Normal view

There are new articles available, click to refresh the page.
Today — 24 July 2026Main stream

Examining the Unintended Consequences of the Online Safety Act

24 July 2026 at 07:43

The 25th July 2026 marks one year since the Online Safety Act’s landmark child safety duties came into force, making it a natural moment to assess what’s changed, what’s worked and what challenges remain. Although the Act itself received Royal Assent in October 2023, its requirements were introduced in phases, with 25th July 2025 being the date many of the most visible obligations on platforms took effect.

The child safety duties require platforms likely to be accessed by children to introduce stronger protections, including effective age assurance, child risk assessments and measures to reduce exposure to harmful content. 

One year on, has the Online Safety Act fundamentally changed the internet for UK users, or has it simply shifted the challenges elsewhere? We spoke to cybersecurity experts for a short series of reports to find out more.  

Today, we’re examining the unintended consequences of the Act… 

Professor George Loukas, Head of Centre for Sustainable Cyber Security, University of Greenwich, said: “Ofcom has moved from consultation to enforcement. Naturally, the larger adult sector platforms have been the most visible early targets, and there have been lots of discussions on whether that led to a shift to more VPN usage as well as to non-compliant adult websites. These were all predictable though.”

Uptick in VPN Usage 

For many, the enforcement date signalled a natural (if not predictable) shift towards VPN usage to get around age verification tests. The evidence backs up this hypothesis: Proton VPN’s 2025 end of year report revealed that one of the biggest spikes in VPN sign-ups globally was seen in the UK from the 25th July. 

Konstantin Levinzon, co-founder of Planet VPN, noted that the real issue is people seeking out ‘free’ or not reputable VPNs, posing a significant security risk: “The biggest unintended consequence has been pushing people towards less secure tools, not more careful online behaviour. Age verification requirements have driven a significant increase in VPN adoption, but many users don’t seek out reputable providers – they simply download the first free VPN they find. Those services are often the ones leaking DNS requests, harvesting telemetry or relying on weak security practices, creating a worse privacy outcome than the legislation was designed to prevent.”

Sanjeev Malhotra, chief information security officer at TSG, emphasised the security risk: “People engaging with unvetted VPNs are potentially opening themselves up to serious risks, including malware infections, phishing attempts and personal data harvesting. At the end of the day, it’s still going through a server somewhere, and most people don’t stop to think about who’s operating it, where that data is going or what safeguards are actually in place. In some cases, people may be trading one privacy concern for another without realising it.”

A Lack of Measurable Outcomes? 

But is the ban on children accessing adult sites actually working? Some experts argue that there’s no hard evidence to back it up.

Elle Todd, Partner and Co-chair of the Entertainment & Media Industry Group at Reed Smith LLP, said:  “Ofcom’s recent age assurance report found that the proportion of children encountering harmful content online has not substantially improved despite widespread implementation efforts. The uncomfortable truth is that, based on this report, significant investment in compliance and technologies has not yet translated into measurable improvements in safety outcomes.”

Brian Higgins, Security Specialist at Comparitech, noted that, despite some non-compliance fines being handed out, there are still notable enforcement gaps: Stats from Ofcom summarising their activities during the first twelve months of the Online Safety Act include the launch of 30 investigations, and fines for statutory violations in the region of £4 million GBP. Unfortunately they have also identified ‘enforcement gaps’ where AI and algorithmic content are concerned.”

This item, in particular, could be a precursor to more widespread enforcement action in the future but a brief investigation into the facts reveals that their twelve-month fine collection figure only stands at £55,000. Couple that with their fairly embarrassing skirmish with the American platform 4chan, where their interjurisdictional service of a £520,000 financial penalty notice was rather infamous met with a picture of a hamster and a heavy dose of internet ridicule and it becomes rather obvious that they aren’t performing particularly well.”

Examining Data Storage and Verification System Security

Boris Cipot, principal security engineer, Black Duck, argues that we should be looking beyond whether checks are working and to whether the software behind the systems doing those checks is actually secure: “For many organisations, the focus has been on whether age checks are working. But an equally important question is whether the software behind those systems is secure and properly maintained. If a vulnerability, misconfiguration or compromised third-party component allows age checks to be bypassed, then this is not just a cybersecurity problem anymore but can quickly become a regulatory one as well.”

Sarah Bone, Co-Founder of YEO Messaging, notes the growing number of specialist identity providers: The biggest unintended consequence has been a shift in where trust actually sits. Before the Online Safety Act, platforms largely carried the responsibility for verifying users themselves. Now we’ve got a growing ecosystem of specialist identity providers, each holding highly sensitive personal information. That’s strengthened online safety, but it’s also concentrated trust into fewer organisations, which makes them increasingly attractive targets for attackers.”

So what should age verification providers be doing?

Martin Wegrostek, Cyber Security Portfolio Manager at cybersecurity specialist OryxAlign, said: “Businesses should work on the assumption that breaches are a matter of when, not if. The question is whether providers have built their services with security and privacy by design. That means collecting the minimum amount of information needed to verify age, encrypting data both in transit and at rest, enforcing strong access controls, continuously monitoring for suspicious activity and having a well-rehearsed incident response plan. Organisations relying on third-party age-assurance services should also carry out regular security assessments and review the resilience of their supply chain, rather than assuming a compliant provider is automatically a secure one.”

On Trust and Risk

The conversation should also focus on human risk, said Tim Ward, CEO and co-founder, Redflags: “Content moderators, trust and safety teams, and customer support staff at in-scope platforms are, for the first time, routinely processing government ID documents, facial scans, and other highly sensitive data belonging to minors as part of their everyday work. That’s a substantial new category of human risk, from simple mishandling to targeted social engineering aimed at staff with access to this data, and it’s had almost no public discussion compared to the technical side of compliance.”

“Organisations that have spent the past year focused on the verification system itself should be asking whether the humans downstream of it have had the same level of scrutiny and support,” Ward noted. 

 

The post Examining the Unintended Consequences of the Online Safety Act appeared first on IT Security Guru.

Before yesterdayMain stream

What Does the Cyber Industry Want to See From the New UK Government?

20 July 2026 at 09:40

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, and the potential reorganisation of the Department for Science, Innovation and Technology (DSIT), with its responsibilities redistributed across other government departments.

So, what does the cyber community hope Burnham will do in the realm of cybersecurity, AI and tech as Prime Minister? We asked the industry…    

Charlotte Wilson, Head of Enterprise at Check Point said: “Britain’s AI department is at the forefront of the country’s productivity strategy, playing a crucial role in how the technology will be developed and rolled out to drive wider economic growth and defence.”

“Incoming policymakers should take heed; artificial intelligence is the gorilla in the room and will remain so for the foreseeable future. Any suggestion of redeployment or downsizing could send the wrong signal to businesses and cyber criminals about how seriously we take the most transformational technology in living memory,” Wilson continued. 

Dray Agha, Senior Manager of Security Operations at Huntress, added: “Smart infrastructure beats a spending war, and fortunately the UK can’t outspend the US or China on AI models anyway, so the new Prime Minister must focus on where we can win: secure public datasets and targeted sovereign compute.”

“Safely unlocking NHS data while fortifying our energy grid will build real domestic leverage without compromising national security. With guaranteed access to US tech currently on ice, relying solely on Washington is no longer a viable security strategy. The UK must leverage our AI Security Institute to build a ‘middle-power’ tech coalition with NATO and Commonwealth allies, pooling resources to ensure collective cyber resilience.”

Additionally, Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, noted: “The UK doesn’t need to win the frontier model race; it needs to be a serious, trustworthy place to deploy AI at scale. That’s a more achievable and arguably more valuable position. The ally-pooling argument on sovereign compute and cloud interoperability is sensible from both an economic and security standpoint.”

“The UK’s convening credibility on this particularly through the AI Security Institute is a genuine asset that Burnham should be using. Unlocking health data for AI R&D is genuinely valuable but it’s only responsible if the security and governance infrastructure around that data is built first, not retrofitted after the damage is done. Right now the ambition is ahead of the security maturity.”

Jake Taylor, Head of Government NEMEA at Filigran, said:  “If the new government wants to bring more critical national infrastructure under public ownership, cybersecurity has to become part of that conversation from day one. National resilience isn’t just about protecting individual organisations anymore. It’s about ensuring energy providers, government, suppliers and operators can share intelligence, understand emerging threats and coordinate their response before disruption spreads.”

“The biggest challenge isn’t a lack of security tools. Most critical infrastructure organisations already have those. The challenge is breaking down the silos that still exist between organisations and turning threat intelligence into something that informs operational decisions, rather than simply generating more alerts. As the geopolitical environment becomes increasingly volatile and nation-state activity continues to rise, collaboration will be every bit as important as technology.”

Taylor continued, “the Cyber Security and Resilience Bill is an important step because it moves the conversation towards common standards and greater coordination. If public ownership expands, cybersecurity needs to evolve from a collection of individual security programmes into a genuinely national capability, where intelligence sharing and continuous threat exposure management become fundamental to protecting essential services.” 

Andy Burnham’s long-term plans for the UK’s cyber, AI and technology sectors are still taking shape. The Guru team will be keeping a close eye on developments as his new government begins to set out its agenda.

The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider

15 July 2026 at 12:17

Moona Ederveen-Schneider is a cybersecurity expert (and Most Inspiring Woman in Cyber Award winner 2026) with more than 20 years of experience across financial services, risk and cyber resilience. She has held senior roles at Deutsche Bank, JPMorgan Chase, UBS, Nomura and ABN Amro, and previously served as Executive Director EMEA at FS-ISAC. 

As the founder of Resilia Connect and author of the Practical Post-Quantum Transition Framework, Moona works with organisations preparing for the security risks created by quantum computing. Her work focuses on post-quantum migration, crypto-agility and helping leaders turn complex technical threats into practical action. 

In this exclusive interview conducted by the Cyber Security Speakers Agency, Moona explains why the quantum threat is already taking shape, where organisations go wrong when preparing for post-quantum cryptography, and why businesses need to begin strengthening their security architecture now. 

Why does quantum computing remain an underestimated cybersecurity threat for many organisations? 

Moona Ederveen-Schneider: “Quantum computing is not simply a future threat. Adversaries are already harvesting encrypted data with the intention of decrypting it once quantum computers become powerful enough. 

“Most organisations have not yet started preparing for that transition. 

“I developed a practical post-quantum transition framework to explain the issue clearly, cut through market hype and vendor noise, and make the process manageable for organisations and their teams. 

“I also run tabletop exercises that teach organisations how to become crypto-agile. I poll participants at the beginning and again at the end of these sessions. The shift in the room is remarkable. 

“People often arrive feeling that the challenge is unmanageable. They leave with greater confidence and a clear understanding of what they need to do next.” 

How close is the quantum threat, and how urgently should organisations begin preparing? 

Moona Ederveen-Schneider: “The UK National Cyber Security Centre says organisations should complete detailed planning by 2028 and be fully migrated by 2035. 

“Google has set its own internal migration deadline of 2029, citing faster-than-expected advances in quantum computing. That reflects the wider sentiment I am seeing and the increasingly strong guidance being issued by governments globally. 

“Google is one of the organisations building these machines, so its decision deserves serious attention. 

“Large organisations typically need at least five years to complete a full cryptographic overhaul, while some may need twice that long. A 2035 deadline is therefore not generous. Organisations need to begin acting now. 

“My practical post-quantum transition framework is designed to deliver security improvements from the first day. It provides a clear starting point and a route through the process without overwhelming teams or budgets. 

“Organisations are also not preparing for a future threat in isolation. They are building more resilient architectures that can improve protection against current threats, including ransomware, AI-enabled attacks and supply chain compromise.” 

What mistakes do organisations make when beginning a post-quantum cryptography migration, and what should they do differently? 

Moona Ederveen-Schneider: “The first common mistake is treating post-quantum cryptography migration as a technology project and handing responsibility solely to the security team. 

“It is a whole organisational transformation. 

“The data that needs protecting sits across HR, legal and finance, not only within what DORA defines as critical business processes. 

“The second common mistake is beginning with the cryptographic inventory. 

“Contrary to the approach commonly repeated across the industry, I advise organisations to strengthen their data security posture first. 

“They must answer a fundamental business question: what are we protecting, and how long does it need to remain secret? 

“My practical post-quantum transition framework begins with that question and is designed to deliver security improvements immediately. It can be adapted for organisations and teams of any size.” 

The post Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider appeared first on IT Security Guru.

Q&A: Cyber’s Headed Back to the CSIDES

13 July 2026 at 14:33

Last year, CSIDES took place on The Grand Pier in Weston-super-Mare for the first time – a day filled with cyber talks, Cyber’s Got Talent, exceptional swag, its own theme song and – we are told – an extraordinary raffle. 

After the success of the inaugural event last summer, on the 9th October 2026, industry experts will gather in North Somerset once again, courtesy of event sponsors Tines, 4FOX Security, Consultants Like Us, Punk Security, PPRO and IASME.  

The Gurus sat down with the event’s organisers, Hazel McPherson and Jess Matthews (both Most Inspiring Women in Cyber Award winners and esteemed cyber professionals) to discuss all things CSIDES.

You’re back at the beach for the second annual CSIDES event! Can you tell readers who aren’t familiar what CSIDES is and who it’s for? 

CSIDES is the UK’s first cyber security event built by and for a coastal community. It is a one-day event which was designed to equip individuals, businesses, and educators with the tools to protect themselves in a rapidly shifting digital world. 

Why Weston? What makes The Grand Pier so special?  

Weston-super-Mare is a popular seaside resort in Somerset. However, like so many coastal communities in the UK it suffers from historical underinvestment in terms of opportunities in tech and cyber security. 

As a result, talent leaves the town to explore roles in larger cities, such as Bristol, Exeter or further afield. CSIDES was created to show that it is possible to stay and be part of the highly dynamic field of cyber security. Not only that, but local businesses also have access to experts on their doorstep who can provide support.

The Grand Pier is a renowned feature of the town. We could not think of anywhere better to host CSIDES, as an iconic symbol which we felt was the perfect setting for the event. Attendees can immerse themselves among the rides and gaze across the Bristol Chanel whilst taking in serious, cyber security topics in a fun atmosphere! 

What can attendees expect to see at this year’s event? Can you give us any sneaky insider insight?

We have a TV celebrity as a speaker! A workshop on scam callers. The Big Fat Quiz of the Pier. We have 5 rooms of accessible talks and interactive activities. Some of (if not the best) swag in the South West!    

Reflecting on last year’s event, what’s your favourite thing about CSIDES? What did you learn? 

It was exciting for me to see people with no experience in cyber working alongside really experienced senior leaders in cyber in the workshops. Realising that we have created a space where people could talk about cyber in a meaningful way regardless of experience or skills.
 

The local community may not be as knowledgeable about cyber as those who work directly in the industry. Why do events like these matter to them too?

We in the industry are poorer when we only look inwards. There are many in cyber security who see their role as more than a job, it is their mission to protect. To protect our families, communities, businesses and nations. We must be outward-looking as it is shared responsibility, and this is why events like CSIDES matter. We can start at home and locally, empowering people with knowledge so they can walk away from the Pier with steps to better protect themselves. What is more rewarding than that? 

And finally (and just for fun), what’s the best part about the seaside?

Hazel: My favourite thing about the seaside is how it never really changes. As a child, it was all about family holidays, donkey rides, building sandcastles, and paddling in the sea. Those are some of my happiest memories. 

These days, I appreciate it in a different way. I love the sound of the waves, the feel of the sand between my toes, and spending hours looking for unusual pebbles or peering into rock pools in the hope of spotting a tiny crab, a shrimp, or another glimpse of life beneath the surface. 

There is something wonderfully calming and familiar about the good old British seaside. It has a way of slowing life down and reminding me to simply enjoy the moment.

Jess: For me, I was born in Weston-super-Mare and the best part about growing up at the seaside has to be crabbing with my brother. I spent a lot of my childhood looking for limpets on the rocks or using bacon as bait (they prefer it smoked!). There is nothing more satisfying than pulling up the line and seeing a lot of crabs. The bucket was always full and releasing them afterwards was chaotic as they all scurried away in multiple directions. Memories!
 

The post Q&A: Cyber’s Headed Back to the CSIDES appeared first on IT Security Guru.

Pentesting is dead. Long live pentesting.

3 July 2026 at 07:11

Penetration testing has been a cornerstone of cybersecurity for decades. For many organisations, it is part of an annual security programme, providing reassurance for boards, evidence for customers and insurers and a demonstration of compliance with regulatory requirements. It is also one of the most commonly purchased cybersecurity services. 

Despite its widespread use, penetration testing is actually one of the least consistently defined services in the industry. Two providers can assess the same environment and produce very different reports. One may identify critical vulnerabilities that another overlooks. Recommendations, severity ratings and conclusions can differ significantly, even though both engagements are described as a “penetration test”. This level of inconsistency raises questions around whether an organisation actually knows what it is buying. 

The answer is more complicated than it may first seem. A penetration test is not a standardised product with identical or even similar outputs regardless of who performs it. Its quality depends heavily on the tester’s methodology used, the time allocated and, crucially, the scope agreed before the work even begins. These variables mean that the value of a penetration test differs enormously from one provider to another. 

Unfortunately, many organisations still purchase penetration testing as if it were a commodity. This means the procurement decisions will often be driven by cost or by the need to satisfy a compliance requirement, instead of by a clear understanding of what the organisation is really trying to achieve. The result is a report that proves that a test has taken place but not necessarily one that provides a meaningful level of insight into the organisation’s real exposure to cyber risk. 

That challenge has become even greater as technology environments have evolved. Organisations operate across cloud platforms, SaaS applications, remote devices, third-party services and complex digital supply chains. Many businesses struggle to maintain a complete inventory of their own assets. And if you do not have full visibility of your environment, it is difficult to define the scope of a penetration test, let alone be confident that every important system has been assessed. 

This is where the phrase “passing a penetration test” can become misleading. A penetration test only assesses the systems and scenarios that have been agreed upon and are within its scope at a particular point in time. It cannot provide assurance about assets that were omitted, systems deployed after the test, or new vulnerabilities that emerge the following week. Treating the report as proof that an organisation is secure risks creating a false sense of confidence. 

Compliance has contributed to this mindset. Many standards and regulations require organisations to demonstrate that security testing has taken place, which is a good thing. However, there is a danger that the objective of the penetration test becomes obtaining the report rather than improving security. Cyber resilience is not measured by whether a penetration test was completed but by whether the findings are understood, prioritised and used to reduce genuine business risk. 

But none of this means that penetration testing is obsolete. It is quite the opposite. Independent, expert-led testing is one of the most effective ways of understanding how an attacker could compromise an organisation. What needs to change is the expectation that every penetration test is equivalent, or that a single assessment can provide lasting assurance in an environment that changes continuously. 

The future of penetration testing is likely to be more contextual and outcome driven. Rather than asking whether a business has had a penetration test, the focus should be on whether they have tested the systems that matter most, whether the testing reflected realistic attack scenarios and whether the findings have improved their security posture. 

Of course, the value of a penetration test has never been the report itself. Its value lies in helping organisations understand where they are vulnerable, why those vulnerabilities matter and what they should do next. If the industry can refocus on those outcomes rather than simply delivering another compliance exercise, then penetration testing has a very strong future.

The post Pentesting is dead. Long live pentesting. appeared first on IT Security Guru.

❌
❌