Helen Molyneux

Fire extinguisher behind break glass panel in an office corridor — the emergency plan nobody reaches for

Your Business Continuity Plan Exists. So Why Did Nobody Use It?

In my experience, organisations that come to me for consultancy often share a similar story. They had a business continuity plan in place, sometimes one they had developed internally, sometimes one built by a previous consultant. Something went wrong, and nobody invoked it. Not because the disruption was trivial, but because nobody felt confident enough […]

Your Business Continuity Plan Exists. So Why Did Nobody Use It? Read More »

A gloved hand on a computer mouse next to a keyboard, with a patient record displayed on a hospital computer screen in the background

The NHS doesn’t have a data security problem. It has a culture problem.

The NHS doesn’t have a data security problem. It has a culture problem. This week, Cambridge University Hospitals referred itself to the Information Commissioner’s Office after it emerged that around 40 members of staff had accessed the medical records of a three-year-old boy injured in a crocodile attack. The child was treated at Addenbrooke’s following

The NHS doesn’t have a data security problem. It has a culture problem. Read More »

Aerial view of a stone architectural maze with a clear navy blue path marked through it, representing navigation through complex ISO standards

ISO Spaghetti: Why the Standards Landscape Is Confusing (and What to Do About It)

The five standards worth knowing about ISO Spaghetti: Why the Standards Landscape Is Confusing (and What to Do About It) I have lost count of the number of tender documents I have reviewed that specify ISO 22301 and ISO 27001 and ISO 31000, sometimes with ISO 22361 thrown in for good measure. Occasionally all four

ISO Spaghetti: Why the Standards Landscape Is Confusing (and What to Do About It) Read More »

Aerial view of a port at dusk with a network of connected transport and logistics icons overlaid, illustrating supply chain interdependency.

The cyber law your organisation probably doesn’t need to worry about — and why that might be exactly the problem

The cyber law your organisation probably doesn’t need to worry about — and why that might be exactly the problem The Cyber Security and Resilience Bill passed its third reading in the House of Commons on 16 June and arrived in the Lords the following day. If you’ve seen coverage of it, you could be

The cyber law your organisation probably doesn’t need to worry about — and why that might be exactly the problem Read More »

Teenager holding a smartphone displaying an age verification prompt — illustrating the data protection challenges of the UK social media ban for under-16s

Banning Social Media for Under-16s: The Data Protection Question Nobody’s Answering

Banning Social Media for Under-16s: The Data Protection Question Nobody’s Answering So it’s official. This morning, the Prime Minister stood in Downing Street and announced a full ban on social media for children under 16. TikTok, Instagram, Snapchat, X, YouTube, Reddit — the lot. Legislation before Christmas, enforcement potentially from Spring 2027. As a parent

Banning Social Media for Under-16s: The Data Protection Question Nobody’s Answering Read More »

A framed certificate hanging on an office wall, slightly out of focus, with a laptop screen showing a security alert in the foreground

Does Your ISO 27001 Certificate Mean You’re Secure?

Does Your ISO 27001 Certificate Mean You’re Secure? After I published my recent piece on the GCHQ Director’s Bletchley Park lecture, a fellow practitioner left a comment that I’ve been turning over in my head ever since. It’s a question about ISO 27001 certification and what it really proves about security that deserves more than

Does Your ISO 27001 Certificate Mean You’re Secure? Read More »

Graphic quoting GCHQ Director Anne Keast-Butler's 2026 Annual Lecture at Bletchley Park: "From boardrooms to living rooms" — Cambridge Risk Solutions commentary

“From Boardrooms to Living Rooms”: What the GCHQ Director’s Bletchley Speech Really Said

“From Boardrooms to Living Rooms”: What the GCHQ Director’s Bletchley Speech Really Said It’s rare for the Director of GCHQ to speak in public. Anne Keast-Butler said as much herself this morning, standing at Bletchley Park to deliver the first annual GCHQ lecture. The fact that she felt compelled to do so tells you something

“From Boardrooms to Living Rooms”: What the GCHQ Director’s Bletchley Speech Really Said Read More »

Empty distribution warehouse with idle conveyor belt and lone worker facing a blank screen — illustrating the operational impact of a cyber incident

M&S just told us exactly what a cyber incident costs. Are you ready for yours?

M&S just told us exactly what a cyber incident cost a UK business. Are you ready for yours? Yesterday, Marks & Spencer published its full-year results. Profits down 23.8%. Fashion and home revenue down 7.7%. £131 million in direct costs attributed to a single cyber incident. And all of it traceable back to a third-party

M&S just told us exactly what a cyber incident costs. Are you ready for yours? Read More »

ISO 14001 environmental management standard — relevance for digital and tech businesses

ISO 14001: The Standard That Doesn’t Know What a Modern Business Looks Like

ISO 14001: The Standard That Doesn’t Know What a Modern Business Looks Like I recently completed training to deliver ISO 14001:2026 — the international standard for environmental management systems. I want to be upfront about why I did it, and equally upfront about why it’s not a space I intend to make a feature of

ISO 14001: The Standard That Doesn’t Know What a Modern Business Looks Like Read More »