Companies newly inside the security duty of care
The single largest change in this market for a decade. These companies are in scope by size and sector rather than by designation, which means most of them have not been told, will not search for help, and will only act once someone explains that the rules moved. Unqualified in the usual sense, and reachable only by name.
Who signs: managing director, head of IT, information security officer where one exists, and across most of this group nobody holds the role yet.