Cybersecurity is not a problem you finish
In his CYBERUK 2025 keynote, NCSC CEO Richard Horne described cybersecurity as a contest. That short framing changes how a governance programme should work. A contest has adaptive opponents, imperfect information and changing conditions. A control that worked last quarter may not be enough after a supplier change, acquisition or new attack technique.
The practical lesson is not that controls are unimportant. It is that GRC teams must connect controls to resilience, decision-making and the organisation’s ability to respond when prevention fails.
Replace false certainty with decision-ready risk
Many risk registers imply more control than the organisation really has. Risks are scored, coloured and accepted, but the assumptions behind those scores are rarely tested. Leadership needs a view of exposure that explains dependencies and uncertainty.
| Governance question | Weak answer | Decision-ready answer |
|---|---|---|
| What could disrupt us? | Cyberattack | Loss of identity, cloud or critical supplier service |
| How exposed are we? | Medium risk | Named systems, users, dependency and plausible duration |
| What protects us? | Policy and tools | Tested prevention, detection, response and recovery controls |
| Who decides? | IT | Named business risk owner with escalation thresholds |
| Can we recover? | Backups exist | Recovery objective demonstrated in a timed exercise |
Govern the services you do not control
Horne emphasises that organisations depend on technology and supply chains they do not own. A supplier questionnaire alone cannot manage that reality. The organisation needs to know which external services can stop a critical business process and what it will do if those services fail.
For each critical supplier, record:
- The business service and data that depend on it
- Concentration and fourth-party dependencies
- Security and availability commitments
- Incident-notification and cooperation duties
- Tested exit, substitution or manual-workaround options
- The executive who accepts residual dependency risk
Measure resilience, not activity
A dashboard full of completed training and closed vulnerabilities can still hide fragility. Add measures that show whether critical services can withstand and recover from disruption.
Useful board-level measures
- Percentage of critical services with tested recovery plans
- Time taken to detect, contain and recover from material incidents
- Critical suppliers without a tested contingency
- High-risk exceptions past their approved date
- Identity, backup and crisis exercises completed against realistic scenarios
- Corrective actions closed after independent validation
Exercise the uncomfortable scenarios
Tabletop exercises should force decisions under pressure. Test the loss of a cloud platform, compromise of an identity provider, ransomware across a supplier, or a destructive insider event. Include legal, communications, operations, finance and leadership—not only the security team.
The result should be a short list of owned improvements. If every exercise ends with a successful score, the scenario may not be challenging the organisation’s assumptions.
A 60-day GRC resilience reset
- Identify the five business services whose disruption would cause the greatest harm.
- Map the technology, people and suppliers each service depends on.
- Connect each dependency to preventive, detective, responsive and recovery controls.
- Define escalation thresholds and accountable risk owners.
- Run one severe but plausible exercise for the weakest service.
- Report decisions, accepted gaps and funded actions to leadership.
ICyberWave perspective
Horne’s framing helps GRC leaders move beyond the illusion that every cyber risk can be controlled. Strong governance makes uncertainty visible, assigns decisions and proves that critical services can recover. ICyberWave supports cyber-risk governance, supplier assurance, control testing and resilience exercises. Continue with our cybersecurity versus GRC guide or contact us to strengthen your operating model.

