The delivery of IT has changed rapidly. The governance of it has not kept up. The expectations have. Boards are now asked to account for a platform most have never had to govern.
For decades, digital systems failed in isolation. When something broke, it broke somewhere specific. You could point to it, contain it and fix it.
Then organisations connected everything. Not recklessly. Sensibly. Fewer systems, less friction, more collaboration, lower cost. Microsoft 365 was adopted because it made work easier, not because anyone intended to redesign the organisation's risk profile.
Identity, access and data now converge on a single platform and a single misconfiguration can affect the entire organisation. The oversight model in most boardrooms is still built on delegation, dashboards and assumption. That holds until something goes wrong. Then the board discovers whether it had evidence or merely reassurance.
Everyone can be competent, well-intentioned and telling the truth and the organisation can still be exposed in ways nobody fully sees.
The real failure mode is not negligence. It is surprise.
Expectations on boards for digital risk, operational resilience and governance have changed materially in recent years.
Renewal questionnaires now interrogate control effectiveness, and the answers are signed, not proven. Where controls cannot be evidenced, claims are challenged.
Regulators expect organisations to demonstrate how operational and information risks are governed, not simply that policies exist.
Directors are expected to show that reasonable steps were taken to understand and manage material risks, including those arising from the systems the business runs on.
All three arrive at the board. All three ask for the same thing. Evidence.
These organisations believed they were protected. The cases are publicly documented and widely reported; between them they have cost billions in damage, thousands of jobs and irreversible reputational harm.
A 158-year-old Northamptonshire haulage company, Knights of Old, valued at around £15 million, destroyed by a single ransomware attack. The entry point was a reused employee password that was guessed. Despite spending over £100,000 annually on IT security and holding cyber insurance, the business collapsed within months. 730 jobs were lost. 500 trucks came off the road. The former director said afterwards: "We felt we were in a very good place in terms of our security, our protocols, the measures we had gone to protect the business."
Nothing on the public record suggests anything other than good faith. That is the point. A board can trust capable people, take their assurances at face value and still have no independent way to test "we are in a good place" against evidence. InquilionGRC exists to ensure that question gets asked, independently and in governance language, before the answer arrives in the form of a ransom note.
Source: BBC Panorama, Fighting Cyber CriminalsJaguar Land Rover ran Microsoft 365 at scale across global manufacturing facilities. In March 2025, the HELLCAT ransomware group breached JLR using stolen credentials from a third-party tool connected via Power Apps to their environment; infostealer credentials dating back to 2021 were still valid. In September 2025, a second attack shut all global production for five weeks. The Cyber Monitoring Centre classified it as the most financially damaging cyberattack in British history, with an estimated impact of £1.9 billion to the UK economy and over 5,000 supply-chain organisations affected.
The questions that matter at board level in any such environment: what external tools and accounts can reach it, what credentials exist outside the organisation's control, who approved those connections and when they were last reviewed. InquilionGRC's assessment covers exactly this ground: which external services connect to the environment, what permissions they hold, how data flows between internal and external systems and whether that access is governed, approved and visible at board level. Whether asking these questions earlier would have changed the outcome is unknowable. That such questions are so rarely asked independently, at any board, is the governance gap these cases illustrate.
Source: Cyber Monitoring Centre, JLR Incident AnalysisAn old account inside Microsoft, set up years earlier for a job long finished, was never closed down. Security standards moved on; the account never did. In late 2023, Russian state attackers, the group Microsoft tracks as Midnight Blizzard, found it, signed in and through one out-of-date permission read the email of Microsoft's own senior leadership, security and legal teams. The intrusion ran for around seven weeks, inside the company that makes the platform.
Every organisation probably has accounts like that one. Leavers, old projects, access granted for reasons nobody now remembers. Detail lost in delegated delivery. Outcomes the board answers for. InquilionGRC evidences what is actually there: the accounts that still exist, the access that has quietly built up and whether today's standards are enforced on yesterday's leftovers.
Source: Microsoft Security Response, Midnight Blizzard guidanceThese are not InquilionGRC clients. We were not involved, and we make no claim that our involvement would have changed the outcome. Each case illustrates a governance gap that was not visible at board level until after the damage was done. Independent assurance does not guarantee prevention. It ensures the right questions are asked before a breach forces them.
It is no longer whether the organisation has IT controls. It is whether the board can show an insurer, auditor or regulator that those controls are demonstrably in place and delivering. Most boards cannot answer that today. InquilionGRC exists so they can.
A briefing takes thirty minutes and commits you to nothing.
REQUEST INFO