top of page

9 Years of Security and Privacy Work, 9 Lessons

  • 12 minutes ago
  • 5 min read

ICA Consultancy turns nine this month. Here's what nearly a decade of advising organisations on security and privacy has actually taught us, including the things we got wrong.


Anniversaries invite a certain kind of writing. The kind with a timeline, a photo of the team, and a paragraph about how proud we are of the journey. We are proud of it. But a list of our own milestones isn't much use to anyone reading this.


So instead, 9 Security and Privacy lessons, one for each year. All of them earned on real engagements, alongside organisations who needed practical answers they could act on, and who taught us as much as we brought them.


Sailboat racing on dark water at sunset with large text, 9 Years Same Crew Stronger Winds, and ICA Consultancy logo.

1. The biggest risk is almost never the one in the headlines

Every few months a breach dominates the news, and the phone ping!

Could that happen to us?

Usually the honest answer is: probably not in that exact form, but there are three things in your environment that worry us considerably more, and none of them will ever make the news.


The headline attack is memorable precisely because it's unusual. The risks that actually take organisations down tend to be mundane: an unmanaged supplier with access nobody documented, a leaver whose credentials were never revoked, a backup regime nobody has tested since it was implemented.


Chasing headlines is a reliable way to spend a security budget on the wrong things. A risk-based, proportionate approach is less exciting and considerably more effective.


2. Security that gets in the way of the business gets bypassed

If your process makes someone's job harder, they will find a route around it. Not out of malice, out of deadline pressure. The shadow IT, the personal file-sharing account, the spreadsheet of passwords: these are almost always symptoms of a control that didn't account for how people actually work.


Which means a security measure that's technically excellent and operationally intolerable is not, in any meaningful sense, a security measure. It's a gap with paperwork attached.

The best controls we've implemented over nine years have been the ones the business barely noticed.


3. Culture does more work than any control you can buy

You can spend heavily on tooling and still be one convincing email away from a bad week.


What changes the outcome is whether the person who receives that email feels able to pause, question it, and report it, and whether they believe reporting a mistake will be met with support rather than blame. That's culture, and it isn't built with an annual e-learning module that everyone clicks through on the last day of the compliance window.


It's built through regular, realistic, well-designed practice, and through leadership visibly modelling the behaviour. The organisations we work with who take awareness seriously see it show up in their incident data within months, not because fewer people are targeted, but because more of them speak up early.


Tip: Our soon to launch Cyber Awareness Month 2026 guide is themed around this. Grab your copy next week.


4. Compliance is a byproduct of good security, not a substitute for it

We've been brought in to help organisations achieve ISO 27001, Cyber Essentials, SOC 2 and similar many times over. They're genuinely valuable, as evidence, as structure, and increasingly as a commercial requirement.


But we're also aware of organisations passing an audit while carrying risks that would have been obvious to anyone looking at the environment rather than the evidence pack. A certificate describes the shape of your programme on a particular day/period. It doesn't promise the programme works everyday.


Build the security. The compliance follows, and it follows much more cheaply than the reverse.


5. You don't need a full-time CISO to get CISO-grade thinking

One of the most persistent problems in this market is a mismatch between the expertise organisations need and the form it's available in.


A mid-sized organisation might genuinely need senior security leadership, someone who can sit with the board, own the risk picture, and set direction. What it doesn't need is that person five days a week at a permanent salary, and it usually can't justify one.


The result, too often, is that the responsibility lands on an IT manager who is already fully occupied and never asked for it. It's unfair to them and it doesn't serve the organisation.


The right experience, at the right time, in an affordable way, is not a compromise. For a great many organisations it's simply the correct answer.


6. Security and privacy must work together, separating them costs you

Organisations frequently treat data protection and information security as adjacent but distinct, different owners, different meetings, different requirements.


In practice they're the same question asked from two perspectives.

What data do we hold, why, who can reach it, where is it stored, who it is shared with and what happens when something goes wrong?

Answer that once, properly, and you've done most of the work for both.


Answer it in two silos, and you get contradictory records, duplicated effort, and a subject access request that takes three months because nobody can agree where the data lives.


7. The board doesn't want your risk register, it wants a decision

The board is not asking to understand cyber security. It's asking three things: how exposed are we, what's it going to cost to change that, and what happens if we don't. Everything else is supporting material.


If you can't get to a recommendation in the first page, you haven't finished the analysis. The technical depth still matters enormously, but it belongs in the appendix, and the value you add is in the judgement, not the volume.


8. Resilience has quietly become more important than prevention

Nine years ago, most conversations were about keeping things out. Increasingly they're about what happens when something gets in, or when a supplier goes down, or a service you depend on has a bad day and takes your operations with it.


That shift is now reflected in regulation as well as good practice. Assuming disruption rather than merely trying to prevent it changes what you invest in: tested recovery, mapped dependencies, rehearsed decision-making, and knowing in advance who makes the call at two in the morning.


The organisations that come through incidents well are rarely the ones that were never going to be hit. They're the ones that had practised.


9. The risks with the longest horizons are the ones nobody budgets for

The clearest current example is cryptography. The consensus is that a sufficiently capable quantum computer will eventually break the public-key cryptography protecting a great deal of what we do, and that data being harvested today may be stored specifically to be decrypted then.


It is genuinely difficult to get that onto an agenda alongside this quarter's priorities. It always is, for anything whose deadline is measured in years.


But the organisations that handle these transitions well aren't the ones that move first. They're the ones that know where their cryptography lives, and could change it without a two-year discovery exercise. Agility is the deliverable, not the algorithm.


The same principle applies to every slow-moving risk: you don't need to solve it today, but you should know what solving it would involve.


Same crew, stronger winds

Nine years in, the thing we're proudest of isn't a client list or a certification. It's that the people who started this are still doing it, still together, and still arguing about the right answer.


The winds have got stronger. The threat landscape in 2026 bears very little resemblance to 2017, in volume, in sophistication, and in how seriously boards now take it. That last change is genuinely welcome.


But a good crew doesn't fear stronger winds. Handled well, they're what gets you moving faster.


Thank you to every organisation that's trusted us over the last nine years. Here's to the next nine.


ICA Consultancy is an independent security and privacy consultancy providing advisory, consultancy and Capability-as-a-Service engagements: including CISOaaS, DPOaaS, managed GRC, security awareness programmes and operational resilience strategies.


If any of the above sounded uncomfortably familiar, get in touch, we are happy to chat.

 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page