In a recent webinar, ARO’s Principal Cyber Solutions Architect, Adam Butler, shared a comprehensive overview of the current cyber security climate. Drawing on over 20 years of experience in IT and cyber defence, Adam, a self-described “purple teamer,” bridged the gap between offensive tactics and defensive strategies. This blog captures the essential intelligence from his presentation and translates it into actionable steps for your organisation.
The Evolving Threat Landscape
The webinar began with a sobering look at the statistics, painting a clear picture of a rising tide of cyber threats in the UK. The key takeaway is that these aren’t just numbers; they represent real-world impacts on businesses and even charities.
- Prevalence: Around half of UK businesses and a third of charities suffered a cyber breach in the last year, according to the 2024 Cyber Security Breaches Survey. For medium to large businesses, this figure jumps to over 70%.
- Most Common Threat: Phishing remains the dominant entry point, affecting 84% of businesses, closely followed by the exploitation of unpatched vulnerabilities.
- The Ransomware Boogeyman: Over 50% of UK companies have experienced a ransomware attack. The financial consequences are severe, as seen in the £32.7 million loss suffered by Synnovis, a laboratory service provider for the NHS.
- A Frightening Delay: The average time it takes for a UK organisation to detect a breach (Mean Time to Detect) is a staggering 197 to 270 days. This long dwell time gives attackers ample opportunity to achieve their objectives.
So, why is this happening? Adam points to a perfect storm of factors: the rapid shift to hybrid work, increased cloud adoption, a lower barrier to entry for attackers thanks to “as-a-service” models, and simple economic drivers: cybercrime pays.
Under the Lens: How Modern Cybercrime Operates
To truly defend ourselves, we must understand the enemy. Adam provided a rare glimpse into the sophisticated structure and tactics of modern cybercrime groups.
The Structure of Ransomware Groups
- Attackers use AI for: Crafting perfectly convincing phishing emails, creating realistic deepfake voice messages (which tricked one CEO into transferring £20 million), and developing malware that can adapt in real-time to evade detection.
- Defenders use AI for: Advanced email filtering that understands normal communication patterns, user behaviour analytics to spot anomalies, predictive threat intelligence, and automated responses that can neutralise threats in seconds.
As Adam put it, “AI is not going to replace cyber teams, but teams using AI will outperform those that don’t.“
Defensible by Design: Your Path to Resilience
So, how do we fight back? The answer isn’t a single product but a strategic approach. Adam advocates for being “defensible by design” by using established cyber security frameworks like NIST CSF or the NCSC’s Cyber Assessment Framework (CAF).
The process is simple but powerful:
- Identify: Understand what assets you have and what risks they face.
- Protect: Implement controls to safeguard those assets.
- Detect: Have systems in place to spot when a control has been bypassed.
- Respond: Know exactly what to do when an incident occurs.
- Recover: Have a tested plan to get back to business as usual.
By mapping your environment against a framework, you can identify your specific gaps and prioritise investment based on the real-world threats targeting organisations today.
Your 5-Point Call to Action
The presentation concluded with a set of clear, actionable steps every organisation should take now.
- Adopt a Framework: Pick a framework (NIST, CAF) and use it to assess your environment. This will provide a strategic roadmap for your security efforts.
- Secure Identities: Enforce Multi-Factor Authentication (MFA) on all external-facing services. Beyond that, implement tools to monitor identity for unusual behaviour. Don’t forget security awareness training for your staff.
- Protect Your Devices: Move beyond traditional antivirus to an Endpoint Detection and Response (EDR), Extended Detection and Response (XDR) or Managed Detection and Response (MDR) solution. A robust vulnerability and patch management program is non-negotiable.
- Strengthen Email Security: Your first line of defence needs to be your strongest. If malicious emails are getting through, it’s time to look at modern, AI-driven email security solutions.
- Prepare for Ransomware: Have a documented and tested Incident Response Plan. Know who to call and what steps to take. For critical infrastructure, consider a specialised ransomware assessment to test your defence’s against a real attack.
Cyber threats are evolving, but your defences can too. Whether it’s uncovering hidden risks, educating your team, or assessing your ransomware readiness, ARO’s complimentary services are designed to give you a head start. Book your free consultation today and take the first step toward becoming defensible by design.

With nearly two decades of experience across the IT and cyber security landscape, Adam Butler is a seasoned expert dedicated to building resilient security postures for organisations. His core passion lies in proactive defence, focusing on helping customers stay “left of breach” by anticipating and neutralising threats before they can impact the business.
Adam’s approach translates a deep, intelligence-led understanding of adversarial techniques, tools, and procedures (TTPs) into practical, multi-layered defensive strategies. His expertise spans a broad spectrum of modern security domains, including Managed Detection and Response (MDR), Extended Detection and Response (XDR), and advanced Email and Cloud Security, all underpinned by advanced Threat Intelligence. This practical insight, honed through foundational experience at BAE Systems and within a Security Operations Centre (SOC), has been proven in the most critical situations, including guiding large organisations through recovery after significant cyber attacks.
His expertise is sought by some of the most demanding environments, from FTSE 100 corporations to Magic Circle law firms. In these capacities, he has partnered with multinational firms to help shape and meet their cyber security strategy demands, ensuring long-term resilience. A cornerstone of Adam’s philosophy is that this strategic, outcome-focused mindset is universal; he applies the same rigour whether advising a global enterprise or empowering a small-to-medium-sized business (SME) to defend itself effectively against the modern threat landscape.
