This week’s threat landscape highlights a continued shift away from traditional malware-centric attacks towards the exploitation of trusted identities, legitimate business processes and increasingly autonomous digital systems.
Cyber security
Supplier Assurance: Assessing and Managing the Risks Presented by Your Organisation’s Suppliers
Arcanum Technical Director, Lawrie Abercrombie, outlines the integral role that supply chains now play in almost every organisation’s operations – and why that can generate risks that need to be managed with care through rigorous supplier assurance. Most organisations...
Arcanum Appointed to BlueLight Commercial Cyber Security Services Framework
We are delighted to announce that Arcanum has been selected as a preferred supplier on the BlueLight Commercial Cyber Security Services Framework, strengthening our position in supporting police forces and fire and rescue services across the UK with independent Cyber...
OT cyber resilience: “availability” is the constraint, not the objective
Arcanum Technical Director, Lawrie Abercrombie, identifies why organisations are often looking in the wrong direction when it comes to improving Operational Technology security and how they can start addressing the right challenges. OT security conversations often...
From “Data Breach” to NIS Enforcement: A CAF-Led Guide for Energy Operators of Essential Services
Arcanum Technical Director, Lawrie Abercrombie, explains how cyber incidents in the energy sector have implications beyond the initial compromise and quickly become a compliance issue. “Under NIS, the question is not whether you had an incident. The question is...
The Cyber Security & Resilience Bill: Why “compliance” is about to become a board-level resilience problem
Arcanum Technical Director, Lawrie Abercrombie, outlines why the UK's new Cyber Security & Resilience Bill is more than a hoop for IT teams to jump through, and how the Arcanum team can support senior leaders to get a handle on incoming regulations. The UK’s Cyber...
Why Scope is the Most Important Decision You Will Make in Your DCC Journey
Chartered Cyber Security Professional and NCSC Head Consultant, Sam Stait breaks down why scope is the most important decision you will make in your DCC journey. DCC takes an organisational view. Unlike previous frameworks that focused primarily on MOD Identifiable...
Common DCC Challenges: Why Organisations Struggle At Assessment Time
Having covered what assessors are looking for, it is worth being direct about where organisations most commonly fall short. The challenges we see are rarely about capability. In most cases, organisations have the controls in place. What lets them down is preparation,...
What Defence Cyber Certification Assessors Actually Look For
Chartered Cyber Security Professional and NCSC Head Consultant, Sam Stait, dives into what we've learnt about the Defence Cyber Certification as we approach the scheme's one year anniversary. One of the most common issues we see with organisations preparing for DCC...
Arcanum strengthens ties with the Welsh defence supply chain
Arcanum attends the inaugural Wales Defence and Security Cluster (WDSC) meeting at the Welsh Government office in Cardiff. In March, Arcanum’s Cullum Morgan Welch was invited to attend the first meeting of the Wales Defence and Security Cluster (WDSC) in the Welsh...
Arcanum welcomes Matthew to the team
Matthew joined Arcanum following two decades of service in the British Army’s Royal Corps of Signals, delivering resilient and secure communications from tactical through to enterprise levels. He brings extensive experience in security operations and incident...
Takeaways from the M&S Cyber Attack: What can we learn from this incident?
The evidence given by senior Marks & Spencer leaders to the Parliamentary SubCommittee on UK Economic Security is one of the most detailed and candid public accounts of a major cyberattack on a British retail institution. Their testimony reveals stark lessons...
Cyber Risk Is Not a Technical Problem – It’s a Storytelling Failure
There are dozens of threads stating authoritatively that you’ve got to be technical to be in cyber. And there are lots of technical people who are really, really, good. But I’ve sat in too many meetings where cyber risks described by a very technically competent...
Professionalising Cyber Security in the UK: Regulation, Accreditation and the Future of the Industry
What would happen if cyber security services in the UK required legal accreditation? A deep dive into regulation, skills, standards, and professionalising cyber security in the UK.
Arcanum’s Festive Stories – “Smarter, Faster, Deadlier” – Charles Dickens’ Take on the AI-Driven Threats Reshaping UK Cyber Security
In the final installment of our series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
Arcanum’s Festive Stories – Missing from the Table: Bah Humbug in the Boardroom
In the sixth of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
Arcanum’s Festive Stories – Great Expectations, Grim Realities: Outsourcing to your MSP
In the fourth of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
Arcanum’s Festive Stories – Ghosts in the machine: Shadow IT
In the fourth of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
Arcanum’s Festive Stories – Fagin’s Digital Pickpockets – The Art of Phishing & Social Engineering
In the third of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
Arcanum’s Festive Stories – Don’t Wait for the Ghost of Breaches Past – Incident Response Readiness
In the second of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
Arcanum’s Festive Stories – A Dickensian Tale of Cyber Peril in the Age of Legacy
In the first of a series of Christmas Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
Planning the move to DCC for defence contractors
DCC – What do defence suppliers need to know?
Navigating Defence Procurement Cyber Security Compliance
Quick Summary: The UK’s Defence Cyber Certification (DCC) and the US’s Cybersecurity Maturity Model Certification (CMMC) set the cyber security standards for defence procurement. Both aim to protect sensitive defence data, but differ in scope, assessment, and cost....
5 Myths About Cyber Essentials – And Why They’re Holding You Back
Cyber Essentials is the UK Government’s baseline cyber security certification - designed to help organisations protect themselves from the majority of common cyber threats. Yet despite its clear benefits, we regularly hear the same misconceptions from businesses of...
Navigating the cyber seas
Navigating the Cyber Seas – Arcanum’s Insights from LISW 2025 London International Shipping Week 2025 (LISW) brought together maritime leaders, regulators, and cyber security experts to address the evolving digital threats facing the global shipping industry. Neil...
COMAH Sites: Cyber Security and Compliance Challenges
For business leaders with responsibility for COMAH, cyber security is fast becoming a top priority. Arcanum provides practical help with cyber security for COMAH site operators.
Defence Cyber Certification (DCC): 5-Step Supplier Guide
Understand the UK MOD’s Defence Cyber Certification (DCC). Follow our 5-step journey to achieve compliance, win contracts, and build cyber resilience.
What’s New? Significant Changes from NCSC CAF 3.2 to CAF 4.0
Discover the key updates in CAF 4.0, the latest Cyber Assessment Framework from the NCSC, released on 6 August 2025. Learn how CAF 4.0 changes impact cyber security standards compared to version 3.2.
Arcanum deliver first DCC certification
Arcanum deliver first DCC certification
Arcanum welcomes Jon to the team
Arcanum welcomes Jon to the team
Armed Forces Day 2025
On Armed Forces Day 2025, we asked Matthew Pemble about his experience in the Armed Forces both as a Regular and a serving Reservist.
Navigating the MOD Defence Cyber Certification Scheme: What Suppliers Need to Know
Navigating the MOD Defence Cyber Certification (DCC) Scheme: What Suppliers Need to Know
Arcanum achieves NCSC Assured status for Security Architecture
Arcanum achieves NCSC Assured status for Security Architecture
Arcanum welcomes Neil to the team
Arcanum welcomes Neil to the team.
Certified ISA/IEC 62443 Experts
After passing all four ISA/IEC 62443 exams, Jonny Keiller and Jack Fairley, Arcanum Cyber Consultants are now certified ISA/IEC 62443 Experts!
Cyber Security in the Commercial Space Sector: Part 3 – Compliance, Training & Emerging Technology
This is part 3 of 3 blogs, written by Sam Stait, Senior Cyber Consultant. Introduction: Why Compliance Matters in Space Cybersecurity In the previous post, "Strengthening the Link: Securing the Supply Chain and responding to incidents", we looked at how securing the...
Cyber Security in the Commercial Space Sector: Part 2 – Strengthening Supply Chains & Responding to Threats
This is part 2 of 3 blogs, written by Sam Stait, Senior Cyber Consultant. In the previous blog, "Cyber Security in the Commercial Space Sector: Part 1 – Governance & Threat Landscape", we looked at how implementing effective cyber security governance, adopting...
The Cyber Security and Resilience Bill
The UK government has unveiled the scope and ambition of the Cyber Security and Resilience Bill, further emphasising that bolstering the UK’s online defences is central to the government’s Plan for Change.
2025 Megabuyte Award Winner!
We are thrilled to announce that Arcanum has been recognised as the best performing company in the IT consulting category within the prestigious 2025 Megabuyte Emerging Stars cohort!
Arcanum welcomes Bradley to the team
Arcanum welcomes Bradley, a cyber security consultant, to the team.
Cyber Security in the Commercial Space Sector: Part 1 – Governance & Threat Landscape
This is part 1 of 3 blogs, written by Sam Stait, Senior Cyber Consultant. “Satellites are increasingly relied upon for nation critical services and the importance of managing cybersecurity risk has never been higher” As a cyber security consultancy in the global space...
Arcanum welcomes Arran to the team
Arcanum welcomes Arran, a cyber security consultant, to the team.
Dydd Gŵyl Dewi Hapus! Happy St David’s Day!
Arcanum is proud to be the only NCSC Assured Cyber Security Consultancy in Wales, and the fastest-growing public sector cyber security consultancy in Wales. As we celebrate St David’s Day, we also celebrate the strong cyber community within Wales, brought together by...
Arcanum welcomes Sinclair to the team
Arcanum welcomes Sinclair, a cyber security consultant, to the team.
Tech200: Highest Ranked Cyber Security Consultancy
We are proud to be recognised as the highest ranked cyber security consultancy on the prestigious Tussell Tech200 list. This ranking highlights Arcanum as one of the fastest-growing UK public sector technology suppliers, reinforcing our reputation as a leader in the...
Introduction to AI Security
Navigating the Risks and Opportunities of AI Security, what does AI Security mean and what Can Be Done?
2024 in review
A few highlights from 2024.
Arcanum recognised as a service provider for the NCSC Cyber Resilience Audit scheme
Arcanum are proud to announce that we are one of the first assured service providers for the National Cyber Security Centre (NCSC) Cyber Resilience Audit (CRA) scheme. This means that we have met the rigorous standards of the CRA scheme, which is overseen by the NCSC....
What is automotive cyber security?
In this article, we will explore automotive cyber security.
What is CHECK & CREST Pen Testing?
In this article, we explore CHECK & CREST pen testing.
What is vishing?
During Cyber Security Awareness month, we will be exploring some cyber related terms you may have heard of but may not fully understand. We hope to raise awareness and ultimately work to improve UK cyber security resilience. In this article, we will explore vishing.
Matthew Pemble awarded Chartered status
Join us in congratulating Matthew Pemble, Lead Security ARchitect, who has been awarded Chartered status for Secure System Architecture & Design by the UK Cyber Security Council.
What is the NCSC, UKCSC & CIISec?
What is the NCSC, UKCSC and CIISec? In this article, we will explore professional bodies and organisations working to keep the UK safe.
UK Data Centres Now Classified as Critical National Infrastructure (CNI) – What It Means for Cyber Security
The UK Government has officially classed data centres as Critical National Infrastructure (CNI). What are the implications, and what experience does Arcanum have in securing CNI?
Why hire a cyber security consultancy? Cyber Assessment Framework
In the 16+ years Arcanum has been operating, we have done all sorts of cyber security jobs for all sorts of clients. Some have been large organisations, some small. Some have been in the Public Sector, some in the Private Sector. Some have been very profitable...
Wendy Goucher awarded Chartered status
Join us in congratulating Wendy Goucher, Cyber Consultant, who has been awarded Chartered status for Risk Management by the UK Cyber Security Council.
Why hire a cyber security consultancy? Employee training
In this post, cyber consultant Wendy Goucher outlines the importance of employee training.
Why hire a cyber security consultancy? Expertise and specialisation
Learn about the specialist expertise required to secure operational technology.
Why hire a cyber security consultancy? Incident response planning
In the 16+ years Arcanum has been operating, we have done all sorts of cyber security jobs for all sorts of clients. Some have been large organisations, some small. Some have been in the Public Sector, some in the Private Sector. Some have been very profitable...
Tamar Everson awarded Chartered status
We are happy to announce that Tamar Everson, Senior Penetration Tester, has been awarded Chartered status for Security Testing by the UK Cyber Security Council. Chartered Cyber Security Professionals have significant practical knowledge in multiple specialisms, and...
Reserves Day 2024
As an Employer Recognition Scheme (ERS) Gold Award holder, Arcanum have demonstrated outstanding support for those who serve and have served. A large proportion of our company have served in the Armed Forces or are still serving as part of the UK Reserves. On Reserves...
Arcanum achieves CHECK accreditation
We are proud to announce that we can now offer CHECK accredited testing to our clients. This means that we have met the rigorous standards of the CHECK Scheme, which is overseen by the National Cyber Security Centre (NCSC) and provides assurance for high-risk...
NIS Regulations. How does it differ from the EU version?
The Network and Information Systems (NIS) Regulations 2018 is the UK’s approach to boost the cyber security of network and information systems that provide essential services and digital services. The UK government laid these regulations in response to the growing...
Lawrie Abercrombie joins CIISec board
We are happy to announce that our co-founder Lawrie Abercrombie is now on the board of directors for the Chartered Institute of Information Security (CIISec). A few words from Lawrie: "CIISec provides a universally accepted focal point for the cyber and information...
NIS2 looms on the horizon. Who’s Ready?
The second iteration of the Network and Information Systems Directive, NIS2, is looming on the horizon. What is it, and how can Arcanum help you prepare?
British Library cyber attack – lessons learned
What can we learn from the British Library cyber attack?
Arcanum achieves NCSC approval for Audit and Review
We are proud to announce that we have been accredited by the NCSC to deliver Assured Cyber Security Consultancy (ACSC) Audit and Review services. This means that we can provide guidance and advice to be able to influence Senior Information Risk Owners or business...
Effective Preparation and Appropriate Response to Cyber Security Incidents: An Analysis of CAF Objective D
This blog piece is the fifth part of our five-part series discussing the National Cyber Security Centre’s (NCSC’s) Cyber Assessment Framework (CAF). Part 1: NCSC’s Cyber Assessment Framework Part 2: Services, Tools, and Resources to Help Your Organisation Understand...
International Women’s Day 2024
For International Women’s Day 2024, we focus on Jane Chappell, co-founder of Arcanum Cyber Security. Since 2008, Jane has jointly led the company, working to protect people, businesses and information. Jane was the first woman to command a cyber unit in the British...
Arcanum conference Malaga 2024
Arcanum have recently returned from our annual company conference, where we were joined by our colleagues from SRM.
Fortifying Your Digital Defences: A Deep Dive into CAF Objective B
This blog piece is the fourth part of our five-part series discussing the National Cyber Security Centre’s (NCSC’s) Cyber Assessment Framework (CAF). Part 1: NCSC’s Cyber Assessment Framework Part 2: Services, Tools, and Resources to Help Your Organisation Understand...
CAF Objective A: The Strong Foundation of Security Risk Management
This blog piece is the third part of our five-part series discussing the National Cyber Security Centre’s (NCSC’s) Cyber Assessment Framework (CAF). Part 1: NCSC’s Cyber Assessment Framework Part 2: Services, Tools, and Resources to Help Your Organisation Understand...
Secure by Design: Revolutionising Cyber Security in the MoD
Blog by Arcanum Defence Relationship Manager, Vicky Carter. In an age where cyber threats are constantly evolving and becoming more sophisticated, it is imperative that organisations and government entities adapt their cyber security practices to stay ahead of the...
Services, Tools, and Resources to Help Your Organisation Understand and Achieve Compliance to the NCSC’s Cyber Assessment Framework: Objective C
The festive season presents a unique set of challenges for organisations in terms of cyber security, and threat actors will seek to exploit the seasonal wind-down followed by periods of minimal staffing, that come at this time of year. That is why we at Arcanum, along...
NCSC’s Cyber Assessment Framework
Blog written by Sam Taylor, Cyber Security Consultant at Arcanum. This blog piece is the first part of our five-part series delving into the National Cyber Security Centre’s (NCSC’s) Cyber Assessment Framework (CAF). In this introductory piece, we will demystify the...
Physical Security considerations in Industrial Environments
Introduction In the world of Industrial Control Systems (ICS) or Operational Technology (OT), a lot of consideration is given to implementing the best technological controls available to mitigate cybersecurity risks, but in many organisations recognising and...
Challenges faced when securing OT/ICS
Industrial Control Systems (ICS) Overview The first Distributed Control Systems used in industry were created around the 1970s. These systems had very limited connectivity, and there was clear segregation between Information Technology (IT) and Operational Technology...
Arcanum Sweeps the UK Cyber Security Council Awards: Celebrating 11 Professional Titles
Eleven Cyber Consultants from leading UK Cyber Security Consultancy Arcanum have been awarded prestigious professional registration titles by the UK Cyber Security Council. The titles were officially awarded on Thursday, 5th of October at the Council’s awards ceremony...
The benefits of working with a CREST accredited Company
Tamar Everson, Senior Pen Tester at Arcanum explains why regular penetration testing by a CREST accredited company is an essential part of any robust cybersecurity strategy. According to the UK Government’s 2023 Cyber Security Breaches Survey, 59% of medium businesses...
Arcanum at Space Comm Expo 2023
Last week, Arcanum exhibited at Space Comm Expo, the UK’s largest Space event. The Arcanum team had a really enjoyable couple of days alongside Space Wales, showcasing our Cyber Security services in the Space Sector. It was a great opportunity for our Consultancy and...
Arcanum will be exhibiting at Space Comm Expo 2023
If you’ve got yourself a Space Comm Expo ticket at Farnborough International Exhibition and Conference Centre, June 7th-8th, head over to the Space Wales stand for a chat with our team about Arcanum’s Cyber Security and Pen Testing services for the Space sector....
Arcanum exhibiting at Cyber Security Expo 2023
Arcanum are exhibiting at the Cyber Security Expo at Aerospace Bristol on the 20th of April. If you’re looking for a career in cyber security, our team will be on hand to talk about our core services and job roles at Arcanum Cyber Security. You’ll find us on stand C4!...
Digital Forensics Case Study: CCTV Analysis – Private Investigation
Digital Forensics and CCTV Evidence Case Study CCTV systems play a vital role in capturing criminal activities. Evidence obtained from a CCTV footage can provide crucial details of the crime. Our digital forensics practitioners are experienced in the recovery of...
Arab International Cybersecurity Conference 2022
Last week Arcanum exhibited at the 3-day Arab International Cybersecurity Conference in Bahrain. As a certified NCSC consultancy, it was a great event for us to exhibit our Cyber Security services to new contacts. Attending the event was Arcanum Co-Owner and Technical...
Lawrie joins panel discussion at Arab International Cybersecurity Conference
Today, Lawrie Abercrombie, Arcanum Co-founder and Technical Director, is part of the panel discussing ‘Securing the future of sustainable energy networks’ as part of the Cyber Leaders Forum at the Arab International Cybersecurity Conference in Bahrain. As economies...
Arcanum will be exhibiting at the Arab International Cybersecurity Summit
Next week, December 6-8th, Arcanum will be exhibiting at the Arab International Cybersecurity Summit in Bahrain. Co-hosted by Bahrain’s National Cyber Security Centre and held under the patronage of His Royal Highness Prince Salman bin Hamad Al Khalifa, Crown Prince,...
Tamar Everson talks all things Cyber Essentials at Midlands CiiSec event
This week Tamar Everson, Arcanum Senior Penetration Tester and Lead Cyber Essentials Assessor spoke at BCS, The Chartered Institute for IT and Midlands Chartered Institute of Information Security's (CiiSec) Cyber Essentials event. The event was hosted at Nottingham...
Cyber Attack on US Airports
Cyber attacks have caused websites at over a dozen US airports to temporarily go offline, with Russian speaking hackers claiming responsibility. These include airports in Atlanta, Chicago, New York and Los Angeles. On Monday morning, LaGuardia airport in New York was...
Kat Abercrombie appointed as UK Cyber Security Council Trustee
We’d like to congratulate Kat Abercrombie, Arcanum Senior Penetration Tester, who began her role as a UK Cyber Security Council (UKCSC) Trustee this week. The UK Cyber Security Council is the self-regulatory body and voice for UK cyber security education, training and...
Arcanum Information Security acquires Security Risk Management Ltd
Arcanum Information Security are delighted to announce that they have acquired a controlling interest in Security Risk Management Ltd. (SRM). SRM’s expertise and experience across a range of cyber security disciplines make them a natural fit within the Arcanum family....
Patch now! Cisco release a security advisory about vulnerabilities in their routers
“Cisco has released a security advisory about several vulnerabilities in the Cisco Small Business RV series routers, covering the RV160, RV260, RV340, and RV345.” Patch now! Cisco VPN routers are vulnerable to remote control – Pieter Arntz, Malware Bytes...
CREST announce new specification document for Penetration Testing
CREST has announced the release of its CREST Defensible Penetration Test, a specification that provides recommendations on how penetration tests should be scoped, delivered and signed off. With significant growth in the numbers of penetration tests being carried out...
Arcanum approved by the Civil Aviation Authority to join the CAA ASSURE scheme
Arcanum Cyber Security have been accredited as a supplier on the Civil Aviation Authority’s (CAA) ASSURE scheme. The ASSURE Scheme provides aviation organisations with a level of assurance in their choice of audit supplier and a structure for how audits should be...
Arcanum Training & Development Week
Arcanum commit to investing in employees by offering training and development programs throughout their career. This week, new Arcanum team members from all areas of the business gathered at the beautiful Severn Manor in Dunley for staff training. The Cyber Risk...
Arcanum Co-founder, Lawrie Abercrombie features in CiiSec newsletter
This week, Arcanum's Co-founder Lawrie Abercrombie, features in CiiSec's members newsletter highlighting individuals who had recently become Fellows members of CiiSec. CIISec is the only pure play information and cyber security institution to have been granted Royal...
What Cyber Essentials is and why it’s important
What is Cyber Essentials? It is a UK Government-backed scheme aimed at increasing the cyber security level of UK businesses. It was launched in 2014 and is operated by the National Cyber Security Centre (NCSC) in combination with its Cyber Essentials partner IASME....
Steve achieves the ISA 99/IEC 62443 Cyber Security Specialist Certification
Steve Rees, Arcanum Cyber Consultant, is now a certified ISA 99/IEC 62443 Cyber Security Specialist. This is a baseline qualification for cyber security professionals covering how the IEC 62443 standard can be implemented to protect Industrial Automation and Control...
Arcanum recognised as a Member of the UK Cyber Security Council
We’re pleased to share the news that Arcanum has been recognised as a Member of the UK Cyber Security Council. The UK Cyber Security Council is the self-regulatory body and voice for UK cyber security education, training and skills. The board of experienced industry...
Arcanum Penetration Testing services receive CREST accreditation
Arcanum’s Penetration Testing services are a consultant lead exercise, designed to expose vulnerabilities that could leave you open to cyber-attacks. Arcanum offer a broad range of services to simulate different types of cyber-attack, and to test organisations...
Lawrie Abercrombie featured in Goldman Sachs report
Arcanum Cyber Security Co-founder, Lawrie Abercrombie has been featured in a Goldman Sachs report following his participation in the 10,000 Small Businesses UK programme. The Goldman Sachs 10,000 Small Businesses UK programme operates nationally and is designed to...
Jane Chappell granted Freedom of the City of London
Yesterday, Arcanum Cyber Security Co-founder, Jane Chappell was granted Freedom of the City of London at the Guildhall London. Jane and her guests were escorted by the Beadle to the Chamberlain’s Court for the ceremony conducted by the Clerk of the Court. Jane was...
Jane Chappell Chairs Inside Housing Keynote Panel Discussion
This week, Arcanum co-founder Jane Chappell chaired a Keynote Panel Discussion at Inside Housing's Connected Futures Summit. Joining Jane on the panel were Rob Miller, Director of Customer Services & ICT London Borough of Hackney and Goher Mohammad, Head of...
Cybersecurity Awareness Month, Week 2: Gone Phishing
Blog by Chris Gausden, Arcanum Principal Consultant. In the old days making money was quite easy for a criminal; you either mugged people, burgled their houses or bought yourself a sawn-off shotgun and robbed the nearest building society or post office. Times have...
Cyber Security Professionals – A Market for Lemons?
Blog by Lawrie Abercrombie, Arcanum Co-founder and Technical Director In 1970, George Akerlof, a US Nobel Prize winning economist wrote a paper on the used car market in the USA titled ‘The Market for Lemons’. It describes a phenomenon where buyers of second-hand...
Cyber security Awareness Month, Week 1: Be Cyber Smart
Blog written by Arcanum Penetration Testing team Strong Passwords/Password Manager Setting passwords is always tricky – you can set something easy to remember but weak or easily guessed like Password1! or something hard to guess, but hard to remember like A@297vBk=....
Lawrie Abercrombie named as Fellow of the Certified Institute of Information Security
Arcanum co-founder and Technical Director, Lawrie Abercrombie has recently joined one of our Principal Consultants, Chris Gausden as a Fellow of the Certified Institute of Information Security (CIISec). CIISec is the only pure play information and cyber security...
Ransomware Attack on US Pipeline
Blog by Lawrie Abercrombie, Arcanum Technical Director Over the weekend a ransomware attack forced the US's largest fuel pipeline operator to shut down its operations. There have been multiple comments in the media along the lines of "why was nothing done to prevent...
You Need To Get With The Process
Blog by Chris Gausden, Arcanum Principal Consultant. I think that it is undisputed that a critical part of any accurate business security risk analysis, is the use of an accurate Business Impact Analysis (BIA), to focus on truly critical business assets. However, I...
An Unhealthy Ransom
Blog by Jane Chappell, Arcanum Operations Director. Following our ‘Stand and Deliver’ ransomware blog published on September 3rd, sadly this form of corporate extortion is still on the increase. Ransomware is not only the encryption of data rendering it unavailable to...
Industrial Clouds On The Horizon
Blog by Chris Gausden, Arcanum Principal Consultant. Despite the title, this is not some scribblings on the subject of chemically vaporous pollution or global warming. However, it does represent a view of managing the practical security and compliance state of current...
Oh… For Compliance Sake!
Blog by Chris Gausden, Arcanum Principal Consultant. I have had an extended career in Cyber Security (AKA Computer security/Information Assurance/Information Assurance and Security etc). During that time I have always perceived the existence of 2 distinct camps; those...
The Fluid World of Cyber Risks in IT and OT
Blog by Chris Gausden, Arcanum Principal Consultant. As part of my far sighted Open University degree in Computer Science in the 1990s, I completed a course that taught the social impacts of IT (before the days of social media); and postulated the future...
Stand and Deliver
Blog by Chris Gausden, Arcanum Principal Consultant. Travelex, Honda, Garmin, Cognizant… who will be the next ‘holdup’ victim of ransomware? [1] Ransomware has been around since the last century. A check on Wikipedia will tell you the first documented attack was...
Practice What You Teach Universities and Cyber Security
Blog by Lawrie Abercrombie, Arcanum's Technical Director, and Chris Gausden, Arcanum Principal Consultant One of the many dichotomies in the Cyber Security world is around the security of universities and their IT assets. Information technology and cyber security are...
A Different Perspective on Protecting Critical National Infrastructure
By Chris Gausden and Lawrie Abercrombie The Australian Government has been quite forward leaning in its approach to cyber security in general and has just published a Consultation Paper titled Protecting Critical Infrastructure and Systems of National Significance as...
Security Gone Cloudy…
Blog by Chris Gausden, Arcanum Cyber Security Principal Consultant. Organisations that haven’t fully migrated to cloud infrastructure and applications must by now be considering it. This has become the standard approach to efficient and resilient business IT services....
Celebrating Cadets Day
Arcanum Managing Director, Russ Wardle, as Deputy Lieutenant for the County of Gwent with Sea Cadets at the Newport D Day parade. Bringing the Armed Forces week to an end, today Arcanum is celebrating Cadets day. Here at Arcanum, we try to support the entirety of the...
The Evolution of Ransomware into Industrial Control Systems
Blog by Chris Gausden, Arcanum Cyber Security Principal Consultant. The publicity around the Wannacray and NotPetya ransomware in 2017 has now been documented and consigned to the history books. Although it was generally acknowledged that this was not a targeted...
Celebrating Reserves Day
Image: Cyber Security Consultant and Royal Navy Reservist, Chris Flynn. Today Arcanum is celebrating Reserves Day, which was created to highlight and recognise the valuable contribution Reservists make to our Armed Forces. Chris Flynn joined Arcanum last year...
Celebrating Armed Forces Week
Arcanum Director, Jane Chappell is Chairman of the Reserve Forces and Cadets Association (RFCA) for Northamptonshire. To mark the start of Armed Forces Week, yesterday Jane was invited to a Flag Raising Ceremony in Northampton. The ceremony took place outside the...
No Lockdown in the Cybercrime World
Blog by Chris Gausden, Arcanum Cyber Security Principal Consultant. Security has been a challenge for many thousands of years, and the advent of IT systems in the 90s merely added a new aspect to this perennial problem. In the past, targeted assets were physically...
The DCMS NIS Regulations Review
The Department for Digital, Culture, Media, and Sport (DCMS) has released a post-implementation review (PIR) of the Network and Information Systems (NIS) Regulations 2018 [1]. It is now two years since the NIS Regulations became law. The aim of the NIS Regulations is...
The USA Declared a National Emergency – Is the Elexon Cyber Attack the UK’s Trigger to Follow Suit?
Blog by Chris Flynn, Arcanum Cyber Security Consultant. The cyber attack on Elexon this week should serve as a warning to the UK’s critical national infrastructure (CNI). It has been noted by thinktank RUSI that cyber-attacks have been on the rise during the CoViD-19...
Arcanum Cyber Security Partners With Toshiba Tec
Arcanum Cyber Security and Toshiba Tec have partnered to provide joint specialist information and cyber security consultancy services. Ben Gaston, Toshiba's UK Sales Director, said: “Given our ambition to disrupt the IT Services market through the provision of...
Could Remote Working Increase the Insider Threat to our Essential Services?
Blog by Chris Flynn, Arcanum Cyber Security Consultant. Recent developments including the current pandemic, technological innovation and climate change have driven a huge rise in the number of remote workers. Our essential services have adapted to this increase...
The Importance of Cyber Security in Design: Zoom & Lessons from my Grandmother
Blog by Chris Flynn, Arcanum Cyber Security Consultant. My Grandmother is a fantastic knitter and often tells me that “a stitch in time, saves nine”. Rather than knitting, I do cyber security but the lesson still resonates; if you’re going to do security stuff, do it...
Blackberry Cylance 2020 Threat Report & The NIS Regulations
Blog by Chris Flynn, Arcanum Cyber Security Consultant. The Blackberry Cylance Threat Report is a report compiled by cyber security experts across many specialisations and is an accurate annual take on the current state of cyber security as well as a look at what is...
Cyber Security for Industrial Automation and Control Systems
Blog by Jane Chappell, Arcanum's Operations Director. Following the trial inspection of COMAH Operators and associated IACS, ICS and OT in 2017, the Health & Safety Executive (HSE) revised its Operational Guidance (OG) 86 “Cyber Security for Industrial Automation...
Defence Against The Dark Arts – Mitigating Against ICS Malware
Blog by Lawrie Abercrombie, Arcanum's Technical Director This month, the UK’s National Cyber Security Centre is hosting an event titled “The Safety and Cyber Security of Industrial Control Systems”. One of the topics is an attack on a Saudi Arabian oil and gas...
Arcanum are listed in the Cyber Security Supplier to Government Scheme
Arcanum are listed under the Cyber Security Supplier to Government Scheme; this means Arcanum are able to publicly advertise our Cyber Security Services to the Government. About Arcanum Group Arcanum Information Security was formed in 2008 and is a leading NCSC...
Cyber Risk Management – It’s not just for the IT Department!
In June this year, Boomerang Video Ltd, a small business selling and renting video games, was fined £60,000 by the Information Commissioner. Why? Because in 2014 an attacker got into its customer database, obtained payment card details and used them to commit...
UK Ports announce trusted Partner Agreement with Arcanum Information Security
UK Ports have recently announced 'Trusted Partner' status for Arcanum Information Security, with Director Bill Anderson stating, "Thanks to Fiona Jobson Arcanum Information Security for excellent work on Cyber security with us at UK Ports." Arcanum Information...
Arcanum: Proudly supporting the Be Cyber Aware at Sea Initiative
We are proud to announce our support of the Be Cyber Aware at Sea Initiative, a global maritime and offshore industry effort to raise awareness of the increasing maritime cyber threats to international shipping, ports and offshore operations. More than 90% of world...
20% of British firms were victims of a cyber-attack in the past year
According to new research released today by the British Chambers of Commerce (BCC), one in five British businesses were hit by a cyber-attack in the last 12 months. The report surveyed more than 1200 businesses across the UK. Of these businesses, 96 percent were SMEs,...































































































































