Heligan Group - Experts & Thought Leaders

Latest Heligan Group news & announcements

Circular reporting detection in security intelligence

Boards are paying for analytical confidence including polished assessments with clear conclusions which signal certainty, but what’s not visible is the process behind that confidence. Businesses rarely see the reasoning chain or the assumptions that would blow an assessment apart if they proved false. Recent geopolitical volatility, such as the US-Iran conflict, has shown the consequences of unverified or weakly interrogated inputs. Misreading political risk According to Adam Irwin Managing Partner of Heligan Strategic Advisory, “Corporate intelligence is only as secure as the safeguards that sit behind it, but analysts will always be biased. No board would accept a set of numbers without an audit trail, yet many accept intelligence that shape approvals and decisions with no method visibility.” “Misidentifying beneficial ownership or misreading political risk in a target market can lead to business choices that have regulatory exposure and reputational risks. Firms must be able to audit their own thinking under pressure to catch those biases before they influence processes.” Irwin argues that the analytical bias can move from being a background risk to directly shaping outputs when the information environment turns hostile. Battle damage assessment “We’ve seen circular reporting dressed up as corroboration: think tanks and briefing notes all echoing the same CENTCOM battle damage assessment on Iranian missile assets as three independent sources when they’re one source. Even synthetic content has entered the intelligence chain like the circulated AI satellite imagery of a destroyed US base in Qatar before its Google Earth origin and SynthID watermark were detected.” “While the distinction between source reliability and credibility is clear, the problem is application. Peer review can help to catch factual slips, but it cannot point out assumptions of analysts reinforcing each other’s conclusions and amplifying uncontested language. The label, groupthink, captures the nature of the error: not bad actors but an architecture that didn’t force disagreement into the room.” Circular reporting detection Irwin points to a structured methodology to solve this: “Firms must build a system that can intercept bias such as a documented register of structural biases by source category, including aligned think tanks, commercial interests, state media, advocacy groups. This isn’t a blacklist but a way to stop treating ‘institutional’ as synonymous with ‘neutral.’” “Circular reporting detection will also be important to trace each cited source back to its data origin,” Irwin said. “If they all terminate in the same place, you don’t have corroboration but amplification. “Complimentary to this will be confidence levels capped by the quality of the source, not the analyst’s comfort level. If the evidence comes from a party with a certain interest, confidence can’t rise above a defined ceiling. This breaks the pattern where familiarity converts tentative reports into assumed fact.” US–Iran information environment Irwin concludes, “The aim isn’t to remove bias but to make it increasingly unlikely that the same bias will pass through every layer unchallenged. The US–Iran information environment is a live stress test that has concentrated every pattern worrying to an intelligence consumer: circular reporting, synthetic content and confidence inflation.” “The firms that build auditable and analytical safeguards will set the benchmark the rest of the market is eventually judged against. That's the standard we should expect and demand from any business within the intelligence sector.”

Phishing attacks surge: Protect UK businesses now

A 2022 report from the Office for National Statistics, the most comprehensive on phishing to date, has revealed that half of all adults residing in the UK have reported receiving a phishing message. In the last year, 85% of UK businesses and 86% of charities faced at least one phishing attack, with 32% of phishing emails being AI-generated, leveraging scraped social media or dark web data and real-time language tweaking. Advance fee fraud The average loss for businesses from phishing attacks increased to £1,600 in 2024 There has been an increase in the evidence of fraudsters taking advantage of widespread behavioural changes following the COVID-19 pandemic, particularly in online shopping cases. This includes a nine-fold increase in advance fee fraud, tricking victims into paying an upfront fee in exchange for a larger reward, service, or goods that never materialise, and a 57% rise in consumer and retail fraud from pre-pandemic levels, with more than half of those who received phishing messages reporting them from senders posing as delivery companies. As such, the average loss for businesses from phishing attacks increased to £1,600 in 2024, rising by 32% over 2023. Growing public awareness Phishing messages most commonly impersonate delivery companies, financial institutions Will Ashford-Brown, Director of Strategic Insights at Heligan Group, said, “UK businesses are lacking the resources and education to safeguard themselves against phishing attacks. It takes one slip-up on one email to cause complete operational chaos.” The Suspicious Emails and Reporting Service (SERS), run by the National Cyber Security Centre (NCSC), has received over 32 million reports from the public since its inception in 2020. Notably, there was a 44% increase in reports made in 2023, compared to 2022, indicating, in part, growing public awareness and vigilance against this specific form of cyber threat – a rare positive when appraising the state of cybercrime in the 21st Century, yet phishing continues to surge. According to a Telephone-operated Crime Survey for England and Wales, phishing messages most commonly impersonate delivery companies, financial institutions, e-commerce companies, and government services. Signs of a scam “To stay safe, UK businesses must report scams as soon as they can, so they can be dealt with and get them taken down,” Ashford-Brown continued. “Employees should be strongly encouraged to reduce the amount of personal information they share online, which contributes to the ability of scammers to target businesses.” “They should also receive training on how to identify the tell-tale signs of a scam. Most phone providers are part of a scheme that allows customers to report suspicious text messages for free by forwarding them to 7726, and this scheme must be encouraged.” Increase in phishing attacks “The alarming increase in phishing attacks year-on-year should be a wake-up call for UK businesses. They cannot afford to bury their heads in the sand and must educate all staff members on how to safeguard against phishing. With the correct education and safeguarding, attacks can be easily avoided.” “Personal information must remain private and off the internet for both business and personal safety. Businesses need to remain vigilant as phishing continues to become a significant threat to the UK,” concluded Ashford-Brown.

Cyber security drives Private Equity growth in UK

Over the last 10 years, threats to the UK, including espionage, terrorism, cyber-attacks, and disinformation, have increased dramatically in volume and velocity. Globally, multiple state-on-state conflicts pose serious risks, with the potential to escalate into both intra and intercontinental struggles. Range of sub-sectors Private Equity activity across Security-Tech has continued to grow year-on-year, with 191 direct investments made since 2018 across a range of sub-sectors. These include Safety & Security, Risk & Crime Prevention, Identity Technology, Intelligence and Surveillance, Communication Technology, Cyber Security, Defence and Frontier Technology. According to Heligan, as threats evolve, Private Equity investment is crucial for accelerating innovation and market readiness and maintaining the operational edge over adversaries. Approaches in other security and defence sectors Security-Tech investment has accelerated across different regions of the UK, with 89 transactions Security-Tech investment has accelerated across different regions of the UK, with 89 transactions in the Southeast from 2018-2024 and 25 in the Midlands, with deal activity also rising in the Northwest and Scotland. Matt Croker, Director at Heligan, said, “Cyber security remains a standout sector for Private Equity, offering scalable, recurring revenues and a fragmented market ideal for buy-and-build strategies that enhance returns. While Private Equity is now exploring buy-and-build approaches in other security and defence sectors, this trend is emerging but is expected to grow quickly." Renewed focus on national security Croker added: “More broadly, 2024 was a record year for new investments. Although volumes dipped in 2022 and 2023, activity remained robust and looking ahead, 2025 could exceed the level of activity experienced in 2024." "Government priorities have shifted with a renewed focus on national security amid conflicts like Ukraine-Russia and Israel Middle East. This geopolitical instability has driven structural change in governmental mindsets and budgets, expanding addressable markets - a crucial factor for investors." Demand for innovative dual-use technologies “The defence and national security technology industry is transforming significantly in response to increased challenges”, added Croker. “The government's increasing demand for innovative dual-use technologies is driving sector growth, which, in turn, is driving private market investment. Private Equity firms are looking to capitalise on this expanding market, which is often supported by government, military and law enforcement needs.” Private Equity platforms Bolt-on transactions for Private Equity platforms are also increasing in volume Bolt-on transactions for Private Equity platforms are also increasing in volume. Cyber security and defence are seeing more roll-up strategies driven by recurring revenue models that attract PE alongside attractive market dynamics. Croker continued: “Technological advances present both threats and opportunities, and the defence and security sectors are actively implementing AI, quantum computing, advanced robotics and novel materials." Security-Tech ecosystem Croker added: "As these technologies continue to evolve it creates new opportunities for Private Equity and Venture Capital investors and we expect the Security-Tech ecosystem to continue to thrive and grow in influence." “Cybersecurity, Intelligence & Security and Defence assets remain highly attractive. Private Equity investment is crucial for accelerating innovation, market readiness and maintaining our operation edge over our adversaries,” concluded Croker.