Our blog

Insights

Hear from thought leaders across the CRI community.
View all
Mega trends

8 shifts changing how organisations manage risk

Cyber risk isn’t being rewritten by a shiny new framework, it’s being forced to evolve because the way organisations use technology has changed. We unpack eight shifts already surfacing in incidents, audits and boardrooms.
Martin Tyley
March 27, 2026
3 min read
CRQ in action

The hidden variable in cyber risk decisions: The decision environment

Inspired by Nobel prize winner, Daniel Kahneman’s timeless lessons on decision‑making, explore how his ideas can help cyber leaders improve group judgement and overcome bias in strategy discussions.
James Hanbury
March 10, 2026
4 min read
Sector insights

Calculating the impact of a cyber-attack on critical infrastructure

What would a systemic cyber-attack cost the UK economy? We recently conducted a study for the Department for Science, Innovation and Technology (DSIT) to answer that question. The findings show the scale of potential disruption and underline why resilience planning matters.
James Hanbury
March 9, 2026
3 min read
Resilience

Cyber resilience in the North West: turning risk into regional strength

According to the Department for Science, Innovation and Technology (DSIT), over 600,000 UK businesses experiencing some form of cyber‑attack. So, if cyber risk isn’t new, why do impacts keep rising? And what can we do in the North West to change the trend?
Martin Tyley
February 16, 2026
3 min read
Sector insights

Making sense of cyber attack costs: A sector by sector view

What might a cyber-attack cost your business? Read more about the patterns we found in research we conducted for the Department for Science, Innovation and Technology (DSIT) – and why those patterns still matter today, even as the threat landscape evolves.
James Hanbury
February 9, 2026
3 min read
Mega trends

Cybersecurity in 2026: What leaders need to know

The latest Global Cybersecurity Outlook from the World Economic Forum highlights three forces reshaping cyber risk in 2026: artificial intelligence, geopolitics and cyber enabled fraud. For many boards, that’s going to raise questions such as “how much loss are we really exposed to?”, and “where should the next pound of investment go?”.
Martin Tyley
January 23, 2026
5 min read
Resilience

Why third-party risk is now a boardroom number

The UK Cyber Security and Resilience Bill is moving supply chain security from compliance to calculus. The days of managing third-party risks with just questionnaires are over. It's time for a new approach.
Elizabeth Huthman
January 5, 2026
3 min read
Sector insights

What’s the impact on your customers if your company gets hacked?

The cost of a cyber-attack on companies is well understood. But what is the impact on the consumers those companies serve?
Martin Tyley
December 18, 2025
5 min read
Mega trends

How do we preserve human agency in a world of AI-driven cyber defence?

AI is increasingly playing an essential role in cyber defence, yet every layer of automation carries both benefit and trade-off. The benefit lies in speed, scale, and consistency. The trade-off lies in the gradual displacement of human interpretation. The question is not whether automation is valuable but whether it remains an extension of human intent or becomes a substitute for it.
James Hanbury
October 30, 2025
5 min read
Sector insights

Building cyber and digital resilience in the public sector

Earlier this year the National Audit Office (NAO) warned that Government cyber resilience isn’t keeping up with the evolving threat. Unsurprisingly, digital and cyber resilience across public sector is now under unprecedented scrutiny and the pressure to act has never been higher.
Francesca Vallely
September 23, 2025
4 min read
Resilience

Five principles for building cyber resilience

Many organisations say they want to be “cyber resilient”, but the term is often vague. At its core, resilience means ensuring the business can continue to operate despite inevitable events – cyber or otherwise. The problem is that resilience is still too often treated as an aspiration, rather than a discipline.
James Hanbury
September 11, 2025
5 min read
Resilience

Are your cyber metrics giving you a false sense of security?

Is your organisation primarily using a traffic light system (red, amber, green) to manage cyber risk? You could be overlooking a crucial dimension of risk management.
Elizabeth Huthman
August 6, 2025
4 min read
Sector insights

5 lessons learned from 2025's ransomware attacks on UK retailers

As UK retailers made the press in a series of cyber-related incidents a familiar question surfaced again from colleagues - “Do we have a summary of key themes we can share with clients to support cyber conversations?”
Martin Tyley
July 30, 2025
4 min read
Sector insights

Cyber insurance needs better quantification

Cyber insurance has become a staple in many organisations’ risk strategies, but its strategic value is often under-leveraged.
James Hanbury
June 9, 2025
4 min read
CRQ in action

Winning the first yes: Navigating the five most common CRQ objections

Before a single scenario is modelled or a number estimated, one of first challenges in adopting cyber risk quantification (CRQ) is simply persuading stakeholders it's worth doing.
James Hanbury
May 6, 2025
8 min read
CRQ in action

Six principles of effective CRQ: How to build an engine that lasts

In this article, I’ll share six working principles I’ve found essential for embedding CRQ in a way that sticks — not just as a project, but as a true business capability.
James Hanbury
April 29, 2025
7 min read
CRQ in action

The art and science of CRQ: Why practitioners must lead the change

What Shackleton Can Teach Us About Navigating Cyber Risk
James Hanbury
April 22, 2025
8 min read
CRQ in action

From insight to action: Making CRQ results actually useful

For all the energy that organisations invest in CRQ, a frustrating truth remains: many results don't actually lead to better decisions. Quantification is a powerful tool. But like any tool, its value lies in how it’s used.
James Hanbury
April 15, 2025
7 min read
CRQ in action

A common language for cyber risk: Why CRQ needs standardised metrics

Just like the weather, Cyber Risk Quantification (CRQ) needs a standardised set of metrics. Let's explore what they can be.
James Hanbury
April 8, 2025
4 min read
CRQ in action

Worst case vs most likely vs ALE in Cyber Risk Quantification

Worst case sets a practical limit on what should be spent to manage/mitigate risk, most likely is what you should expect to occur, while ALE tells you how to do long-term financial planning or to think for (self) insurance.
Alex Lightfoot
November 21, 2024
9 min read
CRQ in action

Cyber Risk Quantification buyer's guide: Ready to report on risk?

One way to fortify your cyber security is by using cyber risk quantification (CRQ), helping you to express risk quantitatively.
Martin Tyley
October 14, 2024
3 min read
Sector insights

How quantifying cyber risk drives proactive Public Sector resilience

Public sector organisations are key to our economy, providing essential services to the population. Given the importance of the sector, they are prime targets for cyber-attacks, due to data-rich environments, critical infrastructure, political and ideological motivations and interconnected systems.
Francesca Vallely
October 10, 2023
3 min read
CRQ in action

Are you ready to report on your cyber risk?

Cyber security threats aren’t going away. If anything, as we evolve our use of technology through continued digitisation, they’ll grow. 
Alex Lightfoot
July 18, 2023
3 min read

See CRI in action

Book a personalised demo and discover how CRI can help you make smarter cyber risk decisions.