Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

What Does the Cyber Industry Want to See From the New UK Government?

20 July 2026 at 09:40

Today (20 July 2026), Andy Burnham became Prime Minister of the UK, succeeding Sir Keir Starmer. While there is not yet a detailed ‘Burnham tech strategy’, pre-transition briefings and reports over recent weeks suggest a strong focus on AI, including plans for a dedicated AI Minister, the scrapping of the hotly debated digital ID programme, and the potential reorganisation of the Department for Science, Innovation and Technology (DSIT), with its responsibilities redistributed across other government departments.

So, what does the cyber community hope Burnham will do in the realm of cybersecurity, AI and tech as Prime Minister? We asked the industry…    

Charlotte Wilson, Head of Enterprise at Check Point said: “Britain’s AI department is at the forefront of the country’s productivity strategy, playing a crucial role in how the technology will be developed and rolled out to drive wider economic growth and defence.”

“Incoming policymakers should take heed; artificial intelligence is the gorilla in the room and will remain so for the foreseeable future. Any suggestion of redeployment or downsizing could send the wrong signal to businesses and cyber criminals about how seriously we take the most transformational technology in living memory,” Wilson continued. 

Dray Agha, Senior Manager of Security Operations at Huntress, added: “Smart infrastructure beats a spending war, and fortunately the UK can’t outspend the US or China on AI models anyway, so the new Prime Minister must focus on where we can win: secure public datasets and targeted sovereign compute.”

“Safely unlocking NHS data while fortifying our energy grid will build real domestic leverage without compromising national security. With guaranteed access to US tech currently on ice, relying solely on Washington is no longer a viable security strategy. The UK must leverage our AI Security Institute to build a ‘middle-power’ tech coalition with NATO and Commonwealth allies, pooling resources to ensure collective cyber resilience.”

Additionally, Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, noted: “The UK doesn’t need to win the frontier model race; it needs to be a serious, trustworthy place to deploy AI at scale. That’s a more achievable and arguably more valuable position. The ally-pooling argument on sovereign compute and cloud interoperability is sensible from both an economic and security standpoint.”

“The UK’s convening credibility on this particularly through the AI Security Institute is a genuine asset that Burnham should be using. Unlocking health data for AI R&D is genuinely valuable but it’s only responsible if the security and governance infrastructure around that data is built first, not retrofitted after the damage is done. Right now the ambition is ahead of the security maturity.”

Jake Taylor, Head of Government NEMEA at Filigran, said:  “If the new government wants to bring more critical national infrastructure under public ownership, cybersecurity has to become part of that conversation from day one. National resilience isn’t just about protecting individual organisations anymore. It’s about ensuring energy providers, government, suppliers and operators can share intelligence, understand emerging threats and coordinate their response before disruption spreads.”

“The biggest challenge isn’t a lack of security tools. Most critical infrastructure organisations already have those. The challenge is breaking down the silos that still exist between organisations and turning threat intelligence into something that informs operational decisions, rather than simply generating more alerts. As the geopolitical environment becomes increasingly volatile and nation-state activity continues to rise, collaboration will be every bit as important as technology.”

Taylor continued, “the Cyber Security and Resilience Bill is an important step because it moves the conversation towards common standards and greater coordination. If public ownership expands, cybersecurity needs to evolve from a collection of individual security programmes into a genuinely national capability, where intelligence sharing and continuous threat exposure management become fundamental to protecting essential services.” 

Andy Burnham’s long-term plans for the UK’s cyber, AI and technology sectors are still taking shape. The Guru team will be keeping a close eye on developments as his new government begins to set out its agenda.

The post What Does the Cyber Industry Want to See From the New UK Government? appeared first on IT Security Guru.

Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider

15 July 2026 at 12:17

Moona Ederveen-Schneider is a cybersecurity expert (and Most Inspiring Woman in Cyber Award winner 2026) with more than 20 years of experience across financial services, risk and cyber resilience. She has held senior roles at Deutsche Bank, JPMorgan Chase, UBS, Nomura and ABN Amro, and previously served as Executive Director EMEA at FS-ISAC. 

As the founder of Resilia Connect and author of the Practical Post-Quantum Transition Framework, Moona works with organisations preparing for the security risks created by quantum computing. Her work focuses on post-quantum migration, crypto-agility and helping leaders turn complex technical threats into practical action. 

In this exclusive interview conducted by the Cyber Security Speakers Agency, Moona explains why the quantum threat is already taking shape, where organisations go wrong when preparing for post-quantum cryptography, and why businesses need to begin strengthening their security architecture now. 

Why does quantum computing remain an underestimated cybersecurity threat for many organisations? 

Moona Ederveen-Schneider: “Quantum computing is not simply a future threat. Adversaries are already harvesting encrypted data with the intention of decrypting it once quantum computers become powerful enough. 

“Most organisations have not yet started preparing for that transition. 

“I developed a practical post-quantum transition framework to explain the issue clearly, cut through market hype and vendor noise, and make the process manageable for organisations and their teams. 

“I also run tabletop exercises that teach organisations how to become crypto-agile. I poll participants at the beginning and again at the end of these sessions. The shift in the room is remarkable. 

“People often arrive feeling that the challenge is unmanageable. They leave with greater confidence and a clear understanding of what they need to do next.” 

How close is the quantum threat, and how urgently should organisations begin preparing? 

Moona Ederveen-Schneider: “The UK National Cyber Security Centre says organisations should complete detailed planning by 2028 and be fully migrated by 2035. 

“Google has set its own internal migration deadline of 2029, citing faster-than-expected advances in quantum computing. That reflects the wider sentiment I am seeing and the increasingly strong guidance being issued by governments globally. 

“Google is one of the organisations building these machines, so its decision deserves serious attention. 

“Large organisations typically need at least five years to complete a full cryptographic overhaul, while some may need twice that long. A 2035 deadline is therefore not generous. Organisations need to begin acting now. 

“My practical post-quantum transition framework is designed to deliver security improvements from the first day. It provides a clear starting point and a route through the process without overwhelming teams or budgets. 

“Organisations are also not preparing for a future threat in isolation. They are building more resilient architectures that can improve protection against current threats, including ransomware, AI-enabled attacks and supply chain compromise.” 

What mistakes do organisations make when beginning a post-quantum cryptography migration, and what should they do differently? 

Moona Ederveen-Schneider: “The first common mistake is treating post-quantum cryptography migration as a technology project and handing responsibility solely to the security team. 

“It is a whole organisational transformation. 

“The data that needs protecting sits across HR, legal and finance, not only within what DORA defines as critical business processes. 

“The second common mistake is beginning with the cryptographic inventory. 

“Contrary to the approach commonly repeated across the industry, I advise organisations to strengthen their data security posture first. 

“They must answer a fundamental business question: what are we protecting, and how long does it need to remain secret? 

“My practical post-quantum transition framework begins with that question and is designed to deliver security improvements immediately. It can be adapted for organisations and teams of any size.” 

The post Q&A: Businesses Are Running Out of Time to Prepare for the Quantum Threat, Warns Moona Ederveen-Schneider appeared first on IT Security Guru.

Q&A: Cyber’s Headed Back to the CSIDES

13 July 2026 at 14:33

Last year, CSIDES took place on The Grand Pier in Weston-super-Mare for the first time – a day filled with cyber talks, Cyber’s Got Talent, exceptional swag, its own theme song and – we are told – an extraordinary raffle. 

After the success of the inaugural event last summer, on the 9th October 2026, industry experts will gather in North Somerset once again, courtesy of event sponsors Tines, 4FOX Security, Consultants Like Us, Punk Security, PPRO and IASME.  

The Gurus sat down with the event’s organisers, Hazel McPherson and Jess Matthews (both Most Inspiring Women in Cyber Award winners and esteemed cyber professionals) to discuss all things CSIDES.

You’re back at the beach for the second annual CSIDES event! Can you tell readers who aren’t familiar what CSIDES is and who it’s for? 

CSIDES is the UK’s first cyber security event built by and for a coastal community. It is a one-day event which was designed to equip individuals, businesses, and educators with the tools to protect themselves in a rapidly shifting digital world. 

Why Weston? What makes The Grand Pier so special?  

Weston-super-Mare is a popular seaside resort in Somerset. However, like so many coastal communities in the UK it suffers from historical underinvestment in terms of opportunities in tech and cyber security. 

As a result, talent leaves the town to explore roles in larger cities, such as Bristol, Exeter or further afield. CSIDES was created to show that it is possible to stay and be part of the highly dynamic field of cyber security. Not only that, but local businesses also have access to experts on their doorstep who can provide support.

The Grand Pier is a renowned feature of the town. We could not think of anywhere better to host CSIDES, as an iconic symbol which we felt was the perfect setting for the event. Attendees can immerse themselves among the rides and gaze across the Bristol Chanel whilst taking in serious, cyber security topics in a fun atmosphere! 

What can attendees expect to see at this year’s event? Can you give us any sneaky insider insight?

We have a TV celebrity as a speaker! A workshop on scam callers. The Big Fat Quiz of the Pier. We have 5 rooms of accessible talks and interactive activities. Some of (if not the best) swag in the South West!    

Reflecting on last year’s event, what’s your favourite thing about CSIDES? What did you learn? 

It was exciting for me to see people with no experience in cyber working alongside really experienced senior leaders in cyber in the workshops. Realising that we have created a space where people could talk about cyber in a meaningful way regardless of experience or skills.
 

The local community may not be as knowledgeable about cyber as those who work directly in the industry. Why do events like these matter to them too?

We in the industry are poorer when we only look inwards. There are many in cyber security who see their role as more than a job, it is their mission to protect. To protect our families, communities, businesses and nations. We must be outward-looking as it is shared responsibility, and this is why events like CSIDES matter. We can start at home and locally, empowering people with knowledge so they can walk away from the Pier with steps to better protect themselves. What is more rewarding than that? 

And finally (and just for fun), what’s the best part about the seaside?

Hazel: My favourite thing about the seaside is how it never really changes. As a child, it was all about family holidays, donkey rides, building sandcastles, and paddling in the sea. Those are some of my happiest memories. 

These days, I appreciate it in a different way. I love the sound of the waves, the feel of the sand between my toes, and spending hours looking for unusual pebbles or peering into rock pools in the hope of spotting a tiny crab, a shrimp, or another glimpse of life beneath the surface. 

There is something wonderfully calming and familiar about the good old British seaside. It has a way of slowing life down and reminding me to simply enjoy the moment.

Jess: For me, I was born in Weston-super-Mare and the best part about growing up at the seaside has to be crabbing with my brother. I spent a lot of my childhood looking for limpets on the rocks or using bacon as bait (they prefer it smoked!). There is nothing more satisfying than pulling up the line and seeing a lot of crabs. The bucket was always full and releasing them afterwards was chaotic as they all scurried away in multiple directions. Memories!
 

The post Q&A: Cyber’s Headed Back to the CSIDES appeared first on IT Security Guru.

Pentesting is dead. Long live pentesting.

3 July 2026 at 07:11

Penetration testing has been a cornerstone of cybersecurity for decades. For many organisations, it is part of an annual security programme, providing reassurance for boards, evidence for customers and insurers and a demonstration of compliance with regulatory requirements. It is also one of the most commonly purchased cybersecurity services. 

Despite its widespread use, penetration testing is actually one of the least consistently defined services in the industry. Two providers can assess the same environment and produce very different reports. One may identify critical vulnerabilities that another overlooks. Recommendations, severity ratings and conclusions can differ significantly, even though both engagements are described as a “penetration test”. This level of inconsistency raises questions around whether an organisation actually knows what it is buying. 

The answer is more complicated than it may first seem. A penetration test is not a standardised product with identical or even similar outputs regardless of who performs it. Its quality depends heavily on the tester’s methodology used, the time allocated and, crucially, the scope agreed before the work even begins. These variables mean that the value of a penetration test differs enormously from one provider to another. 

Unfortunately, many organisations still purchase penetration testing as if it were a commodity. This means the procurement decisions will often be driven by cost or by the need to satisfy a compliance requirement, instead of by a clear understanding of what the organisation is really trying to achieve. The result is a report that proves that a test has taken place but not necessarily one that provides a meaningful level of insight into the organisation’s real exposure to cyber risk. 

That challenge has become even greater as technology environments have evolved. Organisations operate across cloud platforms, SaaS applications, remote devices, third-party services and complex digital supply chains. Many businesses struggle to maintain a complete inventory of their own assets. And if you do not have full visibility of your environment, it is difficult to define the scope of a penetration test, let alone be confident that every important system has been assessed. 

This is where the phrase “passing a penetration test” can become misleading. A penetration test only assesses the systems and scenarios that have been agreed upon and are within its scope at a particular point in time. It cannot provide assurance about assets that were omitted, systems deployed after the test, or new vulnerabilities that emerge the following week. Treating the report as proof that an organisation is secure risks creating a false sense of confidence. 

Compliance has contributed to this mindset. Many standards and regulations require organisations to demonstrate that security testing has taken place, which is a good thing. However, there is a danger that the objective of the penetration test becomes obtaining the report rather than improving security. Cyber resilience is not measured by whether a penetration test was completed but by whether the findings are understood, prioritised and used to reduce genuine business risk. 

But none of this means that penetration testing is obsolete. It is quite the opposite. Independent, expert-led testing is one of the most effective ways of understanding how an attacker could compromise an organisation. What needs to change is the expectation that every penetration test is equivalent, or that a single assessment can provide lasting assurance in an environment that changes continuously. 

The future of penetration testing is likely to be more contextual and outcome driven. Rather than asking whether a business has had a penetration test, the focus should be on whether they have tested the systems that matter most, whether the testing reflected realistic attack scenarios and whether the findings have improved their security posture. 

Of course, the value of a penetration test has never been the report itself. Its value lies in helping organisations understand where they are vulnerable, why those vulnerabilities matter and what they should do next. If the industry can refocus on those outcomes rather than simply delivering another compliance exercise, then penetration testing has a very strong future.

The post Pentesting is dead. Long live pentesting. appeared first on IT Security Guru.

❌
❌