
Security on a reactive budget
Discover why security budgets remain reactive, how CISOs and CIOs can build stronger business cases for investment and practical ways to demonstrate security value beyond breaches.
Talk to an expert +44 (0) 208 132 9267

Discover why security budgets remain reactive, how CISOs and CIOs can build stronger business cases for investment and practical ways to demonstrate security value beyond breaches.

Senior risk, resilience and security leaders gathered at the National Liberal Club to discuss what organisational resilience looks like in practice, covering decision-making under pressure, governance, recovery planning, supply chain vulnerabilities, AI, culture and crisis preparedness.

In this piece, Gavin Wilson argues that supply chains can no longer be treated as purely commercial functions but must be managed as core risk systems. With geopolitical tension, regulation, climate disruption and hidden dependencies all shaping outcomes, disruption is now constant rather than exceptional. He highlights how many organisations remain exposed due to limited visibility and fragmented ownership, often reacting only once issues arise. His focus is on active governance, deeper supplier insight and earlier involvement of risk functions, ensuring resilience is built in before disruption hits rather than after.

In this piece, Katie Barnett argues that insider risk is often misunderstood as a problem of malicious intent when in reality it more often develops gradually through stress, fatigue, financial pressure or disengagement. Many incidents are preceded by subtle behavioural changes that go unnoticed or unaddressed, leaving organisations reacting too late. Her focus is on shifting from a purely technical or disciplinary response to one that recognises the role of wellbeing, culture and early intervention. Supporting people earlier, she suggests, is not a soft option but a more effective way to reduce risk before it escalates.

In this piece, Gavin Wilson argues that workplace activism isn’t something organisations should fear but it does need to be managed. Most employee protest is lawful and often healthy but in sensitive environments strong personal convictions combined with access to systems or data can create real risk. Add in the influence of online narratives and external actors and internal tensions can escalate quickly. His focus is on getting the balance right: allowing open disagreement while tightening access, spotting early behavioural changes and making sure concerns are raised early. Ultimately resilience comes down to whether organisations are prepared for when belief, access and pressure collide.