Industry Insights

Our constant engagement with an evolving and digitally connected world

Aerial shot of wind turbines
by Pete Nisbet 15 September 2025
Discover how businesses can drive value through sustainability by focusing on compliance, cost savings, and credibility—building trust, cutting emissions, and attracting investors | READ ARTICLE NOW
Volcano lava lake
by Scott Armstrong 18 September 2025
Discover why short-term thinking on sustainability risks business growth. Explore how long-term climate strategy drives resilience, valuation, and trust | READ FULL ARTICLE

Industry insights


Neon letters 'Ai' made from stacks of blocks like a 3D bar graph
by Darren Sheppard 4 December 2025
What is the Contract Lifecycle Management and Why does it Matter? The future success of your business depends on realising the value that’s captured in its contracts. From vendor agreements to employee documents, everywhere you look are commitments that need to be met for your business to succeed. The type of contract and the nature of goods or services it covers will determine what sort of management activities might be needed at each stage. How your company is organised will also determine which departments or individuals are responsible for what activities at each stage. Contract Lifecycle Management, from a buyer's perspective, is the process of defining and designing the actual activities needed in each stage for any specific contract, allocating ownership of the activities to individuals or groups, and monitoring the performance of those activities as the contract progresses through its lifecycle. The ultimate aim is to minimise surprises, ensure the contracted goods or services are delivered by the vendor in accordance with the contract, and realise the expected business benefits and value for money. The Problem of Redundant Spend in Contracts Despite the built-in imbalance of information favoring suppliers, companies still choose to oversee these vendors internally. However, many adopt a reactive, unstructured approach to supplier management and struggle to bridge the gap between contractual expectations and actual performance. Currently, where governance exists, it is often understaffed, with weak, missing, or poorly enforced processes. The focus is primarily on manual data collection, validation, and basic retrospective reporting of supplier performance, rather than on proactively managing risk, relationships, and overall performance. The amount of redundant spend in contracts can vary widely depending on the industry, the complexity of the contracts, and how rigorously they are managed. For further information on this, Cambridge MC’s case studies provide insights into typical ranges and common sources of redundant spend. As a general estimate, industry analysts often state that redundant spend can account for as much as 20% of total contract value. In some cases, especially in poorly managed contracts, this can be much higher. What is AI-driven Contract Management? Artificial Intelligence (AI) is redefining contract management, transforming a historically time-consuming and manual process into a streamlined, efficient, and intelligent operation. Traditionally, managing contracts required legal teams to navigate through extensive paperwork, drafting, reviewing, and monitoring agreements — a process prone to inefficiencies and human error. With the emergence of artificial intelligence, particularly generative AI and natural language processing (NLP), this area of operations is undergoing a paradigm shift. This step change is not without concerns however, as there are the inevitable risks of AI hallucinations, training data biases and the threat to jobs. AI-driven contract management solutions not only automate repetitive tasks but also uncover valuable insights locked up in contract data, improving compliance and reducing the risks that are often lost in reams paperwork and contract clauses. Put simply, AI can automate, analyse, and optimise every aspect of your contract lifecycle. From drafting and negotiation to approval, storage, and tracking, AI-powered platforms enhance precision and speed across these processes; in some cases reducing work that might take several days to minutes or hours. By discerning patterns and identifying key terms, conditions, and concepts within agreements, AI enables businesses to parse complex contracts with ease and efficiency. In theory, this empowers your legal and contract teams (rather than reducing them), allowing personnel to focus on high-level tasks such as strategy rather than minutiae. However, it is important to recognise that none of the solutions available in the marketplace today offer companies an integrated supplier management solution, combining a comprehensive software platform, capable of advanced analytics, with a managed service. Cambridge Management Consulting is one of only a few consultancies that offers fully integrated Contract Management as a Service (CMaaS). Benefits of Integrating AI into your Contract Lifecycle Management Cambridge MC’s Contract Management as a Service (CMaaS) 360-degree Visibility: Enable your business to gain 360-degree visibility into contracts and streamline the change management process. Real-time Data: Gain real-time performance data and granularly compare it against contractually obligated outcomes. More Control: Take control of your contracts and associated relationships with an integrated, centralised platform. Advanced meta data searches provide specific information on external risk elements, and qualitative and quantitative insights into performance. Reduces Costs: By automating manual processes, businesses can significantly reduce administrative costs associated with contract management. AI-based solutions eliminate inefficiencies in the contract lifecycle while minimising reliance on external legal counsel for routine tasks. Supplier Collaboration: Proactively drive supplier collaboration and take a data-driven approach towards managing relationships and governance process health. Enhanced Compliance: AI tools ensure that contracts adhere to internal policies and external regulations by flagging non-compliant clauses during the drafting or review stage. This proactive approach reduces the risk of costly disputes or penalties. Reduces Human Errors: In traditional contract management processes, human errors can lead to missed deadlines and hidden risks. AI-powered systems use natural language processing to identify inconsistencies or inaccuracies in contracts before they escalate into larger issues. Automates Repetitive Tasks: AI-powered tools automate time-consuming tasks such as drafting contracts, reviewing documents for errors, and extracting key terms. This frees up legal teams to focus on higher-value activities like strategic negotiations and risk assessment. We can accurately model and connect commercial information across end-to-end processes and execution systems. AI capabilities then derive and apply automated commercial intelligence (from thousands of commercial experts using those systems) to error-proof complex tasks such as searching for hidden contract risks, determining SLA calculations and performing invoice matching/approvals directly against best-in-class criteria. Contract management teams using AI tools reported an annual savings rate that is 37% higher than peers. Spending and tracking rebates, delivery terms and volume discounts can ensure that all of the savings negotiated in a sourcing cycle are based on our experience of managing complex contracts for a wide variety of customers. Our Contract Management as a Service, underpinned by AI software tooling, has already delivered tangible benefits and proven success. 8 Steps to Transition Your Organisation to AI Contract Management Implementing AI-driven contract management requires a thoughtful and structured approach to ensure seamless integration and long-term success. By following these key steps your organisation can avoid delays and costly setbacks. Step 1 Digitise Contracts and Centralise in the Cloud: Begin by converting all existing contracts into a digital format and storing them in a secure, centralised, cloud-based repository. This ensures contracts are accessible, organised, and easier to manage. A cloud-based system also facilitates real-time collaboration and allows AI to extract data from various file formats, such as PDFs and OCR-scanned images, with ease. Search for and retrieve contracts using a variety of advanced search features such as full text search, Boolean, regex, fuzzy, and more. Monitor upcoming renewal and expiration events with configurable alerts, notifications, and calendar entries. Streamline contract change management with robust version control and automatically refresh updated metadata and affected obligations. Step 2 Choose the Right AI-Powered Contract Management Software: Selecting the right software is a critical step in setting up your management system. Evaluate platforms based on their ability to meet your organisation’s unique contracting needs. Consider key factors such as data privacy and security, integration with existing systems, ease of implementation, and the accuracy of AI-generated outputs. A well-chosen platform will streamline workflows while ensuring compliance and scalability. Step 3 Understand How AI Analyses Contracts: To make the most of AI, it’s essential to understand how it processes contract data. AI systems use Natural Language Processing (NLP) to interpret and extract meaning from human-readable contract terms, while Machine Learning (ML) enables the system to continuously improve its accuracy through experience. These combined technologies allow AI to identify key clauses, conditions, and obligations, as well as extract critical data like dates, parties, and legal provisions. Training your team on these capabilities will help them to understand the system and diagnose inconsistencies. Step 4 Maintain Oversight and Validate AI Outputs: While AI can automate repetitive tasks and significantly reduce manual effort, human oversight is indispensable. Implement a thorough process for spot-checking AI-generated outputs to ensure accuracy, compliance, and alignment with organisational standards. Legal teams should review contracts processed by AI to verify the integrity of agreements and minimise risks. This collaborative approach between AI and human contract management expertise ensures confidence in the system. Step 5 Refine the Data Pool for Better Results: The quality of AI’s analysis depends heavily on the data it is trained on. Regularly refine and update your data pool by incorporating industry-relevant contract examples and removing errors or inconsistencies. A well-maintained data set enhances the precision of AI outputs, enabling the system to adapt to evolving business needs and legal standards. Step 6 Establish Frameworks for Ongoing AI Management: To ensure long-term success, set clear objectives and measurable goals for your AI contract management system. Define key performance indicators (KPIs) to track progress and prioritise features that align with your organisation’s specific requirements. Establish workflows and governance frameworks to guide the use of AI tools, ensuring consistency and accountability in contract management processes. Step 7 Train and Empower Your Teams: Equip your teams with the skills and knowledge they need to use AI tools effectively. Conduct hands-on training sessions to familiarise users with the platform’s features and functionalities. Create a feedback loop to gather insights from your team, allowing for continuous improvement of the system. Avoid change resistance by using change management methodologies, as this will foster trust in the technology and drive successful adoption. Step 8 Ensure Ethical and Secure Use of AI: Tools Promote transparency and integrity in the use of AI-driven contract management. Legal teams should have the ability to filter sensitive information, secure data within private cloud environments, and trace data back to its source when needed. By prioritising data security and ethical AI practices, organisations can build trust and mitigate potential risks. With the right tools, training, and oversight, AI can become a powerful ally in achieving operational excellence as well as reducing costs and risk. Overcoming the Technical & Human Challenges While the benefits are compelling, implementing AI in contract management comes with some unique challenges which need to be managed by your leadership and contract teams: Data Security Concerns: Uploading sensitive contracts to cloud-based platforms risks data breaches and phishing attacks. Integration Complexities: Incorporating AI tools into existing systems requires careful planning to avoid disruptions and downtime. Change Fatigue & Resistance: Training employees to use new technologies can be time-intensive and costly. There is a natural resistance to change, the dynamics of which are often overlooked and ignored, even though these risks are often a major cause of project failure. Reliance on Generic Models: Off-the-shelf AI models may not fully align with your needs without detailed customisation. To address these challenges, businesses should partner with experienced providers who specialise in delivering tailored AI-driven solutions for contract lifecycle management. Case Study 1: The CRM That Nobody Used A mid-sized company invests £50,000 in a cutting-edge Customer Relationship Management (CRM) system, hoping to streamline customer interactions, automate follow-ups, and boost sales performance. The leadership expects this software to increase efficiency and revenue. However, after six months: Sales teams continue using spreadsheets because they find the CRM complicated. Managers struggle to generate reports because the system wasn’t set up properly. Customer data is inconsistent, leading to missed opportunities. The Result: The software becomes an expensive shelf-ware — a wasted investment that adds no value because the employees never fully adopted it. Case Study 2: Using Contract Management Experts to Set Up, Customise and Provide Training If the previous company had invested in professional services alongside the software, the outcome would have been very different. A team of CMaaS experts would: Train employees to ensure adoption and confidence in using the system. Customise the software to fit business needs, eliminating frustrations. Provide ongoing support, so issues don’t lead to abandonment. Generate workflows and governance for upward communication and visibility of adherence. The Result: A fully customised CRM that significantly improves the Contract Management lifecycle, leading to: more efficient workflows, more time for the contract team to spend on higher value work, automated tasks and event notifications, and real-time analytics. With full utilisation and efficiency, the software delivers real ROI, making it a strategic investment instead of a sunk cost. Summary AI is reshaping the way organisations approach contract lifecycle management by automating processes, enhancing compliance, reducing risks, and improving visibility into contractual obligations. From data extraction to risk analysis, AI-powered tools are empowering legal teams with actionable insights while driving operational efficiency. However, successful implementation requires overcoming challenges such as data security concerns and integration complexities. By choosing the right solutions, tailored to their needs — and partnering with experts like Cambridge Management Consulting — businesses can overcome the challenges and unlock the full potential of AI-based contract management. A Summary of Key Benefits Manage the entire lifecycle of supplier management on a single integrated platform Stop value leakage: as much as 20% of Annual Contract Value (ACV) Reduce on-going governance and application support and maintenance expenses by up to 60% Deliver a higher level of service to your end-user community. Speed without compromise: accomplish more in less time with automation capabilities Smarter contracts allow you to leverage analytics while you negotiate Manage and reduce risk at every step of the contract lifecycle Up to 90% reduction in creating first drafts Reduction in CLM costs and extraction costs How we Can Help Cambridge Management Consulting stands at the forefront of delivering innovative AI-powered solutions for contract lifecycle management. With specialised teams in both AI and Contract Management, we are well-placed to design and manage your transition with minimal disruption to operations. We have already worked with many public and private organisations, during due diligence, deal negotiation, TSAs, and exit phases; rescuing millions in contract management issues. Use the contact form below to send your queries to Darren Sheppard , Senior Partner for Contract Management. Go to our Contract Management Service Page
Sun through the trees
by Scott Armstrong 26 November 2025
Nature means something different to everyone. For some, it is a dog-walk through the park; for others, it is hiking misty mountains in Scotland, swimming in turquoise waters, or exploring tropical forests in Costa Rica.
Aerial view of Westminster, London.
by Craig Cheney 25 November 2025
With the UK Budget being published tomorrow, councils are facing intense financial pressure. Rising demand for adult and children’s social care, homelessness services, and temporary accommodation has left little room for manoeuvre.
by Cambridge Management Consulting 20 November 2025
Press Release
Lightning strike in dark sky
by Scott Armstrong 17 November 2025
Non-commodity charges are driving UK energy costs higher. Discover what’s changing, why it matters, and the steps businesses should take to protect budgets | READ NOW
Futuristic building with greenery growing out of it.
by Cambridge Management Consulting 10 November 2025
Over the last few decades, carbon offsetting has become a go-to strategy for businesses looking to demonstrate sustainability commitments and enhance their external credibility. Offsetting takes many forms, from tree planting and forest conservation to providing communities with clean cookstoves and renewable energy.
Aerial view of solar panels in a green field.
by Drew Davy 7 November 2025
In today's rapidly evolving business landscape, Environmental, Social, and Governance (ESG) factors have moved from niche considerations to critical drivers of long-term value, investor confidence, and societal impact.
Two blocks of data with bottleneck inbetween
by Paul Brooker 29 October 2025
Read our article on hidden complexity and find out how shadow IT, duplicate tools and siloed buying bloat costs. See how CIOs gain a single view of IT spend to cut waste, boost compliance and unlock 5–7% annual savings | READ FULL ARTICLE
Neon 'Open' sign in business window
by Tom Burton 9 October 2025
SMEs make up 99% of UK businesses, three fifths of employment, over 50% of all business revenue, are in everyone's supply chain, and are exposed to largely the same threats as large enterprises. How should they get started with cyber security? Small and Medium sized Enterprises (SME) are not immune to the threat of cyber attacks. At the very least, if your business has money then it will be attractive to criminals. And even if you don’t have anything of value, you may still get caught up in a ransomware campaign with all of your data and systems made inaccessible. Unfortunately many SMEs do not have an IT team let alone a cyber security team. It may not be obvious where to start, but inaction can have significant impact on your business by both increasing risk and reducing the confidence to address new opportunities. In this article we outline 5 key questions that can help SMEs to understand what they need to do. Even if you outsource your IT to a supplier these questions are still relevant. Some can’t be delegated, and others are topics for discussion so that you can ensure your service provider is doing the right things, as well as understanding where their responsibilities stop and yours start. Q1: What's Important & Worth Defending Not everything needs protecting equally. In your personal life you will have some possessions that are dear to you and others that you are more laissez-faire about. The same applies to your digital assets, and the start point for any security plan needs to be an audit of the things you own and their importance to your business. Those ‘things’, or assets, may be particular types of data or information. For instance, you may have sensitive intellectual property or trade secrets; you may hold information about your customers that is governed by privacy regulations; or your financial data may be of particular concern. Some of this information needs to be protected from theft, while it may be more important to prevent other types of data from being modified or deleted. It is helpful to build a list of these assets, and their characteristics like the table below:
Illustration of EV sensor fields
by Duncan Clubb 25 September 2025
Explore the rise of edge AI: smaller data centres, faster networks, and sustainable power solutions. See why the future of digital infrastructure is distributed and intelligent | READ FULL ARTICLE
A close-up of the Downing St sign
by Craig Cheney 19 September 2025
Craig Cheney | The conversation around artificial intelligence (AI) in Government has shifted in recent years. The publication of the UK Government’s AI Playbook represents more than just updated guidance — it signals a huge shift in the government's approach to AI.
Volcano lava lake
by Scott Armstrong 18 September 2025
Discover why short-term thinking on sustainability risks business growth. Explore how long-term climate strategy drives resilience, valuation, and trust | READ FULL ARTICLE
Close up of electricity pylon
by Duncan Clubb 17 September 2025
The UK’s AI ambitions face gridlock. Discover how power shortages, costly electricity, and rack density challenges threaten data centre growth – and what’s being done | READ FULL ARTICLE
Abstract neon hexagons
by Tom Burton 17 September 2025
Delaying cybersecurity puts startups at risk. Discover how early safeguards boost investor confidence, customer trust, and long-term business resilience | READ FULL ARTICLE
Neon wave
by Anthony Aarons 16 September 2025
An in-depth look at AI risk and governance: OECD frameworks, EU AI Act, and UK/US strategies reveal how nations balance innovation with safety and accountability | READ NOW
Aerial shot of wind turbines
by Pete Nisbet 15 September 2025
Discover how businesses can drive value through sustainability by focusing on compliance, cost savings, and credibility—building trust, cutting emissions, and attracting investors | READ ARTICLE NOW
Abstract kaleidoscope of AI generated shapes
by Tom Burton 10 September 2025
This article explores the ‘Third Way’ to AI adoption – a balanced approach that enables innovation, defines success clearly, and scales AI responsibly for lasting impact | READ FULL ARTICLE
A Data centre in a field
by Stuart Curzon 22 August 2025
Discover how Deep Green, a pioneer in decarbonised data centres, partnered with Cambridge Management Consulting to expand its market presence through an innovative, sustainability‑driven go‑to‑market strategy | READ CASE STUDY
Crystal ball on  a neon floor
by Jason Jennings 21 August 2025
Discover how digital twins are revolutionising project management. This article explores how virtual replicas of physical systems are helping businesses to simulate outcomes, de-risk investments and enhance decision-making.
A vivid photo of the skyline of Stanley on the Falkland Islands
by Cambridge Management Consulting 20 August 2025
Cambridge Management Consulting (Cambridge MC) and Falklands IT (FIT) have donatede £3,000 to the Hermes/Viraat Heritage Trust to support the learning and development of young children in the Falkland Islands.
A modern office building on a wireframe floor with lava raining from the sky in the background
by Tom Burton 29 July 2025
What’s your organisation’s type when it comes to cyber security? Is everything justified by the business risks, or are you hoping for the best? Over the decades, I have found that no two businesses or organisations have taken the same approach to cybersecurity. This is neither a criticism nor a surprise. No two businesses are the same, so why would their approach to digital risk be? However, I have found that there are some trends or clusters. In this article, I’ve distilled those observations, my understanding of the forces that drive each approach, and some indicators that may help you recognise it. I have also suggested potential advantages and disadvantages. Ad Hoc Let’s start with the ad hoc approach, where the organisation does what it thinks needs to be done, but without any clear rationale to determine “How much is enough?” The Bucket of Sand Approach At the extreme end of the spectrum is the 'Bucket of Sand' option which is characterised by the belief that 'It will never happen to us'. Your organisation may feel that it is too small to be worth attacking or has nothing of any real value. However, if an organisation has nothing of value, one wonders what purpose it serves. At the very least, it is likely to have money. But it is rare now that an organisation will not hold data and information worth stealing. Whether this data is its own or belongs to a third party, it will be a target. I’ve also come across businesses that hold a rather more fatalistic perspective. Most of us are aware of the regular reports of nation-state attacks that are attempting to steal intellectual property, causing economic damage, or just simply stealing money. Recognising that you might face the full force of a cyber-capable foreign state is undoubtedly daunting and may encourage the view that 'We’re all doomed regardless'. If a cyber-capable nation-state is determined to have a go at you, the odds are not great, and countering it will require eye-watering investments in protection, detection and response. But the fact is that they are rare events, even if they receive disproportionate amounts of media coverage. The majority of threats that most organisations face are not national state actors. They are petty criminals, organised criminal bodies, opportunistic amateur hackers or other lower-level actors. And they will follow the path of least resistance. So, while you can’t eliminate the risk, you can reduce it by applying good security and making yourself a more challenging target than the competition. Following Best Practice Thankfully, these 'Bucket of Sand' adopters are less common than ten or fifteen years ago. Most in the Ad Hoc zone will do some things but without clear logic or rationale to justify why they are doing X rather than Y. They may follow the latest industry trends and implement a new shiny technology (because doing the business change bit is hard and unpopular). This type of organisation will frequently operate security on a feast or famine basis, deferring investments to next year when there is something more interesting to prioritise, because without business strategy guiding security it will be hard to justify. And 'next year' frequently remains next year on an ongoing basis. At the more advanced end of the Ad Hoc zone, you will find those organisations that choose a framework and aim to achieve a specific benchmark of Security Maturity. This approach ensures that capabilities are balanced and encourages progressive improvement. However, 'How much is enough?' remains unanswered; hence, the security budget will frequently struggle for airtime when budgets are challenged. It may also encourage a one-size-fits-all approach rather than prioritising the assets at greatest risk, which would cause the most significant damage if compromised. Regulatory-Led The Regulatory-Led organisation is the one I’ve come across most frequently. A market regulator, such as the FCA in the UK, may set regulations. Or the regulator may be market agnostic but have responsibility for a particular type of data, such as the Information Commissioner’s Office’s interest in personal data privacy. If regulatory compliance questions dominate most senior conversations about cyber security, the organisation is probably in this zone. Frequently, this issue of compliance is not a trivial challenge. Most regulations don’t tend to be detailed recipes to follow. Instead, they outline the broad expectations or the principles to be applied. There will frequently be a tapestry of regulations that need to be met rather than a single target to aim for. Businesses operating in multiple countries will likely have different regulations across those regions. Even within one country, there may be market-specific and data-specific regulations that both need to be applied. This tapestry is growing year after year as jurisdictions apply additional regulations to better protect their citizens and economies in the face of proliferating and intensifying threats. In the last year alone, EU countries have had to implement both the Digital Operational Resilience Act (DORA) and Network and Infrastructure Security Directive (NIS2) , which regulate financial services businesses and critical infrastructure providers respectively. Superficially, it appears sensible and straightforward, but in execution the complexities and limitations become clear. Some of the nuances include: Not Everything Is Regulated The absence of regulation doesn’t mean there is no risk. It just means that the powers that be are not overly concerned. Your business will still be exposed to risk, but the regulators or government may be untroubled by it. Regulations Move Slowly Cyber threats are constantly changing and evolving. As organisations improve their defences, the opposition changes their tactics and tools to ensure their attacks can continue to be effective. In response, organisations need to adjust and enhance their defences to stay ahead. Regulations do not respond at this pace. So, relying on regulatory compliance risks preparing to 'Fight the last war'. The Tapestry Becomes Increasingly Unwieldy It may initially appear simple. You review the limited regulations for a single region, take your direction, and apply controls that will make you compliant. Then, you expand into a new region. And later, one of your existing jurisdictions introduces an additional set of regulations that apply to you. Before you know it, you must first normalise and consolidate the requirements from a litany of different sets of rules, each with its own structure, before you can update your security/compliance strategy. Most Regulations Talk about Appropriateness As mentioned before, regulations rarely provide a recipe to follow. They talk about applying appropriate controls in a particular context. The business still needs to decide what is appropriate. And if there is a breach or a pre-emptive audit, the business will need to justify that decision. The most rational justification will be based on an asset’s sensitivity and the threats it is exposed to — ergo, a risk-based rather than a compliance-based argument. Opportunity-Led Many businesses don’t exist in heavily regulated industries but may wish to trade in markets or with customers with certain expectations about their suppliers’ security and resilience. These present barriers to entry, but if overcome, they also offer obstacles to competition. The expectations may be well defined for a specific customer, such as DEF STAN 05-138 , which details the standards that the UK Ministry of Defence expects its suppliers to meet according to a project’s risk profile. Sometimes, an entire market will set the entry rules. The UK Government has set Cyber Essentials as the minimum standard to be eligible to compete for government contracts. The US has published NIST 800-171 to detail what government suppliers must meet to process Controlled Unclassified Information (CUI). Businesses should conduct due diligence on their suppliers, particularly when they provide technology, interface with their systems or process their data. Regulations, such as NIS2, are increasingly demanding this level of Third Party Risk Management because of the number of breaches and compromises originating from the supply chain. Businesses may detail a certain level of certification that they consider adequate, such as ISO 27001 or a System & Organization Controls (SOC) report. By achieving one or more of these standards, new markets may open up to a business. Good security becomes a growth enabler. But just like with regulations, if the security strategy starts with one of these standards, it can rapidly become unwieldy as a patchwork quilt of different entry requirements builds up for other markets. Risk-Led The final zone is where actions are defined by the risk the business is exposed to. Being led by risk in this way should be natural and intuitive. Most of us might secure our garden shed with a simple padlock but would have several more secure locks on the doors to our house. We would probably also have locks on the windows and may add CCTV cameras and a burglar alarm if we were sufficiently concerned about the threats in our area. We may even install a secure safe inside the house if we have some particularly valuable possessions. These decisions and the application of defences are all informed by our understanding of the risks to which different groups of assets are exposed. The security decisions you make at home are relatively trivial compared to the complexity most businesses face with digital risk. Over the decades, technology infrastructures have grown, often becoming a sprawling landscape where the boundaries between one system and another are hard to determine. In the face of this complexity, many organisations talk about being risk-led but, in reality, operate in one of the other zones. There is no reason why an organisation can’t progressively transform from an Ad Hoc, Regulatory-Led or Opportunity-Led posture into a Risk-Led one. This transformation may need to include a strategy to enhance segmentation and reduce the sprawling landscape described above. Risk-Led also doesn’t mean applying decentralised, bespoke controls on a system-by-system basis. The risk may be assessed against the asset or a category of assets, but most organisations usually have a framework of standard controls and policies to apply or choose from. The test to tell whether an organisation genuinely operates in the Risk-Led zone is whether they have a well-defined Risk Appetite. This policy is more than just the one-liner stating that they have a very low appetite for risk. It should typically be broken down into different categories of risk or asset types; for instance, it might detail the different appetites for personal data risk compared to corporate intellectual property marked as 'In Strict Confidence'. Each category should clarify the tolerance, the circumstances under which risk will be accepted, and who is authorised to sign off. I’ve seen some exceptionally well-drafted risk appetite policies that provide clear direction. Once in place, any risk review can easily understand the boundaries within which they can operate and determine whether the controls for a particular context are adequate. I’ve also seen many that are so loose as to be unactionable or, on as many occasions, have not been able to find a risk appetite defined at all. In these situations, there is no clear way of determining 'How much security is enough'. Organisations operating in this zone will frequently still have to meet regulatory requirements and individual customer or market expectations. However, this regulatory or commercial risk assessment can take the existing strategy as the starting point and review the relevant controls for compliance. That may prompt an adjustment to security in certain places. But when challenged, you can defend your strategy because you can trace decisions back to the negative outcomes you are attempting to prevent — and this intent is in everyone’s common interest. Conclusions Which zone does your business occupy? It may exist in more than one — for instance, mainly aiming for a specific security maturity in the Ad Hoc zone but reinforced for a particular customer. But which is the dominant zone that drives plans and behaviour? And why is that? It may be the right place for today, but is it the best approach for the future? Apart from the 'Bucket of Sand' approach, each has pros and cons. I’ve sought to stay balanced in how I’ve described them. However, the most sustainable approach is one driven by business risk, with controls that mitigate those risks to a defined appetite. Regulatory compliance will probably constitute some of those risks, and when controls are reviewed against the regulatory requirements, there may be a need to reinforce them. Also, some customers may have specific standards to meet in a particular context. However, the starting point will be the security you believe the business needs and can justify before reviewing it through a regulatory or market lens. If you want to discuss how you can improve your security, reduce your digital risk, and face the future with confidence, get in touch with Tom Burton, Senior Partner - Cyber Security, using the below form.
AI co-pilot
by Jason Jennings 28 July 2025
Jason Jennings | Elevate your project management with AI. This guide for senior leaders explains how AI tools can enhance project performance through predictive foresight, cognitive collaboration, and portfolio intelligence. Unlock the potential of AI in your organisation and avoid the common pitfalls.
SHOW MORE

Featured Case Studies


Abstract neon arc and a curving seam of light - purple and blue
by Simon Brueckheimer 10 January 2025
It is no exaggeration that telecommunications operators worldwide retain an abundance of ‘legacy’ networks: those using decades-old technologies for which support and maintenance contracts, software updates and hardware parts have already ceased to be available. Legacy networks become increasingly expensive to maintain as they age: a dwindling source of parts requires pricey refurbishment of the old, a situation exacerbated by accelerating failure rates causing network and service outages, and even liquidated damages to be paid. These networks should have been retired long ago. However, that they still garner significant revenue, directly and indirectly from the millions of services and other networks they transport – business voice, data, mobile access and core, emergency services, control and signalling – such that continuing worth demands some sort of technology transformation. After all, proprietary and dated tools, and manual processes associated with them, can be transformed alongside, to technologies such as Software-Defined Networking (SDN) and virtualised networks that are highly automated. So, what stands in the way of that transformation? The cost of maintaining the legacy network should outweigh the cost of transforming them, but it is not that straightforward unfortunately. Cost, risk and feasibility prove to be a very complex and circular interaction, and that is what has held back such investment, even by the most resourceful of operators. 3 Problems Three factors dominate their dilemma: Employees familiar with legacy technologies and their arcane proprietary management tools, are a diminishing proportion of the workforce. As they retire year on year, that undermines confidence, to the extent that the problem is thought best left alone Service and billing records and the actual network configuration - the so-called back-office - is data generally only in partial agreement with each other, incomplete, and not always an accurate reflection of reality. Sometimes this data is not available – older nodes can fail management communications – or are in difficult-to-consume formats. Without a reconciled and complete view, no one really knows if transformation is feasible, let alone how to conduct it reliably. Selecting the starting point is critical to success, but even with a clear big-picture strategy, so many detailed considerations and constraints contrive to make this far from obvious. Evaluating many, occasionally opposing, tactics and a myriad of interplays (customer, control, in-building services, physical distributions and virtual protections), must be confected – almost magically – into an effort, spend and recovery efficient roll-out that also mitigates all risks. The Challenge A large NA telecom local and long-distance operator had an established business case and strategy for transformation, but no longer had a planning team with the modelling capability to do so. Their scheduled goal was behind by years, so they sought to source an outside ‘Planning Tool and Service’ and select parts of their network to which it should be applied to meet their priorities. LightRiver, a well-established services supplier with advanced monitoring and management tools already deployed in their network, were awarded the contract. “Despite our accurate inventory of circuits and assets, we needed a partner that could process tens of millions of lines of data, and build a system to manipulate, sequence, and display the data in a way that was consumable and actionable. Cambridge MC was the perfect partner for us. Their tools and dashboards allow us to change the project sequence depending on the customer’s specific needs in each different area of the network.” – Matt Briley, SVP Global Sales & Solutions, LightRiver The Approach Our first step was to dispense with the original piecemeal focus on parts of the network, and analyse the whole: big data for deep insights. That revealed ‘simple’ transformations: those without ramifications for other regions, services or networks, and thereby avoid creating a large backlog of implementation work. That simplicity had to be quantified, to be credible and satisfy the operator’s priorities. We invented a novel ranked evaluation methodology to combine circa 25 complex and often diametrically opposing metrics. This yielded stepwise transformations that were well (but not critically) sequenced, such that dismantling the network became progressively simpler. Our Data Science and ML were also used to combine back-office records with actual network configuration data from LightRiver’s netFlex platform, reconciling information and filling in blanks, to provide for the first time an accurate and complete view to direct implementation and mitigate risks. Our automated ‘planning’ process could be conducted in whatever scope, scale and sequence of priorities the operator needed. Outcomes The plans produced enabled the operator to: Discover empty resources that could be powered down without any procurement. Determine the value of recoverable parts, that turned out 5x greater than anticipated, including previously untrackable inventory. Determine opportunity clusters like whole-site transformations, avoiding repeat site visits boosting field engineering efficiency. Recover their schedule to the extent that legacy products earmarked for 2025 could be conducted in 2024.
Aerial shot over London and the River Thames
by Pete Nisbet 27 November 2024
Thames Freeport is a unique initiative designed to stimulate trade and innovation and transform the lives of people in its region, leveraging global connectivity to over 130 ports in 65 countries. Occupying a strategic position with intermodal capabilities across river, rail, and road, Thames Freeport has recognised its opportunity to achieve social good, and has demonstrated an active commitment to advancing decarbonisation and fostering a circular economy. Thames Freeport is emerging as a hub for clean energy technologies, advanced logistics, and value-added manufacturing. Special Economic Zones (SEZs) such as the Thames Freeport are uniquely positioned to drive decarbonisation. By clustering industries and research institutions, SEZs enable collaboration on sustainable practices and green technology development. This concentration accelerates the adoption of renewable energy sources, smart grids, and circular economy practices. 
by Pete Nisbet 7 November 2024
edenseven Designs Energy Supply Strategy for H2 Green By conducting an energy sourcing review and engaging with suppliers H2 Green are a large-scale hydrogen storage business with a focus onsite close to towns and cities across the UK. H2 Green’s ambition is to build hydrogen hubs that deliver large amounts of hydrogen, providing security of supply for multiple users across whole regions. H2 Green engaged edenseven, one of the Cambridge Management Consulting group of companies, to build an electricity supply strategy to meet their growth aspirations and environmental requirements. Project Overview To provide a clear outline of the contracting structures within the UK electricity market which would support the green credentials of the business. Structures needed to range from REGO back supply contracts to more complex long-term renewables agreements. All contracting requirements needed to meet the ‘Renewables Transport Fuel Obligations’ and ‘Low Carbon Hydrogen Standard’. Investigate the commercial opportunities short short-term flexibility of assets and liaise with the supply commodity on product development. Support in consultations to government departments relating to the proposed price support mechanism. Skills & Knowledge An energy expert with a detailed knowledge of the UK energy market, with a specific understanding of the evolving policy landscape and how green hydrogen fits into the government’s forward plans. An insight into global commodity markets and the various contracting structures currently in place across the supply community. A clear understanding of how assets can be utilised in the short-term trading markets and the value of ‘optionality’. An individual who holds key relationships across the supply community to enable product development and the ability to influence existing standardised offerings. Outcome & Results Market Analysis : The delivery of a clear and concise view of all the contracting structures currently being provided with the UK electricity market; this included both physical and financial products. Engagement with Government Bodies : A well-considered submission to the relevant government bodies in response to a published consultation. This outlined the appropriate pricing and support structure needed to accelerate the Green Hydrogen Industry. Supplier and Investor Relationships : The creation of a strong link to key suppliers and investors within the energy market. Promoting the development of Green Hydrogen and the benefits it can bring to global decarbonisation.
by Cees Van Der Vlugt 4 October 2024
Cambridge MC engaged with a historic and world-famous university to support the reinvigoration of their Human Resource functions. Specifically, we were asked to improve HR service delivery, and establish the first steps towards change readiness preparation to support the HR function during a college-wide Enterprise Resource Planning (ERP) Project. To achieve these outcomes, we conducted a 3-dimensional process review model to assess their current HR operations. Within this, we evaluated and understood the university's HR department through multiple data streams, using the information collected to identify current quick wins and present recommendations going forward. Strategy Cambridge MC used a unique ‘3-dimensional process view model’ to evaluate the efficacy of the processes, people, and systems that formed the HR department at the outset of the project. These three dimensions include: A Maturity Assessment and identification of any Quick Wins to restore. confidence in HR delivery. A Process Map Review against future Employee Life Cycle, using our own ‘Employee Life Cycle Model’, and 40k Service Tickets to improve automation and efficiency. The development of an implementation plan and blueprint for the successful roll-out of HR ERP. Data Streams & Findings The HR Maturity Assessment highlighted strong management support experienced by participants, as well as a solid understanding of HR strategy and of overall University strategy. The HR Process & Programmes Review uncovered that 196 processes in Nimbus (an end-to-end patented cloud WorkForce Optimisation application) are not linked to the HR Sub Functions; the current SLAs are based on historical volume and thus are not fit for an SSO environment; and current expertise in the Hub is not sufficient to deal with the volume of service tickets. Five quick wins were identified as follows: Recruitment Fixed Term Contracts Review Current SLAs Re-Routing Payroll and Pension Queries One single mailbox for sending Service Tickets In the detailing phase, we implemented the aforementioned agreed quick wins, the blueprint for HR ERP, assured the build readiness of the HR team, and built the HR SSO to accommodate HR ERP. Finally, in the communications stage, we developed a Communications Grid for HR Maturity assessment, established Cambridge MC presence in the process, and implemented . Outcomes & Results  1. Cost Savings We identified quick wins that led to an annual saving of £500k, by tightening the relation and process flow between HR and payroll. 2. Systems Optimisation We analysed the efficacy of HR Service Tickets solutions delivery and recommended different workflows for the 1.8k tickets received per month. 3. Forward Planning Our ‘Employee Life Cycle Model’ was instrumental in analysing the gap between current and future HR process and systems needed in an ERP environment.
by Mauro Mortali 10 September 2024
Staying ahead of the curve in a fierce market Our client, a renowned global services provider, approached Cambridge Management Consulting (Cambridge MC) with a critical mission: to benchmark their data connectivity services against industry best practices, identify growth opportunities, and develop an innovative growth strategy. Their objective was to stay ahead of the curve in a rapidly evolving market and solidify their position as a leader in data connectivity solutions globally. The Challenge The client faced significant challenges: Decline in Traditional Voice Services: As the market shifted towards IP-based solutions, traditional voice services were becoming less profitable. Revenue vs. Margin Dilemma: Although data connectivity services were growing in revenue, they yielded lower margins compared to voice services. This trend was impacting overall profitability negatively. Future-readiness of Existing Offerings: The client's current portfolio, while performing adequately, required evaluation to ensure alignment with modern standards and preparedness for future market demands. The client sought actionable insights to enhance their portfolio and capitalise on emerging market opportunities. Cambridge MC was tasked with: Diagnosing the data connectivity services business to benchmark against industry best practices Identifying and prioritising growth opportunities Developing a comprehensive growth strategy aimed at achieving revenue and margin targets Building a set of initiatives with detailed programs and supporting action plans to deliver the growth strategy Our Approach - Diagnostic Phase In the diagnostic phase, Cambridge MC applied its comprehensive Diagnostic Framework to assess the client's organisation across several key parameters: Portfolio Analysis: Evaluating the range and performance of existing products and services Go-to-Market Strategy: Reviewing current market entry strategies and sales approaches Systems & Processes: Assessing internal systems for efficiency and scalability Network Technologies: Analysing the technological infrastructure supporting data connectivity services Product Margins: Examining financial performance metrics for each product line. This involved: Conducting in-depth interviews with key team members Reviewing essential documentation, strategic plans, market reports, and financial statements Performing detailed market, customer, and competitor analysis Utilising Cambridge Subject Matter Experts (SMEs) to benchmark the client against industry Best-in-Class standards Our Approach - Growth Opportunity Phase In this phase, Cambridge MC facilitated: Co-Creation Workshops: Collaborative sessions with the client team to identify and prioritise potential growth opportunities Stress Testing: Rigorous financial analysis involving SMEs and customer feedback to validate identified opportunities Initiative Scoping: Detailed workshops to scope out, quantify, and agree on key initiatives necessary for realising growth opportunities. The culmination of this phase was the development of an agreed-upon growth strategy underpinned by robust financial projections and a detailed delivery plan. Outcomes & Results Through this structured approach, Cambridge MC successfully identified several key improvement areas resulting in: 1. Gross Margin A project ed 66% increase in gross margin. 2. Recurring Revenue An incremental annual recurring revenue of $90 million by year five. These results provided the client with a clear roadmap for enhanced profitability and sustained competitive advantage in the dynamic data connectivity market. 
by Pete Nisbet 23 July 2024
edenseven Helps ISS to Decarbonise their Operations By conducting a review of their market and target audience to align their organisation with their sustainability goals. ISS is a leading workplace experience and facility management (FM) company which provides placemaking solutions that contribute to better business performance and make working life easier, more productive, and more enjoyable. With a significant presence in the build environment, ISS has a clear focus on delivering sustainable services to their customer base, helping them to achieve their net zero ambitions. edenseven , one of the Cambridge Management Consulting group of companies, were commissioned to review ISS’ current sustainability market offering, and, through an engagement programme, make sure that it was aligned to the requirements of their customers’ long-term sustainability ambitions. Project Overview To review the current market relating to sustainability services within the sector and outline the different types of structures and products being offered. Assess the current product and service positioning of ISS and review how they are being presented and articulated to the internal delivery teams and customer base. Create a clear and concise value proposition which outlines ISS’ breadth of services, and which can be communicated to customers by a broad cross section of the ISS team. Through a customer engagement programme, test the value proposition with a set of key accounts and record areas where refinement would be needed to align it to their requirements. Present findings to the ISS UK board and provide clear feedback and next steps. Skills & Knowledge Data Analysis: A broad knowledge of both the FM and sustainability sectors, and an ability to articulate findings from market research and stakeholder/customer interactions in an effective manner. Report Generation: Create documentation and reports which deliver complex requests and findings in a concise and clear manner to senior stakeholders and customers. Stakeholder and Customer Engagement: Build a continuous feedback loop to senior stakeholders within ISS and across key customer accounts. edenseven captured and reviewed customer needs and service requirements to produce effective and timely decision making. Outcome & Results Market Awareness: A clear understanding of market trends and contractive characteristics relating to sustainability services in the FM sector. Organisational Clarity: An outline of current services and how they are delivered through the sales process. Value Proposition: A clear and relatable value proposition which captures all services in a format which can be delivered by a broad cross-section of the ISS workforce. Forward Planning: A board-level presentation and report outlining key findings and next steps to deliver existing and new services which are focussed on meeting key customer requirements.
Aerial view of the beach.
by Aki Uljas 22 July 2024
Replacing microwave connectivity with fibre optic links to provide reliable internet during adverse weather as well as laying the foundations for a digital future In April 2023, the Turks and Caicos Telecommunications Commission (TCITC) completed a Request for Proposals for a study on the feasibility of a domestic submarine telecommunications cable system for the Turks & Caicos Islands (TCI). Originating from a 2016 Turks and Caicos Islands Government mandate to enhance inter-island communication, the initiative aimed to establish a national fibre ring, ensuring robust connectivity—especially during natural disasters—as well as facilitating a secondary international broadband link. In 2023, Cambridge Management Consulting Limited was awarded a contract to prepare the final Strategic Outline Business Case (SOBC), involving consultations and with local stakeholders. The Challenge T he primary objectives of the project include replacing the current microwave links with high-capacity fibre optic cables, ensuring resilient connectivity in adverse weather, offering low latency digital access to underserved TCI communities, and laying the groundwork for further digital investments. Subsea cables, being the internet's backbone, are crucial for island nations, offering superior capacity and latency compared to alternatives like satellite or microwave connections. High-speed internet is crucially important to economic growth across the islands. Tourism and local businesses require reliable and fast service to meet the growing needs of users. Hospitals, ports, and emergency services will also benefit greatly from new digital services—for example, 20% of patients in TCI already use remote doctor appointments. Our Approach The project started by analysing the telecommunications market in the Turks and Caicos Islands. As with many of the other Caribbean Islands, the market data is not readily available. Market information was gathered from a wide range of sources, including official statistics, third-party databases, market data sources, and by conducting meetings with the local stakeholders, including cruise lines, telecom operators and others. Our legal partner in the project, Baker Botts, also conducted a legal review of the regulatory framework, procurement framework, and government financing framework. Ensuring open access to the new subsea cable system and related facilities was emphasised in carrying out this legal review and recommendations from that review. Our technical partner in the project, Pelagian, conducted a desktop study, which is always the basis of any subsea cable system, assessing cable landings, environmental aspects, developing a cable route that would be used to perform marine survey activities and further into the project, the cable installation. This was done by following recommendations from the International Cable Protection Committee to ensure the quality of the study. After the reviews and studies, we created a financial plan for the cable system, including estimated investments, profit and loss calculations, cashflow analysis, and balance sheets. This was followed by writing a Strategic Outline Business Case report, which was based on the UK Government’s Green Book guidelines. The Team Our Senior Partner for Subsea, Aki Uljas, led our contribution to the project, providing his subsea expertise and understanding of government-led projects, based on his previous work—including work with the Finnish Government-owned company Cinia, which he has been advising for the Baltic Sea and Arctic cable projects. Julian Rawle has two decades of experience in the subsea and telecommunications industry, specialising in market analysis, market forecasts and due diligence work. The Cambridge MC team worked alongside the Turks & Caicos Islands Telecommunications Commission (TCITC), specifically with Kenva Williams, Director General, to ensure an effective outcome that benefits all TCI citizens. Outcomes & Results After we completed the Strategic Outline Business Case report, we presented it to the Turks and Caicos Islands Cabinet and the UK Governor of the Turks and Caicos Islands. 1. Strategic Outline Business Report The Strategic Outline Business Case report was delivered in Autumn 2023. Cambridge MC presented the business case to the Cabinet in December 2023, after which the Cabinet approved the project to move forward. 2. Procurement Package Cambridge MC and Pelagian started to work on the Procurement Package and the upcoming tender process in April 2024, after budget allocation for the project was completed. 3. Cable System Extensions We also identified a few possible new international cable systems passing close to the Turks and Caicos Islands, which could have the potential to be extended into the islands: Several potential planned cable systems were identified Cambridge MC reached out to these parties and facilitated discussion and negotiations on behalf of the Turks and Caicos Telecommunications Commission Cambridge MC revised the Strategic Outline Business Case to also include these potential new cable systems to be connected to the islands. 
Satellite going into the sky.
by Steve Tunnicliffe 28 June 2024
Analysing the business to provide recommendations and enhancements The satellite industry is going through an intense period of transformation at every level of the value chain. The status quo within the satellite communications industry has been largely unchanged and unchallenged since its inception over 60 years ago. This is all about to significantly change, and it will force many established businesses to look afresh at how they operate. Many will adapt but many will fail. The two key factors driving this transformation are a) the emergence of Non-Geostationary Satellite Operators (NGSO) and b) the technology drive to digitisation, standardisation, and virtualisation. New market entrants such as Starlink are hugely disruptive and have contributed to a 77% reduction in satellite capacity pricing over the last 5 years. Other new entrants will soon emerge, creating further disruption to the norm and downward price pressure. The Challenge A leading satellite communications service provider had already anticipated this market shift and transformation, but wanted to undertake a brief study to validate their assumptions and to review their Go-To-Market strategy. Spanning operations in the US and Europe, Steve Tunnicliffe was tasked with undertaking this strategic business review that included: Stakeholder Mapping and Engagement Corporate Governance Review Change Management and Communication Revenue Review Performance Management Review Our Approach Steve provided critical insights and enabling methodologies to support the service provider in anticipating where to invest next and what resources to align where. Steve also identified areas of weakness within the company’s corporate governance and identified where changes needed to be made to ensure the service provider seized the opportunity for its next phase of growth. He was able to engage key stakeholders in the identification of business issues and make recommendations on how and what to implement from a change management perspective. His experience in leading a global sales organisation and strategy for a leading player within the satellite industry helped provide critical insights to empower the service provider to achieve its stated objectives. Out comes & Results 1. Go-to-Market Strategy The client refocused its efforts on Defence and Government, which accounted for over 50% of its business but an event greater percentage of its profit. 2. Corporate Governance The client put in place a charter and clear definitions around the role of the Board of Directors and the Executive Management Team defining what matters were reserved for each. 3. Efficiency All of this provided not only the necessary clarity but an efficient plan to implement.
SEE MORE CASE STUDIES