Compliance Week Done: What to Action This Weekend Before the GRC Finale
Compliance week is done. Here’s the whole thing in one place, and what’s worth doing with it before next week.
What We Covered
Monday, we opened with the gap that shaped the entire week: 94% of UK business leaders confident about breach response, against a government survey showing just 5% of businesses hold Cyber Essentials, 47% use two-factor authentication, and 31% have board-level cyber ownership. Two real client audits showed exactly what that gap looks like in practice.
Tuesday, Corrine took the Cyber Security Breaches Survey 2025/2026 apart control by control. The headline finding: 24% of UK businesses already have all five Cyber Essentials technical controls in place. Only 5% hold the certificate. The gap isn’t security, it’s recognition, and it’s closing fast in businesses that are starting to claim what they’ve already built.
Wednesday, Mauven covered the NCSC’s own figures: 204 nationally significant cyber incidents in the year to August 2025, more than double the year before, running at roughly four a week and showing no sign of slowing at CyberUK 2026.
Thursday, Graham built the practical answer to the whole week’s theme: a five-folder evidence pack, one folder per Cyber Essentials control area, that turns “we take security seriously” into a ten-minute, evidence-backed answer. Three to four hours to build, ninety minutes a quarter to maintain.
Friday, Lucy told the story of Fred: not a real person, but the shared SharePoint login five employees at a UK professional services business were all using. Compared directly against a similar accountancy practice that adopted the same controls without a fight, the difference wasn’t budget. It was whether the business argued with the requirement itself.
Saturday, I made the case that 5% Cyber Essentials adoption after twelve years is a boardroom failure, not a budget one, given that a quarter of UK businesses already qualify technically and simply haven’t claimed the certificate.
What to Action This Weekend
If you only do one thing from this week, build Thursday’s five-folder evidence pack. It’s the single highest-value, lowest-cost action in the entire series: firewalls, secure configuration, access control, malware protection, and patch management, each with a dated screenshot or export, reviewed quarterly.
If you do a second thing, check for a shared login anywhere in your business. It’s usually free to fix and it’s the single most common failure we’ve seen in real audits.
Next Week: The GRC Series Finale
Next week, Graham and I bring the entire Governance, Risk and Compliance series together. Three weeks of separate documents, a governance one-pager, a risk register, and this week’s evidence pack, get pulled into a single, workable quarterly rhythm: three documents, one hour, four times a year.
A perfect system you never run is worth nothing. A slightly rough one you actually run every quarter is worth everything. That’s where we’re headed.
What This Means for Your Business
-
Build the five-folder evidence pack this weekend if you haven’t already. It’s the practical centrepiece of everything covered this week.
-
Check your business for shared logins before Monday. It’s the fastest, cheapest fix on this entire list.
-
Block an hour next week for the GRC finale. It’s designed to be the piece that makes governance, risk, and compliance actually stick as an ongoing habit, not a one-off project.
| Source | Article |
|---|---|
| GOV.UK | Cyber security breaches survey 2025/2026 |
| NCSC | Cyber Essentials overview and requirements |