and standards.
The last line of defence is a combination of a couple of factors. For example, if the company can detect attacks at speed, it will take less time to recover from cyber incidents. Technology is only one component of the strategy – there are the people, the SLAs the business requires and so on. The business sector, however, is still lacking a holistic set of guidelines and strategy. But each attack should strengthen the business’s resilience through the lessons learnt from previous vulnerabilities that criminals took advantage of. Suppliers must also constitute a part of a company’s cyber defences through more stringent due diligence procedures and honest and transparent communication. Substitutability is an important aspect here to consider, as the price of substituting one firm for another must be weighed against the benefits it brings.
However, GDPR was laying the groundwork for holding companies responsible for their supply chains, as it required companies to prove not just their own compliance but that of their suppliers as well. The increasing number of cyber attacks then further raised awareness of backdoors though suppliers. Some sectors, such as financial services are more ahead of the curve than others in managing supplier risk, though.
The next area for resilience is around AI deployments, particularly how data that AI models are fuelled by is managed. Impact analysis – or assessing which parts of the business you want to keep going when an incident happens – is an old methodology that remains relevant to resilience even today. The Cyber Assessment Framework aims to avoid becoming a tick the box exercise and encourages a much wider conversation within the board, while also telling security experts what good should look like. It is also principle-based and doesn’t try to be prescriptive. For it to work, the business must have a security strategy and a clear view of how that strategy supports the business.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543