Insights in Category: Converged Security

Risks facing financial institution

Risks facing financial institutions

Financial institutions have invested heavily in security, but more tools, policies and reporting do not necessarily mean greater resilience. Katie Barnett and Gavin Wilson look at the risks financial institutions should be paying closest attention to in 2026, from social engineering and physical security to third-party dependencies, insider threats and AI.

Read More »
Security on a reactive budget

Security on a reactive budget

Security budgets often increase after something has gone wrong. Katie Barnett looks at how CISOs can move away from reactive spending by making the case for security in terms the wider business already understands, from resilience and prioritisation to deals, downtime and risk.

Read More »

Is cybersecurity’s primary attack surface people?

Technology alone cannot stop today’s cyber threats. While organisations continue to invest in advanced security tools, attackers increasingly target the people behind them. In this interview, Peter Connolly, CEO of Toro Solutions, explains why human behaviour has become the primary attack surface in modern security, how criminals exploit trust through social engineering and AI-powered attacks, and why building a culture of resilience is critical to protecting organisations. He also explores the convergence of cyber, physical and human security, and the leadership capabilities needed to stay ahead of an evolving threat landscape.

Read More »
Resilience as readiness not reassurance

Resilience as readiness not reassurance

Senior risk, resilience and security leaders gathered at the National Liberal Club to discuss what organisational resilience looks like in practice, covering decision-making under pressure, governance, recovery planning, supply chain vulnerabilities, AI, culture and crisis preparedness.

Read More »
Supply chain resilience is about managing persistent uncertainty – and needs active governance

Supply chain resilience is about managing persistent uncertainty – and needs active governance

In this piece, Gavin Wilson argues that supply chains can no longer be treated as purely commercial functions but must be managed as core risk systems. With geopolitical tension, regulation, climate disruption and hidden dependencies all shaping outcomes, disruption is now constant rather than exceptional. He highlights how many organisations remain exposed due to limited visibility and fragmented ownership, often reacting only once issues arise. His focus is on active governance, deeper supplier insight and earlier involvement of risk functions, ensuring resilience is built in before disruption hits rather than after.

Read More »