aerial photography of London skyline during daytime

Security expert says businesses must embed safe cyber practices as a shared responsibility

To stay secure, businesses need to treat cyber security not simply as an issue for the IT department but as a shared responsibility across all of its activities, a leading cyber security expert has said.

Roy Shelton, Group CEO of managed service provider Connectus Business Solutions was commenting on a new report which warns that cyber attackers are increasingly targeting MSPs.

They are relying less on finding novel software vulnerabilities and more on impersonation, remote access, and software supply chains within MSP-managed environments.

There are four key areas of concern: identity abuse, misuse of legitimate tools, weaknesses in remote access infrastructure, and compromising software supply chains.

Mr Shelton commented: “The growing cyber risk associated with managed service provider ecosystems and the way attackers are increasingly exploiting trusted technology pathways to scale disruption is rightly highlighted.

“When an MSP is compromised, the potential impact can cascade across dozens or even hundreds of organisations simultaneously, creating systemic cyber risk that extends beyond a single business.”

He said there are two main realities that have come to the fore in the past year or so: “First, MSPs have become critical infrastructure in the digital economy.

“Many small and mid-sized organisations rely on them to manage systems, data and security that would otherwise be beyond their internal capability.

“That trust, however, also makes MSPs an attractive target for threat actors seeking a ‘force multiplier’ effect from a single breach.

“Second, the answer is not to retreat from managed services but to strengthen the ecosystem around them. Cyber resilience today requires deeper collaboration between MSPs, insurers, technology vendors and clients.”

Mr Shelton said that cyber security awareness must be normalised across a business if it is to stay secure within a shifting security landscape.

“Robust security frameworks, transparent risk management, and proactive monitoring must become standard practice rather than optional extras,” he said.

“At Connectus, we believe MSPs have an opportunity to evolve from being viewed purely as technology providers to becoming strategic risk partners for their clients.

“That means helping organisations understand cyber exposure, supporting stronger governance, and ensuring the right blend of security controls and cyber insurance protection.”

He added: “Cyber disruption will continue to grow in scale and sophistication. The organisations that succeed will be those that treat cybersecurity not as an IT issue, but as a shared responsibility across the entire digital supply chain.”

 

Fore more information see: https://connectus.org.uk