Is shadow AI today as great a risk as shadow IT was over the last decade? And have we learned the security lessons from previous IT transformations, including BYOD and the cloud? In this episode, we discuss why unauthorised and uncontrolled AI tools pose growing threats to both security and data confidentiality. And we look at how agentic AI brings a whole new set of risks, as systems create their…
According to the NCSC, there were over 200 attacks against UK critical national infrastructure last year. Some three quarters of these are thought to be linked to state actors. On the surface, that number of attacks might seem small. But their impact could be significant. Attacks against power, water and transport can quickly bring the country to a halt. And no advanced economy can operate for…
In this episode, we hear how security researchers and law enforcement worked together to disrupt Tycoon 2FA, a phishing as a service group. How did they discover, and then counter the group's activities? And what were the results? Our guest is Robert McArdle , director of forward threat research at TrendAI .
In this episode we welcome back the Cyber Agony Aunts, Amelia Hewitt and Rebecca Taylor. As the UK's Cybersecurity and Resilience Bill works its way through Parliament, has the debate about cyber resilience changed? What does a resilient organisation look like? And above all, how do we create one, without putting cybersecurity professionals under extreme pressure? As Amelia and Rebecca explain in…
Cybersecurity has its share of innovators, inventors and, of course, entrepreneurs. Benny Czarny created OPSWAT more than 20 years ago, to develop a common language for security applications. Today, the business is best known for its “firewall of data” approach to detecting and removing malware. In the first of an occasional series of interviews with founders, we speak to Czarny about his journey…
Security researchers have found millions of hard-coded secrets, in plain text, across both public and private code repositories. These include credentials, API keys, AI tokens and MCP configuration files. And AI is making the problem worse, with AI-assisted commits adding to this "secrets sprawl". Unless developers control how they manage secrets in their code, we are leaving the door open to…
How can cybersecurity professionals "engineer" resilience? And why is an effective community an increasingly important part of our defence against cyber attacks? In this episide, editor Stephen Pritchard caught up with Ameet Jugnauth, president of ISACA's London Chapter at their recent conference. They discuss building resilience, why we have reached a tipping point in boards' understanding of…
How do you live through a cyber attack, and recover from it? What lessons can you learn? And why is resilience moving up the cybersecurity agenda? In this special episode, we speak to Edwin Moraal , CISO at Dutch public safety body Veiligheidsregio Noord- en Oost-Gelderland (VNOG), about his experiences. And he's joined by Tim Pfaelzer, Veeam GM for EMEA, whose team helped with the recovery.…
Soon, quantum computers will be able to decrypt "production grade" encryption, putting both privacy and security at risk. But how close is "Q Day", and is a cryptographically relevant quantum computer a realistic prospect? Is it something malicious actors will be able to obtain, and if so, how would they use it and what threat does that pose to confidentiality of our files, as well as our…
DDoS attacks have posed a threat since the late 1990s. And distributed denial of service attacks have proven to be hard to prevent, and to deter. Security teams are better at detecting and blocking DDoS attacks than they were. But malicious actors have not stood still. They are now using complex, multi-vector attacks rather than relying on volume alone; they are using AI to design attacks, and…