Cyber security explained
An introduction to cyber and AI security.
If you run a smaller or growing organisation, this guide explains the main terms and the kinds of specialist help available. It starts with what you need to protect and how security supports the business.
Start the Cyber Security HealthCheckStart with three useful definitions.
Security helps you protect day-to-day operations, manage the use of new technology and prepare for disruption. Cyber security, AI security and resilience each address part of that work.
- 01
Cyber security
Reducing the chance that crime, mistakes or supplier weaknesses disrupt your business, expose information or allow someone to take over accounts.
- 02
AI security
Managing what data goes into AI tools, who can use them and how their outputs are checked, with clear responsibility for systems that use AI.
- 03
Resilience
Preparing to spot problems, keep essential work running and recover safely after an incident.
The six capabilities.
Each capability page explains when the service is useful and how the work is carried out. An assessment can help you decide which ones you need.
- 01 Incident Response & Cyber InsuranceSpecialist response when an incident occurs, including out of hours, with support for evidence collection and insurance claims. Planning ahead establishes who can make decisions and brings the response team together before an emergency.
- 02 Cyber & AI GRCClear senior responsibility for cyber risk, regulatory requirements and AI use, supported by records that show whether controls work. This gives the board the evidence it needs to make informed decisions.
- 03 Attack SimulationAuthorised testing follows potential attack paths through your systems. It checks how weaknesses could be combined and whether your monitoring and response teams would detect the activity.
- 04 Managed SecuritySpecialists monitor, investigate and respond to threats 24/7. Independent review checks what the service detects, how alerts are assessed and whether escalation works as intended.
- 05 Cloud, Identity, AI & DevSecOpsSpecialist work to secure cloud platforms, user and system access, AI use and software delivery. It addresses how data is stored, who can reach it and how changes are put into production.
- 06 Third-Party Risk & Due DiligenceChecks on suppliers, partners and acquisitions that can access your data or disrupt critical services. Reviews and ongoing monitoring are proportionate to the risk, so decisions use more than an annual questionnaire.
Decide where specialist help will be useful.
Start with the most important risks and agree what needs to be done, who will do it and how you will know the work is complete.
- 01
Explain the business
Describe what you do, which information matters and which activities must keep running.
- 02
Check the basics
Review people, devices, accounts, backups and suppliers, including evidence of the protections already in place.
- 03
Prioritise
Decide which risks need urgent attention and which improvements can follow.
- 04
Choose the specialists
Select the expertise needed and agree how the specialists will work together.
Terms you will hear
Short definitions of the words that appear on the capability pages.
- Incident response
- The people, authority and process used to assess, contain, investigate and recover from a cyber incident.
- GRC
- Governance, risk and compliance: deciding how to meet your obligations, who is responsible and what evidence shows the work has been done.
- Attack simulation
- Authorised testing of how weaknesses could be combined in an attack and whether your organisation would detect it.
- Managed security
- A service that uses specialist staff and technology to monitor, investigate and respond to threats around the clock.
- Third-party risk
- Cyber risk created through suppliers, partners, outsourced services and companies being acquired.