<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3798604115389836864</id><updated>2026-06-07T10:40:52.288+01:00</updated><category term="data breach"/><category term="Data Protection"/><category term="Patching"/><category term="ransomware"/><category term="cyber security roundup"/><category term="Microsoft"/><category term="Security Awareness"/><category term="Hacking"/><category term="Home Security"/><category term="privacy"/><category term="GDPR"/><category term="PCI DSS"/><category term="NCSC"/><category term="password security"/><category term="Payment Card Fraud"/><category term="malware"/><category term="DPA"/><category term="Encryption"/><category term="nation-state"/><category term="hackers"/><category term="ICO"/><category term="DDoS"/><category term="Cyber Crime"/><category term="adobe"/><category term="COVID-19"/><category term="Cloud Security"/><category term="ID Theft"/><category term="iot"/><category term="Threat"/><category term="web application security"/><category term="phishing"/><category term="Huawei"/><category term="cyber"/><category term="Cyberwar"/><category term="Wifi Security"/><category term="Mobile Security"/><category term="Network Security"/><category term="Social Media"/><category term="facebook"/><category term="CISO"/><category term="Vulnerability Management"/><category term="cybersecurity"/><category term="yahoo"/><category term="talktalk"/><category term="wannacry"/><category term="AI"/><category term="Apple"/><category term="Cisco"/><category term="application security"/><category term="British Airways"/><category term="Fraud"/><category term="ibm"/><category term="Coronavirus"/><category term="RSAC"/><category term="Risk Management"/><category term="cybercrime"/><category term="dark web"/><category term="marriott"/><category term="Third Party Security"/><category term="amazon"/><category term="brexit"/><category term="nhs"/><category term="Policies"/><category term="Snowden"/><category term="Twitter"/><category term="football"/><category term="infographic"/><category term="training"/><category term="BEC"/><category term="Big Data"/><category term="Insider Threat"/><category term="Intel"/><category term="MFA"/><category term="OWASP"/><category term="vpn"/><category term="APT10"/><category term="GCHQ"/><category term="NSA"/><category term="Terrorism"/><category term="anti-virus"/><category term="aws"/><category term="cryptocurrencies"/><category term="cyber risk"/><category term="email security"/><category term="equifax"/><category term="incident management"/><category term="ryuk"/><category term="scam"/><category term="small business"/><category term="supply-chain"/><category term="5G"/><category term="APT28"/><category term="Compliance"/><category term="Cyber Essentials"/><category term="Magecart"/><category term="Manchester City"/><category term="Physical Security"/><category term="VIPRE"/><category term="bitcoin"/><category term="cyber insurance"/><category term="cyber resilience"/><category term="enterprise security"/><category term="podcast"/><category term="solarwinds"/><category term="Apache"/><category term="DLP"/><category term="Emotet"/><category term="Zero Trust"/><category term="botnets"/><category term="data retension"/><category term="digital transformation"/><category term="human error"/><category term="kaspersky"/><category term="mcafee"/><category term="petya"/><category term="A10 Networks"/><category term="APT29"/><category term="BYOD"/><category term="CCTV"/><category term="CISA"/><category term="Car Security"/><category term="Cobalt"/><category term="Conference"/><category term="Conti"/><category term="Control Assurance"/><category term="Cryptojacking"/><category term="DarkSide"/><category term="FCA"/><category term="Google"/><category term="Hack"/><category term="Hacktivism"/><category term="Meltdown"/><category term="Mirai"/><category term="Mitre"/><category term="NIST"/><category term="O365"/><category term="Revil"/><category term="SME"/><category term="Trickbot"/><category term="Uber"/><category term="VMware"/><category term="Windows XP"/><category term="appscan"/><category term="artificial intelligence"/><category term="bluekeep"/><category term="book review"/><category term="carbon black"/><category term="career"/><category term="ceo fraud"/><category term="credential stuffing"/><category term="cybersecurity governance"/><category term="education"/><category term="firewall"/><category term="management"/><category term="misconfiguration"/><category term="operational resilience"/><category term="ring"/><category term="sans"/><category term="solorigate"/><category term="threat hunting"/><category term="travelex"/><category term="zero-day"/><category term="zoom"/><category term="AI Security"/><category term="AI governance"/><category term="Currys"/><category term="DBIR"/><category term="Deep Secure"/><category term="Dixons carphone"/><category term="FBI"/><category term="HR"/><category term="Heartbleed"/><category term="IAM"/><category term="ISO27001"/><category term="InfoSec"/><category term="Maze"/><category term="NIS"/><category term="NIS2"/><category term="PCI"/><category term="PewDiePie"/><category term="RSA"/><category term="SHA-1"/><category term="SOC"/><category term="SaltDNA"/><category term="Sophos"/><category term="Spectre"/><category term="T-Mobile"/><category term="Verizon"/><category term="Windows 7"/><category term="Windows Server 2018"/><category term="access control"/><category term="bakuk"/><category term="becrypt"/><category term="blockchain"/><category term="bsides"/><category term="bt"/><category term="china"/><category term="control effectiveness"/><category term="cyber extortion"/><category term="disaster recovery"/><category term="dixons"/><category term="fireeye"/><category term="iphone"/><category term="labour party"/><category term="lenovo"/><category term="linux"/><category term="logmeonce"/><category term="penetration test"/><category term="piracy"/><category term="pitney bowes"/><category term="sextortion"/><category term="smart cities"/><category term="social engineering"/><category term="starwood"/><category term="sunburst"/><category term="threat intelligence"/><category term="ticketmaster"/><category term="tor"/><category term="whatsapp"/><category term="2018"/><category term="AI agents"/><category term="AI agents risk"/><category term="AI cyber risk"/><category term="AI cybersecurity"/><category term="AMD"/><category term="API security"/><category term="APT1"/><category term="APT27"/><category term="APT3"/><category term="APT37"/><category term="APT38"/><category term="APT39"/><category term="APT40"/><category term="APTC23"/><category term="ATP"/><category term="Accenture"/><category term="Aebi Schmidt"/><category term="Air India"/><category term="Azure"/><category term="Born Digital"/><category term="Business Impact Analysis"/><category term="CCISO"/><category term="CCPA"/><category term="CDE"/><category term="CEH"/><category term="CESG"/><category term="CISM"/><category term="CISO leadership"/><category term="CISSP"/><category term="CREST"/><category term="CVE-2021-3156"/><category term="CVSS"/><category term="CeX"/><category term="Certes Networks"/><category term="Check Point"/><category term="Citrix"/><category term="Coalfire"/><category term="Cognizant"/><category term="CompTIA"/><category term="Crime Dot Com"/><category term="Cyber Bullying"/><category term="Cyber Security Challenge UK"/><category term="Cyber Tec Security"/><category term="DNS Security"/><category term="DataDome"/><category term="Decathlon"/><category term="Defcon"/><category term="DevOps"/><category term="Disaster Recovery as a Service"/><category term="Disney"/><category term="ECSC"/><category term="EU"/><category term="Enterprise Europe Network"/><category term="European Cyber Security Challenge"/><category term="Exchange"/><category term="F5"/><category term="FASTR"/><category term="FFA"/><category term="FIFA"/><category term="FatFace"/><category term="Flightradar"/><category term="Forrester"/><category term="GRC"/><category term="Gaming"/><category term="Giacom"/><category term="Github"/><category term="HCSEC"/><category term="HIPAA"/><category term="HSBC"/><category term="Hafnium"/><category term="IASME"/><category term="IOC"/><category term="ISACA"/><category term="ISC2"/><category term="ISCN"/><category term="Identity Theft"/><category term="Ikea"/><category term="Intelligencia"/><category term="Iran"/><category term="JBS"/><category term="Kia"/><category term="Krack"/><category term="Kraken"/><category term="KwikFit"/><category term="LOC"/><category term="LORCA"/><category term="LinkedIn"/><category term="Liverpool"/><category term="MH370"/><category term="ML"/><category term="MSP"/><category term="MSPs"/><category term="Maersk"/><category term="Memty"/><category term="Mythos AI"/><category term="NASA"/><category term="NCC"/><category term="NCF"/><category term="NCS"/><category term="Netscout"/><category term="Nintendo"/><category term="Nokia"/><category term="Nominet"/><category term="Online Harms Bill"/><category term="Operation Cleaver"/><category term="PC World"/><category term="PoisonTap"/><category term="PokemonGo"/><category term="Ponemon Institute"/><category term="Project Glasswing"/><category term="RAA"/><category term="RFT"/><category term="Recovery Time Objectives"/><category term="Redcar"/><category term="Regenix"/><category term="SD-WAN"/><category term="SIEM"/><category term="SIEM challenges"/><category term="SIGRed"/><category term="SMBs"/><category term="SOAR"/><category term="SOC operations"/><category term="SSL"/><category term="SaaS security"/><category term="SecureTeam"/><category term="Security Today"/><category term="Sentinel"/><category term="Sepa"/><category term="Serco"/><category term="Service Availability"/><category term="Snake"/><category term="Sodinokibi"/><category term="Steganography"/><category term="TA505"/><category term="TGI Friday"/><category term="Tesla"/><category term="The Lazaus Group"/><category term="TikTok"/><category term="Total Fitness"/><category term="UEFA"/><category term="UK"/><category term="Vision Direct"/><category term="Vulnerability scan"/><category term="Windows 10"/><category term="YesWeHack"/><category term="Zerologon"/><category term="adaptive security leadership"/><category term="adware"/><category term="agentic AI"/><category term="att&amp;ck"/><category term="automation risk"/><category term="autonomous AI"/><category term="awards"/><category term="backup"/><category term="beyer"/><category term="biometrics"/><category term="bitdefender"/><category term="bitsight"/><category term="black friday"/><category term="blueborne"/><category term="boothole"/><category term="bugbounty"/><category term="christmas"/><category term="cloud security alliance"/><category term="contactless"/><category term="continuous control monitoring"/><category term="control validation"/><category term="corvid"/><category term="cyber risk management"/><category term="cyberis"/><category term="darkgate"/><category term="data centres"/><category term="data classification"/><category term="data security"/><category term="defender"/><category term="deltacharlie"/><category term="digital certificates"/><category term="dropbox"/><category term="drown"/><category term="e-crime congress"/><category term="easyjet"/><category term="email"/><category term="embroker"/><category term="end point security"/><category term="enterprise AI security"/><category term="eternalblue"/><category term="evidence based assurance"/><category term="evidence freshness"/><category term="expanding threat surface"/><category term="f-secure"/><category term="fedex"/><category term="films"/><category term="finance"/><category term="fintech"/><category term="flashpoint"/><category term="free"/><category term="freelance"/><category term="goldenspy"/><category term="greene king"/><category term="hacker"/><category term="hidden cobra"/><category term="identity and access management"/><category term="identity management"/><category term="ignite"/><category term="iloveyou"/><category term="imperva"/><category term="isame"/><category term="isf"/><category term="legal sector"/><category term="locky"/><category term="lovebug"/><category term="mimecast"/><category term="moneytaker"/><category term="movies"/><category term="mumsnet"/><category term="netflix"/><category term="nordVPN"/><category term="notpetya"/><category term="npower"/><category term="outpost24"/><category term="oyster"/><category term="paradox"/><category term="plundervolt"/><category term="qualys"/><category term="rbs"/><category term="regtech"/><category term="retail"/><category term="second line assurance"/><category term="security monitoring limitations"/><category term="shadow AI"/><category term="shadow IT"/><category term="shlayer"/><category term="smartphone"/><category term="snapchat"/><category term="sonos"/><category term="spotify"/><category term="spyware"/><category term="stuxnet"/><category term="sudo"/><category term="superfish"/><category term="telegram"/><category term="teletext holidays"/><category term="tfl"/><category term="threatQ"/><category term="timehop"/><category term="translation"/><category term="undervolting"/><category term="unix"/><category term="wearables"/><category term="webroot"/><category term="winzip"/><category term="zavvi"/><title type='text'>Cybersecurity Expert | Cyber Resilience</title><subtitle type='html'>UK cybersecurity analysis, operational resilience, control assurance, AI security, and evidence-based governance from experienced practitioners and guest contributors.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default?alt=atom'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default?alt=atom&amp;start-index=26&amp;max-results=25'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>518</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-6729029560316801818</id><published>2026-05-29T19:00:47.719+01:00</published><updated>2026-05-29T19:05:57.688+01:00</updated><title type='text'> AI in the UK: Driving Innovation Without Expanding Cyber Risk</title><content type='html'>&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;i style=&quot;text-align: center;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;Written by&amp;nbsp;Sean Tilley,&amp;nbsp;Senior Sales Director&amp;nbsp;EMEA at&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;a href=&quot;https://1111systems.com/&quot; style=&quot;color: #96607d; text-align: center;&quot; target=&quot;_blank&quot; title=&quot;https://1111systems.com/&quot;&gt;&lt;i&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;11:11 Systems&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;i style=&quot;text-align: center;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;Artificial intelligence is no longer a future ambition for UK organisations. It is already shaping how decisions are made, how services are delivered, and how quickly businesses can respond to change. From automation and analytics to customer engagement and operational optimisation, AI is becoming an integral part of the modern enterprise.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyZI8mQiqYExVQcWSNaskwhg5B4dBIjENQuwngbVgZEn-sZCOtRAOqVELYfspteQ8rHe4247JFbYQfQNZWeQdDNtyVqf4qdaG-NZ37JqgAuHNHvwyQHdqGoh3JZZNYFyVeJK6V_ad3-hT5FxMjXcXf0V4jubxMUjBp8QdkBljlPBlEZ_kmNbdSXwR3ka5i/s1536/ai-governance-cyber-resilience-uk-organisations.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1024&quot; data-original-width=&quot;1536&quot; height=&quot;266&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyZI8mQiqYExVQcWSNaskwhg5B4dBIjENQuwngbVgZEn-sZCOtRAOqVELYfspteQ8rHe4247JFbYQfQNZWeQdDNtyVqf4qdaG-NZ37JqgAuHNHvwyQHdqGoh3JZZNYFyVeJK6V_ad3-hT5FxMjXcXf0V4jubxMUjBp8QdkBljlPBlEZ_kmNbdSXwR3ka5i/w400-h266/ai-governance-cyber-resilience-uk-organisations.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin: 0cm; text-align: center; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span face=&quot;Aptos, sans-serif&quot; style=&quot;color: #212121;&quot;&gt;&lt;span style=&quot;caret-color: rgb(33, 33, 33);&quot;&gt;&lt;b&gt;&lt;i&gt;AI Governance and Cyber Resilience: A Boardroom Imperative&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span face=&quot;Aptos, sans-serif&quot; style=&quot;color: #212121;&quot;&gt;&lt;span style=&quot;caret-color: rgb(33, 33, 33);&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;As adoption accelerates, however, a quieter risk is emerging, and it is one that boards and executive teams cannot afford to treat solely as a technical issue. AI is not simply another tool for innovation. It is altering the cyber risk landscape and unsettling long held assumptions about security, governance, and resilience.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;Recent&lt;span class=&quot;Apple-converted-space&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;a href=&quot;https://1111systems.com/resources/1111-systems-research-it-leaders-struggle-with-cyberattack-complexity-emea/&quot; style=&quot;color: #96607d;&quot; target=&quot;_blank&quot; title=&quot;https://1111systems.com/resources/1111-systems-research-it-leaders-struggle-with-cyberattack-complexity-emea/&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;research by 11:11 Systems&lt;/span&gt;&lt;/a&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span class=&quot;Apple-converted-space&quot;&gt;&amp;nbsp;&lt;/span&gt;highlights the scale of that concern. In a global survey of more than 800 senior IT leaders, nearly three quarters (74%) said they believe integrating AI into their organisations could increase vulnerability to cyber attacks, a view shared particularly strongly by both UK and European respondents. This reflects that while they aren’t reluctant to innovate, there is growing recognition that AI changes how risk behaves, moving faster, spreading more easily and becoming harder for leadership teams to understand &amp;nbsp;and control.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;b&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Why Boards should be Paying Attention&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;AI can strengthen cyber defences. Machine Learning systems are capable of spotting anomalies at speed, automating elements of incident response, and helping security teams prioritise threats more effectively. In theory, these capabilities should favour defenders.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;In practice, the same techniques are also being adopted by attackers. AI is already being used to generate more convincing phishing campaigns, automate reconnaissance, and adapt malware in real time.&lt;span class=&quot;Apple-converted-space&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;a href=&quot;https://www.gov.uk/government/publications/research-on-the-cyber-security-of-ai/cyber-security-risks-to-artificial-intelligence&quot; style=&quot;color: #96607d;&quot; target=&quot;_blank&quot; title=&quot;https://www.gov.uk/government/publications/research-on-the-cyber-security-of-ai/cyber-security-risks-to-artificial-intelligence&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;UK Government commissioned research&lt;/span&gt;&lt;/a&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span class=&quot;Apple-converted-space&quot;&gt;&amp;nbsp;&lt;/span&gt;has shown that vulnerabilities can arise at every stage of the AI lifecycle, from early design decisions through to deployment and ongoing maintenance This creates new attack surfaces that many organisations are still learning how to manage.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;For boards, the implication is that AI risk can no longer be contained within IT functions. It raises questions about compliance, reputation, operational continuity, and long-term value, while also challenging how risk is identified, tested, and understood at the board level, particularly when AI-driven systems behave in ways that are opaque or difficult to predict.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;While the technical risks continue to evolve, two organisational dynamics are making them harder to control.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;b&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Shadow AI is Becoming Endemic&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;Employees are increasingly turning to unapproved or unsanctioned AI tools to work faster and more efficiently. Often this happens with good intent, but without visibility, governance, or security oversight. UK regulators have been clear that organisations remain accountable for how personal and sensitive data is handled, regardless of whether AI tools are formally approved or informally adopted.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;a href=&quot;https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/ai-and-data-protection-risk-toolkit/&quot; style=&quot;color: #96607d;&quot; target=&quot;_blank&quot; title=&quot;https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/ai-and-data-protection-risk-toolkit/&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;The Information Commissioner’s Office (ICO)&lt;/span&gt;&lt;/a&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span class=&quot;Apple-converted-space&quot;&gt;&amp;nbsp;&lt;/span&gt;has repeatedly emphasised that AI deployments must comply with UK GDPR principles, including transparency, accountability, and data minimisation. When AI use sits outside formal controls, blind spots emerge, making it harder to demonstrate compliance to regulators and auditors and harder to contain incidents when something goes wrong.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;For boards, the risk is not simply the existence of unauthorised tools. Fundamentally, the risk lies in the widening gap between what leaders believe is happening inside the organisation versus how AI is being used day to day, under pressure to move faster.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;b&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Pressure for Speed is Outpacing Resilience Planning&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;AI initiatives are often driven by competitive urgency. Leadership teams want rapid deployment, visible progress, and quick returns. Yet research suggests this urgency often comes at &amp;nbsp;the expense of recovery readiness, oversight and confidence in how incidents should be handled. This is supported by the 11:11 Systems study which found that many organisations remain overconfident in their ability to recover from cyber incidents, even as complexity increases.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;When AI systems are deployed before recovery, backup, and incident response plans have been tested against new threat scenarios, resilience becomes theoretical. In an AI driven incident, the speed and effectiveness of recovery will determine the scale of operational disruption, regulatory scrutiny, and reputational damage the business faces.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;b&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Why Resilience Models Must Evolve&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;Many board level approaches to resilience were designed for risks that were visible, testable, and broadly predictable. AI quietly undermines those assumptions.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;UK organisations are increasingly being encouraged to rethink resilience in light of how AI changes the pace and complexity of incidents. That shift is evident in three areas.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;Recovery processes are evolving to become more automated and scalable. This reflects the reality that manual responses struggle to keep up with fast moving, complex incidents. Research shows that prolonged recovery times significantly increase financial and operational damage following cyber events, particularly in large enterprises.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;Testing is changing. Static, annual recovery plans are poorly suited to adaptive threats. Government research into AI security risks points to the need for ongoing validation across the AI lifecycle, rather than periodic, check list driven assurance.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;Finally, resilience is being treated less as a downstream activity and more as a design principle. Governance, visibility, and recovery capabilities are increasingly expected to be built into AI deployments from the outset, not added after an incident. UK regulatory guidance reinforces the expectation that organisations can demonstrate control and accountability over AI driven processes, even as those systems evolve.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;b&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;The Board Level Takeaway&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;AI represents a strategic opportunity for UK businesses. But adoption that outpaces governance and recovery planning can quietly expand exposure at the very moment organisations believe they are becoming more advanced.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;The question for boards is no longer whether to adopt AI, but how to do so responsibly. Confidence in innovation needs to be matched by confidence in recovery. That requires tougher questions about visibility, testing, and readiness, not just performance and productivity.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; line-height: normal; margin: 0cm; text-decoration-style: solid; text-decoration-thickness: auto;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot;&gt;In this context, AI governance is not about controlling technology. It is about restoring board level confidence in how risk is understood and managed. In an increasingly complex UK threat landscape, the organisations that succeed will not be those that move fastest at any cost. They will be the ones that embed cyber resilience into AI adoption from the outset, innovating with intent and remain resilient in the face of increasing complexity.&lt;/span&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/6729029560316801818/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/6729029560316801818' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/6729029560316801818'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/6729029560316801818'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/05/ai-in-uk-driving-innovation-without.html' title=' AI in the UK: Driving Innovation Without Expanding Cyber Risk'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyZI8mQiqYExVQcWSNaskwhg5B4dBIjENQuwngbVgZEn-sZCOtRAOqVELYfspteQ8rHe4247JFbYQfQNZWeQdDNtyVqf4qdaG-NZ37JqgAuHNHvwyQHdqGoh3JZZNYFyVeJK6V_ad3-hT5FxMjXcXf0V4jubxMUjBp8QdkBljlPBlEZ_kmNbdSXwR3ka5i/s72-w400-h266-c/ai-governance-cyber-resilience-uk-organisations.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-5758785315517845464</id><published>2026-05-22T07:00:00.000+01:00</published><updated>2026-05-22T07:00:00.163+01:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="AI governance"/><category scheme="http://www.blogger.com/atom/ns#" term="continuous control monitoring"/><category scheme="http://www.blogger.com/atom/ns#" term="control validation"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber resilience"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber risk management"/><category scheme="http://www.blogger.com/atom/ns#" term="evidence freshness"/><category scheme="http://www.blogger.com/atom/ns#" term="second line assurance"/><category scheme="http://www.blogger.com/atom/ns#" term="security monitoring limitations"/><category scheme="http://www.blogger.com/atom/ns#" term="SIEM challenges"/><category scheme="http://www.blogger.com/atom/ns#" term="SOC operations"/><title type='text'>Controlling AI Agents: Why Detection Is Too Late</title><content type='html'>&lt;p&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-family: arial; font-size: 12px;&quot;&gt;This is Part 2 of a 2-part series.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-family: arial; font-kerning: none; font-size: 12px;&quot;&gt;Read Part 1:&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-family: arial; font-kerning: none; font-size: 12px; font-style: italic;&quot;&gt;&lt;a href=&quot;https://blog.itsecurityexpert.co.uk/2026/05/your-ai-agent-doesnt-care-about-your.html&quot;&gt;Your AI Agent Doesn’t Care About Your Controls&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(128, 128, 128); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px; min-height: 13.8px;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0);&quot;&gt;If AI agents change how execution happens, they also expose a fundamental limitation in how most security controls operate. Many control models assume there is sufficient time to detect, assess, and respond to events before they result in material impact.&lt;/span&gt;&lt;span style=&quot;color: grey; font-kerning: none;&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;That assumption no longer holds.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;Traditional detection models follow a sequence in which an event occurs, is logged, analysed, and then acted upon. This approach works at human speed, where actions are spaced out and intervention is possible. In automated environments, particularly those involving AI agents, that sequence is compressed to the point where response often occurs after the outcome has already been realised.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwoB7XsdSQ_ug054bIwMyqaM-aTQxiH-Gvak-VL1gNxS540BPo0FnYrgbM3I4RqGA-OAlzwE6I5LY1AgOYhzkpHzp46myWS8vpGVnLd9iNzgON8PLteIbXMheQfX1T7iq-OsmO9lz8IZ9BSllTDpcFCvgul8WjgU5ghbsv6IcqT35yu4cdTbe7ysOflOFa/s1536/ChatGPT%20Image%20May%2021,%202026%20at%2001_48_48%20PM.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1024&quot; data-original-width=&quot;1536&quot; height=&quot;213&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwoB7XsdSQ_ug054bIwMyqaM-aTQxiH-Gvak-VL1gNxS540BPo0FnYrgbM3I4RqGA-OAlzwE6I5LY1AgOYhzkpHzp46myWS8vpGVnLd9iNzgON8PLteIbXMheQfX1T7iq-OsmO9lz8IZ9BSllTDpcFCvgul8WjgU5ghbsv6IcqT35yu4cdTbe7ysOflOFa/s320/ChatGPT%20Image%20May%2021,%202026%20at%2001_48_48%20PM.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial; font-size: 18px; font-weight: bold;&quot;&gt;The Speed Problem&lt;/span&gt;&lt;p&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;AI agents operate at a pace that removes the window for meaningful intervention. They do not pause between actions or wait for approval cycles. Once triggered, they execute tasks rapidly across systems, often chaining multiple actions together in a single flow.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;By the time an alert is generated, the action has already completed. By the time it is reviewed, the downstream effects may already be in place. This fundamentally changes the role of detection. It becomes a mechanism for understanding what has happened, rather than preventing it.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 18px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 14.9px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none; font-weight: bold;&quot;&gt;The Illusion of Monitoring&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;In response to increasing complexity, many organisations invest in expanding their monitoring capability. More logs are collected, more alerts are generated, and dashboards become more detailed. However, this increase in visibility does not automatically translate into improved control.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;Without context, prioritisation, and validation, monitoring becomes a record of activity rather than a means of assurance. Security operations teams are often left dealing with high volumes of alerts that are difficult to interpret in real time. AI agents amplify this problem by increasing both the frequency and the speed of events.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The result is a growing gap between what can be seen and what can be meaningfully controlled.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 18px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 14.9px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none; font-weight: bold;&quot;&gt;Evidence and Its Limitations&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;Control assurance depends on evidence, but evidence is only useful if it reflects the current state of the environment. In slower operational models, evidence can remain valid for extended periods. In highly automated environments, that validity window shortens significantly.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;Access models change, configurations drift, and behaviour evolves rapidly. Evidence that was accurate recently may no longer represent reality. This creates a challenge for organisations that rely on periodic validation or static reporting to demonstrate control effectiveness.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;In this context, evidence must be continuously refreshed and validated against actual behaviour, not assumed based on design.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 18px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 14.9px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none; font-weight: bold;&quot;&gt;What Needs to Change&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;Addressing this challenge does not require abandoning existing frameworks, but it does require changing how they are applied.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The first shift is from access control to execution control. It is no longer sufficient to confirm that an identity has access to a system. Organisations must understand what actions are being executed, in what sequence, and under what conditions.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The second shift is the reintroduction of accountability. Every action performed by an AI agent should be attributable, traceable, and explainable. Without that, it is difficult to demonstrate that controls are operating effectively.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The third shift is towards validating real behaviour. Policies, architectures, and intended workflows provide useful context, but they do not prove how systems behave in practice. Validation must be based on observed activity in production environments.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;Finally, independent assurance becomes increasingly important. Second-line validation provides a mechanism to challenge assumptions, review evidence, and confirm that controls operate as intended under real conditions. Without this, there is a risk that assurance becomes self-declared rather than evidence-based.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 18px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 14.9px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none; font-weight: bold;&quot;&gt;Final Thought&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;AI agents are efficient and highly capable. They execute exactly what they are designed to do, often with greater speed and consistency than human operators.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The risk lies not in the technology itself, but in the assumption that existing control models still provide meaningful assurance. As execution changes, so must the way control effectiveness is measured and validated.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The key question is no longer whether controls exist, but whether their effectiveness can be demonstrated in the context in which they are now operating.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(128, 128, 128); color: grey; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px; min-height: 13.8px;&quot;&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/5758785315517845464/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/5758785315517845464' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5758785315517845464'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5758785315517845464'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/05/controlling-ai-agents-why-detection-is.html' title='Controlling AI Agents: Why Detection Is Too Late'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwoB7XsdSQ_ug054bIwMyqaM-aTQxiH-Gvak-VL1gNxS540BPo0FnYrgbM3I4RqGA-OAlzwE6I5LY1AgOYhzkpHzp46myWS8vpGVnLd9iNzgON8PLteIbXMheQfX1T7iq-OsmO9lz8IZ9BSllTDpcFCvgul8WjgU5ghbsv6IcqT35yu4cdTbe7ysOflOFa/s72-c/ChatGPT%20Image%20May%2021,%202026%20at%2001_48_48%20PM.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-6051044528129279788</id><published>2026-05-21T14:02:27.027+01:00</published><updated>2026-05-21T14:10:54.214+01:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="AI agents risk"/><category scheme="http://www.blogger.com/atom/ns#" term="AI cybersecurity"/><category scheme="http://www.blogger.com/atom/ns#" term="API security"/><category scheme="http://www.blogger.com/atom/ns#" term="automation risk"/><category scheme="http://www.blogger.com/atom/ns#" term="Control Assurance"/><category scheme="http://www.blogger.com/atom/ns#" term="control effectiveness"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber resilience"/><category scheme="http://www.blogger.com/atom/ns#" term="cybersecurity governance"/><category scheme="http://www.blogger.com/atom/ns#" term="identity and access management"/><category scheme="http://www.blogger.com/atom/ns#" term="SaaS security"/><title type='text'>Your AI Agent Doesn’t Care About Your Controls</title><content type='html'>&lt;p&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-family: arial; font-size: 12px;&quot;&gt;This is Part 1 of a 2-part series on AI agents and control assurance. &amp;nbsp;&lt;/span&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-family: arial; font-kerning: none; font-size: 12px;&quot;&gt;Read Part 2: &lt;/span&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-family: arial; font-kerning: none; font-size: 12px; font-style: italic;&quot;&gt;&lt;a href=&quot;https://blog.itsecurityexpert.co.uk/2026/05/controlling-ai-agents-why-detection-is.html&quot;&gt;Controlling AI Agents: Why Detection Is Too Late&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The cybersecurity industry has spent years investing in visibility. Dashboards have improved, detection tooling has matured, and the volume of telemetry available to security teams has increased significantly. Most organisations can now see more of their environment than at any point in the past.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;However, one of the most important emerging risks is not hidden malware or an unknown vulnerability. It is the rapid introduction of AI agents operating across environments that organisations do not fully understand, cannot clearly inventory, and often cannot meaningfully govern.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;This is not simply another software category. It represents the introduction of autonomous digital actors interacting with identity systems, APIs, SaaS platforms, cloud environments, and business processes. These agents are not constrained by the same assumptions that underpin traditional control models, and that is where the risk begins to surface.&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU5sOpEvV9arJsotTksIsihsI51dbEryHSmeuy33OVUyRExxjIer3zjs_sCIb2owp7MXojrgbiEauqV25M9vgexMPeSAcazbHRv2FJIbOBGMPwoLTwgJEEjTXeyftV0Fm0MNFzWrhvV3Yrz1qYDiOmCx7zcMTvrD9cMry6Fcqi3NbF9UU1AGBX5JUSzioC/s1717/ChatGPT%20Image%20May%2021,%202026%20at%2001_47_50%20PM.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;916&quot; data-original-width=&quot;1717&quot; height=&quot;171&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU5sOpEvV9arJsotTksIsihsI51dbEryHSmeuy33OVUyRExxjIer3zjs_sCIb2owp7MXojrgbiEauqV25M9vgexMPeSAcazbHRv2FJIbOBGMPwoLTwgJEEjTXeyftV0Fm0MNFzWrhvV3Yrz1qYDiOmCx7zcMTvrD9cMry6Fcqi3NbF9UU1AGBX5JUSzioC/s320/ChatGPT%20Image%20May%2021,%202026%20at%2001_47_50%20PM.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 18px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 14.9px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none; font-weight: bold;&quot;&gt;From Users to Actors&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;Traditional security models are built around users. Users authenticate, request access, and perform actions within defined boundaries. Even when errors occur, those actions are constrained by identity controls, privilege models, monitoring, and the natural pace of human interaction. There is friction in the system, and that friction is part of how control is maintained.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;AI agents remove much of that friction. They are not passive tools assisting users; they are active actors executing tasks. They retrieve data, make decisions, invoke APIs, and trigger workflows across multiple systems in seconds. The shift is subtle but important. The challenge is no longer limited to managing access. It becomes a question of controlling execution.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 18px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 14.9px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none; font-weight: bold;&quot;&gt;Execution Without Assurance&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;Most organisations assume their existing control frameworks still apply in this new model. On paper, they do. In practice, they often do not.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;Control frameworks were designed to validate human-driven actions, predictable workflows, relatively static privilege models, and slower operational cycles. They were not designed to validate high-frequency automated decisions, cross-system execution chains, or real-time, context-driven behaviour.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;This creates a gap that is easy to overlook. The agent may be authenticating correctly, calling approved APIs, and interacting with authorised systems. From a control perspective, nothing appears to be broken. Yet there is often no mechanism to prove that the actions being executed are appropriate, proportionate, or safe in the context in which they occur.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 18px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 14.9px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none; font-weight: bold;&quot;&gt;Where Controls Start to Fail&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;This is not a theoretical issue. It is a structural one, and it tends to appear in consistent ways across environments.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The first area is identity. AI agents commonly operate using service accounts, shared credentials, or delegated access tokens. While this enables integration and automation, it weakens attribution. In a traditional model, actions can be traced to an individual. In an AI-driven model, activity may be technically valid but operationally ambiguous, making it difficult to establish accountability when something goes wrong.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The second area is privilege. To enable capability, agents are often granted broad access across systems and services. However, least privilege is not simply about limiting access; it is about ensuring that access is used appropriately in context. An agent may be authorised to access a system, but that does not mean every action it performs within that system aligns with business intent or risk tolerance. Most control models validate access rights rather than behavioural appropriateness.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The third area is monitoring. As automation increases, so does logging. However, more data does not necessarily lead to more assurance. When an agent executes hundreds of actions in a short period, logs can quickly become noise, alerts become volume-driven, and meaningful signal is harder to extract. Monitoring shifts from proactive oversight to retrospective analysis.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;The final and most important area is control validation. Controls such as access reviews, segregation of duties, and approval workflows may still exist, but they are rarely tested against autonomous, multi-step execution across systems. The result is not a lack of controls, but a lack of confidence that those controls are operating effectively in the way they were intended.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 18px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 14.9px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none; font-weight: bold;&quot;&gt;Final Thought&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;AI agents are not bypassing controls. In most cases, they are operating within them. The issue is that those controls were not designed to validate how work is now being executed.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial; font-kerning: none;&quot;&gt;If control effectiveness cannot be demonstrated against real behaviour, then the presence of controls alone does not provide assurance.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(128, 128, 128); -webkit-text-stroke-width: 0px; color: grey; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px; min-height: 13.8px;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span face=&quot;TimesNewRomanPS-BoldMT&quot; style=&quot;font-kerning: none; font-weight: bold;&quot;&gt;Next in the series:&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;br /&gt;
&lt;/span&gt;&lt;span face=&quot;TimesNewRomanPS-BoldMT&quot; style=&quot;font-kerning: none; font-weight: bold;&quot;&gt;&lt;a href=&quot;https://blog.itsecurityexpert.co.uk/2026/05/controlling-ai-agents-why-detection-is.html&quot;&gt;Controlling AI Agents: Why Detection Is Too Late&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 12px; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px;&quot;&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/6051044528129279788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/6051044528129279788' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/6051044528129279788'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/6051044528129279788'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/05/your-ai-agent-doesnt-care-about-your.html' title='Your AI Agent Doesn’t Care About Your Controls'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU5sOpEvV9arJsotTksIsihsI51dbEryHSmeuy33OVUyRExxjIer3zjs_sCIb2owp7MXojrgbiEauqV25M9vgexMPeSAcazbHRv2FJIbOBGMPwoLTwgJEEjTXeyftV0Fm0MNFzWrhvV3Yrz1qYDiOmCx7zcMTvrD9cMry6Fcqi3NbF9UU1AGBX5JUSzioC/s72-c/ChatGPT%20Image%20May%2021,%202026%20at%2001_47_50%20PM.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-7564375842260665970</id><published>2026-05-11T07:00:00.000+01:00</published><updated>2026-05-11T07:00:00.118+01:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="agentic AI"/><category scheme="http://www.blogger.com/atom/ns#" term="AI agents"/><category scheme="http://www.blogger.com/atom/ns#" term="AI cyber risk"/><category scheme="http://www.blogger.com/atom/ns#" term="AI governance"/><category scheme="http://www.blogger.com/atom/ns#" term="AI Security"/><category scheme="http://www.blogger.com/atom/ns#" term="autonomous AI"/><category scheme="http://www.blogger.com/atom/ns#" term="Control Assurance"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber resilience"/><category scheme="http://www.blogger.com/atom/ns#" term="cybersecurity governance"/><category scheme="http://www.blogger.com/atom/ns#" term="enterprise AI security"/><category scheme="http://www.blogger.com/atom/ns#" term="operational resilience"/><category scheme="http://www.blogger.com/atom/ns#" term="shadow AI"/><title type='text'>AI Agents Are Creating a New Cybersecurity Blind Spot</title><content type='html'>&lt;style&gt;
  .ise-post {
    font-family: Arial, Helvetica, sans-serif;
    color: #111827;
    line-height: 1.65;
    font-size: 16px;
  }

  .ise-post p {
    margin: 0 0 18px 0;
  }

  .ise-post h2 {
    margin: 34px 0 14px 0;
    font-size: 24px;
    line-height: 1.25;
    color: #0b1f2e;
  }

  .ise-post h3 {
    margin: 26px 0 10px 0;
    font-size: 20px;
    line-height: 1.3;
    color: #0b1f2e;
  }

  .ise-post ul {
    margin: 8px 0 20px 24px;
    padding: 0;
  }

  .ise-post li {
    margin: 0 0 6px 0;
    padding-left: 2px;
  }

  .ise-post a {
    color: #1687b9;
    font-weight: 600;
  }

  .ise-post .post-image {
    margin: 28px 0 32px 0;
    text-align: center;
  }

  .ise-post .post-image img {
    max-width: 100%;
    height: auto;
    border-radius: 10px;
  }

  .ise-post .sources {
    margin-top: 28px;
  }
&lt;/style&gt;

&lt;div class=&quot;ise-post&quot;&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The cybersecurity industry has spent years focusing on visibility. Dashboards expanded. Detection tooling improved. Telemetry volumes exploded. Yet one of the biggest emerging risks in 2026 is not hidden malware or an unknown zero-day. It is the rapid deployment of AI agents that organisations barely understand, cannot fully inventory, and often cannot meaningfully govern.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI agents are moving beyond chat interfaces and simple copilots. They are increasingly capable of reasoning, planning, accessing systems, invoking tools, retrieving information, and taking autonomous actions with limited human involvement. That changes the security conversation entirely.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;This is not simply another software category. It is the emergence of autonomous digital workers operating across identity systems, APIs, SaaS platforms, cloud environments, and business processes.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;And most organisations are deploying them faster than they can secure them.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;a href=&quot;https://www.bvp.com/atlas/securing-ai-agents-the-defining-cybersecurity-challenge-of-2026&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Research and industry reporting throughout 2026&lt;/a&gt; show a growing concern across both government and enterprise sectors around agentic AI security risks. Security leaders increasingly view autonomous AI systems as one of the most significant new attack surfaces facing organisations.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The concern is justified.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI agents introduce a combination of risks that traditional governance and security models were never designed to handle.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkSOTVGT3WHeBO6vLI3IUKRJhuMNEIVRORg49ViI-AxDqMbV-HvUcpWh2QbnCFT4fFMnNLP19PZ1aW0xG-haSGDaSNwUjrgVyhBSID9d7fr18AIdT8vJcBuBC8sK6kYr54T_VXS0LME5ULMmG3IfR-vtWiIv-bMv0R82BTQ2HrEe-jwHwP3By1Ve0zX05i/s1536/AIAgentsSecurityRisk.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1024&quot; data-original-width=&quot;1536&quot; height=&quot;266&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkSOTVGT3WHeBO6vLI3IUKRJhuMNEIVRORg49ViI-AxDqMbV-HvUcpWh2QbnCFT4fFMnNLP19PZ1aW0xG-haSGDaSNwUjrgVyhBSID9d7fr18AIdT8vJcBuBC8sK6kYr54T_VXS0LME5ULMmG3IfR-vtWiIv-bMv0R82BTQ2HrEe-jwHwP3By1Ve0zX05i/w400-h266/AIAgentsSecurityRisk.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI Agents Change the Nature of Identity Risk&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Most cybersecurity programmes were built around managing human identities and traditional service accounts. AI agents disrupt that model because they behave more like autonomous actors than passive software components.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Many organisations are now deploying AI agents with:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;access to internal documentation&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;integration into SaaS platforms&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;permissions to execute workflows&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;API access to sensitive systems&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;delegated authority to make operational decisions&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The problem is not simply access. It is scale and autonomy.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://securitybrief.co.uk/story/ai-s-2026-security-fallout-identity-chaos-deepfake-fear&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Industry forecasts suggest AI agent identities may soon outnumber human identities dramatically inside enterprise environments.&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That creates several immediate challenges:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;identity sprawl&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;excessive permissions&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;unmanaged API tokens&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;poor lifecycle governance&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;invisible machine-to-machine trust relationships&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;difficulty attributing actions and accountability&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;In many environments, organisations already struggle to maintain accurate inventories of privileged accounts or SaaS integrations. AI agents accelerate that problem significantly.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The result is a growing gap between operational reality and governance visibility.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI Agents Create a New Attack Surface&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The security industry often focuses heavily on model risks such as prompt injection or data poisoning. Those are important, but they are only part of the picture.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The bigger issue is that AI agents operate across interconnected runtime environments.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Modern agents may:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;consume external data&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;invoke plugins and APIs&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;interact with cloud services&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;maintain persistent memory&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;chain multiple actions together&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;collaborate with other agents&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;execute operational workflows automatically&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That creates an entirely new form of runtime attack surface.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Recent research highlights risks including:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;memory poisoning&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;malicious tool invocation&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;indirect prompt injection&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI supply chain compromise&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;runtime dependency manipulation&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;self-propagating agent loops&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://arxiv.org/abs/2602.19555&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;excessive agency and unauthorised action execution&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The important point is this:&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Many of these attacks do not exploit traditional software vulnerabilities. They exploit trust, autonomy, orchestration, and context.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That makes detection and governance significantly harder.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Why Existing Security Controls Are Struggling&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;One of the most dangerous assumptions organisations can make is believing existing security tooling automatically extends to AI agents.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;In many cases it does not.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Traditional controls were largely designed for:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;deterministic systems&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;predictable workflows&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;static permissions&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;human-driven actions&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;relatively stable software behaviour&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI agents are fundamentally different.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;They are probabilistic, adaptive, and capable of unexpected behaviour under changing context conditions.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;This creates several assurance problems:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;inventories quickly become outdated&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;permissions drift continuously&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;actions may not be fully explainable&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;logging lacks meaningful context&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;governance ownership becomes unclear&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;accountability boundaries blur&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The challenge is not merely technical. It is operational.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Security teams increasingly face environments where AI functionality appears inside:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;SaaS products&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;collaboration platforms&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;development tooling&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;cloud management interfaces&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;workflow automation systems&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;productivity platforms&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Often these capabilities are enabled by default or adopted informally by business teams before governance frameworks exist.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;This is rapidly becoming one of the largest forms of &lt;a href=&quot;https://thehackernews.com/2026/04/the-hidden-security-risks-of-shadow-ai.html&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;Shadow IT the industry has seen&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The Real Risk Is Governance Lag&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The most significant AI security risk in many organisations is not the AI itself.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;It is governance lag.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Technology deployment is moving faster than:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;control validation&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;identity governance&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;operational assurance&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;policy adaptation&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;board understanding&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;security architecture redesign&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;This creates a dangerous illusion of control.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Dashboards may still appear green while autonomous systems quietly accumulate:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;privileges&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;integrations&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;external dependencies&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;sensitive data access&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;operational authority&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Without strong governance, organisations risk repeating familiar mistakes:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;deploying first&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;governing later&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;discovering exposure during incidents&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The difference now is speed.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI systems compress timelines dramatically.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;What Security Leaders Should Do Next&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The organisations responding most effectively are not trying to ban AI agents entirely. They are focusing on visibility, containment, and evidence-driven governance.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Several priorities are emerging:&lt;/span&gt;&lt;/p&gt;

&lt;h3&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;1. Build an AI Asset Inventory&lt;/span&gt;&lt;/h3&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Most organisations cannot currently answer:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;which AI agents exist&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;what systems they access&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;what permissions they hold&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;what data they process&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;who owns them&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That must change quickly.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI agents should be treated as managed operational assets with clear ownership and lifecycle governance.&lt;/span&gt;&lt;/p&gt;

&lt;h3&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;2. Apply Least Privilege Aggressively&lt;/span&gt;&lt;/h3&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Many AI deployments currently operate with excessive permissions for convenience.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That is unsustainable.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI agents should operate with:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;constrained access scopes&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;segmented permissions&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;time-limited credentials&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;monitored API activity&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;restricted tool invocation&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The principle of least privilege matters even more in autonomous environments.&lt;/span&gt;&lt;/p&gt;

&lt;h3&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;3. Treat AI Runtime Behaviour as an Assurance Problem&lt;/span&gt;&lt;/h3&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The industry increasingly needs continuous validation rather than static approval models.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Security teams should focus on:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;runtime monitoring&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;behavioural drift detection&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;evidence freshness&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;control verification&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;anomalous workflow analysis&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;This aligns closely with broader Continuous Control Monitoring (CCM) approaches already emerging across cybersecurity assurance programmes.&lt;/span&gt;&lt;/p&gt;

&lt;h3&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;4. Update Governance Frameworks&lt;/span&gt;&lt;/h3&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Most governance structures were not designed for autonomous operational actors.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Boards, risk committees, and security leadership teams need clearer accountability models around:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI deployment ownership&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;operational risk tolerance&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;human override mechanisms&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;auditability&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;resilience testing&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;third-party AI exposure&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The governance gap is becoming as important as the technical gap.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Final Thought&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI agents are not simply another cybersecurity trend. They represent a structural change in how digital systems operate.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The organisations that succeed will not necessarily be those deploying AI fastest.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;They will be the organisations that can answer:&lt;/span&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;what their AI systems are doing&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;what authority they possess&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;how they are governed&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;how they are monitored&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;whether their controls still work under real operational conditions&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That is ultimately the real challenge of AI security in 2026.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Not visibility alone.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;But provable assurance.&lt;/span&gt;&lt;/p&gt;

&lt;p class=&quot;sources&quot;&gt;&lt;strong&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Sources and further reading:&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://internationalaisafetyreport.org/publication/international-ai-safety-report-2026&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;International AI Safety Report 2026&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://www.darktrace.com/blog/state-of-ai-cybersecurity-2026-92-of-security-professionals-concerned-about-the-impact-of-ai-agents&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;State of AI Cybersecurity 2026&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://arxiv.org/abs/2602.19555&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Agentic AI security research papers&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://www.cybersecurity-insiders.com/ai-agents-are-the-new-attack-surface-and-most-enterprises-dont-know-it/&quot; rel=&quot;noopener&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Industry reporting on AI agent attack surfaces and governance risks&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/7564375842260665970/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/7564375842260665970' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/7564375842260665970'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/7564375842260665970'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/05/ai-agents-are-creating-new.html' title='AI Agents Are Creating a New Cybersecurity Blind Spot'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkSOTVGT3WHeBO6vLI3IUKRJhuMNEIVRORg49ViI-AxDqMbV-HvUcpWh2QbnCFT4fFMnNLP19PZ1aW0xG-haSGDaSNwUjrgVyhBSID9d7fr18AIdT8vJcBuBC8sK6kYr54T_VXS0LME5ULMmG3IfR-vtWiIv-bMv0R82BTQ2HrEe-jwHwP3By1Ve0zX05i/s72-w400-h266-c/AIAgentsSecurityRisk.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-5640096402805569575</id><published>2026-05-07T07:00:00.000+01:00</published><updated>2026-05-07T15:07:08.151+01:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="AI Security"/><category scheme="http://www.blogger.com/atom/ns#" term="CISO"/><category scheme="http://www.blogger.com/atom/ns#" term="Control Assurance"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber resilience"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber risk"/><category scheme="http://www.blogger.com/atom/ns#" term="Mythos AI"/><category scheme="http://www.blogger.com/atom/ns#" term="operational resilience"/><category scheme="http://www.blogger.com/atom/ns#" term="Project Glasswing"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Management"/><category scheme="http://www.blogger.com/atom/ns#" term="Zero Trust"/><title type='text'>Mythos AI: What Security Leaders Should Do Next</title><content type='html'>&lt;style&gt;
  .post-body {
    font-family: Arial, sans-serif;
  }

  .post-body h2 {
    font-family: Arial, sans-serif;
    margin-top: 26px;
    margin-bottom: 6px;
    line-height: 1.25;
  }

  .post-body p {
    font-family: Arial, sans-serif;
    margin-top: 0;
    margin-bottom: 14px;
    line-height: 1.6;
  }

  .post-body ul {
    font-family: Arial, sans-serif;
    margin-top: 4px;
    margin-bottom: 16px;
  }

  .post-body li {
    margin-bottom: 6px;
    line-height: 1.5;
  }

  .separator {
    margin-top: 18px;
    margin-bottom: 18px;
  }
&lt;/style&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The recent discussion around &lt;a href=&quot;https://www.bbc.co.uk/news/articles/crk1py1jgzko&quot; target=&quot;_blank&quot;&gt;Anthropic’s Claude Mythos Preview&lt;/a&gt; and &lt;a href=&quot;https://www.anthropic.com/glasswing&quot; target=&quot;_blank&quot;&gt;Project Glasswing &lt;/a&gt;has caught the attention of the cybersecurity industry for good reason.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Mythos is not just another AI announcement. It is being positioned as a frontier model with advanced cybersecurity capability, particularly around finding and exploiting software vulnerabilities. &lt;a href=&quot;https://www.anthropic.com/glasswing&quot; target=&quot;_blank&quot;&gt;Anthropic has stated that Project Glasswing&lt;/a&gt; is intended to give selected defenders early access to this capability to help secure critical software, rather than releasing the model broadly.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;a href=&quot;https://www.cisco.com/c/m/en_us/about/doing_business/trust-center/cisco-defending-against-ai-attacks-guidance.html&quot; target=&quot;_blank&quot;&gt;Cisco has also published guidance&lt;/a&gt; following its work with Mythos, explaining that it is changing its near-term threat modelling of AI-enabled attackers and issuing defensive recommendations for customers. That is the important point.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Whether Mythos itself remains tightly controlled or not, the direction of travel is clear. AI-enabled vulnerability discovery and exploitation capability is improving quickly. Security teams need to prepare for a world where attackers can find, chain and act on weaknesses faster than many organisations can currently respond.&lt;/span&gt;&lt;/p&gt;

&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYJVNFASU5i5aSI_GPwnF-Orf9RzfXRneYPe7FJtGuHoycsnm6ARdRn4XUxL-8PgQ7h60RA5MLQyR_nn2XzHcotQwsvNMGIvGtULwK64-gER_rGQFY3aceejGAL5RTj1__LbcDW77S2drxJ6DXqB9TunVYEQg-9Cg03Q5mmJ6hGbmC4dQ-EhYci8C9K2BV/s1536/mythos.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;
    &lt;img border=&quot;0&quot; data-original-height=&quot;1024&quot; data-original-width=&quot;1536&quot; height=&quot;213&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYJVNFASU5i5aSI_GPwnF-Orf9RzfXRneYPe7FJtGuHoycsnm6ARdRn4XUxL-8PgQ7h60RA5MLQyR_nn2XzHcotQwsvNMGIvGtULwK64-gER_rGQFY3aceejGAL5RTj1__LbcDW77S2drxJ6DXqB9TunVYEQg-9Cg03Q5mmJ6hGbmC4dQ-EhYci8C9K2BV/s320/mythos.png&quot; width=&quot;320&quot; /&gt;
  &lt;/a&gt;
&lt;/span&gt;&lt;/div&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Why Mythos Matters&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The concern is not that every attacker suddenly has access to Mythos today.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The concern is that Mythos shows what is becoming possible.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;If AI can accelerate vulnerability discovery, exploit development and attack path analysis, then the defensive timeline changes. Security teams cannot rely on slow review cycles, stale evidence or manual-only response models when the speed of threat discovery is increasing.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;This does not mean the fundamentals no longer matter.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;It means they matter more.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;a href=&quot;https://www.cisco.com/c/m/en_us/about/doing_business/trust-center/cisco-defending-against-ai-attacks-guidance.html&quot; target=&quot;_blank&quot;&gt;Cisco’s guidance&lt;/a&gt; focuses heavily on strengthening fundamentals such as phishing-resistant MFA, Zero Trust, least privilege for AI agents, disciplined patch management and full asset visibility. It also highlights removing end-of-life systems, automating detection and containment, embedding active defences and using AI defensively for threat hunting, validation and testing.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That is where the practical response needs to start.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The Risk Is Speed&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Many organisations still manage cyber risk through processes designed for a slower environment.&lt;/span&gt;&lt;/p&gt;

&lt;ul style=&quot;text-align: left;&quot;&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Monthly reporting.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Quarterly reviews.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Annual testing.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Periodic evidence collection.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Manual triage.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Long remediation cycles.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Those activities still have a place, but they are not enough on their own.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI-enabled attackers will not wait for the next governance cycle. They will look for exposed systems, weak identity controls, unpatched vulnerabilities, misconfigured cloud services and overlooked legacy platforms.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The key question becomes:&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Can we identify and reduce exposure quickly enough?&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That is a very different question from simply asking whether a control exists.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;What Security Leaders Should Focus On&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The response to Mythos should not be panic, hype or rushing to buy more AI tooling.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;It should be disciplined improvement in the areas that matter most.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;1. Strengthen Security Fundamentals&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Start with the controls that reduce the most likely paths of attack:&lt;/span&gt;&lt;/p&gt;

&lt;ul style=&quot;text-align: left;&quot;&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Phishing-resistant MFA.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Least privilege.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Complete asset visibility.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Disciplined patch management.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Removal of end-of-life systems.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Secure configuration.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Segmentation.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Logging and monitoring.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Tested incident response.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;These are not new ideas. The challenge is proving they are actually working across the environment.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;2. Reduce Structural Risk&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;End-of-life platforms, unsupported systems and brittle legacy dependencies become more dangerous when attackers can find and chain weaknesses faster.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;This is not just a technology hygiene issue.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;It is a resilience issue.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Organisations should be clear on where structural risk exists, who owns it, what compensating controls are in place and by when the risk will be reduced.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;3. Automate Where Speed Matters&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Manual response will always have a role, especially where decisions affect operations. But manual-only models will struggle against AI-driven attack velocity.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Security teams should look at where automation can safely support:&lt;/span&gt;&lt;/p&gt;

&lt;ul style=&quot;text-align: left;&quot;&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Detection.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Enrichment.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Prioritisation.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Containment.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Evidence collection.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Control validation.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The aim is not blind automation.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The aim is controlled speed.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;4. Apply Least Privilege to AI Agents&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;One important point in the Cisco guidance is that least privilege must also apply to AI agents.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That is a point worth taking seriously.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI agents may interact with systems, APIs, data, workflows and security tooling. If they are not properly governed, they can become powerful operational pathways.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Security teams should be asking:&lt;/span&gt;&lt;/p&gt;

&lt;ul style=&quot;text-align: left;&quot;&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;What can the agent access?&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;What actions can it take?&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Who approved that access?&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;How is activity logged?&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;How is behaviour reviewed?&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;How is access removed when no longer needed?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI agents should not sit outside normal identity, access and change control disciplines.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;5. Improve Control Assurance&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;This is where Mythos becomes especially relevant.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;It is not enough to say controls exist.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Security leaders need confidence that key controls are operating effectively and that the evidence behind them is current.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;For example, if patch compliance is reported as high, are internet-facing assets included? Are exceptions approved? Are unsupported systems visible? Does asset inventory match the patching data?&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;If MFA is reported as complete, are privileged users covered? Are break-glass accounts monitored? Are service accounts excluded? Are temporary bypasses reviewed?&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;If endpoint protection is deployed, are agents active, current and reporting from all in-scope assets?&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;This is the practical value of control assurance. It challenges assumptions before attackers do.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;What Boards Should Ask&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The Mythos discussion should also sharpen board-level cyber questions.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Instead of only asking:&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Are we secure?&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Boards should increasingly ask:&lt;/span&gt;&lt;/p&gt;

&lt;ul style=&quot;text-align: left;&quot;&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;How quickly can we identify exposure?&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;How fresh is our control evidence?&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Which critical systems still rely on unsupported technology?&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Where are we dependent on manual response?&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Are AI agents governed through least privilege?&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Can we prove key controls are operating effectively?&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;These are practical questions. They move the conversation away from confidence statements and towards evidence.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Using AI Defensively&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI should not only be seen as an attacker advantage.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Defenders should also use AI where it improves speed, analysis and prioritisation. That might include threat hunting, vulnerability analysis, configuration review, testing, simulation and control validation.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;But AI-generated outputs still need challenge.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI can support assurance, but it should not replace evidence.&lt;/span&gt;&lt;/p&gt;

&lt;h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Final Thoughts&lt;/span&gt;&lt;/h2&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Mythos matters because it signals where cybersecurity is heading.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI-enabled capability is likely to make vulnerability discovery, exploit chaining and attack planning faster. That increases pressure on organisations still relying on slow remediation, incomplete visibility and periodic assurance.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The answer is not fear.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The answer is preparation.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Strengthen the fundamentals. Reduce structural risk. Improve visibility. Automate carefully. Govern AI agents. Validate controls with current evidence.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;At &lt;a href=&quot;https://www.cybersecurityexpert.co.uk&quot; target=&quot;_blank&quot;&gt;Cybersecurity Expert UK&lt;/a&gt;, I am continuing to explore these themes around practical cyber resilience, assurance and measurable control effectiveness.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;I have also been developing AI Labs tools to help security leaders think through exposure, control assurance and operational resilience in a more practical way, including:&lt;/span&gt;&lt;/p&gt;

&lt;ul style=&quot;text-align: left;&quot;&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Threat Exposure Analysis.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Control Assurance Validation.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Operational Resilience Mapping.&lt;/span&gt;&lt;/li&gt;
  &lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Cyber Control Failure Simulation.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;You can explore the AI Labs tools here:&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://www.cybersecurityexpert.co.uk/ai-labs&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI Labs – Provable Cyber Resilience Tools&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The core message is simple.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;In an AI-accelerated threat environment, assumptions will not be enough.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Security leaders need evidence they can trust.&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/5640096402805569575/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/5640096402805569575' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5640096402805569575'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5640096402805569575'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/05/mythos-ai-what-security-leaders-should.html' title='Mythos AI: What Security Leaders Should Do Next'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYJVNFASU5i5aSI_GPwnF-Orf9RzfXRneYPe7FJtGuHoycsnm6ARdRn4XUxL-8PgQ7h60RA5MLQyR_nn2XzHcotQwsvNMGIvGtULwK64-gER_rGQFY3aceejGAL5RTj1__LbcDW77S2drxJ6DXqB9TunVYEQg-9Cg03Q5mmJ6hGbmC4dQ-EhYci8C9K2BV/s72-c/mythos.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-5989823000218394804</id><published>2026-04-30T02:00:00.000+01:00</published><updated>2026-04-30T02:00:00.110+01:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="adaptive security leadership"/><category scheme="http://www.blogger.com/atom/ns#" term="CISO leadership"/><category scheme="http://www.blogger.com/atom/ns#" term="control effectiveness"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber resilience"/><category scheme="http://www.blogger.com/atom/ns#" term="cybersecurity governance"/><category scheme="http://www.blogger.com/atom/ns#" term="evidence based assurance"/><category scheme="http://www.blogger.com/atom/ns#" term="expanding threat surface"/><category scheme="http://www.blogger.com/atom/ns#" term="operational resilience"/><category scheme="http://www.blogger.com/atom/ns#" term="Zero Trust"/><title type='text'>Adaptive Security Leadership in an Expanding Threat Surface</title><content type='html'>&lt;p class=&quot;p1&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Last week I joined fellow security leaders at&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://www.inspiredbusinessmedia.com/summit/ciso-inspired-summit-uk-north-2026&quot; style=&quot;font-family: arial;&quot; target=&quot;_blank&quot;&gt;CISO Inspire Summit North&lt;/a&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&amp;nbsp;for a panel discussion on&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;&lt;i&gt;The Expanding Threat Surface: Adaptive Security Leadership for 2026 and Beyond&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;p1&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh27v7IZK03Vb36u_LC07VCptwHIunDsgM5SEuYV8TLf0kjHEOK8qGM3X7ChH7e49992fPXh-nknGnXu6_Hs8luJtYsqZKX65M0d_ypVmRtR7iZnUTP12Pts3YQ7n_pSKKDfCY1t5S-TKZqH_unDTGfYcN1LrMrIkXF3_eZPQAf_yZrj0EBuA4uToaqVRdn/s1792/Screenshot%202026-04-29%20at%2014.29.56.png&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;816&quot; data-original-width=&quot;1792&quot; height=&quot;146&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh27v7IZK03Vb36u_LC07VCptwHIunDsgM5SEuYV8TLf0kjHEOK8qGM3X7ChH7e49992fPXh-nknGnXu6_Hs8luJtYsqZKX65M0d_ypVmRtR7iZnUTP12Pts3YQ7n_pSKKDfCY1t5S-TKZqH_unDTGfYcN1LrMrIkXF3_eZPQAf_yZrj0EBuA4uToaqVRdn/s320/Screenshot%202026-04-29%20at%2014.29.56.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;It was a timely discussion, because the challenge facing security leaders today is not simply more threats. It is more connections, more dependencies, and more complexity. Suppliers, SaaS, identities, automation and distributed ways of working have all expanded the attack surface in ways that traditional control models often struggle to keep pace with.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;p1&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;One theme I returned to during the discussion was that many cyber risks are not new. They are often familiar control failures appearing at greater scale and speed.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That matters, because it shifts the focus from chasing every emerging technology risk to strengthening fundamentals.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Security fundamentals still matter most&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Identity, ownership, visibility and resilience remain foundational.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;As organisations scale, risk often hides where ownership is unclear, where no one truly owns a critical service, a supplier dependency, or a privileged access path.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Adaptive security leadership is not simply about adding more controls. It is about making sure the right controls are owned, evidenced, validated and able to hold under pressure.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Visibility alone is not assurance&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Another discussion point was the danger of equating visibility with confidence.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Dashboards can inform. They do not, on their own, assure.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Confidence should come not just from seeing controls, but from evidence they work in practice.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That distinction matters even more as regulatory expectations increase and boards ask harder questions about resilience, not merely compliance.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;p1&quot;&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJjEQjs26VU8pm39cpCPOzuJoZEWFKwKCvpEv7GZziPI0bNHHozsGSbwJhKyiiKAxuJAlAGqIDt3jNqxzZAg1TG6We4M8znMfdejYNphZ0r8BoaE4FwKrmGEMjpLY-k_Cj9n2XcUvidylGiMgjMD2xLdJZmeSx5aCc0eKjX5E6wbcLyJEAinSBye-QIaH-/s585/IMG_9054.jpeg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;438&quot; data-original-width=&quot;585&quot; height=&quot;240&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJjEQjs26VU8pm39cpCPOzuJoZEWFKwKCvpEv7GZziPI0bNHHozsGSbwJhKyiiKAxuJAlAGqIDt3jNqxzZAg1TG6We4M8znMfdejYNphZ0r8BoaE4FwKrmGEMjpLY-k_Cj9n2XcUvidylGiMgjMD2xLdJZmeSx5aCc0eKjX5E6wbcLyJEAinSBye-QIaH-/s320/IMG_9054.jpeg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Complexity is becoming a risk in itself&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;One point raised during the panel was that we may sometimes over-engineer controls while under-investing in fundamentals.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Complexity can create blind spots.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Adaptive leadership often means simplifying security, making the secure path the default, and reducing friction rather than adding layers that become difficult to sustain.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;In many cases resilience improves not through more complexity, but through clearer ownership, stronger validation and simpler control design.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Zero Trust is a direction, not a destination&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;We also touched on Zero Trust, which is often discussed as an architectural ambition.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;I tend to see it more practically.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Strong identity, least privilege, continuous validation and measurable progress matter far more than treating Zero Trust as a finished state.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;It is less a destination than a discipline.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;One practical takeaway&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;If there was one practical action I would emphasise, it would be this:&lt;/span&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Make ownership explicit for critical services, then test one real failure end-to-end.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That often reveals more about operational resilience than many reporting packs ever will.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Turning assumptions into proven resilience remains one of the most important shifts organisations can make.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;b style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Final reflection&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;A strong message from the session was that adaptive security leadership today is increasingly about judgement, accountability and evidence.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Not just technology.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Not just compliance.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;But proving controls hold when conditions are less than perfect.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;That is where confidence is built.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Thanks again to the organisers, moderator and fellow panellists for a thoughtful discussion.&lt;/span&gt;&lt;p&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/5989823000218394804/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/5989823000218394804' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5989823000218394804'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5989823000218394804'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/04/adaptive-security-leadership-in.html' title='Adaptive Security Leadership in an Expanding Threat Surface'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh27v7IZK03Vb36u_LC07VCptwHIunDsgM5SEuYV8TLf0kjHEOK8qGM3X7ChH7e49992fPXh-nknGnXu6_Hs8luJtYsqZKX65M0d_ypVmRtR7iZnUTP12Pts3YQ7n_pSKKDfCY1t5S-TKZqH_unDTGfYcN1LrMrIkXF3_eZPQAf_yZrj0EBuA4uToaqVRdn/s72-c/Screenshot%202026-04-29%20at%2014.29.56.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-4009522188605541244</id><published>2026-04-26T13:08:39.367+01:00</published><updated>2026-04-26T13:08:39.368+01:00</updated><title type='text'>AI Agents, Security Culture and a Conversation at Abbey Road Studios</title><content type='html'>&lt;span style=&quot;font-family: arial;&quot;&gt;I recently joined a panel at the iconic Abbey Road Studios to discuss a provocative theme: &lt;i&gt;Your AI agent doesn’t care about your security culture.&amp;nbsp;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGPRxRMWBp8xkjfagD7S6V1Cu8ZSU9UP3a1alVf-71jdt7bs8AtsEjarxAgFJz-nQI6g2Y9h5U5z1bjJ_-QSc4oxGbsin_hUJRfdes8VQl8Xj2W_QzcQRDXbctnUxGICSkDl68l-JfOixukIEXFyrqNJ3tyf1Vzg3iudy_LjPxHeCR3fxk4sgOqajCFVGc/s1372/37E9AA24-546C-4BC5-977A-EF26FCBD229E.jpeg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1146&quot; data-original-width=&quot;1372&quot; height=&quot;267&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGPRxRMWBp8xkjfagD7S6V1Cu8ZSU9UP3a1alVf-71jdt7bs8AtsEjarxAgFJz-nQI6g2Y9h5U5z1bjJ_-QSc4oxGbsin_hUJRfdes8VQl8Xj2W_QzcQRDXbctnUxGICSkDl68l-JfOixukIEXFyrqNJ3tyf1Vzg3iudy_LjPxHeCR3fxk4sgOqajCFVGc/s320/37E9AA24-546C-4BC5-977A-EF26FCBD229E.jpeg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://hottopics.ht/hottopics-studio-abbey-road-studios&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;HotTopics Studio: Abbey Road Studios Event&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;It captures an important truth. AI will often scale the quality of the environment it is given, whether that environment is built on strong governance and effective controls, or weak assumptions and poor oversight. &lt;br /&gt;&lt;br /&gt;One of the themes explored was accountability. As organisations move from experimenting with AI to operationalising it, the challenge is not only what AI can do, but who governs it, how outcomes are verified, and how control effectiveness keeps pace. &lt;br /&gt;&lt;br /&gt;My own takeaway was simple: &lt;b&gt;AI does not compensate for weak controls. It can amplify them. &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;A fitting discussion in an iconic setting.&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/4009522188605541244/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/4009522188605541244' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/4009522188605541244'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/4009522188605541244'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/04/ai-agents-security-culture-and.html' title='AI Agents, Security Culture and a Conversation at Abbey Road Studios'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGPRxRMWBp8xkjfagD7S6V1Cu8ZSU9UP3a1alVf-71jdt7bs8AtsEjarxAgFJz-nQI6g2Y9h5U5z1bjJ_-QSc4oxGbsin_hUJRfdes8VQl8Xj2W_QzcQRDXbctnUxGICSkDl68l-JfOixukIEXFyrqNJ3tyf1Vzg3iudy_LjPxHeCR3fxk4sgOqajCFVGc/s72-c/37E9AA24-546C-4BC5-977A-EF26FCBD229E.jpeg" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-2884657060875187324</id><published>2026-03-25T23:58:00.006+00:00</published><updated>2026-03-26T00:05:56.529+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="data centres"/><category scheme="http://www.blogger.com/atom/ns#" term="MSP"/><category scheme="http://www.blogger.com/atom/ns#" term="NCSC"/><category scheme="http://www.blogger.com/atom/ns#" term="NIS"/><category scheme="http://www.blogger.com/atom/ns#" term="NIS2"/><category scheme="http://www.blogger.com/atom/ns#" term="supply-chain"/><title type='text'>What the UK Cyber Security &amp; Resilience Bill Means for Security Practitioners</title><content type='html'>&lt;style&gt;
.csrb-post { font-family: &#39;Georgia&#39;, serif; max-width: 760px; margin: 0 auto; color: #1a1a2e; line-height: 1.8; font-size: 17px; }
.csrb-label { display: inline-block; background: #c0392b; color: #fff; font-family: monospace; font-size: 11px; letter-spacing: 0.12em; text-transform: uppercase; padding: 4px 12px; border-radius: 2px; margin-bottom: 16px; }
.csrb-title { font-family: &#39;Georgia&#39;, serif; font-size: clamp(22px, 4vw, 34px); font-weight: 700; color: #1a3a5c; line-height: 1.25; margin: 0 0 10px; }
.csrb-meta { font-size: 13px; color: #718096; font-family: monospace; margin-bottom: 28px; }
.csrb-hero-img { width: 100%; height: auto; display: block; border: 3px solid #1a3a5c; border-radius: 4px; margin-bottom: 8px; }
.csrb-hero-cap { font-size: 12px; color: #718096; font-style: italic; text-align: center; margin-bottom: 32px; }
.csrb-post p { margin-bottom: 1.4em; }
.csrb-post h2 { font-family: monospace; font-size: clamp(15px, 2.5vw, 19px); font-weight: 700; color: #1a3a5c; margin: 2.2em 0 0.6em; padding-left: 14px; border-left: 4px solid #c0392b; line-height: 1.3; }
.csrb-callout { background: #f7f7f7; border: 1px solid #ddd; border-left: 5px solid #c0392b; border-radius: 4px; padding: 18px 22px; margin: 28px 0; font-size: 15px; color: #4a5568; }
.csrb-callout strong { color: #1a1a2e; display: block; margin-bottom: 6px; font-family: monospace; font-size: 12px; text-transform: uppercase; letter-spacing: 0.08em; }
.csrb-penalty { background: #1a3a5c; color: #fff; border-radius: 6px; padding: 22px 26px; margin: 28px 0; }
.csrb-penalty h3 { font-family: monospace; font-size: 12px; text-transform: uppercase; letter-spacing: 0.1em; margin-bottom: 14px; opacity: 0.75; }
.csrb-penalty ul { list-style: none; padding: 0; margin: 0; }
.csrb-penalty ul li { padding: 8px 0; border-bottom: 1px solid rgba(255,255,255,0.15); font-size: 15px; }
.csrb-penalty ul li:last-child { border-bottom: none; }
.csrb-penalty ul li span { font-family: monospace; font-weight: 700; font-size: 18px; display: block; color: #f6ad55; }
.csrb-checklist { list-style: none; padding: 0; margin: 14px 0 22px; }
.csrb-checklist li { padding: 10px 0 10px 32px; position: relative; border-bottom: 1px solid #e2e8f0; font-size: 15.5px; }
.csrb-checklist li:last-child { border-bottom: none; }
.csrb-checklist li::before { content: &#39;→&#39;; position: absolute; left: 6px; color: #c0392b; font-family: monospace; font-weight: 700; }
.csrb-rule { border: none; border-top: 2px solid #e2e8f0; margin: 36px 0; }
.csrb-post a { color: #c0392b; text-decoration: underline; font-weight: 500; }
.csrb-post a:hover { color: #1a3a5c; }
.csrb-tags-label { font-family: monospace; font-size: 11px; text-transform: uppercase; letter-spacing: 0.12em; color: #718096; margin: 28px 0 10px; border-top: 2px solid #e2e8f0; padding-top: 24px; }
.csrb-tags { display: flex; flex-wrap: wrap; gap: 8px; }
.csrb-tag { background: #edf2f7; color: #1a3a5c; font-family: monospace; font-size: 11px; padding: 4px 10px; border-radius: 2px; border: 1px solid #cbd5e0; letter-spacing: 0.05em; text-transform: uppercase; }
@media (max-width: 600px) {
  .csrb-post { font-size: 16px; }
  .csrb-penalty { padding: 16px 18px; }
}
&lt;/style&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The UK Cyber Security &amp;amp; Resilience Bill is progressing through Parliament Royal Assent expected later in 2026.&lt;/span&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijZ6xEz4ZiENo8UPx78TyjrJFGfZDSvZZmX6njqCKwIMjyO_Kf5MzmnfqYMXCarsR8qCOWdB7FNqZXdubQXHxYqgQtTUvwplXIfPt9DWWvgaiXHdeXYzKEYoZ5wIMa9gAW2c6RVSccRqyeyYUg0aG1GSXUYUrDUCfM1vhapLWV4c3nP6v9TC10Af4QYmi5/s1536/F70B1EE8-570A-4A2A-B576-7BBC64FB3CFF.png&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijZ6xEz4ZiENo8UPx78TyjrJFGfZDSvZZmX6njqCKwIMjyO_Kf5MzmnfqYMXCarsR8qCOWdB7FNqZXdubQXHxYqgQtTUvwplXIfPt9DWWvgaiXHdeXYzKEYoZ5wIMa9gAW2c6RVSccRqyeyYUg0aG1GSXUYUrDUCfM1vhapLWV4c3nP6v9TC10Af4QYmi5/s320/F70B1EE8-570A-4A2A-B576-7BBC64FB3CFF.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;The UK&#39;s Cyber Security and Resilience Bill is working its way through Parliament, and if you haven&#39;t started paying serious attention yet, now is the time. Introduced to the House of Commons in November 2025, the Bill represents the most significant overhaul of UK cyber regulation since the &lt;a href=&quot;https://www.gov.uk/government/collections/nis-directive-and-nis-regulations-2018&quot; target=&quot;_blank&quot;&gt;NIS Regulations&lt;/a&gt; in 2018,  and its implications for security practitioners are immediate and practical.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;What&#39;s Actually Changing &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;At its core, the Bill expands the existing Network and Information Systems regulatory framework. It brings more organisations into scope, imposes stricter incident notification requirements, and hands regulators substantially more enforcement power. Secondary legislation and statutory Codes of Practice will follow, but the primary architecture of what you&#39;ll be working within is already taking shape. &lt;br /&gt;&lt;br /&gt;One of the most significant shifts for practitioners working in or alongside managed services is the creation of a new regulated entity category: the Relevant Managed Service Provider (RMSP). For the first time, MSPs providing services to in-scope sectors face direct regulatory obligations. If your organisation is an MSP, or relies heavily on one, your compliance exposure has materially changed.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;⚠ Key Point - Incident Reporting Timelines&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&amp;nbsp;The Bill introduces two-stage incident reporting: &lt;b&gt;an initial notification within 24 hours and a full report within 72 hours,&lt;/b&gt; with copies sent to the &lt;a href=&quot;https://www.ncsc.gov.uk/&quot; target=&quot;_blank&quot;&gt;NCSC&lt;/a&gt;. Your detection, triage, and escalation workflows need to meet these timelines under real pressure, not just on paper. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;P&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;enalties That Command Attention&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The financial exposure for non-compliance is substantial and should feature prominently in any board-level conversation about investment in cyber controls. &lt;br /&gt; &lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;Maximum Penalty Structure &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Standard maximum penalty - £10m or 2% of global turnover &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Higher maximum (serious breaches) - £17m or 4% of worldwide turnover &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Continuing contraventions (daily) - Up to £100,000 per day &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Extended ceiling (exceptional cases) - Up to 10% of worldwide turnover &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;These are not hypothetical. Regulators will also gain cost recovery powers, able to levy periodic fees to fund their oversight activities. Expect more active enforcement, not passive monitoring.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;UK vs NIS2: Don&#39;t Assume Alignment &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;If your organisation already operates under the &lt;a href=&quot;https://www.mayerbrown.com/en/insights/publications/2026/03/united-kingdom-proposes-changes-in-the-cyber-security-and-resilience-bill-to-the-nis-regulations-with-key-differences-to-nis2&quot;&gt;EU&#39;s NIS2 framework&lt;/a&gt;, a critical warning: the UK Bill and NIS2 share objectives but diverge in material ways. Reporting thresholds differ, customer notification requirements differ, and the sectors in scope are structured differently. A NIS2-aligned incident response playbook will not automatically satisfy UK obligations. &lt;br /&gt;&lt;br /&gt;Practitioners managing cross-border environments will need jurisdiction-specific runbooks. A single process attempting to satisfy both simultaneously risks failing both under pressure. &lt;br /&gt;Supply Chain Risk Is Now Statutory &lt;br /&gt;&lt;br /&gt;The Bill introduces the concept of designated &quot;&lt;a href=&quot;https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/designating-critical-suppliers&quot;&gt;critical suppliers&lt;/a&gt;&quot; organisations whose compromise could cause major disruption to the economy or wider society, even if they are not themselves regulated entities. These suppliers will receive formal written notice and will have the right to make representations or appeal. &lt;br /&gt;&lt;br /&gt;Secondary legislation will likely impose specific &lt;a href=&quot;https://www.gov.uk/government/publications/strengthening-supply-chain-cyber-security-at-the-mhra/strengthening-supply-chain-cyber-security-at-the-mhra&quot;&gt;supply chain security&lt;/a&gt; obligations on regulated entities potentially including contractual requirements, security assessments, and continuity planning mandates. The era of passing a questionnaire and considering supply chain risk managed is ending.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;🔗 Supply Chain Reality Check&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Without consolidated visibility across cloud platforms, SaaS providers, and outsourced partners, your compliance posture is built on assumptions, not evidence. The Bill will expose that gap when regulators come calling. &lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;What Practitioners Should Do Now &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;The Bill has passed its Report Stage in the Commons and is heading to the House of Lords. Royal Assent is expected later in 2026. Waiting for the final text before acting is not a defensible position. &lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Determine whether your organisation or key MSPs fall into newly in-scope categories, including &lt;a href=&quot;https://www.gov.uk/government/publications/cyber-security-and-resilience-network-and-information-systems-bill-factsheets/data-centres&quot; target=&quot;_blank&quot;&gt;data centres with Rated IT Load above 1 MW&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Review incident detection and escalation workflows against the 24-hour initial notification requirement &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Map divergence between your current NIS/NIS2 compliance posture and what the UK Bill will require &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Audit your supplier assurance programme, move beyond annual questionnaires towards continuous oversight &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Engage legal, compliance, and operational teams together; this cannot be owned by security alone &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Monitor the Bill&#39;s progress and watch for secondary legislation, which will contain the operational detail &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;The regulatory environment for UK cyber security is shifting substantially. The organisations best placed when the Bill receives Royal Assent will be those treating this as a live operational project, not a future compliance task.  &lt;br /&gt;&lt;br /&gt; Track the Bill&#39;s progress via the &lt;a href=&quot;https://bills.parliament.uk/bills/4035&quot; target=&quot;_blank&quot;&gt;UK Parliament Bills tracker&lt;/a&gt; and the &lt;a href=&quot;https://commonslibrary.parliament.uk/research-briefings/cbp-10442/&quot; target=&quot;_blank&quot;&gt;House of Commons Library briefing&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/2884657060875187324/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/2884657060875187324' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/2884657060875187324'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/2884657060875187324'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/03/what-uk-cyber-security-resilience-bill.html' title='What the UK Cyber Security &amp; Resilience Bill Means for Security Practitioners'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijZ6xEz4ZiENo8UPx78TyjrJFGfZDSvZZmX6njqCKwIMjyO_Kf5MzmnfqYMXCarsR8qCOWdB7FNqZXdubQXHxYqgQtTUvwplXIfPt9DWWvgaiXHdeXYzKEYoZ5wIMa9gAW2c6RVSccRqyeyYUg0aG1GSXUYUrDUCfM1vhapLWV4c3nP6v9TC10Af4QYmi5/s72-c/F70B1EE8-570A-4A2A-B576-7BBC64FB3CFF.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-6352845280295999176</id><published>2026-03-19T07:00:00.000+00:00</published><updated>2026-03-19T10:54:01.105+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Business Impact Analysis"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber insurance"/><category scheme="http://www.blogger.com/atom/ns#" term="data breach"/><category scheme="http://www.blogger.com/atom/ns#" term="ransomware"/><category scheme="http://www.blogger.com/atom/ns#" term="Recovery Time Objectives"/><category scheme="http://www.blogger.com/atom/ns#" term="Service Availability"/><title type='text'> The True Cost of Cyber Downtime: A UK Board-Level Briefing</title><content type='html'>&lt;p align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm; text-align: center;&quot;&gt;&lt;i&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Written by Sean Tilley, Senior Sales Director EMEA at&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;a class=&quot;outlook-break-word-in-links&quot; data-linkindex=&quot;1&quot; data-outlook-id=&quot;8a60981c-0ec3-46ec-bbf2-74c0bd31a926&quot; href=&quot;https://1111systems.com/&quot; style=&quot;color: #96607d; word-break: break-word;&quot; target=&quot;_blank&quot;&gt;&lt;i&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: #467886; font-size: 11pt; line-height: 17.709999px;&quot;&gt;11:11 Systems&lt;/span&gt;&lt;/i&gt;&lt;/a&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm; text-align: center;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Cyber downtime carries measurable financial consequences, and those consequences are becoming clearer with each major incident.&amp;nbsp;&lt;/span&gt;&lt;a class=&quot;outlook-break-word-in-links&quot; data-linkindex=&quot;2&quot; data-outlook-id=&quot;db8b1918-9a79-46d7-946a-bb7e8ecd748b&quot; href=&quot;https://1111systems.com/resources/1111-systems-research-it-leaders-struggle-with-cyberattack-complexity-emea/&quot; style=&quot;color: #96607d; word-break: break-word;&quot; target=&quot;_blank&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: #467886; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Research from 11:11 Systems&lt;/span&gt;&lt;/a&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;shows that 78% of European organisations report losses of up to $500,000 per hour following a cyber-related outage, while 6% face costs exceeding £1 million per hour. When recovery extends beyond containment, the disruption begins to register in revenue performance, contractual exposure, and customer stability rather than remaining confined to the technology function.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_0qnycD3zHJR0VU0b9HYQT4E0LwQMkpNptredqN6MYsrsSewO945ZqtDJVTeFoEqwRmVky5wymlb6FHywOswMCjPeF23WwkEP1DWo-sac_ASuRzxt89TH1ZR4zIxTYIrnxrxsNHnMvDQLwh4kPOnTmX3E1DDNe1G2Dhio0DxfvG1jYC0ReNlt0_rdipxm/s1536/89C309D0-40C2-46BE-9661-09571C98226A.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1024&quot; data-original-width=&quot;1536&quot; height=&quot;213&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_0qnycD3zHJR0VU0b9HYQT4E0LwQMkpNptredqN6MYsrsSewO945ZqtDJVTeFoEqwRmVky5wymlb6FHywOswMCjPeF23WwkEP1DWo-sac_ASuRzxt89TH1ZR4zIxTYIrnxrxsNHnMvDQLwh4kPOnTmX3E1DDNe1G2Dhio0DxfvG1jYC0ReNlt0_rdipxm/s320/89C309D0-40C2-46BE-9661-09571C98226A.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;For UK leadership teams, the issue centres on continuity of income, fulfilment of obligations, and the strength of customer relationships under strain.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;b&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Recovery delays compound risk&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Half of organisations surveyed require between one and two weeks to fully recover from a cyber incident. Over that period, cost exposure builds in ways that are rarely reflected in early estimates.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Revenue stalls, particularly where digital platforms underpin billing and subscriptions, while service commitments are breached, supply chains experience secondary disruption, and internal teams divert time and budget away from planned initiatives towards remediation and communications.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Extended recovery places additional pressure on customer relationships, especially in sectors where availability is assumed as standard. Regulatory scrutiny increases in parallel, particularly under UK GDPR and sector-specific resilience requirements, where organisations must demonstrate that appropriate safeguards were established before the incident occurred.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;A significant proportion of the cost emerges over time rather than immediately. Insurance premiums adjust at renewal, forensic specialists and legal advisers remain engaged, customer notification programmes continue long after systems are restored, and remediation work extends into future quarters. By the time the full impact is visible, the loss total often exceeds initial projections.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;According to&amp;nbsp;&lt;/span&gt;&lt;a class=&quot;outlook-break-word-in-links&quot; data-linkindex=&quot;3&quot; data-outlook-id=&quot;64449544-f7a5-4cfd-8a32-faaf49a86532&quot; href=&quot;https://cybermonitoringcentre.com/2025/10/22/cyber-monitoring-centre-statement-on-the-jaguar-land-rovercyber-incident-october-2025/?utm_source=chatgpt.com&quot; style=&quot;color: #96607d; word-break: break-word;&quot; target=&quot;_blank&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: #467886; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Cyber Monitoring Centre&lt;/span&gt;&lt;/a&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;recent UK attacks across retail, healthcare and critical infrastructure have collectively cost businesses more than £1.9 billion. At an individual level, even a contained incident can translate into multi-million-pound losses once revenue interruption, remediation spend and longer-term customer attrition are properly accounted for.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Recovery time remains the decisive variable, steadily increasing commercial strain and regulatory attention the longer disruption persists.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;For boards, cyber downtime is no longer a technical failure but a test of governance. In the immediate aftermath of an incident, external scrutiny rarely focuses on how the attack occurred. Instead, attention turns to whether leadership understood its exposure, validated recovery assumptions and exercised informed oversight before disruption struck. Where recovery falters, questions follow around board assurance, investment prioritisation and whether resilience was treated as a compliance exercise rather than a core commercial safeguard worthy of sustained board attention. In that context, prolonged downtime can quickly become a proxy for broader leadership risk.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;b&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;The preparedness gap&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Despite recent high-profile incidents, many organisations still overestimate their ability to recover.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Backup environments may exist without having been stress-tested under realistic conditions, recovery objectives are documented but rarely validated, crisis governance structures that appear clear on paper can lose coherence under pressure and visibility across cloud platforms, SaaS providers, and outsourced partners frequently remains incomplete.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Modern enterprises operate across layered digital ecosystems that depend on managed services, third-party infrastructure, and interconnected suppliers, each introducing dependencies that may sit outside direct oversight. Without a consolidated view of these relationships, recovery planning remains fragmented and assumptions around restoration timelines tend to be optimistic rather than proven. When those assumptions fail, cost exposure accelerates quickly.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;b&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Resilience as a strategic advantage&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;The organisations that recover fastest are rarely those with the most technology, but those with the clearest decision rights. During major incidents, value is lost less through system failure than through delayed executive judgement such as uncertainty over who authorises restoration priorities, how customer communications are sequenced, and which commercial trade-offs are acceptable under pressure. Boards that rehearse these decisions in advance shorten recovery by eliminating hesitation at the moment it matters most. In competitive markets, that decisiveness increasingly separates resilient businesses from those that merely survive disruption.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Containing the cost of downtime requires disciplined preparation rather than reactive response.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Scenario-based recovery testing that includes executive leadership brings clarity to decision-making authority, communication sequencing and operational prioritisation, while tabletop exercises expose governance gaps before they are tested in live conditions.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Disaster Recovery as a Service can materially reduce restoration timelines where isolated environments and immutable backups are properly implemented. Equal attention should be given to external dependencies, with clear understanding of partner capabilities, escalation paths, and recovery commitments established in advance of disruption.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Effective resilience planning therefore extends across internal systems, cloud providers, and supply chain partners, ensuring that recovery capability is aligned rather than siloed.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Preparation does not prevent incidents, but it materially reduces their financial and operational impact.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;b&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;What This Means for Boards&lt;/span&gt;&lt;/b&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;The commercial exposure created by cyber downtime is now quantifiable and, in many cases, escalating. The central question for boards is how effectively the organisation can absorb disruption without sustained damage to revenue, customer trust or regulatory standing.&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;-webkit-text-size-adjust: 105%; caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16.799999px; line-height: 19.32px; margin: 0cm;&quot;&gt;&lt;span face=&quot;Calibri, sans-serif&quot; style=&quot;color: black; font-size: 11pt; line-height: 17.709999px;&quot;&gt;Organisations that embed recovery capability into broader business planning place themselves in a stronger position to manage that exposure with discipline, control and credibility.&lt;/span&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/6352845280295999176/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/6352845280295999176' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/6352845280295999176'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/6352845280295999176'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/03/the-true-cost-of-cyber-downtime-uk.html' title=' The True Cost of Cyber Downtime: A UK Board-Level Briefing'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_0qnycD3zHJR0VU0b9HYQT4E0LwQMkpNptredqN6MYsrsSewO945ZqtDJVTeFoEqwRmVky5wymlb6FHywOswMCjPeF23WwkEP1DWo-sac_ASuRzxt89TH1ZR4zIxTYIrnxrxsNHnMvDQLwh4kPOnTmX3E1DDNe1G2Dhio0DxfvG1jYC0ReNlt0_rdipxm/s72-c/89C309D0-40C2-46BE-9661-09571C98226A.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-375186489714219307</id><published>2026-03-16T00:30:00.030+00:00</published><updated>2026-03-16T00:30:00.124+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Accenture"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber"/><category scheme="http://www.blogger.com/atom/ns#" term="cyber risk"/><category scheme="http://www.blogger.com/atom/ns#" term="HR"/><category scheme="http://www.blogger.com/atom/ns#" term="Insider Threat"/><category scheme="http://www.blogger.com/atom/ns#" term="Microsoft"/><category scheme="http://www.blogger.com/atom/ns#" term="Ponemon Institute"/><title type='text'>When insider risk is a wellbeing issue, not just a disciplinary one</title><content type='html'>&lt;span style=&quot;font-family: arial;&quot;&gt;Written by Katie Barnett, Director of Cyber Security at &lt;a href=&quot;https://www.torosolutions.co.uk/&quot;&gt;Toro Solutions&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Insider risk is still often framed around intent, with the focus placed on malicious employees, disgruntled contractors, or deliberate misuse of access for personal gain.&lt;br /&gt;Those cases exist and they matter, but they are rarely where risk first begins, and they do not reflect how most insider-related incidents actually develop.&lt;br /&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAPVP7BVlhCMtLcZPdGY5DXMwnSy0x4lrWRhW27rhPeAQm8YXOEmtx0FTj2OjuCM-KOAxMUfZfsqhi5LVxos-wz5oCNVWqhp9LOlPSrfO2hzdpcr5xFTiZ_Y2xRqZM0n6vMjtYyiAWpvcNQGKAROg_kE9VHdlAvqZahaWXfPjilYEvO84btNIUHZh0aqQh/s1536/insider-risk.png&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAPVP7BVlhCMtLcZPdGY5DXMwnSy0x4lrWRhW27rhPeAQm8YXOEmtx0FTj2OjuCM-KOAxMUfZfsqhi5LVxos-wz5oCNVWqhp9LOlPSrfO2hzdpcr5xFTiZ_Y2xRqZM0n6vMjtYyiAWpvcNQGKAROg_kE9VHdlAvqZahaWXfPjilYEvO84btNIUHZh0aqQh/s320/insider-risk.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;In reality, many cases take shape slowly and quietly.  They are shaped by pressure, fatigue, disengagement, coercion, manipulation or personal strain rather than hostility. The behaviour that later causes harm is often preceded by long periods of stress, isolation, being influenced or unresolved workplace issues. By the time someone is formally labelled an insider threat,the opportunity for early, proportionate support has usually passed, and the organisation is left with far fewer options.&lt;br /&gt;&lt;br /&gt;This is why treating insider risk purely as a disciplinary or compliance issue consistently falls short. In many situations, the underlying issue is one of wellbeing first, with security consequences following later, whether the organisation recognises that link or not.&lt;/span&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;The scale of the problem&lt;/b&gt;&lt;/span&gt;&lt;/h3&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Insiders are a significant and consistent factor in security incidents. Accenture&lt;a href=&quot;file:///Applications/Microsoft%20Outlook.app/Contents/Frameworks/EmailRendererKit.framework/Resources/reactRenderer_mac.html#_ftn1&quot;&gt;[1]&lt;/a&gt; has reported that a significant proportion of security incidents involve insiders, many of which are linked not to sophisticated intent, but to frustration, opportunism, or poor judgement under pressure.&lt;br /&gt;&lt;br /&gt;Research from the Ponemon Institute&lt;a href=&quot;file:///Applications/Microsoft%20Outlook.app/Contents/Frameworks/EmailRendererKit.framework/Resources/reactRenderer_mac.html#_ftn2&quot;&gt;[2]&lt;/a&gt; also shows that many employees who leave an organisation take some form of sensitive data with them, often without seeing it as wrongdoing. These findings do not mean that most people are inherently risky. They show how easily people can justify their actions when they feel unsupported, unheard, or under strain.&lt;br /&gt;&lt;br /&gt;Despite this, insider risk is still often pushed aside or handled in isolation. In many organisations it moves between HR, security, and legal teams without a shared understanding of what is really driving behaviour. When this happens, patterns are missed and early warning signs become normal, until a more serious incident finally brings the issue to senior attention.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;How insider risk really develops&lt;/span&gt;&lt;/h3&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Insider risk rarely begins with a clear breach of policy. More often we find that it develops incrementally through small changes in behaviour that are easy to explain away, particularly in high-pressure or highly trusted roles.&lt;br /&gt;&lt;br /&gt;Someone may start working excessive hours to manage workload, gradually bypassing controls that feel obstructive rather than protective. They may disengage from colleagues, become defensive when challenged, or withdraw from routine interaction. None of this suggests malicious intent in isolation, but it often marks the point at which judgement can begin to erode.&lt;br /&gt;&lt;br /&gt;In roles with wide access and limited oversight, these issues can go unnoticed for a long time. As people grow more comfortable with the systems, informal shortcuts start to feel normal, and risk builds in the background. By the time leadership becomes aware, it’s often because something has already gone wrong.&lt;br /&gt;&lt;br /&gt;In some cases, the influence is external. Individuals may be targeted by criminals, competitors or organised groups who exploit personal vulnerabilities, financial stress or emotional pressure. This does not always look like blackmail or explicit threats. It can begin with flattery, requests for small favours, or appeals to sympathy, and gradually escalate into access, information sharing or rule-bending that feels difficult to refuse.&lt;br /&gt;&lt;br /&gt;Coercion does not always come from outside. In some environments it can arise internally through power imbalances, unrealistic expectations, or pressure from senior colleagues that makes it hard to say no without fear of consequences.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Connection without closeness&lt;/span&gt;&lt;/h3&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Modern ways of working have added a new layer of complexity. We are more digitally connected than ever, yet many people now experience their work in relative isolation. Messages replace face to face conversations, context gets lost, and informal check-ins happen far less often.&lt;br /&gt;&lt;br /&gt;Judgement does not exist in a vacuum. Stress, fatigue, and emotional strain shape how people interpret information and how carefully they make decisions. When pressure rises and support feels distant, people are more likely to misread situations, take shortcuts, or justify behaviour they would normally question.&lt;br /&gt;&lt;br /&gt;This is not just a wellbeing issue. It is a resilience issue. Emotional strain narrows perspective and makes people more open to influence, whether that influence comes from outside the organisation or from their own internal reasoning.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Why the wider environment matters&lt;/span&gt;&lt;/h3&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;These dynamics are being intensified by wider economic uncertainty. Prolonged cost-of-living pressures, geopolitical instability, and sustained disruption across global markets are all putting strain on individuals’ finances. &lt;br /&gt;&lt;br /&gt;Financial pressure affects how people behave. It makes it harder to focus, increases anxiety, and can reduce how seriously people think about consequences. Some may even feel they have little left to lose. This does not mean they intend to do harm, but it does raise risk, especially for those who have access to sensitive systems, information, or assets.&lt;br /&gt;&lt;br /&gt;From a security point of view, money stress increases risk. When organisations treat financial wellbeing as separate from security, they overlook an important part of the problem.&lt;br /&gt;&lt;br /&gt;Financial strain also increases susceptibility to manipulation. People under pressure are more likely to respond to offers of help, opportunities to “fix” problems quickly, or requests that promise relief from stress. From a security perspective, this creates conditions where coercion becomes easier and more effective, even when individuals have no intention of causing harm.&lt;br /&gt;Why controls alone are not enough&lt;br /&gt;&lt;br /&gt;When insider risk is identified, organisations often respond in a technical way by tightening access, increasing monitoring, and reinforcing policies, but while these actions are important, they rarely address the underlying conditions that allowed the risk to develop in the first place.&lt;br /&gt;&lt;br /&gt;Controls alone do not reduce burnout. Monitoring does not ease financial pressure, and policy reminders do not restore sound judgement. In some situations, a poorly timed escalation can actually increase feelings of mistrust or isolation, which pushes risk further underground instead of resolving it.&lt;br /&gt;&lt;br /&gt;Both research and practical experience show that behavioural warning signs often appear before any technical breach occurs, including changes in performance, disengagement, conflict with management, and financial difficulty, and when organisations wait until behaviour crosses a formal threshold, their options become limited and the consequences are usually far more severe.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;h3 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;What “support as prevention” looks like in practice&lt;/span&gt;&lt;/h3&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Support does not mean ignoring misconduct or lowering standards, but instead means expanding the prevention toolkit so organisations can step in earlier, when the impact is lower and when individuals still have realistic options.&lt;br /&gt;&lt;br /&gt;In practice, this often includes:&lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Clear, normalised escalation routes, so staff can raise concerns without automatically triggering a disciplinary process.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Line managers trained to notice and act on changes in behaviour, workload strain, or disengagement, and to involve the right functions early.&lt;/li&gt;&lt;li&gt;Shared ownership between HR, security, and operational leadership, so people risk does not fall between organisational boundaries.&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Proportionate, temporary risk management, such as short-term access adjustments or additional oversight while a personal issue is being addressed.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;This approach reflects the direction set out in UK protective security guidance, which emphasises treating insider events as connected, strengthening leadership understanding, and addressing the reasons insider risk is often deprioritised or avoided.&lt;br /&gt;Culture determines whether people speak up&lt;br /&gt;&lt;br /&gt;In many insider cases, colleagues notice warning signs but decide not to raise them because they worry about getting someone into trouble, triggering an investigation, or being seen as overreacting.&lt;br /&gt;&lt;br /&gt;Where people believe that raising concerns will lead to fair and supportive action, reporting becomes more likely, but where they expect blame or punishment, staying silent feels safer. &lt;br /&gt;&lt;br /&gt;This is not a training failure. It is a cultural one.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;h2 style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;A quieter form of prevention&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/h2&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The most effective insider risk programmes are often the least visible because they are built into everyday management practice, supported by leadership, and grounded in trust, and they recognise that people are both the greatest asset and the most complex part of any security system.&lt;br /&gt;&lt;br /&gt;In a world that is increasingly connected but emotionally fragmented, emotional and financial pressures are no longer side issues. They are part of the risk landscape.&lt;br /&gt;&lt;br /&gt;For organisations that are serious about resilience, insider risk must be understood not only through controls and compliance, but also through culture, support, and leadership judgement, and this shift does not weaken security. It strengthens it.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/375186489714219307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/375186489714219307' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/375186489714219307'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/375186489714219307'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/03/when-insider-risk-is-wellbeing-issue.html' title='When insider risk is a wellbeing issue, not just a disciplinary one'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgAPVP7BVlhCMtLcZPdGY5DXMwnSy0x4lrWRhW27rhPeAQm8YXOEmtx0FTj2OjuCM-KOAxMUfZfsqhi5LVxos-wz5oCNVWqhp9LOlPSrfO2hzdpcr5xFTiZ_Y2xRqZM0n6vMjtYyiAWpvcNQGKAROg_kE9VHdlAvqZahaWXfPjilYEvO84btNIUHZh0aqQh/s72-c/insider-risk.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-5816289324985666714</id><published>2026-03-13T00:02:00.002+00:00</published><updated>2026-03-13T00:02:56.429+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="AI"/><category scheme="http://www.blogger.com/atom/ns#" term="CISO"/><category scheme="http://www.blogger.com/atom/ns#" term="EU"/><category scheme="http://www.blogger.com/atom/ns#" term="GDPR"/><category scheme="http://www.blogger.com/atom/ns#" term="NIS2"/><category scheme="http://www.blogger.com/atom/ns#" term="SOC"/><category scheme="http://www.blogger.com/atom/ns#" term="UK"/><title type='text'> Building Trust in AI SOC Analyst Solutions: A UK and EU CISO Perspective</title><content type='html'>&lt;p&gt;&lt;i style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px;&quot;&gt;By Brett Candon, VP International at &lt;a href=&quot;https://www.dropzone.ai/&quot; target=&quot;_blank&quot;&gt;Dropzone AI&lt;/a&gt;&lt;/i&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Trust has always been critical in security operations, but in the UK and Europe it carries significant regulatory weight. GDPR, NIS2 and similar related data‑protection frameworks shape far more than legal risk, they directly influence architectural decisions, supplier selection, and how security data can be accessed, processed and reviewed. That becomes more pronounced as autonomous AI systems move from proof‑of‑concept to daily SOC tooling.&amp;nbsp;&lt;/p&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgz9-MtXS2WAv2iVnIiai6ZUhFR47ooJqPCcaS99jqEO_DsNSM5HvqXTSAVSBwatJamKVGKTyxkWjP-8j5gupKk8PisxNd2mKSp1PcONY_Slnh1RbC0H5d_wRgtODSMzq-ljesED0ZuyZ_1NPLW8Eg-ikk5B-Wjbkvqrh5mCtNg3Oplk0V2tR5tSTDerbN6/s1536/AISOCEUCISO.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1024&quot; data-original-width=&quot;1536&quot; height=&quot;213&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgz9-MtXS2WAv2iVnIiai6ZUhFR47ooJqPCcaS99jqEO_DsNSM5HvqXTSAVSBwatJamKVGKTyxkWjP-8j5gupKk8PisxNd2mKSp1PcONY_Slnh1RbC0H5d_wRgtODSMzq-ljesED0ZuyZ_1NPLW8Eg-ikk5B-Wjbkvqrh5mCtNg3Oplk0V2tR5tSTDerbN6/s320/AISOCEUCISO.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;The appeal is undeniable. Faster investigations, more consistent outcomes, and the ability to scale Tier‑1 response are all compelling. However, without clear answers on data flows, access and accountability, AI introduces risk as easily as it removes it. And speed alone does not result in trust.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Against this backdrop, AI‑native approaches to SOC operations are gaining traction, grounded in the idea that autonomy, transparency, and repeatability must be foundational design principles rather than retrofitted controls. These systems are positioned to investigate alerts end‑to‑end using agent‑based reasoning, producing structured, auditable outputs in minutes. If implemented with the right governance, this operating model has the potential to meet the elevated trust and accountability expectations that characterise UK and EU security environments.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;&lt;b&gt;Data Sensitivity Changes the Trust Model&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;However, as SOC data often contains personal data, whether in endpoint identifiers, usernames, IP mapping, or embedded message content, it requires a closer look at where the investigative work happens and who performs it. This is particularly true for UK and European users that must adhere to GDPR. If a platform relies on offshore human review behind the scenes, organisations may be exposing sensitive operational context to jurisdictions with different privacy standards.&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;As a result, interest in autonomous SOC analysis extends beyond speed and efficiency. It reflects a desire to reduce opaque manual processes and replace them with systems that can complete investigations independently, while still producing outputs that are auditable, jurisdictionally compliant. For UK and EU organisations, autonomy only builds trust when it removes uncertainty rather than creating new blind spots. Customers need to be in control of what the AI is investigating, have visibility of what it is doing and have control over the output.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;&lt;b&gt;Explainability and Accuracy Are Key Trust Factors&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;For CISOs, explainability forms the next pillar of trust. An alert closed in seconds means little if the underlying reasoning behind the decision cannot be reviewed. Boards, auditors and regulators increasingly expect security leaders to justify decisions with evidence. Investigation reports need to show what data was examined, which hypotheses were tested, and how conclusions were reached. AI systems that show this reasoning are far better suited to audit review, incident analysis, and regulatory inquiry than those that operate as black boxes.&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;As European AI regulatory frameworks move from legislative text to supervisory enforcement, CISOs should expect closer scrutiny of how AI‑assisted decisions are documented, monitored, and justified after the fact.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Accuracy is another key pillar of trust. European buyers are sceptical of headline claims that cannot be verified. False‑positive and false‑negative rates only matter if they hold up under real-world conditions. This has increased interest in evaluation models that allow security teams to test AI‑driven investigation capabilities against their own data, rather than relying solely on vendor‑curated demonstrations. In environments shaped by due diligence and evidence, the ability to validate claims independently is itself is a signal of trust.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;&lt;b&gt;From Alert Volume to Analyst Impact&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Strategically, the shift toward autonomous SOC operations goes beyond incremental optimisation. It reflects a broader move away from manpower‑bound, alert‑driven models toward operating frameworks that allow AI to absorb routine investigative workload and free experienced analysts to focus on high‑impact decisions.&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Advances in large language models and agent‑based reasoning have made this shift technically possible, while market pressure and workforce constraints have made it necessary. Importantly, industry research increasingly positions this transition as augmentation rather than replacement, a distinction that resonates strongly in European environments and balancing transformation with workforce responsibility.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;None of this removes buyer accountability. UK and EU CISOs still need to apply the same rigour they would to any high‑sensitivity platform, with questions tailored to AI’s specific risk. This starts with end-to-end data-flow transparency to where data is processed, what categories are ingested, and how artefacts are stored or discarded.&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;It also includes understanding whether investigative workflows involve human access outside approved jurisdictions. It requires assessing explainability through real investigation outputs including evidence citation, and decision traceability.&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Finally, it demands validation of accuracy and consistency under realistic conditions. Public metrics may provide context, but operational value is determined locally.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;&lt;b&gt;What Trust Looks Like Going Forward&lt;/b&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Trust builds over time. Market maturity, breadth of deployment, and exposure to real-world scrutiny all contribute to confidence in any emerging operating model. In conservative buying environments, these signals provide evidence that systems have been tested across varied conditions and constraints. Staged rollouts, reference checks, and contractual clarity remain best practice, particularly when incident response decisions may later be examined by regulators or courts.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Looking ahead, the question for UK and EU CISOs is no longer whether AI will play a role in the SOC – it already does – but how to deploy it without compromising sovereignty, privacy, or auditability. The path forward lies in autonomy that supports security teams by reducing opaque processes, investigations that make their reasoning visible, and performance claims that can be tested rather than taken on trust.&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;In a region where trust is both a security principle and a legal requirement, AI systems that are transparent in operation, verifiable in design, and accountable in outcome will earn their place at the centre of modern SOCs.&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/5816289324985666714/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/5816289324985666714' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5816289324985666714'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5816289324985666714'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/03/building-trust-in-ai-soc-analyst.html' title=' Building Trust in AI SOC Analyst Solutions: A UK and EU CISO Perspective'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgz9-MtXS2WAv2iVnIiai6ZUhFR47ooJqPCcaS99jqEO_DsNSM5HvqXTSAVSBwatJamKVGKTyxkWjP-8j5gupKk8PisxNd2mKSp1PcONY_Slnh1RbC0H5d_wRgtODSMzq-ljesED0ZuyZ_1NPLW8Eg-ikk5B-Wjbkvqrh5mCtNg3Oplk0V2tR5tSTDerbN6/s72-c/AISOCEUCISO.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-7019554549664841897</id><published>2026-03-08T23:57:00.007+00:00</published><updated>2026-03-09T00:35:11.784+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="AI"/><category scheme="http://www.blogger.com/atom/ns#" term="GRC"/><category scheme="http://www.blogger.com/atom/ns#" term="Policies"/><category scheme="http://www.blogger.com/atom/ns#" term="Third Party Security"/><title type='text'>AI Is Moving Faster Than Security Controls</title><content type='html'>&lt;p&gt;
  &lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-family: arial;&quot;&gt;&lt;b&gt;AI is entering organisations faster than the security controls designed
      to govern it.&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); font-family: arial;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIx_BM0R6L8GaBc6CG_3kcFwUM7vd1FrdcqU9VC9cHtdevOeElX6cgf8bEiLvN2kHvJLg6Z4KYlFWfIbtJjYtWlok-mZnV3JaHXOyjcKeKzuqQ8aCBRRapyQmYqRwenEczAg9wpw13hkmPLo_5enwfcp6bynnTbFQYwxcXkRnUJ9t1WyQ5g_bGwXY2OQqO/s1536/8024C750-F11A-4A43-B0FD-5CAB46254DD1.png&quot; style=&quot;margin-left: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1024&quot; data-original-width=&quot;1536&quot; height=&quot;213&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIx_BM0R6L8GaBc6CG_3kcFwUM7vd1FrdcqU9VC9cHtdevOeElX6cgf8bEiLvN2kHvJLg6Z4KYlFWfIbtJjYtWlok-mZnV3JaHXOyjcKeKzuqQ8aCBRRapyQmYqRwenEczAg9wpw13hkmPLo_5enwfcp6bynnTbFQYwxcXkRnUJ9t1WyQ5g_bGwXY2OQqO/s320/8024C750-F11A-4A43-B0FD-5CAB46254DD1.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0);&quot;&gt;Artificial intelligence is rapidly becoming embedded across organisations.&lt;br /&gt;&lt;br /&gt;AI assistants are now writing code, summarising documents, analysing data,
    and supporting operational decisions.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0);&quot;&gt;What began as experimentation is quickly becoming operational
    dependency.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0);&quot;&gt;For security teams, the challenge is not simply adopting AI. The real
    challenge is understanding how AI changes the way cybersecurity controls
    need to be validated.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0);&quot;&gt;In many organisations, AI tools are already interacting with corporate
    data, internal systems, and operational workflows.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0);&quot;&gt;Yet when security leaders ask a simple question&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0);&quot;&gt;“How do we know these AI systems are operating within our control
    boundaries?”&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0);&quot;&gt;…the answer is often less clear than expected.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0);&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span face=&quot;TimesNewRomanPS-BoldMT&quot; style=&quot;font-size: medium; font-weight: bold;&quot;&gt;Why AI Security Controls Are Different&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Traditional software behaves in predictable ways. Security teams can audit
    code, validate configuration, monitor logs, and confirm whether controls are
    operating as intended.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;AI systems behave differently.&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Modern AI models generate probabilistic outputs rather than deterministic
    ones. The same prompt may produce different responses, models can evolve
    through updates, and outputs may influence decisions that were never
    explicitly coded into the system.&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;This creates a shift in how security controls need to be assessed.&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Controls designed for traditional systems do not always translate neatly
    into AI-driven environments.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Examples are already appearing in practice:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI coding assistants generating insecure or non-compliant code&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Employees uploading confidential documents into AI tools&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI platforms accessing internal data through integrations&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI agents interacting with APIs or automation platforms beyond their
    intended scope&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;
  &lt;p&gt;&lt;/p&gt;



&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;In many cases, organisations technically have policies that cover these
    scenarios.&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;The real challenge is proving those policies are actually effective in
    practice.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium; font-weight: bold;&quot;&gt;The Growing Problem of Shadow AI&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Just as “Shadow IT” emerged when employees adopted unsanctioned cloud
    services, many organisations are now experiencing Shadow AI.&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;Employees are increasingly using AI tools independently to improve
    productivity. These tools often bypass procurement processes, security
    reviews, and governance frameworks&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Common examples include:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Uploading documents into AI summarisation tools&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Using AI assistants to analyse internal reports or spreadsheets&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Generating code snippets with public AI models&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Connecting AI plug-ins to automate existing workflows&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;
  &lt;p&gt;&lt;/p&gt;



&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;From a security perspective, this creates several unknowns.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Organisations may not know:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Which AI tools are being used&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;What data is being shared with them&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Whether prompts or outputs are stored externally&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;How AI-generated outputs influence operational decisions&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;
  &lt;p&gt;&lt;/p&gt;



&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;The result is a widening gap between policy intent and operational
    reality.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium; font-weight: bold;&quot;&gt;AI Governance Without Visibility&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Many organisations have already responded to AI risk by introducing
    policies, governance groups, or internal guidance.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;These are important foundations.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;But policy alone does not create assurance.&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;The real question is whether organisations can demonstrate that controls
    around AI usage are actually working.&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;That means being able to answer questions such as:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Do we know where AI tools are being used across the organisation?&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Can we detect when sensitive data is submitted to external AI
    services?&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Are AI-generated outputs influencing critical processes without
    validation?&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Do we monitor AI integrations and access permissions?&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;
  &lt;p&gt;&lt;/p&gt;



&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Without measurable answers, AI governance risks becoming another form of
    dashboard compliance.&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;Controls may appear compliant on paper but lack operational
    validation.&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium; font-weight: bold;&quot;&gt;Moving Toward Practical AI Security Assurance&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Organisations that are managing AI adoption successfully are beginning to
    treat AI risk in the same way they treat other critical security
    controls.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;The focus shifts from policy statements to evidence, monitoring, and
    validation.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Practical steps increasingly include:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Maintaining an inventory of approved AI systems&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Monitoring integrations and API activity&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Detecting data flows to external AI platforms&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Ensuring human oversight for critical AI outputs&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Continuously reviewing permissions and access scope&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;
  &lt;p&gt;&lt;/p&gt;




&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;These measures do not remove risk entirely.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;But they shift the conversation from:&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;“Do we have an AI policy?”&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;to the far more important question&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;“Can we prove our AI controls are working?&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;font-size: medium; font-weight: bold;&quot;&gt;The Next Cybersecurity Challenge&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Every major technology shift has forced organisations to rethink how
    security controls are validated.&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Cloud computing did.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;DevOps did.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;SaaS platforms did.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;AI is now doing the same.&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;The organisations that manage this transition successfully will not
    necessarily be those that deploy AI the fastest.&lt;/span&gt;&lt;span style=&quot;font-kerning: none;&quot;&gt;&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;They will be the ones that understand how to measure and validate the
    controls surrounding it.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span&gt;Because in cybersecurity, the most important question is rarely whether a
    control exists.&lt;/span&gt;
&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;-webkit-text-stroke-color: rgb(0, 0, 0); -webkit-text-stroke-width: 0px; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-style: normal; font-variant-alternates: normal; font-variant-caps: normal; font-variant-east-asian: normal; font-variant-emoji: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal; margin: 0px 0px 12px; min-height: 13.8px;&quot;&gt;
  &lt;span style=&quot;font-family: arial;&quot;&gt;The real question is whether it works.&lt;/span&gt;&lt;/p&gt;
&lt;i&gt;&lt;/i&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/7019554549664841897/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/7019554549664841897' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/7019554549664841897'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/7019554549664841897'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/03/ai-is-moving-faster-than-security.html' title='AI Is Moving Faster Than Security Controls'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIx_BM0R6L8GaBc6CG_3kcFwUM7vd1FrdcqU9VC9cHtdevOeElX6cgf8bEiLvN2kHvJLg6Z4KYlFWfIbtJjYtWlok-mZnV3JaHXOyjcKeKzuqQ8aCBRRapyQmYqRwenEczAg9wpw13hkmPLo_5enwfcp6bynnTbFQYwxcXkRnUJ9t1WyQ5g_bGwXY2OQqO/s72-c/8024C750-F11A-4A43-B0FD-5CAB46254DD1.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-9141350669243030307</id><published>2026-03-03T21:51:00.007+00:00</published><updated>2026-03-04T11:34:41.512+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Cyberwar"/><category scheme="http://www.blogger.com/atom/ns#" term="Iran"/><category scheme="http://www.blogger.com/atom/ns#" term="nation-state"/><category scheme="http://www.blogger.com/atom/ns#" term="NCSC"/><category scheme="http://www.blogger.com/atom/ns#" term="Operation Cleaver"/><title type='text'>NCSC Warns UK Organisations to Prepare for Potential Iran-Linked Cyber Activity</title><content type='html'>&lt;p class=&quot;p1&quot;&gt;&lt;span class=&quot;s1&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Geopolitical conflict rarely stays confined to physical battlefields. Increasingly, it spills into the digital domain. The latest escalation of tensions in the Middle East has prompted the UK’s &lt;a href=&quot;https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-middle-east&quot; target=&quot;_blank&quot;&gt;National Cyber Security Centre (NCSC) to issue a warning to organisations&lt;/a&gt;&amp;nbsp;to review their cyber security posture and prepare for possible cyber activity linked to Iran.&lt;/span&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-p36aULwGPL6s32i9o5ZD7SNG3LUdiSBuUhx6-cPesOx8nSnR_PShuLWOjL0ID0DjJkxAYnehmrBHy7k07tu0B0xYFEc8lQlsFXHRYNKEGyg8xvCVuaRZ4WRh7a4abgKj3ClN1O6yi_6v6GoRfneIvDQ8HE8623OD-bL-FfdiIS8I5L0NmFxPDzo53IqF/s1536/IranCyberThreat.png&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1024&quot; data-original-width=&quot;1536&quot; height=&quot;266&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-p36aULwGPL6s32i9o5ZD7SNG3LUdiSBuUhx6-cPesOx8nSnR_PShuLWOjL0ID0DjJkxAYnehmrBHy7k07tu0B0xYFEc8lQlsFXHRYNKEGyg8xvCVuaRZ4WRh7a4abgKj3ClN1O6yi_6v6GoRfneIvDQ8HE8623OD-bL-FfdiIS8I5L0NmFxPDzo53IqF/w400-h266/IranCyberThreat.png&quot; width=&quot;400&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;While the NCSC has stressed that there is currently no confirmed significant increase in direct cyber threats to the UK, it has warned that the situation is fast-moving and organisations should remain alert. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Rising Tensions and Cyber Spillover&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;The warning follows a sharp escalation in the regional conflict involving Iran, the United States and Israel. Military developments have been accompanied by cyber activity targeting digital infrastructure and online services in the region, highlighting how modern conflicts now run across both physical and digital fronts.  &lt;br /&gt;&lt;br /&gt;In response, the NCSC has advised UK organisations to review their cyber defences and ensure they are prepared for possible disruption. The agency noted that while the direct cyber threat level to the UK has not significantly changed, there is “almost certainly a heightened risk of indirect cyber threat” for organisations with operations, assets or supply chains in the Middle East. &lt;br /&gt;&lt;br /&gt;This includes potential activity from Iranian state actors as well as Iran-aligned hacktivist groups.&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;Iran’s established Cyber Capabilities&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Iran has long viewed cyber operations as a strategic tool that allows it to project influence asymmetrically against more technologically advanced adversaries. Over the past decade, Iranian cyber groups have targeted sectors such as energy, finance, transportation and government networks.&lt;br /&gt;&lt;br /&gt;Previous campaigns linked to Iranian actors have included destructive malware operations, espionage campaigns and disruptive attacks against critical infrastructure. For example, the widely documented &lt;a href=&quot;https://www.cylance.com/content/dam/cylance/pages/operation-cleaver/Cylance_Operation_Cleaver_Report.pdf&quot; target=&quot;_blank&quot;&gt;Operation Cleaver &lt;/a&gt;campaign targeted energy and transportation organisations globally.  &lt;br /&gt;&lt;br /&gt;Although Iranian cyber capabilities are generally considered less sophisticated than those of Russia or China, they have demonstrated a willingness to conduct disruptive and politically motivated attacks.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;What the NCSC is advising Organisations to do&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The NCSC’s guidance is not calling for panic, but it does emphasise the importance of cyber resilience during periods of geopolitical instability.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;Organisations are advised to:&lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Review their external attack surface and internet-exposed services&lt;/li&gt;&lt;li&gt;Increase monitoring for suspicious activity&lt;/li&gt;&lt;li&gt;Prepare for common threat tactics such as phishing and distributed denial-of-service (DDoS) attacks&lt;/li&gt;&lt;li&gt;Ensure patching and vulnerability management processes are up to date&lt;/li&gt;&lt;li&gt;Review incident response plans and escalation procedures&lt;/li&gt;&lt;/ul&gt;The NCSC has also encouraged organisations to sign up to its &lt;a href=&quot;https://www.ncsc.gov.uk/section/active-cyber-defence/early-warning&quot;&gt;Early Warning service&lt;/a&gt;, which provides alerts about potential security issues affecting UK networks.  &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;The Risk of Opportunistic Cyber Activity&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;One important point highlighted in the advisory is that not all cyber activity during geopolitical crises comes directly from state actors.&lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;Periods of international tension often attract:&lt;/li&gt;&lt;li&gt;politically motivated hacktivists&lt;/li&gt;&lt;li&gt;cybercriminal groups seeking to exploit confusion&lt;/li&gt;&lt;li&gt;proxy actors aligned with nation-state interests&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;These groups may launch attacks intended to disrupt services, deface websites or leak stolen data for political impact.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&lt;b&gt;A Reminder for Boards and Security Teams&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Events like this are a reminder that cyber risk does not exist in isolation from geopolitical developments. Organisations operating globally, particularly those with supply chains or business interests in politically sensitive regions, must assume that digital infrastructure could become collateral damage during international conflicts.&lt;br /&gt;&lt;br /&gt;For security teams, the key takeaway is not that a wave of attacks is imminent, but that situational awareness and operational readiness matter.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;Cyber resilience is most effective when organisations treat security posture reviews as routine practice rather than emergency reactions.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Sources:&lt;/b&gt;&lt;br /&gt;• National Cyber Security Centre alert: &lt;a href=&quot;https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-the-middle-east&quot;&gt;https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-the-middle-east&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/9141350669243030307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/9141350669243030307' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/9141350669243030307'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/9141350669243030307'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/03/ncsc-warns-uk-organisations-to-prepare.html' title='NCSC Warns UK Organisations to Prepare for Potential Iran-Linked Cyber Activity'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-p36aULwGPL6s32i9o5ZD7SNG3LUdiSBuUhx6-cPesOx8nSnR_PShuLWOjL0ID0DjJkxAYnehmrBHy7k07tu0B0xYFEc8lQlsFXHRYNKEGyg8xvCVuaRZ4WRh7a4abgKj3ClN1O6yi_6v6GoRfneIvDQ8HE8623OD-bL-FfdiIS8I5L0NmFxPDzo53IqF/s72-w400-h266-c/IranCyberThreat.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-5271853500767731686</id><published>2026-02-20T07:30:00.001+00:00</published><updated>2026-02-20T09:49:35.687+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="AI"/><category scheme="http://www.blogger.com/atom/ns#" term="SIEM"/><category scheme="http://www.blogger.com/atom/ns#" term="SOC"/><title type='text'>AI in the SOC: Why Complete Autonomy Is the Wrong Goal</title><content type='html'>&lt;p align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; text-align: center; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Dan Petrillo, VP&amp;nbsp;of&amp;nbsp;Product&amp;nbsp;at&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;a href=&quot;https://www.bluevoyant.com/&quot; style=&quot;color: purple;&quot; target=&quot;_blank&quot; title=&quot;https://www.bluevoyant.com/&quot;&gt;&lt;span style=&quot;color: #467886; font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;BlueVoyant&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;As artificial intelligence (AI) becomes more deeply embedded in security operations, a divide has emerged in how its role is defined. Some argue the security operations centre (SOC) should be fully autonomous, with AI replacing human analysts. Others&amp;nbsp;believe&amp;nbsp;that&amp;nbsp;augmentation&amp;nbsp;is the right path, using AI to support and extend existing teams.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Augmentation&amp;nbsp;probably&amp;nbsp;reflects how SOCs operate in practice. It helps analysts triage alerts, investigate incidents faster, and&amp;nbsp;it&amp;nbsp;brings&amp;nbsp;better context into their work, while&amp;nbsp;still&amp;nbsp;ensuring humans&amp;nbsp;are&amp;nbsp;accountable for decisions.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Complete&amp;nbsp;autonomy assumes a level of reliable, end-to-end decision-making that can operate without continuous human oversight. That’s a high bar. In real SOC environments, the technology, data quality, and operational constraints rarely support that assumption. Detection pipelines are noisy, context is fragmented across tools, and threat signals often require human judgment to interpret correctly. Even the most advanced automation struggles with edge cases, ambiguous alerts, and the dynamic nature of attacker behaviour.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Why&amp;nbsp;an&amp;nbsp;Autonomous SOC Falls Short&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Delving deeper and examining&amp;nbsp;why&amp;nbsp;AI cannot&amp;nbsp;fully replace SOC analysts;&amp;nbsp;in short,&amp;nbsp;it&amp;nbsp;comes down to&amp;nbsp;the&amp;nbsp;oversimplification of the complexities inherent in&amp;nbsp;what&amp;nbsp;security operations involve. Investigation is only one part of a functioning SOC. Organisations also depend on experienced practitioners to interpret ambiguous signals, manage escalation, and communicate risk to senior leadership. When incidents become business issues, that same expertise is required to apply judgement, coordinate stakeholders, and produce reporting that stands up to scrutiny.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;When something goes wrong, such as a logging failure, a broken parser following a third-party firewall update, or months of missing telemetry, automated systems cannot resolve the issue alone. Human expertise is needed to understand context, reconstruct events, and guide remediation.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Governance is another constraint. The cost of false negatives remains unacceptably high, and security leaders are unlikely to deploy solutions that act without clear oversight. Even where AI can execute parts of a workflow, organisations still require process controls, quality checks, and human validation for complex or unfamiliar scenarios. A fully autonomous model cannot reliably make the right&amp;nbsp;judgement&amp;nbsp;call in every situation, particularly when decisions carry&amp;nbsp;real&amp;nbsp;business impact.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Accuracy risks also remain. AI systems can make mistakes, draw incorrect conclusions, or miss important signals if left unchecked. Human oversight therefore remains essential to spot errors early and prevent them from turning into operational problems.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Ultimately, fully autonomous SOC models ask organisations to trade human judgement and accountability for AI that is still maturing. That trade-off is impractical in an environment where consequences are measured in real-world disruption.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Why AI in the SOC Is Still Essential&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;However, none of the above&amp;nbsp;suggests that AI does not have a place in the SOC.&amp;nbsp;When implemented with purpose&amp;nbsp;it delivers measurable improvements in the areas where teams are under the most pressure.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;AI can&amp;nbsp;take on&lt;span style=&quot;color: red;&quot;&gt;&amp;nbsp;&lt;/span&gt;repetitive, high-volume&amp;nbsp;tasks&amp;nbsp;such as alert triage and enrichment, allowing analysts to focus on&amp;nbsp;more&amp;nbsp;complex investigations, decision-making, and response.&amp;nbsp;Deployed effectively, AI in the SOC is essential to reclaiming human time from low&amp;nbsp;value activity, enabling teams to apply expertise where it has the greatest operational&amp;nbsp;payoff.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Some of the most significant benefits of integrating AI agents into human-led SOC teams include:&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Workload reduction:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;AI can handle repetitive, high-volume tasks such as alert triage, dynamic enrichment, and report generation, reducing analyst fatigue and operational backlog.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Process consistency:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;AI helps standardise workflows across varying skill levels, smoothing differences in tool syntax and operating procedures so teams perform more consistently.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol; font-size: 10pt; text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;; font-feature-settings: normal; font-kerning: auto; font-optical-sizing: auto; font-size-adjust: none; font-size: 7pt; font-variant-alternates: normal; font-variant-east-asian: normal; font-variant-ligatures: normal; font-variant-numeric: normal; font-variant-position: normal; font-variation-settings: normal; font-width: normal; line-height: normal;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Improved alert quality:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;By incorporating external threat intelligence, control telemetry, and asset context, AI can reduce false positives and support more accurate prioritisation.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Faster decision-making:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;Attack timelines, path mapping, and context-rich summaries enable analysts to assess scope, impact, and containment options more quickly.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Knowledge retention:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;AI working alongside human analysts captures operational insights over time, mitigating the impact of staff churn and preserving institutional knowledge. It can also identify patterns that may be missed by individuals and recommend rules or remediations accordingly.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Always&amp;nbsp;on:&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;AI doesn’t need breaks, get tired, fall ill, take holidays, or turn up late. It becomes a consistently reliable coworker for&amp;nbsp;stretched&amp;nbsp;teams&amp;nbsp;working under pressure.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Where Augmentation Delivers the Most Value&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;AI delivers the greatest value when applied to SOC activities that are slow, manual, or prone to inconsistency, while keeping humans accountable for decisions and execution.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Augmentation should be introduced first in areas where AI can&amp;nbsp;speed&amp;nbsp;up&amp;nbsp;analysis, surface insight, and support judgement, without removing human oversight.&amp;nbsp;Below are a few areas where you might consider using AI to augment your team:&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;/p&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Alert triage:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;False-positive reduction, dynamic enrichment, and contextual prioritisation using threat intelligence, asset criticality, and exposure data.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Augmented investigations:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;Natural language querying, attack path and timeline visualisation, and suggested queries that speed root-cause analysis.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;I&lt;b&gt;ncident and case summarisation:&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;Automated executive- and GRC-ready reporting that consolidates findings with clear, decision-ready context.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Hypothesis generation:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;Continuous pattern and behaviour analysis to surface new detections, investigative approaches, and remediation opportunities for human approval.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Operational oversight:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;AI that learns expected procedures and flags process deviations, bottlenecks, or underperformance for leadership attention.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;b style=&quot;text-indent: 0cm;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Response recommendations:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; text-indent: 0cm;&quot;&gt;&amp;nbsp;Context-aware guidance and playbook generation, with optional integration-driven execution remaining under human control.&amp;nbsp;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;What This Means for Security Teams&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;Security teams manage millions of investigations every&amp;nbsp;year, even&amp;nbsp;after automating many routine cases. While automation can streamline&amp;nbsp;these&amp;nbsp;routine tasks, full autonomy remains unrealistic. The most critical stages of an investigation still rely on human judgement, context and accountability.&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Segoe UI&amp;quot;, sans-serif; font-size: 9pt;&quot;&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; margin: 0cm; vertical-align: baseline;&quot;&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt;&quot;&gt;AI will continue to enhance the speed,&amp;nbsp;scale&amp;nbsp;and consistency of security operations, but the SOC of the future will remain human led, with AI augmenting,&amp;nbsp;not replacing,&amp;nbsp;analysts. Organisations that adopt AI in targeted,&amp;nbsp;outcome driven&amp;nbsp;ways will scale more effectively, reduce&amp;nbsp;risk&amp;nbsp;and preserve institutional knowledge. As threats evolve, AI&amp;nbsp;augmented SOC teams will not only keep pace but stay ahead of adversaries.&lt;/span&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/5271853500767731686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/5271853500767731686' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5271853500767731686'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5271853500767731686'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/02/ai-in-soc-why-complete-autonomy-is.html' title='AI in the SOC: Why Complete Autonomy Is the Wrong Goal'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-767224410724782558</id><published>2026-02-15T11:34:00.017+00:00</published><updated>2026-02-16T11:42:04.706+00:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="AI"/><category scheme="http://www.blogger.com/atom/ns#" term="disaster recovery"/><category scheme="http://www.blogger.com/atom/ns#" term="identity management"/><category scheme="http://www.blogger.com/atom/ns#" term="MFA"/><category scheme="http://www.blogger.com/atom/ns#" term="password security"/><category scheme="http://www.blogger.com/atom/ns#" term="Physical Security"/><category scheme="http://www.blogger.com/atom/ns#" term="supply-chain"/><category scheme="http://www.blogger.com/atom/ns#" term="Third Party Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Threat"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Management"/><title type='text'>It’s 2026. Why are the basics still being missed?</title><content type='html'>&lt;p&gt;&lt;i style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px;&quot;&gt;Written by Katie Barnett, Director of Cyber Security, and Gavin Wilson, Director of Physical Security and Risk, at&amp;nbsp;&lt;/i&gt;&lt;i style=&quot;color: #96607d; font-family: Aptos, sans-serif; font-size: 16px;&quot;&gt;&lt;a href=&quot;http://www.torosolutions.co.uk/&quot; style=&quot;color: #96607d; font-family: Aptos, sans-serif; font-size: 16px;&quot; title=&quot;http://www.torosolutions.co.uk/&quot;&gt;Toro Solutions&lt;/a&gt;&lt;/i&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;After spending years working with organisations on security, one thing becomes hard to ignore. When something serious happens, the root causes are sadly rarely surprising and there is often a sense of inevitability to them. Access that was never quite tidied up, controls that were written down but not really enforced, multi factor authentication that was recommended but not mandatory or decisions that made sense in the moment and were never revisited.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Last year’s headlines about the Louvre brought this into focus. The Louvre Museum, the world’s most visited cultural landmark, faced heavy criticism after investigators revealed that its internal video surveillance system was protected by the password “Louvre.” This came after a daylight heist in which thieves stole French Crown Jewels valued at over $100 million. The striking thing was not how bold the theft was, but how familiar the weakness behind it felt.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;It would be comforting to see that as a one-off mistake, but it rarely is. The Louvre was simply visible. Similar assumptions exist inside many organisations, often sitting quietly in the background while attention is pulled towards more immediate concerns. In most cases, people are not unaware of the issues they are just not the ones that shout the loudest.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;As you will know there is no shortage of discussion about how the threat landscape is changing, it’s changing every day. AI, geopolitical tension, supply chain exposure and the blending of physical and cyber risks are all moving fast and often featuring heavily in conversations with leadership. However, at the same time, whilst the big conversations are happening it is not unusual to walk into environments where access is loosely understood, vulnerabilities have been accepted by default, and physical security relies on a shared sense of trust rather than consistent control.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Access and identity management is a good example of how this plays out. Access is granted to keep work moving, which is usually the right decision at the time, but we find that what happens less reliably is the follow-up. Projects end, people change roles, suppliers move on, and amid increasingly demanding workloads, access is forgotten or missed and remains because removing it is never a priority. Over time, confidence creeps in where certainty should exist, and that only becomes obvious when something goes wrong.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;This is also where passwords and multi-factor authentication continue to cause problems, despite years of attention. It’s been drilled into everyone that passwords alone are weak, reused and easily compromised. Multi-factor authentication (MFA) is now heavily recommended across organisations, yet it is still common to find critical systems without MFA enabled, with MFA applied inconsistently, or disabled because it caused friction. Exceptions become normal and service accounts are excluded because they always have been. None of these decisions feel dramatic on their own, but together they leave credential compromise as one of the easiest ways in.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;The Louvre example resonates precisely because it reduces this to something uncomfortably simple. A globally recognised institution, with significant resources, still relying on a password that offered little real protection for a critical system. This is not a technology problem; it&#39;s just what happens when basic controls are never quite treated as urgent enough to demand sustained attention.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Vulnerability management tends to follow a similar path. Patching is rarely ignored outright instead it is delayed, deferred and worked around, often for understandable reasons. Each decision feels small, but the cumulative effect is not. When an incident eventually occurs, it is often described as sophisticated or unavoidable, even when the weakness involved had been known about for some time and often one that could be easily resolved.&amp;nbsp;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Physical security is another area where every day behaviour quietly undermines formal controls. We have all seen people wearing work badges in public places or holding secure doors open because it feels impolite not to. These moments are easy to dismiss, but they say a lot about how security is experienced day to day. In environments where physical access can be the door opener for cyber compromise, those behaviours carry more weight than many organisations realise.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Third-party risk is similar. Businesses rely on suppliers to function, and that reliance grows each year. Initial checks are usually done with good intent, but ongoing scrutiny is harder to sustain. Access persists, assumptions build, and visibility fades. When incidents occur through these routes, the surprise often comes from how little the organisation really knew about its own exposure.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;Response and recovery are where many of these gaps finally surface. Plans exist, backups are in place, and there is confidence that people will respond sensibly under pressure. In reality, uncertainty plays a bigger role than expected. Decisions take longer and responsibilities are less clear. Recovery takes more effort than anticipated and the damage often comes as much from this uncertainty which causes delay as from the original incident.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;The reason the basics continue to be missed is not a lack of knowledge or capability. It is that foundational security work rarely feels urgent, and it competes constantly with an ever-changing risk landscape and slick tools and initiatives that promise growth, efficiency or innovation. The basics do not generate visible wins when they work, and they rarely fail in isolation and as a result, risk accumulates quietly as it is normalised by the absence of immediate consequence.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;The organisations that make genuine progress take a different approach. They accept that security fundamentals require ongoing attention, not periodic clean-up. Access is treated as something that changes continuously, physical security is reinforced through everyday behaviour, not just policy and response and recovery are practised because disruption is assumed, not because it is feared.&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot; style=&quot;caret-color: rgb(33, 33, 33); color: #212121; font-family: Aptos, sans-serif; font-size: 16px; line-height: 18.4px; margin: 0cm 0cm 8pt;&quot;&gt;As 2026 progresses, the question is no longer whether threats will continue to evolve. They will. The more challenging question is whether organisations are prepared to be disciplined about the things they already know matter. Until the basics are given the same weight as innovation and growth, we will continue to see familiar failures surface in very public ways, followed by the same uncomfortable question of how something so simple was missed again.&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/767224410724782558/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/767224410724782558' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/767224410724782558'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/767224410724782558'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2026/02/its-2026-why-are-basics-still-being.html' title='It’s 2026. Why are the basics still being missed?'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-6068213413939914947</id><published>2025-03-31T01:02:00.001+01:00</published><updated>2025-03-31T01:02:18.096+01:00</updated><title type='text'>UK Cybersecurity Weekly News Roundup - 31 March 2025</title><content type='html'>&lt;h2&gt;UK Cybersecurity Weekly News Roundup - 31 March 2025&lt;/h2&gt;

&lt;p&gt;Welcome to this week&#39;s edition of our cybersecurity news roundup, bringing you the latest developments and insights from the UK and beyond.&lt;/p&gt;

&lt;h3&gt;UK Warned of Inadequate Readiness Against State-Backed Cyberattacks&lt;/h3&gt;
&lt;p&gt;
Cybersecurity experts have sounded the alarm over the UK&#39;s growing vulnerability to state-sponsored cyber threats. A recent report by the National Cyber Security Centre (NCSC) shows a 16% increase in severe cyber incidents affecting national infrastructure in 2024. A worrying 64% of public sector IT leaders said they are unsure about best practices, with legacy systems worsening the risk. As digital transformation accelerates, public infrastructure like energy and healthcare face increasing exposure to ransomware and espionage.
&lt;a href=&quot;https://www.ccn.com/news/technology/uk-cyber-ill-prepared-state-attacks-surge-public-infrastructure-risk/?utm_source=chatgpt.com&quot; target=&quot;_blank&quot;&gt;Read more&lt;/a&gt;
&lt;/p&gt;

&lt;h3&gt;NCSC Publishes Roadmap for Post-Quantum Cryptography Migration&lt;/h3&gt;
&lt;p&gt;
The NCSC has published official guidance on migrating to post-quantum cryptography (PQC) to protect against future quantum computing threats. The document urges critical infrastructure operators to begin preparations now, with system discovery and risk assessments expected by 2028. Full migration should be completed by 2035. The roadmap highlights the need for cryptographic agility and risk-based planning in anticipation of quantum threats.
&lt;a href=&quot;https://securityboulevard.com/2025/03/the-uks-national-cyber-security-centre-presents-timeline-and-roadmap-for-pqc-migration/?utm_source=chatgpt.com&quot; target=&quot;_blank&quot;&gt;Read more&lt;/a&gt;
&lt;/p&gt;

&lt;h3&gt;UK Government to Update Software Vendor Security Code of Practice&lt;/h3&gt;
&lt;p&gt;
Following a public consultation, the UK government will publish a revised voluntary code of practice for software vendors later this year. The updated framework will include clearer technical requirements and a new attestation mechanism for vendors to demonstrate compliance. The initiative aims to raise the standard of cybersecurity in commercial software used by UK businesses and public services.
&lt;a href=&quot;https://www.osborneclarke.com/insights/Regulatory-Outlook-March-2025-cyber-security?utm_source=chatgpt.com&quot; target=&quot;_blank&quot;&gt;Read more&lt;/a&gt;
&lt;/p&gt;

&lt;h3&gt;Google Patches Actively Exploited Chrome Zero-Day (CVE-2025-2783)&lt;/h3&gt;
&lt;p&gt;
Google has released an emergency update for Chrome to patch CVE-2025-2783, a high-severity zero-day vulnerability that was being actively exploited in the wild. The flaw allowed attackers to bypass sandbox protections. All users are urged to update their browsers immediately. This marks the second major Chrome zero-day reported in 2025.
&lt;a href=&quot;https://www.helpnetsecurity.com/2025/03/30/week-in-review-chrome-sandbox-escape-0-day-fixed-microsoft-adds-new-ai-agents-to-security-copilot/?utm_source=chatgpt.com&quot; target=&quot;_blank&quot;&gt;Read more&lt;/a&gt;
&lt;/p&gt;

&lt;h3&gt;UK Considers Ransomware Payment Ban for Public Sector&lt;/h3&gt;
&lt;p&gt;
A proposal to ban ransomware payments by UK public sector and critical infrastructure organizations is under review. While the policy aims to discourage threat actors, experts warn that it may increase the pressure on under-prepared organizations and push attacks toward entities with no ability to recover quickly
</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/6068213413939914947/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/6068213413939914947' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/6068213413939914947'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/6068213413939914947'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2025/03/uk-cybersecurity-weekly-news-roundup-31.html' title='UK Cybersecurity Weekly News Roundup - 31 March 2025'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-750888375181464493</id><published>2025-03-24T01:23:00.000+00:00</published><updated>2025-03-24T01:23:41.631+00:00</updated><title type='text'>UK Cybersecurity Weekly News Roundup - 23 March 2025</title><content type='html'>&lt;p&gt;Welcome to this week&#39;s edition of our cybersecurity news roundup, bringing you the latest developments and insights from the UK and beyond.&lt;/p&gt;

&lt;h3&gt;NHS Scotland Confirms Cyberattack Disruption&lt;/h3&gt;
&lt;p&gt;On 20 March 2025, &lt;a href=&quot;https://www.itpro.co.uk/security/370936/nhs-scotland-cyber-attack-causes-network-outages&quot; target=&quot;_blank&quot;&gt;NHS Scotland&lt;/a&gt; reported a major cyber incident that caused network outages across multiple health boards. The cyberattack disrupted clinical systems and led to delayed patient care, with staff reverting to paper-based processes. The incident has been linked to a suspected ransomware group, although official attribution is still pending. Investigations are ongoing with support from the National Cyber Security Centre (NCSC).&lt;/p&gt;
&lt;p&gt;Further coverage from &lt;em&gt;The Register&lt;/em&gt; confirmed that some systems were taken offline to prevent further spread, while emergency care remained operational. The affected regions included NHS Dumfries and Galloway, which issued a statement urging patients to only attend if absolutely necessary. (&lt;a href=&quot;https://www.theregister.com/2025/03/20/nhs_scotland_cyber_attack/&quot; target=&quot;_blank&quot;&gt;Read more on The Register&lt;/a&gt;)&lt;/p&gt;

&lt;h3&gt;NCSC Weekly Threat Report – 22 March 2025&lt;/h3&gt;
&lt;p&gt;The &lt;a href=&quot;https://www.ncsc.gov.uk/report/weekly-threat-report-22nd-march-2025&quot; target=&quot;_blank&quot;&gt;NCSC&#39;s latest threat report&lt;/a&gt; highlights ongoing exploitation of known vulnerabilities in Progress Telerik UI by state-aligned threat actors. The report urges UK organisations to patch vulnerable systems immediately, as attackers continue to target unpatched web servers.&lt;/p&gt;
&lt;p&gt;Additionally, the NCSC notes an increase in malicious QR code campaigns—so-called &quot;quishing&quot;—where attackers embed phishing URLs into QR codes used in emails, posters, or even receipts. Organisations are advised to educate staff and implement QR code scanning policies.&lt;/p&gt;

&lt;h3&gt;Cyber Threats on the Rise as UK Eyes General Election&lt;/h3&gt;
&lt;p&gt;As the UK gears up for a general election later this year, the NCSC has raised concerns over potential interference campaigns and disinformation efforts by hostile states. Security services are reportedly on high alert, coordinating with political parties to bolster cyber resilience. While no major incidents have been reported yet, the threat landscape is being closely monitored.&lt;/p&gt;

&lt;h3&gt;Quick Bytes&lt;/h3&gt;
&lt;ul&gt;
  &lt;li&gt;New phishing campaign mimics HMRC emails demanding urgent tax repayment. Be vigilant and double-check all official correspondence.&lt;/li&gt;
  &lt;li&gt;UK universities warned of increased targeting by espionage-motivated groups, particularly in the fields of AI and quantum computing.&lt;/li&gt;
  &lt;li&gt;ICO fines a London-based telemarketing firm £130,000 for unlawful data use and non-compliance with GDPR.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That’s all for this week! Stay tuned for more updates, and follow best practices to keep your systems secure.&lt;/p&gt;

&lt;p&gt;➡️ &lt;strong&gt;Previous Post:&lt;/strong&gt; &lt;a href=&quot;https://blog.itsecurityexpert.co.uk/2025/03/uk-cybersecurity-weekly-news-roundup-17.html&quot;&gt;UK Cybersecurity Weekly News Roundup - 17 March 2025&lt;/a&gt;&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/750888375181464493/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/750888375181464493' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/750888375181464493'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/750888375181464493'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2025/03/uk-cybersecurity-weekly-news-roundup-23.html' title='UK Cybersecurity Weekly News Roundup - 23 March 2025'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-7368413553702305451</id><published>2025-03-16T09:43:00.000+00:00</published><updated>2025-03-17T09:43:39.560+00:00</updated><title type='text'>UK Cybersecurity Weekly News Roundup - 16 March 2025</title><content type='html'>
&lt;p&gt;Welcome to this week&#39;s edition of our cybersecurity news roundup, bringing you the latest developments and insights from the UK and beyond.&lt;/p&gt;

&lt;h3&gt;UK Government&#39;s Stance on Encryption Raises Global Concerns&lt;/h3&gt;

&lt;p&gt;The UK government has ordered Apple to provide backdoor access to iCloud users&#39; encrypted backups under the Investigatory Powers Act of 2016. This secret order applies not just to UK users but potentially to Apple users worldwide. In response, Apple has removed its Advanced Data Protection feature in the UK, expressing disappointment. This move has significant implications, raising concerns about global user privacy and security. Experts argue that creating backdoors compromises overall security, potentially allowing malicious entities to gain access. Apple&#39;s compliance or resistance will set a precedent for other governments seeking similar access. &lt;a href=&quot;https://www.theverge.com/policy/612136/uk-icloud-investigatory-powers-act-war-on-encryption&quot;&gt;Read more&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;Sellafield Nuclear Site Improves Physical Security Amid Cybersecurity Concerns&lt;/h3&gt;

&lt;p&gt;Sellafield, the world&#39;s largest plutonium store, has been taken out of special measures for physical security by the UK&#39;s nuclear industry regulator, the Office for Nuclear Regulation (ONR). This decision follows significant improvements in guarding arrangements, allowing routine inspections instead of enhanced regulatory oversight. However, concerns regarding its cybersecurity remain. Last year, Sellafield was fined almost £400,000 for cybersecurity failings, allegedly involving hacking groups linked to Russia and China. While there was no conclusive evidence of a successful cyber-attack, cybersecurity remains a critical concern. &lt;a href=&quot;https://www.theguardian.com/environment/2025/feb/19/sellafield-nuclear-site-taken-out-special-measures-physical-security&quot;&gt;Read more&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;UK Businesses Face Significant Financial Impact from Cyberattacks&lt;/h3&gt;

&lt;p&gt;In the past five years, cyberattacks have cost British businesses approximately £44 billion ($55.08 billion) in lost revenue, with 52% of private sector companies experiencing at least one attack during that period, according to insurance broker Howden. On average, these attacks cost companies 1.9% of their annual revenue. Larger companies, with over £100 million in annual revenue, are more likely to be targeted. Despite the significant risk, only 61% of businesses employ anti-virus software, and only 55% use network firewalls, due to cost and lack of internal IT resources. &lt;a href=&quot;https://www.reuters.com/technology/cybersecurity/cyberattacks-cost-british-businesses-55-billion-past-five-years-broker-says-2024-11-25/&quot;&gt;Read more&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;Global Sanctions Target Russian Cybercrime Network&lt;/h3&gt;

&lt;p&gt;The United States, United Kingdom, and Australia have jointly sanctioned Zservers, a Russian bulletproof web-hosting service provider, and two Russian operators linked to it for supporting the LockBit ransomware syndicate. The U.S. Treasury Department&#39;s Office of Foreign Assets Control, along with its U.K. and Australian counterparts, targeted Zservers for facilitating LockBit attacks by providing specialized servers resistant to law enforcement actions. Lock
&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/7368413553702305451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/7368413553702305451' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/7368413553702305451'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/7368413553702305451'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2025/03/uk-cybersecurity-weekly-news-roundup-16.html' title='UK Cybersecurity Weekly News Roundup - 16 March 2025'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-64232308723665256</id><published>2025-03-09T20:16:00.001+00:00</published><updated>2025-03-09T20:23:07.925+00:00</updated><title type='text'>UK Cybersecurity Weekly News Roundup – 9 March 2025</title><content type='html'>Welcome to this week&#39;s edition of our cybersecurity news roundup, bringing you the latest developments and insights from the UK and beyond.&lt;br /&gt;&lt;h2&gt;Microsoft Engineer&#39;s Transition to Cybersecurity&lt;/h2&gt;
    &lt;p&gt;Ankit Masrani, a 36-year-old software engineer, successfully transitioned into a cybersecurity role at Microsoft. With a background in IT and a Master&#39;s degree in computer science, Masrani secured an internship and later a full-time position at AWS, focusing on data and network security. He now serves as a principal software engineer on Microsoft&#39;s Security Platform team, emphasizing the importance of skills in big data technologies, machine learning, cloud services, and comprehensive security knowledge for such career pivots. &lt;a href=&quot;https://www.businessinsider.com/resume-microsoft-employee-used-land-cybersecurity-job-2025-3&quot;&gt;Read more&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;StubHub Breach: Taylor Swift Tickets Stolen&lt;/h2&gt;
    &lt;p&gt;Cybercriminals exploited a backdoor in StubHub&#39;s system, stealing nearly 1,000 tickets, primarily for Taylor Swift&#39;s Eras Tour, resulting in over $600,000 in profits. The breach highlights vulnerabilities in ticketing platforms and the need for robust cybersecurity measures to protect consumer interests. &lt;a href=&quot;https://www.wired.com/story/stubhub-backdoor-stolen-taylor-swift-tickets&quot;&gt;Learn more&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;UK&#39;s Cyber Security and Resilience Bill Introduced&lt;/h2&gt;
    &lt;p&gt;The UK government has introduced the Cyber Security and Resilience Bill, aiming to update existing regulations and strengthen the nation&#39;s cyber defenses. The legislation seeks to expand regulatory oversight, enforce stringent cybersecurity measures across various sectors, and introduce mandatory compliance with established standards to protect critical infrastructure and the digital economy. &lt;a href=&quot;https://en.wikipedia.org/wiki/Cyber_Security_and_Resilience_Bill&quot;&gt;Details here&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;British Library Cyberattack: A Wake-Up Call&lt;/h2&gt;
    &lt;p&gt;In October 2023, the British Library suffered a significant ransomware attack by the Rhysida group, leading to the theft of approximately 600GB of data. The attack disrupted services, delayed payments to authors, and highlighted vulnerabilities in cultural institutions. Recovery efforts are ongoing, emphasizing the need for robust cybersecurity measures in public sector organizations. &lt;a href=&quot;https://en.wikipedia.org/wiki/British_Library_cyberattack&quot;&gt;More information&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;Global Impact: US Charges Chinese Hackers&lt;/h2&gt;
    &lt;p&gt;The US Department of Justice has charged 12 Chinese nationals, including hackers and government officials, for their roles in extensive cybercrime campaigns targeting dissidents, news organizations, U.S. agencies, and universities. This action underscores the growing concerns over state-sponsored cyber espionage and the need for international cooperation in cybersecurity. &lt;a href=&quot;https://apnews.com/article/0bd01004160d63904374bb25cf3eae6c&quot;&gt;Read the full story&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;Protecting Your Devices: Recent TV Box Malware Attack&lt;/h2&gt;
    &lt;p&gt;TV owners are urged to perform essential security checks following a cyber attack affecting 1.6 million Android TV devices. Hackers infiltrated home networks through TVs, stealing data and using devices to mine cryptocurrencies, leading to increased energy bills. Users should update devices, uninstall unused apps, install anti-malware software, and avoid third-party vendors to safeguard against such threats. &lt;a href=&quot;https://www.thescottishsun.co.uk/tech/14424735/tv-owners-important-checks-hackers-boxes-attack-energy-bills/&quot;&gt;Learn how to protect your devices&lt;/a&gt;&lt;/p&gt;

    &lt;p&gt;Stay informed and vigilant to protect your digital assets in this evolving cybersecurity landscape.&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/64232308723665256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/64232308723665256' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/64232308723665256'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/64232308723665256'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2025/03/uk-cybersecurity-weekly-news-roundup-9.html' title='UK Cybersecurity Weekly News Roundup – 9 March 2025'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-5141758855192798631</id><published>2025-03-03T00:25:00.006+00:00</published><updated>2025-03-09T20:19:59.821+00:00</updated><title type='text'>UK Cybersecurity Weekly News Roundup – 2 March 2025</title><content type='html'>
    &lt;h2&gt;UK Government&#39;s Encryption Demands Lead to Apple&#39;s Data Protection Withdrawal&lt;/h2&gt;
    &lt;p&gt;The UK government has mandated that Apple provide access to encrypted iCloud backups under the Investigatory Powers Act of 2016. In response, Apple has withdrawn its &quot;Advanced Data Protection&quot; feature for UK users, citing concerns over user privacy and security. This move has sparked a global debate on the balance between national security and individual privacy rights. &lt;a href=&quot;https://www.thetimes.co.uk/article/apple-data-protection-british-government-l55nw7c0l&quot;&gt;Read more&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;International Sanctions Target Russian Cybercrime Network&lt;/h2&gt;
    &lt;p&gt;The United States, United Kingdom, and Australia have jointly imposed sanctions on Russian web-hosting provider Zservers and two Russian nationals for supporting the ransomware group LockBit. This group has been linked to numerous high-profile cyberattacks, including those on Boeing and the UK&#39;s National Health Service, extorting over $120 million since 2019. &lt;a href=&quot;https://apnews.com/article/361e788f5482bfd787af01002af2ff4c&quot;&gt;Learn more&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;Sellafield Nuclear Site Improves Physical Security Amid Cybersecurity Concerns&lt;/h2&gt;
    &lt;p&gt;The UK&#39;s Office for Nuclear Regulation has acknowledged significant improvements in physical security at the Sellafield nuclear site, leading to its removal from special measures. However, ongoing cybersecurity challenges persist, highlighting the need for continued vigilance in protecting critical infrastructure. &lt;a href=&quot;https://www.theguardian.com/environment/2025/feb/19/sellafield-nuclear-site-taken-out-special-measures-physical-security&quot;&gt;Details here&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;Google Expands AI Initiatives in Poland to Enhance Energy and Cybersecurity&lt;/h2&gt;
    &lt;p&gt;Google has signed a memorandum with Poland to develop artificial intelligence applications in the energy and cybersecurity sectors. This initiative aims to bolster Poland&#39;s technological infrastructure and reduce reliance on external energy sources, amidst increasing cyber threats. &lt;a href=&quot;https://apnews.com/article/475ad8b95cb3f3060e352be8720008bd&quot;&gt;More information&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;US Department of Homeland Security Overhauls Cybersecurity Personnel&lt;/h2&gt;
    &lt;p&gt;The Department of Homeland Security is set to terminate 12 employees from the Cybersecurity and Infrastructure Security Agency involved in monitoring misinformation. Additionally, all election security activities are temporarily paused to assess implications on free speech, reflecting ongoing debates about the role of federal agencies in regulating information. &lt;a href=&quot;https://nypost.com/2025/02/14/us-news/dhs-moves-to-fire-12-cisa-employees-who-policed-misinformation-and-pause-all-election-security-activities/&quot;&gt;Read the full story&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;AI Safety Policies Shift Focus Towards Security&lt;/h2&gt;
    &lt;p&gt;Recent policy changes in the US and UK are reframing AI safety as a security-focused issue, potentially sidelining ethical considerations such as bias and content accuracy. This shift has raised concerns among experts about the comprehensive governance of AI technologies. &lt;a href=&quot;https://www.axios.com/newsletters/axios-codebook-8f49fd00-f470-11ef-92ba-1ff14a657929&quot;&gt;Explore the implications&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;Polish Space Agency Suffers Cyberattack&lt;/h2&gt;
    &lt;p&gt;The Polish Space Agency (POLSA) detected unauthorized access to its IT infrastructure, prompting immediate security measures. Investigations are underway to identify the perpetrators, amid ongoing concerns about cyber threats targeting national agencies. &lt;a href=&quot;https://www.reuters.com/world/europe/cyberattack-detected-polish-space-agency-minister-says-2025-03-02/&quot;&gt;Find out more&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;Australian IVF Clinic Hacked, Exposing Sensitive Patient Data&lt;/h2&gt;
    &lt;p&gt;Genea, an Australian IVF clinic, suffered a ransomware attack by the group Termite, compromising nearly a terabyte of sensitive patient data. The breach has raised significant concerns about data security in healthcare institutions. &lt;a href=&quot;https://www.news.com.au/lifestyle/health/breathtaking-genea-cyberattack-reveals-stunning-australian-problem/news-story/5e6fe1e4a3d0634064a4c3f53d53e6f0&quot;&gt;Read more&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;US Treasury Department Breached by Chinese Hackers&lt;/h2&gt;
    &lt;p&gt;The US Treasury Department disclosed a significant cybersecurity breach attributed to Chinese state-sponsored actors. The attackers accessed unclassified documents, highlighting vulnerabilities in federal cybersecurity defenses. &lt;a href=&quot;https://www.nytimes.com/2024/12/30/us/politics/treasury-department-hack-china.html&quot;&gt;Learn more&lt;/a&gt;&lt;/p&gt;

    &lt;h2&gt;UK&#39;s War on Encryption Affects Global User Privacy&lt;/h2&gt;
    &lt;p&gt;The UK&#39;s demand for access to encrypted iCloud data under the Investigatory Powers Act has led to Apple&#39;s withdrawal of its Advanced Data Protection feature for UK users. This move has significant implications for global user privacy and sets a concerning precedent for government overreach into personal data. &lt;a href=&quot;https://www.theverge.com/policy/612136/uk-icloud-investigatory-powers-act-war-on-encryption&quot;&gt;Read the a
&lt;/a&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/5141758855192798631/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/5141758855192798631' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5141758855192798631'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5141758855192798631'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2025/03/uk-cybersecurity-weekly-update-2-march.html' title='UK Cybersecurity Weekly News Roundup – 2 March 2025'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-1946743057876539237</id><published>2025-02-24T01:53:00.005+00:00</published><updated>2025-03-09T20:20:12.134+00:00</updated><title type='text'>UK Cybersecurity Weekly News Roundup – 24 February 2025</title><content type='html'>&lt;p&gt;Welcome to this week&#39;s edition of our cybersecurity news roundup, bringing you the latest developments and insights from the UK and beyond.&lt;/p&gt;

&lt;h2&gt;Home Office Contractor&#39;s Data Collection Sparks Privacy Concerns&lt;/h2&gt;

&lt;p&gt;The Home Office faces scrutiny after revelations that its contractor, Equifax, collected data on British citizens while conducting financial checks on migrants applying for fee waivers. A report mistakenly sent to the Refugee and Migrant Forum of Essex and London (Ramfel) contained information on 260 individuals dating back to 1986, raising significant privacy issues. The Home Office has ceased using Equifax for visa fee waiver processing pending an investigation into the potential data breach. &lt;a href=&quot;https://www.theguardian.com/technology/2025/feb/23/home-office-contractor-collecting-data-on-uk-citizens-while-checking-migrants-finances&quot;&gt;Read more&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Apple Withdraws Advanced Data Protection in the UK Amid Government Dispute&lt;/h2&gt;

&lt;p&gt;Apple has removed its Advanced Data Protection (ADP) feature for UK users following a dispute with the British government. The government demanded access to encrypted material on Apple&#39;s iCloud under new evidence-collection powers. Apple, opposing the creation of a &quot;back door&quot; to its encryption service, opted to discontinue ADP in the UK. This decision highlights ongoing tensions between tech companies and governments over privacy and security regulations. &lt;a href=&quot;https://www.thetimes.co.uk/article/apple-data-protection-british-government-l55nw7c0l&quot;&gt;Learn more&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Sellafield Nuclear Site Improves Physical Security but Cyber Concerns Persist&lt;/h2&gt;

&lt;p&gt;The UK&#39;s Office for Nuclear Regulation (ONR) has removed Sellafield nuclear site from special measures concerning physical security, citing significant improvements. However, concerns over cybersecurity remain. Sellafield has been under scrutiny due to previous safety issues and cybersecurity deficiencies. Collaborative efforts are ongoing to address these challenges as the site continues to manage the nation&#39;s nuclear waste. &lt;a href=&quot;https://www.theguardian.com/environment/2025/feb/19/sellafield-nuclear-site-taken-out-special-measures-physical-security&quot;&gt;Full story&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;UK Government Introduces AI Cybersecurity Standards&lt;/h2&gt;

&lt;p&gt;The UK government has unveiled a new Code of Practice aimed at protecting AI systems from cyber-attacks. This initiative seeks to provide businesses and public services with guidelines to secure AI technologies, thereby safeguarding the digital economy. The voluntary code is expected to form the basis of a global standard for AI security, reinforcing the UK&#39;s position as a leader in safe technological innovation. &lt;a href=&quot;https://www.gov.uk/government/news/world-leading-ai-cyber-security-standard-to-protect-digital-economy-and-deliver-plan-for-change&quot;&gt;Details here&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Cyberattacks Cost UK Businesses Over £40 Billion in Five Years&lt;/h2&gt;

&lt;p&gt;Recent findings reveal that cyberattacks have cost British businesses approximately £40 billion in lost revenue over the past five years. More than half of private sector companies have experienced at least one attack, with compromised emails and data theft being the most common threats. Despite the increasing risks, many businesses lack adequate cybersecurity measures, often due to high costs and limited IT resources. &lt;a href=&quot;https://www.reuters.com/technology/cybersecurity/cyberattacks-cost-british-businesses-55-billion-past-five-years-broker-says-2024-11-25/&quot;&gt;Read the report&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Stay tuned for more updates and insights in our next weekly roundup.&lt;/p&gt;
</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/1946743057876539237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/1946743057876539237' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/1946743057876539237'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/1946743057876539237'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2025/02/cybersecurity-weekly-update-24-february.html' title='UK Cybersecurity Weekly News Roundup – 24 February 2025'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-5205090120590212464</id><published>2021-09-13T18:32:00.003+01:00</published><updated>2021-09-13T18:32:38.960+01:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="cyber risk"/><category scheme="http://www.blogger.com/atom/ns#" term="DarkSide"/><category scheme="http://www.blogger.com/atom/ns#" term="phishing"/><category scheme="http://www.blogger.com/atom/ns#" term="ransomware"/><category scheme="http://www.blogger.com/atom/ns#" term="Security Awareness"/><category scheme="http://www.blogger.com/atom/ns#" term="training"/><category scheme="http://www.blogger.com/atom/ns#" term="VIPRE"/><title type='text'>Prevention is Better Than Cure: The Ransomware Evolution</title><content type='html'>&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5qO112iFOlMWQAx2Mgt0onTZGuFBxyxMB8zAw0bYawfjFue5gKeLydloiPDFBGH7a47zrLCCs3KoVjCbTU1gL-rI6Y6ptq0x6v7ZThdzscpUMGJ_R32P5hNFBPZSfZkW5UJ130dNfQggV/s1680/ransomware.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1316&quot; data-original-width=&quot;1680&quot; height=&quot;251&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5qO112iFOlMWQAx2Mgt0onTZGuFBxyxMB8zAw0bYawfjFue5gKeLydloiPDFBGH7a47zrLCCs3KoVjCbTU1gL-rI6Y6ptq0x6v7ZThdzscpUMGJ_R32P5hNFBPZSfZkW5UJ130dNfQggV/s320/ransomware.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Ransomware tactics have continued to evolve over the years, and remain a prominent threat to both SMBs and larger organisations. Particularly during the peak of COVID-19,&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://www.itpro.co.uk/security/ransomware/357290/ransomware-incidents-exploded-in-june-says-ibm?_mout=1&amp;amp;utm_campaign=itpro_newsletter&amp;amp;utm_medium=email&amp;amp;utm_source=newsletter&quot; style=&quot;font-family: arial;&quot; target=&quot;_blank&quot;&gt;research by IBM&amp;nbsp;&lt;/a&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;found that ransomware incidents ‘exploded’ in June 2020, which saw twice as many ransomware attacks as the month prior, taking advantage of remote workers being away from the help of IT teams. The same research found that demands by cyber attackers are also increasing to as much as £31 million, which for businesses of any size, is detrimental for survival.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;In recent months, ransomware attacks have not left mainstream media headlines. And with the number and frequency of ransomware attacks increasing, not to mention the innovation in distribution methods, this should be a wake-up call for organisations to strengthen their defences. Jack Garnsey, Product Manager Security Awareness Training and SafeSend, VIPRE explains that by taking a preventative approach, businesses can take the necessary steps to strengthen their cybersecurity posture. This includes a combination of education, processes, hardware and software to detect, combat and recover from such attacks if they were to arise.  &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Ransomware in the 21st Century &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Ransomware is not a new phenomenon, but its use has grown &lt;a href=&quot;http://news.techworld.com/security/3343528/ransom-trojans-spreading-beyond-russian-heartland/&quot;&gt;exponentially&lt;/a&gt;&amp;nbsp;and has led to the development of the term ‘Ransomware as a Service&#39; (RaaS), which is a subscription-based model that enables affiliates to use already-developed ransomware tools to execute attacks. &lt;br /&gt;&lt;br /&gt;As ransomware incidents become more sophisticated and frequent, such as the increase in fileless attacks which exploit tools and features that are already available in the victim’s environment, the level of potential damage to a business is heightened. These types of attacks can be used in combination with social engineering targeting, such as phishing emails, without having to rely on file-based payloads. And unfortunately, ransomware is extremely difficult to prevent – all it takes is one employee clicking on the wrong link in an email or downloading a malicious attachment.  &lt;br /&gt;&lt;br /&gt;No matter the size of an organisation, the effects of ransomware can be devastating financially, as well as inflicting longer-term damage to business reputation. The Irish Department of Health and Health Service Executive (HSE) was recently attacked by The Conti ransomware group, who reportedly asked the Health Service for $20 million (£14 million) to restore access. This attack caused substantial cancellations to outpatient services, part of a system already stretched to the max due to COVID-19. Some ransomware gangs operate by a&lt;a href=&quot;https://www.bbc.co.uk/news/world-europe-57197688&quot; target=&quot;_blank&quot;&gt; flimsy code of &quot;ethics&quot;&lt;/a&gt;, stating they don&#39;t intend to endanger lives, but even if a minority of ransomware organisations are developing a sense of conscience, businesses are not exempt from the damage that can be done from such attacks.  &lt;br /&gt;&lt;br /&gt;Additionally, in the US, Colonial Pipeline paid the cyber-criminal group DarkSide nearly $5m (£3.6m) in ransom, following a cyber-attack that took its service down for five days, causing supplies to tighten across the US. Unfortunately when under attack, a majority of businesses, such as the major pipeline, often pay the ransom. Luckily for Colonial Pipeline, some of the money was later recovered by the American Department Of Justice&#39;s Ransomware and Digital Extortion Task Force. But if they pay once – they will pay multiple times. A successful ransomware attack can be used various times against many organisations, turning an attack into a cash cow for criminal organisations offering Ransomware as a Service. So much so, that there is now an &lt;a href=&quot;https://www.cuinfosecurity.com/should-paying-ransoms-to-attackers-be-banned-a-16726?rf=2021-05-25_ENEWS_SUB_CUIS__Slot1_ART16726&amp;amp;mkt_tok=MDUxLVpYSS0yMzcAAAF9QxFCBq6tGADPboNlpVaO5NzH-j7b2k2QbHsvC59_uRXkYCxpZV0ZRglm-cIytx1921tqK0lXhXm2ERr2LgB2Xq9mZrIP3rXtexmIam0la6EAbNBc0Q&quot; target=&quot;_blank&quot;&gt;ongoing debate&lt;/a&gt; around whether it should be illegal for businesses or an individual to pay a ransom in order to try and deter the attackers, or at the minimum, to at least report it to the necessary regulators.  &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Contain and Report It &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;If a ransomware attack were to take place, it is important that the organisation works with local authorities to try to rectify the issue and follow the guidance. Often, many ransomware attacks go unreported – and this is where a lot of criminal power lies.  &lt;br /&gt;&lt;br /&gt;Prevention is always better than cure, and damage limitation and containment are important right from the outset. As the United States President, Joe Biden, highlighted in his&lt;a href=&quot;https://www.whitehouse.gov/wp-content/uploads/2021/06/Memo-What-We-Urge-You-To-Do-To-Protect-Against-The-Threat-of-Ransomware.pdf&quot; target=&quot;_blank&quot;&gt; recent letter &lt;/a&gt;to business leaders around ransomware: “The most important takeaway from the recent spate of ransomware attacks on U.S., Irish, German and other organizations around the world is that companies that view ransomware as a threat to their core business operations, rather than a simple risk of data theft will react and recover more effectively.”  &lt;br /&gt;&lt;br /&gt;Most organisations should have a detailed disaster recovery plan in place and if they don’t, they should rectify this immediately. The key to every disaster recovery plan is backups. Once the breach has been contained, businesses can get back up and running quickly and relatively easily, allowing for maximum business continuity.  &lt;br /&gt;&lt;br /&gt;As soon as the main threat has passed, it is recommended that all organisations conduct a full retrospective audit, ideally without blame or scapegoats, and share their findings and steps taken with the world. Full disclosure is helpful – not only for the customer, client or patient reassurances but also for other organisations to understand how they can prevent an attack of this type from being successful again.  &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;The Support of Digital Tools &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;When it comes to ransomware, the importance of getting security foundations right must be emphasised. These attacks are not likely to stop or slow any time soon, but their success can be prevented with the right security armoury.  &lt;br /&gt;&lt;br /&gt;Particularly to mitigate the threat of ransomware, it is crucial to have secure endpoint protection in place which protects the files, application and network layer across a number of devices, and respond to security alerts in real-time. This has never been more important than during the ongoing pandemic, where employees are dispersed and working from home in order to ensure all devices are protected and comply with the same standards.  &lt;br /&gt;&lt;br /&gt;Additionally, solutions such as email attachment and URL sandboxing are also vital, as these digital tools provide vital protection against malicious emails. They can help prevent dangerous links, attachments or forms of malware from entering the user&#39;s inbox by examining and quarantining them. By filtering out this traffic and automatically restricting dangerous content, businesses can maintain greater control over email and the access points to the network. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;The Human Layer &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;The users themselves are a key part of any security strategy. Those who are educated about the types of threats they could be vulnerable to, how to spot them and the steps to take in the event of a suspected breach, are a valuable and critical asset to any organisation. &lt;br /&gt;&lt;br /&gt;Employees need to be trained to be vigilant, cautious, suspicious and assume their role as the last line of defence when all else fails. The final decision to click send on an email or a link lies with the human, but this one click could mean the entire organisation falls prey to a ransomware attack. The key is to change the mindset from full reliance on IT, to one where everyone is responsible. In order to strengthen a business’ human layer protection, security awareness training and education must be implemented across the board. &lt;br /&gt;&lt;br /&gt;These programmes are designed to support users in understanding the role they play in helping to combat attacks and malware. Using phishing simulations, for example, as part of the wider security strategy, will help to give employees insight into real life situations they may face at any point. The importance of testing your human firewall was also outlined in Joe Biden’s ransomware &lt;a href=&quot;https://www.whitehouse.gov/wp-content/uploads/2021/06/Memo-What-We-Urge-You-To-Do-To-Protect-Against-The-Threat-of-Ransomware.pdf&quot; target=&quot;_blank&quot;&gt;letter&lt;/a&gt;: “Use a 3rd party pen tester to test the security of your systems and your ability to defend against a sophisticated attack. Many ransomware criminals are aggressive and sophisticated and will find the equivalent of unlocked doors.” &lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Conclusion  &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Cyber security is a multi-faceted, complicated area, and one which must receive investment in each layer, from the technology to the people, to the tools we give to the users. Nevertheless, businesses of all sizes can safeguard their data and themselves from these types of ransomware attacks by investing in their cybersecurity and ensuring their workforces are conscious and informed of the threats they face.  &lt;br /&gt;&lt;br /&gt;Both detection and prevention play a key role in stopping ransomware, but it shouldn’t be one or the other. The essence of a solid cybersecurity strategy is a layered defence that includes endpoint detection and response, email security, advanced threat protection, web security and a business-grade firewall for the security of your network – at its most basic. But even with the most sophisticated software in place, hackers make it their mission to stay one step ahead of IT defences. That is why regular training, in addition to complementary security tools which reinforce security best practices, can provide a fortified strategy for users to mitigate the threat of a cyberattack.&lt;/span&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/5205090120590212464/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/5205090120590212464' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5205090120590212464'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/5205090120590212464'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2021/09/prevention-is-better-than-cure.html' title='Prevention is Better Than Cure: The Ransomware Evolution'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5qO112iFOlMWQAx2Mgt0onTZGuFBxyxMB8zAw0bYawfjFue5gKeLydloiPDFBGH7a47zrLCCs3KoVjCbTU1gL-rI6Y6ptq0x6v7ZThdzscpUMGJ_R32P5hNFBPZSfZkW5UJ130dNfQggV/s72-c/ransomware.png" height="72" width="72"/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-2086408499919759118</id><published>2021-08-13T14:00:00.002+01:00</published><updated>2021-08-13T14:12:22.220+01:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="application security"/><category scheme="http://www.blogger.com/atom/ns#" term="Hacking"/><category scheme="http://www.blogger.com/atom/ns#" term="penetration test"/><category scheme="http://www.blogger.com/atom/ns#" term="Physical Security"/><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Management"/><category scheme="http://www.blogger.com/atom/ns#" term="Wifi Security"/><title type='text'>How Businesses Can Utilise Penetration Testing</title><content type='html'>&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;span style=&quot;background-color: white; font-size: 13px; font-style: italic;&quot;&gt;&lt;table align=&quot;center&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;tr-caption-container&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhzaHzsdTkBJDMqWDGv-S5ga5iyEh86rk1neCEPzR-09XORLRPfZt2XgWQ5uH5-8VOS7eBcI5BwheDV6-s9l_zTeDmgn58n4bREkHz5CpGrBVbLO6IhaEbk7gLWubyK4WJ15ujkqGuKBOF/s610/PenetrationTesting.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;407&quot; data-original-width=&quot;610&quot; height=&quot;268&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhzaHzsdTkBJDMqWDGv-S5ga5iyEh86rk1neCEPzR-09XORLRPfZt2XgWQ5uH5-8VOS7eBcI5BwheDV6-s9l_zTeDmgn58n4bREkHz5CpGrBVbLO6IhaEbk7gLWubyK4WJ15ujkqGuKBOF/w400-h268/PenetrationTesting.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;tr-caption&quot; style=&quot;text-align: center;&quot;&gt;&lt;i style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;Understand your security vulnerabilities&lt;/span&gt;&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Article by&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://beaupeters.contently.com/&quot; style=&quot;background-color: white; color: #009be1; font-size: 13px; font-style: italic; text-decoration-line: none;&quot; target=&quot;_blank&quot;&gt;Beau Peters&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The basic approaches like&amp;nbsp;&lt;a href=&quot;https://blog.itsecurityexpert.co.uk/2021/05/keeping-phishing-simulations-on-track.html&quot; target=&quot;_blank&quot;&gt;phishing simulations&lt;/a&gt; are good, but they tend to have limited reach. This is why more agile methods, penetration testing among them, have been getting increasing attention. In essence, this sees experts with a background in ethical hacking utilizing the techniques of cybercriminals to breach a business’ systems. This also receives a certain amount of hesitancy — business owners are often unsure about the idea of letting somebody hack their systems in the name of cybersecurity. &lt;br /&gt;&lt;br /&gt;As always, there is more to this issue. So, let’s explore what penetration testing is, why businesses should engage with it and how they can do so to get the most impact. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;What are the Benefits? &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Penetration testing requires a significant amount of trust. Therefore, it’s important to look at what the payoffs of this approach are as opposed to ostensibly safer techniques. &lt;br /&gt;&lt;br /&gt;Some of the key benefits include:    &lt;br /&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;Ascertaining Vulnerabilities&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote style=&quot;border: none; margin: 0px 0px 0px 40px; padding: 0px; text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Penetration testing
tends to be the most direct and reliable approach to identifying what parts of
a company’s systems are vulnerable to attack. In general, testers will go
through each aspect of the network architecture, the website and software code,
applications, and hardware to identify where weaknesses lie. This doesn’t just
apply to external threats but internal issues, too.&lt;/span&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;These experts are
also approaching their review of a business’ systems with the creative,
outside-of-the-box thinking cybercriminals are likely to use. As such,
companies benefit from perspectives not usually offered by in-house information
technology staff. Once points of vulnerability have been identified, the tester
will often provide information about what issues are the highest priority to
handle based on the severity of the risk and the consequences.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;b&gt;Maintaining Trust&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote style=&quot;border: none; margin: 0px 0px 0px 40px; padding: 0px; text-align: left;&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Perhaps above all else, the benefit of penetration testing is the opportunity to maintain and strengthen trust between a business, its customers, and its supply chain. This is vital given the amount of consumer and partner data companies are gathering and storing. Security is particularly vital in cases when &lt;/span&gt;&lt;a href=&quot;https://www.course5i.com/blogs/data-democratization/&quot; style=&quot;font-family: arial;&quot;&gt;companies are undergoing data democratization&lt;/a&gt;&lt;span style=&quot;font-family: arial;&quot;&gt; — where important data is not just accessible to analysts and leadership but to all members of the organization.&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;This can be an empowering use of data, helping workers to understand how best to use and protect such information. However, alongside practical obstacles like deficient tools and siloed data, there is a need to prevent breaches. Penetration testing identifies where risks are throughout democratization practices, giving businesses the tools to strengthen their approaches. In turn, consumers and suppliers are assured their data is used to its best purpose and kept safe.&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Understand the Needs &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;While &lt;a href=&quot;https://www.wgu.edu/blog/what-penetration-tester2101.html&quot; target=&quot;_blank&quot;&gt;penetration testing utilizes curious, creative ethical hackers&lt;/a&gt;, businesses shouldn’t be mistaken in thinking this means it’s a simple process. It requires technological experts who usually go through at least five stages of protocols — from planning the right approach for the goals of the test to analyzing the data they’ve received and compiling a detailed report. The testing methodologies, too, can vary depending on the circumstances. As such, to make the most out of the process, businesses need to have a clear idea of what their needs are. &lt;br /&gt;&lt;br /&gt;Some of the common tests and the relevant needs they serve include:&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;Application Testing &lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;&lt;blockquote style=&quot;border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Many brands are producing their own apps to improve customer engagement. However, consistent data security can be difficult to achieve, particularly when working across multiple operating systems. Application penetration testing is used to spot flaws in the current security systems, as well as how they interact with user’s devices and represent vulnerabilities to consumers. &lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;Physical Testing &lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;blockquote style=&quot;border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Businesses often think cybersecurity attacks will originate remotely. But when a company keeps its servers and equipment on-site, there is potential for criminals to break into the premises and cause a breach. Hacks may even come from staff. Physical penetration testing should, therefore, be sought to understand whether the equipment is vulnerable to the types of tools and methods in-person hackers may use. &lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;ul style=&quot;text-align: left;&quot;&gt;&lt;li&gt;&lt;span style=&quot;font-family: arial; font-size: medium;&quot;&gt;&lt;b&gt;Wireless Testing &lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;blockquote style=&quot;border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Businesses are increasingly utilizing wireless tools for integral parts of operations. This includes capturing sensitive data, through contactless payment machines or sensors on devices in the Internet of Things (IoT) that track and control the supply chain. Wireless penetration testing can be used to understand how easy it is to illicitly collect data or even disrupt operations through the connected ecosystem. They’ll also confirm where stricter measures need to be in place to prevent access.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Finding the Right Expert &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Having established what pen testing is and how it can fit in with a business, how can companies find the right people for the job? After all, one of the key concerns companies have in this area is that they are essentially hiring hackers — there’s a lot of social and legal baggage accompanying this activity. &lt;br /&gt;&lt;br /&gt;When bringing on a consultant or hiring an in-house tester, the best approach is to look for relevant certification. Some of the most recognized examples here include &lt;a href=&quot;https://blog.itsecurityexpert.co.uk/2021/01/the-top-cybersecurity-certifications-in.html&quot; target=&quot;_blank&quot;&gt;the Certified Ethical Hacker licenses&lt;/a&gt; issued by the International Council of E-Commerce Consultants (EC-Council), and the Certified Penetration Tester course offered by the Information Assurance Certification Review Board (IACRB). Global Information Assurance Certification (GIAC) also provides various specialized qualifications that are considered to be reliable. These courses are designed to provide knowledge not just about the technical skills to positively impact a business, but also the ethical standards to help make sure testers are staying on the right moral and legal track throughout their activities. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Conclusion &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Penetration testing is an agile tool offering various benefits for businesses, including maintaining trust and highlighting points of vulnerability. However, it’s important to remember that getting the most out of the process requires clarity on the company’s challenges and goals for testing, alongside sourcing the relevant certified tester to collaborate with.&lt;/span&gt;&lt;br /&gt; &lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/2086408499919759118/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/2086408499919759118' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/2086408499919759118'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/2086408499919759118'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2021/08/how-businesses-can-utilise-penetration.html' title='How Businesses Can Utilise Penetration Testing'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjhzaHzsdTkBJDMqWDGv-S5ga5iyEh86rk1neCEPzR-09XORLRPfZt2XgWQ5uH5-8VOS7eBcI5BwheDV6-s9l_zTeDmgn58n4bREkHz5CpGrBVbLO6IhaEbk7gLWubyK4WJ15ujkqGuKBOF/s72-w400-h268-c/PenetrationTesting.jpg" height="72" width="72"/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-1909493564745862578</id><published>2021-07-28T19:40:00.006+01:00</published><updated>2021-07-28T19:42:00.879+01:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="Compliance"/><category scheme="http://www.blogger.com/atom/ns#" term="Payment Card Fraud"/><category scheme="http://www.blogger.com/atom/ns#" term="PCI"/><category scheme="http://www.blogger.com/atom/ns#" term="PCI DSS"/><title type='text'>Payment Security: Understanding the Four Corner Model</title><content type='html'>&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Introduction &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Online shopping digital payment transactions may seem quite simple, but in reality, just one single transaction sets off multiple, long-chain reactions. The Payment Card Industry comprises debit cards, credit cards, prepaid, e-purse/e-wallet, and POS payment transactions that enable easy payment transactions for consumers.  However, the card scheme is a popular payment transaction process which is also a central payment network that uses credit and debit cards to process payments.&amp;nbsp;&lt;/span&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;The card scheme comes in two variants namely the Three-Party Scheme and the Four Party Scheme payment model. The Four Corner Model also popularly known as Four-Party Scheme is the model under which most of the payment systems in the world operate. It is used in almost all standard card payment systems around the globe. So, explaining in detail the payment model, we have shared details on how the Four Corner Model works while also explain the role of every entity involved in it&lt;/span&gt;&lt;div&gt;&lt;table align=&quot;center&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;tr-caption-container&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmy_yCAt932e5kPr7uCm5nEvWnh-fN10VKsZ_o7xxtli9SZ_H2_xdYwqiEtkyNNq9_JA2U7SgD5kXOH7IW9Yw2AbDsqYCarbvM8VlfGGizOBlLt_c-tTj5vbSE03qdhACEDXfEXVThQ84T/s460/credit-cards.jpg&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;288&quot; data-original-width=&quot;460&quot; height=&quot;200&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmy_yCAt932e5kPr7uCm5nEvWnh-fN10VKsZ_o7xxtli9SZ_H2_xdYwqiEtkyNNq9_JA2U7SgD5kXOH7IW9Yw2AbDsqYCarbvM8VlfGGizOBlLt_c-tTj5vbSE03qdhACEDXfEXVThQ84T/s320/credit-cards.jpg&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;tr-caption&quot; style=&quot;text-align: center;&quot;&gt;&lt;i&gt;The Payment Network: Four Corner Payment Security Model&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;The Four Corner Model of Payment Security and How it Works&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;The card payment network, often called the Four Party Scheme, comprises multiple entities involved in an online transaction. The entities involved would include the &lt;b&gt;Cardholder&lt;/b&gt;, the &lt;b&gt;Merchant&lt;/b&gt;, the &lt;b&gt;Issuer&lt;/b&gt;, and the &lt;b&gt;Acquirer&lt;/b&gt;. So, before moving on to understanding how the Four Corner Model works, let us briefly learn about the entities involved and their role in the process. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;Cardholder &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Cardholders are the consumers who are issued a debit or credit card by a financial institution, such as a bank. The cardholder is a client of the issuing financial institution and may have an account directly linked to the payment card. The cardholder uses the card to make financial transactions for products or services they avail from businesses. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;Merchant &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Merchants are organisations that accept card payments from cardholders for the products or services they offer to them. These can be merchants offering “&lt;b&gt;&lt;i&gt;Card Present Payment&lt;/i&gt;&lt;/b&gt;” digital payment options such as card swipe terminals and/or “&lt;b&gt;&lt;i&gt;Card Not Present&lt;/i&gt;&lt;/b&gt;” digital payment options such as online portals or even using modes such as UPI at the POS itself.) For instance, the e-commerce platforms, restaurants, hotels, and shops equipped with POS payment terminals, etc. can be termed as merchants. For that matter even an ATM can be termed as a Merchant as the primary role of the merchant is to “accept” payment cards.  &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;Issuer/Issuing Bank &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;The issuer is the Financial Institution that issues the payment card to the cardholder. It is generally the bank that issues a payment card which could be a debit card, credit card, or prepaid card. However, it is important to note the issuing bank on behalf of various payment card brands like Visa, Mastercard, American Express etc provides customers with payment cards. This can even be a private payment brand or network like a domestic scheme.  But it is the issuing bank that is responsible for the security of the payment card, the cryptography, and the other relevant security controls. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: medium;&quot;&gt;Acquirer &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;An acquirer is basically a software and hardware vendor who provide a medium or a tool for accepting payment cards to the Merchants. They are a third-party system and not the bank where the merchant has an account. So, an acquirer provides hardware or a software application to the merchant for accepting card payments and process the transactions. That said, the acquirer is responsible for managing the final return authorization codes from a transaction and ensures the merchant delivers the goods or services based on the payments received. Examples for this can be Razorpay, PayU, Paytm, etc. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;How the Four Corner Model Works &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;The Four Corner Model triggers when a consumer makes a payment online with a payment card for products or services purchased from the merchant. This triggers the event or flow of payment authentication and processing with various entities involved in the process. However, for this to happen a cardholder needs to have a payment card while the POS terminal of the merchant must be able to accept the payment card. &lt;br /&gt;&lt;br /&gt;So, when a customer makes a payment with the card, an authorization request transmits from the merchant&#39;s POS terminal to the acquirer, and then to the issuer who either returns a positive or negative response which then again goes back to the merchant and then to the cardholder. The authorization process and response can be obererved on the POS terminal screen. It is important to note that the authorization requests and associated responses are transmitted via the card networks like VISA and MasterCard or a vast network of switches, gateways, and servers by card scheme network. On receiving a positive response from the issuing bank, the merchant processes the delivery of the goods or services to the client. At this point, it is also important to note that the Four Corner Model can also be a Three Corner Model if the Acquirer bank is skipped in the process, and the switches and gateways route the authorization flow directly to the Issuer. This makes the payment process less hassle on the payment network and also speeds up the transactions. &lt;br /&gt;&lt;br /&gt;While this is just one side of the payment process, now there is the clearing and settlement process that requires the merchant to transmit the transaction details to the acquirer. On receiving the transaction details, the acquirer collects the funds from the cardholders’ account by transmitting the corresponding payment flows to the issuing banks. So finally the merchant bank receives the money only after there is an interbank settlement of funds.  &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Conclusion &lt;/span&gt;&lt;/b&gt;&lt;br /&gt;The Four Corner Model is a popular model for online payment transactions. It is a systematic payment transaction process that facilitates end-to-end secure transactions that are ciphered and protected at every stage of the information or payment transmission process. That said, such payment transactions often need HSM and automated key management to prevent hacks or criminal activity during the processing of online payment transactions. It provides the framework for managing numerous keys throughout their life cycles and ensuring secure payment transactions.   &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;b&gt;Author Bio &lt;br /&gt;Narendra Sahoo (PCI QSA, PCI QPA, CISSP, CISA, and CRISC)&lt;/b&gt; is the Founder and Director of &lt;a href=&quot;https://www.vistainfosec.com/&quot; target=&quot;_blank&quot;&gt;VISTA InfoSec&lt;/a&gt;, a global Information Security Consulting firm, based in the US, Singapore &amp;amp; India. Mr Sahoo holds more than 25 years of experience in the IT Industry, with expertise in Information Risk Consulting, Assessment, &amp;amp;amp; Compliance services. VISTA InfoSec specializes in Information Security audit, consulting and certification services which include GDPR, HIPAA, CCPA, NESA, MAS-TRM, &lt;a href=&quot;https://www.vistainfosec.com/uk/service/pci-dss-audit-certification-service/&quot; target=&quot;_blank&quot;&gt;PCI DSS Compliance &amp;amp; Audit&lt;/a&gt;, PCI PIN, SOC2, &lt;br /&gt;&lt;br /&gt;PDPA, PDPB to name a few. The company has for years (since 2004) worked with organizations across the globe to address the Regulatory and Information Security challenges in their industry. VISTA InfoSec has been instrumental in helping top multinational companies achieve compliance and secure their IT infrastructure.&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/1909493564745862578/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/1909493564745862578' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/1909493564745862578'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/1909493564745862578'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2021/07/payment-security-understanding-four.html' title='Payment Security: Understanding the Four Corner Model'/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmy_yCAt932e5kPr7uCm5nEvWnh-fN10VKsZ_o7xxtli9SZ_H2_xdYwqiEtkyNNq9_JA2U7SgD5kXOH7IW9Yw2AbDsqYCarbvM8VlfGGizOBlLt_c-tTj5vbSE03qdhACEDXfEXVThQ84T/s72-c/credit-cards.jpg" height="72" width="72"/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3798604115389836864.post-8266099412141825505</id><published>2021-07-13T20:41:00.004+01:00</published><updated>2021-07-13T20:41:46.761+01:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="DPA"/><category scheme="http://www.blogger.com/atom/ns#" term="free"/><category scheme="http://www.blogger.com/atom/ns#" term="GDPR"/><category scheme="http://www.blogger.com/atom/ns#" term="privacy"/><category scheme="http://www.blogger.com/atom/ns#" term="training"/><title type='text'>Free Coventry University Course to Help Everyone Protect their Online Privacy    </title><content type='html'>&lt;div class=&quot;separator&quot;&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;Now everyone can learn what privacy means, how your privacy is impacted when using the web and mobile apps, and how to protect your privacy online thanks to a &lt;/span&gt;&lt;a href=&quot;https://csi-cop.eu/informal-education-mooc/&quot; style=&quot;font-family: arial;&quot; target=&quot;_blank&quot;&gt;free course &lt;/a&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;from Coventry University.&lt;/span&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;The UK university has worked closely with experts including Pat Walshe at &lt;a href=&quot;https://www.coventry.ac.uk/news/2021/moocs-world-rankings/&quot;&gt;PrivacyMatters &lt;/a&gt;to create an informative online course, offering participants easy access to key information about how to keep their online privacy safe.    &lt;br /&gt;&lt;br /&gt;Coventry University has a strong reputation for its digital education provision and online offering after it was &lt;a href=&quot;https://www.coventry.ac.uk/news/2021/moocs-world-rankings/&quot; target=&quot;_blank&quot;&gt;ranked number 1 in the world for the delivery of Massive Online Open Courses (MOOCs) &lt;/a&gt; by MOOCLabs for 2021.   &lt;br /&gt;&lt;/span&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhz92U13n6yuYNY2IXiFpIkmOBE7Q3VSgV-lrirWru0GYUBJt8_YJufWYi_dRf23mitiumoaf3yAn__dxiZeKtVIS8_BR6wCGxxTYR-ogDEViUQ7jZSA4go_Fw-WHdLAKXKM6xoDXg2KNgf/s610/ITSE-Blog-1.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;407&quot; data-original-width=&quot;610&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhz92U13n6yuYNY2IXiFpIkmOBE7Q3VSgV-lrirWru0GYUBJt8_YJufWYi_dRf23mitiumoaf3yAn__dxiZeKtVIS8_BR6wCGxxTYR-ogDEViUQ7jZSA4go_Fw-WHdLAKXKM6xoDXg2KNgf/s320/ITSE-Blog-1.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span style=&quot;font-family: arial;&quot;&gt;&lt;br /&gt;With people&#39;s information and digital footprint becoming increasingly sought after, the university hopes the course will build further awareness while helping people stay protected online. Typically, data is collected through cookies and pixels on websites or other means such as browser fingerprinting and trackers embedded in mobile apps. Tracking techniques allow multiple parties to learn about the pages you visit, what you click and view, what devices you use and your location, all of which has data protection and privacy implications. &lt;br /&gt;&lt;br /&gt;Citizen Scientists Investigating Cookies and App GDPR compliance (CSI-COP), an EU Horizon2020 funded project led by Coventry University, has facilitated the free informal education course, called ‘Your Right to Privacy Online’. The project has already seen the creation of a &lt;a href=&quot;http://tracking.vuelio.co.uk/tracking/click?d=olxy8eIQSFLMzI18HIxI9EimEs2aPZHy2_nruWrGvWYoK77rXE_x1oxZEMByvkPQSu26In4w-uZywizLi0KJ9W3XRGQbXyxr4x-bIBYu2W9iaqfHtDy4mR66x29njVNeVQ2&quot; target=&quot;_blank&quot;&gt;privacy-by-design, no-tracking website. &lt;/a&gt; &lt;br /&gt;&lt;br /&gt;The course is designed to help people gain the knowledge and skills to turn off tracking by disabling cookies on websites and changing app permissions on mobile devices. It features an introductory video, practical tasks and activities, a knowledge test and recommended reading to help participants stay safe online.    &lt;br /&gt;&lt;br /&gt;Huma Shah, Assistant Professor and Researcher in Artificial Intelligence at Coventry University, said: “We’re delighted to be able to tap into the university’s expertise in digital education to deliver this new, accessible and really useful course. The hope is that we can help as many people as possible to protect their online privacy and personal data while using the internet as well as giving them the tools and knowledge to better understand their rights to online privacy.”    &lt;br /&gt;&lt;br /&gt;Beyond the MOOC, members of the public can join the CSI-COP team as citizen scientists to explore the extent of tracking across the internet. Citizen science is a great way for volunteers to collaborate with research teams, raising awareness of issues impacting society and increasing trust between the general public and scientists.    &lt;br /&gt;&lt;br /&gt;Pat Walshe, Director for PrivacyMatters, said:  “It’s never been more important to help people understand how their privacy is impacted when using websites and mobile apps and to help them protect their rights under data protection and ePrivacy law. I’m glad to see Coventry University working hard to achieve this with the development of this course which I’m sure will help greatly.&quot;   &lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://csi-cop.eu/faq/&quot; target=&quot;_blank&quot;&gt;Find out more  about this new course and the CSI-COP project&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='https://blog.itsecurityexpert.co.uk/feeds/8266099412141825505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3798604115389836864/8266099412141825505' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/8266099412141825505'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3798604115389836864/posts/default/8266099412141825505'/><link rel='alternate' type='text/html' href='https://blog.itsecurityexpert.co.uk/2021/07/free-coventry-university-course-to-help.html' title='Free Coventry University Course to Help Everyone Protect their Online Privacy    '/><author><name>SecurityExpert</name><uri>http://www.blogger.com/profile/02816379340772195492</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhz92U13n6yuYNY2IXiFpIkmOBE7Q3VSgV-lrirWru0GYUBJt8_YJufWYi_dRf23mitiumoaf3yAn__dxiZeKtVIS8_BR6wCGxxTYR-ogDEViUQ7jZSA4go_Fw-WHdLAKXKM6xoDXg2KNgf/s72-c/ITSE-Blog-1.png" height="72" width="72"/><thr:total>0</thr:total></entry></feed>