Category: Advent IM Blog

News and information from the Advent IM team.

If DCC Is MOT Testing, Secure by Design Is Aerodynamic Engineering

Rather than viewing Defence Cyber Certification (DCC) and Secure by Design (SbD) as similar or overlapping, it’s more accurate to see them as operating at different layers of the system and supplier lifecycle. They serve different purposes, influence different behaviours, and deliver different types of assurance. Many discussions focus on what each framework requires, but […]

Read More

Cyber Essentials v3.3: What the April 2026 Update Means for Your Organisation

The UK’s Cyber Essentials scheme is about to undergo one of its most significant evolutions in years. From 27 April 2026, all new Cyber Essentials and Cyber Essentials Plus assessments will be based on the updated Cyber Essentials v3.3 Requirements for IT Infrastructure, bringing clearer definitions, stricter security expectations, and a renewed focus on cloud‑first […]

Read More

Forced supplier exit: when “just terminate the contract” stops being realistic 

There’s a phrase in DORA that sounds like it belongs in a Cold War handbook rather than a compliance framework: forced supplier exit.  It has the energy of someone slamming a big red button. The nuclear option. The “right, that’s it” moment.  But when you sit with it for five minutes, you realise it isn’t actually dramatic at all. It’s painfully practical. It’s what happens […]

Read More

Sovereignty for Sale? Why Britain Must Rebuild Its Own Combat Air Power

Between Q1 2019 and Q4 2024, the Ministry of Defence (including its arms length bodies) paid roughly £52.5 billion to private sector contractors—about half to UK headquartered firms and much of the remainder to U.S. companies like Boeing and Lockheed Martin. Tussell’s analysis shows a clear pattern: the lion’s share of non UK spend goes to U.S. suppliers, […]

Read More

New Whitepaper Release: From Digital Transformation to Agentic AI Governance

Free to download — no sign‑up required The rapid rise of agentic AI is reshaping the way financial services operate, make decisions, and manage risk. But with autonomy comes a new governance challenge: how do firms stay in control when systems can act, not just assist? From Digital Transformation to Agentic AI Governance: Operational Control, […]

Read More

Secure by Design: where we are now – the requirement for evidence

Secure by Design is growing up. Quietly. Relentlessly. A couple of years ago, “Secure by Design” was often treated like a well-meaning poster on the wall. Useful, yes. Enforced, not always. That has changed. Across the UK government, Secure by Design is increasingly how teams are expected to show that security is built into the […]

Read More

From Digital Banking to AI Trading: The Top Cyber Risks Financial Institutions Face in 2026

Financial institutions in 2026 are innovating faster than ever, but so are attackers. As digital banking, cloud services, and AI-based trading grow, so do cyber threats that can disrupt operations, damage trust, and cause financial losses. Cyber Risk is now a Top Strategic Threat A 2026 industry survey by the Depository Trust & Clearing Corporation […]

Read More

**PRESS RELEASE** Advent IM Data (Use and Access) Act (DUA) Training Receives CPD Certification

Media Contact: Olivia Lawlor Blackburn  (0) 121 559 6699, bestpractice@advent-im.co.uk Date : 14.01.2026 Certification strengthens Advent IM’s commitment to high-quality, practitioner-focused data governance and security training as organisations prepare for new legislative requirements. Advent IM is pleased to announce that its Data (Use and Access) Act (DUA) Training has been formally CPD Certified, reinforcing the […]

Read More

Proxy SROs, real accountability, and why cyber risk keeps slipping through delivery cracks

Cyber risk rarely “appears” at go-live. It gets designed in, quietly, through decisions made under pressure: a deadline nudged forward, a control deferred “temporarily”, a supplier integration accepted with caveats, an exception granted because “the business needs it”. None of that is inherently evil. It’s just how complex programmes behave when incentives, timelines and accountability […]

Read More