Posts

Showing posts with the label operational resilience

AI Agents Are Creating a New Cybersecurity Blind Spot

Image
The cybersecurity industry has spent years focusing on visibility. Dashboards expanded. Detection tooling improved. Telemetry volumes exploded. Yet one of the biggest emerging risks in 2026 is not hidden malware or an unknown zero-day. It is the rapid deployment of AI agents that organisations barely understand, cannot fully inventory, and often cannot meaningfully govern. AI agents are moving beyond chat interfaces and simple copilots. They are increasingly capable of reasoning, planning, accessing systems, invoking tools, retrieving information, and taking autonomous actions with limited human involvement. That changes the security conversation entirely. This is not simply another software category. It is the emergence of autonomous digital workers operating across identity systems, APIs, SaaS platforms, cloud environments, and business processes. And most organisations are deploying them faster than they can secure them. Research and industry reporting throughout 2026 s...

Mythos AI: What Security Leaders Should Do Next

Image
The recent discussion around Anthropic’s Claude Mythos Preview and Project Glasswing has caught the attention of the cybersecurity industry for good reason. Mythos is not just another AI announcement. It is being positioned as a frontier model with advanced cybersecurity capability, particularly around finding and exploiting software vulnerabilities. Anthropic has stated that Project Glasswing is intended to give selected defenders early access to this capability to help secure critical software, rather than releasing the model broadly. Cisco has also published guidance following its work with Mythos, explaining that it is changing its near-term threat modelling of AI-enabled attackers and issuing defensive recommendations for customers. That is the important point. Whether Mythos itself remains tightly controlled or not, the direction of travel is clear. AI-enabled vulnerability discovery and exploitation capability is improving quickly. Security teams need to prepare for a...

Adaptive Security Leadership in an Expanding Threat Surface

Image
Last week I joined fellow security leaders at  CISO Inspire Summit North  for a panel discussion on  The Expanding Threat Surface: Adaptive Security Leadership for 2026 and Beyond . It was a timely discussion, because the challenge facing security leaders today is not simply more threats. It is more connections, more dependencies, and more complexity. Suppliers, SaaS, identities, automation and distributed ways of working have all expanded the attack surface in ways that traditional control models often struggle to keep pace with. One theme I returned to during the discussion was that many cyber risks are not new. They are often familiar control failures appearing at greater scale and speed. That matters, because it shifts the focus from chasing every emerging technology risk to strengthening fundamentals. Security fundamentals still matter most Identity, ownership, visibility and resilience remain foundational. As organisations scale, risk often hides where ownership is ...