LOADING…
Platform  /  Resources  /  Blog
The E2E Risk blog

Sharper thinking oncyber risk.

Analysis and practical guidance on UK public-sector cyber risk - GovAssure, the CAF, Secure by Design, threat intelligence and operational resilience.

All resources
★ Featured
Compliance

GovAssure and your supply chain: what actually changes

GovAssure made the NCSC CAF the spine of UK government cyber assurance. The part that catches teams out is the supply chain.

10 June 2026 · 6 min read
Resilience

A recovery plan you have never tested is a hypothesis

Operational resilience is now a regulator question. If your most critical service went down tomorrow, could you recover in time - and prove it?

12 June 2026 · 6 min read
Secure by Design

Five ways Secure by Design quietly fails

A security mandate run on a spreadsheet fails in five predictable ways: no control, evidence chaos, late governance, weak defensibility, cross-team friction.

12 June 2026 · 6 min read
Threat intelligence

The nine surfaces of supplier risk

A strong questionnaire shows how a supplier governs itself; an outside-in rating shows what an attacker sees. You need both.

12 June 2026 · 6 min read
Resilience

Prevent, absorb, recover

An untested recovery plan is a wish with a cover page. Operational resilience is a posture you can score.

12 June 2026 · 6 min read
Compliance

GovAssure and your supply chain: what actually changes

GovAssure made the NCSC CAF the spine of UK government cyber assurance. The part that catches teams out is the supply chain.

10 June 2026 · 6 min read
Threat intelligence

The breach always starts with a third party

SolarWinds, MOVEit, Okta, Kaseya - the defining breaches share one trait. The lesson isn’t trust less; it’s assure continuously.

3 June 2026 · 5 min read
Third-party risk

Beyond the annual questionnaire

A questionnaire is a photograph; risk is a film. Why point-in-time supplier assurance fails - and what replaces it.

27 May 2026 · 5 min read
Frameworks

Answer once, report everywhere

CAF, ISO 27001, Cyber Essentials and NIST ask the same questions in different shapes. Control mapping turns one answer into evidence for all.

20 May 2026 · 4 min read
Secure by Design

Secure by Design isn’t a spreadsheet

The Secure by Design mandate asks for security designed in and continuously assured. A tracker spreadsheet can’t do either.

13 May 2026 · 5 min read
Stay sharp

The E2E Risk briefing

Occasional, practical notes on UK public-sector cyber risk and compliance. No spam, unsubscribe anytime.

Next step

Put the thinking into practice.

See how continuous, AI-assisted assurance works on your own suppliers.

All resources