This week I had a chance to attend the Google Summit. A welcome opportunity to step back from the day-to-day of cybersecurity and connect with peers across the industry. One of the most compelling themes that came across, was how teams in financial services are using AI to augment their workflows. The headline narrative that…
Category: Uncategorized
Automating Repetitive Cybersecurity Tasks with AI
In cybersecurity, Security Operations Centre (SOC) teams are often trying to be do more with less. The reality is that analysts are sifting through thousands of alerts every single day. The human brain, as brilliant as it is, can only realistically investigate a fraction of these. This isn’t just a challenge; it’s a crisis leading…
AI Evolving The Cybersecurity Landscape
The era of cybersecurity equilibrium is over. For twenty years, the cybersecurity landscape has not changed dramatically it has evolved however the landscape remained relatively predictable, but we have reached a tipping point. As highlighted by Anthropic’s recent disclosures, the economics of exploitation are shifting. The cost to find and weaponising critical flaws is collapsing,…
The Deepfake Arms Race: The Death of “Seeing Is Believing”
Reality is now the most hackable system on earth – and the people defending it are losing. Picture this: a video appears showing a world leader announcing nuclear strikes. The audio is clean. The lighting matches the actual press room. The little mannerisms – the head tilt, the way he pauses before a hard word…
A Quick Guide to Automating Repetitive Cybersecurity Tasks with Free and Low-Cost AI Tools
Cybersecurity professionals have many essential tasks that are repetitive, time-consuming, and prone to human error. These often include drafting routine communications, scheduling security awareness sessions, and performing basic data entry to maintain compliance and inventory. While dedicated Security Orchestration, Automation, and Response (SOAR) platforms are powerful, they are often cost-prohibitive for smaller teams or individual…
The Identity Crisis of AI – Why Traditional Security Fails Agentic Systems
The rise of autonomous AI agents is transforming business and also exposing a critical flaw in our digital security ecosystem. Our identity and access management systems are reaching their limitations. Protocols like OAuth and SAML were built for human users and static applications. They rely on one-time authentication and fixed permissions, a model that simply…
Who Owns Security? Insights from a panellist at DTX London 2025
“Whose responsibility is security?” This question dominated the conversation at DTX London 2025’s Agile stage. I was a panellist discussing this topic at DTX this week. The unanimous answer: security is everyone’s responsibility—not just the CISO’s or the security team’s. Speed vs. Security As development cycles shrink to days or hours, security vulnerabilities are becoming…
Communication in Cybersecurity
This week, I attended a Toastmasters event and witnessed what is arguably the best public speaking I have heard this year. This was an interesting session; it caused me to reflect on my communication style and the broader cybersecurity fraternity. Are we communicating clearly? There has been a few interesting cybersecurity articles that have either…
Who doesn’t want to write secure code?
Software engineers typically make hundreds of decisions every day and in my experience no one sets out to write insecure code, so everyone is well meaning however in those decisions some have a bearing on security outcomes and some don’t. It is vital that developers spot security-relevant decisions as they are encountered, and have a clear…
Effective security monitoring
This week, I stumbled across the NCSC blog post on how to keep your security monitoring effective. This is a topic that is definitely worth revisiting on a regular basis. Far too often I come across instances where security activities sound good but are implemented in a way that causes them to lack the effectiveness…