
Risk Domain
Cyber-security
Twelve referenced research reports on cyber-security posture: threat exposure, security controls, regulation, insurance and resilience. Pick a country and an industry; receive a researched PDF.
Each question page in this Domain surfaces senior advisors who have positioned themselves as the experts on that exact risk for the country you select. Read the Risk Briefing; talk to a real expert.
Threat Exposure & Attack Surface
Ransomware is the operational risk most likely to halt a business outright. Modern campaigns steal data before encrypting it, so the event is at once an extortion, an outage and a breach.
This report sets out the ransomware framework in your chosen jurisdiction and industry: the sanctions regimes that make paying a designated group a strict-liability risk, and the parallel notification duties, from GDPR's 72 hours to NIS2's 24.
It documents the scenarios that recur, including plants idled for weeks, hospitals diverting patients and bank systems taken offline, with recovery routinely running into millions before any ransom is considered.
It covers the controls that most reduce severity, immutable tested offline backups, multi-factor authentication, rapid patching and segmentation, and the point at which to engage negotiators, forensic responders and regulatory counsel.
Nation-state and geopolitically-motivated actors pursue objectives ordinary criminals do not: espionage, pre-positioning in critical infrastructure, and disruption timed to events. Exposure follows what an organisation does and where it operates, not merely its size.
This report sets out the state-threat framework in your chosen jurisdiction and industry: the critical-infrastructure duties and rapid reporting that regimes such as NIS2 impose, and the sanctions and export-control limits on dealings with designated actors.
It documents the campaigns that define the risk, compromised software supply chains reaching thousands of downstream organisations, intellectual property stolen at long-term competitive cost, and access pre-positioned in utilities and telecommunications.
It covers the priorities that follow, identity and access management, monitoring for living-off-the-land techniques and vendor assurance, and when to engage a threat-intelligence firm with nation-state experience or the national agency.
Operational-technology and industrial-control systems run the physical world, so a compromise can cause physical damage, safety incidents and prolonged outage. The equipment is often old, hard to patch, and never designed to be networked.
This report sets out the OT and ICS framework in your chosen jurisdiction and industry: the critical-infrastructure duties and 24-hour reporting that NIS2 extends across energy, transport, water and manufacturing, and the control standards that now function as the baseline.
It documents the scenarios that recur, production lines halted, fuel and water distribution disrupted, and precautionary shutdowns costing millions a day, with safety exposure no data breach carries.
It covers the controls that matter, strict IT and OT segmentation, governed remote access, industrial-protocol monitoring and rehearsed manual fallback, and when to engage OT specialists and equipment vendors together.
The fastest-growing route into a well-defended organisation is through a weaker one it trusts. Strong internal controls do not contain this risk, because the breach arrives through legitimate, authorised access.
This report sets out the supply-chain framework in your chosen jurisdiction and industry: the third-party security and oversight duties imposed by NIS2 and DORA, and the data-protection rule that leaves the controller answerable for a processor's breach.
It documents the campaigns that define the exposure, file-transfer and remote-management compromises reaching thousands of organisations from a single vulnerability, with victims bearing notification and litigation costs for a breach they did not cause.
It covers the programme that works, tiering vendors by privileged access, verifying assurances rather than accepting attestations, and contracting for prompt notification, and when to engage counsel and forensic support as a vendor discloses.
Security Posture & Controls
Behind every specific threat sits a question a board should be able to answer: does the organisation meet the security baseline expected of its sector and jurisdiction? Insurers, regulators and major customers increasingly require it before doing business.
This report sets out the controls-baseline framework in your chosen jurisdiction and industry: the recognised standards that now function as the expectation, and the proportionate technical and organisational measures NIS2 requires of essential entities.
It documents what the loss data shows, that firms missing core controls suffer more frequent and more severe incidents, higher premiums or refused cover, and worse regulatory outcomes, with major breaches repeatedly traced to one absent control.
It covers the load-bearing controls to evidence, multi-factor authentication, disciplined patching, endpoint detection, tested backups and least privilege, and when to engage an assessor for independent validation against a sector expectation.
As workloads move to the cloud, the security perimeter becomes identity. Most cloud breaches trace not to a provider failure but to customer misconfiguration: exposed storage, over-privileged accounts, and credentials without multi-factor authentication.
This report sets out the cloud and identity framework in your chosen jurisdiction and industry: the shared-responsibility model, the controller's continuing accountability wherever processing occurs, and the cloud-outsourcing and concentration expectations that DORA formalises.
It documents the scenarios that recur, some of the largest exposures on record from a single unsecured storage bucket or over-permissioned identity, and the operational risk of one identity-provider outage cascading across every dependent service.
It covers the priorities that follow, enforced multi-factor authentication, least-privilege identity, continuous configuration monitoring and encryption at rest, and when to engage cloud-security specialists and data-protection counsel on residency.
Cyber insurance has shifted from a comfort purchase to a conditional contract that both prices and polices security. Cover is more tightly underwritten, and easier to lose at claim time, than most firms assume.
This report sets out the cyber-insurance framework in your chosen jurisdiction and industry: how a policy sits alongside rather than instead of regulatory duty, the sanctions limits on ransom reimbursement, and the effect of a misstatement on an application.
It documents what the market now shows, premiums risen materially, financial services often priced above average, and a rising share of claims declined for unmet conditions such as missing multi-factor authentication or unpatched systems.
It covers the evidence underwriters demand before renewal, and when to engage a specialist broker and counsel to read exclusions, sub-limits and notification conditions, treating the policy's assumptions as a controls checklist.
Governance & Regulation
Cyber-security is now a body of hard law, not best practice, and the obligations vary sharply by jurisdiction and sector. A firm operating across borders may face EU, US federal, US state and sector-specific rules at once.
This report sets out the regulatory framework in your chosen jurisdiction and industry: the regimes that apply, from NIS2 and GDPR to securities disclosure rules and sector regimes, and the deadlines that differ across them.
It documents the enforcement pattern, multi-million penalties for security and disclosure failures, mandated programme rebuilds, and parallel investigations from a single incident, each with its own timeline and disclosure duty.
It covers the mapping exercise that prevents this, the jurisdiction and sector regimes, their duties and exact reporting deadlines, and when to engage regulatory and privacy counsel to validate the map as law and business change.
When a breach happens, the notification decision is often the most consequential and time-critical judgement a firm makes, and the clock starts at discovery, not at convenience. Penalties for getting it wrong can exceed those for the breach.
This report sets out the notification framework in your chosen jurisdiction and industry: how the obligations stack, from GDPR's 72 hours and NIS2's 24-hour initial notice to state and sector deadlines, and why the duty turns on data type and affected individuals.
It documents the pattern regulators have set, penalising late, incomplete or misleading notification as heavily as the breach itself, while a single incident can require dozens of distinct notifications on different timelines.
It covers the preparation that holds under pressure, a current data map, pre-drafted templates and rehearsed ownership, and when to engage breach counsel and forensic specialists to establish scope.
Cyber-security has become a board-level duty with personal dimensions for directors. Inadequate board attention is itself a governance failure, and cyber is no longer wholly delegated to technical staff.
This report sets out the oversight framework in your chosen jurisdiction and industry: the disclosure of board cyber-risk oversight that listed-company rules require, the management-body responsibility and potential personal liability under NIS2, and the rising reasonable-oversight standard.
It documents the consequences where oversight cannot be evidenced, regulatory findings, shareholder derivative suits following major breaches, and direct consequences for officers who overstated security or delayed disclosure.
It covers what demonstrable oversight looks like, board reporting in business terms, a named accountable executive, cyber on the risk register with a defined appetite, and when to engage independent advisers for an external read.
Resilience
Resilience assumes prevention will eventually fail, and measures how quickly and completely the business recovers when it does. Regulators, insurers and customers increasingly judge firms on recovery capability, not defensive controls alone.
This report sets out the resilience framework in your chosen jurisdiction and industry: the testing and recovery requirements DORA sets for financial entities and their ICT providers, the impact tolerances UK operational-resilience rules require, and NIS2's continuity duties.
It documents what the loss data shows, that recovery time more than the initial compromise determines total cost, including organisations reverting to manual operation for extended periods and others unable to restore because backups were themselves encrypted.
It covers what resilience rests on, immutable offline tested backups, defined recovery-time objectives and rehearsed manual fallback, and when to engage incident-response and continuity specialists to validate the plan.
Cyber Suite
All 12 cyber reports for one country and industry.
USD 412 USD 588 Save USD 176 (30%)
Browse other risk domains
HR Risk
HR & Workplace Risk
22 reports from USD 49
BrowseForensic
Forensic Accounting & Investigations
13 reports from USD 49
BrowseForensic Tech
Forensic Technology, eDiscovery & Incident Response
11 reports from USD 49
BrowsePersonal Security
Executive Personal Security
30 reports from USD 49
BrowseFraud
Fraud & Investigations
40 reports from USD 49
BrowseLegal Risk
Legal Risk
40 reports from USD 49
BrowseCompliance
Compliance
40 reports from USD 49
BrowseRegulatory
Regulatory & Government Risk
40 reports from USD 49
BrowseFinancial
Financial Risk
40 reports from USD 49
BrowseDeal
Deal Risk
40 reports from USD 49
BrowseBoardroom
Boardroom Disputes
45 reports from USD 49
BrowseInsurance
Insurance & Claims Risk
45 reports from USD 49
Browse
Reference material for informed readers, not professional advice. Reports are produced against current, verifiable sources; material claims are referenced. Always consult a qualified adviser before acting on the contents of a report.