top of page

Strengthening Scotland's Cyber Resilience

4 minutes ago
1 min read

In a recent parliamentary debate I discussed the critical need for cyber resilience in Scotland, drawing on my 20-year background in the IT industry.



I explained that the focus has evolved from simple "disaster recovery" to "cyber resilience," emphasizing that organizations must plan for the inevitability of future attacks rather than just trying to prevent them entirely.


Using the example of the Arnold Clark cyberattack in 2022, I highlight that even large organizations with dedicated security teams remain vulnerable.


The debate acknowledged that while AI acts as a threat accelerator for attackers, it can also be harnessed for defense. Members also discussed the risks of "data harvesting" where encrypted data is stolen now in anticipation of future decryption capabilities.


I note a potential legal loophole regarding the "knowing purchase of stolen personal data" under current Scots law and advocate for a coordinated four-nations approach to address it.


The discussion also touches upon the disproportionate impact of cybercrime on women, particularly regarding the weaponization of sexualized images.


I conclude that cyber resilience is ultimately about maintaining public trust in digital systems, records, and services.


Have a listen.

bottom of page