Lasting change in the private sector’s attitude to threats is key to achieving better cyber security, says APMG

Lasting change in the private sector’s attitude to threats is key to achieving better cyber security, says APMG GCHQ seeks to draw…
Firefly biometrics with a cyber digital background abstract

Share this article:

Lasting change in the private sector’s attitude to threats is key to achieving better cyber security, says APMG

GCHQ seeks to draw line under the UK organisations’ poor cyber strategies

In a speech delivered to CESG’s IA15 conference last week, Robert Hannigan, director of intelligence and GCHQ, declared that the international market for cyber security is flawed, as the provisions of cyber security measures do not meet the demand, assuming there is significant demand at all.

Usually reluctant to speak publicly, Hannigan’s warning to the UK’s public and private sectors comes at the same time as GCHQ recently disclosed climbing cyber crime statistics. The British intelligence agency now identifies 200 major cyber attacks every month, double last year’s figure.

According to Richard Pharro, CEO of APMG International, CIOs and CISOs should use Hannigan’s speech as a means of raising the importance of improved security strategies with the board as an important first step towards establishing a safe online culture across their organisation.

Richard Pharro, commented:

“To prevent these numbers creeping up, and reflecting on the balance sheet of large UK businesses, it’s essential that organisations take a proactive approach to securing their infrastructure. Hannigan recognises CIOs and CISOs in UK organisations simply aren’t keeping up with the pace of change, and so are increasingly overwhelmed by the threat of cyber attacks.”

Pharro continued:

“Although time and again the latest hack is dutifully followed by a flurry of public statements making claim to a renewed focus and tightening of internal security standards, most organisations have already proved there is far too much inertia in the industry for a large scale cyber attack to have a meaningful impact on changing behaviours. The carrot and stick assumption that companies have continually worked to improve their security is now inappropriate; security strategies cobbled together in response to the latest threat simply aren’t enough. Instead, to achieve coherent and sweeping change, business leaders must assume greater responsibility for the security of their data.”

In order to instigate this widespread change, Hannigan suggested the introduction of disclosure requirements for businesses along with greater liability and tougher regulation of standards.

“Any large-scale attack could threaten jobs and detract from the credibility of big business, however, there are wider implications to organisations not directly embroiled in the hack. BT’s Chief Executive believes the TalkTalk hack, for instance, could have caused a lasting loss of trust in the telecoms industry as a whole. While companies have traditionally been thought to provide adequate security, ‘adequate’ security in some boardrooms is defined by the actions of cyber attackers, rather than the proactive security strategy put in place across the organisation.”

However, one of Hannigan’s key messages was that it is not the government’s job to prevent risk among organisations.

Pharro continued:

“Companies invite instability into their infrastructure through an incomplete, reactive approach to the protection of their systems. By their nature, the methods hackers use to approach a company’s infrastructure continually change, so organisations are required to mitigate the threat of new attacks as though these attack vectors have already proven to have breached defences elsewhere.

“The onus is on the private sector to account directly for imperfections in security strategies. With cyber assessment tools, such CDCAT (Cyber Defence Capability Assessment Tool), appetite for risk and the degree of control an organisation has over their infrastructure can be identified with a view to improving preparedness in the case of an attack. Only with this information is it possible for CISOs to raise the importance of cyber security with the Board,” he concluded.

[su_button url=”http://www.apmg-international.com/” target=”blank” style=”flat” background=”#df2027″ color=”#ffffff” size=”10″ radius=”0″ icon=”icon: arrow-circle-right”]Click here to find out more about APMG International[/su_button]

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Verkada

Verkada Expands AI Security Platform

Verkada, a provider of AI-powered physical security and operations, has unveiled new capabilities for vehicle fleets, enterprise sound systems, and building operations during its annual customer conference, VerkadaOne.
Assa Abloy

“Mobile-first” access 

David Moser, of ASSA ABLOY Opening Solutions EMEIA explores how mobile digital access unlocks new possibilities for organizations everywhere.
Traka - securitybuyer.com

Integrating Digital and Physical Security

Tom Smith, Vice President and Head of EMEIA for Traka, discusses convergence and the expanding role of integrated key and asset management. 
Traka GSX

GSX Exhibitor Spotlight – Traka

Traka, an ASSA ABLOY company and the global leader in intelligent management solutions for keys and equipment, returns to GSX 2026 at Booth #1233. Traka experts will be available to provide personal demonstrations of how smart asset management systems are streamlining operations in numerous industry verticals. 
Rhombus GSX

GSX Exhibitor Spotlight – Rhombus

When it comes to modernising physical security, Rhombus stands out by making it smarter, simpler, and genuinely easier to manage; no matter the size or complexity of the business. 
Keynetics at Essen - securitybuyer.com

Keynetics to Debut at Security Essen 2026

The UK-based Keynetics will exhibit at Security Essen for the first time, showcasing SentriGuard, its smart key-management
Scroll to Top