Steven Furnell, PI and Lead of CyCOS, has passed the baton to CIISec’s Amanda Finch at Infosecurity Europe 2026

In an AI-driven, highly interconnected digital world, no company or individual is immune to cybercrime. The fact that approximately 42 per cent of micro and 46 per cent of small businesses experience a cyber-breach or hack each year, is dispelling the too-small-and- petty-to-be-hacked myth at speed.
As new cyber-incidents make headlines daily, SMEs are becoming increasingly aware of the threat, but are often too cash-strapped or overwhelmed to take action.
The urge to find out what micro-to-medium-sized companies are lacking to turn acknowledgement into action led to a university project in late 2023 with a view to investigating the gaps in available cyber-security guidance.
Steven Furnell – Professor of Cyber Security at the University of Nottingham and Principal Investigator of the CyCOS project – is a returning speaker at Infosecurity Europe, where last year he talked about the new Communities of Support approach that CyCOS designed and trialled to help SMEs engage with cyber-issues in a collaborative setting.
This year, in a panel discussion, he discussed the handover of the CyCOS project to the Chartered Institute of Information Security (CIISec). Furnell, who serves as a Board Director of CIISec, was joined on the panel by that organisation’s CEO, Amanda Finch.
The transition marks a major milestone for CyCOS, as it moves from a university research project into professional management, where CIISec is bringing frameworks, quality standards and standardised training materials to the programme.
Members of the support community will be able to leverage CIISec’s links with UK cyber-security employers and training providers as well.
How can SMEs benefit from a collaborative approach?
CyCOS’s mission is to connect SMEs with relevant cyber-security guidance in a landscape where support comes in fits and starts through sources and platforms that often overlap, while leaving other areas uncovered.
Another challenge is the lack of personalised support and concerns about the commercial bias that can influence recommendations when businesses are choosing security vendors and solutions.
By joining the Communities of Support matching their size – there is one for SMEs and another for microbusinesses – organisations can access a range of resources to fill the gaps in their cyber-security posture.
Members gain access to regular thematic webinars and occasional in-person meetings, plenary sessions offering opportunities for cross-community discussions and live “ask me anything” sessions, where volunteer experts answer questions in real time.
They can also use CyCOS’s support broker online platform for community threads, polls, session recordings and ad hoc Q&A between events.
Currently, five new communities are being added to the original two of the pilot, which will be organised either on a geographical or sectoral basis, or connect larger organisations with their smaller suppliers.
The five volunteer founding SMEs have discretion over the organising principles of their respective communities. However, the selection criteria for each of them include their capability to attract other small businesses into the fold.
Beyond creating a space where more experienced SMEs can guide less mature businesses on how to improve their cyber-resilience, CyCOS also aims to raise awareness of government-backed initiatives designed to help businesses strengthen their cyber-security.
This gap was identified by the UK Government’s Cyber Security Breaches Survey 2025, which found that only 1 per cent of all responding businesses – regardless of size – mentioned the National Cyber Security Centre (NCSC) by name, while awareness of its 10 Steps guidance and that of the Cyber Essentials Certification both stood at just 12 per cent.
More publicity is required for the Cyber Action Toolkit too. Launched in October 2025, this free resource provides practical, tailored guidance from NCSC experts based on a business’s size and specific needs.
So if the will exists in an SME to take cyber-risk seriously, there are several ways to start – whether through self-directed action, participation in peer-led communities or a combination of the two.
While turning to external cyber-experts and consultants can be a burden on the topline, there is also a growing range of free guidance, tools and resources available to help organisations reduce their attack surface.
The emergence of advanced AI systems such as Claude Mythos 5, reportedly capable of autonomously discovering and exploiting software vulnerabilities, has intensified concerns about the scale and speed of future cyber-attacks.
Although access to the technology is currently restricted to vetted partners, the possibility of similar capabilities eventually falling into the wrong hands cannot be dismissed.
At the same time, intensifying supply chain attacks are posing significant risks too. While large organisations may absorb the financial fallout of these hacks, smaller suppliers can face severe disruption and, in some cases, existential consequences.
We are at an inflection point, where neglecting cyber-security is increasingly becoming a material business risk or, for some, even a threat to their survival.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543