Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

The Hunt-to-Detection Gap: Choosing an AI Threat Hunting Solution in 2026

1 September 2026 at 12:05

If you’re in the market for an AI threat hunting solution, chances are you’re evaluating based on investigation quality. That’s an understandable and reasonable metric to go on – investigation quality is important, and most vendors focus their marketing on it.

It’s not, however, the most important metric. Pretty much every vendor has decent investigation quality. If they didn’t, they wouldn’t be competitive, and you wouldn’t be considering them.

You need to be looking at what happens after the investigation. Does a validated finding survive handoff into a live, tuned detection rule? Or does it become a case report that sits in a queue until someone manually rediscovers the same technique next time around?

This is called the hunt-to-detection gap, and it makes the difference between a tool you should consider, and one that’s not worth wasting budget on.

Most AI Threat Hunting Lists Miss The Hunt-to-Detection Gap

By the time you’re reading this, you’ll probably be a ways into your research. You’ll have checked out Reddit, reached out to your peers, and have read a fair few of these blogs.

Most of those blogs talk about the same capabilities: query flexibility, data source coverage, UI, how deep you can pivot into an investigation, that sort of thing. It all falls under the umbrella of investigation depth and feature breadth. They are, of course, important, but after a while, all the vendors start to blur into one. Some are marginally better than others, but not by much.

However, precious few of these blogs consider whether a validated hunt converts into a live detection rule without a human manually reconstructing the reasoning trail.

This is for several reasons. The first is that this is harder to communicate in a simple roundup blog. The second is that most AI threat hunting solutions can’t do this. And the third is that buyers often won’t get the answer in a vendor demo, and it doesn’t have the same pizazz as a screenshot of a slick query interface. It’s not sexy, but it matters.

Why the Hunt-to-Detection Gap Matters

The hunt-to-detection gap matters because speed has never been more important.

Mandiant’s M-Trends 2026 report puts global dwell time at 14 days, up from 11 the previous year, reversing the steady improvement of the past few years. In part, that jump materialized as a result of highly sophisticated, low-and-slow tactics. Automated detection tends to miss these attacks, so it’s AI threat hunting’s job to catch them.

However, catching a technique once isn’t enough. You want to catch it, fast, the next time it appears. If an AI threat hunting solution has a hunt-to-detection gap, it can’t do that. It will just rely on the same slow discovery process it did the first time around, and won’t cut dwell time.

Moreover, the SANS 2026 CTI Survey saw security operations reclaiming the top CTI use case, overtaking threat hunting for the first time since 2022. That’s likely because hunts are being folded into daily detection work. If that’s the case, tools that keep hunting and detection separate are behind the curve.

Evaluating a Vendor on Hunt-to-Detection Metrics

So, when evaluating a vendor, how can you make sure that the solution you’re buying does what you need it to do? Here are four questions that will help you do just that.

Does the solution provide structured evidence output?

A narrative summary is fine for a human, but it’s useless as an input for a detection rule. Make sure your solution breaks evidence into discrete, structured fields that include the specific telemetry, artifacts, and conditions that triggered the finding. It should also be formatted in such a way that you can feed directly into rule logic.

The Hunters SOC Platform is an example of a solution that does this properly. It expresses hunts in the same lead/detector schema that drives its production detections. That means findings are structured as a detection input from the moment they are created.

How complete is the reasoning trail?

If all a tool does is flag something as malicious but not tell you what signals mattered, in what sequence, and against what baseline, analysts will have to manually reconstruct that reasoning. That’s what delays conversion. Always ask to see the full trail behind a verdict.

Prophet Security, a leading AI SOC platform recognized in Rising in Cyber 2026, does complete reasoning trails particularly well. Every investigation ends with case documentation that already names the specific telemetry, artifacts, and reasoning steps behind the verdict. That means the reconstruction work is already done by the time the hunt is validated.

Does the solution have a direct translation path?

Validated hunts need to become tunable detection rules without a human rewriting the logic from scratch. Some platforms require a separate detection engineering step, in a different tool, by a different person, with nothing but a case report as the rough guide. That slows everything down.

For example, Anvilogic builds and versions a rule inside the same workspace as the hunt itself, so the translation is closer to a save action than a full rewrite.

Query.AI, meanwhile, runs detection directed against federated data with no ingestion pipeline required. That removes the data-migration step that stalls conversion on platforms with separate hunting and detection capabilities.

Prophet Security closes that gap from the detection side. Its AI Detection Engineer turns investigation and hunt findings into detections, backtests them against the organisation’s history, and ships each as a reviewable, version-controlled change to the SIEM already in place, with a person approving what goes live.

How long between a hunt validation and a live rule in production?

If a tool has structured evidence, a complete reasoning trail, and a direct translation path, this time should be short. If a solution takes weeks, even if the vendor has strong answers for the other three questions, something in the pipeline is still manual.

Vectra AI is a useful example here. Analysts can turn a saved hunt into a Custom Model, assigning it a threat and certainty score rather than reusing Vectra’s built-in behavioural models directly. That distinction matters: the resulting detection is analyst-scored, not scored by the same machine learning models that drive Vectra’s automated, unsupervised detections.

The post The Hunt-to-Detection Gap: Choosing an AI Threat Hunting Solution in 2026 appeared first on IT Security Guru.

Tech Moves: AWS data leader jumps to Oracle; Seattle Children’s names new CIO; Zillow’s new legal chief

21 August 2026 at 11:26
Mehul Shah. (LinkedIn Photo)

Mehul Shah joined Oracle as group vice president for OCI data and storage services, ending a 14-year run at Amazon and Amazon Web Services.

In his last role at AWS, Shah led engineering and product for Amazon RDS for SQL Server, Oracle and Db2, and ran the launch and expansion of Oracle Database@AWS, the partnership that put Oracle’s database inside Amazon’s cloud.

“Through that collaboration, I saw firsthand that OCI shares the same DNA that inspired me to join Amazon back in 2012,” Shah said on LinkedIn, citing “deep curiosity, a passion to innovate, the courage to make bold decisions, and relentless drive to excel.”

Shah, who is based in Seattle, spent more than eight years at AWS, earlier leading real-time data streaming services including Amazon Data Firehose and Kinesis Data Streams, and serving as director and general manager of Amazon EMR. He started at Oracle this month.

Dr. Natalie Pageler. (Seattle Children’s Photo)

Seattle Children’s named Dr. Natalie Pageler senior vice president and chief information officer, putting her in charge of digital strategy and IT operations for the pediatric hospital system.

Pageler comes from Stanford Children’s Health and the Stanford University School of Medicine, where she was division chief of clinical informatics and earlier spent a decade as chief medical information officer. She is a pediatrician and clinical informaticist with more than 20 years of experience.

Seattle Children’s CEO Dr. Christopher Longhurst followed a similar path. He was chief medical information officer at Stanford Children’s Health, the same role Pageler held, before spending a decade at UC San Diego Health, most recently as chief clinical and innovation officer.

Cassandra “Sandi” Knight. (Zillow Photo)

Zillow Group named Cassandra “Sandi” Knight its first-ever chief legal and policy officer, a role the Seattle company created this month as part of a broader leadership shuffle. Reporting to CEO Jeremy Wacksman, she oversees Zillow’s legal, compliance and government relations functions.

Knight joins from Google, where she spent four years as a vice president leading global civil litigation and discovery. She was previously vice president and chief litigation counsel at PayPal, and spent 11 years at Morgan Stanley in senior litigation and compliance roles.

She began her career as a trial lawyer at the San Diego Public Defender’s Office, the firm Keker & Van Nest and the San Francisco City Attorney’s office. She holds a law degree from Stanford and is based in the San Francisco Bay Area.

She arrives at a busy moment: Zillow and Redfin are set to go to trial Aug. 24 as defendants in an antitrust case brought by the FTC and five state attorneys general over the companies’ $100 million rental listings deal. Zillow has spent $26 million on the case so far this year.

Two longtime Zillow leaders are heading out:

  • Sara Bonert, vice president of industry engagement for Zillow Group and ShowingTime+, is leaving after nearly 20 years. One of Zillow’s earliest employees, she joined in the fall of 2006 as director of broker services, helped build Zillow’s first platform for taking in listing data, and signed the partner agreements that took the site from zero to a million listings in four months.
  • Jeff Tompkins, head of corporate real estate and operations, wrapped up almost five years with the company. Tompkins, who is based in Denver, ran Zillow’s workplace strategy across North America and beyond. He said he will share his next role soon.
Amir Pelleg. (Uber Freight Photo)

Amir Pelleg, a veteran of companies including Amazon and Convoy, is the new chief product officer at Uber Freight. He is based in Seattle, working out of the shared Uber and Uber Freight office on Second Avenue.

At Amazon, Pelleg was principal product manager for Kindle Fire, launched the Dash Button and initiated Alexa’s smart home controls, then incubated and launched Amazon Shipping in India, the U.K. and the U.S. as a director and general manager in Amazon Transportation.

He was a vice president on Convoy’s executive team until the Seattle freight startup shut down in 2023, then spent two and a half years at dental tech company Dandy.

“I’ve seen what works and what fails in digital freight,” Pelleg said in a Q&A posted by Uber Freight.

— Seattle’s Frazier Healthcare Partners added Wes Wheeler to its Growth Buyout team as an executive in residence, advising on diligence and on life science logistics and infrastructure.

Wheeler was most recently CEO of LabConnect, a central laboratory services company serving clinical trials, and before that president of UPS Healthcare, where he built a vertical of 10,000 employees across 35 countries. During Operation Warp Speed he was the primary industry interface to the U.S. government, overseeing distribution of more than 1.5 billion COVID-19 vaccine doses to over 100 countries.

Dr. Heather Cheng. (Fred Hutch Photo)

Dr. Heather Cheng was announced as the inaugural recipient of the Marty Lazarus Weiden Family Endowed Chair at Fred Hutch Cancer Center, which will fund her work detecting, preventing and treating hereditary cancers.

Cheng is clinical director of cancer genetics programs at Fred Hutch and directs its prostate cancer genetics clinic. In 2016 she was part of a team that found more than 10% of men with advanced prostate cancer carry inherited mutations in DNA-repair genes such as BRCA1 and BRCA2.

The chair is named for Marty Lazarus Weiden, who was diagnosed with breast cancer in 1993 and died in 2001. The family learned only later that some of its members carry a BRCA mutation.

— Microsoft corporate vice president Darryl Willis was named to the board of ONE Nuclear Energy, a natural gas and advanced nuclear developer going public this quarter through a merger with Hennessy Capital Investment Corp.

Willis has led Microsoft’s energy and resources group since 2019. He was previously a Google Cloud vice president and a BP executive who ran the company’s Deepwater Horizon claims process and testified before Congress. He will officially join the board when the merger closes, and he is expected to chair its compensation committee.

Jake Milstein. (LinkedIn Photo)

Jake Milstein was named head of healthcare solutions marketing at Zscaler, a return to healthcare cybersecurity. He joins from application security company Contrast Security and was earlier chief marketing and revenue officer at Critical Insight, the Bremerton, Wash.-based security firm acquired by Lumifi Cyber.

Before moving into technology, Milstein spent a decade at Seattle’s KIRO TV, including four years as news director.

Michele Mehl left Amazon Web Services after nearly two and a half years to become senior public relations manager at ALSO, arriving the same week the electric vehicle company announced a $150 million Series D round led by Prysm Capital.

ALSO builds the TM-B consumer electric bike and the TM-Q commercial delivery quad, and counts Amazon and DoorDash among its commercial partners.

Richard Van Bibber was named senior vice president of research and development at Verasonics, the Kirkland, Wash.-based maker of ultrasound research platforms used in fields including biomedical ultrasound, materials science and earth sciences.

Van Bibber has spent much of a 25-year medtech career in the Puget Sound region, including seven years as director of research at Kirkland’s Cardiac Dimensions and five years leading clinical affairs at Bellevue-based Aortica.

Dave Cotter joined the board of Nickson, the apartment-furnishing startup led by Cameron Johnson, alongside MarcyPen Capital Partners and Larry Braithwaite. Cotter is CEO of Greenwood and has previously worked at Amazon, Nordstrom, zulily, RealNetworks and Leafly.

PCC Community Markets president and CEO Krish Srinivasan will retire effective Jan. 29, 2027. Srinivasan was chief financial officer at Remitly and vice president of finance at Lyft before joining the Seattle grocery co-op as CFO, and earlier held leadership roles at Amazon and Microsoft.

Seattle Foundation named Elizabeth Wong as chief philanthropy officer, reporting to President and CEO Alesha Washington. Wong spent more than a decade at Foundation Source and earlier worked directly with the Gates family at the Bill & Melinda Gates Foundation.

And in case you missed it:

Jay Bartot, a co-founder of the airfare-prediction startup Farecast and former chief technology officer of Madrona Venture Labs, was named CTO of Lev, the Pioneer Square Labs spinout building an “AI co-founder” for entrepreneurs. Read more here.

Expedia Group is parting ways with at least eight vice presidents and senior vice presidents, and promoted five other leaders, as it reorganizes its product and technology groups around AI. Read more in this GeekWire story.

Fake evidence: How generative AI is changing fraud capabilities

14 August 2026 at 09:17
Scams are evolving with technology. Generative AI is a game changer for scammers and has been blamed for the rise in increasingly sophisticated phishing campaigns. It is also enabling scammers to add credibility to their schemes by providing a quick, cheap, and easy way to create fake websites, videos, documents, and photographs. Tasks that once [...]

Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White

11 August 2026 at 12:21

Cybercrime no longer divides neatly between lone hackers, organised gangs and state-backed operations. These groups exchange tactics and tools, while stolen data gives them an asset that can be sold, used for fraud, held to ransom or weaponised for political damage. 

Geoff White is an award-winning investigative journalist whose reporting has taken him inside global hacking networks, cryptocurrency thefts and modern money-laundering operations.  

A former Technology Correspondent for Channel 4 News, he has also reported for the BBC and The Sunday Times. Geoff co-created and presented the BBC World Service podcast The Lazarus Heist and has written three books on cybercrime and organised crime. Champions Speakers 

In this exclusive interview for the IT Security Guru conducted by the Cyber Security Speakers Agency, Geoff explains how cybercrime became a mature global industry, why segmentation remains critical against ransomware and how criminals are using AI in practice. He also examines why stolen data has become one of their most useful assets. 

What drove the convergence of lone hackers, organised crime gangs and state actors into today’s global cybercrime ecosystem? 

Geoff White: “Hacking has always been a thing with computers. From the earliest days, there were people who hacked, which originally didn’t necessarily mean criminal behaviour. 

“Hacking something together is an engineering term. If all you’ve got is some gaffer tape and string, you make the engine work. That was the principle behind hacking in the early days. 

“The apple in the Garden of Eden was money. As soon as websites such as eBay and Amazon started getting set up, credit cards began flooding onto the web. That’s where organised crime gangs started to become interested in the technology. 

“What’s happened since has been an evolution. You started to see organised crime gangs become interested in cyber and hacking. Governments also became interested because getting hold of secrets and manipulating other nations is very useful. 

“You also had lone hackers, what they call hacktivists, the classic kid in a hoodie in a bedroom somewhere. 

“Over time, these movements have moved together and learned from each other. Governments realised that the tactics used by bedroom hackers and activists could be used effectively to push other nations around. 

“Organised crime gangs have sometimes obtained incredibly powerful cyber tools from government hackers. 

“We’re starting to see all these different types of groups coming together. If you want to know why cyber has risen up the agenda, that’s the real explanation.” 

Ransomware now operates like a mature industry. Why do major organisations remain vulnerable, and what defence matters most once attackers get inside?

Geoff White: “The thing to realise about ransomware is that this is a very mature industry, and it is an industry. There are hundreds of people working in it. 

“It’s been through its start-up phase, seed-funding phase and venture-capital phase. It is now a fully fledged industry. 

“At the last count, I found 62 different groups on the dark web who were all carrying out ransomware attacks. They’re extremely strategic. 

“They will say: “Today, we are going to target the transport sector.” They will find companies in that sector and work out which ones are vulnerable, which are most valuable and which are juicy targets. 

“The next day, they might decide to target pharmaceuticals. They are very strategic in how they work and will target those organisations until they find a way in. 

“Unfortunately, the likelihood is that a ransomware gang will get inside your organisation. The only thing you can do to prevent the damage becoming much worse is segmentation. 

“Make sure that if attackers get into one part of your organisation, they can’t access everything. If they break into one department, they shouldn’t be able to move into other departments. 

“Segmentation, breaking things apart and introducing barriers for attackers, is your best defence.” 

How are cybercriminals using AI in practice, and is the threat currently outpacing cyber defence? 

Geoff White: “Like all industries, the cybercrime industry is looking very hard at artificial intelligence. Our working practices are gradually being revolutionised by AI, and the cybercrime space is no exception. 

“However, there’s some good news. 

“If you look at how cybercriminals are using AI in practice, rather than theoreticals, hypotheticals or unverified services being offered on the dark web, it’s the same stuff we’re using it for. 

“They’re using it to improve their emails, audit their code and conduct reconnaissance on targets they might want to hit. That’s not reinventing the wheel. 

“I would contrast that with what’s happening on the defensive side of cyber. AI has always been used in cyber defence. We used to call it machine learning. 

“The cyber-defence industry is using AI at scale and pace. I think we’re in a good place. 

“If we can double down on those AI wins in cyber defence now, we can hopefully stave off the day when cybercriminals start using AI at scale as well.” 

What makes stolen data more useful to cybercriminals and nation states than assets such as cash or cryptocurrency? 

Geoff White: “Cybercriminals have realised that the one thing organisations possess that is easy to obtain and use is data. 

“I can get hold of credit cards as a crook, but then I’ve got to wash the credit card money. I can steal Bitcoin, but then I’ve got to put the Bitcoin somewhere. 

“If I steal data, I’ve got an instant win. I can go on the dark web and sell it. If it’s customer data, I can contact people and send them phishing emails. 

“I can also contact the organisation and say: “I’ve got a bunch of your data. Pay me and I won’t leak it.” 

“There are many different ways data can be used. This isn’t limited to criminals. Nation states have become involved as well. 

“We’ve seen massive data leaks and government hackers breaking into organisations. One famous example was the Democratic Party during the 2016 US presidential election. Incredibly sensitive data was stolen and then weaponised to cause damage. 

“Data has become the new currency for cybercrime gangs in the same way it became the new currency for organisations.” 

 When audiences hear the stories behind your investigations, what do you want them to understand about cybercrime and how to confront it? 

Geoff White: “When I give talks, I’m lucky as a journalist because I have these amazing stories. 

“Regardless of how technical this becomes or how much financial crime might appear to concern spreadsheets, it’s always about people. 

“There’s always a set of characters behind it who are interesting, sometimes crazy and sometimes extremely quirky. 

“I look at the people and their motivations. Then we examine how they work and the lessons organisations need to learn to fight them. 

“I hope people leave my talks with a thumping good story and some valuable, applicable lessons that they can start putting in place to stop the bad guys winning.” 

The post Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff White appeared first on IT Security Guru.

When AI Agents Meet Real Infrastructure: Hype, Human Error or a Genuine New Threat?

4 August 2026 at 07:15

Just days after OpenAI disclosed that one of its security research agents had escaped a testing sandbox by exploiting a previously unknown vulnerability, Anthropic revealed that its own AI models had compromised three real organisations during a cybersecurity evaluation after a configuration error inadvertently gave them internet access. The similarities between the two incidents have inevitably fuelled headlines about “rogue AI”, prompting questions about whether frontier AI models are becoming too autonomous to control.

The reality is both more reassuring and, arguably, more concerning.

Neither incident involved an AI system developing malicious intent or deciding to attack organisations of its own accord. Both models were pursuing the objectives they had been given. The difference was that flaws in the environments surrounding them allowed those objectives to spill beyond the boundaries researchers believed were in place. Rather than proving that AI has become uncontrollable, the incidents expose a more familiar problem: organisations are building increasingly capable autonomous systems while still relying on operational security controls that have failed humans for decades.

We’ve seen this behaviour before

There is a temptation to view these incidents as something unprecedented. In reality, AI systems have been finding unexpected ways to achieve their objectives for years. OpenAI’s own reward-hacking research in 2016 demonstrated how reinforcement learning agents would exploit loopholes in games rather than complete tasks in the way their designers intended. The famous “CoastRunners” experiment showed an AI repeatedly collecting reward points by driving in circles instead of racing to the finish line.

Anna Collard, SVP Content Strategy & CISO Advisor at KnowBe4 Africa, pointed out that the behaviour itself is nothing new. “None of this should surprise us,” she said. “The Hugging Face incident was also not unprecedented, as OpenAI demonstrated a decade ago that models will ‘cheat’ to reach a goal. What’s changed is the blast radius. Those agents crashed boats in a video game. Today’s agents have shells, credentials and, apparently, accidental internet access.”

The optimisation behaviour has remained largely the same. What has changed is the environment in which these systems now operate. Instead of navigating virtual worlds, AI agents are increasingly interacting with cloud infrastructure, development environments, APIs, public repositories and enterprise credentials. The consequences of pursuing an objective have therefore become significantly more tangible.

The security failures were remarkably ordinary

Perhaps the most striking aspect of both disclosures is that neither relied on sophisticated cyber techniques that defenders have never encountered before.

Anthropic’s models exploited weak passwords and unauthenticated services after being mistakenly granted internet access. OpenAI’s agent escaped a sandbox by exploiting a vulnerability in the environment designed to contain it. Both incidents ultimately depended on familiar weaknesses in privilege management, segmentation and infrastructure.

As Darren Guccione, CEO and Co-founder of Keeper Security, observed: “This is fundamentally a story about test environments and automated agents governed as lower-risk entities. Any system with standing credentials and network reach, whether a production service account or a pre-deployment research environment, needs the same discipline as a human privileged user.”

This should sound familiar to security professionals. Organisations have spent years learning that service accounts, development environments and privileged identities deserve the same scrutiny as production systems. The difference now is that those accounts may belong to autonomous agents capable of carrying out complex sequences of actions at machine speed.

If a penetration tester had exploited exposed credentials, weak authentication and poor network segmentation during an assessment, few would have described the attack as revolutionary. AI simply changes the speed, persistence and scale at which those opportunities can be exploited.

Oliver Simonnet, Lead Cybersecurity Researcher at CultureAI, also noted that the incidents also demonstrate how AI accelerates well-understood attack techniques. “Exposed credentials once needed to be uncovered by humans or automated tooling. They can now easily be uncovered by an AI agent operating at superhuman speeds.” Rather than introducing entirely new attack methods, autonomous AI has the potential to compress the time between discovering an opportunity and exploiting it.

Where the genuine shift begins

That does not mean these incidents should be dismissed as overhyped.

There is a meaningful difference between automation and autonomy. Traditional security tooling executes predefined instructions. Frontier AI models can adapt, plan and pursue objectives across multiple steps without requiring continual human intervention.

The OpenAI incident demonstrated this clearly. The agent did not simply complete the task it had been assigned. It identified the sandbox itself as an obstacle, located a vulnerability, escaped the environment and continued pursuing its objective beyond its intended boundaries.

Kieran B, Director of Technical Services at Bridewell, explained: “This is a genuinely significant moment because it represents something we haven’t really seen before. The AI wasn’t simply successful at the task it was given. It identified the testing environment itself as an obstacle, found a vulnerability in the sandbox, escaped into a broader environment and continued pursuing its objective.”

Equally important is Kieran’s reminder that this should not have been entirely unexpected. “Sandboxes, testing environments and security controls are all software, and like any software they can contain vulnerabilities.”

The lesson is not that AI has suddenly become dangerous. It is that attackers will inevitably direct increasingly capable autonomous systems towards the same weaknesses human adversaries have always targeted.

The conversation may be focused on the wrong problem

Much of the public discussion following both incidents has centred on AI alignment, safety guardrails and model behaviour. Those issues remain important, but they risk overshadowing an equally significant question: are the organisations developing frontier AI investing enough in the security of the environments surrounding those models?

Collin Hogue-Spears, Senior Director of Solution Management at Black Duck, believes the distinction between the two incidents is important. “OpenAI’s models picked a lock, exploiting an unknown flaw to break out of a sealed environment. Anthropic’s found the door already open.””

In other words, neither model suddenly became self-aware or malicious. One escaped because a vulnerability existed, while the other was inadvertently given access to real infrastructure and simply treated it as part of the exercise.

Perhaps the more significant observation from Anthropic’s disclosure was that one model recognised it had reached a real organisation and stopped, while another continued because it reasoned that the real environment must still be part of the simulation. “A model’s own judgment is not a containment control. Put the boundary in the infrastructure,” agrued Hogue-Spears.

That simple principle captures the lesson from both incidents. Organisations cannot rely on AI to recognise when it has crossed a line. Containment must be enforced through robust network segmentation, least-privilege access, restricted outbound connectivity and continuous monitoring, regardless of how capable or trustworthy a model appears.

Neena Sharma, Senior Executive at Filigran, believes that is where attention should now shift. “Industry’s safety conversation has focused heavily on model alignment and behaviour, while comparatively little scrutiny has gone into whether the labs building these models have the operational security maturity to actually contain them.”

She argued that frontier AI developers should adopt the same disciplines that highly regulated industries have relied upon for years, including independent validation of sandbox environments, least-privilege architectures, robust segmentation and continuous verification that isolation mechanisms function as intended.

Being exceptional at developing advanced AI models does not automatically make an organisation exceptional at securing the infrastructure those models rely upon. These are distinct disciplines that increasingly need to converge.

AI agents now belong in the insider threat model

Perhaps the most significant takeaway is that organisations may need to rethink how they classify AI agents altogether.

For years, cybersecurity strategies have largely separated risks into external attackers, malicious insiders and trusted systems. Autonomous AI increasingly blurs those boundaries. These systems may hold credentials, interact with sensitive infrastructure and make operational decisions without direct human oversight. While they do not possess malicious intent, they are capable of creating real-world security consequences if given inappropriate access or operating within poorly controlled environments.

As Collard noted: “The lesson is that AI agents now belong in your insider threat model. We’ve spent years defending the perimeter against external attackers. We now need to plan for our own agents and other people’s going off-script inside and outside our environment.”

That shift has implications far beyond frontier AI laboratories. Organisations deploying AI assistants, coding agents, autonomous workflows or AI-driven operational tooling will increasingly need to apply identity governance, privileged access management, network segmentation and continuous monitoring to those systems just as rigorously as they would for human users.

Agentic security comes of age

If there is one lasting consequence of the OpenAI and Anthropic disclosures, it may be that they mark the moment agentic security became a distinct discipline rather than simply another aspect of AI security.

Roey Eliyahu, CEO and Co-founder of Salt Security, believes the industry has reached a turning point.

“This week feels like the point where the industry acknowledged that agentic security deserves to be treated as its own discipline,” he said. “We have seen an AI model escape a controlled evaluation environment and interact with external infrastructure. We have also seen one of the world’s largest technology companies describe that incident as a warning shot. We have also seen competitors and partners come together to launch dedicated initiatives focused specifically on securing AI systems.”

While organisations have spent the past few years focusing on securing AI models, Eliyahu argued that autonomous agents introduce a different challenge altogether.

“An AI agent is making decisions, invoking APIs, authenticating to business systems, accessing sensitive data and taking actions on behalf of users. Every one of those actions has security implications that extend far beyond the model itself.”

That changes the questions security teams need to ask. Rather than focusing solely on how a model behaves, organisations also need visibility into what happens once an agent decides to act.

As Eliyahu explained: “The key to agentic security becomes what happens after the model decides to act. Which APIs can it call? Which identities is it using? Which systems can it modify? Can those actions be monitored, governed and stopped if something unexpected happens?”

For enterprises embracing autonomous AI, those questions are becoming just as important as securing the models themselves. As AI agents become more deeply embedded in business operations, governing their actions may prove just as critical as protecting the technology that powers them.

Transparency should be recognised, not criticised

One final point deserves acknowledgement.

It is easy to focus solely on the fact that these incidents occurred. It is equally important to recognise that both OpenAI and Anthropic disclosed them publicly, published detailed technical findings and shared the lessons with the wider security community.

In cybersecurity, responsible disclosure has long been recognised as essential to improving collective resilience. These incidents should be viewed through the same lens. They exposed uncomfortable truths about AI evaluations, containment and infrastructure security, but they also accelerated an industry-wide conversation that was likely inevitable.

The future challenge is unlikely to be rogue AI. It will be ensuring that increasingly autonomous systems are governed with the same discipline, visibility and restraint that security teams have spent decades applying to their most privileged human users.

 

The post When AI Agents Meet Real Infrastructure: Hype, Human Error or a Genuine New Threat? appeared first on IT Security Guru.

Expert panel: AI is writing the code. Who is defending it?

31 July 2026 at 05:56
AI is changing the way software is being developed. From generating code, helping developers make sense of new frameworks, reviewing pull requests, and even suggesting solutions for existing vulnerabilities, AI is playing an increasingly active role in the software development process. There is an upside here, too. AI is speeding up development, eliminating redundant efforts, [...]

Examining the Unintended Consequences of the Online Safety Act

24 July 2026 at 07:43

The 25th July 2026 marks one year since the Online Safety Act’s landmark child safety duties came into force, making it a natural moment to assess what’s changed, what’s worked and what challenges remain. Although the Act itself received Royal Assent in October 2023, its requirements were introduced in phases, with 25th July 2025 being the date many of the most visible obligations on platforms took effect.

The child safety duties require platforms likely to be accessed by children to introduce stronger protections, including effective age assurance, child risk assessments and measures to reduce exposure to harmful content. 

One year on, has the Online Safety Act fundamentally changed the internet for UK users, or has it simply shifted the challenges elsewhere? We spoke to cybersecurity experts for a short series of reports to find out more.  

Today, we’re examining the unintended consequences of the Act… 

Professor George Loukas, Head of Centre for Sustainable Cyber Security, University of Greenwich, said: “Ofcom has moved from consultation to enforcement. Naturally, the larger adult sector platforms have been the most visible early targets, and there have been lots of discussions on whether that led to a shift to more VPN usage as well as to non-compliant adult websites. These were all predictable though.”

Uptick in VPN Usage 

For many, the enforcement date signalled a natural (if not predictable) shift towards VPN usage to get around age verification tests. The evidence backs up this hypothesis: Proton VPN’s 2025 end of year report revealed that one of the biggest spikes in VPN sign-ups globally was seen in the UK from the 25th July. 

Konstantin Levinzon, co-founder of Planet VPN, noted that the real issue is people seeking out ‘free’ or not reputable VPNs, posing a significant security risk: “The biggest unintended consequence has been pushing people towards less secure tools, not more careful online behaviour. Age verification requirements have driven a significant increase in VPN adoption, but many users don’t seek out reputable providers – they simply download the first free VPN they find. Those services are often the ones leaking DNS requests, harvesting telemetry or relying on weak security practices, creating a worse privacy outcome than the legislation was designed to prevent.”

Sanjeev Malhotra, chief information security officer at TSG, emphasised the security risk: “People engaging with unvetted VPNs are potentially opening themselves up to serious risks, including malware infections, phishing attempts and personal data harvesting. At the end of the day, it’s still going through a server somewhere, and most people don’t stop to think about who’s operating it, where that data is going or what safeguards are actually in place. In some cases, people may be trading one privacy concern for another without realising it.”

A Lack of Measurable Outcomes? 

But is the ban on children accessing adult sites actually working? Some experts argue that there’s no hard evidence to back it up.

Elle Todd, Partner and Co-chair of the Entertainment & Media Industry Group at Reed Smith LLP, said:  “Ofcom’s recent age assurance report found that the proportion of children encountering harmful content online has not substantially improved despite widespread implementation efforts. The uncomfortable truth is that, based on this report, significant investment in compliance and technologies has not yet translated into measurable improvements in safety outcomes.”

Brian Higgins, Security Specialist at Comparitech, noted that, despite some non-compliance fines being handed out, there are still notable enforcement gaps: Stats from Ofcom summarising their activities during the first twelve months of the Online Safety Act include the launch of 30 investigations, and fines for statutory violations in the region of £4 million GBP. Unfortunately they have also identified ‘enforcement gaps’ where AI and algorithmic content are concerned.”

This item, in particular, could be a precursor to more widespread enforcement action in the future but a brief investigation into the facts reveals that their twelve-month fine collection figure only stands at £55,000. Couple that with their fairly embarrassing skirmish with the American platform 4chan, where their interjurisdictional service of a £520,000 financial penalty notice was rather infamous met with a picture of a hamster and a heavy dose of internet ridicule and it becomes rather obvious that they aren’t performing particularly well.”

Examining Data Storage and Verification System Security

Boris Cipot, principal security engineer, Black Duck, argues that we should be looking beyond whether checks are working and to whether the software behind the systems doing those checks is actually secure: “For many organisations, the focus has been on whether age checks are working. But an equally important question is whether the software behind those systems is secure and properly maintained. If a vulnerability, misconfiguration or compromised third-party component allows age checks to be bypassed, then this is not just a cybersecurity problem anymore but can quickly become a regulatory one as well.”

Sarah Bone, Co-Founder of YEO Messaging, notes the growing number of specialist identity providers: The biggest unintended consequence has been a shift in where trust actually sits. Before the Online Safety Act, platforms largely carried the responsibility for verifying users themselves. Now we’ve got a growing ecosystem of specialist identity providers, each holding highly sensitive personal information. That’s strengthened online safety, but it’s also concentrated trust into fewer organisations, which makes them increasingly attractive targets for attackers.”

So what should age verification providers be doing?

Martin Wegrostek, Cyber Security Portfolio Manager at cybersecurity specialist OryxAlign, said: “Businesses should work on the assumption that breaches are a matter of when, not if. The question is whether providers have built their services with security and privacy by design. That means collecting the minimum amount of information needed to verify age, encrypting data both in transit and at rest, enforcing strong access controls, continuously monitoring for suspicious activity and having a well-rehearsed incident response plan. Organisations relying on third-party age-assurance services should also carry out regular security assessments and review the resilience of their supply chain, rather than assuming a compliant provider is automatically a secure one.”

On Trust and Risk

The conversation should also focus on human risk, said Tim Ward, CEO and co-founder, Redflags: “Content moderators, trust and safety teams, and customer support staff at in-scope platforms are, for the first time, routinely processing government ID documents, facial scans, and other highly sensitive data belonging to minors as part of their everyday work. That’s a substantial new category of human risk, from simple mishandling to targeted social engineering aimed at staff with access to this data, and it’s had almost no public discussion compared to the technical side of compliance.”

“Organisations that have spent the past year focused on the verification system itself should be asking whether the humans downstream of it have had the same level of scrutiny and support,” Ward noted. 

 

The post Examining the Unintended Consequences of the Online Safety Act appeared first on IT Security Guru.

What Does the Cyber Industry Want to See From the New UK Government?

20 July 2026 at 09:40

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, and the potential reorganisation of the Department for Science, Innovation and Technology (DSIT), with its responsibilities redistributed across other government departments.

So, what does the cyber community hope Burnham will do in the realm of cybersecurity, AI and tech as Prime Minister? We asked the industry…    

Charlotte Wilson, Head of Enterprise at Check Point said: “Britain’s AI department is at the forefront of the country’s productivity strategy, playing a crucial role in how the technology will be developed and rolled out to drive wider economic growth and defence.”

“Incoming policymakers should take heed; artificial intelligence is the gorilla in the room and will remain so for the foreseeable future. Any suggestion of redeployment or downsizing could send the wrong signal to businesses and cyber criminals about how seriously we take the most transformational technology in living memory,” Wilson continued. 

Dray Agha, Senior Manager of Security Operations at Huntress, added: “Smart infrastructure beats a spending war, and fortunately the UK can’t outspend the US or China on AI models anyway, so the new Prime Minister must focus on where we can win: secure public datasets and targeted sovereign compute.”

“Safely unlocking NHS data while fortifying our energy grid will build real domestic leverage without compromising national security. With guaranteed access to US tech currently on ice, relying solely on Washington is no longer a viable security strategy. The UK must leverage our AI Security Institute to build a ‘middle-power’ tech coalition with NATO and Commonwealth allies, pooling resources to ensure collective cyber resilience.”

Additionally, Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, noted: “The UK doesn’t need to win the frontier model race; it needs to be a serious, trustworthy place to deploy AI at scale. That’s a more achievable and arguably more valuable position. The ally-pooling argument on sovereign compute and cloud interoperability is sensible from both an economic and security standpoint.”

“The UK’s convening credibility on this particularly through the AI Security Institute is a genuine asset that Burnham should be using. Unlocking health data for AI R&D is genuinely valuable but it’s only responsible if the security and governance infrastructure around that data is built first, not retrofitted after the damage is done. Right now the ambition is ahead of the security maturity.”

Jake Taylor, Head of Government NEMEA at Filigran, said:  “If the new government wants to bring more critical national infrastructure under public ownership, cybersecurity has to become part of that conversation from day one. National resilience isn’t just about protecting individual organisations anymore. It’s about ensuring energy providers, government, suppliers and operators can share intelligence, understand emerging threats and coordinate their response before disruption spreads.”

“The biggest challenge isn’t a lack of security tools. Most critical infrastructure organisations already have those. The challenge is breaking down the silos that still exist between organisations and turning threat intelligence into something that informs operational decisions, rather than simply generating more alerts. As the geopolitical environment becomes increasingly volatile and nation-state activity continues to rise, collaboration will be every bit as important as technology.”

Taylor continued, “the Cyber Security and Resilience Bill is an important step because it moves the conversation towards common standards and greater coordination. If public ownership expands, cybersecurity needs to evolve from a collection of individual security programmes into a genuinely national capability, where intelligence sharing and continuous threat exposure management become fundamental to protecting essential services.” 

Andy Burnham’s long-term plans for the UK’s cyber, AI and technology sectors are still taking shape. The Guru team will be keeping a close eye on developments as his new government begins to set out its agenda.

The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider

15 July 2026 at 12:17

Moona Ederveen-Schneider is a cybersecurity expert (and Most Inspiring Woman in Cyber Award winner 2026) with more than 20 years of experience across financial services, risk and cyber resilience. She has held senior roles at Deutsche Bank, JPMorgan Chase, UBS, Nomura and ABN Amro, and previously served as Executive Director EMEA at FS-ISAC. 

As the founder of Resilia Connect and author of the Practical Post-Quantum Transition Framework, Moona works with organisations preparing for the security risks created by quantum computing. Her work focuses on post-quantum migration, crypto-agility and helping leaders turn complex technical threats into practical action. 

In this exclusive interview conducted by the Cyber Security Speakers Agency, Moona explains why the quantum threat is already taking shape, where organisations go wrong when preparing for post-quantum cryptography, and why businesses need to begin strengthening their security architecture now. 

Why does quantum computing remain an underestimated cybersecurity threat for many organisations? 

Moona Ederveen-Schneider: “Quantum computing is not simply a future threat. Adversaries are already harvesting encrypted data with the intention of decrypting it once quantum computers become powerful enough. 

“Most organisations have not yet started preparing for that transition. 

“I developed a practical post-quantum transition framework to explain the issue clearly, cut through market hype and vendor noise, and make the process manageable for organisations and their teams. 

“I also run tabletop exercises that teach organisations how to become crypto-agile. I poll participants at the beginning and again at the end of these sessions. The shift in the room is remarkable. 

“People often arrive feeling that the challenge is unmanageable. They leave with greater confidence and a clear understanding of what they need to do next.” 

How close is the quantum threat, and how urgently should organisations begin preparing? 

Moona Ederveen-Schneider: “The UK National Cyber Security Centre says organisations should complete detailed planning by 2028 and be fully migrated by 2035. 

“Google has set its own internal migration deadline of 2029, citing faster-than-expected advances in quantum computing. That reflects the wider sentiment I am seeing and the increasingly strong guidance being issued by governments globally. 

“Google is one of the organisations building these machines, so its decision deserves serious attention. 

“Large organisations typically need at least five years to complete a full cryptographic overhaul, while some may need twice that long. A 2035 deadline is therefore not generous. Organisations need to begin acting now. 

“My practical post-quantum transition framework is designed to deliver security improvements from the first day. It provides a clear starting point and a route through the process without overwhelming teams or budgets. 

“Organisations are also not preparing for a future threat in isolation. They are building more resilient architectures that can improve protection against current threats, including ransomware, AI-enabled attacks and supply chain compromise.” 

What mistakes do organisations make when beginning a post-quantum cryptography migration, and what should they do differently? 

Moona Ederveen-Schneider: “The first common mistake is treating post-quantum cryptography migration as a technology project and handing responsibility solely to the security team. 

“It is a whole organisational transformation. 

“The data that needs protecting sits across HR, legal and finance, not only within what DORA defines as critical business processes. 

“The second common mistake is beginning with the cryptographic inventory. 

“Contrary to the approach commonly repeated across the industry, I advise organisations to strengthen their data security posture first. 

“They must answer a fundamental business question: what are we protecting, and how long does it need to remain secret? 

“My practical post-quantum transition framework begins with that question and is designed to deliver security improvements immediately. It can be adapted for organisations and teams of any size.” 

The post Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider appeared first on IT Security Guru.

Q&A: Cyber’s Headed Back to the CSIDES

13 July 2026 at 14:33

Last year, CSIDES took place on The Grand Pier in Weston-super-Mare for the first time – a day filled with cyber talks, Cyber’s Got Talent, exceptional swag, its own theme song and – we are told – an extraordinary raffle. 

After the success of the inaugural event last summer, on the 9th October 2026, industry experts will gather in North Somerset once again, courtesy of event sponsors Tines, 4FOX Security, Consultants Like Us, Punk Security, PPRO and IASME.  

The Gurus sat down with the event’s organisers, Hazel McPherson and Jess Matthews (both Most Inspiring Women in Cyber Award winners and esteemed cyber professionals) to discuss all things CSIDES.

You’re back at the beach for the second annual CSIDES event! Can you tell readers who aren’t familiar what CSIDES is and who it’s for? 

CSIDES is the UK’s first cyber security event built by and for a coastal community. It is a one-day event which was designed to equip individuals, businesses, and educators with the tools to protect themselves in a rapidly shifting digital world. 

Why Weston? What makes The Grand Pier so special?  

Weston-super-Mare is a popular seaside resort in Somerset. However, like so many coastal communities in the UK it suffers from historical underinvestment in terms of opportunities in tech and cyber security. 

As a result, talent leaves the town to explore roles in larger cities, such as Bristol, Exeter or further afield. CSIDES was created to show that it is possible to stay and be part of the highly dynamic field of cyber security. Not only that, but local businesses also have access to experts on their doorstep who can provide support.

The Grand Pier is a renowned feature of the town. We could not think of anywhere better to host CSIDES, as an iconic symbol which we felt was the perfect setting for the event. Attendees can immerse themselves among the rides and gaze across the Bristol Chanel whilst taking in serious, cyber security topics in a fun atmosphere! 

What can attendees expect to see at this year’s event? Can you give us any sneaky insider insight?

We have a TV celebrity as a speaker! A workshop on scam callers. The Big Fat Quiz of the Pier. We have 5 rooms of accessible talks and interactive activities. Some of (if not the best) swag in the South West!    

Reflecting on last year’s event, what’s your favourite thing about CSIDES? What did you learn? 

It was exciting for me to see people with no experience in cyber working alongside really experienced senior leaders in cyber in the workshops. Realising that we have created a space where people could talk about cyber in a meaningful way regardless of experience or skills.
 

The local community may not be as knowledgeable about cyber as those who work directly in the industry. Why do events like these matter to them too?

We in the industry are poorer when we only look inwards. There are many in cyber security who see their role as more than a job, it is their mission to protect. To protect our families, communities, businesses and nations. We must be outward-looking as it is shared responsibility, and this is why events like CSIDES matter. We can start at home and locally, empowering people with knowledge so they can walk away from the Pier with steps to better protect themselves. What is more rewarding than that? 

And finally (and just for fun), what’s the best part about the seaside?

Hazel: My favourite thing about the seaside is how it never really changes. As a child, it was all about family holidays, donkey rides, building sandcastles, and paddling in the sea. Those are some of my happiest memories. 

These days, I appreciate it in a different way. I love the sound of the waves, the feel of the sand between my toes, and spending hours looking for unusual pebbles or peering into rock pools in the hope of spotting a tiny crab, a shrimp, or another glimpse of life beneath the surface. 

There is something wonderfully calming and familiar about the good old British seaside. It has a way of slowing life down and reminding me to simply enjoy the moment.

Jess: For me, I was born in Weston-super-Mare and the best part about growing up at the seaside has to be crabbing with my brother. I spent a lot of my childhood looking for limpets on the rocks or using bacon as bait (they prefer it smoked!). There is nothing more satisfying than pulling up the line and seeing a lot of crabs. The bucket was always full and releasing them afterwards was chaotic as they all scurried away in multiple directions. Memories!
 

The post Q&A: Cyber’s Headed Back to the CSIDES appeared first on IT Security Guru.

Pentesting is dead. Long live pentesting.

3 July 2026 at 07:11

Penetration testing has been a cornerstone of cybersecurity for decades. For many organisations, it is part of an annual security programme, providing reassurance for boards, evidence for customers and insurers and a demonstration of compliance with regulatory requirements. It is also one of the most commonly purchased cybersecurity services. 

Despite its widespread use, penetration testing is actually one of the least consistently defined services in the industry. Two providers can assess the same environment and produce very different reports. One may identify critical vulnerabilities that another overlooks. Recommendations, severity ratings and conclusions can differ significantly, even though both engagements are described as a “penetration test”. This level of inconsistency raises questions around whether an organisation actually knows what it is buying. 

The answer is more complicated than it may first seem. A penetration test is not a standardised product with identical or even similar outputs regardless of who performs it. Its quality depends heavily on the tester’s methodology used, the time allocated and, crucially, the scope agreed before the work even begins. These variables mean that the value of a penetration test differs enormously from one provider to another. 

Unfortunately, many organisations still purchase penetration testing as if it were a commodity. This means the procurement decisions will often be driven by cost or by the need to satisfy a compliance requirement, instead of by a clear understanding of what the organisation is really trying to achieve. The result is a report that proves that a test has taken place but not necessarily one that provides a meaningful level of insight into the organisation’s real exposure to cyber risk. 

That challenge has become even greater as technology environments have evolved. Organisations operate across cloud platforms, SaaS applications, remote devices, third-party services and complex digital supply chains. Many businesses struggle to maintain a complete inventory of their own assets. And if you do not have full visibility of your environment, it is difficult to define the scope of a penetration test, let alone be confident that every important system has been assessed. 

This is where the phrase “passing a penetration test” can become misleading. A penetration test only assesses the systems and scenarios that have been agreed upon and are within its scope at a particular point in time. It cannot provide assurance about assets that were omitted, systems deployed after the test, or new vulnerabilities that emerge the following week. Treating the report as proof that an organisation is secure risks creating a false sense of confidence. 

Compliance has contributed to this mindset. Many standards and regulations require organisations to demonstrate that security testing has taken place, which is a good thing. However, there is a danger that the objective of the penetration test becomes obtaining the report rather than improving security. Cyber resilience is not measured by whether a penetration test was completed but by whether the findings are understood, prioritised and used to reduce genuine business risk. 

But none of this means that penetration testing is obsolete. It is quite the opposite. Independent, expert-led testing is one of the most effective ways of understanding how an attacker could compromise an organisation. What needs to change is the expectation that every penetration test is equivalent, or that a single assessment can provide lasting assurance in an environment that changes continuously. 

The future of penetration testing is likely to be more contextual and outcome driven. Rather than asking whether a business has had a penetration test, the focus should be on whether they have tested the systems that matter most, whether the testing reflected realistic attack scenarios and whether the findings have improved their security posture. 

Of course, the value of a penetration test has never been the report itself. Its value lies in helping organisations understand where they are vulnerable, why those vulnerabilities matter and what they should do next. If the industry can refocus on those outcomes rather than simply delivering another compliance exercise, then penetration testing has a very strong future.

The post Pentesting is dead. Long live pentesting. appeared first on IT Security Guru.

❌
❌