Insights
-
Autonomous pentesting is solving the wrong half of the problem
Jay Kaplan, CEO and Co-founder of Synack, argues autonomous pentesting can expand coverage, but without expert human validation it risks shifting security teams from untested assets to untriaged findings.
-
Four exploited vulnerabilities CISOs should check — now
Four vulnerabilities affecting Microsoft, VMware, and Apple products are now listed by CISA as actively exploited, putting patch status, internet exposure, and the role of affected systems under renewed scrutiny.
-
Resilience shouldn’t be a luxury item: why every organisation must prepare for frontier AI
Mark Molyneux, Field CTO North Europe at Commvault, examines how frontier AI could compress vulnerability response windows and why resilience operations should not depend on access to the most advanced models.
-
Alleged Azure dumps expose cloud identity gap
Alleged Azure and Entra datasets linked to some of the world’s largest companies show how credential theft outside the cloud perimeter can become access inside it without any cloud zero-day.
-
Private APNs expose an overlooked OT boundary
Poland’s investigation into a destructive energy attack shows how infrastructure outside an operator’s direct control can provide a route between otherwise separate industrial environments.
-
Cybersecurity and AI: What Mythos means for organisations now
Todd Moore, Vice President of Encryption Products at Thales, examines how AI security models such as Claude Mythos are compressing cyber timelines and reshaping software protection, identity governance, and operational defence.
-
Can boards truly be accountable for cyber resilience if they can’t measure it?
Paul Cragg, CTO at NormCyber, argues that board accountability for cyber resilience depends on continuous, evidence-based measurement rather than fragmented reporting and point-in-time assurance.
-
Geofencing isn’t about blocking countries. It’s about spotting logins that make no sense
Daniel Shone, Founder of Apex Computing, explains how geofencing can add location context to authentication, helping organisations identify access requests that make little sense even when credentials appear valid.
-
Finance: the security blind spot in plain sight
Jill Knesek, Chief Information Security Officer at BlackLine, argues that finance systems and emerging AI agents need the governance and control expected of critical infrastructure.
-
Why your identity database is your biggest liability (and what’s replacing it)
Stefan Deiss, CEO and Co-Founder of The Hashgraph Group, argues that verifiable credentials and distributed ledgers can reduce the risks created by centralised identity databases.









