
Security on a reactive budget
Discover why security budgets remain reactive, how CISOs and CIOs can build stronger business cases for investment and practical ways to demonstrate security value beyond breaches.
Talk to an expert +44 (0) 208 132 9267

Discover why security budgets remain reactive, how CISOs and CIOs can build stronger business cases for investment and practical ways to demonstrate security value beyond breaches.

Discover the biggest security risks facing financial institutions in 2026, including AI threats, insider risk, supply chain vulnerabilities and resilience challenges.

Senior risk, resilience and security leaders gathered at the National Liberal Club to discuss what organisational resilience looks like in practice, covering decision-making under pressure, governance, recovery planning, supply chain vulnerabilities, AI, culture and crisis preparedness.

In this piece, Gavin Wilson argues that supply chains can no longer be treated as purely commercial functions but must be managed as core risk systems. With geopolitical tension, regulation, climate disruption and hidden dependencies all shaping outcomes, disruption is now constant rather than exceptional. He highlights how many organisations remain exposed due to limited visibility and fragmented ownership, often reacting only once issues arise. His focus is on active governance, deeper supplier insight and earlier involvement of risk functions, ensuring resilience is built in before disruption hits rather than after.

Our second converged security session hosted in partnership with Mitie brought together senior leaders from security, risk and resilience to explore a practical question: what does convergence look like when it works and why does it remain so difficult to achieve? The session was designed to focus on practice rather than theory. Each panellist was asked to share an example of where convergence is

Why supply chains must be treated as risk systems. Explore geopolitical risk, climate disruption and resilience in modern supply chain governance.

At Toro, business continuity is treated as an operational capability rather than a compliance document.

In this article, Katie Barnett, Director of Cyber Security, and Gavin Wilson, Director of Physical Security and Risk at Toro Solutions, warn that many organisations talk about convergence but stop short of true accountability.
While cyber, physical and people risks are increasingly connected, ownership of those risks often remains fragmented. Different teams manage different parts of the picture, with no single leader responsible for how those threats combine. The result is blurred accountability, slow decision-making and gaps that only become visible during an incident.
Barnett and Wilson argue that collaboration alone is not enough. Without clear authority, board-level visibility and a culture that supports joined-up thinking, risk continues to sit between functions rather than being actively managed. Convergence, they conclude, only works when someone is clearly accountable for the whole picture.

In this recent press piece, Toro Solutions’ Directors of Cyber Security and Physical Security and Risk discuss why resilience is about people, not paperwork.
They argue that most organisations don’t fall short because they lack plans, but because their teams operate in silos. When cyber, physical and operational functions fail to share context early, warning signs are missed and response slows down. Convergence, they explain, isn’t about restructuring it’s about getting the right people talking before small issues turn into bigger problems.
Because when pressure hits, it’s not the plan that makes the difference, it’s how well your teams work together.

Explore third party risks and learn how to identify and manage the potential impact on your organisation’s security and operations.

The biggest cyber risks in 2026 aren’t new technologies – they’re old controls that were never enforced, reviewed or removed.

Resilience isn’t built on plans alone. Learn how breaking down silos, improving communication and connecting people strengthens real organisational resilience.