Our blog

Insights

Hear from thought leaders across the CRI community.
View all
CRQ in action

The hidden variable in cyber risk decisions: The decision environment

Inspired by Nobel prize winner, Daniel Kahneman’s timeless lessons on decision‑making, explore how his ideas can help cyber leaders improve group judgement and overcome bias in strategy discussions.
James Hanbury
March 10, 2026
4 min read
Sector insights

Calculating the impact of a cyber-attack on critical infrastructure

What would a systemic cyber-attack cost the UK economy? We recently conducted a study for the Department for Science, Innovation and Technology (DSIT) to answer that question. The findings show the scale of potential disruption and underline why resilience planning matters.
James Hanbury
March 9, 2026
3 min read
Resilience

Cyber resilience in the North West: turning risk into regional strength

According to the Department for Science, Innovation and Technology (DSIT), over 600,000 UK businesses experiencing some form of cyber‑attack. So, if cyber risk isn’t new, why do impacts keep rising? And what can we do in the North West to change the trend?
Martin Tyley
February 16, 2026
3 min read
Sector insights

Making sense of cyber attack costs: A sector by sector view

What might a cyber-attack cost your business? Read more about the patterns we found in research we conducted for the Department for Science, Innovation and Technology (DSIT) – and why those patterns still matter today, even as the threat landscape evolves.
James Hanbury
February 9, 2026
3 min read
Resilience

How to achieve resilience in third-party risk management

Discover the results of KPMG's latest global third-party risk management (TPRM) survey.
KPMG International
February 5, 2026
10 min read
Mega trends

Cybersecurity in 2026: What leaders need to know

The latest Global Cybersecurity Outlook from the World Economic Forum highlights three forces reshaping cyber risk in 2026: artificial intelligence, geopolitics and cyber enabled fraud. For many boards, that’s going to raise questions such as “how much loss are we really exposed to?”, and “where should the next pound of investment go?”.
Martin Tyley
January 23, 2026
5 min read
Resilience

Why third-party risk is now a boardroom number

The UK Cyber Security and Resilience Bill is moving supply chain security from compliance to calculus. The days of managing third-party risks with just questionnaires are over. It's time for a new approach.
Elizabeth Huthman
January 5, 2026
3 min read
Sector insights

What’s the impact on your customers if your company gets hacked?

The cost of a cyber-attack on companies is well understood. But what is the impact on the consumers those companies serve?
Martin Tyley
December 18, 2025
5 min read
Mega trends

How do we preserve human agency in a world of AI-driven cyber defence?

AI is increasingly playing an essential role in cyber defence, yet every layer of automation carries both benefit and trade-off. The benefit lies in speed, scale, and consistency. The trade-off lies in the gradual displacement of human interpretation. The question is not whether automation is valuable but whether it remains an extension of human intent or becomes a substitute for it.
James Hanbury
October 30, 2025
5 min read
Sector insights

Building cyber and digital resilience in the public sector

Earlier this year the National Audit Office (NAO) warned that Government cyber resilience isn’t keeping up with the evolving threat. Unsurprisingly, digital and cyber resilience across public sector is now under unprecedented scrutiny and the pressure to act has never been higher.
Francesca Vallely
September 23, 2025
4 min read
Resilience

Five principles for building cyber resilience

Many organisations say they want to be “cyber resilient”, but the term is often vague. At its core, resilience means ensuring the business can continue to operate despite inevitable events – cyber or otherwise. The problem is that resilience is still too often treated as an aspiration, rather than a discipline.
James Hanbury
September 11, 2025
5 min read
Resilience

Are your cyber metrics giving you a false sense of security?

Is your organisation primarily using a traffic light system (red, amber, green) to manage cyber risk? You could be overlooking a crucial dimension of risk management.
Elizabeth Huthman
August 6, 2025
4 min read
Sector insights

5 lessons learned from 2025's ransomware attacks on UK retailers

As UK retailers made the press in a series of cyber-related incidents a familiar question surfaced again from colleagues - “Do we have a summary of key themes we can share with clients to support cyber conversations?”
Martin Tyley
July 30, 2025
4 min read
Sector insights

Cyber insurance needs better quantification

Cyber insurance has become a staple in many organisations’ risk strategies, but its strategic value is often under-leveraged.
James Hanbury
June 9, 2025
4 min read
CRQ in action

From pilot to capability: The journey to operationalise CRQ

Part of a collection:
Cracking the CRQ code
CRQ can’t remain a pilot forever. To drive meaningful, repeatable value, it needs to mature into a business capability: trusted, embedded, and regularly informing decisions.
James Hanbury
May 13, 2025
CRQ in action

Winning the first yes: Navigating the five most common CRQ objections

Part of a collection:
Cracking the CRQ code
Before a single scenario is modelled or a number estimated, one of first challenges in adopting cyber risk quantification (CRQ) is simply persuading stakeholders it's worth doing.
James Hanbury
May 6, 2025
8 min read
CRQ in action

Six principles of effective CRQ: How to build an engine that lasts

Part of a collection:
Cracking the CRQ code
In this article, I’ll share six working principles I’ve found essential for embedding CRQ in a way that sticks — not just as a project, but as a true business capability.
James Hanbury
April 29, 2025
7 min read
CRQ in action

The art and science of CRQ: Why practitioners must lead the change

Part of a collection:
Cracking the CRQ code
What Shackleton Can Teach Us About Navigating Cyber Risk
James Hanbury
April 22, 2025
8 min read
CRQ in action

From insight to action: Making CRQ results actually useful

Part of a collection:
Cracking the CRQ code
For all the energy that organisations invest in CRQ, a frustrating truth remains: many results don't actually lead to better decisions. Quantification is a powerful tool. But like any tool, its value lies in how it’s used.
James Hanbury
April 15, 2025
7 min read
CRQ in action

A common language for cyber risk: Why CRQ needs standardised metrics

Part of a collection:
Cracking the CRQ code
Just like the weather, Cyber Risk Quantification (CRQ) needs a standardised set of metrics. Let's explore what they can be.
James Hanbury
April 8, 2025
4 min read
CRQ in action

Making data driven decisions on cyber security

Understanding the cyber threats you face and where best to invest in strengthening your cyber security is a business priority.
Multiple
January 6, 2025
Mega trends

Cybersecurity considerations 2025

The digital landscape continues to evolve at an unprecedented rate, bringing forth new challenges and amplifying the urgency for robust cybersecurity measures.
KPMG International
January 1, 2025
CRQ in action

Worst case vs most likely vs ALE in Cyber Risk Quantification

Worst case sets a practical limit on what should be spent to manage/mitigate risk, most likely is what you should expect to occur, while ALE tells you how to do long-term financial planning or to think for (self) insurance.
Alex Lightfoot
November 21, 2024
9 min read
CRQ in action

Cyber Risk Quantification buyer's guide: Ready to report on risk?

One way to fortify your cyber security is by using cyber risk quantification (CRQ), helping you to express risk quantitatively.
Martin Tyley
October 14, 2024
3 min read
Mega trends

Cybersecurity considerations 2024

The KPMG annual Cybersecurity considerations report identifies eight key considerations that CISOs should prioritise in 2024 to help mitigate risk, drive business growth and build resilience.
KPMG International
May 1, 2024
Mega trends

A new age of cybersecurity culture

Cyber Human Risk Management (HRM) is essential to cybersecurity culture, as the way people manage technology is the window through which threat actors can infiltrate organisations.
KPMG International
April 30, 2024
Mega trends

The hostile limelight

Organisations around the world need to factor the geopolitical risk to cyber security – and the cyber-driven elements of geopolitical risk – into their strategic decision making.
KPMG in the UK
November 1, 2023
Sector insights

How quantifying cyber risk drives proactive Public Sector resilience

Public sector organisations are key to our economy, providing essential services to the population. Given the importance of the sector, they are prime targets for cyber-attacks, due to data-rich environments, critical infrastructure, political and ideological motivations and interconnected systems.
Francesca Vallely
October 10, 2023
3 min read
CRQ in action

Are you ready to report on your cyber risk?

Cyber security threats aren’t going away. If anything, as we evolve our use of technology through continued digitisation, they’ll grow. 
Alex Lightfoot
July 18, 2023
3 min read

See CRI in action

Book a personalised demo and discover how CRI can help you make smarter cyber risk decisions.