What happened
CyberOne announced that Philip Ridley, Director of Cyber Risk Management, has been appointed to the CREST UK Council, expanding the company’s role in helping shape cyber security standards and resilience efforts in the UK. The company said the appointment reflects the depth of expertise within the business and strengthens its contribution to the development of a more mature, accountable, and professional cyber security industry. CyberOne said Ridley will bring frontline experience into ongoing work to develop practical, outcome-focused standards that reflect today’s threat landscape. The company also said the appointment comes as regulatory and board-level expectations continue to rise around accountability, governance, operational resilience, and demonstrable preparedness.
Who is affected
The direct impact falls on CyberOne and its role in UK cyber security industry forums through the CREST UK Council. The announcement is also relevant to organizations that follow or depend on evolving standards, assurance models, and resilience expectations shaped through collaboration among industry, regulators, and government.
Why CISOs should care
This matters because the appointment connects operational cyber risk experience with an industry body involved in shaping best practice, trust, and professional standards. It also reflects the wider pressure on organizations to show measurable resilience, stronger governance, and tested preparedness as regulatory expectations continue to evolve.
3 practical actions
- Track standards-setting bodies closely: Monitor developments from industry groups that influence what good cyber resilience, assurance, and governance look like in practice.
- Align resilience with measurable outcomes: Make sure cyber resilience programs can demonstrate tested preparedness and continuous improvement rather than relying only on stated controls.
- Use regulatory change to reassess readiness: Review whether current governance and resilience efforts match the growing emphasis on accountability, operational resilience, and demonstrable preparedness.
For more news about cyber resilience efforts and industry security developments, click Cybersecurity to read more.
