❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security

How 9/11 Changed the Way America Surveils Its Citizens

By: Staff
10 September 2026 at 07:40
9/10/26
SURVEILLANCE
Enable IntenseDebate Comments:Β 
Enable IntenseDebate Comments

Twenty-five years after 9/11, the surveillance infrastructure built and expanded in its aftermath has become part of a far larger digital ecosystem β€” producing tools that can collect and analyze information on a scale unimaginable inΒ 2001.

The terrorist attacks of Sept. 11, 2001, did more than reshape the nation’s approach to terrorism. They changed the architecture of American intelligence and policing. They expanded how government agencies collect, share and analyze information, and brought national security tools deeper into ordinary lawΒ enforcement.

read more

Why Provision 29 is raising the bar for board accountability

26 August 2026 at 07:05

By Tim Williams, CEO at Quod Orbis

Under the 2024 UK Corporate Governance Code, the revised Provision 29 requires boards to demonstrate that their material internal controls are working effectively. Every business has hundreds of controls, however material controls have the potential to create an immense operational, security or regulatory impact. The message behind this latest update is that it’s no longer enough to be compliant on paper, and boards – now more than ever – must provide consistent evidence that is timely, accurate, reliable and capable of surfacing risks.

In the past, it was easier for businesses to claim they had good internal controls, but Provision 29 has changed the game. It calls for businesses to maintain assurance that their controls work across finance, compliance and reporting, and be able to validate their claims with real-time, accurate data.

Regulations usually demand annual, point-in-time, reporting exercises, however, the Financial Reporting Council is explicit that this new framework should not be seen as a periodic compliance exercise, but instead as an integral part of the company’s day-to-day business and governance processes.

Security teams face a new era of accountabilityΒ 

Provision 29 places greater responsibility on IT, security teams and the board when it comes to reporting the effectiveness of their internal controls. Teams have become accustomed to conducting infrequent manual data collections that provide a small snapshot of their entire system that becomes out of date the moment you have it. But businesses are now expected to have visibility over their controls throughout the year, not just before a review, and having accurate and timely data gives teams greater confidence that the decisions they are making today reflect the current risk exposure of their business.

Reporting and gathering data in silos is a hard task, especially when boards have to manually reconcile five conflicting reports, indicating varying levels of risk. Shared reporting architecture resolves this, providing greater collaboration between risk, internal audit and compliance teams, which is invaluable for verifying whether businesses have truly achieved organisational resilience., Provision 29 need not be a burden, but instead an opportunity to gain better visibility of how their controls are performing and improve their overall security posture and cyber resilience. While most boards comply, the most resilient are explaining their findings, and disclosing their reports properly.

Annual testing is no longer enoughΒ 

Businesses are reassessing their existing risk management strategies to make sure they are robust enough to provide the evidence boards need to report with confidence. Annual reporting cannot keep up with businesses operating in complex digital ecosystems, made up of cloud platforms, traditional infrastructure and third-party suppliers.

When you take a car in for its annual MOT, the mechanic only reports on the problems that exist there and then. What an MOT can’t do is warn of potential faults that may arise as soon as you leave the garage. The same logic applies to annual testing of security controls. What was deemed effective a few months ago may not be now, especially as many businesses keep evolving their systems and exposing them to new risks.

Businesses need continuous visibility to understand how their control environment changes over time. By relying on annual reports, businesses risk making important decisions based on a snapshot of information that becomes outdated the second it’s extracted. They thereby move forwards with a false sense of security over their entire system.

Getting ahead of the risk

Most businesses know what internal controls they have, but lack the visibility into whether they are operating effectively. Closing that gap means pinpointing where their internal controls are situated across their estate and what potential risks they could be exposed to.

Continuous assurance lets businesses monitor their internal controls in real-time, allowing them to identify degraded systems, know how long the exposure existed and explain what was done to resolve it. When security, IT, risk and compliance teams have consistent visibility over their internal controls, they can prioritise their efforts on strengthening resilience and preparing for risks before they arise. Imagine knowing that your car’s headlight is going to go out before it does?

This continuous visibility also helps teams communicate with the board. When it comes to reporting, Provision 29 can give boards greater confidence when they sign the declaration as it encourages a more evidence-led view of whether controls are operating as they should. Continuous monitoring reinforces this confidence by providing teams and boards with timely, accurate data rather than manual and sporadic assessments. Think of it as a navigation system rather than a handbrake. A handbrake only stops you from rolling backwards while a navigation system shows you the road ahead, warns you of the hazards you cannot yet see and keeps you moving towards where you want to go. The guidance provided through Provision 29 is designed to give businesses the confidence to move forward and know exactly where they stand.

The post Why Provision 29 is raising the bar for board accountability appeared first on IT Security Guru.

A reverse image search platform exposed more than 9 million facial images

24 August 2026 at 03:43
A publicly accessible database linked to reverse image search service ClarityCheck exposed more than nine million images, including photographs of adults, teenagers, and children. Cybersecurity researcher Jeremiah Fowler discovered the database, which was neither password-protected nor encrypted. It contained approximately 9,042,977 image files, amounting to 450.2GB of data. Most were stored in folders labeled β€œfaces” [...]

AI agents taking unsanctioned action during cyber testing

24 August 2026 at 03:41
The UK’s AI Security Institute (AISI) has disclosed a security incident in which frontier AI agents took unsanctioned actions against real people and organisations during a controlled cybersecurity evaluation.Β  This included attempts to socially engineer software maintainers and insert malicious code into an open-source project.Β  The incident happened during routine cyber capability testing between 25 [...]

The Hidden Risk in Data Transfer

19 August 2026 at 11:13

Cybersecurity has become one of the most defining business challenges of recent times. Organisations have invested heavily in protecting their networks, securing cloud environments and strengthening identity and access management. At the same time, organisations are under increasing pressure to prove they are handling sensitive information securely, not just storing it safely but protecting it throughout its journey.

Yet despite this progress, one area continues to receive far less attention than it deserves: how data is shared.

Most organisations have become very good at protecting data while it is stored. Files are encrypted, key handling is properly managed, access is restricted and systems are monitored around the clock. However, once that information needs to leave the organisation, whether it’s being sent to a customer, supplier, auditor or business partner, the controls often become less robust.

Every day, organisations exchange contracts, financial information, employee records, legal documents and commercially sensitive files. More often than not, this happens via email attachments or cloud-based file-sharing services because they are familiar and convenient. The problem is that convenience does not always equal security.

Email remains one of the most common routes for cyber attacks. Phishing, spoofed domains, malicious attachments and business email compromise continue to account for a significant proportion of successful breaches. However, most incidents do not involve a sophisticated bad actor. The official UK annual Cyber Security Breaches Survey continues to show the majority of incidents stem from everyday mistakes.Β  An email sent to the wrong recipient, an attachment forwarded outside the organisation or a file shared with overly broad permissions can expose sensitive information in seconds.

Human error remains one of the biggest cyber risks organisations face, particularly as businesses become increasingly connected. Information now flows constantly between employees, customers, suppliers, consultants and regulators. Every transfer creates another opportunity for something to go wrong.

What is often overlooked is that securing data is not just about protecting where it is stored. It is also about understanding the journey it takes.

Many organisations assume that because they operate in the UK, their sensitive information remains within UK borders. In reality, emails and attachments may be routed through multiple countries and cloud infrastructures before arriving at their destination. While this is often an invisible part of modern digital communications, it raises important questions around governance, compliance and data sovereignty.

For organisations operating in regulated sectors, this matters. Financial services firms, local authorities, healthcare providers and legal organisations are increasingly expected to demonstrate not only that data is protected, but also that it is managed responsibly throughout its entire lifecycle. Knowing where information is stored is only part of the picture. Understanding where it travels, who has access to it and how it is controlled has become equally important.

This is why conversations around geofencing and data sovereignty are gaining momentum. Rather than simply encrypting information and hoping for the best, organisations are beginning to ask whether they should have greater control over where sensitive data is permitted to travel. If businesses routinely place restrictions on the movement of physical assets, it seems only logical that they should apply similar thinking to digital information.

At the same time, regulators and auditors are asking more searching questions about how organisations exchange information with third parties. They want to understand how access is controlled, whether there is a complete audit trail and what safeguards exist once information leaves the organisation. These are no longer technical questions reserved for IT teams. They are governance issues that increasingly involve compliance, procurement, risk and senior leadership.

There is also a growing disconnect between the way organisations work and the security controls they have in place. Hybrid working, cloud collaboration and increasingly complex supply chains mean information rarely stays within a single organisation. Yet many businesses continue to rely on processes that were designed for a very different way of working.

This is where a change in mindset is needed.

Cybersecurity should not end when a document is saved securely on a server or in the cloud. Information is often at its most vulnerable when it is moving between people, organisations and systems. Protecting data in transit should therefore be considered just as important as protecting data at rest.

That does not mean making it harder for employees to do their jobs. Quite the opposite. Security should support the way people work, allowing information to be shared safely without creating unnecessary barriers or encouraging workarounds that introduce even greater risk.

Organisations need to take a more holistic view of information security. Protecting sensitive data means understanding its entire lifecycle, from creation and storage through to sharing, collaboration and eventual deletion. It means knowing not only who can access information, but where that information is travelling and whether that journey aligns with the organisation’s security, compliance and governance obligations.

Threats aren’t standing still, and neither are regulators. Focusing only on data that’s sitting in storage means missing one of the biggest holes in your security. It’s not enough to just lock data away; it needs to stay safe wherever it travels.

*DOQEX provides a secure data exchange and email gateway platform that helps businesses protect confidential information.

Β 

The post The Hidden Risk in Data Transfer appeared first on IT Security Guru.

The Digital Panopticon: Why Automated Surveillance Threatens a Free Society

13 August 2026 at 07:45
8/13/26
SURVEILLANCE
Enable IntenseDebate Comments:Β 
Enable IntenseDebate Comments

In an essay inΒ The AtlanticΒ titled β€œIn Defense of Flock,” the Manhattan Institute’s Charles Fain Lehman rightly recognizes a foundational principle of criminology: TheΒ certainty of apprehensionΒ serves as a potent crime deterrent. Yet, in framing automated surveillance as a technological panacea, Lehman ignores the critical trade-off at the heart of a freeΒ society.

read more

10th Annual Security Serious Unsung Heroes Awards Open for Nominations

Cybersecurity PR agency Eskenzi PRΒ  has opened nominations for its tenth annual Security Serious Unsung Heroes Awards. The awards celebrate the UK’s most extraordinary cybersecurity professionals who work to make the industry not only more secure, but also more diverse, healthier and better informed about current events. Key sponsors include CultureAI, OneAdvanced and The Zensory. [...]

One-click Claude Desktop flaw could enable hidden prompt injection and code execution

28 July 2026 at 07:12
Security researchers at Oasis Security have disclosed a vulnerability in Claude Desktop that could allow attackers to execute hidden prompts, access local files, exfiltrate conversation history, or execute code with a single click on a malicious link. The vulnerability, dubbed PromptFiction, affects the way Claude Desktop handled claude:// links.Β  According to the researchers, clicking one [...]

Russian state attackers exploiting misconfigured routers, new multi-nation advisory warns

28 July 2026 at 06:53
Russian state-sponsored actors are compromising poorly secured routers and networking devices around the world, with critical infrastructure organisations among the primary targets, reveals a new joint cybersecurity advisory from 20 government agencies.Β  The advisory attributes the activity to cyber actors associated with the Russian Federal Security Service (FSB) Center 16, saying the group continues to [...]

Americans are ignoring scam calls, but phishing emails still fool many

15 July 2026 at 02:28
Americans are becoming more effective at avoiding spam calls and texts, but new research suggests that the strategy comes with an unexpected cost. A new survey of 1,000 Americans from privacy company Cloaked, revealed that two-thirds of respondents have missed an important phone call because they ignored an unknown number. One in three have missed [...]

Sysdig uncovers first documented agentic ransomware operation

10 July 2026 at 03:36
Security researchers at Sysdig have documented what they believe is the first documented case of an AI agent running a ransomware operation from end to end. Dubbed JADEPUFFER, the operation used a large language model (LLM) to automate an attack that began with the exploitation of an internet-facing Langflow instance and ended in destructive database [...]

AI-assisted software engineering is creating a new delivery paradox

10 July 2026 at 03:35
AI can generate code faster than most software organizations can absorb it. This should be a productivity breakthrough, but it also exposes a larger problem: many of the processes surrounding software delivery still happen at human speed. A new white paper from code4thought looks at what happens when AI changes how quickly teams write software, [...]

Filigran report: Organisations can see their threats but can’t act fast enough

Fragmented tools and manual processes are widening the gap between threat awareness and effective CTEM. Only 41% of organisations have a fully consolidated view of cyber risk exposure, and security teams spend 42% of their time investigating risks that turn out to be low priority or non-exploitable At the same time, AI-driven CTEM processes expected [...]
❌
❌