Emerging threats

We support organisations striving to build a trustworthy, safe online environment where users can engage authentically in their communities.
Commercial organisationsWe support commercial organisations operating in a digital world, seeking to protect their reputation and prevent business disruption caused by cyber attacks and compliance breaches.
International programmes and developmentWe support international government organisations and NGOs working to provide infrastructure or improve the capabilities, security and resilience of their nation.
UK government and public sectorWe support UK government organisations responsible for safeguarding critical infrastructure, preserving public trust, and maintaining national security.



Every organisation has that one member of staff who everyone relies on—that single point of failure (or SPOF). They're core to every business process, nobody else is trained to take on their role, and if you took them out the equation, it would cause a real mess.
Unfortunately, despite the fact that we hoped deploying AI would avoid the issue of a SPOF in human form, it has become an equally critical piece of the puzzle - going without it is likely cause widescale disruption. In fact, maybe you can't imagine your organisation staying competitive, or even operating at all, without AI.
That's exactly why AI deserves the same scrutiny you'd apply to any process or aspect of your organisation that's a single point of failure. But where to start? Well, the first step is mapping your business processes, understanding the possible alternatives you could fall back on and managing your supply chain.
Based on conversations we’ve been having over the last few months as many organisations work towards ensuring they won’t get caught out, here are some of the key questions you can be asking internally to get an understanding of your resilience level.
AI dependency is common. Many of your suppliers will now rely on AI to deliver their service to you, often drawing on the same handful of underlying AI model providers. That creates hidden concentration risk: a single upstream change or outage could impact several of your suppliers at once. Understanding how your suppliers work, and who they depend on, is the only way to see where those shared points of failure sit.
It's not enough to just assume alternatives exist until you need to turn to one in a crisis. If your provider discontinues a model, changes its pricing, or alters its behaviour, could you smoothly move to an alternative? Think through the viability of a switch:
In some cases, it may even be worth practising the transition, so you know the escape route works before you're forced to use it.
Models change, sometimes without much warning, and outputs that were once dependable can start to drift and become unreliable. The risk is that you or your team might not even notice it. Could a change in quality be identified early, or could it quietly work its way into your decisions and deliverables, and even result in damage to your reputation?
Do you have staff with the knowledge and ability to verify that the AI is giving correct, reasonable answers or do you trust it blindly? Are you currently lacking the oversight to recognise what ‘correct’ actually looks like? This is a risk we manage with humans all the time: people have bad days and face their own challenges. AI, likewise, can be less than 100% reliable. The difference is that a well-run organisation already knows how to quality check a person's work. The same discipline needs to apply to AI.
These questions just scratch the surface of the issues worth preparing for. AI is a powerful tool, but responsible usage comes with effective governance and contingency planning. Know your dependencies, test your alternatives and keep capable human oversight in the loop. That's where we can help. Get in touch with our team today to get started.

The Ministry of Defence (MoD) recently requested that all industry partners must achieve at least DCC Level 0 by the end of 2026.

What happens when someone walks into your office unauthorised?Organisations in highly sensitive sectors often invest heavily in cyber defences, but physical security needs to be treated as an equally high priority.

A new Five Eyes advisory published this week confirms what we're seeing in client environments: the time available to respond to a known vulnerability is shrinking fast.