Why Combining Compliance and Cybersecurity Training Makes Your Programme Stronger

Why Combining Compliance and Cybersecurity Training Makes Your Programme Stronger Article Most organisations run security awareness and compliance training as two entirely separate efforts. I’ve previously written on how you can develop each of those strands; find those articles here and here. There may not be a dedicated HR team to own compliance training. It might fall to an office manager, a senior PA. Meanwhile, the IT side sits with you. The result is twofold: trainings on overlapping topics fail to reinforce each other, and both underdeliver on their individual potential. There’s a better way. Bringing these two areas together into one cohesive programme saves time, improves engagement and retention, and builds the kind of security-aware culture that actually reduces risk. We’re going to look at four strategies that you can employ to make it work. The Case for a Combined Programme When you merge security awareness and compliance training into a single, continuous programme, several things improve: Engagement increases Knowledge retention improves Administration and reporting become easier Compliance is easier to evidence These should all be no-brainer goals for your cyber security and compliance programme. 4 Strategies to Build Your Combined Programme Strategy 1: Start With Goals, Not Content Think about what your organisation actually needs to achieve before picking specific topics. Do you need to reduce phishing click rates? Demonstrate compliance readiness for a cyber insurance renewal? Satisfy FCA training requirements? Define the outcomes first and work backwards. Not every employee needs the same training; your goals can vary across teams. A finance controller under FCA oversight may need the full financial crime and conduct risk module, while a warehouse operative needs only a basic data handling overview. Map content to roles from the outset and avoid content overload. Strategy 2: Vary Your Content and Test Regularly Different teams learn differently. IT-literate staff may prefer interactive scenarios while finance professionals may want case study-led content that reflects real-world incidents in their sector. Work with a training provider that offers a wide library of formats, and either tailor the content yourself or work with them to select it. Variety keeps engagement high. Simulated phishing tests should sit within the content mix, not outside it. While they’re often seen just as a measurement tool, they should also be used as a training mechanism. Monthly simulated phishing tests are a sensible minimum. Don’t forget real attackers use varied, well-crafted approaches. Your tests should reflect that variety. Threading compliance and security content together in the same programme also removes the disconnect employees notice when the two feel unrelated. A module on client data handling followed by a scenario about a targeted phishing attack using that data drives the message home. Strategy 3: Keep It Front of Mind Between Sessions Training isn’t only what happens inside a module. It plays out in regular communications, brief reminders, internal updates, team briefings. Reinforce key messages between formal sessions. A short monthly update to staff, a slide in the all-hands meeting, or a pinned post in your Microsoft Teams channel can all contribute to keeping security and compliance visible throughout the year. If your business has a director, partner, or owner willing to add their name to a brief message about why this matters, use that. Their influence will be much greater. The tone across all communications should be positive and practical. The goal is to help employees understand why this matters to them personally, not just to the business. Strategy 4: Measure What Actually Matters Not every metric you can track is worth tracking. In training programmes, it’s easy to generate numbers that look impressive but tell you very little about whether behaviour has actually changed. Metrics that indicate real change: Phishing simulation click rate over time - this is your most direct behavioural indicator. Track it consistently, across varied template difficulty levels. A meaningful downward trend over 6–12 months is genuine evidence that training is working. Reporting rate - are employees actually reporting suspicious emails rather than just ignoring or deleting them? Repeat clickers - individuals who click on multiple phishing simulations across several months need targeted intervention, not just another generic module. Pre- and post-assessment scores - if you run a knowledge assessment before the programme launches and repeat it at six or twelve months. This is also useful evidence for regulators and insurers. Incident response behaviour - are staff reporting suspected incidents faster? Are they following the correct procedure when they think something has gone wrong? Measurement should start before the programme launches. An initial assessment across both security awareness and compliance knowledge gives you a baseline. From there, you can identify gaps, prioritise content, and track genuine progress. Pulling It All Together A combined compliance and cybersecurity training programme isn’t just administratively convenient. It builds a more capable and aware workforce, and it demonstrates to regulators, insurers, and clients that your organisation takes risk management seriously. If training responsibility in your business is currently split across people with other primary roles, consolidation doesn’t have to happen overnight. Begin by mapping the overlap in your existing content, aligning your goals, and identifying a platform that can host both under one roof.
Compliance Training and Security Culture: A Practical Roadmap for IT Managers

Compliance Training and Security Culture: A Practical Roadmap for IT Managers Article Most organisations treat compliance training as a box to tick. Do this > Don’t get fined. But real compliance doesn’t live in a spreadsheet; it is rather an active, collective effort to handle data, report suspicious activity, or respond to conflicts of interest in ways that adhere to the rules. We’re going to look at the three key pillars of a compliance training roadmap – requirements, organisational needs, and cadence – and how they should be implemented. By the end of this article, you will hopefully have a clear idea of how to form your compliance training processes into an effective machine. Why Once-a-Year Compliance Training No Longer Works The “check-the-box” approach to compliance, to meet the minimum requirement and move on, creates a false sense of security. Regulations like GDPR require ongoing vigilance. When employees only encounter compliance content once a year, they don’t retain it. And low retention leads to real-world risk: poor data handling decisions, unreported incidents, and behaviours that expose your organisation to fines, reputational damage, or worse. Compliance training needs the same sustained, structured approach you’d apply to cybersecurity awareness (for more information, take a look at the article I wrote on the matter here). The Three Pillars of a Compliance Training Roadmap Before you build anything, you need clarity on what you’re building toward. Every effective compliance roadmap is built around three main pillars. The questions below form a sort of foundation to start building these pillars on. Pillar 1: Requirements – What training do you have to deliver? Start with your regulatory requirements. If your organisation handles personal data, GDPR training is non-negotiable. If you operate in sectors like finance or healthcare, sector-specific regulation will add further mandatory content. Map your entire regulatory landscape. Identify every piece of mandatory training your organisation needs to deliver; data protection, anti-bribery, workplace safety, so on. Place these as fixed points across the year. Missing them puts you at risk during audits and leaves your staff without the knowledge they need to act safely. Pillar 2: Organisational Needs – What training do your people actually need? Required and needed aren’t always the same thing. Think about the decisions your people make every day. HR managers involved in recruitment need to understand what can and can’t be asked in an interview. That won’t come up in a compliance audit, but the risk of getting it wrong is very real. Topics like diversity and inclusion, ethical business conduct, or conflict of interest awareness might not carry a specific legal training mandate, but each of these carry legal risk if not understood and applied. The organisations that build the strongest compliance cultures are those that go beyond the minimum. They connect training to broader risk reduction goals and treat compliance as something that protects the business, not just satisfies an auditor. The best-case scenario is that your required and needed behaviours are embedded into your culture at large. How can you ensure that, you ask? Pillar 3: Cadence – How often, and in what format, will you train? The answers to the first two pillars are meaningless if your employees never engage with the content. Frequency and format matter as much as substance and this is where many compliance programmes fall down. Nobody engages well with two hours of compliance training delivered in a single sitting. Shorter, more frequent training leads to better knowledge retention. Aim to spread training across the year in bite-sized modules, ideally under 20 minutes per sitting. Supporting those modules with reinforcement materials like posters, newsletters, and infographics keeps the message alive between formal sessions. The aim should be to keep the topic in people’s minds beyond the training. It’s at that point you’ll know it’s embedded in the culture. Integrating Compliance Training with Cybersecurity Awareness If you’re already running a cybersecurity awareness programme, you’re well placed to integrate compliance training alongside it. The two disciplines share more than people realise; both are about changing behaviour under pressure, and both depend on regular reinforcement. The practical starting point is simple. Use the same platform for both where possible, distribute modules intelligently so employees aren’t overwhelmed in any given week, and look for natural content overlaps. Data handling, for instance, is both a security and a compliance topic. Incident reporting sits in both worlds too. Reinforcing those themes from two directions is more effective than treating them in isolation. Measuring Whether It’s Working Completion rates are the baseline metric, and you’ll need them for audit purposes. But they shouldn’t be the only thing you track. Feedback matters. Build in a mechanism for employees to rate and comment on training modules. Critical feedback is valuable; if a few people found something confusing or unhelpful, others probably did too but didn’t say so. Reporting needs to reach leaders. Compliance training only changes culture when organisational leaders are invested in it. Share completion data with team managers regularly, not just at the end of a campaign. Automated progress reports that highlight incomplete learners per team give managers the information they need to act. Track trends over time. A single data point tells you little. Comparing completion rates, assessment scores, and feedback quarter-on-quarter shows you whether your programme is improving, and where it needs attention. Building a Culture, Not Just a Programme A compliance training roadmap is a tool, not an end point. The goal is a workforce that instinctively makes good decisions, knows what to report, understands why data handling matters, and doesn’t need a reminder to act ethically. That culture is built through consistency, relevance, and genuine leadership buy-in. It doesn’t happen after one training cycle. But it does happen if you’re methodical about it. If you’d like to talk through how to build compliance training into your existing security awareness programme, or how Trustack can help you structure and manage both, get in touch with our team at trustack.co.uk. We’ll help you build a programme that works for your organisation and holds up under scrutiny.
Cybersecurity Awareness Training: A 7-Step Guide to Building a Security Culture

Cybersecurity Awareness Training: A 7-Step Guide to Building a Security Culture Article Most organisations invest in firewalls, endpoint protection, and monitoring tools… Yet breaches keep happening. That’s because the majority trace back to human behaviour. That is not a criticism. It’s an opportunity. That’s because human behaviour can be changed, so long as the right culture is in place. And building a genuine security culture means shifting how your people think about and respond to threats every day, not just in the midst of a breach. In this piece, we’re going to explore the steps you should take to establish a security culture that sticks. For those of you pressed for time, just look at the following seven steps: Choose two behaviours to change Design a plan to influence them at scale Secure buy-in from leadership Communicate the “why” Execute with flexibility Measure the results Plan the next cycle For those of you who want the detail, stick with me. We’ll go through each step so you can take this back to your team and build a lasting security culture. What Is Security Culture and Why Does It Matter? In plain terms, security culture is what your people do when no one is watching. Employees who understand threats make better decisions like spotting phishing attempts and reporting suspicious activity while following company policies. With that definition in mind, let’s get to how we can actually build it. Step 1: Choose Two Behaviours to Change You should start narrow. Trying to change everything at once guarantees you change nothing meaningfully. How to identify the behaviours: Run a Security Culture survey to learn where you currently stand across key dimensions: attitudes, behaviours, compliance, communication, and norms. Map your top risks. The UK Government’s annual Cyber Security Breaches Survey and the NCSC’s Threat Report are practical starting points. From our experience, the behaviours most UK SMEs will want to start with are phishing awareness and credential hygiene. With your behaviours identified, it’s time to make a plan. Expect this first cycle to play out over a quarter or two. Step 2: Design a Plan to Influence Those Behaviours at Scale You cannot be everywhere. Your plan needs to scale beyond your team, without your constant oversight. How to design your plan: Think of this like a technology rollout. Map dependencies, identify failure points, build in contingency. Identify security champions across the business. Who else in your organisation is naturally security-conscious and trusted by their peers? Understand how you will drive change both formally (policy updates) and informally (social modelling by leaders and champions). Invest time in briefing your champions and making them feel ownership over the programme; they will be key to making it happen. Step 3: Secure Leadership Buy-In No cultural shift succeeds without visible support from the top. How to get leadership buy-in: Prepare a short executive summary. Focus on business risk and consequences, not technical detail. Ask for a specific, low-friction commitment. A mention at an all-hands meeting or a signed communication carries significant weight. Bonus points for writing it on their behalf so their commitment is as frictionless as possible. Pitch it simply. “Ransomware is our biggest exposure. I want to reduce it by improving how staff spot and report phishing. I need your backing for a short programme and five minutes at the next all-staff.“ Executives are the most visible employees of any company, so having them publicly on board is important. They can help acquire champions for you, as well. Step 4: Communicate the ‘Why’, Not Just the ‘What’ Telling people to lock their screens means little without context. Explaining that an unlocked screen can take less than 60 seconds to compromise, and that this has happened in organisations like yours, lands much better. How to apply this: Frame every communication around personal relevance. People (bless them) are selfish; they’ll act when they understand the threat to them, not just the organisation. Use multiple channels: email, intranet banners, team briefings etc. Repetition matters, and not everyone will engage with your comms in the same way. Keep your tone supportive. Position the security team as an ally rather than an enforcer. Explaining the reasons behind each change will hammer home the personal relevance of the project. Step 5: Execute (With Flexibility Built In) A well-designed plan still needs room to adapt; no plan survives first contact with the sales team… How to execute: Define what success looks like before you start. Set measurable targets (e.g. phishing report rates). Communicate progress as it happens. Celebrate early wins visibly, across those same channels you’ve been rolling the plan out on. Expect some pushback. People resist change. If you acknowledge friction points, and resolve them where possible (communicating when you do), you’ll build the trust you need. Keep champions informed and supported throughout. They are your early warning system if something is not landing. So long as you’re listening out for criticism and examining how the plan can be adapted, you’re in good shape. Step 6: Measure Results What gets measured gets improved. This protects your programme’s budget and support (especially from those execs we talked about earlier). How to measure effectiveness: Run a follow-up Security Culture Survey and compare results against your baseline from step 1. Quantify where you can: reduction in phishing click rates, increase in incident reports, drop in help desk tickets related to security issues – anything relevant. Write a brief results summary for leadership. Hard numbers make future buy-in far easier to secure. (Remember executives want outcomes, not process detail). Step 7: Plan the Next Cycle Security culture is not a project with an end date. It is an ongoing programme that you’ve just signed up for! How to plan your next steps: Review your threat landscape. Check whether your priorities still reflect the current risk environment. Is identity hygiene still key? Or has a new threat emerged? Gather feedback from your champions. They will surface insights you will not get from surveys alone, no matter how anonymous they are. Decide whether to deepen the behaviours from the last cycle or introduce new ones. (Never abandon previous gains). Go back to step 1. With each iteration, the process gets smoother and the culture shifts further in the right direction. Bringing It All Together Cybersecurity awareness training works best when it sits inside a structured, repeating programme, not as an annual video and a quiz.
How Petards built a stronger cyber culture

How Petards built a stronger cyber culture with Managed User Awareness from Trustack Customer: Petards is a technology company specialising in security, surveillance and communication solutions, with 80+ employees. Challenge: Lack of cyber awareness was leading to employees unknowingly violating policies and seeking workarounds to security measures which was consuming vast amounts of the IT team’s time. The Result: Improved employee awareness around phishing and suspicious emails Reduced the number of basic phishing queries being escalated to IT Gained better visibility of user behaviour About Petards Sector: Advanced technology, security, surveillance, communications & Manufacturing Location: Newcastle Upon Tyne Employees: 80+ Petards is a technology company that develops advanced solutions for security, surveillance and communication. Its work spans specialist sectors such as rail, traffic, wireless communications and defence, supporting organisations that rely on secure technology in complex environments. Because Petards works in technically complex and security-conscious environments, employee awareness plays an important role in protecting business data and reducing cyber risk. The Challenge Petards needed to improve cyber awareness across the business. Employees were receiving phishing emails and, without a consistent level of understanding, some were unsure how to respond or were looking for ways around security processes. This created unnecessary pressure on the internal IT team, who were spending significant time helping users assess suspicious emails and manage security-related queries. It also increased the risk of human error, particularly if employees failed to report phishing attempts or unknowingly acted outside company policy. As a technology company working across complex and security-focused sectors, Petards wanted to take a more proactive approach. The priority was to give employees the confidence to recognise and report threats, while reducing the amount of time IT spent dealing with avoidable awareness-related issues. The Solution Trustack delivered and manages KnowBe4, a security awareness training and phishing simulation platform, for Petards. The rollout was smooth, with support provided across setup, user imports, the phishing report button and ongoing reporting. This gave Petards a structured way to improve cyber awareness and monitor risky behaviours, without adding more day-to-day management to the internal IT team. The Results Petards gained clearer visibility of how employees were responding to phishing threats, while users became more confident recognising and reporting suspicious emails. With Trustack managing KnowBe4, the organisation reduced pressure on IT and built a more proactive approach to human risk management. Petards also found the platform more engaging than alternatives they had reviewed, with content that received positive feedback from staff. “I would definitely recommend KnowBe4 as a platform. I would also recommend getting Trustack to manage it for you. From an IT manager’s point of view, when you’ve got so many products to look after in-house, having an MSP manage security awareness for you is the best thing I’ve ever done.” Carl Webber IT Manager, Petards Strengthen Your Human Risk Management Now Build a more cyber-aware workforce with HRM training that improves reporting and reduces pressure on IT. Start the Conversation
Global RAM Shortages: How should you prepare?

Global RAM Shortages: How should you prepare? Article Publish Date: The global memory market has been stretched to its absolute limit with demand exceeding supply and production capabilities, driven primarily by AI and data centre expansions. How does this impact you? Courtesy of the booming demand, memory prices are rising — especially for RAM-heavy server and workstation configurations. We’ve personally witnessed prices tripling in some cases! It’s also becoming more difficult to source high-capacity systems. As suppliers constrain lower priority hardware to meet demand from hyperscalers and AI data centres, there are fewer server and workstation configurations to choose from. And, if you can find the extra budget and get the configuration you desire, you’ll join a queue of orders impacted by increased lead times that are expected by vendors to persist for months to years. How can you mitigate its impact? Right size your memory, tune your workloads and validate real RAM headroom. Consider balanced upgrades to meet performance requirements such as, CPU, GPU and SSD Pull forward orders for planned work to lock in availability and pricing ahead of continued increases in demand and price. Plan for alternative configurations to reduce risk if preferred parts aren’t available. If you have major projects or hardware upgrades planned in 2026, we recommend you review your roadmap before the impact continues to grow. Contact Us Today!
The cybersecurity baseline: What are the essentials you need?

The Cybersecurity Baseline: What Are the Essentials You Need? Article Publish Date: Let’s start by building the foundations that will support your business as it grows and it’s needs evolve. The truth is there isn’t one definitive answer – every business’ way of working is unique be that in the office, hybrid or fully remote. However, while there’s no “one size fits all” solution, there are some best practices and tools that (if implemented correctly) give you a solid base to protect your business and build your wider security strategy. A note from our technical team: this isn’t a “here’s the least you can have and be cyber secure” guide. The following are solutions that can be applied to all business whether cloud only, hybrid or on-prem. Protect your business by safeguarding your people The first pillar of our cybersecurity foundation is Cyber Awareness Training also known as “Human Risk Management” (HRM). Knowing that 88% of data breaches start by successfully exploiting human error, keeping your team aware of the threat landscape and promoting a security-first culture is key to stopping cyber threats. The second pillar takes some pressure off your team by preventing phishing, malware, and other harmful spam from reaching a real person while preventing data leaks in both incoming and outgoing emails. It takes the form of a Secure Email Gateway. The third and final pillar of this guide is Next-Gen Anti-Virus. NGAV performs threat prevention by blocking and quarantining threats using machine learning and behavioural analysis without requiring advanced technical knowledge. It’s a start but what’s next? This is what our team recommends if you’re taking the first steps of your cybersecurity journey however, we always recommend following the government framework, Cyber Essentials, which mitigates or prevents over 80% of common cyber attacks. For more information on the cybersecurity baseline, or to learn more about our cyber security services, contact us today. Contact Us
Understanding the UK Cyber Security & Resilience Bill: What It Means for 2026 and Beyond

Understanding the UK Cyber Security & Resilience Bill: What It Means for 2026 and Beyond Article Publish Date: The UK Government is entering a new era of cyber regulation. Cyber threats are intensifying and recent attacks have caused serious disruption across public and private sectors. The new Cyber Security and Resilience Bill signals a shift from voluntary best practice to mandatory cyber resilience. The Bill is designed to strengthen essential services, protect national security, and update the UK’s ageing NIS Regulations (2018) to keep pace with modern cyber risks. Full implementation is anticipated after Royal Assent, expected in 2026, pending the bill’s progression beyond its current committee stage and the development of secondary legislation and regulator guidance. Why Is This Bill Needed? Cyber threats have accelerated dramatically, for example: 204 nationally significant cyber incidents were recorded by the NCSC in the year to August 2025, a 130% year on year increase. The Synnovis ransomware attack disrupted NHS pathology services, leading to over 10,000 cancelled outpatient appointments and critical care delays. Attacks against European energy providers caused operational shutdowns, highlighting vulnerabilities in critical infrastructure. The Government has made cyber resilience a national priority. Services such as healthcare, water, energy, and digital infrastructure are now too essential, and too interconnected, to remain exposed to preventable disruption. What the Bill Does: Key Changes Expands Who Falls Within Regulation The Bill significantly widens the regulatory net to reflect modern supply chain risk. This aligns the UK more closely with the EU’s NIS2 Directive, while retaining UK specific flexibility. Tougher Incident Reporting Requirements Under the new bill, businesses must notify regulators within 24 hours of a significant incident and provide a full report within 72 hours. Stronger Security Standards Organisations must maintain security measures that are: “Appropriate, proportionate, and up to date,” and Measurable against the NCSC Cyber Assessment Framework (CAF). The CAF now becomes the expected standard for demonstrating compliance. Expanded Regulator Powers Regulators (such as the ICO, Ofcom, or sector bodies) will have powers to: Designate critical suppliers. Issue enforcement notices and conduct inspections. Direct organisations to take specific actions where national security risks arise. Tougher Penalties Non‑compliance can result in fines of up to £17 million, or 4% of global annual turnover. How to Prepare Review and update incident response plans Ensure you can meet both the 24-hour initial report and 72-hour full notification requirement by incorporating reporting into your incident response plan. Strengthen supply chain assurance Assess whether you could be designated a critical supplier, or whether your suppliers could endanger your cyber readiness. Review contracts, access models, and due diligence processes. Align with the NCSC CAF Map your controls to CAF principles and identify gaps around governance, risk management, asset control, and resilience. Test resilience scenarios Conduct tabletop exercises for ransomware, data centre outages, MSP compromise, and cascading supply chain failures. Take Action Now This Bill represents a major step change in UK cyber regulation, and the expectation is clear: resilience is no longer optional. As a leading cyber security company in the north east England, we’re well placed to help you start preparing now. Contact us today to discuss how to adapt your incident response plan to the legislative landscape. Contact Us
VMware Is Changing Their Strategy. What Does It Mean For You?

VMware Is Changing Their Strategy. What Does It Mean For You? Article Publish Date: VMware’s parent company Broadcom are shifting strategy this year. Their focus is shifting to hyperscalers and datacentres, removing the SMB and smaller enterprise products from the catalogue while enacting substantial price increases to what remains. As a loyal partner of VMware since Trustack’s founding in 2008, we’ve always taken pride in keeping our clients ahead of any critical changes that could affect their business. This latest change is among the most impactful we’ve experienced, with Broadcom shifting to an entirely new strategy forcing all VMware users to take action before their next renewal or be caught out with price increases in some cases of up to 300%. Key Changes at VMware: Essentials & Essentials Plus removed from catalogue. Standard remains in the product catalogue. However, we expect this to be removed soon and have already seen Broadcom refuse to issue new Standard licences. VMware have announced they will be selling vCloud Foundation exclusively going forward. Several thousand partners have already been removed from their partner programme, indicating a trend away from resellers. Trustack have avoided that thus far due to our longstanding relationship with VMware. What Are Your Options Going Forward? Our top recommendation is to consider Scale Computing, a hyperconverged solution which we now use internally to run a large part of Trustack. Scale Computing will not only give you cost savings but also improved efficiency and simplified management of your virtualisation solution. Alternatively, Microsoft Hyper-V is Microsoft’s virtualisation technology that integrates effectively with the Windows ecosystem. Hyper-V has the basic features you might need in a hypervisor, but it lacks some of the more advanced functionality of VMware. Finally, you can choose to remain with VMware by upgrading to vCloud Foundation, but you can expect potential cost increases of 300% on your previous renewal. To discuss what your next steps should be, contact Trustack today. Contact Us
Trustack named Arctic Wolf EMEA Partner of the Year

Trustack named Arctic Wolf EMEA Partner of the year News Publish Date: We are thrilled to announce that we have been awarded the title of Arctic Wolf’s EMEA Partner of the Year, after receiving the Partner of the Quarter award earlier this year. Trustack is proud to work with Arctic Wolf daily to continuously improve our customers’ cybersecurity posture. A huge moment for Trustack Trustack has been named Arctic Wolf’s EMEA Partner of the Year. This honour recognises the company’s commitment to improving its customers’ cybersecurity posture through a strategic partnership with Arctic Wolf that focuses on joint business growth and planning, engagement and training, demand generation, and executive and security practice alignment. “This is an absolutely huge moment for us at Trustack – to say we are proud to be named partner of the year is an understatement. Arctic Wolf has a thriving partner community across Europe, the Middle East and Africa so to be named partner of the year for the entire region is a huge achievement for the business. The recipe for success when it comes to partnerships is for both sets of people to get on and understand one another, and for there to be a market for the product or service you are offering. In this case, all these ingredients have been present and have led to a successful partnership between Trustack and Arctic Wolf.” said Phil Cambers, Commercial Director at Trustack. Trustack receives Arctic Wolf Partner of the year Celebrating their fifth year globally, and first year in EMEA, the Arctic Wolf Partner of the Year Awards honour top-performing partners for their achievements in helping organisations improve their security operations through the use of Arctic Wolf solutions and for their commitment to shared customer success through a partnership with Arctic Wolf. Managed IT Services provider Trustack, based in Cramlington, Northumberland, was formed following the merger of three companies in 2019. Trustack has grown rapidly, despite the Covid-19 pandemic. its workforce has increased 30% percent from 43 to 55. and has around 450 active clients. North East’s Top 200 Companies These include several of the North East’s Top 200 companies such as Muckle LLP and Collingwood Business Solutions – as well as big names across the UK such as the Premier League and Vertu Motors. Trustack Specialises in: Cloud Management Infrastructure Security Unified Communications View our stack Trustack began working with Arctic Wolf in July 2021 We were named the organisation’s partner of the quarter for August – October 2021. “The Arctic Wolf partner community leads the way in embracing security operations and playing a transformative role in the security journey of their customers. Our Partner of the Year Awards recognise and celebrate those partners who share our mission to end cyber risk, and we congratulate Trustack on their significant achievements.” – Clare Loveridge, Vice President & General Manager, EMEA, Arctic Wolf Arctic Wolf is a global leader in security operations Who pioneered a cloud-native security operations platform designed to end cyber risk. Built on open XDR architecture, the Arctic Wolf Security Operations Cloud ingests and analyses more than two trillion security events a week across endpoint, network, and cloud sources to deliver critical security outcomes and optimise an organisation’s disparate security solutions. Now deployed to more than 2,700 customers worldwide, the Arctic Wolf Platform delivers automated threat detection and response at scale and empowers organisations of virtually any size to establish security operations with the push of a button. Get your business on the front foot Share the article to your socials About the Authors Connect on Linkedin Spotlighted Articles See all insights