This week’s threat landscape highlights a continued shift away from traditional malware-centric attacks towards the exploitation of trusted identities, legitimate business processes and increasingly autonomous digital systems.
CNI
When “It’s Just a Data Breach” Becomes a NIS Problem: What Operators of Essential Services Should Learn from South Staffordshire Water
Arcanum Technical Director, Lawrie Abercrombie, outlines how the recent data breach suffered by South Staffordshire Water can be assessed through a compliance and regulatory lens – and what other organisations working in Critical National Infrastructure should take...
COMAH Sites: Cyber Security and Compliance Challenges
For business leaders with responsibility for COMAH, cyber security is fast becoming a top priority. Arcanum provides practical help with cyber security for COMAH site operators.
Cyber Security in the Commercial Space Sector: Part 1 – Governance & Threat Landscape
This is part 1 of 3 blogs, written by Sam Stait, Senior Cyber Consultant. “Satellites are increasingly relied upon for nation critical services and the importance of managing cybersecurity risk has never been higher” As a cyber security consultancy in the global space...
UK Data Centres Now Classified as Critical National Infrastructure (CNI) – What It Means for Cyber Security
The UK Government has officially classed data centres as Critical National Infrastructure (CNI). What are the implications, and what experience does Arcanum have in securing CNI?
Arcanum achieves CHECK accreditation
We are proud to announce that we can now offer CHECK accredited testing to our clients. This means that we have met the rigorous standards of the CHECK Scheme, which is overseen by the National Cyber Security Centre (NCSC) and provides assurance for high-risk...
Effective Preparation and Appropriate Response to Cyber Security Incidents: An Analysis of CAF Objective D
This blog piece is the fifth part of our five-part series discussing the National Cyber Security Centre’s (NCSC’s) Cyber Assessment Framework (CAF). Part 1: NCSC’s Cyber Assessment Framework Part 2: Services, Tools, and Resources to Help Your Organisation Understand...
Fortifying Your Digital Defences: A Deep Dive into CAF Objective B
This blog piece is the fourth part of our five-part series discussing the National Cyber Security Centre’s (NCSC’s) Cyber Assessment Framework (CAF). Part 1: NCSC’s Cyber Assessment Framework Part 2: Services, Tools, and Resources to Help Your Organisation Understand...
CAF Objective A: The Strong Foundation of Security Risk Management
This blog piece is the third part of our five-part series discussing the National Cyber Security Centre’s (NCSC’s) Cyber Assessment Framework (CAF). Part 1: NCSC’s Cyber Assessment Framework Part 2: Services, Tools, and Resources to Help Your Organisation Understand...
Services, Tools, and Resources to Help Your Organisation Understand and Achieve Compliance to the NCSC’s Cyber Assessment Framework: Objective C
The festive season presents a unique set of challenges for organisations in terms of cyber security, and threat actors will seek to exploit the seasonal wind-down followed by periods of minimal staffing, that come at this time of year. That is why we at Arcanum, along...
NCSC’s Cyber Assessment Framework
Blog written by Sam Taylor, Cyber Security Consultant at Arcanum. This blog piece is the first part of our five-part series delving into the National Cyber Security Centre’s (NCSC’s) Cyber Assessment Framework (CAF). In this introductory piece, we will demystify the...
Physical Security considerations in Industrial Environments
Introduction In the world of Industrial Control Systems (ICS) or Operational Technology (OT), a lot of consideration is given to implementing the best technological controls available to mitigate cybersecurity risks, but in many organisations recognising and...
NCSC Annual Review warns of threat to UK’s critical infrastructure
The National Cyber Security Centre's (NCSC) Annual Review offers a compelling narrative on the evolving landscape of cybersecurity. One critical aspect that took centre stage was the escalating importance of industrial cybersecurity. In an era dominated by...
Cyber Attack on DP World Australia
Recent reporting has provided insight into the notable attack against Australia’s biggest ports operator ‘DP World Australia’. DP World Australia detected an unauthorised breach of its network on Friday 10th November 2023, and subsequently disconnected its networks...
Challenges faced when securing OT/ICS
Industrial Control Systems (ICS) Overview The first Distributed Control Systems used in industry were created around the 1970s. These systems had very limited connectivity, and there was clear segregation between Information Technology (IT) and Operational Technology...
Arcanum attend “Adoption of Industrial Digital Technology in UK Manufacturing” workshop
The Arcanum Operational Technology (OT) Team recently attended the “Adoption of Industrial Digital Technology (IDT) in UK Manufacturing Small and Medium Enterprises (SMEs)” workshop at Leeds University. Key insights were that while many manufacturing SMEs wanted to...
Arab International Cybersecurity Conference 2022
Last week Arcanum exhibited at the 3-day Arab International Cybersecurity Conference in Bahrain. As a certified NCSC consultancy, it was a great event for us to exhibit our Cyber Security services to new contacts. Attending the event was Arcanum Co-Owner and Technical...
Lawrie joins panel discussion at Arab International Cybersecurity Conference
Today, Lawrie Abercrombie, Arcanum Co-founder and Technical Director, is part of the panel discussing ‘Securing the future of sustainable energy networks’ as part of the Cyber Leaders Forum at the Arab International Cybersecurity Conference in Bahrain. As economies...
Arcanum approved by the Civil Aviation Authority to join the CAA ASSURE scheme
Arcanum Cyber Security have been accredited as a supplier on the Civil Aviation Authority’s (CAA) ASSURE scheme. The ASSURE Scheme provides aviation organisations with a level of assurance in their choice of audit supplier and a structure for how audits should be...
Steve achieves the ISA 99/IEC 62443 Cyber Security Specialist Certification
Steve Rees, Arcanum Cyber Consultant, is now a certified ISA 99/IEC 62443 Cyber Security Specialist. This is a baseline qualification for cyber security professionals covering how the IEC 62443 standard can be implemented to protect Industrial Automation and Control...
Ransomware Attack on US Pipeline
Blog by Lawrie Abercrombie, Arcanum Technical Director Over the weekend a ransomware attack forced the US's largest fuel pipeline operator to shut down its operations. There have been multiple comments in the media along the lines of "why was nothing done to prevent...
You Need To Get With The Process
Blog by Chris Gausden, Arcanum Principal Consultant. I think that it is undisputed that a critical part of any accurate business security risk analysis, is the use of an accurate Business Impact Analysis (BIA), to focus on truly critical business assets. However, I...
Industrial Clouds On The Horizon
Blog by Chris Gausden, Arcanum Principal Consultant. Despite the title, this is not some scribblings on the subject of chemically vaporous pollution or global warming. However, it does represent a view of managing the practical security and compliance state of current...
Oh… For Compliance Sake!
Blog by Chris Gausden, Arcanum Principal Consultant. I have had an extended career in Cyber Security (AKA Computer security/Information Assurance/Information Assurance and Security etc). During that time I have always perceived the existence of 2 distinct camps; those...
The Fluid World of Cyber Risks in IT and OT
Blog by Chris Gausden, Arcanum Principal Consultant. As part of my far sighted Open University degree in Computer Science in the 1990s, I completed a course that taught the social impacts of IT (before the days of social media); and postulated the future...
Practice What You Teach Universities and Cyber Security
Blog by Lawrie Abercrombie, Arcanum's Technical Director, and Chris Gausden, Arcanum Principal Consultant One of the many dichotomies in the Cyber Security world is around the security of universities and their IT assets. Information technology and cyber security are...
A Different Perspective on Protecting Critical National Infrastructure
By Chris Gausden and Lawrie Abercrombie The Australian Government has been quite forward leaning in its approach to cyber security in general and has just published a Consultation Paper titled Protecting Critical Infrastructure and Systems of National Significance as...
Security Gone Cloudy…
Blog by Chris Gausden, Arcanum Cyber Security Principal Consultant. Organisations that haven’t fully migrated to cloud infrastructure and applications must by now be considering it. This has become the standard approach to efficient and resilient business IT services....
The Evolution of Ransomware into Industrial Control Systems
Blog by Chris Gausden, Arcanum Cyber Security Principal Consultant. The publicity around the Wannacray and NotPetya ransomware in 2017 has now been documented and consigned to the history books. Although it was generally acknowledged that this was not a targeted...
No Lockdown in the Cybercrime World
Blog by Chris Gausden, Arcanum Cyber Security Principal Consultant. Security has been a challenge for many thousands of years, and the advent of IT systems in the 90s merely added a new aspect to this perennial problem. In the past, targeted assets were physically...
The DCMS NIS Regulations Review
The Department for Digital, Culture, Media, and Sport (DCMS) has released a post-implementation review (PIR) of the Network and Information Systems (NIS) Regulations 2018 [1]. It is now two years since the NIS Regulations became law. The aim of the NIS Regulations is...
The USA Declared a National Emergency – Is the Elexon Cyber Attack the UK’s Trigger to Follow Suit?
Blog by Chris Flynn, Arcanum Cyber Security Consultant. The cyber attack on Elexon this week should serve as a warning to the UK’s critical national infrastructure (CNI). It has been noted by thinktank RUSI that cyber-attacks have been on the rise during the CoViD-19...
Arcanum Cyber Security Partners With Toshiba Tec
Arcanum Cyber Security and Toshiba Tec have partnered to provide joint specialist information and cyber security consultancy services. Ben Gaston, Toshiba's UK Sales Director, said: “Given our ambition to disrupt the IT Services market through the provision of...
Could Remote Working Increase the Insider Threat to our Essential Services?
Blog by Chris Flynn, Arcanum Cyber Security Consultant. Recent developments including the current pandemic, technological innovation and climate change have driven a huge rise in the number of remote workers. Our essential services have adapted to this increase...
Blackberry Cylance 2020 Threat Report & The NIS Regulations
Blog by Chris Flynn, Arcanum Cyber Security Consultant. The Blackberry Cylance Threat Report is a report compiled by cyber security experts across many specialisations and is an accurate annual take on the current state of cyber security as well as a look at what is...
Cyber Security for Industrial Automation and Control Systems
Blog by Jane Chappell, Arcanum's Operations Director. Following the trial inspection of COMAH Operators and associated IACS, ICS and OT in 2017, the Health & Safety Executive (HSE) revised its Operational Guidance (OG) 86 “Cyber Security for Industrial Automation...


































