The evidence given by senior Marks & Spencer leaders to the Parliamentary SubCommittee on UK Economic Security is one of the most detailed and candid public accounts of a major cyberattack on a British retail institution. Their testimony reveals stark lessons...
Cyber Crime Updates
Arcanum Cyber Security Review 2025
Just before our team closed their laptops and headed off for the Christmas break, we invited some of our senior team to reflect on the cyber landscape as part of a virtual round table event.Jane Chappell, Chris Flynn, Sam Stait and Jonny Keiller took some time to...
British Library cyber attack – lessons learned
What can we learn from the British Library cyber attack?
Physical Security considerations in Industrial Environments
Introduction In the world of Industrial Control Systems (ICS) or Operational Technology (OT), a lot of consideration is given to implementing the best technological controls available to mitigate cybersecurity risks, but in many organisations recognising and...
Cyber Attack on US Airports
Cyber attacks have caused websites at over a dozen US airports to temporarily go offline, with Russian speaking hackers claiming responsibility. These include airports in Atlanta, Chicago, New York and Los Angeles. On Monday morning, LaGuardia airport in New York was...
Arcanum recognised as a Member of the UK Cyber Security Council
We’re pleased to share the news that Arcanum has been recognised as a Member of the UK Cyber Security Council. The UK Cyber Security Council is the self-regulatory body and voice for UK cyber security education, training and skills. The board of experienced industry...
Jane Chappell granted Freedom of the City of London
Yesterday, Arcanum Cyber Security Co-founder, Jane Chappell was granted Freedom of the City of London at the Guildhall London. Jane and her guests were escorted by the Beadle to the Chamberlain’s Court for the ceremony conducted by the Clerk of the Court. Jane was...
Jane Chappell Chairs Inside Housing Keynote Panel Discussion
This week, Arcanum co-founder Jane Chappell chaired a Keynote Panel Discussion at Inside Housing's Connected Futures Summit. Joining Jane on the panel were Rob Miller, Director of Customer Services & ICT London Borough of Hackney and Goher Mohammad, Head of...
Cybersecurity Awareness Month, Week 2: Gone Phishing
Blog by Chris Gausden, Arcanum Principal Consultant. In the old days making money was quite easy for a criminal; you either mugged people, burgled their houses or bought yourself a sawn-off shotgun and robbed the nearest building society or post office. Times have...
Cyber security Awareness Month, Week 1: Be Cyber Smart
Blog written by Arcanum Penetration Testing team Strong Passwords/Password Manager Setting passwords is always tricky – you can set something easy to remember but weak or easily guessed like Password1! or something hard to guess, but hard to remember like A@297vBk=....
Lawrie Abercrombie named as Fellow of the Certified Institute of Information Security
Arcanum co-founder and Technical Director, Lawrie Abercrombie has recently joined one of our Principal Consultants, Chris Gausden as a Fellow of the Certified Institute of Information Security (CIISec). CIISec is the only pure play information and cyber security...
An Unhealthy Ransom
Blog by Jane Chappell, Arcanum Operations Director. Following our ‘Stand and Deliver’ ransomware blog published on September 3rd, sadly this form of corporate extortion is still on the increase. Ransomware is not only the encryption of data rendering it unavailable to...
Industrial Clouds On The Horizon
Blog by Chris Gausden, Arcanum Principal Consultant. Despite the title, this is not some scribblings on the subject of chemically vaporous pollution or global warming. However, it does represent a view of managing the practical security and compliance state of current...
Oh… For Compliance Sake!
Blog by Chris Gausden, Arcanum Principal Consultant. I have had an extended career in Cyber Security (AKA Computer security/Information Assurance/Information Assurance and Security etc). During that time I have always perceived the existence of 2 distinct camps; those...
The Fluid World of Cyber Risks in IT and OT
Blog by Chris Gausden, Arcanum Principal Consultant. As part of my far sighted Open University degree in Computer Science in the 1990s, I completed a course that taught the social impacts of IT (before the days of social media); and postulated the future...
Stand and Deliver
Blog by Chris Gausden, Arcanum Principal Consultant. Travelex, Honda, Garmin, Cognizant… who will be the next ‘holdup’ victim of ransomware? [1] Ransomware has been around since the last century. A check on Wikipedia will tell you the first documented attack was...
Practice What You Teach Universities and Cyber Security
Blog by Lawrie Abercrombie, Arcanum's Technical Director, and Chris Gausden, Arcanum Principal Consultant One of the many dichotomies in the Cyber Security world is around the security of universities and their IT assets. Information technology and cyber security are...
A Different Perspective on Protecting Critical National Infrastructure
By Chris Gausden and Lawrie Abercrombie The Australian Government has been quite forward leaning in its approach to cyber security in general and has just published a Consultation Paper titled Protecting Critical Infrastructure and Systems of National Significance as...
Security Gone Cloudy…
Blog by Chris Gausden, Arcanum Cyber Security Principal Consultant. Organisations that haven’t fully migrated to cloud infrastructure and applications must by now be considering it. This has become the standard approach to efficient and resilient business IT services....
The Evolution of Ransomware into Industrial Control Systems
Blog by Chris Gausden, Arcanum Cyber Security Principal Consultant. The publicity around the Wannacray and NotPetya ransomware in 2017 has now been documented and consigned to the history books. Although it was generally acknowledged that this was not a targeted...
No Lockdown in the Cybercrime World
Blog by Chris Gausden, Arcanum Cyber Security Principal Consultant. Security has been a challenge for many thousands of years, and the advent of IT systems in the 90s merely added a new aspect to this perennial problem. In the past, targeted assets were physically...
The DCMS NIS Regulations Review
The Department for Digital, Culture, Media, and Sport (DCMS) has released a post-implementation review (PIR) of the Network and Information Systems (NIS) Regulations 2018 [1]. It is now two years since the NIS Regulations became law. The aim of the NIS Regulations is...
The USA Declared a National Emergency – Is the Elexon Cyber Attack the UK’s Trigger to Follow Suit?
Blog by Chris Flynn, Arcanum Cyber Security Consultant. The cyber attack on Elexon this week should serve as a warning to the UK’s critical national infrastructure (CNI). It has been noted by thinktank RUSI that cyber-attacks have been on the rise during the CoViD-19...
Arcanum Cyber Security Partners With Toshiba Tec
Arcanum Cyber Security and Toshiba Tec have partnered to provide joint specialist information and cyber security consultancy services. Ben Gaston, Toshiba's UK Sales Director, said: “Given our ambition to disrupt the IT Services market through the provision of...
Could Remote Working Increase the Insider Threat to our Essential Services?
Blog by Chris Flynn, Arcanum Cyber Security Consultant. Recent developments including the current pandemic, technological innovation and climate change have driven a huge rise in the number of remote workers. Our essential services have adapted to this increase...
The Importance of Cyber Security in Design: Zoom & Lessons from my Grandmother
Blog by Chris Flynn, Arcanum Cyber Security Consultant. My Grandmother is a fantastic knitter and often tells me that “a stitch in time, saves nine”. Rather than knitting, I do cyber security but the lesson still resonates; if you’re going to do security stuff, do it...
Cyber Security for Industrial Automation and Control Systems
Blog by Jane Chappell, Arcanum's Operations Director. Following the trial inspection of COMAH Operators and associated IACS, ICS and OT in 2017, the Health & Safety Executive (HSE) revised its Operational Guidance (OG) 86 “Cyber Security for Industrial Automation...
Defence Against The Dark Arts – Mitigating Against ICS Malware
Blog by Lawrie Abercrombie, Arcanum's Technical Director This month, the UK’s National Cyber Security Centre is hosting an event titled “The Safety and Cyber Security of Industrial Control Systems”. One of the topics is an attack on a Saudi Arabian oil and gas...



























