Industrial Mastery Pathway
Cyber Security in Practice
Operational Overview
Cyber Security Foundations covered the habits that protect you personally: recognising phishing, verifying identity, reporting fast. This course goes further, into the practices that protect your organisation as a whole, especially when the weak point is not your own inbox but somewhere else in the chain entirely.
One of the most disruptive UK cyber incidents of recent years did not start inside the organisation it affected at all. It started at a supplier. This course uses that case to explore third-party risk, data handling, business continuity, and what it actually looks like to play an active role when an incident is genuinely underway.
Node Parameters
Authorisation Cost
£25
Inclusion & Accessibility
Engineered for total accessibility. We provide full screen-reader compatibility and high-contrast visual modes.
Support: support@ikigaixr.com
System Configuration
Instructional Objectives
- Working Beyond the Office. Apply secure practice to remote, hybrid and personal-device working.
- Data Handling. Classify and handle data responsibly across its full lifecycle.
- Third-Party Risk. Recognise the risk a supplier or vendor can introduce into your own organisation.
- Physical and Insider Risk. Identify risks that exist alongside, not instead of, digital ones.
- Continuity and Response. Understand backup basics and take an active role during a real incident.
The Critical Logic of Safety
In June 2024, a ransomware attack hit Synnovis, a pathology partnership providing laboratory testing services to several NHS trusts across London. Synnovis was not the NHS itself, it was a third-party supplier the NHS trusts depended on for blood tests and other essential diagnostic services. Attackers got in through unpatched remote access infrastructure and the absence of multi-factor authentication, then encrypted systems and stole data.
The disruption ran for months. Over 10,000 outpatient appointments and more than 1,700 elective procedures were postponed at the two worst-affected trusts alone, and data relating to hundreds of thousands of patients was later leaked. A subsequent NHS trust review confirmed that the resulting disruption to patient care contributed to one patient's death.
Patients experienced real, direct harm from an attack that had never touched an NHS system directly, because it did not need to. It only needed to compromise a supplier those systems depended on.