|  By Razorthorn
Razorthorn has worked with wide range of technically savvy clients who are confident they would spot a fake, but confidence is exactly what makes deepfake fraud so effective. In 2024, a finance manager at engineering firm Arup transferred $25 million to fraudsters after taking part in a video call with what appeared to be his CFO and several colleagues. Every person on that call was fabricated. None of it was real.
  |  By Razorthorn
Your third party suppliers probably aren’t as secure as you think they are. SecurityScorecard’s 2025 Global Third Party Breach Report found that at least 35.5% of all data breaches in 2024 originated from third party compromises. That’s not a minor risk you can ignore. The numbers tell a stark story. But here’s what most organisations miss: the real figure is likely higher since many breaches aren’t disclosed or are mistakenly reported as internal incidents.
  |  By Razorthorn
Let’s get right to it: Razorthorn Security helps organisations achieve and maintain PCI DSS compliance through expert consultancy, gap analysis and preparation for formal assessment and has been recognised by Gartner as a market leader in PCI DSS QSA services. If you’re handling payment card data, you’ll need qualified support to navigate the 500+ controls that PCI DSS demands.
  |  By Razorthorn
Passwords were invented in the 1960s. Six decades later, we’re still using them to protect everything from email accounts to bank transfers to corporate networks. The problem isn’t just that they’re old technology, it’s that they were never designed for the world we live in now.
  |  By Razorthorn
Guest post by Capsule Cyber insurance has rapidly evolved from being considered a specialist offering to a critical pillar of modern risk management. Yet many businesses still misunderstand what it covers and just as importantly, what it doesn’t do.
  |  By Razorthorn
When it comes to cyber insurance for SMEs, many small and medium-sized enterprises believe that cyber insurance feels like an optional extra, not a necessity, something to worry about later. This risk-taking attitude is often driven by various common misconceptions: The opposite is often true. Smaller businesses are frequently seen as easier targets due to limited budgets, lean security teams, and less mature cyber defences.
  |  By Razorthorn
By James Rees, MD, Razorthorn Security The Digital Operational Resilience Act (DORA) isn’t just another regulatory hurdle to clear. It’s fundamentally changing how financial institutions think about operational risk, particularly when it comes to the third party providers that now handle much of their critical technology infrastructure. DORA third party compliance has become a critical priority for EU financial institutions since the regulation came into force in January 2025.
  |  By Razorthorn
By James Rees, MD, Razorthorn Security The artificial intelligence revolution isn’t coming. It’s here and it’s moving faster than anyone predicted. Children now trust ChatGPT more than their parents for information. AI-generated content is becoming indistinguishable from human work. Entire industries are being reshaped by technology that seemed like science fiction just a few years ago.
  |  By James Rees
The artificial intelligence revolution isn’t coming. It’s here and it’s moving faster than anyone predicted. Children now trust ChatGPT more than their parents for information. AI-generated content is becoming indistinguishable from human work. Entire industries are being reshaped by technology that seemed like science fiction just a few years ago.
  |  By James Rees
Continuous Threat Exposure Management (CTEM) is gaining increasing recognition as a crucial component for mature cybersecurity programmes. Both Gartner and Forrester have highlighted CTEM as “a strategic imperative,” underscoring its importance in addressing modern cyber risks. This recognition is well founded, as demonstrated by recent cyberattacks on major organisations including Marks & Spencer, Co-op, Harrods, the NHS and American healthcare institutions.
  |  By Razorwire Cybersecurity
AI adoption is accelerating, cyber attacks are increasing and organisations are transforming faster than their security can keep up. In this Razorwire Raw, James Rees looks at why cybersecurity could be in the lull before the storm. AI agents, vibe coding and automation are changing business at extraordinary speed, while attackers are using the same technology to find vulnerabilities and accelerate attacks.
  |  By Razorwire Cybersecurity
Getting shortlisted for an industry award can be only the beginning of the bill. A £500 ceremony ticket, a long shortlist, application fees, publicity packages and even paying extra for the trophy can turn professional recognition into a surprisingly expensive business model.
  |  By Razorwire Cybersecurity
Getting in front of CISOs and senior decision-makers is one thing. Getting them genuinely interested is another. Targeted executive dinners can offer better conversations than an expensive conference stand, but only when organisers are realistic about what vendors are actually paying for. Why CISOs Really Attend VIP Dinners Hint- It's Not For You.
  |  By Razorwire Cybersecurity
Tech conference speakers can have very different experiences depending on where they are invited to speak. Some international events discuss budgets and fees upfront, while UK cybersecurity events may offer little financial support or rely increasingly on sponsored speaking slots.
  |  By Razorwire Cybersecurity
Pay-to-play cybersecurity awards can turn professional recognition into something you simply purchase. One example promises an industry award and magazine coverage for $1,200, raising an obvious question about what that recognition is actually worth.
  |  By Razorwire Cybersecurity
B2B events can charge extraordinary amounts for access to senior decision-makers. One tech conference pitched a £10,000 table with ten decision-makers and claimed the investment would generate £100,000 in business, until that “guarantee” was put to the test.
  |  By Razorwire Cybersecurity
Public speaking requires far more preparation than simply getting on stage and reading a deck. Even a short presentation can take hours or days to prepare, while effective delivery is a skill that has to be learned and practised.
  |  By Razorwire Cybersecurity
Cybersecurity awards can create credibility surprisingly quickly, even when nobody stops to question where the recognition came from. A fake Canva award for “best shirts in cybersecurity” attracted more than 100 congratulations, demonstrating how easily perceived authority can influence people.
  |  By Razorwire Cybersecurity
Awards you have to pay to win, events you have to pay to attend and conferences that expect speakers to work for free. When did recognition and expertise in cybersecurity become something you have to buy? Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode I'm joined by security consultant and regular community speaker James Bore and Gary Hibberd, co-founder of Consultants Like Us and the Real Cyber Awards and Conference.
  |  By Razorwire Cybersecurity
HIPAA compliance becomes considerably more complicated when a stolen healthcare laptop may contain patient information. Keeping protected health information away from local storage changes the consequences of device theft and reduces the endpoint’s exposure.

Razorthorn has a single purpose: to defend business-critical data and applications from cyber attacks and internal threats. Founded in 2007, Razorthorn has been delivering expert security consulting and testing services to some of the largest and most influential organisations in the world, including many in the Fortune 500.

Leaders in Cyber Intelligence:

  • Cyber Security Consultancy: Delivering professional and dedicated consultants to our clients, we are specialists in all areas of cyber security consulting. Whether you need help with cyber security compliance or require CISO services, we work closely with our clients to provide short term or ongoing support, in line with your requirements and budget.
  • Cyber Security Testing: It is essential to test your cyber security posture regularly, whether it’s a requirement for compliance or to ensure you are getting value for money from your cyber security solutions. In addition to pen testing, Razorthorn offer a comprehensive suite of cyber security testing services to ensure your data and business reputation is as secure as possible.
  • Managed Services: We provide 24/7 managed cyber security services, working as an extension to your in house team or as your dedicated managed services partner. You will benefit from the skills and expertise of our team, the cost efficiency and flexibility that comes with outsourcing to a specialist service provider.
  • Cyber Security Solutions: We work in partnership with hand-picked, industry leading solution providers, carefully selected for quality, effectiveness and to complement the services we offer.

Defending businesses against cyber attacks since 2007.