For Family Adventures Group, a rapidly growing organisation in the childcare sector, cyber security has been a cornerstone of their success. Led by CEO and co-founder, Tom Filer, the company has tripled in size over the past two years, growing from 150 employees in 2024 to over 400 in 2026. This remarkable growth has been accompanied by a steadfast commitment to cutting-edge technology and robust security practices, including the annual renewal of IASME Cyber Assurance certification. This case study explores how Family Adventures Group has leveraged cyber security as a foundation for growth and innovation.
The importance of cyber security certification renewal
Family Adventures Group’s journey into cyber security began in 2024, spurred by private equity investment. Tom explains, “We were told that once the press release goes out that you’ve got money, you’re going to be targeted.” This warning proved prescient, as the childcare sector faced significant cyber threats, including a high-profile incident involving Kido nursery schools. Recognising the risks, Family Adventures Group went beyond basic compliance, obtaining both Cyber Essentials certification, the government-backed minimum standard and IASME Cyber Assurance certification, a comprehensive, IASME-owned standard that goes beyond cyber security controls to address people, processes and incident response and recovery.
Reflecting on the past two years, Tom acknowledges that their initial focus in 2024 was simply on meeting the required standards. However, over time, the principles of cyber safety and security have become deeply embedded in the company’s culture. “What started as a compliance exercise has evolved into a ‘belts and braces’ approach,” he explains, highlighting how cyber security is now a fundamental part of their day-to-day operations.
Renewing these certifications annually has been central to this transformation. “Our default is always to ensure our systems are secure, even if it means accepting some inconvenience.” This commitment has cultivated a heightened sense of awareness and vigilance among colleagues, reinforced by monthly focus areas and continuous education initiatives.
Tom also emphasises the unique responsibility of operating in the childcare sector. “As a sector, we’re naturally focused on safeguarding children in the traditional, physical sense. But from a cyber perspective, protecting our customers’ information is just as critical to keeping them safe.”
Cyber security as a competitive advantage
Cyber security has also become a competitive advantage for Family Adventures Group. “Having the certifications we do has gone down really well in conversations with parents,” Tom explained. “It’s an added benefit that demonstrates our commitment to safeguarding children and data.”
A foundation for future growth
As Family Adventures Group continues to expand, technology and cyber security remain central to their operations. Outsourcing IT management to cyber security consultancy and Certification Body, Cool Waters has ensured ongoing compliance and monitoring, allowing the company to maintain robust security practices as they scale. By embracing innovative tools and strategies, Family Adventures Group has positioned itself as a forward-thinking leader in the childcare sector. Tom stresses, “In today’s fast-paced business environment, staying ahead means prioritising both security and innovation. If you’re not looking at these areas as a business leader, you risk being left behind.”
About the Certifications:
Cyber Essentials (CE) is an annually renewable, government-backed certification scheme consisting of five controls that will reduce the impact of the most common cyber attacks.
IASME Cyber Assurance (ICA) is a flexible, risk-based standard that provides a roadmap to cyber resilience for every organisation.
Cyber Essentials is an important prerequisite for IASME Cyber Assurance certification and ensures that organisations have got the basics in place. IASME Cyber Assurance focuses on the governance which will helps an organisation prepare, withstand and recover from successful attacks. It will also address other potential disruptions to an organisation’s digital systems, such as systems failure and insider threat, ensuring that critical operations and services can continue with minimal impact.
Cyber Essentials is operated under the oversight of the National Cyber Security Centre (NCSC). The IASME Cyber Assurance (ICA) scheme is independently owned and is not affiliated with the NCSC.
