Reading view

There are new articles available, click to refresh the page.

NeuroCyber granted charity status to expand support for neurodivergent talent in cybersecurity

NeuroCyber, the organisation dedicated to improving opportunities and career outcomes for neurodivergent individuals across the cybersecurity profession, has been granted charity status by the Charity Commission for England and Wales. This is a major milestone for NeuroCyber, enabling it to expand its work to create a more inclusive cybersecurity profession where neurodivergent people can access opportunities, thrive and progress throughout their careers.

Charitable status will enable NeuroCyber to significantly expand its programmes, partnerships and community initiatives, helping more neurodivergent people build successful careers in cybersecurity while supporting employers to create more inclusive workplaces.

To support this next phase of growth, NeuroCyber is launching a UK-wide appeal for corporate partners, strategic partners and volunteers. Support from partners and volunteers will help fund an expanding programme of events, research, awareness campaigns, educational resources and practical initiatives designed to reduce barriers to employment and career progression for neurodivergent professionals.

Over the coming months, NeuroCyber will also launch the NeuroCyber Charter, giving organisations the opportunity to publicly demonstrate their commitment to creating workplaces where neurodivergent employees are welcomed, understood, supported and empowered. The Charter encourages organisations to embed neuro-inclusive practices across recruitment, onboarding, career development and workplace culture, recognising that neuro-inclusion is an ongoing commitment rather than a one-off initiative.

Allie Andrews, founding trustee at NeuroCyber CIO, said: “Achieving charity status is recognition of the vital role neurodiversity has to play in the future of cybersecurity. Our focus has always been on helping neurodivergent people access rewarding careers, realise their potential and thrive within the cybersecurity profession. Too many talented individuals still encounter unnecessary barriers to entering and progressing within the industry, despite the unique skills and perspectives they can bring.

“The wider opportunity is also clear. The UK Government reports that 49% of UK businesses have a basic cybersecurity skills gap, while latest ISC2 research found that 12% of cybersecurity professionals surveyed globally identify as neurodivergent. Neurodivergent talent is already an important part of the cybersecurity workforce but there is enormous potential to unlock more of that talent by creating workplaces where everyone has the opportunity to succeed.

“This new chapter gives us the platform to scale our impact but we can’t do it alone. We’re calling on organisations and individuals who share our vision to help us build a cybersecurity profession where talent is recognised for its strengths, not limited by outdated ways of thinking. Whether through sponsorship, volunteering or signing our forthcoming NeuroCyber Charter, everyone has a role to play in creating lasting change.”

NeuroCyber is inviting organisations of all sizes to become partners, with opportunities designed to help businesses demonstrate their commitment to diversity while supporting meaningful industry change. Partners can contribute to NeuroCyber’s work through thought leadership, event participation, networking, research and other industry initiatives, with every pound directly funding the charity’s work.

NeuroCyber also welcomes organisations able to provide non-financial support, including mentoring, design, event support and specialist expertise.

NeuroCyber is also calling on volunteers from across the cybersecurity community to share their skills and experience by supporting mentoring, research, events, outreach and community engagement activities.

The post NeuroCyber granted charity status to expand support for neurodivergent talent in cybersecurity appeared first on IT Security Guru.

Why hostile state cyber activity is now a day-to-day business risk

Christopher Clark, Cyber Security Incident Response Team Director, Thrive 

Geopolitical escalation can become a cyber security problem for businesses far more quickly than many boards expect.

The National Cyber Security Council (NCSC) has warned that UK critical infrastructure faced more than 200 cyber incidents over the past year, with around three-quarters believed to be linked to state actors. Analysis of the conflict involving Iran has also found cyber retaliation following military escalation within hours, bringing events overseas much closer to the day-to-day reality of UK organisations.

That risk has already been demonstrated on UK soil. In July, a cyber-attack reportedly linked to Iranian hackers forced a small UK power generator offline for four days. The government said there was no risk to the wider energy system, but the incident shows how quickly geopolitical cyber activity can translate into operational disruption.

Energy, healthcare, water and telecoms remain obvious targets because disruption can affect essential services. Yet, hostile state activity does not stop at the boundary of critical infrastructure.

Hostile state risk extends beyond critical infrastructure

A business does not have to be an obvious target to become one. It may be connected to a larger customer, supplier, regulator or public body that an attacker ultimately wants to reach. In other words, you do not have to be the objective. You just have to be the way in.

There is also the risk of spillover. Targeting can follow politics rather than the size of a company or its balance sheet. If an organisation has operations or suppliers connected to a live conflict, it can become collateral even when nobody set out specifically to target it.

Businesses also need to reconsider what hostile state activity is likely to look like inside their own environments. The most significant intrusions are not necessarily the noisiest.

Security teams may be watching for malware, failed logins or a sudden increase in DDoS activity. Capable attackers increasingly use valid credentials and legitimate administration tools, allowing malicious behaviour to resemble normal activity.

There may also be no obvious warning to investigate. If the plan is to wait for one, the organisation may already be too late by the time it appears.

A better working assumption is that a capable actor could already be inside, or could get in without immediately triggering an alert. The question then becomes what they can actually do once they have that foothold.

Trusted technology can create the same problem. Management platforms and legitimate system tools can be repurposed by attackers, while compromised software packages can provide access to many organisations at once. Activity entering through a tool or supplier that the business already trusts may attract less scrutiny because it appears legitimate.

The same principle applies to suppliers. If a connected partner has been compromised, one of the first questions should be what has been done to separate that organisation from your own environment. Continuing normal access without understanding what happened risks transferring their exposure into your network.

Organisations should know how they would isolate an affected supplier and what evidence would be required before connectivity resumed. They may need confirmation of how the attacker entered and which systems were affected, alongside assurance that the access has been removed. Shared applications or other connections may have to remain unavailable until that information is clear.

That can be uncomfortable for the business, but restoring connectivity too quickly can create a much bigger problem later.

The time available to make these decisions is shrinking. Threat actors can analyse newly disclosed vulnerabilities and move to exploitation quickly, with AI making parts of that process faster. In some cases, organisations can be exposed within hours of a vulnerability becoming known.

Patch management therefore cannot always wait for the normal maintenance cycle. Teams need to know which vulnerable systems create the greatest risk and be ready to prioritise them when a new vulnerability emerges.

Geopolitical risk can also outlast the immediate conflict.  A ceasefire does not automatically remove access established during a period of heightened activity, nor does it mean proxy groups will stop operating. Attackers have good reason to preserve a foothold that may be useful later. I have seen access remain available inside an environment for three years or more.

That is why an easing of geopolitical tension should not automatically be treated as a reduction in cyber risk.

Containment depends on preparation and experience

Preparation has to focus on containing an attacker as well as keeping them out. Standing privileges should be kept to a minimum, networks should be segmented so an attacker cannot move freely towards critical systems or backups, and offline backups need to be regularly tested.

Organisations also need a clear view of their external attack surface and where their greatest points of exposure lie. Regular tabletop exercises should use realistic scenarios informed by current threat intelligence.

If an attacker gained access through a VPN or compromised supplier, what could they reach next? How far could the incident spread? And who has the authority to cut them off?

That authority needs to be clear before an incident. Time can be lost when technical teams know what needs to happen but must wait for decisions on whether systems can be disconnected or business processes interrupted.

Experience is equally important. Frameworks provide structure, but serious incidents rarely follow a script. Responders who have handled repeated compromises understand where investigations can stall, which decisions cannot wait and what needs to be secured before systems are safely returned to service.

For many organisations, maintaining that level of incident response experience entirely in-house is difficult. What matters is having access to people who have dealt with incidents under real operational pressure and can apply that experience quickly when normal assumptions no longer hold.

Hostile state cyber activity should now be treated as a routine business risk rather than something considered only when international tensions make the headlines.

Organisations should be asking a more immediate question: if something gets through today, how far can it spread before we stop it?

Answering that question before an attack happens can make the difference between a contained security incident and a prolonged operational crisis.

The post Why hostile state cyber activity is now a day-to-day business risk appeared first on IT Security Guru.

The UK’s Cyber Community Comes North as CyberFest returns for 2026

The North East’s biggest cyber security festival returns this October. Now in its ninth year, CyberFest has grown into a major national platform for showcasing the region’s cyber and secure AI excellence. Taking place across the North East throughout October, the festival will connect businesses, innovators, government and specialist clusters from across the UK, putting the region’s talent, ambition and capability firmly in the spotlight.

CyberFest is organised by CyberNorth, a membership community which brings together people, organisations and ideas from across the North East to drive progress in cyber security, AI, data and quantum technologies.

Although regionally grown, CyberFest is no longer just a regional event says Jon Holden, CEO of CyberNorth, CyberFest is about bringing the UK’s cyber community to the North East and showing the country what this region can do. What started as a regional festival has grown into a national platform, bringing together businesses, government, innovators and industry leaders to connect, collaborate and create new opportunities.”

The mission is simple: connect, educate and empower the region’s digital ecosystem, while putting the North East firmly on the map as a place to innovate, invest, collaborate and build business.

More than 1,000 people attended CyberFest events last year and this year organisers CyberNorth emphasise the festival will build on that momentum, exploring the opportunities and challenges facing the UK.

The programme will feature high-impact events throughout October, including the CyberFest Community Conference on 19 October and the CyberNorth Awards on 21 October, alongside a series of specialist afternoon sessions exploring the critical role of cyber across adjacent industries.

At the heart of this year’s festival is the CyberFest Community Conference, a major gathering of the North East’s cyber community alongside national and international businesses, government, industry leaders and specialist clusters. The conference will deliver a packed programme of insight, debate and networking, starting with high-profile speakers from the UK Government’s National Cyber Security Centre, CFC Insurance and Information Security for London, covering everything from data and cyber resilience to the dark web and the rapidly evolving threat landscape.

Attendees will also hear from an expert cyber and AI panel, featuring industry leaders from organisations including the Department for Work & Pensions and Tombola, exploring the importance of human centric security cultures and the opportunities and challenges emerging as cyber and AI become increasingly interconnected.

Specialist afternoon sessions will bring cyber professionals together with experts from key adjacent sectors in Space, Defence, AI, Energy and Advanced Manufacturing, highlighting the region’s strength in cross-cluster collaboration and the vital role cyber security plays across different sectors, from securing the UK’s AI Growth Zone and protecting offshore energy infrastructure to safeguarding digital production lines and building regional capability for future defence threats.

Jon Holden added: The North East has a huge opportunity to lead in secure AI and technology, but growth and security have to go hand in hand. CyberFest gives us a chance to put the region’s talent, businesses and innovation centre stage, while bringing the conversations that matter most directly into the North East.

Secure AI will take centre stage at CyberFest this year, reflecting the North East’s growing ambition to become a leading UK destination for Secure AI innovation and growth, exploring how the region can maximise its position as an AI Growth Zone, while recognising that growth must go hand in hand with security.

The showcase continues on 21 October with the CyberNorth Awards, celebrating the people and organisations driving the region’s cyber and AI sector forward. CyberNorth is calling on North East businesses, organisations and cyber professionals to submit nominations before 5:00pm on 14 September 2026.

The awards are open to all CyberNorth members and affiliations and recognise achievements across six categories including Rising Star and Outstanding Cyber Professional.

Two new categories have also been added to the line up to celebrate the Micro Businesses and those on the international stage. This year’s prestigious judging panel includes representatives from the Department for Digital, Culture, Media and Sport, Barclays, Northstar Ventures, TLT LLP and the North East Mayoral Strategic Authority, formerly the North East Combined Authority.

Jon Holden said: “CyberFest is about showcasing and celebrating the North East – we are helping to put the North East on the national stage, opening the region’s doors to the UK’s cyber and technology community and turning connections into real opportunities. 

CyberNorth’s ambition is to attract new business, investment and talent to the region, forge partnerships across the UK and beyond, and showcase the North East as a leading destination for cyber, secure AI and technology innovation. 

We have incredible businesses, brilliant people, world-class expertise and huge opportunities in front of us. CyberFest gives us a chance to bring all of that together and show the rest of the UK what is happening here.” 

With a month of events, national and international organisations coming to the region, and conversations spanning some of the UK’s most strategically vital industries, CyberFest 2026 is set to put the North East at the heart of the UK’s cyber and secure AI conversation.

The post The UK’s Cyber Community Comes North as CyberFest returns for 2026 appeared first on IT Security Guru.

7 Ways to Boost Conversions on Your Website

If your website is attracting visitors but not generating enough enquiries, sales or leads, there are several techniques you can use to improve your conversion rate. From adding a website toolbar and interactive calculators to using limited-time offers and personalised pop-ups, the key is to make it easier and more compelling for visitors to take the next step.

This is particularly important because even small improvements can have a meaningful impact. For example, Baymard Institute estimates that the average ecommerce cart abandonment rate is 70.22%, highlighting how many potential customers leave before completing a purchase. 

Meanwhile, research from Popupsmart found that more than 10,000 popup campaigns achieved an average conversion rate of 3.49%, demonstrating that well-designed pop-ups can still play an important role in lead generation.

1. Website Toolbar

A website toolbar like this one from Barra can provide visitors with immediate access to your most important calls to action. Instead of making users search through your website for contact details, offers or booking options, a toolbar can keep these features easily accessible as they browse.

For example, you could include your telephone number, live chat, special offers, reviews, social media links or a “Get a Quote” button.

The advantage is that visitors don’t need to scroll back to the top of the page to take action. Your key conversion opportunities remain visible throughout their journey.

2. Limited-Time Offers

Creating urgency can encourage visitors who are interested in your product or service to act now rather than putting off their decision.

Limited-time discounts, seasonal promotions and offers with a genuine expiry date can all help create this sense of urgency. You could also include a countdown timer showing exactly how long remains.

The important word here is genuine. If customers regularly see the same “24-hour” offer every day, it can undermine trust. Make sure your deadlines and promotions are legitimate.

3. Calculators

Interactive calculators can be an excellent conversion tool because they provide something useful while getting visitors actively involved with your website.

A mortgage company could offer a repayment calculator, for example, while a finance provider might have a borrowing calculator. A business offering professional services could provide a cost calculator to give visitors an indication of what they might pay.

Once someone has entered their information and received a result, you can then encourage them to take the next step, such as requesting a personalised quote or speaking to an expert.

4. Pop-Ups

Pop-ups have a reputation for being intrusive, but the right pop-up, shown at the right time, can be an effective conversion tool.

Rather than displaying one immediately after someone lands on your website, consider triggering it after a visitor has spent some time on the page, scrolled through your content or shown an intention to leave.

You could use a pop-up to offer a discount, collect an email address, promote a downloadable guide or encourage someone to contact your sales team.

Recent research from Omnisend, based on 1.24 billion popup displays, found an average email popup conversion rate of 2.1% in 2025. The takeaway isn’t that every pop-up will achieve the same result, but that timing, relevance and simplicity matter.

5. Phone Numbers with a Sales Agent’s Face

A telephone number can become more effective when it’s paired with a real person.

Adding a photograph and name alongside your phone number can make your business feel more approachable and give visitors confidence that there is a real person available to help them.

This can work particularly well for businesses offering expensive, complicated or highly personalised products and services. Instead of simply seeing “Call us”, visitors see exactly who they could speak to, like this example from VZ Builders.

You can strengthen this further with messaging such as “Speak to Sarah today” or “Call our team for expert advice”.

6. Spin the Wheel

Gamification can make an otherwise standard lead-generation form more engaging. A “spin the wheel” feature gives visitors the opportunity to win a discount, free consultation or another incentive.

It can be particularly effective for ecommerce businesses, where a visitor might receive 10% off, free delivery or another relevant reward in exchange for their email address.

There is some evidence behind the approach, too. Omnisend’s 2025 data found that gamified pop-ups such as “Wheel of Fortune” formats achieved conversion rates of 3.5% or higher, compared with its overall average of 2.1%.

7. Questionnaires

Finally, consider replacing a traditional contact form with an interactive questionnaire.

Instead of asking visitors to immediately provide their name, email address and telephone number, you can start by asking questions about their requirements such as this example from Daylight Protect. This makes the process feel more like a conversation and can help you understand what the visitor actually needs. It is essentially ‘less forced.’

Plus, there is evidence that narrowing down a customer’s requirements helps with the final conversion.

At the end of the questionnaire, you can ask for contact details in exchange for a quote, recommendation or more information.

Start Testing Your Website

There isn’t one conversion technique that will work for every business. What works for an ecommerce store may be completely different from what works for a financial services company or property business.

The best approach is to test different techniques, measure the results and continually refine your website. A combination of a persistent website toolbar, well-timed offers, useful calculators, targeted pop-ups and personalised interactions can help turn more of your existing website traffic into genuine enquiries and customers.

The post 7 Ways to Boost Conversions on Your Website appeared first on IT Security Guru.

Retired Devices, Active Risks: How an ITAD Company Protects Data After Decommissioning

A laptop can be removed from an employee’s desk, disconnected from the network and marked retired in an asset system within the same afternoon. None of those steps means the data risk has disappeared.

Retired technology often sits in storage rooms or staging locations before reaching its final destination. During that period, devices still contain business records, credentials, customer information and employee files. Once hardware leaves normal IT operations, familiar controls such as endpoint monitoring and access management often stop following it.

For security teams, decommissioning is a transition point rather than the end of the job. A secure disposition process must account for the device, the data on it, every handoff and the evidence showing what ultimately happened.

1. Retired Devices Are Still Data Bearing Assets

The first mistake in technology retirement is treating unused equipment as ordinary surplus. A device that no longer has operational value can still hold valuable information.

That is why working with a certified IT asset disposition company matters when equipment leaves active service. A qualified ITAD Company should treat security as part of disposition from the first inventory scan through sanitization, reuse, recycling or destruction.

Risk is not limited to functioning equipment. A laptop with a broken screen can still contain a readable solid state drive. A server that will not boot can retain intact storage media. Even devices headed to recycling need controlled handling until data has been addressed.

2. Residual Data Appears in More Places Than Expected

Security teams usually think first about hard drives and solid state drives. Those are obvious targets, but they are not the only places information remains. Retired technology can contain:

  • Local documents, downloads and cached files
  • Browser history, saved sessions and authentication tokens
  • Email archives and application data
  • Customer, employee or student records
  • Network settings, configuration files and system logs
  • Stored credentials and encryption related information
  • Data on removable media, memory cards and attached storage

Printers, multifunction devices, phones, tablets, networking equipment and specialized hardware also contain storage. A sound retirement program begins by identifying data bearing assets rather than assuming only traditional computers require sanitization.

3. Factory Resets and File Deletion Are Not a Security Program

Deleting a file normally removes its reference from the active file system. It does not prove that the underlying information is unrecoverable. A factory reset also varies by device, operating system and storage technology.

This matters when hundreds or thousands of devices are retired at once. A technician clicking through reset menus is not the same as a controlled sanitization process with defined methods, verification and reporting.

An experienced ITAD Company should have a written approach for different media types and clear procedures when a normal wipe fails. Security teams need evidence of the result, not simply confirmation that someone started a reset.

4. Pickup and Transportation Create a Different Kind of Exposure

Once equipment leaves an office, school, hospital or data center, physical security becomes part of data security. Devices can be misplaced, mixed with another shipment or arrive with inventory discrepancies.

The strongest controls start before pickup. Organizations should establish an inventory or manifest, define who can release the equipment and document the point where custody transfers. Packaging, loading, transport and receiving should fit into the same controlled process.

For multi location projects, consistency matters even more. Equipment collected from several offices should follow the same handling rules even when pickup dates differ.

5. Chain of Custody Turns Movement Into Evidence

A documented chain of custody answers a basic audit question: where was the asset, and who controlled it?

Good records connect a unique asset identifier with meaningful events. Depending on the project, that includes pickup, receipt, serialized intake, data processing and final disposition. If the receiving count does not match the pickup manifest, the difference should be recorded and investigated. Useful chain of custody records generally include:

  • Serial number, asset tag or another unique identifier
  • Collection location and pickup information
  • Receiving and inventory confirmation
  • Data sanitization or destruction status
  • Exceptions such as missing drives, damaged devices or failed wipes
  • Final disposition such as resale, reuse, recycling or destruction

For security and compliance teams, this record closes the gap between equipment leaving the building and knowing what happened to it.

6. NIST 800-88 Provides a Framework for Sanitization Decisions

NIST SP 800-88 gives organizations a structured way to manage media sanitization. The current Revision 2 guidance focuses on a sanitization program based on information sensitivity, the media involved and its intended disposition.

The three methods are Clear, Purge and Destroy. Clear uses logical techniques to protect against simple, noninvasive recovery through the normal device interface. Purge uses stronger physical or logical techniques intended to make recovery infeasible even with advanced laboratory methods while preserving potential reuse. Destroy renders recovery infeasible and leaves the media unusable for data storage.

The right method depends on the device, storage technology, data sensitivity and what will happen to the asset afterward. Reusable equipment often benefits from verified sanitization that preserves resale or redeployment value. Media that cannot be reliably sanitized needs another path.

7. Physical Destruction Has a Specific Role

Shredding every drive is not automatically the right answer. It eliminates opportunities for reuse and value recovery when secure sanitization is appropriate. At the same time, some media should not return to service.

Physical destruction is appropriate when storage is damaged, sanitization fails, policy requires destruction or the media contains information that warrants that disposition method. It also provides a route for drives that cannot be accessed well enough to complete a verified wipe.

A capable ITAD Company should distinguish between assets that can be securely sanitized and reused and media that requires destruction. That decision should follow policy rather than convenience.

8. Asset Level Reporting Exposes the Exceptions

Large disposition projects rarely proceed without a few surprises. A listed laptop is missing. A drive has been removed. A device arrives damaged. A wipe does not complete. A serial number appears in the shipment but not on the original inventory.

These are not administrative nuisances. They are security exceptions that need to be visible.

Asset level reporting allows an organization to reconcile the project instead of receiving one final number. Reports should show what was received, how each data bearing asset was handled, which records failed normal processing and how those exceptions were resolved.

This detail also helps other business teams connect security outcomes with resale, recycling and final disposition.

9. A Certificate of Data Destruction Needs Supporting Detail

A certificate has value only when it proves something specific. A generic document stating that a shipment was destroyed offers little help if an auditor asks about one particular server or laptop.

A useful certificate of data destruction should connect the outcome to identifiable assets and the processing record. It should establish what was sanitized or destroyed, the method used, the result and the relevant date or project information.

The certificate should also align with the broader audit trail. If an exception occurred, reporting should show how it was resolved. If some devices were sanitized for reuse while other drives were physically destroyed, the records should make that difference clear.

10. Provider Evaluation Should Go Beyond a Certification Logo

Certifications give buyers an important starting point, but security teams still need to understand how a provider operates. R2v3 and recognized ISO management system certifications can demonstrate that documented processes and independently assessed controls are in place. They do not replace project specific evidence.

When evaluating an ITAD Company, buyers should examine how the provider handles serialized inventory, chain of custody, sanitization, physical destruction, exceptions, downstream recycling and final reporting. They should also ask which controls apply at the facility processing their equipment.

A provider should explain the process plainly. Security teams should know when custody changes, how failed sanitization is handled and how each asset is reconciled at project close.

Keeping Data Security Intact Through Final Disposition

Technology retirement changes a device’s location and purpose, but it does not erase the information stored on it. The security obligation continues until data has been appropriately sanitized or destroyed and the organization has records that support the outcome.

A well managed ITAD process keeps those final steps visible. It connects physical control, data handling and documentation so retired hardware does not become an overlooked gap in an otherwise mature security program.

The post Retired Devices, Active Risks: How an ITAD Company Protects Data After Decommissioning appeared first on IT Security Guru.

Why compliance does not guarantee cyber resilience

Cyber security has become one of the most audited and regulated areas of enterprise technology. Yet an organisation can satisfy every requirement on paper and still discover, during a real incident, that its systems, people or processes are not ready for the pressure that follows. Compliance can demonstrate that controls have been put in place; it cannot, on its own, demonstrate that those controls will continue to work when a critical service is disrupted. Here, Nathan Charles, head of customer experience at cyber resilience specialist OryxAlign, explains why organisations need to look beyond compliance and test whether their resilience claims stand up in practice.

Organisations invest significant time and resource into achieving certifications such as ISO 27001 and Cyber Essentials, while regulated firms face additional obligations under frameworks such as the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) operational resilience rules. These frameworks provide valuable structure and demonstrate a credible baseline of security maturity.

Compliance frameworks like these set a recognised baseline, create accountability and give boards and customers a way to benchmark security maturity. The risk lies in what happens post-certification.

For many organisations, passing an audit becomes the objective in itself, rather than a step towards genuine resilience. Certification and self-assessment exercises capture a snapshot of security controls at a single point in time, under conditions that are largely predictable. They rarely test what happens when those controls are placed under real pressure, such as a ransomware attack that spreads faster than the incident response plan anticipated, a misconfigured update that takes core systems offline, or a supplier outage with knock-on effects nobody had mapped. 

When the paperwork doesn’t match reality

The gap between documented compliance and operational reality is well evidenced. The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43 per cent of UK businesses reported experiencing a cyber security breach or attack in the past twelve months. This is despite most organisations already having basic technical measures, such as malware protection, firewalls and access controls, in place.

The financial services sector, where operational resilience obligations are most mature, illustrates the same gap. In March 2026, the FCA published its first detailed review of how firms had performed since the transition period for its operational resilience rules ended in March 2025. The review examined whether firms had genuinely embedded resilience into daily operations, or whether their self-assessments amounted to little more than a paperwork exercise.

This distinction matters because resilience is ultimately about outcomes rather than the existence of controls. An organisation may have an incident response plan, supplier assessments and documented recovery procedures, but that does not necessarily mean the right people know what to do when a critical service fails. It may also be unclear how one disruption affects another system, supplier or business process. These dependencies can be difficult to identify through conventional compliance exercises because they only become visible when the organisation is placed under stress.

In other words, an organisation can produce all the required documentation and still be unable to demonstrate that its most critical services would survive a severe but plausible disruption. The challenge is moving from asking whether a control exists to asking whether it delivers the intended outcomes when it matters most. 

Regulators are recognising the gap too

Encouragingly, this is not a case of compliance frameworks being wrong; it reflects how regulators and standard-setters are actively evolving what they expect organisations to demonstrate. The National Cyber Security Centre (NCSC) has developed its Principles Based Assurance approach specifically to move away from assessment against fixed, compliance-driven control sets, in favour of a risk-based approach.

The FCA has followed a similar trajectory, shifting its supervisory focus from asking firms whether they have identified their important business services, to asking whether they can prove they remain within agreed impact tolerances today, through tested evidence rather than policy documents.

Similar principles underpin the EU’s Digital Operational Resilience Act, which requires financial entities to test their resilience through scenario-based exercises rather than rely on point-in-time compliance reviews. Across sectors and geographies, there is a consistent direction of travel where demonstrated resilience, not paperwork, is the real measure of readiness.

This shift is important because it changes the question organisations need to ask themselves. Rather than viewing resilience as something demonstrated during an audit, it should be treated as an ongoing capability that needs to be evidenced throughout the year. A successful assessment should therefore be viewed as a starting point for further testing, rather than confirmation that the organisation is resilient. 

From checklist to stress test

For organisations that want to close this gap, the starting point is treating resilience as something that is tested and proven, not assumed because a framework has been satisfied. That means running scenario-based exercises that simulate severe but plausible disruption, such as the loss of a critical supplier, a ransomware incident or a major cloud outage, and observing how systems, teams and decision-making actually hold up under pressure.

The value of these exercises is not just about identifying whether an organisation can recover. They can expose assumptions that have gone unchallenged, reveal dependencies between critical services and show where responsibilities become unclear during an incident. They can also provide evidence for whether recovery objectives are realistic and whether teams have the information they need to make effective decisions when normal processes are no longer available.

Crucially, testing should not be treated as another compliance exercise. If an exercise only seeks to demonstrate that an existing plan works, there is a risk that organisations will overlook the weaknesses the exercise is intended to uncover. Instead, scenarios should be designed to challenge assumptions and provide an honest assessment of how systems, people and processes perform under pressure.

Compliance frameworks and regulatory obligations remain an essential part of managing cyber risk, and organisations should not disregard them. But they represent a floor, not a ceiling. Genuine operational resilience is proven under pressure, not certified on paper.

Organisations that build a culture of continuous testing, honest assumption-challenging and cross-functional ownership will be far better placed to keep critical services running when, not if, disruption occurs. The objective should not be to abandon compliance, but to use it as the foundation for a broader approach in which resilience is continually tested, evidenced and improved. 

To learn how OryxAlign helps organisations map digital dependencies and strengthen operational resilience, visit www.oryxalign.com.

The post Why compliance does not guarantee cyber resilience appeared first on IT Security Guru.

The first domino of AI disruption: How frontier models are revolutionising software security

Jimmy White, Chief Technology Officer, AI Security, F5

The first domino has well and truly fallen. The advent of high-powered AI models that can rapidly find software vulnerabilities that have lain hidden – in some cases, for decades – effectively makes static code analysis the first significant problem to be solved by AI.

The first-, second-, and even third-order effects of models such as Anthropic’s Claude Mythos Preview and ChatGPT 5.4-Cyber by OpenAI are the hottest topic in enterprises globally, for good reason. By pairing powerful AI with huge volumes of code data and existing vulnerability databases, these models know what good and bad code looks like, and can cycle through code at machine speed to find bugs and security issues.

Put simply, there has never been anything better than these AI models at detecting vulnerabilities in source code; they are highly capable tools that outperform all current best-in-class solutions. Their ability equates to a human coder that knows every existing disclosed software flaw, can read as fast as a computer, has perfect memory, and has 100% recall in milliseconds.

The potential and limitations of frontier models

There are already countless examples of the models finding real-world software vulnerabilities that have lain dormant for long periods but never known. There are also likely to be flaws that are unknown to their host company but are being abused by threat actors behind the scenes – a known tactic of attackers who want to keep their best weapons under wraps.

Most recently, there are eye-opening incidences of test models chaining together attacks or breaking their boundaries, such as the OpenAI models that accessed Hugging Face from a sandbox environment. Anthropic is investigating three incidents where Claude test models accessed the internet and breached the systems of outside organisations.

What does it all mean for already-stretched IT security teams and the industry as a whole? First, the utopian scenario: organisations with access to these models can rapidly find all the vulnerabilities in their existing code base and go about fixing them, reaching a better security posture. At the same time, all their new code can go through the models, so there is no ‘bad’ new code, no new security vulnerabilities.

Enterprises can also apply the models at all the entry points for potentially harmful code into their organisation. Any open source tools can be checked before usage; in M&A scenarios, acquirers can insist on the code base of potential acquisitions going through the AI models; companies can evaluate the source code of vendors that want their business; and so on.

However, the utopian thesis quickly breaks, for two reasons. One is that the AI models are performing static code analysis. Yes, that’s a very big, important thing, but it’s not everything; there are still many flaws that AI can’t find because it can’t understand the patterns in runtime or race conditions.

Secondly, and maybe more importantly, because AI makes coding easier, enterprises around the world will undoubtedly be generating exponentially more new code. Google says that 75% of its new code is AI generated; at Anthropic and other AI-native companies, the proportion is as high as 90%. So, the speed that new code – and new vulnerabilities – are being created will at least match the speed these powerful models can find those vulnerabilities.

Static code analysis is just the opening act

For now, access to frontier AI models is limited, allowing participating organisations to find and fix bugs before they can be exploited in anger. But the frontier model companies have been frank that these models present unprecedented attack capability, as demonstrated in the Hugging Face incident, making them dangerous in the hands of a bad actor.

This is a familiar pattern in AI: each time the technology catches up from a cyber defence perspective, it offers similar advancements from an offensive perspective. As an industry, we are in an established cycle of ‘leap ahead, catch up’, a game of leapfrog between defenders and attackers as both sides advance their capabilities.

For the AI model makers, there is another aspect to the story. Source coding itself looked set to be the first market to be ‘cracked’ by AI, but it remains imperfect and still requires human input and oversight. In static code analysis, the frontier model companies have found a market they can dominate, defying the naysayers who question the enormous investment in AI and the technology itself.

Anthropic was first to this particular market, but OpenAI and other frontier model companies were quickly out of the blocks. Open-source models will similarly reach the bar for effective code vulnerability scanning, sooner rather than later.

Other markets will follow too. Anthropic’s collaboration with Canva, the design software company, and the launch of Claude Design signal is another example of a market that will be disrupted by the application of powerful AI to existing practices.

The AI giants are becoming surgeons, not general practitioners

In the Western world, there are now five titans in the AI arena: Anthropic, OpenAI, Google, Meta and xAI. They are going toe-to-toe with regular improvements in their models, opening up the prospect of a new class of specialised AI models for specific tasks that have practical – and financial – value.

Each time one of these players picks a new thing to focus on, it is a signal to where there’s market value. Sometimes they will choose the same market, but sometimes they will go for unique ones, maybe niche to their business area.

What those markets are will partly be decided by the model companies’ access to relevant datasets. Because of the popularity of its models with coders, for instance, Anthropic had access to an enviable source code dataset for training Mythos Preview.

Meta and xAI have access to vast social and communication data, though the nature of their data is very different. On top of that, search, email and mapping services hold near-infinite amounts of data on how people communicate and where they go.

This is all ripe for disruption by AI, with profound downstream effects. For example, enterprises may be discouraged from choosing a single AI provider as various model makers offer increasingly differentiated capabilities.

Buyers will benefit from competitive tension, but the cost and complexity of maintaining and securing multiple AI models will rise. Enterprises will have multiple subscriptions with multiple providers for different use cases.

AI disruption has only just begun

The static code analysis breakthrough did not happen by accident. The frontier model companies have pointed their currently most powerful models at a 20-year-old problem where they have the training data – and the models perform very well.

They will point the models at hundreds of other 20-year-old problems and do equally well. For the foreseeable future, we can expect massive disruption. This is the first domino to fall; there will be another, and another, and another.

The post The first domino of AI disruption: How frontier models are revolutionising software security appeared first on IT Security Guru.

Is AI entering the SOC at the right stage?

By Simon Phillips, CTO, CybaVerse

Alert fatigue is an issue that has plagued Security Operations Centres for years.

As organisations’ digital estates grow, there is more architecture to secure and more architecture for threat actors to attack, which has ultimately led to more alerts.

Today, on average a SOC will face thousands of alerts every day, each of which could indicate a potential threat. Each alert must therefore be analysed and investigated before appropriate action can be taken.

However, ask any SOC analyst and they will tell you the majority of these alerts are benign or false positives.

Yet, analysts will still spend hours investigating activity that ultimately poses little or no risk, hoping to identify the small number of genuine threats hidden amongst the noise.

Given the volume they face, and the possibility of missing something before it’s too late, it’s a noisy, high-stress environment that often leads to burnout and fatigue.

To tackle these issues, many SOCs today are turning to Artificial Intelligence (AI) to support the management of alerts.

In this scenario, the first-line analyst is replaced by an agent that reviews the incident to determine whether it’s malicious and if further action is required. The analyst must then review the conclusion reached by the agent to ensure it is accurate, but they don’t conduct the initial investigations themselves, which reduces the volume of alerts they have to investigate every day.

However, even despite these improvements, is there another way that could reduce the noise even further?

If organisations are still generating huge numbers of unnecessary alerts, have they actually solved the underlying problem, or simply moved it further downstream?

Moving AI upstream

Instead of asking AI to investigate incidents after they have been created, some organisations are using the technology much earlier in the detection process.

Rather than having AI decide whether an alert is malicious, in this scenario it’s used to help build better detection logic and more effective workflows before alerts ever reach an analyst.

For instance, in a phishing attack when an employee reports an email as suspicious, many security platforms immediately generate an incident that someone must investigate.

Traditionally, either a human analyst or an AI assistant would then collect additional context, checking whether links have been clicked, whether anyone else received the email, or whether similar activity appeared elsewhere in the environment.

If these types of checks are incorporated into the detection process, and the answers to the questions are no, then an incident would never need to be created in the first place.

The AI would determine that there was no wider threat, meaning the alert could be filtered out before it ended up in the SOC ticket queue.

The result is a faster, more efficient SOC, with far fewer unnecessary alerts reaching analysts.

From a customer perspective, this can also reduce the costs of working with an outsourced SOC partner.

Many AI-powered investigation platforms price their services according to the number of alerts they process, so reducing unnecessary alerts before they reach the investigation stage can improve efficiency while also helping organisations control operational costs.

Improving security through engineering

Another benefit of moving AI further upstream is that it limits access to sensitive customer data.

Many AI-driven investigation platforms analyse real customer logs and incident data to determine whether activity is malicious. While providers implement safeguards, some organisations are uncomfortable with sensitive operational data being processed by external AI systems, particularly where regulatory or contractual obligations apply.

Using AI during detection engineering changes this process. The AI is used to create the logic that identifies threats, not to inspect live customer data.

Once the detection rules have been verified, they can be applied consistently across customer environments without repeatedly sending operational data through AI models.

Solving the cause, not the symptom

The cyber security industry has become very good at handling alert fatigue, but not so good at preventing it. Is it time a different approach was adopted?

If security teams continue generating thousands of low-value alerts every day, replacing analysts with AI may improve efficiency, but it won’t address why the alerts exist in the first place.

As AI becomes more deeply embedded within security operations, organisations should consider where it delivers the greatest value. In many cases, the answer may not be at the point where analysts investigate incidents, but much earlier, where better detection engineering prevents unnecessary incidents from being created at all.

By reducing false positives at the source, this allows analysts to spend more time on genuine threats, while improving consistency, cutting costs and helping organisations make better use of both their technology and their people.

The post Is AI entering the SOC at the right stage? appeared first on IT Security Guru.

Vega Introduces Detection Skills, The New Open Standard for AI Reasoning in Agentic Cyber Defense

Vega, the pioneer of Agentic Cyber Defense, today launched Detection Skills: an open standard that redefines security operations for the AI era. The standard captures a team’s expert judgment as a self-improving agentic loop across detection, triage, and investigation. Available to the community as an open standard, or natively within the best-in-class Vega platform, they allow modern Cyber Defense Engineers to architect their reasoning once and scale it across everything they defend. It gives every company an answer to the question that matters most: can our defense keep pace with AI?

“AI-driven adversaries bypass static rules in every legacy SIEM, and no rule catches an attack it has never seen,” said Eli Rozen, co-founder and CTO, Vega. “Detection Skills answer with scaled AI reasoning that brings the judgment of your best Cyber Defense Engineers to every alert, in real-time. We made the standard open to ensure the whole industry rises with it: as attacks scale, defense compounds.”

Why Now

Frontier AI has collapsed the economics of cyberattacks. Intrusions that took skilled teams weeks now take minutes, with advanced models breaking containment and autonomously breaching organizations. Defenses built on legacy SIEM have not kept pace: they can only recognize known patterns in a threat landscape where attacks are generated, not repeated.

From Static Rules to AI Reasoning

Just as Sigma defined the traditional detection rule format, Detection Skills is what comes next for AI-first Cyber Defense teams. The engineer who builds a detection and the analyst who answers it at 2 a.m. often never meet, and the context dies in the handoff.

Detection Skills solves that: built on the Agent Skills framework originally developed by Anthropic, it attaches triage, investigation, and optimization directly to the detection, so the reasoning travels with it, enabling security teams to:

  • Detect and decide at AI speed. Triage and investigations run automatically the moment a detection fires, slashing MTTD and MTTR. Only what matters reaches a human, with a finished, evidence-backed workbook attached.
  • Scale cyber defense expertise. Author a skill once and the same judgment reaches every alert, known or unknown. Engineers keep complete transparency and control over the AI’s reasoning: what it checked, why it decided, and no change without their sign-off.
  • Adopt without disruption. Works alongside existing security investments. It launches with the Agentic Detection Library: 50+ skills from Vega Research and our partners, plus a sandbox to build, test, and export spec-compliant detections, and GitHub to contribute your own.

Vega proved Detection Skills in production on its Cyber Defense Platform, the standard’s reference implementation. Built on the Security Analytics Mesh (SAM), the platform runs the full loop directly on an organization’s data wherever it lives, across cloud object storage, Legacy SIEMs, and data lakes, with no data migration or ingestion tax.

Everything is live today at detectionskills.io and within the Vega platform. The full framework debuts this week at Black Hat USA 2026 at booth 3452.

Rushmere Fernandes, Deputy Chief Information Security Officer, Peloton

“We adopted Detection Skills early and started by encoding our own triage logic, the way our team actually works an alert, not a generic playbook. Every skill we ship gives us more explicit control over what the AI checks, escalates, and dismisses. The result is a queue we trust: fewer false positives, and every verdict arrives with its reasoning attached.”

Shawn McGhee, Chief Information Security Officer, Exemplar Luxury Group

“Retail runs on peak moments, and attackers know exactly when those are. My team cannot be the constraint on a Saturday in December. Detection Skills gives us leverage we can plan around: the expertise is written down, it runs on every alert, and it holds up when volume spikes. We are adopting it and sharing what we learn, because no security team should have to rebuild this work alone.”

Lamont Orange, Chief Information Security and Trust Officer, Cyera

“Defenders have never faced a moment like this: attackers are compounding their capability, and for the first time we can compound ours. An open standard for how detection decisions get made – auditable, transparent, shared – is how trust gets built at industry scale. Adopting Detection Skills and helping shape it is what good digital citizenship looks like in the AI era.”

Read the announcement: https://vega.io/blog/vega-introduces-detection-skills · See it live: vega.io/get-a-demo

The post Vega Introduces Detection Skills, The New Open Standard for AI Reasoning in Agentic Cyber Defense appeared first on IT Security Guru.

Margarita Howard’s HX5 Operationalizes CMMC Compliance Before AI Rules Arrive

Margarita Howard has spent two decades running a company in a government contracting market where the rules rarely hold still.

HX5, the defense and aerospace services firm she founded in 2004 and still leads, supports Department of Defense and NASA missions and has employed over 1,000 people across 34 states and 90 government locations over the course of its history.

For most of that span, the price of remaining eligible to do the work has been a requirement that keeps changing shape. Its current form is the Pentagon’s Cybersecurity Maturity Model Certification, known as CMMC, and behind it a second, still-forming set of rules aimed at artificial intelligence. How HX5 has prepared for both is a case study in the need to prepare for sudden shifts in security technology.

The CMMC

For years, contractors handling sensitive government data attested to their own cybersecurity practices. CMMC replaces much of that self-attestation with graded, checkable proof. The framework, which took effect under a Defense Department rule in 2025, sorts contractor obligations into three levels tied to the sensitivity of the information involved.

Level 1 covers basic Federal Contract Information and allows an annual self-assessment. Level 2 applies to Controlled Unclassified Information (the sensitive-but-unclassified material that runs through most substantive defense work) and, depending on the program, requires verification by an accredited outside assessor. Level 3 covers the government’s most critical programs and is assessed by the Pentagon itself.

The schedule is what gives the program its teeth. Phase 1 took effect on November 10, 2025, and the first certification requirements entered new contracts. Phase 2 follows exactly one year later, on November 10, 2026, when independent third-party certification becomes a condition of award for contractors handling Controlled Unclassified Information. At Level 2, that means demonstrating all 110 security practices drawn from the NIST SP 800-171 standard, backed by evidence an assessor can test rather than a contractor’s word.

That evidentiary bar is where many contractors are finding a gap between feeling compliant and being audit-ready. By early 2026 the assessment market had become a bottleneck. Industry trackers counted only about 1,000 contractors certified at Level 2, far short of the tens of thousands expected to need it, with roughly 80 accredited assessment organizations available to do the work. Wait times now stretch into months.

HX5 entered that crunch from the front of the line. The company was among a limited group of contractors to hold CMMC Level 2 certification by the end of 2025, well ahead of the Phase 2 mandate.

The distinction at the center of the scramble is between being aligned and being audit-ready. Many contractors hold documentation showing they meet the NIST practices on paper; far fewer can produce the evidence a certified third-party assessor will demand to confirm each control is implemented and operating. Early assessments can falter on the unglamorous fundamentals: access control, audit and accountability, incident response. The program also limits how much a contractor can defer through a plan to fix gaps later. Critical practices have to be working at the time of assessment, not promised. Closing that gap typically takes six to 12 months of focused work.

HX5’s Distributed Footprint and the Audit-Ready Bar

Firms like HX5 work across dozens of government locations, supporting research and development, engineering, information technology, and mission operations for federal customers. Holding a single, defensible compliance posture across distributed operations is an exercise in standardization: building the same expectations into vendor qualification, contract management, and the daily routines of each location, rather than reconstructing them program by program.

Certification is not a perimeter a contractor can defend alone, either. CMMC obligations flow down a contract: a prime that handles controlled data is responsible for confirming that the subcontractors and vendors it shares that data with meet the level required of them before the information changes hands. For a firm spread across dozens of programs, that turns compliance into a procurement function as much as a technical one. The company has to qualify partners against the standard, write the expectation into agreements, and verify it rather than assume it. The administrative weight of that work scales with the number of relationships a contractor maintains, which is part of why a footprint as broad as HX5’s makes the discipline harder to retrofit and more valuable once it’s in place.

Margarita Howard points to the pandemic as the stress test that proved the model. When operations went remote in 2020, the company had to keep meeting the government’s security and reporting standards while its workforce scattered. “We very quickly had to set up our employees to work remotely … to ensure the security standards that we have to report on,” she said, crediting a flexible, secure infrastructure the company had already paid for. The episode reinforced a lesson that maps directly onto CMMC: the firms that weather a sudden change in requirements are usually the ones that built the capacity before they needed it.

Howard frames the work as a matter of record-keeping discipline as much as technology. “It’s important that a company’s records are impeccable when working with the government due to the compliance reporting and audits that companies have to agree to in order to perform on government contracts,” she said.

She explained that HX5 put money into accounting and management systems built for government-contracting environments early on, and it keeps standing advisory capacity on hand for the regulatory questions that surface as programs evolve.

“We have built and maintained a team of advisers that specialize in the government industry,” Howard said. “They help us stay current with the policies and regulations that govern the defense sector.”

Workforce composition reinforces the same habit. Veterans make up more than 30% of HX5’s employees. Many arrive having already worked inside government security environments, with a built-in sense of why controls exist and what an audit will ask for. The company has taken part in the Defense Department’s SkillBridge initiative and the Hiring Our Heroes Corporate Fellowship Program since 2021, and the Department of Labor recognized its veteran-hiring record with a 2025 HIRE Vets Gold Medallion.

The capability also depends on a steady supply of people who can do the technical work behind the controls. Howard pointed to university partnerships as one of the company’s more productive and less expected investments. Those collaborations keep HX5 close to emerging technology and feed a pipeline of graduates into roles that, in this market, are hard to fill and harder to clear. A compliance program is only as strong as the staff who implement it day to day, and the same recruiting channels that bring in cleared engineers and technicians supply the people who keep audit evidence current between assessments.

The same rising bar that burdens HX5 also reshapes the field it competes on. Compliance has become a fixed cost of doing defense work, and fixed costs fall hardest on firms without the scale or the standing infrastructure to absorb them. Some smaller contractors may decide the controlled-data work is no longer worth the overhead; some larger primes have narrowed the lower-margin contracts they pursue. A mid-tier company that has already paid for the capability sits in the gap that opens between those two retreats, potentially able to take on work that requires certification without treating each new requirement as a fresh capital project.

But for contractors that deferred the investment, Phase 2 arrives as both a timeline problem and a cost problem. Assessor capacity is finite, the queue is long, and assembling a compliance foundation under deadline pressure costs more than building it in calmer conditions.

Howard’s read on that math reflects a market she has worked in since the company’s small-business beginnings. “There are heightened cybersecurity requirements,” she said, “and contractors will not have a choice but to implement them if they want to be a government contractor.”

The AI Layer Arriving on Top of CMMC

The next requirement is already visible. The FY2026 National Defense Authorization Act, signed in December 2025, directs the Pentagon to build a cybersecurity and physical-security framework for artificial-intelligence and machine-learning systems and to fold it into the existing CMMC program, a step often shorthanded as “CMMC for AI.”

Section 1513 of the law tells the Defense Department to address workforce, supply-chain, and adversarial-tampering risks in AI systems acquired for government work, drawing on established NIST standards. The provision does not set a final implementation date, but it required a status report to Congress on the plan in June 2026, with the new requirements ultimately expected to reach contractors through the same acquisition rules that carry CMMC.

The framework Congress has in mind is broad. As drafted, it reaches “covered” AI and machine-learning systems acquired by the Defense Department along with their components (source code, model weights, and the data and methods used to build them), and concentrates the most stringent requirements on the highly capable systems likeliest to draw the attention of sophisticated adversaries. It extends the logic of CMMC, protecting sensitive information, into a new category of asset the original program was not written to address.

The timing is what makes the moment unusual. The third-party certification requirement and the new AI rules are advancing through the same window, on the same acquisition machinery, aimed at overlapping populations of contractors. A firm that treats them as two separate fire drills faces a doubled burden in a compressed period. A firm that treats compliance as one continuous capability sees the AI framework as an extension of work already under way rather than a second front.

How fast the AI requirements bind on contractors is still unsettled. Section 1513 sets a planning process in motion rather than a finished rule, and the report due to Congress is a milestone in that process rather than the finalized rule itself. The practical questions will be answered in rulemaking still to come: which systems count as covered, how the requirements map onto CMMC levels, and when they appear in contract clauses.

For HX5, that uncertainty is an argument for the posture it already holds. A contractor with mature compliance machinery can wait for the specifics without falling behind, because adapting an existing program is a smaller task than building one.

The point is less whether the AI rules are wise than that they will arrive on top of an obligation the company already meets, through machinery it has already built. A contractor that has internalized CMMC should have the assessment discipline, documentation habits, and advisory bench to absorb an added layer without starting over. One still scrambling for its first Level 2 certification will be asked to take on a second, harder problem before finishing the first.

Howard has been pointing in this direction for some time. She, like many others in the industry, has stressed that government agencies will increasingly use AI to streamline procurement and evaluate contractor performance, and that compliance itself will grow more automated.

“Contractors will be required to integrate systems that provide continuous reporting and real-time audit capabilities,” she said. “We’ve invested heavily in technology infrastructure to meet these future demands.”

The post Margarita Howard’s HX5 Operationalizes CMMC Compliance Before AI Rules Arrive appeared first on IT Security Guru.

Blockchain and AI: Why Trusted Data Matters

The internet has crossed a threshold that content teams can no longer ignore. Independent analysis of tens of thousands of web pages found that mostly AI-generated articles accounted for an estimated 49.9% of sampled content published in the first quarter of 2026, a level that has held roughly steady since AI-written material briefly overtook human-written content in late 2025. For an industry built on accurate, verifiable information, that shift raises an uncomfortable question: how does anyone know what to trust? Enterprise blockchain technology and the sourcing discipline it enforces offer one of the clearest answers.

An internet flooded with unverified AI content

The volume of machine-generated writing, images, and video has scaled far beyond what most readers can manually vet. Detection studies tracking Common Crawl data, an open archive of hundreds of billions of web pages, show that AI-assisted publishing rose sharply after ChatGPT’s late-2022 launch. Since then, close to half of all newly published articles have involved AI.

Visual content shows a similar pattern: industry estimates suggest roughly 70% of social media images now involve an AI tool at some stage of creation or editing. Some of that content is well-edited and factually sound. However, much of it is not—generated at scale by automated pipelines with no editorial review, no named author, and no way for a reader to verify where a claim originated.

For readers and institutions alike, the practical effect is the same: provenance, not production speed, has become the differentiator. Knowing who created an image or video, what it was built from, and whether it has been altered since publication now matters more than how quickly it appeared online.

The trust problem AI creates for business

For enterprises, the risks go beyond misinformation. AI models can hallucinate figures, misattribute quotes, or launder unverified claims from one AI-generated source into another, creating a feedback loop where inaccurate information gets cited as fact simply because it appears in enough places. Business decisions built on unverifiable data, whether a compliance record, a supply chain log, or a financial disclosure, carry real financial and legal exposure.

Regulators are increasingly asking companies to demonstrate that their data has not been tampered with, not just that it looks correct. That is a harder problem than fact-checking a single article: it requires a system where the origin and history of a piece of data can be independently confirmed, rather than taken on faith from whichever platform published it.

Blockchain automation as a verification layer

This is where blockchain automation earns its place in the conversation. A blockchain ledger timestamps and hashes every entry at the moment it is recorded, then distributes identical copies across a network of nodes. Because altering one copy without altering all the others is computationally impractical, the record becomes tamper-evident by design. Applied to content and data pipelines—that means a document, dataset, or transaction—can carry a permanent, independently verifiable fingerprint of when it was created and whether it has changed since.

Enterprises exploring blockchain automation for provenance are not trying to stop AI from generating content; they are building an infrastructure layer that lets anyone confirm a piece of data’s origin and integrity after the fact, regardless of how it was produced.

Smart contracts turn trust into an automated process

Smart contracts extend that verification from static records into active processes. Rather than relying on a person to manually check that conditions were met before releasing funds, approving a transaction, or publishing an update, a smart contract executes automatically once predefined, on-chain conditions are satisfied. That removes a point where human error, or a manipulated input, could quietly undermine a process.

Combined with AI, smart contracts can also flag anomalies, such as data that deviates from an expected pattern, before that data is acted on. The result is a system where automation does not just move faster than manual review; it also creates its own audit trail, so any downstream user can trace exactly how and why a given outcome occurred.

Enterprise blockchain adoption accelerates

That combination of speed and accountability explains why enterprise blockchain adoption is accelerating even as AI-generated content becomes the norm rather than the exception. Financial services firms are using blockchain ledgers to record transaction histories that regulators can audit independently. Supply chain operators are using them to confirm that a shipment record has not been altered between origin and destination. Media and publishing organizations are exploring similar approaches to timestamp original content and establish a clear chain of authorship, a direct counter to the anonymous, unverifiable AI content flooding search results.

None of these use cases require blockchain to replace AI. They require it to sit alongside AI as the layer that answers the question AI cannot answer on its own: is this data what it claims to be?

As AI-generated material continues to make up roughly half of new web content, the value of a verifiable source only grows. Blockchain does not slow AI down or compete with it directly. It gives businesses, publishers, and regulators a way to confirm that the data feeding their decisions, and the content reaching their audiences, can be trusted.

The post Blockchain and AI: Why Trusted Data Matters appeared first on IT Security Guru.

Greg Soros Shares How Podcasters Build Lasting Authority Through Thought Leadership

Authority in podcasting is earned slowly and lost fast. Any host can launch a show. Building a reputation that makes listeners return for your take, over everyone else’s on the same subject, requires something more deliberate: a consistent editorial identity that holds up episode after episode, not just on the days when the topic lands perfectly.

Why Podcast Thought Leadership Works Differently From Other Platforms

LinkedIn posts, op-eds, and keynote talks can signal expertise. Podcasting does something different. It gives audiences an extended, unfiltered window into how a host thinks, reasons, and engages with complexity. Across 40 minutes, a listener forms a genuine impression of a host’s intellectual range and editorial judgment. That impression accumulates over episodes into something closer to a relationship than a resume.

Greg Soros has produced thought leadership content for executives, entrepreneurs, and independent voices across industries. Across those projects, the shows that built the deepest authority had something in common: a host willing to model good thinking in real time, draw unexpected connections, and hold a position under pressure. A bio might earn initial attention. The quality of the thinking across those 40 minutes is what earns a subscription.

Building a Recognizable Point of View

The most common mistake new podcast hosts make is trying to cover everything. A host with a take on every development in a broad space ends up sounding like a trade publication. The ones who build lasting reputations pick a lane and defend it. They develop a point of view that listeners learn to anticipate, argue with, and come back to test against new information.

Building that kind of editorial focus takes deliberate decisions in pre-production: What does this show believe? What would it refuse to say? What positions is the host willing to hold even when they’re unpopular? Answering those questions before recording begins is the difference between a podcast and a platform.

Greg Soros works with clients at this stage of development to find the angle that fits their actual expertise and stands apart in the market. Most professionals have a stronger point of view than they give themselves credit for. The job of production is to surface it and give it a format that holds up over time.

The Long Game of Podcast Brand Authority

Thought leadership built through podcasting compounds. A host who publishes consistently for two years with a clear editorial identity accumulates a body of work that’s searchable, shareable, and worth quoting. Each episode adds to a public record of ideas that keeps reinforcing the host’s credibility on specific topics.

That body of work tends to open doors other content formats rarely do: speaking invitations, media requests, business development conversations. The podcast becomes evidence. When someone is evaluating a host’s expertise before bringing them onto a panel or into a deal, a back catalog of substantive episodes carries more weight than a bio page.

Greg Soros built his studio around this long-game philosophy. The company creates content built to hold its value across time, earn attention on an ongoing basis, and keep building the case for the host’s authority long after the recording session ends.

The post Greg Soros Shares How Podcasters Build Lasting Authority Through Thought Leadership appeared first on IT Security Guru.

Managing cyber-physical risk in smart buildings

Smart buildings promise greater efficiency, improved sustainability and enhanced operational oversight. However, as building management systems, security platforms and energy infrastructure become increasingly interconnected, they also create new pathways for cyber threats that can disrupt physical operations as readily as digital services. Here, Peter Schwartz, senior technology consultant at cybersecurity expert OryxAlign, explains why organisations need to rethink how they manage cyber-physical risk in connected buildings. 

As organisations continue to integrate building management systems, access control, CCTV, environmental monitoring and energy infrastructure, the benefits of connectivity are clear. Shared networks provide greater operational visibility, support remote management and help organisations optimise energy use and building performance.

Yet this growing connectivity also expands the attack surface. Smart buildings should be viewed as operational environments where cybersecurity has a direct impact on business continuity, not just technology platforms that improve efficiency.

Connected systems, connected consequences

The conversation around smart buildings often focuses on energy savings, occupancy analytics and automation. These capabilities undoubtedly deliver value, but they can also overshadow a fundamental consideration in resilience. As building systems become more connected, organisations must consider what happens if those systems are unavailable or deliberately manipulated.

Unlike traditional cyber incidents, the impact is not always measured by stolen data. A cyber-attack against a building management system can have immediate and physical and operational consequences. Consider a modern office where the building management system controls heating, ventilation and air condition (HVAC), access control and environmental monitoring. If an attacker gains access through poorly secured connected devices and moves into the building management network, they may choose not to steal information at all.

Instead, they could alter HVAC schedules and disable environmental alerts. Temperatures begin rising in communications rooms and equipment spaces, critical systems experience outages and facilities teams lose visibility of alarms and system status. The result is operational disruption and potential equipment damage rather than a conventional data breach.

This is why smart buildings should be viewed as operational environments rather than collections of connected technologies. Cybersecurity is now about maintaining operational continuity as well as protecting information.

Overlooked security gaps

Many of the systems that present the greatest cyber-physical risk are not traditionally managed as IT assets. Environmental sensors, smart cameras, access control devices, energy management systems and legacy building management controllers are frequently considered operational technology, meaning they can fall outside conventional cybersecurity reviews.

During procurement, organisations understandably focus on functionality, performance and integration. However, security requirements, patching responsibilities and lifecycle management often receive far less attention. As more connected systems are introduced, these gaps become increasingly significant because vulnerabilities with operational technology can create an entry point into wider business operations.

The technology itself is only part of the challenge. Third-party vendors and systems integrators often retain privileged remote access for maintenance and support, making supplier security practices an equally important consideration. The UK Government’s Cyber Security Breaches Survey 2025 highlights the wider governance challenge, reporting that only 14 per cent of businesses formally review the cybersecurity risks associated with their immediate suppliers, while just seven per cent assess risks across their wider supply chain.

Although these figures are not specific to smart buildings, they demonstrate that third-party risk remains an area where many organisations have more work to do. Strong governance, clear contractual accountability and regular security assessments should therefore apply equally to both connected technologies and the organisations responsible for supporting them.  

Resilience through visibility

Reducing cyber-physical risk does not require organisations to sacrifice the benefits of integration. Instead, the priority should be integrating systems in a way that improves visibility while maintaining appropriate separation between them.

Effective integration is about ensuring systems can share information securely through appropriate network segmentation, clearly defined trust boundaries, robust identity controls and centralised monitoring. The objective is greater operational awareness and faster incident response rather than creating a larger interconnected environment.

This approach is reflected in guidance from the National Institute of Standards and Technology (NIST). Its Guide to Operational Technology (OT) Security identifies building automation and physical access control systems as operational technology requiring dedicated cybersecurity controls, recommending measures such as network segmentation, strong identity management and continuous monitoring to reduce operational risk.

Monitoring also plays a critical role because most cyber-physical incidents begin as relatively small anomalies. Unexpected device behaviour, unusual network communications, failed authentication attempts, unauthorised configuration changes or equipment unexpectedly going offline can all indicate an emerging issue. Combining asset visibility, operational telemetry and cybersecurity insights enables organisations to identify problems before they affect building operations. Simply, organisations cannot protect systems they cannot see.

Shared ownership matters

As building systems IT infrastructure and physical security increasingly overlap, organisations also need to rethink how responsibility is managed. Traditional siloed ownership models are becoming increasingly difficult to sustain because operational resilience now depends on multiple disciplines working together.

Facilities teams, IT departments and physical security specialists each bring different expertise, but connected buildings require a shared governance framework that applies cybersecurity policies, risk assessments and incident management processes consistently across both IT and operational technology environments. Shared accountability is essential for protecting connected buildings against increasingly complex operational risks.

For organisations looking to strengthen resilience, the most effective starting point is often the simplest. Establish a complete inventory of connected building systems and devices. Many organisations still do not have a comprehensive understanding of everything connected to their environment. Once that visibility exists, unsupported systems can be identified, unnecessary connectivity removed, vulnerabilities assessed and appropriate monitoring introduced. Improving visibility remains one of the fastest and most cost-effective ways to reduce cyber-physical risk.

As organisations continue investing in smarter buildings, cyber-physical risk should no longer be considered a specialist concern for facilities or IT teams in isolation. Connected environments deliver significant operational benefits, but they also require a shared approach to governance, monitoring and resilience. Organisations that understand what is connected, establish clear ownership across facilities, security and IT teams, and build visibility into their operational environments will be far better placed to maintain business continuity as smart buildings continue to evolve.

To learn more about strengthening the resilience of connected buildings, visit the OryxAlign website.

The post Managing cyber-physical risk in smart buildings appeared first on IT Security Guru.

Securing What Matters: Why Cyber Resilience Needs Prioritisation

Recent government data shows the scale of cyber threats facing security teams. According to the Cyber Security Breaches Survey 2025/2026, it’s estimated that UK businesses experienced 5.19million cyber crimes in the last 12 months. This means an average of over 14,000 incidents per day.

The volume and frequency of threats show little sign of slowing. IT Security Guru recently reported a 34% increase in cyber attacks in June, compared with the same month last year. Every day seems to bring new vulnerabilities, new alerts and new attacks, compounding a mounting challenge for teams operating with stretched resources and budgets. Threats are intensifying, while security teams are tracking thousands of vulnerabilities across on-premises infrastructure, cloud environments and increasingly complex supply chains.

While organisations continue to invest in cyber defences, the reality is that security teams cannot patch every vulnerability or investigate and act on every threat. Adversaries understand this imbalance and are increasingly exploiting it. Rather than relying solely on sophisticated attach techniques, many threat actors are attempting to hit businesses from every direction by increasing the volume, speed and frequency of attacks. The aim is to overwhelm security teams and misdirect their attention through a constant stream of alerts, vulnerabilities and incidents. Attackers can then, in theory, concentrate on a successful breach that flies under the radar.

Artificial Intelligence (AI) is being leveraged by cyber criminals to evolve this form of attack. LLMs can be used to accelerate reconnaissance of targets, amplify deception and social engineering, and significantly cut the time between vulnerability disclosure and working exploit. The expansion of cybercrime-as-a-service ecosystems are also lowering the barriers to entry for less-skilled adversaries and further contributing to a trend of faster, smaller, harder-to-disrupt attacks.

Faced with a relentless avalanche of cyber attacks, security teams must accept the uncomfortable truth that not every vulnerability matters equally. A key step for achieving this is building an intelligence led approach to vulnerability prioritisation, shifting beyond an over-reliance on Common Vulnerability Scoring System (CVSS) scores to manage risk.

Many businesses rely heavily on CVSS ratings to organise patching and remediation priorities. And, although CVSS remains a useful measure of technical severity, it doesn’t tell security teams whether a vulnerability is actually being targeted by threat actors. There may be instances, for example, where a vulnerability receives a critical score, but it isn’t being actively being exploited or lined up in a threat actor’s crosshairs. The consequence of this can be that fixes are made to what’s deemed a critical threat, whilst an adversary is weaponising a lower-rated vulnerability that’s not high up the list of priorities for remediation.

Rather than focusing solely on severity ratings, organisations need to assess vulnerabilities according to real-world risk. This means having the ability to combine exploitation signals, threat actor activity, ransomware group associations and specific tech stacks to effectively surface the CVEs that actually require attention. Essentially, security teams can utilise cyber threat intelligence to build an understanding of whether adversaries are actively discussing or weaponising vulnerabilities to prioritise where they direct their resources and mitigation efforts.

The businesses getting ahead of attackers are those breaking a reactive cycle of vulnerability patching. They are increasingly adopting intelligence-led strategies to effectively determine where a vulnerability sits in the exploitation lifecycle to take action before attackers can take advantage.

Threat intelligence also enables automation and the foundations for embracing AI to prioritise vulnerability remediation at machine-speed. By continuously ingesting exploitation signals, monitoring threat actor activity and correlating insights against an organisation’s tech stack, teams can significantly reduce the manual effort for triaging vulnerabilities. This can prove beneficial for evolving from reactive patching to proactive risk reduction.

Ultimately, cyber resilience is no longer about trying to fix everything. It’s about fixing what matters most in a timely way, before attack intent becomes a breach. Vulnerability prioritisation is crucial to this and can enable security teams to consistently identify and address the highest-risk cyber threats.

By Alexander Leslie, Senior Advisor at Recorded Future 

The post Securing What Matters: Why Cyber Resilience Needs Prioritisation appeared first on IT Security Guru.

Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns

Global ransomware attacks climbed 3% in the second quarter of 2026, rising from 2,165 incidents in Q1 to 2,229, according to NCC Group’s latest Quarterly Cyber Threat Intelligence Report. While the increase in volume was modest, the security firm warned that supply chain attacks are growing rapidly in both scale and sophistication, and that the overall trajectory of ransomware activity continues to point upwards.

The report recorded 665 ransomware attacks in June alone, with the industrials sector once again the most heavily targeted, accounting for 30% of attacks across the quarter and 28% in June. Consumer Discretionary and Information Technology rounded out the top three targeted sectors for the quarter.

North America remained the most targeted region, absorbing 44% of all Q2 attacks and 41% of June’s total, followed by Europe (26% for the quarter, 23% in June) and Asia. Qilin held its position as the most active ransomware group for a fifth consecutive quarter, linked to 14% of all Q2 attacks (301 victims), ahead of The Gentlemen (238 victims) and DragonForce (145 victims). NCC Group also flagged the emergence of KryBit, a new Ransomware-as-a-Service operation that claimed 56 victims in its first full quarter of activity.

VPNs remain a favoured entry point

The report’s spotlight section highlights corporate VPNs and internet-facing edge devices as the ransomware ecosystem’s most exploited entry point so far in 2026. Groups including Akira, Qilin and The Gentlemen have all been observed exploiting vulnerabilities in products from vendors such as Fortinet, SonicWall, Citrix and Check Point to bypass authentication and gain a foothold inside victim networks.

NCC Group said vulnerabilities affecting VPN products account for around 15% of the 150-plus Threat Intelligence Alerts it has issued so far this year, many rated high or critical severity. The report also points to “FortiBleed,” a large-scale credential exposure incident uncovered in June affecting roughly half of all publicly exposed FortiGate devices, as a development likely to fuel further exploitation in the coming months.

Software supply chain under sustained assault

Alongside the ransomware data, NCC Group’s analysts describe a marked escalation in attacks against the software development ecosystem during Q2, with campaigns hitting GitHub Actions, npm, PyPI, Docker Hub, Open VSX and the Visual Studio Code Marketplace. The financially motivated group TeamPCP was linked to some of the most significant activity, including the self-propagating “Mini Shai-Hulud” worm, which continued to spawn derivative campaigns, dubbed Miasma and Hades, after its source code was published to GitHub in May.

The report warns that these campaigns exploit “transitive trust” in software supply chains, turning maintainer accounts, CI/CD tokens and cloud credentials into high-value targets, with effects that can cascade well beyond the organisation initially compromised.

“A board-level issue”

Matt Hull, VP and Head of Cyber Intelligence and Response at NCC Group, said supply chain attacks remain one of the most attractive routes for threat actors to inflict significant operational, financial, and reputational damage, and that businesses need continuous, rather than ad hoc, monitoring and resilience.

“Although there has not been a material rise in ransomware volume in the last quarter,” Hull said, the trajectory of attacks continues upwards, and VPNs remain an increasingly attractive target. He added that organisations must treat cyber security as the board-level issue it is, pointing to geopolitical tensions and rapidly evolving AI capabilities as compounding pressures on defenders.

NCC Group’s report also examines the deepening professionalisation of ransomware operations such as The Gentlemen, a rapidly-scaling RaaS group whose leaked internal database revealed structured negotiation tactics and a dedicated suite of EDR-disabling tools distributed to affiliates. Separately, the report notes a growing convergence between commodity infostealer malware and higher-end intrusion tradecraft, with new variants adopting rootkit-style concealment, browser-extension-based credential theft, and off-host decryption to evade detection.

The full report also covers geopolitical developments, including rising China-Taiwan tensions, Belarus’s shifting posture toward Russia, and Ireland’s incoming EU Council presidency, which NCC Group assesses could shape targeting patterns for state-linked threat actors in the second half of the year.

The post Ransomware Attacks Rise 3% in Q2 as Supply Chain Compromises Escalate, NCC Group Warns appeared first on IT Security Guru.

Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns

A new threat intelligence report has painted a stark picture of the cyber risks facing the UK and Ireland, describing an environment in which ransomware gangs, nation-state spies and politically motivated hacktivists are increasingly working the same terrain, often against the same victims.

The “Cyber Threat Landscape: UK & Ireland” report, published by threat intelligence firm CYFIRMA, finds that financially motivated cybercriminals and state-aligned actors are frequently targeting the same sectors, finance, telecoms, technology, healthcare and government, and warns that cybercrime, espionage and geopolitical disruption are becoming harder to tell apart.

Russia, China, North Korea and Iran all in the mix

According to the report, Russia remains the most immediate geopolitical cyber threat to the region, with Russian-linked groups focused on critical infrastructure, undersea cables and disinformation tied to the ongoing war in Ukraine. China is flagged as the more significant long-term concern, with state-linked groups pursuing intellectual property theft and “living off the land” techniques designed to maintain quiet, persistent access inside critical networks.

The report also names several state-sponsored groups actively targeting the UK, including Russia’s APT28 (Fancy Bear) and APT29 (Cozy Bear), and China-linked APT15 and GALLIUM. It highlights a recent APT28 campaign that hijacks vulnerable home and small-office routers to redirect DNS traffic, quietly harvesting credentials and login tokens from unsuspecting users. North Korea’s Lazarus Group is also named in connection with fake job-offer lures targeting European defence and drone manufacturers, part of the long-running “Operation DreamJob” campaign.

Ransomware still dominates, with the UK bearing the brunt

Ransomware remains the most visible threat. CYFIRMA’s data shows Qilin as the most active gang targeting the region between January and May 2026, followed by DragonForce, The Gentlemen and Cl0p, with the UK absorbing the overwhelming majority of recorded victims. Ireland saw far fewer incidents, but the report notes that groups including The Gentlemen, Qilin and Interlock have all claimed Irish victims, and activity there peaked sharply in May 2026.

Professional services, manufacturing, real estate and IT emerged as the sectors hit hardest by ransomware, the report finds, with most groups now relying on double extortion, encrypting systems while also stealing data to threaten public leaks if a ransom isn’t paid.

Financially motivated crews get creative with social engineering

The report also details the tactics of financially motivated groups such as FIN6, which has been posing as job seekers on LinkedIn and Indeed to trick recruiters into opening fake résumé links laced with malware, and Scattered Spider, which continues to abuse identity and access management systems by impersonating employees to helpdesk staff in order to reset credentials or bypass multi-factor authentication.

Dark web trade in UK and Irish data continues unabated

Beyond ransomware, the report catalogues a steady stream of underground forum listings offering UK and Irish personal data for sale throughout 2026 — including an alleged 120-million-record database from a UK gambling platform, a combo list of more than 657,000 UK email-password pairs, and a dataset said to contain 734,000 UK student records. CYFIRMA says this reflects a growing emphasis among criminal groups on monetising stolen data and credentials rather than relying solely on encryption-based extortion.

Critical vulnerabilities add to the pressure

The report also flags a cluster of critical vulnerabilities disclosed during the period, including several rated 9.0 or above in the n8n workflow automation platform, Cisco’s Secure Firewall ASA and FTD software, Fortinet’s FortiOS and FortiProxy products, and VMware’s ESXi and Workstation platforms — several of which have already been linked to active exploitation.

What organisations should do

CYFIRMA’s recommendations for organisations in both countries include:

  • Accelerating patching of internet-facing systems, VPNs and edge devices, which remain the most common entry point for both ransomware crews and state-backed actors.
  • Enforcing phishing-resistant multi-factor authentication and tightening helpdesk identity-verification processes to blunt social engineering attacks like those used by Scattered Spider and FIN6.
  • Testing ransomware and DDoS response plans, including backup recoverability, given the sustained pace of attacks on critical infrastructure and public services.
  • Increasing scrutiny of third-party and vendor access, as supply chain compromise continues to be used to reach multiple organisations through a single trusted relationship.

The report’s overall message is one of convergence: as ransomware operators, spies and hacktivists increasingly pursue overlapping goals through similar tools and techniques, CYFIRMA argues that organisations can no longer treat these as separate risks to be managed in isolation.

The full research report can be found here: https://www.cyfirma.com/research/cyber-threat-landscape-uk-ireland/

The post Ransomware, Spies and Hacktivists Converge on UK and Ireland, New Threat Report Warns appeared first on IT Security Guru.

1 in 4 businesses hit by cyber attacks through their supply chain in the last year

One in four UK businesses (26%) have suffered a cyber incident that originated in their supply chain over the last year, according to new research from business continuity and disaster recovery specialist Databarracks. The finding is particularly striking given that organisations are highly aware of the risk they face: nearly half (48%) admit they have continued working with suppliers despite known resilience or security concerns.

The figures come from the Data Health Check 2026, Databarracks’ annual survey of 500 UK IT decision-makers, which has tracked IT resilience since 2008. This year’s report paints a picture of organisations that recognise the danger posed by their supply chains, but frequently feel unable to act on that knowledge.

In many cases, the research suggests, businesses simply lack viable alternatives. More than a quarter of respondents (26%) identified “dependence on suppliers” as a main barrier to improving their organisation’s resilience.

Awareness without action

The Data Health Check found that supplier assessment is now standard practice for most organisations. Almost nine in ten businesses (89%) assess supplier resilience at the point of onboarding, and the majority (61%) go further by conducting assessments annually, quarterly, or continuously.

Despite this due diligence, the risk clearly persists once a supplier relationship is underway. “Supply chain vulnerabilities” was named as one of the top three IT resilience challenges organisations expect to face over the next five years, cited by 23% of respondents – behind only AI-driven cyber threats (46%) and ransomware attacks (26%).

The data also shows a clear link between known risk and real-world impact. Organisations that knowingly continued working with risky suppliers were more than four times as likely to experience a supplier-originated cyber incident: 43% of those organisations went on to suffer an incident, compared with just 10% of organisations that had not knowingly worked with risky suppliers.

“Treat your critical suppliers like you would your own business”

Commenting on the findings, Chris Butler, Resilience Director at Databarracks, said that supply chain resilience remains one of the most persistent weaknesses in UK organisations’ defences. “This year’s findings indicate that supply chain resilience remains a critical pain point for many businesses, which the majority are aware of and which continues to be exploited by attackers. When something goes wrong at a key supplier, the cascade effects can be profound for businesses throughout the chain.”

“Despite good intentions around assessing supplier resilience, most companies don’t fully understand the depth of complexity in their supply chains. Often they’ll know who their core suppliers are, but beyond that, visibility drops away.”

“The traditional approach to assessment has long been tick-box based, with compliance questionnaires growing longer every year. This approach creates a false sense of assurance rather than real resilience.”

Butler argued that genuine improvement requires businesses to move beyond paper-based assurance and to take direct ownership of the risk that suppliers pose to their operations. “To truly manage your supply chain continuity, it’s vital to actually get visibility of the situation. Business leaders need to treat supplier resilience as part of their own resilience, not somebody else’s problem. It’s a bit of a cliché but for good reason: you really need to treat your critical suppliers like you would your own business.”

He also urged organisations to take a more collaborative approach where smaller or less mature suppliers cannot be easily replaced. “Where there isn’t a viable alternative and your existing suppliers don’t have in-house business continuity skills, offer to help. Include your suppliers in your business continuity exercises and give them the chance to rehearse with you. It’s important to practice the response to disruption together rather than in isolation. Doing this will benefit you in the long run.”

Additionally, Jamie Akhtar, CEO and Co-Founder of CyberSmart, added: “This research highlights the severe impact supply-chain attacks are having on businesses of all sizes. It is concerning that one in four businesses has experienced a cyberattack through its supply chain, but what’s even more concerning is that almost half knowingly continue to work with suppliers that have identified security weaknesses. The findings show how difficult it can be for organisations to remain secure. Businesses must manage their own security, but also the security and resilience of their supplies as well.”

“Organisations, especially SMEs, should treat suppliers as part of their own security perimeter. They should assess third-party risks before onboarding, restrict access to essential systems and data, enforce multi-factor authentication, keep software patched and maintain tested backups. Regular supplier reviews and shared incident-response plans can also reduce disruption if a partner is compromised,” Akhtar continued. 

Part of a wider resilience picture

The supply chain findings sit within a broader Data Health Check 2026 report that shows organisations bracing for a harsher resilience environment. The study found that 65% of organisations now believe a serious cyber attack could threaten their survival, while cyber remains the leading cause of IT downtime for the fourth year running, cited by 30% of organisations as their biggest cause of outages.

The report also found reasons for optimism. Business continuity planning has reached a new high, with 90% of organisations now holding a plan and four in five of those kept up to date. Ransomware resilience is also improving: although one in four organisations (25%) experienced a ransomware attack in the last 12 months, only 18% of those affected paid the ransom, while 59% recovered from backups instead.

Databarracks said the overall findings point to “integrating IT and business resilience” as the most-cited priority for organisations in 2026, reflecting a growing recognition that modern incidents – including those originating in the supply chain – rarely respect the boundaries between cyber security, IT operations, business continuity and executive decision-making.

The post 1 in 4 businesses hit by cyber attacks through their supply chain in the last year appeared first on IT Security Guru.

DigiCert expands its EMEA channel strategy with Ignition Technology

DigiCert, a global leader in intelligent trust, has announced a strategic distribution partnership with Ignition Technology to scale its presence across EMEA, accelerate market entry and expand partner-led growth.

Through the partnership, Ignition will bring DigiCert ONE® to customers and partners across the UK and Ireland, DACH, France, Benelux and the Nordics. DigiCert’s comprehensive platform unifies PKI, DNS and automated certificate lifecycle management, helping organisations establish trust across machine identities, software, devices, digital content, and AI agents, while reducing outages, strengthening compliance and supporting the transition to post quantum cryptography.

“Across EMEA, organisations are facing increasingly complex security, operational and regulatory challenges as they embrace AI, modernise infrastructure and prepare for the post quantum era,” said Sean Remnant, Chief Strategy Officer, Ignition Technology. ”They don’t need more disconnected tools. They need a platform that simplifies complexity, helps them move faster and gives them confidence they’re ready for what’s next.”

“This partnership is about creating high impact, scalable growth across EMEA,” said Paul Holt, Group Vice President, EMEA at DigiCert. ”Ignition understands how to build markets, grow partner ecosystems and execute at pace. Together, we’ll help more organisations build the confidence to embrace AI, automate trust at scale and prepare for the post quantum era.”

The partnership reinforces DigiCert’s commitment to growing its channel across EMEA, enabling partners to help organisations simplify security, strengthen resilience and prepare with confidence for the AI and post quantum era.

The post DigiCert expands its EMEA channel strategy with Ignition Technology appeared first on IT Security Guru.

95% of Security Teams Blindsided by Vulnerabilities Between Tests

The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes itself as the provider of the first AI-powered continuous pentest for enterprises.

The company’s new report, The State of Continuous Security Validation, surveyed enterprise security leaders and practitioners and found that 95% had discovered high or critical vulnerabilities outside their scheduled testing windows within the past year. Of those, 42% said this had happened at least once a month, underscoring a widening gap between how quickly enterprise environments change and how infrequently they are actually tested.

Three connected gaps

Synack’s researchers point to three related problems undermining enterprise security assurance. The first is a coverage gap: 38% of respondents said at least a quarter of their critical attack surface had gone independently tested or validated for more than 90 days.

The second is what the report calls an AI trust gap. Despite growing enthusiasm for AI-assisted testing, 79% of respondents said they would not act on an AI-generated finding without a human validating it first.

The third is a maturity gap: only 15% of respondents described their security testing and validation programme as continuous, despite continuous testing being the most commonly cited method (named by 22%) for confirming whether a finding is actually exploitable.

One CISO who took part in the study summed up the operational impact: “It simply means we operate with a constant blind spot, where new code changes run in production for days or weeks before they are finally validated.”

AI expands coverage, but humans are still needed to prove exploitability

The research suggests enterprises are keen for AI to take on a bigger role in reconnaissance, surfacing potential vulnerabilities and expanding testing coverage, but are far less willing to let it operate without human oversight. Respondents said human expertise remains essential for validating exploitability, assessing severity and business risk, testing complex workflows, cutting down false positives, and communicating risk to stakeholders.

“Point-in-time testing is reaching its limit because the environment changes faster than a scheduled test can represent,” said Angela Heindl-Schober, Chief Marketing Officer at Synack. “The market direction is clear: AI expands coverage, humans prove exploitability, and security validation becomes continuous. The gap is not awareness. It is execution.”

The study also identifies the main barriers to continuous security validation, including compliance-driven test cycles, integration complexity, a lack of trust in automated findings, false positives, difficulty demonstrating return on investment, and unclear ownership across teams.

“Automation can surface more signals, but security teams need evidence, not noise,” said Mark Kuhr, Co-Founder and Chief Technology Officer at Synack. “Human researchers bring the creativity and context to chain weaknesses, confirm exploitability and show what an attacker can actually do.”

A Human + AI model for continuous validation

Synack argues the findings reinforce the case for a combined Human + AI approach to security validation. Its Sara AI Pentesting offering uses what the company calls the Synack Autonomous Red Agent to scale reconnaissance and testing, while the Synack Red Team, a vetted network of more than 1,500 security researchers, is used to validate real-world exploitability, uncover chained attack paths, and provide context that automation alone cannot supply.

Together, the company says, the two approaches are designed to help organisations move away from periodic, point-in-time security snapshots and towards continuous security validation.

The post 95% of Security Teams Blindsided by Vulnerabilities Between Tests appeared first on IT Security Guru.

New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience

Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.

The partnership brings together Critical Cloud’s Managed Runtime Assurance operating model with Tarian Labs’ offensive security specialists, whose experience spans government, defence and critical national infrastructure projects.

Managed Runtime Assurance focuses on the day-to-day operation of production applications, cloud platforms and AI systems, helping organisations maintain visibility, resilience, security, operational efficiency and compliance readiness. Instead of producing a report that reflects a single point in time, security findings become part of an ongoing cycle of remediation, retesting and evidence-based validation.

The service combines Critical Cloud’s Datadog-powered managed operating model with Tarian Labs’ independent testing capabilities through an Observe, Detect, Validate methodology. Critical Cloud manages monitoring, governance and runtime operations across production environments, while Tarian Labs performs penetration testing, cloud and infrastructure assessments, web application reviews, API testing and follow-up verification. Findings move directly into remediation before independent retesting confirms they have been addressed.

The partnership preserves clear separation of responsibilities. Tarian Labs owns testing methodology, findings, severity ratings and retesting, while Critical Cloud leads remediation and operational improvements. Every engagement is delivered under customer authorisation, agreed scope, defined rules of engagement and controlled evidence management.

“Detection without validation is hope, not assurance,” said James Smith, CEO of Critical Cloud. “Today’s regulated organisations need continuous proof that production controls continue to perform as intended, particularly as technology changes at an increasingly rapid pace.”

“A penetration test should be the beginning of improvement rather than the end of the process,” said Kevin Hanford, Co-Founder and CEO of Tarian Labs. “By linking independent testing with remediation and verification, we help organisations demonstrate that security risks have been effectively resolved.”

Continuous Runtime Security Validation is now available across the UK and Ireland, with a packaged joint offering planned for a later date. Future joint activities include fintech events in Wales and a live demonstration environment that illustrates the complete Observe, Detect, Validate lifecycle, including remediation, retesting and evidence of closure.

Critical Cloud is ISO 27001 certified, holds Cyber Essentials Plus, and is recognised as a Powered by Datadog accredited partner and Datadog Advanced Partner. Tarian Labs delivers engagements through CREST registered practitioners with final sign-off at NCSC-recognised CHECK Team Leader (CSTL-INF) level.

The post New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience appeared first on IT Security Guru.

❌