Cybersecurity in the Racing & Leisure Industry: Why You Need a Co-Driver, Not Just Another Supplier

For organisations operating in the racing and leisure industry, cybersecurity isn’t simply about protecting servers and endpoints.

Racecourses, hotels and event venues bring together a complex combination of technology, people, suppliers and customer-facing services. Ticketing systems, CCTV, gaming networks, radio communications, public Wi-Fi and corporate systems all need to work together — often while thousands of visitors are on site.

And when race day arrives, there is very little room for disruption.

This was the reality for one UK-based organisation operating prestigious racecourse venues alongside a hotel, bars and event facilities. With a small internal IT team and a diverse technology environment, the organisation recognised that it needed to strengthen its cybersecurity — but without creating unnecessary complexity or disrupting its operations.

The solution wasn’t simply another security product.

It was a cybersecurity co-driver.

The challenge: security needs to fit the business

Around three years ago, the organisation recognised that its cybersecurity strategy needed to evolve.

Its IT team was managing an increasingly complex environment, while specialist cybersecurity expertise was limited. There was also growing pressure from the board to better understand and demonstrate how cyber risk was being managed.

A comprehensive security review in 2022 provided a clearer picture.

While existing anti-malware and filtering controls were providing effective protection, the review identified several areas requiring improvement:

  • Limited network segregation
  • Gaps in authentication services
  • No formal cyber awareness training
  • Underutilised security technologies
  • Limited visibility of emerging threats
  • A lack of long-term cybersecurity planning

The organisation effectively had many of the building blocks in place — but needed help bringing them together into a more structured and proactive approach.

This is where the partnership with ANSecurity began.

The solution: a co-driver, not another supplier

The organisation chose ANSecurity because it wanted more than a traditional supplier relationship.

It needed specialist expertise that could work alongside its existing IT team, understand its operational environment and provide an independent perspective on where improvements should be made.

Our Co-Driver approach was designed around exactly that.

Rather than simply recommending products, ANSecurity worked alongside the team to understand the environment, identify priorities, challenge existing thinking and create a practical roadmap for improvement.

The approach was also flexible enough to accommodate the organisation’s seasonal operations.

Security improvements couldn’t simply be scheduled whenever convenient. Race days, events and peak visitor periods had to be considered.

The objective was therefore to improve security without getting in the way of the business.

1. Make better use of what you already have

One of the first principles of the engagement was that cybersecurity improvement doesn’t always mean buying more technology.

The organisation already had a number of security tools in place, including an anti-malware platform, network firewalls and inventory technology.

Rather than immediately replacing these technologies, ANSecurity looked at what capabilities were already available but underutilised.

By enabling additional licensed functionality within existing technologies, the organisation was able to increase its security capabilities and improve the return on its existing investment.

The lesson: before buying another security product, understand what your existing technology can actually do.

2. Build stronger foundations

The security review highlighted areas where the organisation’s underlying architecture needed to become more resilient.

ANSecurity supported improvements across several areas, including:

Stronger authentication

Authentication controls were strengthened beyond the capabilities of the legacy MFA approach, including the implementation of security keys.

Network segregation

The network was redesigned to make better use of existing segmentation, while introducing stricter traffic controls and inspection.

This helped establish clearer boundaries between different areas of the environment and reduce unnecessary exposure.

Cyber awareness

Technology is only one part of the security equation.

Cyber awareness training was introduced to strengthen the human layer of defence and give employees a better understanding of the threats they could encounter.

3. Test whether your security actually works

Having security controls in place doesn’t necessarily mean they will work when you need them.

That’s why the engagement also introduced mini threat emulation exercises.

These exercises were designed to simulate realistic attack techniques and assess how effectively the organisation and its third-party Managed Detection and Response provider could identify, alert on and respond to suspicious activity.

The exercises helped answer practical questions:

Would we detect this attack?

Would we know what was happening?

Could we respond quickly enough?

Using the MITRE ATT&CK framework provided a structured way to measure progress.

The organisation moved from having limited ability to detect and prevent specific techniques and procedures towards a more mature capability covering detection, prevention, alerting and response.

4. Turn cybersecurity into a board-level conversation

For many organisations, one of the biggest cybersecurity challenges isn’t identifying technical vulnerabilities.

It’s communicating what those vulnerabilities actually mean to the business.

As part of the engagement, ANSecurity helped improve cybersecurity reporting through clearer KPIs and visual reporting.

This gave leadership greater visibility of:

  • Current cyber risks
  • Progress against security objectives
  • Areas requiring further investment
  • Improvements in detection and response
  • The organisation’s overall security maturity

As a result, cybersecurity conversations increasingly reached board level.

This represented an important shift: cybersecurity was no longer simply an IT issue. It was becoming part of the organisation’s wider approach to business risk.

5. Build capability within the team

A Co-Driver relationship shouldn’t create dependency.

The aim is to make the internal team stronger.

Throughout the engagement, ANSecurity worked closely with the client’s IT team through a combination of on-site and remote sessions.

Each engagement could include recommendations and practical actions for the team to take forward — creating an ongoing cycle of improvement and knowledge transfer.

This gave the team:

A clearer roadmap
A structured view of what needed to happen next.

Greater confidence
Improved knowledge and understanding of cybersecurity risks.

Access to specialist expertise
Additional support when internal resources or specialist knowledge were limited.

An independent challenge function
Someone willing to question existing approaches and provide an external perspective.

As Fred, IT Manager, explains:

“It’s been very valuable to have James involved — he’s professional, engaging, and challenges us in the right way. He’s flexible, but firm, and understands the operational realities we face.”

The result: stronger security without disrupting the business

The partnership has helped the organisation make measurable progress in its cybersecurity maturity while continuing to operate within the realities of a busy racing and leisure environment.

The results included:

  • Significant improvement in MITRE ATT&CK coverage
  • Enhanced incident response readiness
  • Greater visibility of cyber risk
  • Clearer executive reporting and KPIs
  • Better utilisation of existing security technologies
  • Stronger authentication controls
  • Improved employee security awareness
  • Continued progress towards Cyber Essentials and Cyber Essentials Plus
  • A clearer roadmap for continuous improvement
  • No disruption to critical systems during race days

Most importantly, the organisation now has a more proactive approach to cybersecurity — with the internal team better equipped to understand, manage and continually improve its security posture.

The bigger lesson: cybersecurity should work around your business

The experience of this racing and leisure organisation demonstrates that effective cybersecurity isn’t necessarily about having the biggest technology stack.

It’s about having the right strategy, the right expertise and the right approach.

For organisations with complex environments and limited internal resources, a cybersecurity partner can provide something that technology alone cannot:

perspective.

Someone who can look across the environment, identify where the real risks are, challenge assumptions, make better use of existing investments and help the internal team move forward.

That’s the principle behind ANSecurity’s Co-Driver approach.

We don’t aim to take the wheel away from your IT team.

We work alongside them.

Helping them understand their environment, make informed decisions, strengthen their security and build the confidence to keep moving forward.

Read the full case study

Discover how ANSecurity worked with this UK racing and leisure organisation to strengthen its cybersecurity, improve threat detection and response, maximise existing technology investments and build a long-term security roadmap — without disrupting critical race-day operations.

LET’S TALK ABOUT YOUR DATA SECURITY