Business Leaders Cyber Briefing

By: Cool Waters Cyber
  • Summary

  • A short summary of the latest cyber security news and trends, from the perspective of business leaders and owners. Hosts Trish and Tom provide plain English explanations along with practical advice to keep your business safe and secure from cyber crime and disruption.


    For cyber security help and advice, speak to Cool Waters Cyber: www.cool-waters.co.uk

    © 2025 Cool Waters Consulting Ltd
    Show More Show Less
activate_mytile_page_redirect_t1
Episodes
  • How to fast-track the UK Cyber Governance Code of Practice using IASME Cyber Assurance
    May 8 2025

    Implementing the UK Cyber Governance Code of Practice with IASME Cyber Assurance

    In this episode, we discuss the crucial topic of cyber governance for business leaders. With 74% of large businesses and 70% of medium businesses in the UK experiencing a cyber breach in the past year, boards are now clearly expected to lead on cyber risk. In response, the UK government (via DSIT and NCSC) has introduced the voluntary Cyber Governance Code of Practice to guide boards and directors.

    The Code distils five key principles for effective cyber governance: Risk Management, Strategy, People, Incident Planning & Response, and Assurance & Oversight. However, implementing these practices can be a challenge.

    Our deep dive focuses on a pragmatic roadmap to implement the Code: the IASME Cyber Assurance standard. Formerly known as "IASME Governance", this government-backed standard is comprehensive yet accessible, developed with UK government support as an alternative to more complex standards like ISO/IEC 27001.

    Using IASME Cyber Assurance to implement the Code offers several benefits:

    Integrated Approach: It delivers both the Cyber Governance Code's requirements and the technical controls of Cyber Essentials in one unified effort, avoiding duplicate work.

    Structured Guidance: IASME provides detailed guidance, templates, and a structured question set to lead you through implementing controls, so you don't have to "reinvent the wheel".

    Comprehensive Coverage: The standard covers technical controls, risk management, data protection (like GDPR), and regulatory compliance.

    External Assurance: It culminates in an independent certification, providing tangible proof to stakeholders that your cyber governance meets a national standard.

    Learn how following a structured roadmap using IASME can help organisations achieve significant cyber maturity relatively quickly, often within ~3–6 months to certification.

    Implementing these steps can be challenging, which is why partnering with an NCSC-accredited Cyber Advisor can be invaluable. Advisors, like our sponsor Cool Waters Cyber, provide expert gap analysis, hands-on remediation support, plain-English communication, project management, and certification liaison. They offer a clear, pragmatic roadmap and help streamline the process, ensuring you meet the standards effectively.

    Cool Waters Cyber offers a comprehensive service to help boards implement the Cyber Governance Code of Practice. They provide tailored support backed by real-world experience and plain-English advice.

    Ready to strengthen your cyber governance? Cool Waters Cyber can help your firm implement the new code.

    Need help with Cyber Security?

    Speak to Cool Waters Cyber - NCSC assured Cyber Advisors and Cyber Essentials experts - www.cool-waters.co.uk

    Show More Show Less
    20 mins
  • Unpacking the UK Cyber Governance Code of Practice
    Apr 28 2025

    Tune into this episode for a deep dive into the UK government's Cyber Governance Code of Practice. This Code is a crucial resource designed specifically for boards and directors. Understanding it can significantly benefit your organisation.

    By listening, you will gain insights into:

    Why cyber governance is essential for modern businesses and organisations. Digital technologies are deeply embedded in most businesses, and critical operations often rely on them. Cyber risk is a material risk for almost all organisations.

    The critical role of boards and directors in managing digital risks and protecting their organisations from cyber attacks. Governing cyber risk requires strong engagement and action at a leadership level.

    How the Code helps protect your organisation's financial viability. Effective management of cyber risks is crucial, and building cyber resilience is key to recovering from harm caused by cyber events.

    What the Cyber Governance Code of Practice is and how it sets out the most critical governance actions that directors are responsible for. It shows how boards and directors can build resilience to a wide range of cyber risks.

    Who should use the Code: It's tailor-made for boards and directors of both public-sector and private organisations, especially medium and large ones. While not specifically for small organisations, they play a critical role in UK economic resilience and should seek to implement the Code's principles.

    How the Code helps manage cyber risks effectively and reduce the likelihood and impact of cyber attacks. Cyber incidents can lead to major impacts like loss of income, damage to customer trust, or costly remedial action.

    How the Code fits into a wider government support package. It is underpinned by resources such as Cyber Governance Training and the Cyber Security Toolkit for Boards, which help strengthen understanding and support implementation.

    The key areas covered by the Code, including Risk Management, Strategy, People, Incident Planning, Response and Recovery, and Assurance and Oversight, detailing specific actions for each area.

    Understanding the minimum standards for managing cyber risk, especially when the Code is used alongside Cyber Essentials, a government-backed certification scheme.

    Understanding the principles and actions outlined in the Code of Practice is crucial for effective governance and protecting your organisation in today's digital landscape

    Need help with Cyber Security?

    Speak to Cool Waters Cyber - NCSC assured Cyber Advisors and Cyber Essentials experts - www.cool-waters.co.uk

    Show More Show Less
    13 mins
  • The Quantum Revolution and the death of encryption
    Apr 1 2025

    Is your organisation ready for the quantum revolution? This episode delves into the looming threat of quantum computing to current cybersecurity, explaining how powerful quantum computers could break widely used encryption like RSA and ECC, potentially by the early to mid-2030s. Understand the "harvest now, decrypt later" attacks that could expose your sensitive data in the future.

    This episode highlights the critical risks to UK businesses, especially in finance and the public sector, including the potential collapse of secure transactions, compromised citizen data, and threats to critical infrastructure. Learn about the UK's National Cyber Security Centre (NCSC) guidance and their 2035 deadline for migrating to quantum-resistant cryptography.

    Discover the essential steps business leaders need to take now to prepare for a post-quantum world, including raising executive awareness, assessing cryptographic usage, adopting crypto-agility, and planning for the transition to Post-Quantum Cryptography (PQC) standards recommended by NIST and the NCSC. For financial institutions, the episode also touches upon PCI-DSS compliance implications. Don't wait until it's too late – future-proof your organisation by understanding and acting on the quantum threat today..

    Need help with Cyber Security?

    Speak to Cool Waters Cyber - NCSC assured Cyber Advisors and Cyber Essentials experts - www.cool-waters.co.uk

    Show More Show Less
    15 mins

What listeners say about Business Leaders Cyber Briefing

Average Customer Ratings

Reviews - Please select the tabs below to change the source of reviews.

In the spirit of reconciliation, Audible acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.