Blog Archive

Cyber Attacks on Water Production in the USA – What You Need to Know

In today’s bulletin, Charlie gives an insight into the recent cyber incidents targeting water companies in the US, and advises on how water companies can strengthen their systems. I have been on holiday for the last couple of weeks, but I have followed these attacks with interest. Having worked in the water industry for eight

Read More »

Practical Business Continuity Exercises: Introducing Charlie’s New Book!

In this week’s bulletin, Charlie gives us an exciting insight into his new published book, ‘Practical Business Continuity Exercises: How to Test Your Organization’s Resilience‘, and discusses the takeaways from the book. After a year of late nights, early mornings, and weekend work, at last I have a copy of my new book on exercises in

Read More »

The UK National Risk Register: Backside Covering and Window Dressing?

In today’s bulletin, Charlie shares his initial thoughts on the recently published UK National Risk Register and provides recommendations for how risk can be better prepared for. This week, during one of my calls, it was mentioned that the new UK National Risk Register had been published on 14th July. It appears to have been

Read More »

How to Incorporate an Organisation’s Use of AI Within Your BIA

In today’s bulletin, Charlie discusses using AI when conducting a Business Impact Analysis (BIA) and gives an insight into the different areas that AI can be used within the BIA. I haven’t written a BIA-focused bulletin for a while, and AI is a subject that continues to fascinate me. This week, I thought I would

Read More »

Providing Advice to Those Impacted by a Data Breach

In today’s bulletin, Charlie discusses communicating with individuals who have been affected by a loss of data and provides an insight into how these individuals can protect themselves in the future. I have been waiting to write this bulletin for a while but needed to find the time to do the research needed. This week,

Read More »

Where Do ISO Standards Come From? (Revised)

In today’s bulletin, Charlie discusses his recent ISO meeting in Berlin and provides an insider’s view of how international ISO standards are developed, reviewed, and published. I have been in Berlin this week at DIN, the German standards agency, as part of an ISO meeting, and I thought I would share what we did and how

Read More »

10 Learning Points on Cyber from Databarracks’ Latest Wargame

In this bulletin, Charlie reflects on taking part in a cyber security wargame and shares ten key lessons organisations should consider when preparing for and responding to a serious cyber incident. On Tuesday, I took part in the latest Databarracks wargame at the People’s History Museum in Manchester. The purpose of the wargame was to

Read More »

Using AI to Conduct a BIA: What Worked and What Didn’t

In today’s bulletin, Charlie gives an insight into conducting a BIA interview using AI and discusses the positives and negatives of the outcome. This week, I have been exploring AI and I wanted to share some thoughts on where I see AI and business continuity going as I learn more about its uses and limitations.

Read More »

Mythos: The New ‘Dangerous’ AI – What You Need To Know

In this week’s bulletin, Charlie gives insight into Claude’s Mythos and its potential negative impacts on organisations. Mythos has been prominent in the news over the last couple of weeks. As I am keen on using AI in my daily work and have a wider interest in how it can change the business continuity profession,

Read More »

Stryker Corporation Cyber Incident Case Study

In today’s bulletin, Charlie discusses Stryker Corporation’s recent cyber attack and provides a timeline of events and the lessons we can learn from the attack. Over the last couple of weeks, I have been doing some research into the Stryker attack. It was interesting to me for a number of reasons. I like writing case

Read More »

From Encryption to Erasure: Understanding Wiper Cyber Attacks

In today’s bulletin, Charlie gives an insight into wiper attacks and how these differ from traditional ransomware cyber attacks, and advises how organisations can protect themselves from these attacks. This week, I have been working on a case study of the Stryker Corporation cyber attack, which was of interest to me as it is collateral

Read More »

Disinformation and the DEPICT Framework

Charlie shares the negative impacts on disinformation and gives an insight into the DEPICT framework which categorises the different types of disinformation. “Fere libenter homines id quod volunt credunt.” – Men willingly believe what they wish. Julius Caesar – Commentaries on the Gallic War I came across the DEPICT framework in one of Philippe Borremans’ ‘Wag

Read More »

The Glasgow Union Street Fire – The Ripple Effect

In today’s bulletin, Charlie discusses the recent fire in Glasgow and the effects it has had on the local community. Although I don’t live in Glasgow itself but in Houston, about 20 miles outside the city, the fire was the talk of the locals and had pushed President Trump and the war with Iran aside

Read More »

The Future of Business Continuity: Cyber, Conflict and Supply Chains

In this bulletin, Charlie discusses how business continuity has evolved in response to COVID‑19, the rise of cyber threats, geopolitical instability (including the Middle Eastern war), and supply chain vulnerabilities, and reflects on whether the profession has the right skills to remain relevant as these risks change. When writing the bulletin “Some Updated Cyber Ransomware

Read More »

Should RTOs Be Aspirational Or Achievable?

In today’s bulletin, Charlie discusses the debate of aspirational vs achievable RTOs (Recovery Time Objectives) and looks at the types of incidents and their impact on our organisation’s RTO. We got all of our consultants together this week and, under the guidance of Simon Freeston, had a session to align our views, outputs, and templates

Read More »

Managing the Impact of a Cyber Attack on a Key Supplier

In today’s bulletin, Charlie discusses how to manage a cyber attack involving a supplier and explains the importance of planning for a potential issue. This week I was on site with a client. On Monday we conducted a half-day training session for their Silver Team and then their Gold Team, while on Tuesday, led by

Read More »

Some Updated Cyber Ransomware Figures

In today’s bulletin, Charlie gives an insight into the latest trends in ransomware data and how this has changed in the last few years. It has been three years since I published a bulletin on the facts and figures of cyber ransomware attacks, and I thought I would look at what the latest data says, especially around:

Read More »

What Is Payment Fraud And What Do I Need To Know About It?

In this week’s bulletin, Charlie discusses payment diversion fraud and how organisations can protect themselves from fraudsters aiming to access financial transactions. I receive daily emails from The Record which lists cyber incidents. Yesterday, the headline read ‘Microsoft disrupts RedVDS cybercrime platform behind $40 million in scam losses’. The article went on to say ‘popular

Read More »

My New Year’s Business Continuity Resolutions of 2026

In his first bulletin of the year, Charlie discusses his business continuity resolutions that he is taking into 2026. In addition to my usual resolutions of going to the gym, losing weight, and reading more books, I thought I would share some business continuity New Year’s resolutions. As they say, if you write them down,

Read More »
Scroll to Top
Scroll to Top