Insights

Hear from thought leaders across the CRI community.

Filter by content topic

Blogs

30 October 2025

How do we preserve human agency in a world of AI-driven cyber defence?

AI is increasingly playing an essential role in cyber defence, yet every layer of automation carries both benefit and trade-off. The benefit lies in speed, scale, and consistency. The trade-off lies in the gradual displacement of human interpretation. The question is not whether automation is valuable but whether it remains an extension of human intent or becomes a substitute for it.
5 min read
23 September 2025

Building Cyber and Digital Resilience – The four questions every public sector leader must answer.

Earlier this year the National Audit Office (NAO) warned that Government cyber resilience isn’t keeping up with the evolving threat. Unsurprisingly, digital and cyber resilience across public sector is now under unprecedented scrutiny and the pressure to act has never been higher.
4 min read
11 September 2025

Five Principles for Building Cyber Resilience

Many organisations say they want to be “cyber resilient”, but the term is often vague. At its core, resilience means ensuring the business can continue to operate despite inevitable events – cyber or otherwise. The problem is that resilience is still too often treated as an aspiration, rather than a discipline.
5 min read
06 August 2025

Are your cyber metrics giving you a false sense of security?

Is your organisation primarily using a traffic light system (red, amber, green) to manage cyber risk? You could be overlooking a crucial dimension of risk management.
4 min read
30 July 2025

5 lessons from the frontline: What UK retailers can learn from 2025’s ransomware attacks

As UK retailers made the press in a series of cyber-related incidents a familiar question surfaced again from colleagues - “Do we have a summary of key themes we can share with clients to support cyber conversations?”
4 min read
09 June 2025

Cyber insurance needs better quantification

Cyber insurance has become a staple in many organisations’ risk strategies, but its strategic value is often under-leveraged.
4 min read
06 May 2025

Winning the First Yes: Navigating the Five Most Common CRQ Objections

Before a single scenario is modelled or a number estimated, one of first challenges in adopting cyber risk quantification (CRQ) is simply persuading stakeholders it's worth doing.
8 min read
29 April 2025

Six Principles of Effective CRQ: How to Build an Engine That Lasts

In this article, I’ll share six working principles I’ve found essential for embedding CRQ in a way that sticks — not just as a project, but as a true business capability.
7 min read
22 April 2025

The Art and Science of CRQ: Why Practitioners Must Lead the Change

What Shackleton Can Teach Us About Navigating Cyber Risk
8 min read
15 April 2025

From Insight to Action: Making CRQ Results Actually Useful

For all the energy that organisations invest in CRQ, a frustrating truth remains: many results don't actually lead to better decisions. Quantification is a powerful tool. But like any tool, its value lies in how it’s used.
7 min read
08 April 2025

Building a Common Language for Cyber Risk: Why CRQ Needs Standardised Metrics

Just like the weather, Cyber Risk Quantification (CRQ) needs a standardised set of metrics. Let's explore what they can be.
4 min read
21 November 2024

Worst Case vs Most Likely vs ALE

Worst case sets a practical limit on what should be spent to manage/mitigate risk, most likely is what you should expect to occur, while ALE tells you how to do long-term financial planning or to think for (self) insurance.
9 min read
14 October 2024

Ready to report on cyber risk? A buyer’s guide to Cyber Risk Quantification

One way to fortify your cyber security is by using cyber risk quantification (CRQ), helping you to express risk quantitatively.
3 min read
10 October 2023

How quantitative risk management enables proactive resilience in the Public Sector

Public sector organisations are key to our economy, providing essential services to the population. Given the importance of the sector, they are prime targets for cyber-attacks, due to data-rich environments, critical infrastructure, political and ideological motivations and interconnected systems.
3 min read
18 July 2023

You need to be ready to report on your cyber security risk

Cyber security threats aren’t going away. If anything, as we evolve our use of technology through continued digitisation, they’ll grow. 
3 min read

See CRI in action

Book a personalised demo and discover how CRI can help you make smarter cyber risk decisions.