Posts

Showing posts with the label cybersecurity

AI Governance Has a Control Problem, Not a Policy Problem

Image
We’re getting good at writing policies about how AI should be used. Responsible AI principles. Acceptable-use policies. AI risk frameworks. Approval processes. Governance committees. All of these have a place. But there is a harder question that I think organisations need to start asking: What evidence proves those controls actually work? Because AI is changing the nature of the control problem. We are moving from AI that simply provides information to AI that can increasingly access data, make decisions, call tools, trigger workflows and take actions. And much of our traditional assurance thinking still assumes there is a human sitting somewhere in the process. That assumption is becoming increasingly uncomfortable.  Autonomy is scaling faster than assurance Consider a relatively simple AI agent. It might be able to: Read information from internal systems  Search documents and databases  Make decisions based on predefined criteria  Trigger workflows  Create or...

IBM Quantum System One London: Why Every Organisation Should Be Preparing for Post-Quantum Cryptography (PQC)

Image
Walking past IBM's offices on York Road, just a short walk from Waterloo Station , I spotted the IBM Quantum System One on public display. Like many people, I initially wondered whether it was simply a replica or a marketing exhibit. The answer is no. This is a genuine IBM Quantum System One , housed within a sophisticated dilution refrigerator designed to keep its superconducting quantum processor at temperatures only a fraction of a degree above absolute zero. The striking gold structure that catches everyone's attention is not the quantum processor itself. The processor is tiny compared with the surrounding equipment and sits deep inside the system. Much of what you can see exists to cool, control and protect the processor from heat, vibration and electrical interference. It is a fascinating sight and well worth stopping to admire when passing through Waterloo. More Than a Display What many people do not realise is that IBM...

What the Anthropic Decision Reveals About the Future of AI Security

Image
The recent decision by the U.S. administration to lift restrictions on Anthropic’s frontier AI models has generated plenty of debate. Some have questioned whether the original restrictions were justified, while others argue they reflected legitimate concerns about the cybersecurity capabilities of increasingly powerful AI systems. Regardless of where you stand, I believe the real story lies elsewhere. This is one of the clearest examples yet of governments treating AI models as technologies with potential national security implications rather than simply another software product. That should make every cybersecurity leader take notice. AI Security Is Different For decades, cybersecurity has focused on protecting systems from attack. Today, we are entering an era where AI itself can influence the speed, scale and sophistication of those attacks. Modern frontier models can assist with code analysis, vulnerability discovery, malware understanding and offensive research. While t...

When the Frontier Blinks: What the Mythos and Fable Controversy Reveals About AI Security

Image
When Anthropic abruptly pulled Mythos 5 and Fable 5 from circulation , the move sent a jolt through the AI and cybersecurity communities. These were not minor point releases. They were widely regarded as among the most capable models the company had ever shipped, and watching them withdrawn, even temporarily, raised an uncomfortable question: if the frontier itself can be paused over a safety concern, what exactly are we securing, and how would we know if it failed? At the time of writing, much of the detail remains disputed. Anthropic and government officials appear to hold very different views about how serious the issues really were, and until more technical evidence is made public, nobody outside the organisations directly involved can say with confidence what happened. What we can do is step back and ask why an episode like this matters at all, because the answer says a great deal about where AI security is heading. A bigger jump than the version number suggests Part of what made ...

Cyber Security: Data ‘Re’-Assurance

Image
How do you know company data is secure?   How do organisations know their data is secure? And how can companies ensure that a network breach won’t result in a loss of sensitive data? The consequences of a data breach are potentially disastrous for any organisation, so companies need to be reassured that their data is secure at all times in line with any internal and external compliance needs - and that they have the tools and visibility to prove this, should a network breach occur. With 78% of IT security leaders lacking confidence in their company’s cybersecurity posture, now is the time for organisations to focus on applying a ‘Zero Trust’ approach to their cybersecurity strategy. In doing so, security professionals acknowledge that they cannot trust the security of their underlying infrastructure and therefore implement controls from a data assurance perspective, placing emphasis on protecting their sensitive data, irrespective of where this data travels within the network. And...

Cybersecurity Is Not A One-Stop-Shop

Image
Cybersecurity is not a One-Stop-Shop Boris Johnson announced the Government’s roadmap to lift Coronavirus restrictions for both businesses and the general public earlier in February, and since then, this has provided a glimmer of hope for many across the country. However, since the start of the pandemic, the way business is conducted has changed permanently, with many workforces wanting to continue to work remotely as lockdowns and restrictions ease over time. So, as companies relax and rules are eased, life is expected to return to a form of ‘new normal.’ But, the issues around cybersecurity are here to stay, and the gas pedal must not be eased – especially with the increased risks associated with continued remote working. If anything, security should be more reinforced now than ever before to ensure all aspects of a business are secure. But this isn’t the case. Steve Law, CTO, Giacom and Kelvin Murray, Threat Researcher, Webroot, detail the importance of embedding a trilogy securi...

Important Strategies for Aligning Security With Business Objectives

Image
What is the objective of implementing cybersecurity in a business? The answer might vary depending on whether you ask a security professional or a business executive. However, in any cybersecurity implementation, it’s very important to stay focused on the big picture: cybersecurity is there to secure the business and its assets, so the business can concentrate on achieving its business objectives. For example, if we are a coffee shop, then cybersecurity should be implemented to help the restaurant sell more coffee, and cybersecurity by itself is not an end goal. To do so, security professionals and executives must align cybersecurity with business objectives, which can be quite challenging in certain cases. Below, we’ll share important strategies that can help cybersecurity teams move business and cybersecurity alignment in the right direction, starting with the first one. Know the business objectives inside out One of the key challenges in aligning security with business objectives is...

Building a Security Conscious Workforce

Image
Article by Daniel Warelow, Product Manager at Giacom and Charles Preston, CEO & Founder of usecure Employees are a vital part of the security strategy Security Awareness Training the foundation of a Cyberculture Life and work as we know it is changing as a result of the COVID-19 crisis, and cybercriminals are using this to their advantage. A  new report  has found that more than one in four UK cyber-attacks have been related to the pandemic, and as attackers continue to come up with sophisticated and dangerous methods to attack businesses and individuals, cyber security measures must be prioritised.  Businesses can no longer rely on technology alone to mitigate the risks that come from cyber threats, especially while many workforces work remotely through the pandemic. Instead, they need to encourage their employees to work mindfully and responsibly on the frontlines of cyber defence. Daniel Warelow, Product Manager at Giacom and Charles Preston, CEO & Founder of ...

Fintech Cybersecurity Trends in 2021

Image
Article by  Beau Peters When the pandemic struck, online bad actors took it as an opportunity to double-down on their attacks through ransomware, malware, and social engineering. Newly remote workers and remotely connected workplaces had to adapt rapidly to a greater digital threat as well as a public health crisis. Now, cybersecurity may just be the most important aspect of financial technology (fintech) in the modern world. With 2020 being the worst year on record in terms of files exposed in data breaches , a thorough security approach is necessary to combat modern dangers. Fintech relies on cybersafety more than any other digital platform. Luckily, new tech trends could help keep our financial data safe even with an increase in risk. Here’s what you should know.  The Rising Risks The widespread shift to a work-from-home (WFH) economy left countless networks vulnerable to cyber attacks. Hastily implemented cloud data processes and security needs failing to keep pace with te...

Trends in IT-Security and IAM in 2021, the “New Normal” and beyond

Article by Dennis Okpara, Chief Security Architect & DPO at IDEE GmbH Yes, there is hope for 2021, but the challenges of the “New Normal” are here to stay. CISOs have to prepare and start acting now, because cybersecurity and the IT-infrastructure will have to face threats that have only just started. The year 2020 was the year working from home lost its oddity status and became normality. Big names like Google and Twitter are planning long-term and hold out the prospect of working from home on a permanent basis. More than 60 percent of companies are trying the same and have implemented home office policies in 2020. But with great flexibility comes great responsibility: Everyone responsible for Cybersecurity and a secure IT infrastructure is now dealing with new challenges closing the last gaps and weak points when it comes to allowing access to company resources. Dennis Okpara, Chief Security Architect & DPO at IDEE GmbH, the specialist for secure identity access managemen...