Emerging threats

We support organisations striving to build a trustworthy, safe online environment where users can engage authentically in their communities.
Commercial organisationsWe support commercial organisations operating in a digital world, seeking to protect their reputation and prevent business disruption caused by cyber attacks and compliance breaches.
International programmes and developmentWe support international government organisations and NGOs working to provide infrastructure or improve the capabilities, security and resilience of their nation.
UK government and public sectorWe support UK government organisations responsible for safeguarding critical infrastructure, preserving public trust, and maintaining national security.



"Recently I’ve noticed that clients often come in with a clear idea of what they think they need: A specific framework, certification or service they've heard about. And as a consultant, it would be easy to just blindly run with that. The brief is already set, the client seems confident and then it’s my job to explain how I can fulfil that need, sometimes with little scope to move outside of what they’ve asked for.
What I've found is that what a client says they want and what they actually need aren't always the same thing. If you don't take the time to probe it and understand the real business context, you risk delivering something that solves the wrong problem, or creates new problems later."
"I was recently on a client call discussing how we could support them on their ISO 27001 certification journey. During the call, the client asked: “do you think a business like ours actually needs this?”.
This led to a much more valuable conversation that became a feasibility assessment."
"The aim was to understand why they thought they needed ISO 27001, identify who was driving that Information Security requirement, any issues they foresee in becoming ISO compliance and what they were trying to achieve.
This then allowed me to tell them what their scope would actually look like in reality – and to flesh it out, learn about their business; including locations, people, systems, and functions.
From these conversations, I could then map out what their compliance roadmap should look like."
"Exactly. And whilst this example still focuses on a specific framework, what I'm actually doing is working with the client as a ‘Trusted Advisor’. I'm putting myself in a position to learn about the business to truly identify gaps and ways I can support them in a cost-effective way.
If I sell someone something they don't need or don't want to follow through on long term, that becomes a blocker to delivery. As an advisor, I can identify solutions based on what they actually need. This could be simplifying scope, identifying issues they didn't know they had or flagging services they'd never considered.
Most clients appreciate someone who pushes back thoughtfully rather than just saying yes straight away. It builds trust quickly and it usually results in a more honest and realistic conversation about what they're actually trying to achieve."
"Don't just look for a partner who is capable. Look for someone who:
This is where the role of a Trusted Advisor really becomes valuable. Taking that time upfront leads to better decisions, a clearer scope and outcomes that are far more likely to stick long term. And it means the work we do together is shaped into a realistic and deliverable solution."
Samuel Middleton is a Senior Security Consultant at PGI, specialising in compliance and information security advisory. To find out how PGI can support your organisation with your objectives, get in touch with us.

Many organisations invest heavily in ISO 27001 and PCI DSS year after year — but few realise they may be paying for a scope that is larger, more complex, and more expensive than necessary.

The UK Ministry of Defence (MoD) recently introduced the Defence Cyber Certification (DCC) Scheme: a framework for suppliers in the defence supply chain.

What is third-party due diligence? Third-party due diligence is simply the process of evaluating the third parties you work with—like your suppliers and service providers—to ensure they meet your internal standards for security and compliance.