Cyber Security News and Advice
Making sense of Cyber Security for business owners

Quantum Computing: What It Means for Your PCI Compliance
The idea of quantum computing might sound like science fiction—but it’s becoming science fact faster than most businesses realise. While we’re still years away from fully operational quantum computers, developments are accelerating—and they could have serious implications for the way we protect sensitive data.

Passkeys: A deep dive for IT Managers
Passkeys have gained prominence because they directly address the growing weaknesses of password-based security. Cybersecurity risks related to passwords are well-documented: the majority of cyber breaches involve lost, stolen, or weak credentials . Attackers commonly obtain passwords via phishing scams, database breaches, or by exploiting password reuse. Traditional passwords are simply not adequate protection on today’s internet

Not all ISO 27001 certificates are the same – how to avoid expensive mistakes
When your customers request ISO 27001 certification, it's because they need credible assurance that your information security is robustly managed. However, many businesses fall into the trap of obtaining an ISO 27001 certificate that isn't accredited by a recognised body like the United Kingdom Accreditation Service (UKAS)

Cyber Safety Briefing: Say Goodbye to Passwords, Hello to Passkeys!
Passwords are out, and passkeys are in! But what exactly are passkeys, and why should you care?

The Next Big Shift in Construction Safety: Are You Ready for Cyber Safety?
For decades, the construction industry has worked tirelessly to improve health and safety culture. What was once a regulatory headache has transformed into a core business value, saving lives and improving project outcomes.
Now, a new safety frontier is emerging—one that construction firms can no longer ignore: Cyber Safety.

ISO 27001: Why It’s Not Just for Large Corporations
Many small and medium-sized businesses (SMBs) believe that ISO 27001 certification is something only large corporations need. After all, isn’t cybersecurity just an issue for massive enterprises with thousands of employees and deep pockets?
The truth is, cyber threats don’t discriminate based on company size. In fact, the latest NCSC Annual Review 2024confirms that smaller businesses are prime targets for cybercriminals, particularly those handling sensitive data or sitting in the supply chain.

ISO 27001 Beyond Certification: The Importance of Continuous Compliance
Achieving ISO 27001 certification is a significant milestone for any business—it demonstrates a commitment to protecting sensitive information and managing cybersecurity risks. However, many organisations make a critical mistake: they view certification as the finish line rather than the beginning of an ongoing process.
Cyber threats are not static, and compliance should not be either. Without continuous compliance, businesses risk falling out of certification, exposing themselves to security breaches, and damaging their reputation.

Cyber News - February 2025
In today’s interconnected digital landscape, the importance of robust cybersecurity measures cannot be overstated. Recent events have highlighted vulnerabilities that, if left unaddressed, can have severe repercussions for businesses of all sizes. This article delves into three significant incidents, elucidating their implications and offering actionable steps for business leaders to fortify their organisations against similar threats.

Cyber Security for Business Leaders - our new podcast
Understand the risks and implications of the latest cyber security news - summarised and explained for business leaders

Cyber Essentials for St James’s Place Partners
In today’s hyper-connected world, cybersecurity is no longer optional—it’s an essential foundation for business resilience and trust. Recognizing this, St. James’s Place (SJP) has mandated its partners to obtain Cyber Essentials certification, reinforcing their commitment to safeguarding sensitive information and ensuring regulatory compliance.

New Cyber Security obligations for Colleges
This summer the EFSA announced new Cyber Security rules that will apply to colleges and special post-16 institutions (SPIs) in England from the 2024-2025 funding year.


Compliance-as-a-Service: How Cool Waters Cyber Helps Businesses Achieve ISO 27001 Certification
In this case study, we will look at how Cool Waters Cyber helped two of its customers, MindCraft and Zappit, achieve ISO 27001 certification, and how this benefited their businesses.

Secure your success in 2024
Investing in cybersecurity with the Cyber Essentials scheme is not just about protecting your business; it's about positioning your small business for growth and success in the digital age. As you make your business resolutions for the New Year, consider adding Cyber Essentials to your list. It’s an affordable, effective way to ensure your business is secure, reputable, and ready for the opportunities ahead.

Breakdown of a scam
Here’s a breakdown of a type of complicated telephone scam used against vulnerable people

What is a Cyber Advisor?
We are Cyber Advisors - helping small-medium sized firms improve their cyber security.

We’re recruiting
Doughnuts on your birthday is just one of the many benefits of working at Cool Waters Cyber as an apprentice

How to secure your charity
How to secure your charity and pick the right level of cyber security based on your size and the types of risk unique to your charity’s work

Solving the Cyber Skills Gap
Half of all UK organisations lack the basic cyber security skills to protect themselves according to a new government survey.

How to prove to your customers that you can be trusted
How can you prove to your potential clients that you can be trusted with their most previous commodities - their data and their reputation?