Cyber Security: Complacency is the biggest risk – An evening with Eddie Hawthorne & Jude McCorry

 

 

‘It’s not a case of if, but when’

 

This was the stark message from Eddie Hawthorne, CEO of Arnold Clark, Europe’s largest privately owned car retailer, when talking about the company’s high profile cyber-security attack on 23rd December 2022. Joined by Jude McCorry, CEO of the Cyber and Fraud Centre – Scotland, Eddie has taken a position of sharing the hard lessons learned from this crisis in a bid to highlight the very real and increasing threats from this major criminal activity to a wide variety of organisations and individuals.

Our guests heard how he and his team responded to the criminal attack, the key lessons they learned, and the strategies now in place to build both cyber resilience across the business, and personal resilience within the leadership team. Cyberattacks are a growing and inescapable reality, yet few leaders are willing, or permitted, to share their experiences. We are therefore grateful to Eddie for his openness.

Together Eddie and Jude provided some very useful and fundamental learnings.

It is important to be aware that a cyber-attack comes in four stages, with stages 2-4 happening very rapidly:

  • Reconnaissance – the cyber attackers gather intelligence and identify weaknesses
  • Landing and access – First entry to the system is gained
  • Expansion – Escalation and gains control of the network
  • Exploitation – The attacker executes their objective, such as stealing data or deploying ransomware. This is the stage where ransoms and demands are made.

Protecting, prioritising, proactivity and professional support are fundamental:

  • Complacency is not an option – this is the biggest risk to any organisation. Cyber security should be a significant Board priority with dedicated resource and strategic focus.
  • Kill Chain Response – Speed of response is vital to be able to stop a cyber attack. Introduce at least four layers of protection and defence across the attack chain.
  • Prioritise Incident Response capabilities – engage your own Incident Response partner, or ensure your insurance company can offer this service. You don’t know you need it, until you need it, but better to have it in place.
  • Internal cyber hygiene – Foster a no blame culture where staff can easily report any suspected security, spam or phishing emails.
  • Test, Test, Test– akin to a regular fire drill, test your cyber resilience and incident response regularly with staff, suppliers and other stakeholders. This could be the difference in stopping or controlling an attack.
  • Risk Register categorisation – Cyber threats should always be red and considered at every opportunity by the Executive and the Board, regardless of organisational size or data held.
  • Cyber security skills on the Executive – embed cyber security expertise within your leadership team, or secure external advisors. As attacks become more sophisticated, dedicated expertise will be essential.
  • Honest communication – Transparency with your staff, customers, suppliers or stakeholders, as much as is legally permitted, is welcomed and helps to mitigate reputational damage as well as build trust.
  • Professional body support – working with the National Cyber Security Centre or Cyber Security Scotland to gain industry and policy advice is hugely beneficial to your organisation, but also to help others mitigate further crises.

In an era where cyber-attacks are escalating in both frequency and sophistication, the insights shared by Eddie and Jude serve as a crucial reminder that no organisation or individual is immune. Their candid reflections reinforced the importance of proactive cybersecurity measures, strong leadership, and a culture of resilience. The discussion underscored that cybersecurity is not just an IT issue—it is a fundamental business risk that requires Board-level attention and continuous investment.

Latest

British Pharmacological Society appoints Dr Neha Issar-Brown as new Chief Executive Officer

Christ College Brecon announces new Head

“You can’t separate the family from the business so consider it a strength”: A conversation with Sarah Squire, Chair of Squire’s Garden Centres

GPhC appoints new Chief Executive and Registrar

“Automation as our partner, not the sole author of decisions”: Sir Robert Buckland on the future of justice

Ashmolean Museum appoints Dr John Chu as Keeper of Western Art

“Finally, I’ve Made an Impression”: The Subtle Art of Political Leadership – Sir Robert Buckland

Monash University appoints new Provost and Senior Vice-President

Enver Solomon is appointed as Nacro’s Chief Executive

Unity Schools Partnership announces Dominic Norrish as new Chief Executive

Big Picture Medical appoints Hilary Thomas to Senior Advisory Team

The Journey of a Search CEO Podcast: Kate Ludlow

Our 2025 Social Impact Confidence Index is out now

Lyndsey Jackson announced as new Executive Director of The Royal Lyceum Edinburgh

Molly Bretton to become Outside In Director in 2026

West Kent Housing Association Announces CEO Successor

RSPCA appoints new Chief Executive

Tomorrow’s Warriors announces new leadership appointments

Black Country Living Museum welcomes new Chair

Experts in education, culture and strategy join Goldsmiths’ Council

Royal Botanic Garden Edinburgh appoints 17th Regius Keeper

From ‘Nice to Have’ to ‘Must Have’: Amerjit Chohan on the strategic value of healthcare volunteering

Enter the tiger: it’s time for the UK’s creative industries to take India seriously

Tobias Alpsten joins Big Picture Medical’s Senior Leadership Team

Damien Régent appointed as Non-Executive Director of Homerton Healthcare NHS Foundation Trust

Less is more: Why law firms sometimes need to subtract to grow

Healthy Neighbourhoods, Thriving Communities: A conversation with Laura Churchill at Central London Community Healthcare NHS Trust

Government Practice Update by Sophie Tredinnick

Low Carbon Contracts Company announces Tony Bickerstaff as new Chair

“Paralysis to action is a route to failure”: interview with Lord Barwell

Sheena Wrigley appointed as Royal Exchange Theatre’s Executive Director / Co-CEO

The Royal College of General Practitioners announces new Chief Executive

UWL appoints Professor Anthony Hilton as Deputy Vice-Chancellor (Academic)

Vivensa Foundation Announces New Chief Executive Officer

New members of The Courtauld Governing Board announced

“You cast a shadow as a leader”: a conversation with Steve Scrimshaw CBE

New Battery Innovation Programme Director

Revd Dr Harriet Harris MBE appointed new Principal of Ripon College Cuddesdon

Nigel Topping CMG appointed Chair of the Climate Change Committee

Music Patron welcomes Augusta Quiney as new CEO

ActionAble publishes 2025 Impact Report

From Analogue to Digital: Rethinking Patient-Centred Healthcare: Dr Mohammad Al-Ubaydli

Professor Paul Monks appointed as new Henry Royce Institute Chair

Dr Helen Phillips appointed as new Chair of the General Dental Council

Radical Simplification? The Leadership of Development Funding

MAT Talks: Nicole McCartney, CEO of Creative Academies Trust

Matt Risley appointed National Theatre’s first Chief Digital Officer

Belfast Health and Social Care Trust appoints new Chief Executive

Orbit appoints three new non-executive directors to its Common Board

RSA announces David Joseph CBE as new Chief Executive Officer

SRA appoints Sarah Rapson as new Chief Executive Officer

“Always expect the unexpected. That’s leadership” – A conversation with Ian Funnell, Chair of NG Bailey 

Xavier Salomon appointed to be new Director of the Calouste Gulbenkian Museum

Leadership in the Age of AI: Mary Few on the Future of Legal Talent

We’re in this together: Celebrating Employee Ownership Day 2025

Future Generation Leadership: OnBoard Programme’s Fifth Cohort Celebration

Eleanor Passmore appointed as new Scotland Director at Thrive at Five

Empowering the next generation of board leaders – EPOC partnership event 2025

Dominic Cooke appointed as new Artistic Director of the Almeida Theatre

Anthem Schools Trust appoints David Hatchett as new CEO

Plan International UK announces new Chair

Clarion Housing Group names David Lunts as Chair of Latimer Developments

The AI Advantage: Rethinking Legal Talent and Delivery

Euan McVicar appointed as Non-executive Director of Low Carbon Contracts Company

Pitzhanger Manor & Gallery Announces New Director

A spotlight on Scotland’s business leadership: Russell Smith, CEO of Glasgow Clan and Braehead Arena

Take Five: A spotlight on leadership in the Arts and Creative Industries

Remembering Kat Mason, our cherished colleague

Saxton Bampfylde appoints Jonathan Badyal as Senior Advisor to Arts, Culture and Creative Industries Practice

Genomics England welcomes new Chief Technology and Product Officer

Squire’s appoints Sam Dickson as new Managing Director

Mountbatten Isle of Wight appoints Becky McGregor as new CEO

Professor Anjali Goswami becomes Defra’s new Chief Scientist

Russell Hobby CBE announced as the new TKAT CEO from September 2025

Monisha Shah Announced as New PLS Chair

Building Together for the Future: Expanding and evolving the leadership pool

Beyond Innovation: How Multi-Academy Trusts are reimagining educational leadership

RBG Kew announces new Director of Gardens

Emanuela Tarizzo appointed Director of Frieze Masters

Tom Adeyoola appointed to lead Innovate UK

Welcoming Dame Ruth May: Strengthening leadership insight in our Health Sector

Professor Karen Stanton Announced as UAL’s permanent Vice Chancellor

MSSC Welcomes New Chief Executive, Guy Holloway

Margaret Obi appointed as House of Lords Commissioner for Standards

Professor Sir Ian Chapman appointed next CEO of UK Research and Innovation

Is AI displacing your value as a non-executive in the boardroom? An Interview with Eugene Sadler-Smith

George Heriot’s School Appoints new Head of Senior School

Saxton Bampfylde Announces Leadership Evolution with New CEO and Board Appointments

Building Together for the Future: Priorities for the next decade

Nurturing future leaders: Irfan Latif, Head of Royal Hospital School

New CEO appointed for the Glasgow Clan and the Braehead Arena

Partner Movements: Experiences and Reflections – The Lawyer Practice Analysis in collaboration with Saxton Bampfylde

Legal Leaders Dinner: Transformation and AI in the Legal Sector

Elizabeth Honer CB becomes the new Chief Executive of the Royal Academy of Dance

Pilvi Kalhama appointed Director of Finland’s New Museum of Architecture and Design

Glasgow Academy announces new Head of Senior School.

Welcoming Nick Ricketts: Strengthening Leadership in the Social Impact Sector

British Museum appoints new Director of Collections

Non-executive director appointments at Guy’s and St Thomas’

Orbit appoints two customer non-executive directors to its Group Board