header-logo header-logo

28 November 2025 / Jack Morris
Issue: 8141 / Categories: Features , Profession , Cyber , Cybercrime , Technology , Risk management
printer mail-detail

This is a drill!

237018
Cyber resilience goes beyond documentation. Businesses should stress-test their response in real time, writes Jack Morris
  • Paper-based cyber response strategies often collapse in real incidents; real-time adaptability is essential.
  • Simulations sharpen instincts—immersive tabletop exercises train teams to make fast, coordinated decisions under stress.
  • These drills empower legal teams, boost insurer confidence and turn organisations into proactive cyber defenders.

When a cyberattack strikes, the disruption is immediate and the clock starts ticking. Whether it’s ransomware, data exfiltration or denial-of-service, organisations don’t have the luxury of leafing through manuals. Every second counts and every decision matters.

Despite the increasing frequency and sophistication of cyber threats, many companies continue to place their trust in static, paper-based cyber incident response (CIR) plans. These documents may satisfy regulatory checkboxes, but in the heat of a live breach, they often prove inadequate. Plans that look watertight on paper can unravel in practice, especially when legal teams, IT and the board are suddenly thrust into a high-pressure, high-stakes environment.

As someone who regularly supports

If you are not a subscriber, subscribe now to read this content
If you are already a subscriber sign in
...or Register for two weeks' free access to subscriber content

MOVERS & SHAKERS

Bellevue Law—Lianne Craig

Bellevue Law—Lianne Craig

Workplace law firm expands commercial disputes team with senior consultant hire

EIP—Rob Barker

EIP—Rob Barker

IP firm promotes patent attorney to partner

Muckle LLP—Ryan Butler

Muckle LLP—Ryan Butler

Banking and restructuring team bolstered by insolvency specialist

NEWS
The Supreme Court has delivered a decisive ruling on termination under the JCT Design & Build form. Writing in NLJ this week, Andrew Singer KC and Jonathan Ward, of Kings Chambers, analyse Providence Building Services v Hexagon Housing Association [2026] UKSC 1, which restores the first-instance decision and curbs contractors’ termination rights for repeated late payment
Secondments, disciplinary procedures and appeal chaos all feature in a quartet of recent rulings. Writing in NLJ this week, Ian Smith, barrister and emeritus professor of employment law at UEA, examines how established principles are being tested in modern disputes
The AI revolution is no longer a distant murmur—it’s at the client’s desk. Writing in NLJ this week, Peter Ambrose, CEO of The Partnership and Legalito, warns that the ‘AI chickens’ have ‘come home to roost’, transforming not just legal practice but the lawyer–client relationship itself
A High Court ruling involving the Longleat estate has exposed the fault line between modern family building and historic trust drafting. Writing in NLJ this week, Charlotte Coyle, director and family law expert at Freeths, examines Cator v Thynn [2026] EWHC 209 (Ch), where trustees sought approval to modernise trusts that retain pre-1970 definitions of ‘child’, ‘grandchild’ and ‘issue’
Fresh proposals to criminalise ‘nudification’ apps, prioritise cyberflashing and non-consensual intimate images, and even ban under-16s from social media have reignited debate over whether the Online Safety Act 2023 (OSA 2023) is fit for purpose. Writing in NLJ this week, Alexander Brown, head of technology, media and telecommunications, and Alexandra Webster, managing associate, Simmons & Simmons, caution against reactive law-making that could undermine the Act’s ‘risk-based and outcomes-focused’ design
back-to-top-scroll