Cyber Rebels

UK flag with digital lock overlay

The UK Government Cyber Action Plan: What It Really Tells Us About Cyber Risk

On 6 January 2026, the UK Government published the Government Cyber Action Plan, setting out how cyber resilience is expected to be strengthened across central government, local authorities, public services, and the suppliers they rely on. At face value, this is a delivery plan. It outlines how responsibility is organised, how capability will be developed, […]

Desk with insurance documents, laptop, and phone.

Cyber Insurance Explained: What It Covers, What It Doesn’t, and Why That Matters

Cyber insurance is often spoken about in the same way as firewalls, backups, and incident response plans. Something sensible organisations are expected to have. Something that reassures boards, clients, and insurers alike. And yet, when incidents actually happen, many businesses discover that their understanding of cyber insurance was built on assumptions rather than reality. Claims […]

Cybersecurity vs Information Security debate illustration 2026

Cybersecurity vs Information Security in 2026: What’s the Difference?

If you sit in enough meetings about risk, compliance, or “cyber”, you start to notice something interesting. The language changes, but the assumptions rarely do. Cybersecurity and information security are used as if they’re interchangeable. Different words, same meaning. Same budget line. Same responsibility. Most of the time, no one challenges that assumption. It feels […]

Certificate of Green Small Business achievement on shelf.

Why We Chose to Pursue Green Small Business Certification

Running a small, service-based business doesn’t automatically exempt you from thinking about environmental responsibility. In fact, in many ways it makes the question more uncomfortable. When your footprint is modest, it’s easy to tell yourself that the impact is negligible, that bigger organisations are the ones who need to worry about policies, plans, and accountability. […]

Cybersecurity under FCA, behaviour meets regulation.

Cybersecurity Under the FCA: The Supervisory Expectations Firms Still Struggle to Meet in 2025

Financial services operate in one of the most heavily regulated environments in the world, and yet the failures identified in FCA cybersecurity reviews often have little to do with whether a firm understands the rules. Most institutions can recite the familiar acronyms — SYSC, SMCR, PRIN, and the operational resilience framework — with ease. They […]

Shopping cart close