Cybersecurity risk is no longer driven by lack of technology. It is driven by misunderstanding responsibility.
This month’s newsletter focuses on three assumptions that continue to expose organisations.
The belief that certification equals security. The belief that cloud platforms are secure by default. The belief that data in the cloud is automatically protected.
All three are wrong.
Each creates a gap between what organisations think is happening and what is actually in place. That gap is where incidents occur, audits fail, and trust is lost.
The common thread is accountability.
Whether it is controls, configuration, or data protection, responsibility remains with the business.
If that is not clearly understood, risk is being accepted by default rather than managed deliberately.
Many organisations approach cybersecurity accreditation with the wrong objective.
The question is often framed as whether there is a badge that can be displayed following certification to Cyber Essentials, CAF, or ISO 27001. While such badges do exist, focusing on them reflects a misunderstanding of what cybersecurity is intended to achieve.
Cybersecurity should not be viewed as only a marketing asset. It is an operational discipline.
Frameworks and certifications provide structured guidance on how to manage risk. They define controls, processes, and governance expectations. However, their annual review they represent point in time assurance, not an enduring state of security.
Organisations are not static. Systems evolve, business models change, and new technologies are introduced. At the same time, threat actors continuously adapt their methods. A control environment that was appropriate at the point of certification degrades quickly if it is not actively maintained.
The risk appears when cybersecurity is treated as a finite project.
This creates a gap between documented controls and operational reality, which is exactly where audits fail and incidents occur.
Effective cybersecurity requires continuous engagement.
Standards such as ISO 27001 and schemes such as Cyber Essentials are valuable when used correctly. They provide a baseline and a common language for risk management. They should shape how an organisation operates, not simply how it demonstrates compliance.
Final Thought
A badge may support commercial credibility. It does not reduce risk. Cybersecurity only delivers value when it is embedded into daily operations, continuously maintained, and owned at a strategic level. Treat accreditation as the end, and you create exposure. Treat it as the starting point, and you build resilience.

The adoption of cloud platforms has accelerated rapidly across all sectors. Services such as Microsoft 365, Azure, SharePoint, Google Workspace, and AWS are now embedded into core business operations.
With that adoption comes a common and often unchallenged assumption.
If the platform is secure, then the organisation using it must also be secure.
That assumption is wrong.
Cloud providers deliver secure infrastructure, high availability, and a wide range of security capabilities. However, they operate under a shared responsibility model. The provider secures the underlying platform. The customer is responsible for how services are configured, accessed, and managed.
This is where risk is introduced.
Most cloud security incidents are not caused by platform failure. They are caused by misconfiguration and weak governance.
Common issues include:
The complexity of modern cloud environments amplifies the problem. Services are deployed quickly to support growth, often without clear ownership or baseline configurations.
Third party tools can strengthen visibility and control, particularly in areas such as threat detection, identity and access management, configuration monitoring, and centralised logging.
However, tools do not solve governance failures.
Clear accountability is required.
Cloud providers are explicit. Responsibility is shared, not transferred.
Final Thought
Cloud platforms give you the tools to build a secure environment. They do not build it for you. Assume security is included, and you create unmanaged risk. Security in the cloud comes from deliberate configuration, strong governance, and continuous oversight.

As organisations increasingly rely on cloud platforms, a related assumption has become widespread.
If data is stored in Microsoft 365, Google Workspace, or AWS, it is automatically backed up and recoverable.
That assumption is wrong.
Cloud platforms are designed for resilience and availability. They replicate data across infrastructure and protect against hardware failure. This is not the same as having a backup strategy.
The same shared responsibility model applies.
The provider ensures the service runs.
You are responsible for your data.
This becomes critical when something goes wrong.
Data loss rarely comes from infrastructure failure.
In many of these scenarios, native recovery options are limited.
Be precise.
A proper backup strategy gives you control through independent, recoverable copies of your data, defined recovery points and timelines, and the ability to restore operations with confidence after both accidental and malicious loss.
Third party backup solutions exist to address this gap. However, their effectiveness depends on alignment with business requirements.
You must define:
Without that clarity, backup solutions may exist but fail when needed.
Final Thought
Data is a core business asset. Its protection cannot be assumed. Cloud platforms provide availability, not guaranteed recovery. If you do not take ownership of your backup strategy, you will discover the gap during an incident, when recovery options are limited and the impact is immediate.

