Blog

News and information from the Advent IM team.

What a box of American breakfast cereal can still teach us about cyber security, OT and legacy risk

One of the most famous stories from the early days of hacking did not involve sophisticated code, advanced persistence or organised cyber crime. It involved a plastic whistle found in boxes of Cap’n Crunch, an American breakfast cereal. In the early 1970s, phone phreaks discovered that the whistle could generate a 2600 Hz tone. At […]

Read More

When No One Owns the Incident: The Risk Gap | RISK & BUSINESS PODCAST

Who really owns cyber incidents involving information — your IT team or your Information Governance team? 🤔 IT often gets treated as the default owner, but in reality, IT is essentially the filing cabinet: they store it, move it, and protect it — but they don’t own the information inside. That responsibility sits firmly with […]

Read More

Volunteering in Action: Mike’s Experience at The Bread and Butter Thing

  • by Olivia Lawlor-Blackburn
  • General

Over the 2025 festive period, our CEO, Mike Gillespie, spent his Christmas and New Year a little differently. After several years of hoping to volunteer over the holidays – but never quite managing due to work and life commitments – this year presented the perfect opportunity. And Mike grabbed it. His chosen charity was The […]

Read More

NCSC: No increase in cyber threat from Iran, but be prepared

In the wake of a major series of new US and Israel-led attacks on Iran and subsequent retaliatory strikes on Gulf states including Bahrain, Kuwait and the UAE, the UK’s National Cyber Security Centre (NCSC) has reassured British organisations that there is likely no significant change in the direct cyber threat posed by Iranian actors. Read via […]

Read More

Ransomware payment restrictions are coming. Your resilience plan needs to assume you can’t pay.

The UK is moving towards a tougher stance on ransomware payments, particularly for the public sector and regulated critical national infrastructure. Policy proposals have included a targeted ban for those sectors, alongside measures that increase incident reporting and introduce a notify-to-pay approach for organisations outside the ban.  This shift matters because it changes the shape […]

Read More

Complaints Handling Under the DUA Act: A Governance Test for Modern Organisations

The Data (Use and Access) Act does more than introduce new legal obligations — it quietly raises the bar on organisational accountability. By making formal data protection complaints handling a regulatory requirement, the legislation shifts responsibility firmly back to organisations to resolve issues properly before they reach the regulator. This reflects a wider move in […]

Read More