top of page
An Analysis of ASD's PQC Vendor Approach.
One supplier can destroy five years of post-quantum planning. Not through incompetence. Through dependency. The conversation around post-quantum cryptography still revolves around algorithms, migration plans and technical roadmaps. That misses the point. Modern organisations no longer control much of their own cryptography. It sits inside cloud platforms, software, managed services, operational technology and hardware supplied by third parties. Your programme cannot move fast
Brian Couzens
Jul 161 min read


Kudankulam Shows Why Critical Infrastructure Security Is a Governance Problem, Not Just a Cybersecurity Problemcff
Sensitive documents reportedly linked to India's Kudankulam Nuclear Power Plant have been exposed following a ransomware attack affecting a contractor. According to Reuters, the leaked material includes engineering drawings, supplier information and inspection records, while there is currently no evidence that reactor control systems themselves were compromised. That distinction matters. Too often, critical infrastructure security is viewed through the lens of perimeter defen
Brian Couzens
Jul 151 min read


A Watershed Moment for UK Financial Regulation - Or Just the Beginning?
The designation of #Amazon Web Services, #Microsoft, #Google Cloud, and #Oracle as the UK’s first Critical Third Parties (#CTPs) is not just another operational resilience milestone. It is a structural shift in where systemic risk is understood to live-and who regulators believe must be accountable for it. For the first time under the Financial Services and Markets Act 2023, the Bank of England, #PRA, and #FCA will exercise direct, joint oversight over organisations that sit
Brian Couzens
Jul 142 min read
bottom of page