Why Cyber Governance Matters Now More Than Ever The recent statistics are eye-opening: 70% of medium businesses and 75% of large businesses in the UK have experienced a cyber breach in the past year. With digital risks continuing to mount, the UK government has introduced the Cyber Governance Code of Practice to guide boards and directors in their oversight of cyber risk.
But for many organisations, a burning question remains: "How do we actually implement this in practice?"
At Cool Waters Cyber, we've answered this question with our comprehensive guide: "Implementing the UK Cyber Governance Code with IASME Cyber Assurance: A Practical Roadmap." Today, we're sharing key insights from this report to help your organisation navigate the path to stronger cyber governance and providing a free download of the full report.
The Perfect Marriage: The Code and IASME Cyber AssuranceOur research reveals a powerful approach: using the IASME Cyber Assurance standard (formerly "IASME Governance") as your implementation framework for the Cyber Governance Code.
Why this approach works so effectively:
The Five Principles and How IASME DeliversThe Cyber Governance Code focuses on five key areas. Here's how IASME Cyber Assurance helps you address each:
IASME delivers through:
Regular reassessment requirements that keep your risk picture current
StrategyThe Code expects a formal cyber strategy aligned with business goals and supported by adequate resources.
IASME implements this via:
Monitoring requirements to track strategy effectiveness
PeopleThe Code emphasizes culture, training, and policies that foster security-aware behaviour.
IASME's approach includes:
Metrics to measure the effectiveness of awareness initiatives
Incident Planning, Response & RecoveryThe Code requires robust incident response plans that are regularly tested and updated.
IASME delivers through:
Post-incident review processes to drive continuous improvement
Assurance & OversightThe Code calls for governance structures, regular reporting, and independent assurance.
IASME supports this with:
Our 9-Step Implementation RoadmapWe've distilled the implementation process into nine practical steps:
This roadmap typically takes 3-6 months to implement, depending on your organisation's starting point and resources.
Fast-Track Your Journey with Cool Waters CyberAs Cornwall's first NCSC-assured Cyber Advisor provider, Cool Waters Cyber has helped numerous organisations achieve Cyber Essentials and IASME Cyber Assurance certification efficiently and effectively.
Our approach removes the complexity for you:
Many of our clients have achieved certification in as little as 8-10 weeks with our support—far faster than tackling it alone.
Take Action Today Don't let cyber governance remain a box-ticking exercise or an overwhelming challenge. With the right approach and support, you can transform it into a strategic advantage that protects your organisation and demonstrates your commitment to cyber resilience.
Download our comprehensive guide to explore the complete implementation roadmap in detail.
Ready to fast-track your journey to Cyber Governance Code compliance? Contact our team today for a no-obligation consultation and discover how we can help your organisation achieve certification within weeks, not months.
Cool Waters Cyber is an NCSC-assured Cyber Advisor provider and IASME Certification Body, specialising in helping organisations build practical cyber resilience through Cyber Essentials, IASME Cyber Assurance, and tailored cyber advisory services.
What is the Cyber Governance Code of Practice? The Code outlines the critical governance actions directors are responsible for. It is supported by free Cyber Governance Training and a Cyber Security Toolkit for Boards, providing a full package of resources.
The Code focuses on five key areas:
It complements existing frameworks like Cyber Essentials and should be treated as the foundational standard for any organisation taking cyber governance seriously.
Why it matters:* 74% of large businesses and 70% of medium businesses have reported cyber breaches in the last 12 months (Cyber Security Breaches Survey 2024). * Cyber risk is a material risk that can threaten business continuity, reputation, and long-term viability. * Strong cyber governance enables businesses to embrace digital innovation safely and competitively.
First Steps Directors / Trustees Should Take:1. Identify Critical Assets
* Gain assurance that your organisation has clearly identified and prioritised the systems, information, and processes that are essential to achieving your objectives.
Establish Senior Ownership
Define Risk Appetite
Agree and document the level of cyber risk your organisation is willing to accept. Align your cyber strategy with this appetite.
Review Supply Chain Risks
Ensure that you regularly assess the cyber security of your suppliers and business partners.
Develop or Refresh Your Cyber Strategy
Confirm your cyber strategy is up to date, aligns with your business goals, and that adequate resources are in place to deliver it. If you are not sure where to start, a fractional CISO can do this for you.
Foster a Positive Cyber Security Culture
Promote cyber awareness at all levels, including board training to improve directors' cyber literacy.
Test Your Incident Response Plans
Regularly exercise your cyber incident response and recovery plans and update them based on lessons learned.
Implement Formal Governance Structures
Set clear roles and reporting requirements for cyber governance, ensuring it’s part of your existing governance and assurance frameworks. There is no need to re-invent the wheel, existing frameworks like IASME Cyber Assurance or ISO 27001 work well here.
Want to Dive Deeper?Listen to Episode 10 of our podcast, the Business Leaders Cyber Briefing, where we explain the new Code of Practice in plain English, discuss what it means for your board, and share real-world tips on getting started. Listen Now
How Cool Waters Cyber Can HelpNavigating new governance responsibilities can feel overwhelming. Cool Waters Cyber is here to make it simple. We offer tailored support to help businesses and charities implement the Cyber Governance Code of Practice, including:
Let us help you build stronger cyber resilience from the top down.
Read more about our Implementation Service to help you align with the Code of Practice
Fast Track compliance with IASME Cyber AssuranceRead how the IASME Cyber Assurance standard provides a ready made framework for compliance with the Cyber Governance Code of Practice, saving time and money and fast-tracking compliance:
Read: How to Implement the Cyber Governance Code with IASME Cyber Assurance
Speak to us todayGet in touch with Cool Waters Cyber today to start your journey towards effective cyber governance.
Download the Code of PracticeYou can download the Cyber Governance Code of Practice here: https://www.gov.uk/government/publications/cyber-governance-code-of-practice
If your PCI compliance process feels like an annual panic, it’s time for a rethink.For many organisations, PCI DSS is still treated as a once-a-year hurdle—something to rush through, report on, and then forget until next time. But that approach creates gaps, introduces risk, and adds pressure that no business needs.
At Cool Waters Cyber, we’re flipping that script. Just like we’ve done with ISO 27001, we’re helping businesses see PCI DSS for what it really is:
➡️ A standard that’s meant to protect, not punish.
➡️ A process that works best when it’s always on.
➡️ A goal that becomes a lot easier with the right partner.
🔄 From Point-in-Time to Always-OnA typical PCI project starts strong: you pull together policies, tweak your firewall rules, gather evidence—and after a few weeks of effort, your business is deemed compliant.
But what happens 3 months later?
Without continuous oversight, your compliance status fades fast.
And when next year’s audit rolls around, you’re back at square one—only this time with even more technical debt and risk to untangle.
🧾 What is PCI Compliance-as-a-Service?It’s a subscription-based model that gives you expert-led, ongoing PCI support—so your business stays compliant and secure all year round.
You still get the same outcome—compliance with PCI DSS—but you get there without the panic and without wasting time reinventing the wheel.
With Cool Waters, you get:🔍 Continuous control monitoring and evidence tracking
👥 A named expert who knows your systems and your goals
🧩 Advice that fits your infrastructure—not off-the-shelf answers
🔄 Support for changes, incidents, re-scoping, and audits as they arise
📅 Monthly summaries and actionable, jargon-free recommendations
📅 On-going compliance monitoring and internal audits and quarterly board reports
🛠️ Designed for Real-World BusinessesOur clients don’t have big in-house security teams.
They’re IT managers, compliance leads, or directors juggling a dozen other priorities.
So we don’t just tell you what’s wrong—we help you fix it.
We work in partnership with your team, helping you:
No scare tactics. No upselling. Just the right-sized help you actually need.
💸 Predictable Pricing, Scalable SupportWe know budgets are tight. That’s why our PCI-as-a-Service packages are designed to:
This isn’t just consulting. It’s your outsourced PCI team—on demand.
✅ Ready to Step Off the Annual Treadmill?If you’re tired of PCI being a once-a-year disruption, it’s time to do it differently.
Let’s turn compliance into something that adds value—without draining your team’s energy or time.
📞 Book a free discovery call
🌐 Learn more at www.cool-waters.co.uk/pcidss
The idea of quantum computing might sound like science fiction—but it’s becoming science fact faster than most businesses realise. While we’re still years away from fully operational quantum computers, developments are accelerating—and they could have serious implications for the way we protect sensitive data.
At Cool Waters Cyber Security, we’ve been looking ahead to understand how this next-generation tech could affect compliance, especially for businesses working under PCI DSS requirements. Here's what you need to know.
⚛️ Quantum Computing Will Break Today’s EncryptionMost of today’s digital security relies on one big idea: encryption is safe because breaking it would take thousands of years using current computing power. But quantum computers will change the rules.
Algorithms like RSA and ECC—widely used in PCI environments—are particularly vulnerable to quantum attacks.
What used to be "secure" for decades could be cracked in hours.
🔐 What This Means for PCI DSSPCI DSS requires strong cryptographic protection for cardholder data. While the current version doesn’t mandate "quantum-safe" encryption, that could change—fast. Organisations that handle payments or store cardholder data need to start thinking about:
This is known as a "harvest now, decrypt later" threat—and it’s real.
🧭 What You Should Do Now1. Take inventory of cryptographic use
Know where encryption is used in your environment—especially for data at rest and in transit.
2. Avoid proprietary or outdated encryption
Stick to well-established, standards-based algorithms and libraries.
3. Watch for guidance updates
Keep an eye on PCI DSS future revisions, NCSC advisories and NIST’s post-quantum cryptography programme.
4. Start future-proofing
Transitioning to quantum-resistant algorithms won’t happen overnight. It makes sense to plan ahead, especially if your business has long-term data retention needs.
Download your free copy of the Quantum Crisis report
🛡️ How Cool Waters Can HelpWhether you're working toward PCI compliance or already certified, we can help you:
We're here to help you stay compliant today—and ready for what’s coming next.
🔗 Download our full report on quantum computing and PCI compliance here
Passkeys are emerging as a modern alternative to passwords, offering a blend of strong security and ease of use for online authentication.
Passkeys are digital credentials based on FIDO standards that let users sign in to apps and websites using the same method they use to unlock their devices (such as a fingerprint, face scan, or PIN) . Unlike traditional passwords, a passkey is a cryptographic key pair: a private key that stays on your device and a public key stored with the service. When you log in, the service sends a one-time challenge that your device signs with the private key (after you verify with biometrics or PIN), and the service uses the public key to verify the signature . This happens behind the scenes almost instantaneously – from the user’s perspective, you simply confirm your identity (e.g. with a fingerprint) and you’re signed in . In summary, passkeys eliminate the need for typing a password or remembering secret codes, instead leveraging public-key cryptography and device authentication to prove who you are.
Passkeys have gained prominence because they directly address the growing weaknesses of password-based security. Cybersecurity risks related to passwords are well-documented: the majority of cyber breaches involve lost, stolen, or weak credentials . Attackers commonly obtain passwords via phishing scams, database breaches, or by exploiting password reuse. Traditional passwords are simply not adequate protection on today’s internet . While adding multi-factor authentication (MFA) on top of passwords can help, not everyone enables it and many MFA methods (like SMS one-time codes) are still vulnerable to phishing and social engineering . This has created an urgent need for stronger authentication methods that both improve security and remain user-friendly. Passkeys have emerged as a leading solution to this problem, effectively replacing the password with a phishing-resistant, device-based credential . In short, a passkey is a more secure replacement for passwords that “stops phishing in its tracks” by design . In the next sections, we’ll explore how passkeys achieve these security benefits, how they align with modern cybersecurity recommendations, and what their adoption means for businesses and everyday users.
Security Benefits of PasskeysPasskeys offer significant security advantages over traditional passwords. First and foremost, they eliminate the pitfalls of human-created passwords. Users can choose weak or common passwords (like password123) or reuse them across sites, but passkeys don’t have these issues – they are strong, cryptographically random credentials generated by the device . Every passkey is unique to each service, removing the risk that one stolen credential could be used elsewhere . There’s also nothing for a user to forget or mistype; the complexity is handled by the device, not the person. Additionally, passkeys can’t be guessed or brute-forced in the way a simple password can, since the “secret” (private key) is large, random, and never leaves your device . These inherent properties mean passkeys are strong by default, delivering robust security without relying on the user to create or manage a complex password .
Another major benefit is phishing resistance. Phishing attacks trick users into entering credentials into fake websites or divulging one-time codes, but passkeys largely nullify this threat. When you use a passkey, the private key never leaves your device and will only respond to the legitimate service that it’s registered to . In technical terms, the passkey protocol (WebAuthn/FIDO2) is bound to the web domain of the service – it won’t authenticate the wrong site . Even if an attacker creates a perfect replica of a website, your passkey won’t work on it because the cryptographic exchange checks that the server’s domain is correct . This means an attacker cannot trick you into “signing in” and then steal your credentials; the private key is never revealed to the server or the attacker . In the event a company’s database is breached, passwords might be leaked, but with passkeys the server holds only public keys – which are useless to an attacker on their own . By removing passwords from the equation, passkeys dramatically reduce phishing, credential theft, and credential stuffing attacks . In fact, security experts categorize passkeys (and other FIDO2 security keys) as phishing-resistant MFA, meaning they meet the highest standards for thwarting phishing attempts .
Passkeys not only improve security; they often enhance user experience compared to traditional MFA. With a passkey, signing in typically becomes a one-step action – for example, just scanning your fingerprint – rather than typing a password and a second factor code. This streamlined process can reduce login friction while still maintaining strong authentication. Studies have shown that logins with passkeys are more successful on the first try (users are less likely to get locked out or require resets); one industry report noted 20% more successful sign-ins when using passkeys versus passwords . Users appreciate not having to remember or manually enter credentials, and there are no cumbersome one-time codes to transcribe. In short, passkeys manage to be both more secure and more convenient than the password-plus-OTP model . They essentially combine the security of a hardware token with the ease of biometric login. A passkey is “something you have” (your device) plus “something you are/know” (your biometric or PIN) folded into a seamless experience . This dual-factor nature is why passkeys are considered a form of multi-factor authentication – but without the user having to juggle separate devices or codes.
Comparison with other authentication technologies: It’s useful to see how passkeys stack up against alternatives:• Biometric-only authentication: Many devices let you unlock with a fingerprint or face, but usually this just unlocks a stored password or token. For example, using Face ID to log into an app often means Face ID is autofilling a password in the background. Passkeys are different – when you use a biometric with a passkey, there is no underlying password at all . The biometric simply unlocks the passkey’s private key on your device, which then performs a crypto exchange. This means your fingerprint or face isn’t being sent over the network, and there’s no static credential to steal. In essence, passkeys leverage biometrics for user convenience, but the security comes from cryptographic keys. This is more secure than approaches where biometrics might be used to retrieve a password or a code. Notably, your biometric data itself never leaves your device in the passkey model, alleviating privacy concerns – it’s only used locally to unlock the credential.
• Hardware security keys: Physical security keys (like YubiKeys) have been the gold standard for phishing-resistant authentication in recent years. They also use FIDO2 technology, so in terms of security passkeys and security keys are equivalent in their core mechanism – both use public-key crypto tied to the real website, thwarting phishers . The difference is in usability and form factor. Traditional security keys are external devices (USB sticks, smart cards) that a user must carry and physically use during login. This works well for employees or tech-savvy users, but it’s a hurdle for many consumers . Passkeys aim to bring the security of hardware keys to everyone by using devices people already have (phones, laptops) as the authenticator. In practice, a phone or computer can perform the same role as a security key – storing the private key in a secure enclave and requiring user verification to use it. By removing the need for a separate USB key, passkeys make advanced authentication more accessible to the average user . Enterprises may still choose hardware tokens for certain high-security use cases or regulatory requirements, but passkeys open the door for much broader adoption of hardware-backed security. It’s worth noting that passkeys come in two flavors: “multi-device” (syncable across your devices via cloud) and “single-device” (bound to one hardware token). We’ll discuss the implications of those in a later section, but both types are based on the same FIDO2 standards and both are far more phishing-resistant than passwords.
• Traditional MFA (e.g. SMS codes, authenticator apps): Any form of MFA is generally more secure than a password alone, but traditional methods have weaknesses. One-time passcodes sent via SMS can be intercepted (through SIM-swaps or phishing sites that prompt users to enter their code). Authenticator apps or email codes are safer than SMS but still susceptible to real-time phishing – an attacker can trick a user into giving up the code, or use a proxy website to capture it. In contrast, a passkey can only be used on the legitimate site/app and cannot be “diverted” to an attacker . Also, passkeys remove the human element of transcribing codes. From a usability standpoint, passkeys avoid the common problems of MFA fatigue (e.g. being tired of constant prompts) by making the login a single, quick action. In terms of security levels, agencies like the U.S. NIST now classify passkeys as phishing-resistant MFA, on par with physical smart cards and security keys . Standard two-factor methods (SMS, TOTP apps) do not meet this “phishing-resistant” bar. Thus, passkeys can be seen as the next evolution of MFA – providing two-factor security in a one-factor package. They address the same threat models as a hardware token would (remote attackers, phishing, credential replay), but in a more user-friendly way.
In summary, passkeys drastically improve security by eliminating password vulnerabilities and preventing phishing and online credential theft. At the same time, they make authentication faster and easier for users. This combination of security and usability is why organizations like the NCSC describe passkeys as the future of authentication . Passkeys embody the principle of “phishing-resistant multi-factor authentication,” which is now recommended by many cybersecurity standards as the secure way forward.
Cybersecurity Standards and RecommendationsPasskeys have quickly gained support in the cybersecurity community, and they align well with modern security standards and guidance. In the UK, the National Cyber Security Centre (NCSC) has been openly advocating for passkeys as a viable password replacement. The NCSC notes that most cyber incidents affecting individuals stem from compromised passwords and that “passwords are just not a good way to authenticate users on the modern internet” . In an NCSC blog post, they refer to passkeys as “the world’s best option for going passwordless” – a strong endorsement of the technology’s security and convenience benefits . While acknowledging some challenges to widespread adoption, the NCSC is actively working to address those, indicating a high level of confidence that passkeys will play a key role in the future of secure logins . The message from the UK authorities is clear: organizations and developers should be preparing for a passkey-centric future to improve both security and user experience.
The UK’s Cyber Essentials scheme (a government-backed security certification for businesses) has also updated its requirements to accommodate passwordless authentication. Starting in 2025, the Cyber Essentials guidelines explicitly recognize passkeys and other passwordless methods as compliant ways to secure access to systems . This is a notable change – historically, Cyber Essentials focused on enforcing strong passwords and 2FA. Now the scheme acknowledges that logging in without a password can be even more secure. In their documentation, passwordless authentication is defined as using “a factor other than a user-managed password” to authenticate, and it is accepted as long as it provides equivalent or better protection. For example, using a biometric with a cryptographic device (a passkey) or a hardware token with push approval would meet the requirements . Cyber Essentials still advises that if a backup password exists, it must follow all the standard rules (length, complexity, brute-force lockout, etc.) – but if you eliminate passwords entirely via passkeys, you can comply without those legacy controls. The inclusion of passwordless options in Cyber Essentials demonstrates how security benchmarks are evolving to favor phishing-resistant authentication. It encourages UK businesses to adopt modern methods like passkeys, reflecting the consensus that these methods reduce risk.
Internationally, other standards bodies echo this direction. The U.S. National Institute of Standards and Technology (NIST) recently updated its digital identity guidelines (SP 800-63) to account for passkeys. NIST’s updated guidance states that synced passkeys are considered valid multi-factor authenticators at AAL2 (Authentication Assurance Level 2) when properly implemented . In plain terms, this means that passkeys (even those synced via cloud to multiple devices) satisfy the requirements for MFA in many use cases. NIST also clarified the definition of phishing-resistant MFA – essentially, an authenticator is phishing-resistant if it cryptographically verifies the service’s identity (for instance, binding the login to the legitimate domain) . By this definition, FIDO2 passkeys qualify as phishing-resistant, since the protocol ensures the authentication is tied to the correct website or application . Moreover, NIST assigns an even higher assurance level (AAL3) to device-bound passkeys stored in dedicated hardware (like a FIDO security key) . This acknowledges that passkeys can scale from consumer-friendly implementations (synced across your phone and laptop) up to high-security implementations (stored in a hardware token for critical systems). The key takeaway is that passkeys meet modern compliance requirements for strong authentication. Both government and industry guidelines are being updated to include passkeys as an accepted (and even preferred) form of MFA . This means organizations adopting passkeys can do so with confidence that they are meeting or exceeding recommended security practices, whether it’s under UK Cyber Essentials, NCSC best practices, or international standards like NIST.
Finally, the FIDO Alliance (which develops the passkey standards) and tech industry leaders are providing resources to ease the transition to passkeys. For example, FIDO’s own documentation emphasizes that passkeys are “phishing resistant and secure by design,” helping mitigate phishing attacks, credential stuffing, and other remote attacks . The alliance notes that with passkeys there are “no passwords to steal and no sign-in data that can be used to perpetuate attacks.” It also highlights that passkeys offer an improved security model over not just passwords but even traditional MFA, and they’re easier for people to use . In the eyes of both security experts and standards bodies, passkeys represent a best-of-both-worlds solution: they significantly raise the security bar and simultaneously simplify the user login experience. As such, they feature prominently in contemporary cybersecurity recommendations. Organizations aiming for compliance with frameworks like Zero Trust security or government mandates for phishing-resistant MFA (such as U.S. Executive Order requirements for federal agencies) will find that implementing passkeys helps satisfy those goals. In summary, authorities and industry groups are strongly encouraging passkey adoption, seeing it as a key step in countering the rampant credential-related attacks in today’s threat landscape.
Implementing Passkeys in BusinessesFor organizations, deploying passkeys for employee and enterprise authentication can yield big security improvements – but it requires planning and the right infrastructure. Implementing passkeys in a business environment typically involves integrating with identity platforms or services that support FIDO2 authentication. Many major identity providers now support passkeys or similar passwordless tech for the enterprise. For instance, Microsoft Entra ID (Azure AD) allows businesses to enable FIDO2 passkey sign-in for their users (with options to use device-bound security keys or platform passkeys stored in Windows Hello or Microsoft Authenticator) . Similarly, Google Workspace and Azure AD have added support for passkeys as a login option for workforce accounts, and Okta and other third-party SSO providers offer WebAuthn integration. This means that in many cases, businesses can activate passkey login through configuration, without heavy custom development – assuming their directory or SSO system supports it. In other cases, organizations might implement passkeys directly in their own applications (for customer-facing apps or internal tools). This involves using WebAuthn APIs to register and authenticate users’ passkeys. Many libraries and services exist to streamline this integration, and the FIDO Alliance maintains a directory of passkey-enabled solutions . Businesses can also leverage products like Auth0, Duo, or cloud IAM platforms that have built-in support for WebAuthn/passkeys. In short, the ecosystem is rapidly maturing to make enterprise adoption of passkeys easier, whether through native OS support or third-party solutions.
When rolling out passkeys in an organization, best practices are emerging from early adopters. One strategy is to start by enabling passkeys for specific user groups or scenarios rather than flipping the switch enterprise-wide on day one. Companies often prioritize high-value or high-risk accounts first – for example, privileged IT administrators, developers with access to code repositories, or executives – to gain immediate security benefits . A recent industry survey found that organizations most commonly targeted administrator accounts, users with access to intellectual property, and executive accounts as the first to get passkeys . This makes sense: these groups are frequent phishing targets and have access to sensitive data, so upgrading them to phishing-resistant authentication has a strong payoff. Alongside a phased rollout, communication and training are crucial. Employees need to understand what passkeys are, how to use them, and why they’re an improvement. Many organizations deploying passkeys report investing in user education and documentation to smooth the transition . For example, IT might run internal workshops or provide how-to guides for using passkeys on employee devices. Emphasizing the convenience (no more password resets!) as well as the security benefits helps get buy-in from staff.
From a technical perspective, businesses should ensure that users have the necessary hardware/software to use passkeys. This might include providing FIDO2 security keys to employees who don’t have modern smartphones or who need a portable credential for shared workstations. In fact, some enterprises adopt a mixed approach – using device-bound security keys (hardware tokens) for certain cases and platform passkeys (synced on phones/laptops) for others . In a recent FIDO Alliance survey, 47% of organizations rolling out passkeys chose to deploy a mix of physical security keys and platform (synced) passkeys . The physical keys can serve as a backup or as the primary method in very locked-down environments, while platform passkeys offer ease of use for everyday scenarios. The key is to have a backup and recovery plan: even though passkeys eliminate passwords, users could still lose access if a device is lost. Companies handle this by allowing multiple passkeys per account (e.g. register both your laptop and your phone, maybe even a backup security key) and maintaining an account recovery process (such as administrator-issued reset tokens or fallback to verified email/SMS in worst case). It’s important that any fallback methods are secure – for instance, if an account can fall back to a password, that password should still be strong and protected by policies . Some organizations choose to keep a nominal password as a last-resort login but store it in a sealed envelope or secure vault, to be used only by IT support if needed – thereby essentially operating day-to-day without passwords at all.
The business benefits of moving to passkeys are notable. Companies that have implemented passwordless authentication have seen reductions in successful phishing attacks and drops in password-related helpdesk calls (like reset requests) . In one report, 90% of organizations noted improved security after deploying passkeys, and 77% saw a reduction in help center calls, while also improving user experience and productivity . These are significant operational gains. Additionally, eliminating passwords can help with compliance in sectors that require multi-factor authentication or protection of customer data; passkeys achieve MFA in a user-friendly way that employees are more likely to actually use (versus trying to bypass cumbersome procedures) . We are also seeing real-world case studies of businesses and government agencies adopting passkeys. For example, Australia’s VicRoads (the road transport authority in Victoria) recently implemented a passkey authentication system for their user portal, moving away from traditional passwords as part of a digital security enhancement initiative . They joined the broader trend alongside major tech providers like Microsoft, which has been enabling passwordless sign-in options for its users and services . In the consumer space, PayPal, eBay, Google, Microsoft, and Apple have all introduced passkey support for customer accounts, signaling to enterprise organizations that the technology is mature and user-accepted. Even government services (like Australia’s myGov portal) have seen tens of thousands of users opt to disable their passwords and switch entirely to passkeys, once given the option . Such examples illustrate that passkeys can work at scale, and that users—when properly onboarded—appreciate the convenience.
To implement passkeys enterprise-wide effectively, an organization should follow a few key steps:
(1) Ensure your identity and access systems support FIDO2/passkeys (update software or leverage an identity provider if needed);
(2) Start with a pilot group and gather feedback;
(3) Educate users on how to set up and use passkeys (perhaps integrate enrollment with your single sign-on portal, so it prompts users to register a passkey);
(4) Have a backup plan for account recovery (multiple registered devices or a secure break-glass method); and
(5) Gradually expand the rollout, possibly making passkeys the preferred login and passwords the backup.
Many businesses find that once users try passwordless login, they prefer it. Over time, you can then disable password-based login for the majority of accounts, greatly reducing your attack surface. By following best practices and learning from early adopters, organizations can successfully deploy passkeys for employees, strengthening security and reducing the burden of password management.
Managing Passkeys for ConsumersFor individual users (consumers), passkeys may sound complex, but they are designed to be simple to set up and use – often easier than managing passwords. Encouraging staff to use passkeys in their personal life will help adoption at work. Many popular websites and apps now offer passkeys as a login option, and the process to use them is quite straightforward. Here are some practical tips and guidance for non-technical users to start using passkeys:
• Enable passkeys on services you use: Whenever you create an account or log in to a site that supports passkeys, opt to “Use a passkey” if prompted. Typically, the site will guide you – for example, after logging in with your password, it might say “Add a passkey to your account.” Following the prompt usually triggers your device to save a passkey. You’ll be asked to verify your identity on the device (for instance, by scanning your fingerprint or face, or entering your device PIN). This step is just to ensure you are the one creating the passkey. Once confirmed, the passkey (a secure key pair) is generated and stored. From then on, you can log in by approving a prompt on that device without typing a password. The next time you visit the site, it may say “Do you want to sign in with your passkey?” – and a simple tap of your fingerprint or Face ID will log you in.
• Use your device’s built-in passkey manager: Modern operating systems come with built-in support for passkeys and will usually handle storing and syncing them for you. For example, Apple’s iOS and macOS use iCloud Keychain to automatically save and sync passkeys across your Apple devices (iPhone, iPad, Mac) that are logged into the same iCloud account. Google’s Android and Chrome can likewise sync passkeys through the user’s Google Account (Google Password Manager). Using these built-in solutions is seamless – if you create a passkey on your phone, it can be available on your tablet or laptop via cloud sync . Make sure you’re signed into your device’s cloud account and that you have device backups enabled (so that if you lose a phone, your passkeys can be recovered on a new phone through iCloud or Google backup). Syncing is generally automatic once you opt-in, so you don’t have to manually copy anything. This cloud syncing of passkeys ensures you’re not locked to one device , and it keeps your credentials safe – they are typically end-to-end encrypted in the cloud, meaning even Apple or Google cannot read your private keys, but they can deliver them securely to your other devices.
• Consider a password manager for cross-platform syncing: If you use multiple platforms (say an iPhone and a Windows PC, or an Android phone and a Mac), you might benefit from a third-party password manager that supports passkeys. Services like 1Password, Dashlane, and Bitwarden have started integrating passkey support . For instance, 1Password can store your passkeys in your encrypted vault and sync them to all your devices (regardless of manufacturer) . This way, a passkey created on your phone can be used on your Windows laptop even if you’re not in the same ecosystem. Using a reputable password manager can be a great alternative or complement to the built-in phone/OS syncing. It’s worth noting that these managers also keep the passkeys encrypted and usually require you to log into the manager (with a master password or biometric) to retrieve them, adding an extra layer of security. If you already use a password manager for traditional passwords, check if it has added passkey capabilities – it can serve as a one-stop solution to manage both passwords and passkeys until all your accounts go fully passwordless .
• Using passkeys across devices: You might wonder, how do you log in with a passkey on a device where the passkey isn’t stored? For example, you created a passkey on your phone but now you want to log in from a friend’s computer or a work laptop. Websites handle this with what’s called cross-device authentication. Typically, when you choose “log in with a passkey” on a new device, the website will show a QR code or give an option like “Use a passkey from another device.” You can then scan that QR code with your phone (which has the passkey) or approve a Bluetooth prompt, and your phone will securely transmit the authentication to the new device . In practice, it might look like this: on the login screen you click “Use passkey from phone,” a QR code appears, you point your phone’s camera at it, and your phone pops up “Do you approve login to example.com?” – you confirm with Face ID or fingerprint, and the computer logs you in. This process uses a secure WebAuthn hybrid transport method (often referred to as caBLE – cloud-assisted Bluetooth Low Energy) to ensure the devices communicate safely . The takeaway for non-technical users is that yes, you can still use your passkeys even on a device that doesn’t have them saved. Just keep your phone handy if you need to do this, and follow the on-screen instructions – it usually involves scanning a code or verifying a number that pairs the devices. This way, you’re not strictly limited and you won’t get locked out as long as you have one trusted device with your passkeys.
• Protect your devices: Because passkeys shift security to your personal devices, it’s important to maintain good security hygiene on those devices. Always use a strong PIN or biometric to lock your phone, keep your devices updated with the latest OS security patches, and enable features like remote find/wipe in case of loss. The security of a passkey is only as strong as the security of the device that holds it. The good news is most modern phones and computers have very robust protection (secure enclaves, encrypted storage). Just avoid the temptation to disable your phone’s lock or add someone’s fingerprint who you don’t trust. Treat your devices like the keys to your accounts – because they are.
• Backup and recovery: In general, if you’re using an ecosystem (Apple or Google) or a password manager, your passkeys are backed up. However, it’s wise to have at least two devices enrolled for important accounts. For example, register a passkey on both your phone and your laptop for your email account. That way, if one is lost or in repair, you have the other. Some services may still provide a recovery mechanism (like a one-time backup code or the ability to fall back to password if you set one). Be aware of what recovery options each service offers and keep any backup codes in a safe place. As passkeys become more common, services will improve account recovery flows (for instance, allowing you to verify your identity through email or phone verification to bootstrap a new passkey if all devices are lost). For now, a simple rule is: register passkeys on multiple devices when you can, and don’t rush to delete your old password for an account until you’re confident you have passkey access on all the devices you need.
By following the above tips, even non-technical users can safely adopt passkeys. The experience is meant to be very intuitive: if you can unlock your phone, you can use a passkey. And using passkeys means you’ll no longer have to remember a litany of passwords or worry about whether you used your dog’s name for five different accounts. It’s a big win for security with minimal effort on the user’s part. As a final example, consider what a login looks like with a passkey: Instead of seeing a password box, you might see a button that says “Login with device” – you click it, your computer asks for your fingerprint (or your phone buzzes you to confirm), and within seconds you’re in. No typing, no forgetting, and no falling for phishing links. This simplicity is why passkeys are often touted as a user-friendly solution to the password problem.
Challenges and Future of PasskeysWhile passkeys hold a lot of promise, there are still challenges to overcome in their widespread adoption. One challenge is the ecosystem readiness – both services and users need to adopt new habits. As of 2023-2025, not every website or enterprise system supports passkeys yet, which means passwords aren’t gone overnight. Many organizations have legacy systems that may take time to upgrade to passwordless authentication. On the user side, familiarity is a factor: people are used to passwords and may be initially unsure about using their phone or biometric for third-party logins. There’s sometimes a misconception to dispel – for example, users might worry “if my phone is lost, do I lose all my accounts?” (which, as discussed, is manageable with backups). Education and awareness will need to catch up as we enter this new era.
For businesses, a recent survey highlighted perceived complexity and cost as the top obstacles in rolling out passkeys. About 43% of organizations not yet deploying passkeys cited implementation complexity as a concern, and one-third pointed to costs or lack of clear information . These concerns indicate that some IT decision-makers are still wrapping their heads around how to integrate passkeys into their infrastructure and how to budget for it. In reality, many modern platforms have passkey support built-in, and the long-term cost savings (fewer breaches, fewer password resets) can outweigh upfront expenses. To bridge the gap, increased enterprise education and robust tooling are emerging – from passkey SDKs and cloud services to guidance from groups like the FIDO Alliance and Yubico’s “Passkey Hub” for best practices. As success stories accumulate, the uncertainty is expected to diminish. It’s telling that in the same survey, 87% of companies said they have pilots or plans underway for passkeys, driven by goals of improved security, user experience, and compliance . In other words, despite the challenges, the momentum is strongly in favor of adoption across industries.
Another challenge is the matter of cross-platform and account recovery – essentially, handling the “what if I lose my device?” scenario. The industry has tackled this by introducing multi-device passkeys (cloud-synced) and by allowing multiple passkeys per account, but organizations will need to implement policies around it. Some high-security environments might be hesitant to allow cloud synchronization of credentials for fear of cloud compromise. In such cases, they may opt for device-bound keys (like smart cards or YubiKeys) which don’t sync. This is a trade-off between security assurance and convenience. NIST’s guidance, for example, suggests that synced passkeys are appropriate for most users (moderate assurance), but for the highest-risk scenarios, device-bound (non-syncable) passkeys offer an extra degree of control . We might see a future where companies classify accounts and assign the appropriate type of passkey – much like how some employees get privileged access tokens. For the average consumer, however, the synced model (with strong cloud encryption) will likely be the norm because it’s far more user-friendly. As the technology matures, cloud providers will continue to harden the security of passkey synchronization (for instance, using hardware security modules and end-to-end encryption so that even a cloud breach won’t expose keys). Additionally, standards for secure transfer or escrow of keys might develop, possibly involving user-controlled hardware backups. These are areas of active development, and the FIDO Alliance is working on protocols and best practices to ensure passkeys are both safe and convenient in all scenarios .
Looking ahead, the future of authentication appears to be firmly trending toward passwordless methods like passkeys. Tech giants are heavily investing in this direction – for example, Apple, Google, and Microsoft jointly announced support for passkeys in their platforms and have been rolling out updates to make them ubiquitous. This kind of industry alignment is rare and indicates a collective agreement that the password’s days are numbered. We can expect that in a few years, most mainstream services will prioritize passkeys or similar methods by default. Some experts predict that passkeys (or passwordless auth in general) will gradually replace passwords for the majority of use cases . It won’t happen overnight – there will be a transition period where passwords and passkeys coexist – but as more users get comfortable and more providers implement it, the network effect will kick in. It’s very possible that in the near future, using a password will be the exception rather than the rule, reserved only for legacy systems or as an emergency fallback. One survey of security professionals showed optimism that passkeys will go mainstream, yet a realistic understanding that complete replacement of passwords will take time and careful rollout .
In the enterprise future state, we might see organizations adopting full passwordless onboarding: new employees given corporate devices that use certificate-based or passkey-based login from day one, never receiving an account password at all. This not only improves security but also reduces IT overhead related to password resets and account lockouts. On the consumer side, the experience of logging into apps and websites will become smoother – no more creating a password when signing up, just create a passkey (which often happens with a single tap on a prompt). This could also boost security for users who otherwise might have foregone adding two-factor authentication. Passkeys make strong auth the path of least resistance, which is a win for everyone’s security.
Potential challenges in adoption that remain include ensuring universal support and addressing edge cases. There will always be some users who don’t have a compatible device (e.g. an old phone that can’t update to use passkeys) – solutions like fallback to OTP or providing a hardware token on request can cover these instances. There’s also the challenge of malicious software: if a user’s device is heavily infected with malware, could it abuse a passkey? The risk isn’t zero, but it’s still far less than keylogging a password, because using a passkey usually requires a user action (touch ID) and the crypto cannot be invoked without it. Nonetheless, keeping devices secure remains important. From a future development perspective, we can expect ongoing improvements. For example, standards for shared passkeysmay emerge (think of a family passkey that multiple members can use for a joint account login, with secure sharing mechanisms). There’s also talk of integrating passkeys with hardware like TPMs (Trusted Platform Modules) and secure elements to even better prevent export of keys. Another future angle is wider application: passkeys could expand beyond web/app logins to things like unlocking cars or IoT devices, as part of a general move to secure authentication tokens. They might also dovetail with digital identity initiatives – for instance, combining a passkey with a digital ID verification to prove your identity to a service without passwords.
In conclusion, passkeys represent a major leap forward in balancing security and usability. They directly tackle the weaknesses of passwords and most common MFA, making it significantly harder for attackers to compromise accounts while making it easier for users to log in safely. Both consumers and enterprises stand to benefit: users get a smoother login experience and far less risk of being phished, and organisations get stronger assurance of user identity with fewer support headaches. There are certainly challenges to iron out (as with any new technology), but the trajectory is clear. As standards bodies, cybersecurity agencies, and tech companies continue to refine the ecosystem, passkeys are poised to become a cornerstone of modern authentication. In the coming years, we’ll likely look back at text passwords the way we now look at dial-up internet – an old inconvenience we shed in favor of something faster and safer. The investment in passkeys today is an investment in a more secure and user-friendly digital future, for both enterprises safeguarding critical assets and individuals protecting their personal information online. The era of the password is giving way to the era of the passkey, and that is a positive development for cybersecurity.
Speak to Cool Waters Cyber for help with your Cyber projects, including managing your passkey migration. Lets #GetCyberSorted
Let's Talk
When your customers request ISO 27001 certification, it's because they need credible assurance that your information security is robustly managed. However, many businesses fall into the trap of obtaining an ISO 27001 certificate that isn't accredited by a recognised body like the United Kingdom Accreditation Service (UKAS). This mistake can lead to expensive consequences, including losing contracts and having to repeat the certification process.
At Cool Waters Cyber, our ISO 27001 implementation consultants frequently encounter scenarios where our clients’ end customers explicitly demand ISO 27001 certification issued by a UKAS-accredited audit body, or its international equivalent. This isn't just a technicality; it significantly impacts trust and business opportunities.
Why UKAS accreditation mattersUKAS accreditation means your certification body has itself been rigorously audited to ensure impartiality, consistency, and competence in issuing ISO certifications. An ISO 27001 certificate from a UKAS-accredited organisation carries genuine credibility and is universally recognised by procurement teams and auditors worldwide. Without it, you're potentially wasting resources on a certification that your key customers will reject.
Plan ahead – ISO 27001 certification takes time
Achieving ISO 27001 certification typically takes between 6 and 9 months from project kick-off to the completion of your Stage 2 audit and the issuance of the certificate. Waiting until a potential customer demands ISO compliance is simply too late. Businesses that proactively start their certification process position themselves to seize opportunities without delays or lost contracts.
**Affordable ISO 27001 with our new Pay Later service**Cool Waters Cyber understands that investing in ISO 27001 certification can be challenging for some businesses. That's why we've partnered with iwocaPay to offer a flexible Pay Later service. Our clients can now spread the cost of their entire ISO 27001 project—including penetration testing—over 12 months. This means you can start your journey toward compliance sooner and be fully prepared for future opportunities when they arise.
Avoiding bureaucracy with practical ISO 27001 implementationAchieving ISO 27001 certification doesn't mean your business has to drown in red tape. The right implementation partner knows how to integrate ISO 27001 compliance seamlessly into your daily operations, enhancing your security posture without unnecessary complexity or overhead.
Our ISO 27001 experts at Cool Waters Cyber don't just shout instructions from the sidelines; they roll up their sleeves and work directly alongside your teams. They understand modern business dynamics and how crucial it is to maintain operational agility while embedding robust security controls. Their hands-on approach ensures your ISO project delivers real value, tangible improvements, and successful certification outcomes.
Choose the right partner for your ISO 27001 journeyDon’t risk costly mistakes or unnecessary bureaucracy. Choose a partner who understands the nuances of ISO 27001, appreciates the importance of UKAS accreditation, and actively participates in your project’s success. At Cool Waters Cyber, we ensure your investment in ISO 27001 delivers exactly what your customers demand—credible, reliable assurance of your information security management.
If you're embarking on ISO 27001 certification or need expert support, reach out to our team today and #GetCyberSorted
Book a free consultation
What are Passkeys?Passkeys are a new, safer, and simpler way to log in to your online accounts without using traditional passwords. Instead of remembering and typing complicated passwords, passkeys allow you to securely log in using your device (like your phone or laptop), fingerprint, face recognition, or a secure PIN.
Why are Passkeys Better than Passwords? More Secure: Passkeys protect you from phishing attacks because they can’t be stolen or tricked out of you by a fake website. * Easier to Use: No more remembering or resetting forgotten passwords. * Faster Login:* Use your fingerprint, face, or PIN instead of typing out passwords.
Passkeys and Multi-Factor Authentication (MFA)Using passkeys automatically counts as Multi-Factor Authentication (MFA), essential for Cyber Essentials compliance. MFA requires at least two forms of proof to access your account:
Passkeys seamlessly meet this MFA requirement because your device and your biometric or PIN provide two separate proofs of identity.
Practical Example: Setting Up a Passkey for Microsoft365Here’s how you can set up your Microsoft365 account with a passkey:
Follow the prompts on your device:
Managing Your PasskeysYou’ll likely have passkeys for multiple accounts. Here’s how you can manage them easily:
Expect More Passkeys SoonYou’ll soon see passkeys becoming the default option for most online services, significantly enhancing your online safety and simplifying your digital life.
Stay secure, simplify your login, and #GetCyberSorted!
For decades, the construction industry has worked tirelessly to improve health and safety culture. What was once a regulatory headache has transformed into a core business value, saving lives and improving project outcomes.
Now, a new safety frontier is emerging—one that construction firms can no longer ignore: Cyber Safety.
With construction sites becoming more digital—using cloud-based project management, Building Information Modelling (BIM), IoT-connected machinery, and remote working tools—the threat of cyberattacks has never been greater. A single compromised email could lead to financial fraud, a hacked supplier system could halt an entire project, and ransomware could bring a construction firm’s operations to a standstill.
Yet, many construction companies still see cybersecurity as just an IT issue. In reality, it should be treated just like physical safety: everyone’s responsibility, built into everyday working life.
🚧 From Hard Hats to Firewalls: The Evolution of Safety in Construction 🚧Our latest white paper, “It’s all just #Safety - the next evolution of safety culture”, explores how safety thinking has evolved over the decades—from physical protection, to mental well-being, and now, to cyber safety.
Inside the report, you’ll discover:
✔️ How health and safety evolved from a fringe concern to a core business value.
✔️ Why mental well-being is now a critical part of workplace safety.
✔️ How cyber threats are the next major risk facing construction firms—and why ignoring them could be catastrophic.
✔️ What construction leaders can learn from decades of safety culture improvements to build a strong cyber safety culture.
🔽 Download the full report to get the complete insights. 🔽
👉 [Register here to download the full report]
💡 A 6-Point Action Plan to Build Cyber Safety into Everyday Construction WorkThe report doesn’t just explore the problem—it provides solutions.
At Cool Waters Cyber and Cyber Coach, we’ve developed a 6-Point Cyber Safety Action Plan designed specifically for construction firms.
This practical, easy-to-follow plan helps construction companies:
✅ Make cyber safety a leadership priority—discuss cyber risks in the same breath as physical and mental safety.
✅ Empower employees with real-world cyber training—help teams spot phishing scams, invoice fraud, and other cyber threats.
✅ Encourage reporting of cyber near-misses—just like physical hazards, cyber incidents should be reported before they cause real damage.
✅ Secure digital tools and supply chains—ensure third-party vendors, mobile devices, and on-site technology meet strong security standards.
✅ Align cybersecurity with compliance—integrate cyber safety into safety audits and regulatory frameworks.
✅ Create a cyber safety-first culture—making security an everyday habit, just like PPE and risk assessments.
📢 Want to future-proof your business?
📥 Download the full report now and get the complete 6-Point Cyber Safety Action Plan!
🔽 [Get Your Copy Here] 🔽
Why This Matters NOW 🚀Cybercrime is rising rapidly in the construction industry. Last year alone, UK businesses lost millions due to cyberattacks targeting construction firms. The good news? Those who prepare NOW can dramatically reduce their risk.
Our report outlines real steps construction companies can take today to integrate cybersecurity into their existing safety culture.
✅ Don’t wait until a cyber incident disrupts your business.
✅ Don’t let weak security put your projects, finances, and reputation at risk.
✅ Take action NOW to build a strong, cyber-resilient construction business.
🔹 Ready to get started?
📥 Download the full white paper and get the 6-Point Cyber Safety Action Plan today.
👉 [REGISTER NOW TO GET YOUR COPY]
Many small and medium-sized businesses (SMBs) believe that ISO 27001 certification is something only large corporations need. After all, isn’t cybersecurity just an issue for massive enterprises with thousands of employees and deep pockets?
The truth is, cyber threats don’t discriminate based on company size. In fact, the latest NCSC Annual Review 2024confirms that smaller businesses are prime targets for cybercriminals, particularly those handling sensitive data or sitting in the supply chain.
Yet, many businesses wait until a client or regulator demands certification before acting. The problem? ISO 27001 certification is not instant—it typically takes 6-9 months. By the time you scramble to get compliant, the business opportunity that required it has already passed you by.
Let’s explore why ISO 27001 isn’t just for large enterprises and why getting certified proactively is the best move for your business.
Small Businesses Are Prime Cybercrime TargetsA common misconception is that cybercriminals only go after large organisations. However, the NCSC 2024 Annual Review highlights that ransomware, phishing, and supply chain attacks continue to be top threats to UK businesses of all sizes.
Why SMBs are Attractive Targets:✔ Weaker Defences: Many SMBs lack dedicated security teams, making them easier targets. ✔ Valuable Data: SMBs handle sensitive customer and financial data, which attackers can exploit. ✔ Supply Chain Weakness: Cybercriminals often target smaller suppliers to gain access to larger companies.
💡 ISO 27001 helps SMBs defend against these threats by establishing a structured, globally recognised framework for cybersecurity.
Waiting Until You ‘Need’ ISO 27001 is a Costly Mistake We often hear businesses say:
🔹 “We’ll worry about ISO 27001 when a client asks for it.”
🔹 “We’re too small to need certification right now.”
🔹 “We’ll do it next year when we have more time.”
Here’s the reality: If you wait until you need ISO 27001, it’s already too late.
ISO 27001 Takes 6-9 Months – Longer If You’re UnpreparedISO 27001 isn’t a quick box-ticking exercise—it’s a strategic security transformation. Most companies take 6-9 monthsto become fully certified, as the process includes: ✅ Gap analysis – Identifying where your security practices fall short.
✅ Risk assessments – Understanding what needs to be protected.
✅ Security controls implementation – Putting in place the required policies and measures.
✅ Internal audits – Ensuring everything is working as intended.
✅ External certification audit – Passing the formal assessment to achieve certification.
📌 By the time you start the process, that potential contract or client requiring ISO 27001 may already be gone.
ISO 27001 Opens Doors – Don’t Let Certification Be a DealbreakerISO 27001 isn’t just about protecting your business—it’s also a competitive advantage.
🔹 Many corporate clients require suppliers to be ISO 27001 certified before signing contracts.
🔹 Public sector contracts increasingly favor vendors with strong cybersecurity credentials.
🔹 Investors and partners see ISO 27001 as a sign of long-term business stability and security.
💡 Getting certified before it’s required puts you ahead of competitors and ensures you never have to say no to a business opportunity.
How Cool Waters Cyber Makes ISO 27001 EffortlessMany companies hesitate to pursue ISO 27001 because they think it’s complex, time-consuming, and expensive. That’s why Cool Waters Cyber makes compliance simple, efficient, and fully managed.
✅ We handle all the work for you – daily, weekly, and monthly compliance tasks.
✅ We take care of risk assessments, policy creation, and ongoing monitoring.
✅ We don’t just get you certified—we keep you certified year-round.
🚀 And right now, we’re offering a special deal: Sign up for our ISO 27001 Compliance-as-a-Service and get ISO 9001 Compliance-as-a-Service FREE for the first year!
Get Ahead, Stay Secure, and Win More BusinessISO 27001 is not just for large enterprises—it’s a powerful security and business growth tool for SMBs looking to stay competitive, win bigger contracts, and protect their reputation.
If you wait until you need certification, it may already be too late. But by acting now, you’ll position your business for long-term success.
📞 Ready to future-proof your business? Contact Cool Waters Cyber today for a free consultation!
Achieving ISO 27001 certification is a significant milestone for any business—it demonstrates a commitment to protecting sensitive information and managing cybersecurity risks. However, many organizations make a critical mistake: they view certification as the finish line rather than the beginning of an ongoing process.
Cyber threats are not static, and compliance should not be either. Without continuous compliance, businesses risk falling out of certification, exposing themselves to security breaches, and damaging their reputation.
At Cool Waters Cyber, we take a different approach—we ensure that ISO 27001 compliance is not just a one-time achievement but an integral part of your daily operations. Our experience supporting companies like MindCraft and Zappit has shown that organizations gain the most value from ISO 27001 when it becomes part of their business DNA. Let’s explore why continuous compliance matters and how it can benefit your business.
Why Continuous Compliance is EssentialCyber Threats Evolve DailyCybercriminals are constantly developing new ways to exploit vulnerabilities. If your organisation only focuses on compliance during the initial certification process, you may find yourself unprepared for new threats that emerge after your audit.
Real-World Example: When Zappit, a marketing technology firm handling GDPR-protected personal data, pursued ISO 27001 certification, they needed more than just a one-time audit. Their IT environment was dynamic, with new features being added every month. Cool Waters Cyber provided continuous security monitoring and risk assessment reviews, ensuring that Zappit maintained compliance beyond certification and even passed its second annual surveillance audit with no non-conformities.
Solution: Continuous risk management ensures that evolving threats are identified and mitigated before they can be exploited.
Compliance Drifts Without Ongoing ManagementISO 27001 is built around the Information Security Management System (ISMS), which requires ongoing monitoring, reviewing, and improving security controls. Without regular attention, compliance deteriorates, increasing the risk of security gaps and audit failures.
Real-World Example: MindCraft, a boutique digital consultancy working with public sector clients, initially lacked a formal security team. Without dedicated compliance oversight, maintaining ISO 27001 would have been a challenge. Cool Waters Cyber provided managed compliance-as-a-service, handling daily, weekly, and monthly security tasks. This approach allowed MindCraft to pass certification in just four months, with no non-conformities, and maintain compliance effortlessly.
Solution: Implementing a continuous compliance framework ensures that all required controls are consistently reviewed and updated.
Protecting Your Business ReputationISO 27001 certification is more than a compliance requirement—it’s a trust signal for customers, partners, and stakeholders. Falling out of compliance not only puts your data at risk but can also result in lost business opportunities.
Real-World Example: Zappit’s Tier 1 global brand clients demanded independent verification of their platform’s security. By implementing ISO 27001 and ensuring ongoing compliance with Cool Waters Cyber’s support, Zappit strengthened its security posture and gained a competitive advantage in the marketplace.
Solution: Continuous compliance ensures that your certification remains active and verifiable, reinforcing trust with customers and partners.
How Cool Waters Cyber Makes ISO 27001 Compliance EffortlessMany cybersecurity firms walk away after the initial certification audit, leaving businesses to manage compliance on their own. At Cool Waters Cyber, we take a different approach.
Daily, Weekly, and Monthly Compliance Tasks: We handle all the routine security activities needed to maintain your certification, from risk assessments to security policy updates.
Automated Monitoring & Regular Audits: We provide continuous oversight to ensure your ISMS remains compliant every day—not just once a year.
Ongoing Support & Expert Guidance: We act as your dedicated compliance partner, providing expert cybersecurity advice and immediate support when risks arise.
Our work with clients like MindCraft and Zappit proves that a proactive approach to ISO 27001 compliance doesn’t just keep businesses secure—it also enhances reputation, improves operational efficiency, and opens new market opportunities.
Compliance is a Continuous Journey ISO 27001 certification is not the finish line—it’s just the beginning of a strong cybersecurity posture. Businesses that fail to embed compliance into their daily operations risk falling behind and exposing themselves to unnecessary threats.
With Cool Waters Cyber’s Compliance-as-a-Service, your ISO 27001 certification is effortless and continuous—so you can focus on growing your business with confidence.
📞 Want to ensure your ISO 27001 compliance never slips? Contact us today for a free consultation!
Let's Talk - Book a Meeting #ISO27001 #ContinuousCompliance #CyberSecurity #EffortlessCompliance #CoolWatersCyber #GetCyberSorted
In today’s interconnected digital landscape, the importance of robust cybersecurity measures cannot be overstated. Recent events have highlighted vulnerabilities that, if left unaddressed, can have severe repercussions for businesses of all sizes. This article delves into three significant incidents, elucidating their implications and offering actionable steps for business leaders to fortify their organisations against similar threats.
The Bybit Cryptocurrency Heist: A Stark Reminder of Digital VulnerabilitiesIn a recent high-profile cyberattack, approximately $1.5 billion was illicitly siphoned from the Dubai-based cryptocurrency exchange, Bybit. The breach, attributed to North Korea’s notorious Lazarus Group, involved unauthorised access to an Ethereum cold wallet, marking one of the most substantial cryptocurrency thefts to date.
Implications for BusinessesFinancial Exposure: Even if your enterprise doesn’t engage directly with cryptocurrencies, the methodologies employed in such attacks can be adapted to target traditional financial assets.
Erosion of Trust: A security breach can severely damage client trust and tarnish your brand’s reputation, leading to potential loss of business and revenue.
Protective Measures:Implement Multi-Factor Authentication (MFA): Enhance security by requiring multiple forms of verification for system access, thereby reducing the risk of unauthorised entry.
Conduct Regular Security Audits: Periodic assessments can help identify and rectify vulnerabilities within your systems, ensuring they remain robust against evolving threats.
Invest in Employee Training: Educate your staff about phishing and social engineering tactics, empowering them to recognise and thwart potential threats before they manifest.
Australia’s Prohibition of Kaspersky Products: Navigating Supply Chain SecurityThe Australian government has recently banned the use of Kaspersky Lab products across all its agencies, citing concerns over potential security risks associated with foreign interference and espionage. We started advising clients to migrate away from Kaspersky over 18 months ago due to these concerns and now several countries (including Australia and the USA) are issuing the same official advice.
Implications for BusinessesSupply Chain Vulnerabilities: Utilising software from certain vendors may introduce unforeseen vulnerabilities, especially amidst geopolitical tensions.
Regulatory Compliance Challenges: Businesses must remain vigilant and informed about governmental directives to ensure compliance and avoid potential legal and operational repercussions.
Protective MeasuresConduct Thorough Vendor Risk Assessments: Regularly evaluate the security posture of third-party vendors and their products to ensure they align with your organisation’s security standards.
Diversify Security Solutions: Avoid over-reliance on a single vendor by implementing a multi-layered security approach, thereby enhancing resilience against potential vulnerabilities.
Stay Informed and Agile: Keep abreast of governmental advisories and global cybersecurity trends, adjusting your security infrastructure proactively to navigate the dynamic threat landscape.
Exploitation of PayPal’s “New Address” Feature: The Perils of Trusted PlatformsCybercriminals have been found exploiting PayPal’s “New Address” feature to dispatch phishing emails directly from PayPal’s official domain. These deceptive emails, appearing legitimate, aim to trick recipients into divulging sensitive information.
Implications for BusinessesElevated Phishing Risks: Even trusted platforms can be manipulated to launch sophisticated phishing attacks, making it imperative for businesses to remain vigilant.
Potential Data Breaches: Employees may inadvertently disclose confidential information, leading to data breaches that can have legal and financial consequences.
Protective MeasuresEstablish Robust Email Verification Protocols: Encourage meticulous scrutiny of email addresses and domains, even if they appear authentic, to detect potential anomalies. Use the ‘report phishing’ features of Outlook to train both the phishing filters and your team’s vigilance.
Implement Phishing Simulations: Regularly test employees with simulated phishing attacks to enhance their awareness and response to real threats.
Secure Communication Channels: Develop and enforce protocols for verifying requests for sensitive information through multiple channels to confirm authenticity before action.
ConclusionThese incidents underscore the ever-evolving nature of cyber threats in our digitally driven world. For business leaders, adopting a proactive and comprehensive approach to cybersecurity is not merely a technical necessity but a strategic imperative. By implementing the measures outlined above, organisations can significantly mitigate their vulnerability to such attacks, safeguarding their assets, reputation, and operational continuity.
At Cool Waters Cyber, we are committed to assisting businesses in navigating the complexities of cybersecurity. Our expertise spans compliance certifications, managed security services, and tailored training programs designed to fortify your organisation’s defences. Together, we can build a resilient digital future.
Trish and Tom - your podcast hosts
We’ve launched a new podcast, which covers everything business leaders need to know about cyber security and how to protect your organisation against ransomware, data breachers and other cyber threats.
Short, to the point and not too techie, this is business centric and practical.
Here’s a link to episode 1 which explores several recent and upcoming changes to the law in the UK and EU and a summary of the key messages from Felicity Oswald, the CEO of the UK National Cyber Security Centre, who gave a speech on threats facing UK business at the CYBERUK conference recently.
Enjoy!
If you need help to improve your cyber security, talk to us.
Subscribe to Podcast
St James’s Place is a pioneer in the list of major UK organisations that are requiring their supply chain and partners to be certified to the Cyber Essentials Plus standard.
Alongside leading UK businesses such as:
In today’s hyper-connected world, cybersecurity is no longer optional—it’s an essential foundation for business resilience and trust. Recognizing this, St. James’s Place (SJP) has mandated its partners to obtain Cyber Essentials Plus certification, reinforcing their commitment to safeguarding sensitive information and ensuring regulatory compliance. At Cool Water Cyber, we specialize in simplifying this journey, offering a fully managed service to help you achieve certification with ease.
What is Cyber Essentials?Cyber Essentials is a government-backed scheme developed by the National Cyber Security Centre (NCSC) to protect organizations against the most common cyber threats. The scheme provides businesses with a clear framework to strengthen their cybersecurity, focusing on five key areas:
1.Firewall and internet gateways: Ensuring secure connections on your network.
2.Secure configuration: Optimizing settings on your computers for maximum protection.
3.Access control: Limiting user access to data and systems.
4.Malware protection: Safeguarding against malicious software and viruses.
5.Patch management: Keeping systems updated to fix vulnerabilities.
Why is St. James’s Place Requiring Cyber Essentials Certification?In today’s evolving threat landscape, SJP understands that its reputation and client trust rely on robust cybersecurity measures across its partner network. Cyber Essentials certification ensures partners align with best practices, protecting sensitive client information and reducing vulnerability to cyberattacks.
Moreover, according to the NCSC’s 2024 Annual Review, organizations with Cyber Essentials certification are 92% less likely to make a claim on their cyber insurance—a clear testament to its effectiveness in mitigating risks.
The Effectiveness of Cyber EssentialsThe NCSC’s 2024 report highlights the importance of adopting basic cybersecurity measures like Cyber Essentials:
How Cool Water Cyber Makes Certification EasyAt Cool Water Cyber, we understand the challenges of navigating cybersecurity frameworks. That’s why we’ve developed a fully managed service tailored to your needs:
The Bottom Line: A Secure & Compliant Future Starts TodayAdopting Cyber Essentials is more than achieving compliance; it’s a statement of intent to protect your business, your clients, and your future. With Cool Water Cyber by your side, you can embrace the benefits of certification without the stress of navigating the process alone.
Ready to achieve Cyber Essentials certification? Contact Cool Water Cyber today and let us guide you to a more secure tomorrow. Let’s talk
Speak to a Cyber Essentials Advisor
This summer the EFSA announced new Cyber Security rules that will apply to colleges and special post-16 institutions (SPIs) in England from the 2024-2025 funding year.
“For the 2024 to 2025 funding year, Department for Education (DfE) is changing the requirements regarding IT security for colleges and special post-16 institutions (SPIs).
Colleges and SPIs will now be required to achieve cyber essentials during the 2024 to 2025 funding year. The requirement to obtain an annual IT health check will be removed.
IASME, the National Cyber Security Centre’s (NCSC) cyber essentials delivery partner, has created useful guidance documents for schools which also apply to colleges. ”
— EFSA EFSA advises Colleges to work with an NCSC Cyber Advisor or local certification body in order to smooth the journey to Cyber Essentials certification.
Cool Waters Cyber is Cornwall’s only NCSC Cyber Advisor and Cyber Essentials Certification body and our team of cyber experts includes ex-teachers and school administrators, making us the ideal choice for your Cyber Essentials project.
Cyber Essentials Guidance for Colleges and Schools The government-approved Cyber Essentials scheme encompasses five technical controls designed to protect organizations from the most prevalent cyber attacks. Cyber Essentials offers a clear method for elevating your school’s or college’s cybersecurity to the minimum level recommended by the government. It serves as an effective baseline to ensure that your educational institution is adequately protected.
How does Cyber Essentials work?Cyber Essentials is a verified self-assessment where colleges answer questions on a secure portal. A senior board member signs off, and a qualified assessor reviews the answers. Questions cover the IT network scope, staff, devices, cloud services, software, and five technical controls: access control, secure configuration, security update management, firewalls, and malware protection. This certification process helps schools and colleges understand and improve their cyber security.
How much does it cost?The Cyber Essentials verified self-assessment questions are available for free download. The cost of certification varies depending on the size of the school or college seeking certification. For assessment purposes, your organisation includes all parts of your school and any other schools that share the same network.
The UK government defines the size of an organisation based on the number of employees. In the education sector, employees are the paid staff employed by the school or trust. Students are considered more like customers rather than employees in this certification process. School governors are not technically employees, but if they access business information (such as work emails) and services, they must be included when calculating the size of your organisation. Additionally, if the governors use their devices to access any school systems or data, those devices will fall within the scope of this assessment.
0-9 Employees - £320 + VAT
10-49 Employees - £440 + VAT
50-249 Employees - £500 + VAT
250+ Employees - £600 + VAT
UK-based colleges with funding under £20m that certify to Cyber Essentials and include the entire college in the assessment are eligible for cyber liability insurance with a £25,000 limit.
Getting ready for Cyber Essentials for your SchoolDownload the Cyber Essentials self-assessment questions and Requirements for Infrastructure Document for free from the IASME website.
Decide whether you will complete the assessment questionnaire yourself or if assistance is needed to understand the questions and how they apply to your school or college. Preparing your assessment answers in advance using a working document or spreadsheet is advisable. This approach allows you to address any compliance issues that may take longer to resolve.
For professional cyber security advice, contact us - Cornwall’s only NCSC assured Cyber Advisor and licensed IASME Certification Body.
Cyber Advisors are cyber security consultants who have passed an NCSC assessment and work for an Assured Service Provider. We can assist your college in implementing basic cyber security measures and achieving Cyber Essentials certification. Our advisors have been evaluated for their ability to understand and communicate with smaller organisations to provide appropriate and practical cyber security support.
Learn more
“All charities ultimately rely on public trust and continued public generosity. The impact of any cyber-attack on a charity can be devastating, undermining public confidence and support.”
— CEO, UK Charities Commission October is National Cyber Security Awareness Month, and at Cool Waters Cyber, we are dedicated to empowering charities to bolster their cyber defences. As the digital landscape evolves, the risks from cybercrime continue to grow, making it essential for all organisations, especially charities, to stay vigilant and secure.
Why Cyber Security Matters for CharitiesHelen Stephenson, recent Chief Executive of the Charity Commission for England and Wales, emphasizes, “All charities ultimately rely on public trust and continued public generosity. The impact of any cyber-attack on a charity can be devastating, undermining public confidence and support.” Cyber Essentials, a UK government-backed scheme, is a foundational standard in cyber security, offering crucial protection against common cyber threats.
Exclusive October Offer for CharitiesIn recognition of National Cyber Security Awareness Month, Cool Waters Cyber is pleased to offer a 10% discount on our managed Cyber Essentials and Cyber Assurance services for any charity that signs up in October 2024. This is an excellent opportunity for charities to fortify their cyber defences while benefiting from expert guidance and support – and a greater discount that the one offered by IASME for charities this month.
Benefits of Cyber EssentialsCyber Essentials helps guard against the most common cyber threats and demonstrates a charity’s commitment to cyber security. According to the UK National Cyber Security Centre:
· 93% of certified organisations are confident that they are protected against common, Internet-based cyber-attacks.
· Certified organisations are 80% less likely to need to claim on their cyber insurance.
Achieving Cyber Essentials not only enhances your charity's security but also opens up new avenues for funding, as grant-making bodies increasingly require Cyber Essentials certification from applicants.
Obtaining a recognised cyber security certification is a cost effective way to demonstrate to your stakeholders that the charity has taken all reasonable steps to protect their data and operational systems from cyber-attack. For more information, download free copy of the Trustees Guide to Cyber Essentials from our website: https://www.cool-waters.co.uk/cyber-essentials-for-charities
Join Us in Strengthening Your Cyber SecurityTake advantage of our special offer this October and ensure your charity is well-protected against cyber threats. Our team at Cool Waters Cyber is here to help you navigate the certification process with ease and confidence.
To learn more about our ‘Cyber Essentials with Managed Compliance’ service, which guarantees a first-time pass by ensuring you have all the necessary processes and policies in place, visit our website. You can also book a free initial consultation with a Cyber Essentials expert and obtain a quote tailored to your charity’s needs.
Visit our website today and secure your charity's future: https://www.cool-waters.co.uk/cyber-essentials-for-charities
Let's work together to make this National Cyber Security Awareness Month a stepping stone towards a more secure digital environment for all charities.
Set up a free, no obligation consultation
A Case Study of Two Customers: MindCraft and ZappitIntroductionISO 27001 is the international standard for information security management systems. It provides a framework for establishing, implementing, maintaining, and improving the security of an organisation's information assets. Achieving ISO 27001 certification demonstrates that a business has implemented best practices for protecting its data, systems, and customers from cyber threats.
However, achieving ISO 27001 certification is not an easy task. It requires a lot of time, resources, and expertise to conduct a gap analysis, implement the necessary controls, document the policies and procedures, and undergo an audit by an accredited certification body. For many small and medium-sized businesses, this can be a daunting and costly challenge, especially if they lack the in-house skills and experience to manage the project.
That's where Cool Waters Cyber comes in. Cool Waters Cyber is a cyber security consultancy that offers compliance-as-a-service for firms seeking ISO 27001 accreditation. Cool Waters Cyber provides end-to-end support for the entire certification process, from planning and scoping, to implementation and testing, to audit and maintenance. Cool Waters Cyber leverages its team of certified experts, proven methodologies, and cutting-edge tools to deliver the project on time and on budget, leaving the customers free to focus on their core business activities.
In this case study, we will look at how Cool Waters Cyber helped two of its customers, MindCraft and Zappit, achieve ISO 27001 certification, and how this benefited their businesses.
MindCraft: A boutique digital consultancy MindCraft provides digital advisory, service management and IT transformation services to mainly public sector clients across various industries. They also offer custom software development, cloud migration, and complex project and programme management expertise, priding themselves on delivering high-quality solutions that meet challenging and specific customer needs and expectations.
As an IT service provider, MindCraft handles sensitive and confidential information from its clients, such as financial data, personal data, and intellectual property. MindCraft understands the importance of protecting this information from unauthorised access, disclosure, modification, or loss. Therefore, MindCraft decided to pursue ISO 27001 certification to demonstrate its commitment to information security and to gain a competitive edge in the market.
However, MindCraft faced some challenges in achieving ISO 27001 certification. First, MindCraft did not have a dedicated information security team or a formal information security management system in place. Second, MindCraft had limited resources and time to devote to the certification project, as it had to balance the demands of its existing and new customers. Third, MindCraft lacked the expertise and experience to navigate the complex and rigorous requirements of ISO 27001.
That's why MindCraft turned to Cool Waters Cyber for help having worked with them on another project to manage ISO 27001compliance for a large public sector project: the A303 Stonehenge tunnel bypass. Cool Waters Cyber assigned a dedicated project manager and consultants to work with MindCraft on the certification project. Cool Waters Cyber conducted a gap analysis to identify the current state of MindCraft's information security and the areas that needed improvement. Cool Waters Cyber then developed a project plan and a roadmap to implement the necessary controls, policies, and procedures to meet the ISO 27001 standard. Cool Waters Cyber also provided training and awareness sessions to MindCraft's staff to ensure they understood their roles and responsibilities in the information security management system. Cool Waters Cyber also conducted regular reviews and tests to monitor the progress and effectiveness of the project. Finally, Cool Waters Cyber prepared MindCraft for the audit by a UKAS accredited certification body and supported them throughout the audit process.
As a result of Cool Waters Cyber's compliance-as-a-service, MindCraft achieved ISO 27001 certification within four months, with no non-conformities or issues. MindCraft was able to demonstrate to its clients and stakeholders that it had implemented a robust and reliable information security management system that met the international best practices. MindCraft also gained the following benefits from ISO 27001 certification:
MindCraft's CEO, Angus Walker, said: "We are very pleased with the outcome of the ISO 27001 certification project. Cool Waters Cyber did an excellent job of leading and managing the project, providing us with the resources and expertise we needed to achieve our goal. Cool Waters Cyber became very much part of our team. They were professional, responsive, and flexible throughout the project, and they delivered on time and on budget. We would highly recommend Cool Waters Cyber to anyone looking for a cyber security partner to help them achieve ISO 27001 certification."
Zappit: A Marketing Technology Firm Zappit is a marketing technology firm that offers a suite of innovative solutions for coupon and cashback based marketing and customer care. Zappit helps its customers optimise their marketing campaigns, increase their conversions, and grow their revenue.
As a marketing technology firm, Zappit collects and processes large amounts of data from its customers and their end-users including GDPR protected personal information. Zappit respects the privacy and security of this data and wanted to ensure it is was protected and secure at all times and this protection had been independently verified.
Therefore, Zappit decided to pursue ISO 27001 certification to enhance its information security capabilities and to demonstrate its compliance with the data protection laws and regulations. Zappit also wanted to achieve ISO 27001 certification to differentiate itself from its competitors and to attract more customers who value data security and privacy.
However, Zappit faced some challenges in achieving ISO 27001 certification. First, Zappit had an agile and dynamic IT environment and its internal team was already working flat out to deliver the innovative solutions promised to their clients. Second, Zappit’s clients, often tier 1 global brands, were increasingly asking for independent verification of their platform's security. Third, Zappit had a diverse and distributed workforce, with employees working from different locations and countries.
That's why Zappit turned to Cool Waters Cyber for help to provide day to day managed cyber security and to gain ISO 27001 certification. Cool Waters Cyber assigned a dedicated project manager and ISO 27001 expert to work with Zappit on the certification project and cyber security experts to be Zappit’s cyber security team including a Chief Information Security Officer (CISO) to lead Zappit’s security strategy. Cool Waters Cyber conducted a comprehensive risk assessment to identify the potential threats and vulnerabilities that Zappit faced in its IT environment and its business processes. Cool Waters Cyber then developed a project plan and a roadmap to implement the necessary controls, policies, and procedures to mitigate the risks and to meet the ISO 27001 standard. Cool Waters Cyber also provided training and awareness sessions to Zappit's staff to ensure they understood their roles and responsibilities in the information security management system. Cool Waters Cyber conducted regular reviews and tests to monitor the progress and effectiveness of the project. Finally, Cool Waters Cyber prepared Zappit for the audit by a UKAS accredited certification body and supported them throughout the audit process.
As a result of Cool Waters Cyber's compliance-as-a-service, Zappit achieved ISO 27001 certification within nine months, with no non-conformities or issues and have just passed their second annual surveillance audit – again with no non-conformities or issues being discovered. Zappit was able to demonstrate to its customers and stakeholders that it had implemented a robust and reliable information security management system that met the international best practices. Zappit also gained the following benefits from ISO 27001 certification:
Zappit's CEO, Mark Fraser, said: "We are very happy with the outcome of the ISO 27001 certification project and working with the team at Cool Waters Cyber. They do an outstanding job of managing our day-to-day cyber security and compliance – leaving my team free to focus on delivering our projects and platform innovations. Cool Waters Cyber were professional, responsive, and flexible throughout the project, and they delivered the project on time and on budget. I’d recommend Cool Waters Cyber to anyone looking for a cyber security partner to help them achieve ISO 27001 certification or provide an outsource managed cyber security team."
ConclusionCool Waters Cyber is a cyber security consultancy that offers compliance-as-a-service for firms seeking ISO 27001 accreditation. Cool Waters Cyber provides end-to-end support for the entire certification process, from planning and scoping, to implementation and testing, to audit and maintenance. Cool Waters Cyber leverages its team of certified experts, proven methodologies, and cutting-edge tools to deliver the project on time and on budget, leaving the customers free to focus on their core business activities.
In this case study, we have seen how Cool Waters Cyber helped two of its customers, MindCraft and Zappit, achieve ISO 27001 certification, and how this benefited their businesses. Both customers were able to demonstrate their commitment to information security and compliance, enhance their reputation and trust, increase their customer satisfaction and loyalty, reduce their risk of data breaches and cyber attacks, improve their operational efficiency and performance, and access new markets and opportunities.
If you are interested in learning more about Cool Waters Cyber's compliance-as-a-service offering, or if you want to start your ISO 27001 certification journey, please contact us at daniel@cool-waters.co.uk or visit our website at www.cool-waters.co.uk.
Download PDF of this case study
The Cyber Coach recording studio is up and running again this week to record new security awareness training videos for 2024. These videos are available to our clients on our bespoke Cyber Coach training platform https://www.cybercoa.ch/
But why take over our office every year to create this training content? Surely doing other work is much more important than ‘training’…?
A key defence against cyber attacks is a well-educated team. According to the UK National Cyber Security Centre (NCSC), one of the most significant threats faced by business and individuals in the UK is cyber fraud. With the rise of cyber-crime-as-a-service it is easier than ever to for anyone to get started as a cyber criminal – and so the number of attacks organisations face continues to rise.
80% of cyber breaches are down to human error! Having a cyber-aware team that know how to avoid falling for phishing emails or malicious websites, the importance of keeping their software up to date, and how to report a potential issue if they spot one can become your biggest cyber security asset.
You may already be implementing technical protections, such as anti-virus software, however this is not the only element of cyber security. Antivirus software can help protect your devices from malware, and some anti-virus software will even successfully block phishing attacks. However, this is only possible if the attack methods are well-known and documented. Many phishing attacks are brand new (known as zero-day attacks), so not all attempts will be recognised and prevented by software. This is one reason why the NCSC recommends a multi-layered approach to phishing defences. Proper training of users - to spot phishing attempts and to report them – can ensure much greater protection against phishing attacks for your business.
UK businesses are also at risk of ransomware attacks – a type of malware attack that results in file encryption or data theft, with the criminals demanding a financial ransom to return access to your data, or promise to delete it and not publish it online. The NCSC says this is the largest risk facing medium and large organisations. Ransomware is often distributed through malicious websites, which could be linked to from emails or messages. These messages often display many of the same techniques used in phishing emails, so education of staff against phishing can also protect your business against other cyber attacks.
Cyber security can feel like a tricky subject to approach, especially from a non-technical background. One of the things we like to do is break down the barriers to understanding cyber security, in a simple and entertaining way.
Cyber Coach Security Awareness Training can turn your team into a security asset rather than a security risk. Your staff are often the last line of defence against a cyber attack and can mean the difference between an attack failing or succeeding. Providing training to your staff to support them in this demonstrates that you value them and recognise their importance to your business.
Do you want access to these security awareness training videos? Sign up with Cyber Coach today, and get your staff on the right training path for your business.
Cyber Coach training can be customised to meet the unique needs of your business, with a range of modules and topics available including Compliance focused training to meet the annual training requirements of any standards you might hold or be working towards, such as Cyber Essentials, Cyber Assurance, ISO 27001, or PCI-DSS.
To find out more – contact Bethany, our Cyber Coach product manager: bethany@cool-waters.co.uk
Most people have heard of a Firewall, but what exactly is one, and what do they do?
A Firewall can be in the form of a security device in your office, or a piece of software installed on your computer. It is the first line of cyber security defence, to help prevent unauthorised access to your network and the private data within. The basic principle is that it forms a barrier, constantly checking all traffic coming from between you and the outside world and blocking anything that shouldn’t be allowed.
Firewalls often come in many different shapes and sizes and can provide additional features, but there are two distinct different types; Software and Hardware.
Software Firewalls, also known as Host-based Firewalls, are commonly pre-built into your laptop or computer's operating system (Windows or MacOS). They help block unwanted traffic to and from your device, but not other devices, on your network.
Hardware Firewalls, also known as a Network-based firewall, is a device that sits on your local network between your office and the internet. They help block unwanted traffic coming in and out of your network, but not typically between network connected devices (such as PCs, laptops, and servers) within your office.
With both firewalls working, they provide robust and predictable protection across your devices on the network.
*https://nordlayer.com/learn/firewall/host-based/*
All network connected devices talk to each other through ‘ports’ - think of them like entrances to an office building. Each entrance serves a specific purpose for different needs such as a loading bay, door with key card access to a secure area, employee pigeonholes, and a storefront. These could be likened ports that handle file transfer (FTP - port 21), accessing server rooms (SSH – port 22), email delivery (IMAP – 143) and your webpage (ports 80/443). Some of these examples need to be opened to the public, but some would need to have restricted access. Cyber criminals can exploit and access confidential data through these open ports, much like a thief would exploit an unlocked door or open loading bay. Keeping ports open only when needed and closing them to external use when there is no longer a business need will help ensure that they aren’t open to exploit.
The Cyber Security Breaches Survey run by the UK government recorded that the use of network (hardware) firewalls dropped from 78% in 2021 vs. 66% in 2023. This is a staggering decline in the use of this crucial technology. It also reports that around a third of businesses (32%) and a quarter of charities (24%) report having experienced any kind of cyber security breach or attack in the last 12 months which accounts for approximately 462,000 businesses and 48,000 registered charities in the UK. These reported figures are already very high, but the true number of cyber security breaches are likely to be even higher!
The Cyber Essentials certification covers 5 technical controls to help secure your charity or organisation. Firewall use is the first control, and often one of the easiest to get set up, with the majority of software firewalls being built-in to the operating system, and may simply need turning ‘on’, and hardware firewalls commonly ‘plug-and-play’ with minimal setup necessary. They ensure that the network services that need to be running to, from, and on your devices are able to do so, such as communication with other devices in your business, while restricting access to devices and internet services that you don't know and trust, which reduces your exposure to attacks.
Where open doors and broken key card locks are easier to spot, it’s not always easy to keep track of which ports are open and which are closed. That’s why it’s recommended that the firewall configuration rules that manage the ports are checked and reviewed every 90 days. This ensures that ports that were once open, but are no longer needed, are closed off, reducing the attack surface and keeping your network more secure.
At Cool Waters, our specialist consultants are available to help support your organisation navigate through your desired cyber security certification from Cyber Essentials to ISO27001.
Our Cyber Advisor service, inclusive of Cyber Essentials certification fees and a full 12 months of ongoing cyber security support starts at just £97 per month for an organisation with 9 or fewer employees.
Learn more about Cyber Advisor
When opportunities arrive, it’s too late to prepare! As we get ready to step into a new year, it's the perfect time to reflect on our business goals and the strategies that can help us achieve them. One aspect that often gets overlooked but is crucial in today’s digital world is cybersecurity. That’s where the Cyber Essentials scheme comes into play. Let’s explore how embracing this scheme can be a game-changer for your business growth in the New Year.
What is the Cyber Essentials Scheme?Cyber Essentials is a straightforward yet effective, Government-backed scheme that helps protect your organisation against a wide range of the most common cyber attacks. The guidance is clear and manageable, even for those with limited IT knowledge.
Key Benefits of Cyber Essentials for Small Businesses1. Protection from Cyber Threats: Implementing the controls required by Cyber Essentials can significantly reduce your risk of common cyber attacks by up to 80%, safeguarding your business data and customer trust. 2. Boosting Customer Confidence: In an era where data breaches are a frequent headline, demonstrating your commitment to security can distinguish your business as a trusted partner. 3. Enhancing Business Reputation: Achieving certification showcases your dedication to security, potentially opening doors to new business opportunities, especially where cybersecurity is a prerequisite. 4. Compliance and Beyond: The scheme helps you align with basic compliance standards, setting a foundation for further security measures as your business grows. 5. Cost-Effective Security: For small businesses, the investment in achieving Cyber Essentials certification is modest compared to the potential cost of a cyber attack. Our ‘Done for You’ service which includes help from an NCSC Cyber Advisor starts at just £97+VAT per month. * 6. Inclusive Cyber Insurance: For UK based businesses the scheme provides £25,000 of Cyber Insurance for free - to help you manage and recover should the worst happen. *
How to Implement Cyber Essentials in Your BusinessGaining Cyber Essentials certification is quite straightforward for most businesses, as the scheme tells you exactly what needs to be in place in your business. Your IT support provider may be able to help or you can ask a Cyber Advisor.
We are one of only 70 Cyber Advisors in the UK assured by the NCSC to help businesses implement the Cyber Essentials scheme - especially smaller firms with little in house IT expertise.
How Quickly Can I get Cyber Essentials certifiedMost of our clients using our Cyber Advisor supported ‘Done for You’ service find that can achieve Cyber Essentials in 6-8 weeks - so now is the perfect time to start in order to secure your business success in the New Year!
Get started today by signing up for our cost effective monthly subscription that spreads the investment over 12 months and includes a whole year of security advice from our helpdesk plus other bonuses to keep you secure all year round.
Learn more about Cyber Essentials Investing in cybersecurity with the Cyber Essentials scheme is not just about protecting your business; it's about positioning your small business for growth and success in the digital age. As you make your business resolutions for the New Year, consider adding Cyber Essentials to your list.
It’s an affordable, effective way to ensure your business is secure, reputable, and ready for the opportunities ahead.
Sign Up for Cyber Essentials The Small Print* UK based organisations with a turnover under £20m, Price includes Cyber Essentials certification fees which start at £300 +VAT
I recently helped respond to a fraud that had a significant impact on the person who was scammed
Here's a quick breakdown of what happened as far as we can tell.
The victim received a phone call claiming to be from Amazon Customer Service saying someone was trying to buy an iPhone15 on their account, was it them?
Obviously the victim said 'No' and the voice on the phone said not to worry, we can sort this out. Then 'so they can help' please install the support app from the link I will send you.
The 'support app' was a copy of AnyDesk for Android.
Then the fraudster said, 'so we can be sure its you- security is important' we need a copy of your driving license, front and back.
The unsuspecting victim complied and then while their colleague kept the victim talking on the phone, including getting their card number so they can 'send the money back where it came from'. The fraudsters used anydesk to navigate to the amazon webstore in the browser on the phone and look up an iphone15, so that it was registered in the 'things you were recently browsing' history on the victims Amazon account. The victim was then instructed to take the phone away from their ear (which is presumably why they did not notice the anydesk tomfoolery) and check their Amazon history - and sure enough there was the iPhone15 just like the scammer had warned.
Meanwhile someone else was using Anydesk to install more apps onto the phone including the Revolut banking app.
An account was opened with Revolut in the victims name using the photo of the driving license to pass through the automated onboarding and KYC process.
The scammers then tried to use the provided bank card details to load funds into the Revolut account so they could then pay them away to an account they owned. This however did not work and two attempts were declined by the victims debit card issuer.
The fraudsters then went to an online giftcard mall to buy £150 gift cards telling the victim each payment was actually a refund to their account. After several similar transactions the HSBC fraud detection system kicked in a blocked the victims debit card.
We also found a copy of the western union app had been installed on the victims phone, but was not used on the day.
Overall the victim was kept on the phone for over and hour with alternating team members - some friendly some taking offence when asked 'is this a scam' - working the victim to keep them bamboozled and compliantly confused.
I wonder if a central register could be created that money transfer businesses and banks used as part of their KYC when opening accounts so that vulnerable people and those especially at risk of fraud and impersonation could voluntary register so that attempts to open online accounts in their name would automatically be declined.
If there is someone vulnerable to telephone or online fraud in your life, give them this advice:
LinkedIn is a popular social networking site used for professional business connections, job searching, and hiring. Because of this, people are much more willing to share their personal information on this site, specifically surrounding their current role and job history. It is also very common for users to prominently display their contact information on their LinkedIn profiles. All of this makes it easier for job seekers and recruiters to get in touch with each other and find suitably qualified candidates for available roles. However, once you share information online it is available for anyone to access, especially on a public profile like LinkedIn. Whereas, on other social media sites, users often set privacy restrictions to ensure that only the people they confirm as friends can access their private profile information.
You should always be cautious about any emails you weren’t expecting, especially on your work email account, or any other accounts you have shared or listed publicly online. Check the sender address carefully to determine if any messages are likely to be legitimate or if they need to be reported as a threat. Cyber criminals can gather information from your LinkedIn profile to use in targeted phishing attacks against you, known as spear phishing. Emails or private messages that discuss a personal interest of yours, or reference a specific club or group you belong to, are more likely to appear legitimate despite actually being a part of a scam. Your profile likely already includes your job role and what company you work for, but what you post may enable cyber criminals to piece together who else works there, what current projects you are working on, and maybe even customer-specific or sales information that is supposed to be private and confidential.
New employees are particularly susceptible on LinkedIn. In our firm, a new employee recently posted about their new job on LinkedIn and within 48 hours they received a spear phishing email, pretending to be from their new boss (also discovered from LinkedIn) asking them for a ‘favour.’ New employees, eager to impress and maybe still doing their orientation and security awareness training are easy targets for fraudsters.
LinkedIn have a Sales Navigator feature called LinkedIn Smart Links, which companies can use to provide tracking information on who access the links. The purpose behind this feature is to help marketing teams determine engagement levels. When a Smart Link is created, it uses LinkedIn’s domain with an 8-digit code added to the end. This makes the link appear to come from a legitimate source, as it is recognised by users and email programs as a LinkedIn link. However, cyber criminals have been abusing this system in phishing messages to bypass security features and provide malicious links to their targets.
Cyber security firm Cofense detected a recent phishing campaign utilising these links, which they have identified as a resurgence of this cyber attack type, first seen in late 2022. The links used in this phishing campaign were over 80 unique links derived from LinkedIn business accounts that had been previously compromised, or were links from newly created accounts. Over 800 emails were detected to be using these malicious links between late July and August, targeting a range of industries and business types. Although this is currently a fairly small scale campaign currently compared to other phishing attacks, it still presents a serious threat, as the obfuscated links can bypass security filters on email applications that are supposed to detected and prevent phishing messages from reaching your inbox.
As is common with other phishing scams, these links will take the user to a fake sign-in page that is pretending to be an official Microsoft login page. The victim is tricked into providing their password and other account credentials to the cyber criminals by being prompted to enter them in a fake login attempt. Because of the tracking information encoded into the smart links, the criminals are able to obtain their victims’ emails and autofill some details into the fake Microsoft sign-in form, making it appear more convincing in requesting further details such as passwords.
You should also be cautious about connecting with people you don’t know on LinkedIn, such as people posing as recruiters. They may be offering too-good-to-be-true business opportunities, which results in them tricking you into revealing information about your job role and what your company handles in the guise of extended interview-type conversations. They may have connected with a few of your co-workers and friends in an attempt to gain as much information as possible and be more convincing in their scam. To spot a fake profile, you need to be critical about what they are offering, and whether or not it seems legitimate. Are the questions they’re asking related to the opportunity? Or do they seem too interested in specific details about your current role, without describing what their company does or what your new role would be? Do they seem more interested in your employers than they are interested in you? You can also check up on the recruiters themselves to see if the profile is real, and if their ‘company’ has a web presence.
Identifying and reporting all suspected phishing attempts is the best way to protect yourself at home and at work. When using an email reading programme such as Outlook, or when accessing emails online such as through Gmail, you can report phishing messages directly. This is done by opening the (…) menu when you have the phishing message open and click the ‘Report Phishing’ option. The best defence against attack is a well-educated team, that know how to avoid malicious websites or clicking links in suspicious emails. Cyber Coach Security Awareness Training can turn your team into a security asset rather than a security risk. Get in touch to book a free consultation with our experts today, and find out how to turn your employees into your biggest cyber security asset.
ISO 27001 is the gold standard for information security frameworks and is increasingly becoming required as a part of contracts with large businesses. That being said, what exactly is it? And why would you want it? I’m here to tell you exactly that!
What is it? ISO 27001 is a management standard designed to allow organisations of any size to design their information security program – what the standard calls an Information Security Management System (ISMS). An ISMS is the policies and procedures that together define how an organisation protects itself from data loss, breaches and cybercrime.
ISO 27001 is a set of requirements designed in line with best practices for cyber and information security in the modern world and is applicable to all industries.
ISO 27001 is highly customisable to ensure suitability for all businesses and industries while still providing the same level of security. It is just as applicable for businesses with only paper records as it is for a 100% remote, cloud-based business, thanks to its optional clauses found in the Statement of Applicability. The Statement of Applicability (SOA) lets you decide what is applicable for you and your business out of the 93 controls spread over the 4 sections found in the document. The 4 sections of the SOA are:
Each section of the SOA is accompanied by multiple controls which you get to decide if they fit for you on a control-by-control basis, rightsizing and customising the standard to meet your needs, ensuring compliance be applicable for every business in every sector.
Who needs it? ISO 27001 certifications are maintained by some of the largest and well-known businesses in the world. It requires businesses to define information and cyber security requirements for their suppliers, with most requiring their suppliers to hold an ISO 27001 certification from an accredited auditor. This means that if you want to work with any of these businesses, you’ll need a certificate before they’ll even let you in the door:
As you can see from this list, ISO 27001 is the go-to certification for businesses in all sectors from software or hardware for computing devices, to social media and entertainment giants, even to the motor industry, ISO 27001 is used by them all!
Why should you have it? You need ISO 27001 to do business with industry giants, but what if you aren’t aiming for clients or partners of that size? There are many benefits other than just getting a certificate on the wall or a badge on your website. ISO 27001 shows to your customers, clients, and stakeholders that you take your information and cyber security seriously. It gives confidence in your business’ risk management and data handling processes, and lets you rest easy at night knowing you’re operating with industry best practices for security every day, protecting your data and business from cyber-attacks and malicious threat actors. There is a reason it is referred to as the GOLD standard!
ISO 27001 has many benefits, but a few you’re likely to notice immediately are:
Do you have any choice but ISO 27001? As business move increasingly online, cyber security becomes a bigger concern for all organisations. Requirements for stronger cyber and information security controls are becoming baked into contractual agreements, meaning some businesses won’t even entertain the idea of working with you if you don’t maintain at least one industry recognised security certification, and the industry standard is ISO 27001.
If you want your business to be a supplier to a large business, no matter how small you are, ISO 27001 is increasingly becoming non-negotiable. It’s not a matter of if you’ll need it, but when.
Becoming ISO 27001 certified can look like a long and complex road requiring many hours, specific expertise, and constantly evolving challenges, which is why our team of certified ISO 27001 implementors are always available for a chat. We take the stress out of ISO 27001, smoothing the path to certification so you can focus on running your business.
Whether you need a team to implement ISO in your business or just want some free advice from ISO experts on how best to get started book in a free 15-minute virtual coffee with a member of our team! We’re always happy to give free advice, and hope to speak with you soon.
Cyber criminals quickly react to changes in situation, whether that’s a crack down by cyber security bodies, exploiting newly discovered weaknesses, or taking advantage of changes in available technology. They quickly pivot to new business models that allow them to work around any restrictions and perform their attacks.
Recently, an international cyber security operation has resulted in the shutdown of a botnet responsible for distributing Qakbot malware. A botnet is a network of devices, also known as ‘bots’, used by cyber criminals to carry out large scale attacks. In this case, the botnet was used to deliver malware to the victims devices that was capable of gathering and stealing information, as well as helping to download and install additional payloads such as Black Basta ransomware. Qakbot malware can also detect and infect other connected devices within a network, which is known in cyber security as reconnaissance and lateral movement.
Since this international shutdown by cyber authorities has taken place, Microsoft have observed these cyber criminals immediately beginning to use different malware, and different distribution infrastructure, in order to continue their operations without interruption. That’s right – cyber criminals have Business Continuity Plans! These criminals are now using DarkGate malware, which is capable of not just stealing information and installing other malware and ransomware, but also keylogging, cryptomining, and collecting stored information from browsers such as saved passwords and session tokens and cookies. This new malware has many more functions than was previously being used by these criminals, meaning after cyber authorities have successfully shut down their operations, they are now potentially more dangerous than before, as they are able to perform a wider range of attacks.
Even the malware used by the criminals evolves over time, such as with Qakbot. This was originally known as a banking trojan, a type of malware designed to collect banking details and login credentials to enable the criminals to steal your money or in some cases aid in identity theft. However, 16 years later this malware is now able to gather and steal all kinds of confidential and sensitive information, not just financial credentials, as well as delivering additional payloads, reconnaissance, and lateral movement. If cyber criminals and the malware they are utilising is changing rapidly and effectively, your business needs to be able to do the same! 
How can you be sure that your business is protected, especially when the risks you’re facing could change suddenly due to a change in how the cyber criminals are operating? Having an always-on cyber security team, not a part-time solution, can ensure protection for your business 24/7. Your cyber security team should be able to proactively keep you safe if an attack occurs against your business at any time.
Cool Waters Managed Cyber Team provides a dedicated team of experts to proactively manage your cyber security on a day-to-day basis. With Cool Waters Managed Cyber Team you get more people, more expertise, more experience for less than the cost of one employee. Our Security Operations Centre (SOC) provides proactive 24/7 monitoring of your network and systems. If ransomware manages to get into your network and activates at 3 am on a Sunday, or someone logs into your SharePoint site in the middle of the night and starts stealing all your documents our team will spot it and step in to contain and remediate the problem while you sleep.
Book a free discovery call to find out how quickly and easily we can get started.
We’re delighted to announce that Cool Waters Cyber is Cornwall’s first and only NCSC Assured Service Provider helping micro and small-medium sized organisations improve their cyber security and gain the Cyber Essentials certification.
According the National Cyber Security Centre:
Cyber Advisors (Cyber Essentials) can help you assess the gap between your current cyber security stance, and that achieved by implementing the Cyber Essentials technical controls. This might sound daunting, but this service is tailored towards small and medium sized organisations and the Advisors have all been assessed not just on their technical knowledge, but also their ability to work specifically with small organisations.
We believe that the technical controls set out in Cyber Essentials can help you to avoid many commonly experienced cyber attacks, including ransomware attacks.
How does it work? All our Cyber Advisors are certified to the stringent levels required by the National Cyber Security Centre and have passed a rigorous assessment process and exam.
First we will review your current cyber security to identify any gaps or weaknesses and then develop a plan to fix them - a plan that works for you and your budget and does not get in the way of your daily operations. You will find our advice is pragmatic and our advisors friendly and down to earth. All our advice and reports are guaranteed jargon free!
We can then implement the agreed plan for you, or support you or your IT support company while they make the changes.
We usually perform all our work remotely, but if you prefer we can visit your offices and work on-site.
Once all the work is done, we will confirm you are now compliant with Cyber Essentials before submitting your details for certification. Since we are also a Cyber Essentials certification body we can ensure you are fully compliant before we submit - ensuring you pass first time.
After you gain Cyber Essentials, our service continues for the rest of the year - you can call us any time for unlimited cyber security advice all year long.
When you pass Cyber Essentials you receive a certificate and badges for your website, as well as being listed on the scheme’s website so your customers and potential customers can see that you take cyber security seriously. Your certification report also include details of your free cyber insurance cover (if you opt-in and qualify)
How Much Does it Cost?Our Cyber Advisor service, inclusive of Cyber Essentials certification fees and a full 12 months of ongoing cyber security support starts at just £97 per month for an organisation with 9 or fewer employee.
Want to know more? Book a free no-obligation consultation: Let’s TalkReady to get going? Sign up below for Cyber Essentials Done For You with one of our Cyber Advisors
Cyber Essentials - Done for You: Effortless Cybersecurity Compliance from £97.00 every month for 1 year Simplifying Cybersecurity with Cyber Essentials In the digital age, protecting your business from cyber threats is crucial. Our 'Cyber Essentials - Done for You' service is designed to make this process as straightforward and stress-free as possible. We handle everything, ensuring your business meets the Cyber Essentials standards without hassle.
Why Choose Our Cyber Essentials Package? 🎯 Guaranteed First-Time Pass * 🔍 Gap Analysis * 📄 Plain English Report * 🚀 Implementation Support * 📜 Custom Policies * 💳 Certification Included * 💷 Cyber Insurance Included (£25,000)** * 🖊️ Ready-to-Sign * 🔗 Ongoing Help * 🤝 Friendly Advice
Done For You: Select Done For You 0-9 Employees (Cyber Advisor)10-49 Employees (Cyber Advisor)50-249 Employees (Cyber Advisor)250+ Employees (Cyber Advisor) 0-9 Employees (Cyber Advisor) 10-49 Employees (Cyber Advisor) 50-249 Employees (Cyber Advisor) 250+ Employees (Cyber Advisor) Get certified now >
A government survey found that about a third of UK businesses identified a cyber security breach or attack in the year leading up to April 2023. This number is believed to be much higher due to small and medium sized businesses being less likely to report on cyber incidents. However, only 21% of businesses have a formal incident response plan for how to act when a cyber incident does occur.
It’s all well and good to say you will take action following a cyber incident, but what actions will you take? Who is responsible for taking those actions? And what will happen if the decision makers or experts aren’t present at the time of the incident? A formal incident response plan answers all these questions for you and ensures everyone is on the same page when it comes to responding to a cyber incident or attack.
Be prepared
The first thing that needs to happen before executing your incident response plan is making one in the first place! Being prepared and creating a plan to follow is the most important step any business can take. When a crisis hits, it’s too late to prepare, so be sure to take steps now, and not while you are trying to deal with an attack.
The UK National Cyber Security Centre (NCSC) defines 4 core stages that need to be taken in response to any cyber incident.
1 - Spot the threats
In the analysis stage, you should review everything that could potentially introduce threats to the business, including a technical analysis to find any gaps in the cyber security of the organisation. Identifying potential threats and conducting risk assessments can allow your incident response plan to be well-informed and appropriate for the type of cyber incident you might face. Testing for flaws in the cyber security of the business in a simulated attack, such as penetration testing, helps everyone to understand the potential impact of an incident occurring.
2 - Contain the damage
When an incident or attack occurs, making sure the damage or effects of it are contained to affect the smallest area possible can reduce the impact, and increase the chance for full recovery. Decisions may need to be made at this stage to help mitigate the threat, such as taking key business systems offline, in order to prevent things from getting worse.
3 - Remove the threat
The remediation stage involves elimination of the threat. Both stages 2 and 3 can be performed successfully by antivirus software, such as SentinelOne. This is an example of endpoint detection and response software that not only identifies malicious software such as ransomware, but also is capable of removing it from your systems, and reversing any changes made. Ensuring all malicious files and malware has been completely removed from all devices and networks prevents the incident reoccurring and allows for the recovery stage to begin.
4 - Recover and repair
After the incident has been cleared from the network you can begin to conduct business as usual again. Minimising the amount of time it takes before getting to this step is the main goal behind having an effective incident response plan.
Lessons Learned
After the incident has occurred it is important to review how the incident response process was managed and learn from the incident. This allows everyone to see what went well and what could be improved upon within the incident response plan. It is also important to analyse how the incident occurred in the first place so that steps can be taken to ensure the same incident does not happen again. Important questions to ask during this review include the 5 W’s – Who, What, When, Where, and Why. The results of this should be shared with everyone in the business, such as through employee training sessions, to best ensure the weaknesses and threats that triggered the incident are not allowed to repeat.
Test and Practice
Testing and re-testing the incident response plan should be carried out to see if it covers everything necessary to properly ensure the security of the business and its assets. Testing the plan can help everyone in the organisation become familiar with what to do if an incident occurs and help reduce the recovery time for the business.
The plan will get tested at some point, don’t let that be during a real cyber incident!
The best way to test out your incident response plan is to simulate an incident within the company. This involves gathering together the decision makers within the business as well as the people designated as your emergency response team to test if they know what actions they should take if an incident occurs. Help and advice in planning these sessions is made available for free by GHCQ on the NCSC website.
Looking to start a career in Cyber Security?We are recruiting for 2 apprentices to join our team based in our offices in Penryn, Cornwall.
We are looking for two people to join as L4 Cyber Security Apprentices, which is a two year apprenticeship and provides a living wage and first class training to kick start your career in Cyber Security.
You can choose between two learning pathways: Cyber Security Engineer or Cyber Risk Analyst.
To learn more about our apprentice opportunities, goto www.cool-waters.co.uk/careers and download the specifications and how to apply.
We offer a range of company benefits including: private medical insurance, pension and doughnuts on your birthday!
“All charities ultimately rely on public trust and continued public generosity. So the impact of any cyber attack on a charity can therefore be devastating, not just for the organisation and those who rely on its services, but also in undermining public confidence and support.
Taking steps to stay secure online is not an optional extra for trustees, but a core part of good governance.”
Helen Stephenson, Chief Executive of the Charity Commission for England and Wales
As a trustee of two charities, I understand first-hand the challenges trying to balance prudent investment in back-office systems and infrastructure with the need to deliver the core front line service that meet the charitable aims. However, without the back-office systems the charity’s work will quickly grind to a halt and key systems such as safeguarding, record keeping, and financial controls cannot operate without IT systems. Which means the disruption that comes from a cyber-attack such as ransomware can be devastating to the daily operations of the charity and the loss of trust and donations that would follow a data breach could leave the charity unable to continue operation. Several jurisdictions have started taking legal action (including prison) against the officers of commercial organisations for failing to provide essential cyber protections for customer and client data, I predict that UK regulators and insurance companies will soon start to move in this direction as well.
How can you, as a trustee, know that your charity’s IT systems and networks are cyber secure – whether you rely on an in-house team or external help to manage your IT?
One very effective approach is to ensure your policies and practices align with a recognised standard that defines ‘good cyber security’ for you. In the UK, the definition of the minimum acceptable standard for cyber security is called Cyber Essentials. It does, as the name implies, define the bare essentials necessary to keep your network and internet-based services cyber secure.
We have created a free resource – The Trustees Guide to Cyber Essentials which you can get here.
Get started with Cyber EssentialsCyber Essentials is a great starting point as it gives you a clear list of all the things you must do. However, it does not tell you how to do those things.
As a Cyber Essentials Certification Body, our team evaluates many Cyber Essentials applications every month. The sad truth is that firms and charities which apply directly through the central Cyber Essentials portal have a greater than 90% failure rate for their first applications. Not because Cyber Essentials is hard to achieve but because the questions are not as clear as they could be or require certain processes and policies to be in place. This is why we created a special service to guide charities through the Cyber Essentials process with 4 hours of discounted consultancy and included provision of template policies and procedures that will ensure you are Cyber Essentials compliant – if you follow them.
Learn more about Cyber Essentials with Expert Help.
Getting Cyber AssuranceWhen you are ready to step up your cyber protections beyond the bare necessities of Cyber Essentials, the next step is Cyber Assurance – a scheme run by IASME, the same people who manage the Cyber Essentials Scheme for the NCSC.
Cyber Assurance is a comprehensive, flexible and affordable cyber security standard. It provides assurance that an organisation has put into place a range of important cyber security, privacy and data protection measures.
The IASME Cyber Assurance standard emerged from a UK government-initiated project, aiming to provide an affordable and realistic alternative to some of the prevailing international cybersecurity standards. Tailored for small and medium enterprises (SMEs), this standard offers a balanced way for businesses to showcase their cybersecurity measures, emphasising the safety of customer data.
Key Highlights of IASME Cyber Assurance:
Cyber Essentials Level 1 Verified Assessments cost between £300 and £500 annually depending on the number of employees.
For more information on Cyber Assurance or to book your assessment, click here.
International RecognitionFor larger charities and those working with NHS data or safeguarding issues, the highest level of internationally recognised certification is the ISO 27001 standard for information security.
ISO 27001 is a management system which will affect almost every part of your charity, not just the IT team - so it is important that you choose to work with an implementation consultancy like Cool Waters Cyber who can help you smoothly manage all the changes that will be required to your organisation.
Once your ISO 27001 Information Security Management System (ISMS) is in place, you will need to be audited by an external and independent auditor. Pick one who is registered with UKAS to ensure your ISO certificate is recognised as valid by your stakeholders. We can recommend auditors we often work with.
Learn more about ISO 27001 or book a free initial consultation with one of our experts.
Need Help with your Charity’s Cyber Security?Book a free initial consultation with one of our experts to better understand the options available to secure your charity. With our special charity sector terms you will find that all charities can afford the right cyber security for their size and risk profile.
Book free initial consultation
Half of UK businesses struggle to find even basic cyber security skilled staffA third of UK business have a skills gap for more advanced cyber security needsAccording to the latest UK Government report on Cyber Security Skills in the UK, half of all uk businesses are struggling to find people with the basic cyber security skills needed to protect their business and the number of vacancies for Cyber skilled roles has increased by 30% since the previous year.
What this means in practical terms is enough to make any CEO lose sleep - to quote the report:
Approximately 739,000 businesses (50%) have a basic skills gap. That is, the people in charge of cyber security in those businesses lack the confidence to carry out the kinds of basic tasks laid out in the government-endorsed Cyber Essentials scheme, and are not getting support from external cyber security providers. The most common of these skills gaps are in setting up configured firewalls, storing or transferring personal data, and detecting and removing malware
Approximately 487,000 businesses (33%) have more advanced skills gaps, most commonly in forensic analysis of breaches, security architecture, interpreting malicious code and penetration testing
41% have an internal skills gap when it comes to incident response and recovery, and do not have this aspect of cyber security resourced externally
50% of businesses and 47% of charities have just one person who is directly responsible for … cyber security
Read on to understand how we can help you solve these challenges in your business or charity.
Closing the cyber skills gap in your organisations With half of all UK organisations struggling to find people with even basic cyber security skills, there is a security crisis in many organisations. The people in place do not have the skills they need to protect the organisation, and those who get trained up are more likely to leave for higher paid jobs due to large shortage of cyber skills people across the country.
For many years firms have outsourced their desk top and IT support to specialist firms - people who can configure laptops, create logins for new staff and provide help and advice when the finance spreadsheet gets corrupted (again). They are good at what they do, offering a break-fix service based on a helpdesk - that is: when something breaks, they react and fix it. However, people who are experts in Windows laptop set-up and Email server configuration are not necessarily cyber security gurus and few offer expertise in the cyber security standards such as Cyber Essentials or ISO 27001 which are being demanded by insurers and clients alike.
Enter a new breed of firm, like Cool Waters Cyber, who provide outsourced cyber security-as-a-service and work alongside your IT support firm.
The key difference between the IT desktop support firm and the managed Cyber Security firm is the cyber firm’s operating model needs to be pro-active not reactive. In cyber security if something breaks it is too late - because that means your data has been exposed or stolen - so you need a cyber security team that is proactively looking for issues and risks and fixing them before they turn into problems.
Working with a firm like Cool Waters Cyber to run your cyber security on a day to day basis is a cost effective way to close the cyber skills gap in your firm. You will see the following benefits:
Removing single points of failure If you are one of the 50% of UK organisations that has a single person responsible for Cyber Security - (assuming there is anyone at all) - then holidays and sick days place your organisation at risk when your in house security team is not available. And what about over night and at weekends?
Partnering with a security-as-a-service firm like Cool Waters Cyber that offers 24 * 7 Security Operations ensures your business is protected while you are asleep and in the off-hours preferred by cyber criminals to launch their attacks and ransomware because they assume that the in-house cyber security team will not be on duty.
Having a team of cyber security experts to support your in house resource or take over the responsibility for security will release that person to add value to another part of your organisation.
Creating new cyber security expertsThe only way to solve the national cyber security skills gap is to create more cyber security experts, and we are doing just that with our award winning cyber apprentices scheme which is bringing new cyber careers to some of the UK’s most deprived areas in Cornwall. (Find out more and apply for an apprenticeship)
How can we help? Speak to Us If you are facing a cyber skills gap in your organisation or are looking for a trusted partner to secure your business or charity, arrange a free no obligation chat to discuss your options. Let’s Talk.
The recent security vulnerabilities discovered in the MOVEit file transfer system has affected dozens of companies and millions of individuals who have had their data compromised and stolen as a result. Organisations a diverse as the BBC, US Department of Energy, Boots the Chemist, Oregon and Indiana local government and payroll provider Zellis - all around the world from Canada to India to UK to USA and Germany. Web scanning engine CENSYS has identified at least 3000 vulnerable MOVEit servers on the internet.
To their credit, Progress Software who provide MOVEit appear to be handling the incident in a professional, clear and transparent way unlike other recent security breaches (yes Capita, we’re looking at you).
Not all publicity is good publicity View fullsize
View fullsize
View fullsize
View fullsize
But if you are a supplier of software or services to other businesses, charities or public sector – how can you prove to your customers and potential customers that your systems and services are secure and can be trusted?
How can you give them confidence to trust you with their two most precious possessions - their data and their reputation?
There are two simple answers:
Certifications
External independent security help
CertificationsBy getting certified to a recognised security standard, your clients are able to trust in the certification scheme as providing independent verification of your information security. Increasingly we are seeing cyber security certification being a requirement for responding to RFP across all sectors and insurers are starting to ask for them as well!
Starting with Cyber Essentials the UK scheme designed by the National Cyber Security Centre – it is already proven to reduce the likelihood of needing to claim on cyber insurance by 80% and is a pre-requisite for many UK local and national government contracts. Cyber Essentials focuses on 5 essential areas of basic cyber security which prevent the majority of cyber attacks. With certification costs starting at just £300 per year, it is a very effective and economic scheme for any business to achieve. It also provides £25,000 of cyber insurance should the worst happen.
Cyber Assurance is the next step up – designed and run by the same people who run the Cyber Essentials Scheme. Cyber Assurance builds on Cyber Essentials to expand the scope to include data protection and GDPR, Business Continuity, Asset and People Management and how to respond to and manage Security Incidents. This is useful to demonstrate a wider level of cyber security and resilience to problems and uniquely it is one of the few ways to get a certificate that demonstrates GDPR and Data Protection compliance for your business. Self Assessment starts at £300 per year whereas an audited level two assessment starts at £1400 per year – depending on the size and complexity of the organisation.
ISO 27001 is the internationally recognised Gold Standard for Information Security and is widely accepted and requested by larger clients and public sector organisations. Provided the certificate is issued by a UKAS accredited audit firm, and the scope includes the whole business, it provide the ultimate assurance for clients and stakeholders that your business is operating and being managed securely.
External HelpAnother way to demonstrate you take cyber security seriously is to rely on outside professionals either for ongoing advice or to fully outsource to someone who can provide a managed security-as-a-service or compliance-as-a-service. Someone like Cool Waters would you believe.
You are experts at running your business, making your products, operating your services - but that does not mean you are experts in cyber security - and why should you be? You may well rely on external help to audit your books, gain certification to ISO standards for quality and environmental impact, manage HR problems and motivate your sales team or generate sales leads or run your marketing. By working with a cyber security consultancy you will be able to tap into wider and deeper experiences than you are likely to be able to recruit (of afford) to retain as permanent members of staff.
Our Managed Cyber Team service is a great example of this - providing a end-to-end managed cyber and information security service which looks after everything from the desktop to the cloud, leaving you free to focus on running your business and your clients impressed that you are punching above your weight in the security stakes and can be trusted with their most precious commodity - their data.
To chat more about any of these topics, arrange an initial informal chat with our team here: https://www.cool-waters.co.uk/lets-talk
Book Free Initial Consultation
Business Owners often ask me about the products and services they should be using to build and run a secure startup or new business. This is what I tell them.
Office 365 or Google Workspace for Email and Documents
When it comes to the essentials of any business - email, calendar and somewhere to store your files, 99% of businesses are best served by using one of the main Cloud services - either Microsoft 365 (Office 365 as was) or Google Workspace. Personally I find the Microsoft offering is more useful for most organisations as it includes Sharepoint which is great for providing a place to store documents and policies that all staff need to be able to find and refer to - but you do need to opt for the ‘Business Premium’ edition to get the bundled cyber security tools to best protect your business. We look after configuring, security and managing our clients Office365 and GSuite environments as part of our Managed Cyber Team service.
Backup the cloud
Many people do not realise that neither Microsoft or Google provide any guarantee that the files and emails you give them to look after will actually be looked after and still be there tomorrow. In other words, you have to provide your own backup solution to archive emails and documents and also allow you to recover a file accidentally deleted or over written. Backups are also your best defence against ransomware. (Google Drive and OneDrive do not count, ransomeware will trash all those files as well if it gets onto your system)
We provide all our clients with backups for the Microsoft and Google environments using our own solution - Cool Waters Cloud Backup
Secure PC and Servers
Every PC and Server needs to be protected against malware (viruses, ransomware and other malicious code). We provide SentinelOne to all our clients along with 24*7 monitoring and support from our Security Operations Centre (SOC). This means that if the security alarms go off at 3 in the morning on a Sunday, our SOC team will spring into action to resolve the incident while you keep sleeping.
We can also take it up a level with a managed network Intrusion Detection System coupled with our 24*7 SOC making enterprise grade security available to businesses of any size, and at a surprisingly affordable price point.
Whether you go Windows or Mac is a matter of personal preference - we use both due to some tools only being available for Windows - and for that we use the Windows365 virtual Cloud PC service from Microsoft. The main thing is to ensure all security updates are applied promptly to the operating system and all apps, and get anti-ransomware protection from something like SentinelOne.
Public Website
Run your public website outside your network and use a managed service - you don’t want to get into having to install security patches and updates on your website every week. We’ve been using Squarespace for over 20 years and have never had a problem.
Get Certified
There is no point re-inventing the wheel when to comes to cyber-security, it is always best to go with a proven solution that is well tested. So how do you know your cyber security is done right - and how can you prove that to clients and potential clients? The easy answer is to get your business certified against a well known and trusted cyber security standard. In the UK the four main ones are:
Cyber Essentials - the UK government’s standard from the National Cyber Security Centre - it opens the door to public sector contracts and includes free cyber insurance
Cyber Assurance - from the same people who run Cyber Essentials, this increases the scope to include Data Protection, GDPR compliance and Business Continuity
ISO27001 - the internationally recognised gold standard for information security
PCI-DSS - the international standard required if you handle card payments
Introducing Cornwall’s only IASME Certification Body able to deliver the Cyber Essentials and Cyber Assured certifications to businesses across the Duchy and the whole of the UK. We’re delighted to announce that Cool Waters Cyber has attained IASME Certification Body status, which means we are able to help organisations gain and retain the NCSC backed Cyber Essentials scheme and the IASME Cyber Assured scheme. Both of these certifications help organisations to improve their cyber security and protect their business and their customers data from cyber crime and ransomware.
The NCSC recently revealed that firms that have implemented Cyber Essentials are 80% less likely to need to make a claim on their cyber insurance.
Founder and CEO, Mark Faithfull, says:
I’m delighted and proud we have achieved certification body status. It’s a rigorous process that assess the whole firm to validate that we are able to provide the best advice and support to firms who want to achieve Cyber Essentials or Cyber Assured certifications.
What are the Cyber Essentials and Cyber Assured Schemes?Cyber Essentials is, as the name implies, the essential minimum any firm should have in place to protect themselves from cyber crime and ransomware. It is cost effective, starting at only £300 a year for a micro business and comes with £25,000 of cyber insurance.
Cyber Assured builds on Cyber Essentials and it provides assurance that an organisation has put into place a range of important cyber security, privacy and data protection measures - including compliance with GDPR and the UK Data Protection Act.
Learn more about Cyber Essentials and Cyber Assured
An Endpoint is any device that is connected to a network. This can include the devices we most commonly think of when we talk about cyber security, such as desktop computer, laptops, and mobile devices like phones and tablets, but there are more endpoints than just these on almost every home and work network. Wearable technology such as smart watches, integrated smart solutions that connect to Wi-Fi such as door control, CCTV, and smart home technology (called Internet of things (IoT) devices), as well as practical utilities such as printers, and network infrastructure devices including servers and switches are all considered endpoints.
Any endpoint can be used by hackers to access your network, so endpoint security is very important in order to protect your data and privacy. Traditionally when you consider security for your devices such as PCs and laptops, you think of antivirus. Antivirus is a program that protects your device from lots of different forms or malware and viruses, as well as blocking dangerous websites and preventing phishing attempts by flagging malicious links and emails. Antivirus software is usually installed on one endpoint at a time and offers protection for that device only. Endpoint Protection systems, also called Endpoint Detection and Response (EDR) solutions, take a more holistic approach to your cyber security. Instead of focusing on the security of just one device, endpoint protection offers security to the whole network and all connected endpoints.
Antivirus software works by having a library of malicious content that it is looking out for on your systems. When it recognises a website or piece of malware that is knows is dangerous, it will alert you to the problem and sometimes also step in to block it from running. This works well for controlling old, known malware, but what about a new cyber attack with new malware that hasn’t been seen before? Endpoint protection is cloud-based, and keeps up to date automatically, using threat hunting capabilities to identify instances of an attack on your network, identify and block malicious activity, and build a connected story of how the attack happened and what steps were taken to remediate it for your SOC team to review. Using AI capabilities, EDR solutions can resolve security incidents before they spread and have a proactive role in maintaining the security of your network, not just functioning as an alert system that then requires human interaction.
Endpoint protection software is managed centrally by IT security admins and the SOC team. Any changes that are made to the security configurations at the central location, whether that is a physical server or cloud-based, are automatically applied to all the endpoints on the network. This can also be used across a virtual network environment, when devices are out of the offices because employees are working remotely, or in situations where no physical office exists. If your employees can access your corporate network remotely, then any cyber criminals with access to their devices or home networks can too. Endpoint protection systems being applied to those remote working devices, including BYOD (bring your own device) and IoT devices, reduces the likelihood and effectiveness of a cyber attack.
Our Managed Cyber Team is a great way to outsource your cyber security operations to ensure the best protection for your business. We use the industry leading endpoint protection solution SentinelOne combined with a SIEM service that collects all the event logs from across your network. This provides a holistic view of your network and endpoints to effectively manage suspicious activity and deal with malware or hackers. SentinelOne’s EDR provides the SOC team with a full picture of events, through their behavioural engine that tracks all activity across the network. This removes the likelihood of attacks being missed by human error through ‘alert fatigue’, where the threat analysts have so many logs to dig through that they miss what is really important.
Cool Waters Managed Cyber Team provides you with a Security Operations Centre (SOC) team to proactively manage your cyber security, actively monitoring 24 hours a day, 7 days a week. This includes training and monitoring the SIEM to spot attacks and attempted breaches as they occur and then to respond in real time to contain the intruders or malware. Our SIEM service, backed up by our SOC, is a cost-effective way to meet the needs of PCI-DSS for daily log monitoring and investigations – including log retention for 12 months. Our Emergency Response Team (ERT) is available to assist with significant attacks on your network, drawing the expertise of the SOC team to deploy at short notice experts skilled in handling the most complicated and aggressive ransomware and cyber attacks.
Book a free discovery call to find out how quickly and easily we can get started.
A Security Operations Centre (SOC) uses a combination of people and technology to proactively manage the cyber security of your business on a day-to-day basis. This is managed by security event management software, such as SIEM solutions, and a team of cyber security experts called the SOC team. The SOC team monitors the output of the SIEM to effectively prevent, detect, analyse, and respond to security incidents.
What is SIEM? Check out our article on this topic first to find out more.
The SOC team is made of dedicated experts who provide proactive 24-by-7 monitoring of your network and systems. This includes training and monitoring the SIEM to spot attacks and attempted breaches as they occur. The SOC team can then respond in real time to contain the intruders or malware. In order to be effective a SOC team must be able to stay one-step-ahead of the attackers. This can be difficult to manage in-house due to a shortage of cybersecurity skills in existing employees within the business.
Your SOC team need to be able to analyse suspicious activity to determine the scale of any given threat. This is managed by looking at the network and operations from the perspective of an attacker, such as looking for exposed areas of the network that can be exploited. To better understand the threats that could be faced by your business, the SOC team will perform a triage on various types of security incident to understand how potential attacks could unfold, and how to respond effectively to them. Up-to-date information about the global threat intelligence landscape, information about the organisation’s network, and specifics on attacker tools, techniques, and trends are all used by the SOC team to perform this triage.
In the event of a security incident the SOC team act as the first responder. If ransomware manages to get into your network and activates at 3 am on a Sunday, the team will spot it and step in to contain and remediate the problem while you sleep. The goal of the SOC team is to return the network to the state it was in before the incident or attack took place. The SOC team do this by isolating endpoints, which might mean removing computers from the network, terminating harmful processes such as stopping a piece of malware from running on a device, and preventing malicious files from executing in the first place. After an incident the SOC team works to restore and recover data including wiping and restarting endpoints, reconfiguring systems, and deploying backups in the case of ransomware attacks.
An assortment of security tools are used by most organisations, which are often hosted and controlled by different departments. This can present a challenge to SOC teams who have to translate and coordinate security policies and alerts between these tools and environments which can be costly, complex, and inefficient. Security is a holistic exercise, which is why we prefer to use SIEM systems, which correlate event logs from multiple systems so that you can see what is going on across the entire network at the same time. Our SIEM service, backed up by our SOC, is a cost-effective way to meet the needs of PCI-DSS for daily log monitoring and investigations – including log retention for 12 months.
When tools are used to aid the threat detection process, they must be properly configured, otherwise they are going to produce too many alerts. Going through pages and pages of alerts adds to the workload of the security monitoring team without effectively identifying incidents, meaning the important event logs showing potential breaches are still often missed. An expert SOC team can properly configure the tools used so that the critical events are not missed and are addressed immediately to properly investigate suspicious activity, contain any intruders or malware, and isolate compromised machines. This includes training and monitoring the SIEM to spot attacks and attempted breaches as they occur and then to respond in real time to contain the intruders or malware.
Cool Waters Managed Cyber Team provides industry leading SentinelOne endpoint protection for PC and Servers combined with a SIEM service which captures the logs from all your computers, firewalls, and network devices. The SOC team actively monitors your whole network to immediately detect and remediate incidents. Our SOC service is only available to Managed Cyber Team clients and is a cost-effective way to meet the log capture and active monitoring requirements of PCI-DSS.
Our Emergency Response Team (ERT) is available to assist with significant attacks on your network, drawing the expertise of the SOC team to deploy at short notice experts skilled in handling the most complicated and aggressive ransomware and cyber attacks. ERT is only available to customers who use our SOC services.
Book a free discovery call to find out how quickly and easily we can get started.
SIEM stands for Security Information and Event Management, and a SIEM system does exactly what you’d expect based on that name – it is software that manages security events and other important pieces of security information across the network it is installed on. A SIEM system is used to detect security incidents and cyber attacks at the time they occur, which can allow an organisation to responding quickly and minimise the damage done by the incident or attack. This is possible through the SIEM system collecting and analysing event logs across the network in real time, providing the security team with the ability to see everything that is going on in the network ‘right now’ or at a chosen point in history.
When an event happens on a computer, such as a user signing on, or an application running, the computer keeps a record of this in a log file. There are so many events produced through normal operation of computer systems that important log events can be missed in all the ‘noise’. After a security breach has been detected, a common finding is that evidence of the incident was available at the time, but no-one spotted this, or realised it’s significance, and so staff did not act to stop the breach. The Verizon Data Breach Investigation report states that “In 82 percent of cases ... the victim possessed the ability to discover the breach had they been more diligent in monitoring and analyzing event-related information available to them at the time of the incident.”
SIEM systems contain rules that can be configured by the security team to identify important events in the logs and not report on false positive alerts so that staff are not overwhelmed by notifications of events that don’t require further investigation, and time can be better spent focusing on important events instead. Many modern SIEM systems have initial configurations and rulesets ready to be used, however a period of ‘training’ is still needed to fine tune the system to the network. Each network is unique, so the way your SIEM system is set up should be unique also.
Lots of different systems will be running on your network at all times, and these are often managed by different departments. A firewall will be configured by your network engineers, an SQL database will be controlled by database analysts and engineers, and the Windows configurations will be set up by the systems administrators. Because of this separation of roles and responsibilities, the log files produced about events happening in each of these systems will also be kept separate. Keeping all of these logs separate makes sense from an engineering perspective, however from a security perspective it presents a problem.
Security is a holistic exercise, and the segregation of event logs from different systems can mean that the whole picture of a security event is not seen, and important indicators about a security incident or attack can be missed. When investigating problems in complex systems, context is king – and the ability to know what was going on at the same time in many different systems can mean the difference between staff identifying an incident in time to prevent further damage, and an incident going unnoticed long enough to cause significant security issues. SIEM systems correlate event logs from multiple systems so that you can see what is going on across the network at the same time.
Event logs on computers and devices will have a finite amount of available storage space, but as events are constantly occurring, the logs are continually produced. This results in the device automatically overwriting the oldest log files as needed. SIEM systems store copies of event logs from each device and system in a separate secure location – often on a security appliance within the data centre. By copying the logs to a central repository, the logs can be preserved and made available for forensic analysis any time after the attack occurred. Using a central location to store the logs also allows the SIEM system to secure them and protect them from change. An attacker might try to alter event logs to hide the evidence of their attack, but the secure copies of the logs will allow staff to identify the truth of what has happened in an attack.
SIEM provides a means for both security operations and support staff to take a holistic view of current and historic activity across the network – spot intrusions, attacks, and system problems as well as conduct post-mortem and forensic investigations after and attack. The most import element though is not the SIEM system’s ability to spot a problem and raise an alert, but for a well-trained staff member to see the SIEM alert and respond to it in a timely and appropriate manner.
Cool Waters Managed Cyber Team provides industry leading SentinelOne endpoint protection for PC and Servers combined with a SIEM service that can be installed across your network, which our Security Operations Centre (SOC) team actively monitors 24 hours a day, 7 days a week. The SOC is a dedicated team of experts who proactively manage your cyber security on a day-to-day basis. This includes training and monitoring the SIEM to spot attacks and attempted breaches as they occur and then to respond in real time to contain the intruders or malware.
Our SIEM service, backed up by our SOC, is a cost-effective way to meet the needs of PCI-DSS for daily log monitoring and investigations – including log retention for 12 months.
Book a free discovery call to find out how quickly and easily we can get started.
Further revelations relating to the LastPass Hack in December 2022 indicate that customers who have been using LastPass for longer are more at risk as the encryption applied to their vault has not been updated and improved over time in the way it was for new customers signing up for the service.
The key factor in protecting encrypted data from a brute force attack (guessing all possible password variations) is the number of times the data is hashed (encrypted) using an algorythm called PBKDF. In the olden days - back in the early 2000, computers were slow and passing your data through the PBKDF once was enough to consider it secure. But as computers got faster it became more viable to try to guess all possible permutations and the execution of the encryption function got quicker. So the simple answer was to run the encryption multiple times.
LastPass changed the number of times the data was hashed from 1 to 500 in 2012. Then less than a year later is was increased again to 5000 and then in February 2018 it was changed to 100,100 iterations. That means when you enter your master password to unlock your vault, your computer has to run through the PBKDF process 100,100 times before your data is available.
At least that is the theory - unfortunately it appears that a flaw in LastPass’ design means that when the default number of interations was increased, this was only applied to new customer accounts - existing customers were left using whatever was the default when they signed up.
For me, as a long time LastPass customer, I checked by vault settings today the PBKDF iterations was set to 500 - just 0.005% as strong as LastPass recommends for new customers - which itself is way less than the 300,000 iterations recommended by OWASP.
You can check the password iterations settings in your LastPass vault by going to Settings > Advanced Settings and scrolling down to Password Iterations. This should be at least 100,100 but a value over 300,000 is better.
Although I had a LastPass account from history, I have been using 1Password as my main password manager for many years. 1Password offers a more secure design in that as well as using a password to secure your vault, it also uses a secret key which remains on your computer meaning that even if your password vault were to be stolen from 1Passwords servers, it can never be decrypted without the secret key which remains on your device and is never sent to 1Password.
LastPass Password Iterations - should be ***at least*** 100,100
What should LastPass customers do?LastPass vault encryption does not work in the way you would expect - most of the information stored in the vault is actually not encrypted at all - including the URL of the website the password belongs to, it is only the passwords and usernames that are encrypted.
So the criminals that have stolen everyones LastPass vaults are able to scan every vault easily and look for bank, crypto or valuable business logins and target those accounts either to brute force guess the password (see above) or using phishing or other social engineering to trick people into revealing their vault master password allowing the criminals to access all their passwords.
We recommend the following action plan for LastPass customers
Change the Master Password on your LastPass accountChanging your password will not protect the data already stolen but it will help protect the data still in your vault. Companies that are breached are often targeted again and again so update your security today for the attack that will come tomorrow
Enable MFA on your LastPass accountGo to Account Settings > Multi-factor Options to set up an MFA device such as Google or Microsoft Authenticator
Check the Password IterationsIf your password iterations setting is below 100,100 update the setting to at least 100,100 and then you need to consider changing every password stored in your lastpass vault - or at a minimum all the high value accounts such as: email, banking, crypto wallets and gaming accounts.
Consider changing password managerIf you do decide to change password managers, you should use a different master password on your new account and at least change all the high value passwords in your vault such as: email, banking, crypto wallets and gaming accounts.
Password manager company LastPass have confirmed that customer vault data was stolen in a recent cyber attack. Hackers targeted LastPass’s cloud storage backups at the end of November 2022, where they were able to obtain personal customer information including encrypted passwords. The cyber criminals were able to carry out this data breach due to information they had already stolen back in August 2022 in an attack they performed on the LastPass developer environment. In the August attack cyber criminals stole “cloud storage access key and dual storage container decryption keys”, as well as source code, that allowed them to perform the November attack.
Both encrypted and unencrypted data was stolen from a cloud backup of customer vault data, including plain-text website URLs and encrypted usernames and passwords, secure notes, and form-filled data.
The other data stolen includes basic customer account information such as:
The encrypted username and password data is believed to be unable to be decrypted by the cyber criminals, as each user account has a unique encryption key that is created based on their master password. The master password is not stored anywhere on LastPass servers and so if attackers wanted to access the sensitive data they would have to brute force the master passwords, which LastPass CEO Karim Toubba has said would take “millions of years” based on current password guessing technology.
However, this claim is based on if users follow the strong password guidelines LastPass suggest for the creation of a master password. If these guidelines have not been followed then your master password would be easier to guess, and your data could be more easily decrypted. When the stronger password policy was enforced in 2018 for LastPass master passwords, this was not applied to existing accounts, and so some users may be at risk due to having a less complex and more easy-to-crack master password.
If you now change your master password to be a stronger password, this can help protect your data in any future similar attack, however it will not affect the data that has already been stolen. To protect data that has already been stolen, all individual passwords for each site should be changed that were previously stored in LastPass at the time of the attack. If the recent data breaches have made you want to move to a different password manager, it is possible to recover your data from LastPass to move it across to a new provider, however in order to protect your accounts all passwords should still be changed individually.
To move your current passwords to a new provider, first log into lastpass.com with your login details, then open ‘Advanced Options’ from the left hand menu. Under the heading ‘Manage your vault’ will be the option to ‘Export’. Clicking this will ask you for your login details again, and then you will be able to view your data, which can be saved as a .CSV file. You should not keep this file of passwords longer than is necessary and should enter them into a new password manager as soon as possible, such as DashLane, 1Password, or BitWarden, then delete the .CSV file permanently. You can now go through each website you hold an account with and change each password individually to make sure they are not compromised.
When a company uses the Google Ads platform, they are paying to show up first in the list when a Google Search is performed in order to promote their web page. Google Ads often appear before any actual search results including the official website being searched for, which can cause users to click onto these ads before scrolling further down to see the true search results because they look so similar.
For legitimate users, this makes Google Ads a good source of advertising in order to increase the number of visitors to your website. However, cyber criminals are now abusing this system to create copies of legitimate websites that when visited install malware onto your computer. There are a few ways in which these criminals try to trick their victims into clicking on their malicious site instead of the genuine search result, the first of which is known as typosquatting. This is where the cyber criminals choose a website domain name that is very similar to the legitimate website they are impersonating, except for one or two letters, such as using common typos of the legitimate domain name. This can make it harder to spot a fake website from the real one without inspecting the links carefully.
Normally Google would be able to identify a malicious website that is using their Google Ads platform which results in the ad campaign being blocked and the ads being removed. Unfortunately, cyber criminals have found a way around this, by having the Google Ads direct users to a benign site first when the ad is clicked. As soon as this decoy site is loaded, the user is redirected automatically to the malicious site, where malware is then installed onto the device. When Google check the ads for any suspicious activity, they are taken to the decoy site which is safe, and the ad campaign is not removed by moderators.
This malicious ad campaign has been identified across many large companies that potential victims are searching for and accessing every day. Grammarly, MSI Afterburner, Slack, Dashlane, Audacity, Ring, Visual Studio, Zoom, AnyDesk, Adobe, Discord, and Fortinet are just some of the impersonated websites identified by cybersecurity researchers at Guardio Labs and Trend Micro. Users were tricked into downloading malware from these malicious sites in a bundle with the legitimate software they had gone searching for in the first place. This means that even after falling victim to this cyber crime, because the legitimate software was also present, the installed malware could go unnoticed until it was too late.
The cyber criminals used reputable file-sharing services such as GitHub and Dropbox to deliver these downloads, which would not be likely to raise a red flag with the antivirus software running on the victim’s computer. This combined with the fact the victim had triggered the download on purpose to receive legitimate software, which they do actually end up installing, means the malware would be successfully installed into the computer. If you regularly install software in this way then you may be able to spot an unusual file size when on a malicious site, because it is a bundle of the true software and the dangerous malware. However, this is not always easily identified and not everyone is familiar with what file size to expect for different programmes.
One way you can check the legitimacy of a download is to use a website directory or the company’s Wikipedia page to find the true web link to be sure you are accessing the correct website. Checking the web domain on the Google Ads links carefully for common misspellings or swapped characters can reveal if typosquatting is being used and help you navigate to the correct site instead. If you visit a particular site regularly to download software or updates to an application you use often, then you could bookmark this legitimate web page in order to avoid the risk of accessing a malicious one in the future.
As is often the case with cyber security, the best defence against attack is a well-educated team, that know how to avoid malicious websites and where to safely access software. Especially as these cyber criminals have found a way to bypass antivirus software checks into allowing these sorts of malicious downloads by using trusted file sharing platforms. Fake Google Ads is just one of the ways your team can be tricked into putting your business at risk. Cyber Coach provides Security Awareness Training and managed Cyber Security services for our clients, turning your team from a security risk into a security asset. Learn more with a free consultation with one of our experts today.
For further help in managing cyber defences, consider Cool Waters Managed Cyber Team. The Managed Cyber Team provides a dedicated team of experts for less than the price of one full time employee to proactively manage your cyber security on a day-to-day basis. We look after your cyber security so you can look after your business. For a free review of your cyber defences, click here to arrange a call with one of our consultants: https://www.cool-waters.co.uk/lets-talk
The holiday season brings more users to many websites, for shopping, media streaming, and online gaming. Cyber criminals can use this increase in website traffic to carry out targeted attacks on these websites, causing the site to run slowly, or crash completely. This sort of attack, called a Distributed Denial of Service (DDoS) attack, is on the rise, with the second half of 2021 showing a 43% increase in attacks since the first half of the same year. All holiday seasons where online traffic is increased shows an increase in DDoS attacks being performed against a wide range of targets such as websites and servers for gaming companies and retailers.
The Microsoft Digital Defence Report for 2022 shows trends in DDoS attack frequency from March 2021 to May 2022. Large peaks are seen over the summer holidays in August, and in the October to December holiday period, with a smaller peak seen around springtime holidays in March. The October to December holiday period in previous years has seen an even greater increase in this form of cyber attack. Due to the already increasing traffic to their target websites, cyber criminals are more likely to be able to carry out their attack undetected, as they are hidden by the large amount of legitimate traffic.
What is a DDoS Attack? Attackers attempt to cause disruption to their targets by overwhelming their resources such as by flooding a website with a large amount of traffic. This causes the website to function poorly or can cause a crash that takes it fully offline. DDoS attacks can be performed by individual devices known as bots, or more commonly by a network of devices, called a botnet. These devices will be infected with malware that causes them to perform the attack by sending a very high volume of traffic to the target website. In November last year, Microsoft’s Azure DDoS Protection Team interrupted and stopped one of the largest DDoS attacks ever recorded, where the approximate 10,000 devices performing the attack were found across multiple countries.
DDoS attacks could have a range of motivations behind them, including financial gain for the attackers. In this instance, the attackers will demand a payment to stop the attack that is disrupting the target website’s functionality, essentially holding the website hostage until they are paid. However, these attacks could also be performed by rivals in order to obtain a competitive advantage such as the targeting of ecommerce sites and other online retailers in order to boost sales on a competitor's site. Targeting sites over the holiday period, when the uptime is critical to the business allows the attackers to demand more lucrative pay outs as the victims may choose this solution over the continued loss of revenue and damage to their reputation with customers that would come from their site remaining inaccessible.
Cyber criminals will also often combine DDoS attacks with other forms of cyber attack, such as ransomware. Known as triple extortion ransomware, a cyber criminal can expect a greater financial reward from combining these forms of attack. DDoS attacks can also be used as a distraction tactic, to keep the IT team busy fixing the website and servers while the ‘real’ attack takes place elsewhere in the system, such as a malware infection, or the stealing of confidential data. The prevalence of all cyber crime is increasing with the introduction of many as-a-service models, where less sophisticated criminals can purchase pre-designed cyber attacks that would be otherwise out of their technical skill set.
How to Protect Yourself from DDoS Attacks The Microsoft Digital Defence Report for 2022 revealed that so far in 2022 Microsoft have intercepted, prevented, or stopped nearly 2000 DDoS attacks every day. Whatever your business, having an online presence that clients and customers can interact with means you could be vulnerable to DDoS attacks. The best way to ensure that your business is protected from these sorts of cyber attack is to plan and prepare in advance. Once an attack occurs it is too late to start defence preparations. Without effective planning you will not be able to sufficiently deal with the instance of an attack, so some steps should be taken in advance to prepare your business and server environment and come up with a response strategy in the event of a DDoS attack.
The NCSC (National Cyber Security Centre), a branch of GCHQ in the UK, offer an example response plan to help get you started on your defence preparations. DDoS protection services are also helpful in ensuring your business does not suffer this kind if attack. They can monitor web traffic based on expected normal volume of web traffic, send alerts, and can mitigate suspected attacks in real time. Various services exist that perform very similar protections for businesses of different sizes so whatever your budget there will be a solution available that fits the scale of expected attacks to your site. Monitoring the normal traffic of your sites, servers, and applications is especially helpful, as it can make DDoS attacks easier to identify, even in peak times such as the holiday period.
Running attack simulations to test your defences and response strategy can give you a good picture of how your business will respond in the event of a real attack. This will test the roles assigned to staff within your response strategy as well as any mitigation software you have in place and help you to identify any gaps in your defences. In response to testing it is important to fix any identified weaknesses that could put you at risk in the event of an attack. This is also true after the event of an attack if your business does end up falling victim to a DDoS attack. Although moving on quickly may be your initial goal after an attack, it is important to learn from what allowed the attack to happen in order to protect your business from it happening again.
Keeping all the software you use up to date can reduce the risk of vulnerabilities being exploited and help protect your services even further. The NCSC advise that updates including security patches are applied regularly, and that even when automatic updates are turned on that you continue to monitor the software to determine if any additional updates need to be applied manually.
For further help in managing cyber defences, consider Cool Waters Managed Cyber Team. The Managed Cyber Team provides a dedicated team of experts for less than the price of one full time employee to proactively manage your cyber security on a day-to-day basis. We look after your cyber security so you can look after your business.
For a free review of your cyber defences, click here to arrange a call with one of our consultants: https://www.cool-waters.co.uk/lets-talk
New security updates for Google Chrome and Microsoft Edge have been released as an emergency fix for a security bug that is present in both web browsers.
In cyber security, we discuss risk and risk management on a frequent basis. Read on to understand what risk is, and the simple things you can do to manage risk within your business.
Phishing is a term used to describe cyber crime that targets victims via email, telephone, or text message. We hear it most in reference to malicious emails, where criminals are disguising themselves as legitimate companies to trick their victims into clicking on links in the email or open documents attached to the email.
Ransomware is the biggest cyber threat facing most business owners in the UK today. A 2022 report states that 40% of cyber-attacks experienced by companies were ransomware attacks. Read on to understand what it is, and the surprisingly simple things you can do to protect your business from the risks of ransomware.
When it comes to cybersecurity, there are lots of ways to get it wrong, and far fewer ways to do it right. To keep your company safe from falling victim to the most frequently seen forms of cyber-attack, ask your IT team these 10 questions.
Huge security vulnerabilities with Meeting Owl Pro and Whiteboard Owl devices have been identified that give hackers your personal information and access to all data on your network.
Why do companies like Microsoft and Meta keep asking you to set up Multi-Factor Authentication (MFA) on your accounts?
If you have a business account on any large platform, you will likely have noticed a recent push towards the use of MFA, to the extent that Meta even threatened to remove administrative privileges from Facebook business page owners, preventing them from managing their accounts, unless they started using MFA.
But what exactly is MFA, and does it really make your accounts more secure?
What is Multi-Factor Authentication?Authentication is the process through which we can determine whether someone is who or what they say they are. During an authentication process, ‘factors’ such as login credentials entered by the user are compared to the credentials on file. If a match is found, the login attempt is successful, and the user is granted access. They have proven they are who they say they are by entering the correct details.
There are three types of factors used for authentication:
Something you know
Something you have
ID badges/cards, one-time password (OTPs) via text or on an authenticator app.
Something you are
Biometrics, such as fingerprint scanners and facial recognition.
When you use only one type of factor to authenticate your login attempt this is called single-factor authentication (SFA). It doesn’t matter how many different things you enter while logging in, if they are all of the same type of factor, then you are only using SFA. An example of this is when logging into an account, if you are asked to enter a username, password, and a certain number of digits from a known passcode or memorable word. All of these things you have been from the same factor, therefore this example login only uses one factor of authentication – something you know – to confirm your identity.
Multi-factor authentication uses 2 or more different factors of authentication. Because of this, you may have also heard of MFA described as two-factor authentication (2FA) or two-step verification, although this description is not always accurate as MFA can be a combination of all three factors. We can adapt our example from SFA to MFA by keeping the need to enter our username and password, but changing the request for some digits of a known passcode or memorable word so that instead we are asked for a one-time password (OTP). OTPs can be sent via text, or to an authenticator app (such as Microsoft Authenticator or Google Authenticator). Our phone that is receiving the OTP text, or the device we have our authenticator app installed on is something we HAVE, and our username and password are both something we KNOW. We now have MFA, as this uses two different types of authentication factor.
Why should you use MFA?Using the single-factor authentication of just a username and passcode makes your accounts more vulnerable to hacking attempts. Any mal-intended individual wanting to get into your accounts would only need to guess or steal your login credentials to have full access. With usernames very often being publicly known email addresses, if anyone gets a hold of your password there is no way of preventing them from logging in as you and stealing your data.
Multi-factor authentication, on the other hand, makes it easier to check that the right person is using the credentials. If someone has tracked down your username and password, they cannot log in without also having your second authentication factor, such as a one-time passcode (OTP) generated on an authenticator app. It is very rare that a hacker attempting to access your accounts will be on your device, so they will reach the MFA stage of the login, and not be able to get any further.
How can MFA help my business?A huge advantage of MFA is the increased protection it provides your confidential or sensitive data. The password policies in your business may be dependent on the level of security you require for each account, based on the level of access that account has. For example, an administrative account with full access to the network may need a higher level of login security than a guest account. Passwords are a lot like pants, in that they should not be shared around, or left on display for others to see in the workplace! Your company’s password policies are like pants too - there is not a one-size-fits-all solution.
In addition to this, MFA gives a higher level of assurance that the user logging in really is the person you granted this access to. This is also known as non-repudiation – an employee can’t say that they didn’t change something, or deny that they had access to a file, as the secure authentication process ensures that the users who have the access are the exact people you gave that access to, and no one else. With this level of accountability for all logins, you can be assured your personal and confidential data is safe and secure, leaving you free to focus on other things.
Get in touch for Independent Cyber Security help from someone who is not trying to sell you expensive technology solutions. We provide impartial, expert Cyber Security support for business leaders so that you can be confident that your business is secure, resilient to cyber-crime and your suppliers are providing value for money. This could be a one-off review or ongoing oversight of projects or suppliers.
Cool Waters can help you and your company make sense of cyber security in plain English.
For Cyber Security Awareness Training that keeps you safe and meets your compliance needs for standards like Cyber Essentials, PCI-DSS and ISO 27001, check out Cyber Coach.
Complicated and expensive is how many business leaders think about Cyber Security – but it doesn’t need to be that way. One way we help our clients improve their Cyber Security is by making use of the excellent free to use services offered by the UK’s National Cyber Security Centre.
If you have a Microsoft Exchange Server then you need to urgently check how the Hafnium / Proxylogon hack affects you
Network cables - from Unsplash
The way your office network is designed can make your business more or less secure. Imagine a bank with no internal doors between offices or even to the vault - once the bad guys get in through the window they have free run of the whole bank and can steal anything. Many businesses have a network just like this. A better approach is called Network Segmentation - it puts locked doors on every room in the bank. Learn more about why asking for a segmented network will help your IT team keep your business secure. Read Network Segmentation
The latest underhand technique employed by Ransomware criminals is to buy Facebook Ads in order to try to further intimidate the client into paying up!
It sounds too crazy to be true - but unfortunately it’s not.
Make sure you have backups - and get your team to prove they work - regularly! This is the only effective defence against ransomware.
Read more about this story which affects the Campari drinks company: https://secureteam.co.uk/news/ransomware-group-now-using-fb-ads-to-pressure-victims/
Want to know what cyber security vulnerabilities the bad guys are using to attack your business?
The NSA just published a top 25 list of the vulnerabilities being used by Chinese state sponsored actors... now BEFORE you switch off thinking this doesn't apply to you: look at it this way - if these are the best ways for hackers to target American business, they are almost certainly the best ways for any criminal to target your business. And the shame of it... all these vulnerabilities that are being exploited by the hackers have already been fixed by the software suppliers - its just that businesses have not bothers to install the free updates yet.... (!)
Read the full article here: https://secureteam.co.uk/articles/the-top-10-vulnerabilities-being-exploited-today/