Risk and Resilience Blog

Welcome to the Cambridge Risk Solutions risk and resilience blog — practical insights on business continuity, crisis management, information security and more, written by people who work in the field every day.
Eroding coastline path — disruption is a gradual slope, not a cliff edge

The Problem with MTPD

The Problem with MTPD. There is a number buried in every business impact analysis that drives more planning decisions than almost anything else: the Maximum ...
Read More →
A framed certificate hanging on an office wall, slightly out of focus, with a laptop screen showing a security alert in the foreground

Does Your ISO 27001 Certificate Mean You’re Secure?

Does Your ISO 27001 Certificate Mean You’re Secure? After I published my recent piece on the GCHQ Director’s Bletchley Park lecture, a fellow practitioner left ...
Read More →
Graphic quoting GCHQ Director Anne Keast-Butler's 2026 Annual Lecture at Bletchley Park: "From boardrooms to living rooms" — Cambridge Risk Solutions commentary

From Boardrooms to Living Rooms”: What the GCHQ Director’s Bletchley Speech Really Said

From Boardrooms to Living Rooms”: What the GCHQ Director’s Bletchley Speech Really Said It’s rare for the Director of GCHQ to speak in public. Anne ...
Read More →
Empty distribution warehouse with idle conveyor belt and lone worker facing a blank screen — illustrating the operational impact of a cyber incident

M&S just told us exactly what a cyber incident costs. Are you ready for yours?

M&S just told us exactly what a cyber incident cost a UK business. Are you ready for yours? Yesterday, Marks & Spencer published its full-year ...
Read More →
ISO 14001 environmental management standard — relevance for digital and tech businesses

ISO 14001: The Standard That Doesn’t Know What a Modern Business Looks Like

ISO 14001: The Standard That Doesn’t Know What a Modern Business Looks Like I recently completed training to deliver ISO 14001:2026 — the international standard ...
Read More →
A blurred figure walks past rows of colour-coded medical records files in a hospital records room

48 staff. No dismissals. No ICO investigation. The Southport records breach tells us everything we need to know about insider threat.

48 staff. No dismissals. No ICO investigation. The Southport records breach tells us everything we need to know about insider threat. When the news broke ...
Read More →

Get In Touch

Whether you're starting your Business Continuity journey or looking to enhance your existing risk framework, we're here to help. Get in touch today for a no-obligation conversation with our expert team.