A new report from Ivalua has found that, in the past 12 months, 70% of businesses have had between one and five critical suppliers fail, while 41% say they’re one supplier failure away from a supply chain crisis.
UK
Senior leaders are now able to demonstrate an ability to anticipate, prepare for, and recover from crises under new National Occupational Standards launched by the UK Resilience Academy.
Security teams remain overly committed to keeping humans in the loop and it isn’t a sustainable approach says Ashley Leonard.
Cyber security agencies from Australia, the US, the United Kingdom, and Canada have published new guidance to help critical infrastructure operators isolate vital operational technology (OT) and enabling systems during a major cyber incident or geopolitical crisis.
The Cloud Security Alliance has worked with the SANS Institute, RSAC, FIRST, [un]prompted, and Knostic to quickly develop a post incident review for the recent Hugging Face AI attack incident.
In a disaster scenario getting backups or secondary cloud environments online and functional in time to meet recovery point and recovery time objectives can be hard enough, but sometimes only represents half the challenge.
Although written from an insurance perspective, this recently published academic paper’s treatment of cloud concentration, correlated failure, and scenario calibration is highly transferable to operational resilience.
ASIS Foundation has published a new report exploring security culture, its development, and its role in developing resilience.
The quantum threat is global and a long-term resilience programme is needed in response. However, post-quantum cryptography migration timelines are fragmented, increasing the complexity of preparatory actions.
Chris Newton-Smith explores how the UK Government’s Cyber Resilience Pledge is strengthening board accountability for this area.









