Emerging threats

We support organisations striving to build a trustworthy, safe online environment where users can engage authentically in their communities.
Commercial organisationsWe support commercial organisations operating in a digital world, seeking to protect their reputation and prevent business disruption caused by cyber attacks and compliance breaches.
International programmes and developmentWe support international government organisations and NGOs working to provide infrastructure or improve the capabilities, security and resilience of their nation.
UK government and public sectorWe support UK government organisations responsible for safeguarding critical infrastructure, preserving public trust, and maintaining national security.



A major UK financial services organisation needed to scale its third-party supplier due diligence programme to keep pace with a growing supplier portfolio.
With a large number of suppliers requiring review and limited specialist capacity in-house, the organisation sought a specialist partner who could deliver rigorous assessments at pace — working within their existing tools, processes and compliance framework.
This case study outlines how PGI embedded within the client's environment to more than double their monthly assessment completion rate — and what we found along the way about the systemic risks hiding across their supplier base.
For the methodology, findings, and practical recommendations for maturing your own third-party risk programme:

You have clients approaching you with a brief of what they want. What's the pattern you keep seeing?"Recently I’ve noticed that clients often come in with a clear idea of what they think they need: A specific framework, certification or service they've heard about.

Retail businesses are good at implementing things like new technology and payment channels. What often goes unnoticed is the compliance and operational overhead that accumulates around them, building quietly in the background, year after year, and lingering long after the technology itself has been replaced.

The Ministry of Defence (MoD) recently requested that all industry partners must achieve at least DCC Level 0 by the end of 2026.