Tag Archives: NCSC

Scaling Cyber: A Startup Founder’s Journey from Idea to Exit

This virtual book is a guide to the entrepreneurial journey, drawn from real-world experiences in cyber startups. It distils insights from my time on the NCSC for Startups accelerator (cohort 13, 2023), the DSIT Cyber Runway Scale programme (2024/2025), and my mentoring on DSIT’s Cyber ASAP programme. It’s a collection of lessons, reflections, and hard-earned knowledge from the founders, investors, and industry leaders I’ve met along the way. Thanks to Marcel Duchamp you can think of it as a “ready made”, a curated work built from my blog articles, assembled to help you navigate the path from startup to scale, and beyond.

Continue reading

Overview, Summary, Thoughts, and Recommendations on the NCSC Cyber Security Risk Management Guidance

This article evaluates the NCSC’s Cybersecurity Risk Management Guidance, highlighting its strengths in broad coverage and practical tools but identifying key weaknesses, including the lack of an integrated end-to-end framework, inconsistent depth, and limited audience-specific tailoring. It recommends strengthening the framework’s integration, providing accessible tools, addressing organisational resistance, and incorporating strategies for emerging technologies and black swan events. These enhancements could elevate the guidance to a truly comprehensive standard for diverse organisations.

Continue reading

Masking and Personality Typing: An Asperger’s Perspective

This article explores how masking, often necessary for those with Asperger Syndrome, complicates the accuracy of personality typing systems. Drawing from personal experiences in a challenging post-war inner-city environment, it critiques the limitations of these systems in truly capturing one’s authentic self and offers insights into the interplay between identity, masking, and neurodiversity.

Continue reading

Cyber Governance at a Crossroads: Responding to DSIT’s Consultation

This framing article summarises a set of responses to DSIT’s Cyber Governance Code of Practice consultation in Jan/Feb 2024. It highlights practitioner and institutional submissions, alongside thematic deep dives on law, assurance, incentives, and professionalism. The message: DSIT asked the right questions, but the hardest answers were still missing.

Continue reading

Professionalism and Accountability: Why Cyber Needs Recognition like Law and Engineering

This article argues that DSIT’s Cyber Governance Code of Practice must embed professional recognition for cyber experts, just as directors rely on lawyers, accountants, and engineers. Without a register of recognised professionals, directors risk being accountable without credible support.

Continue reading

Incentives, Not Just Obligations: Driving Real Uptake of Cyber Governance

This article argues that obligations alone will not drive the adoption of DSIT’s Cyber Governance Code of Practice. To succeed, the Code must be backed by incentives — tax relief, insurance benefits, procurement levers, and reputational recognition — that make governance valuable to boards. Obligations can enforce compliance; incentives will create commitment.

Continue reading

From Cyber Essentials to Corporate Governance: Raising the Bar

Cyber Essentials has value as a baseline, but reaches only 0.3% of UK organisations and says little about governance. This article argues that DSIT’s Cyber Governance Code of Practice must raise the bar, from compliance to accountability, from self-attestation to credible assurance, and from one-off certificates to continuous governance. Cyber Essentials is the floor; governance must be the ceiling.

Continue reading

Why Self-Attestation Doesn’t Work: Lessons for the DSIT Code

This article argues that self-attestation has failed as a credible assurance mechanism, citing Cyber Essentials’ low uptake and ISO 27001’s limits. It warns that if DSIT builds the Cyber Governance Code of Practice on self-assessment, it will fail. To succeed, the Code must mandate independent, accredited assurance that directors, investors, and regulators can trust.

Continue reading

Directors and Cyber Responsibility: Towards a New Company Law

This article examines DSIT’s 2024 proposal to embed cyber responsibility into company law. It argues that directors should carry legal duties for cyber resilience, as they already do for finance and health and safety — but only if those duties are proportionate, professionalised, and practical. The consultation did not change the law, but the direction of travel is unmistakable.

Continue reading

Directors and Cyber Governance: My Practitioner’s Response to DSIT’s Consultation

This article revisits my practitioner-led response to DSIT’s 2024 consultation on the Cyber Governance Code of Practice. It highlights key issues I raised: supply chain risk, flaws in self-attestation, tool overload, lack of incentives, and the need for continuous governance. The argument is simple: cyber resilience belongs in the boardroom, but only if policy is grounded in practice.

Continue reading

Before the DSIT Cyber Governance Code of Practice: What the Consultation Proposed

The DSIT Cyber Governance Code of Practice consultation (Jan 2024) proposed five principles for boards: risk management, strategy, people, incident response, and assurance. But it left key gaps: no incentives, little for SMEs, no professional recognition, and weak thinking on assurance. This article argues the consultation was historic, but incomplete — a foundation that required sharper, practitioner-led input.

Continue reading

Comparing SaaS GitHub and Self-Hosted GitLab: An In-Depth Analysis of Pros and Cons with Alternatives

On the penultimate day of the NCSC For Startups programme, there was an ad hoc discussion on code repositories and DevOps tooling. A couple of the cohort were long-time GitHub users, while we use a self-hosted version of GitLab. One of the teams had just moved from the latter to the former, while the final team used Azure DevOps. I thought it would be nice to write up an objective look at the first two options, along with alternatives, as well as summarise our decision. I didn’t want to cover Azure DevOps as I’ve just spent two years using it and I’m grateful to have escaped its clutches. Learn more here.

Continue reading

“What’s Causing a Rise in Seed-Stage Valuations?”: Analysis, Key Takeaways, and Advice

In response to Beauhurst’s article “What’s Causing a Rise in Seed-Stage Valuations?” on seed-stage valuations, this critique offers a concise analysis, highlighting strengths, areas for improvement, and key takeaways. We delve into the complex landscape of seed-stage valuations, exploring the factors behind their rise and assessing the article’s contribution to the discussion.

Continue reading

Thriving in Perpetuity: Simon Sinek’s Infinite Mindset in Action

Explore how Simon Sinek’s Infinite Mindset model can revolutionize organizational strategy and leadership in our comprehensive analysis. This article provides an in-depth look at the model’s principles, showcases their application within the cybersecurity pioneer Cyber Tzar, and offers a step-by-step guide to cultivating an infinite mindset in your own organization. Learn how to lead with vision, adapt with courage, and build a legacy of sustained success.

Continue reading

Empowering Success Through Purpose: Mastering Simon Sinek’s Golden Circle Model

Discover the essence of Simon Sinek’s Golden Circle model in our latest article, where we explore its foundational principles and offer a practical guide to applying it in your organization. Learn how to articulate your purpose, differentiate your approach, and clearly define your offerings to inspire and achieve lasting success. Whether you’re enhancing cybersecurity with Cyber Tzar or navigating another sector, this article provides the insights you need to connect deeply with your audience and turn vision into action.

Continue reading

Crafting Compelling Value: Mastering the Value Proposition Canvas and Mapping

Unlock the full potential of your business offerings with our in-depth guide on the Value Proposition Canvas and Mapping. Learn how to align your products and services precisely with customer needs, crafting a value proposition that speaks directly to your target audience. This article provides a step-by-step approach to understanding customer requirements, optimizing your offerings, and communicating value effectively, setting the stage for enhanced customer satisfaction and business success.

Continue reading