Transform your PDFs into Flipbooks and boost your revenue!
Leverage SEO-optimized Flipbooks, powerful backlinks, and multimedia content to professionally showcase your products and significantly increase your reach.
Computing
Security
Secure systems, secure data, secure people, secure business
THE CHASE IS ON
AI is already in full pursuit of
becoming an irresistible force
NEWS
OPINION
INDUSTRY
COMMENT
CASE STUDIES
PRODUCT REVIEWS
FREE FALLING
Is AI Anthropic setting
us on a rocky path or a
force for future comfort?
ONE FALSE STEP...
Failure to embrace risk
management properly
can have devastating
consequences
THE HEAT IS ON
Advanced AI tools have the
power to blow the lid off
cybersecurity’s best efforts
Computing Security May/June 2026
Privacy-First AI Protects
If email isn’t private,
it’s not secure
Libraesva’s privacy-first AI analyses all messages locally in your environment, so no
content is ever sent to third-party clouds or external services.
Layered security defends your business against spam, malware, phishing, email
fraud, spoofing, zero-day threats, account takeover, social engineering, business
email compromise, inadvertent disclosure of sensitive information and more.
Test your security for FREE with our Email Security Tester
emailsecuritytester.com
libraesva.com
comment
DEEPFAKE ANXIETIES GROW
Daniel Spicer, Ivanti.
UK CEOs are dangerously unprepared
for the deepfake era.
That is the major finding of research
carried out by Ivanti. Its 2026 State of
Cybersecurity Report: Bridging the Divide
report draws on insights from more than
1,200 cybersecurity professionals
worldwide to reveal a rapidly widening
divide between escalating cyberthreats and
the ability of organisations to defend
against them.
AI is reshaping cybersecurity for both
defenders and attackers, but - on the plus
side - defenders believe they are gaining
the edge. Indeed, the report finds that
security professionals are 2.7x more likely
to believe defenders use AI as effectively as threat actors, if not more so. That
confidence level grows to 7.3x in favour of defenders using AI as effectively or more
effectively than threat actors over the next 24 months.
But here's the rub. Says Daniel Spicer, chief security officer at Ivanti: "Although
defenders are optimistic about the promise of AI in cybersecurity, Ivanti's findings also
show companies are falling further behind, in terms of how well prepared they are to
defend against a variety of threats. This is what I call the 'Cybersecurity Readiness Deficit'
- a persistent, year-over-year widening imbalance in an organisation's ability to defend
their data, people and networks against the evolving threat landscape. This challenge is
intensified by the accelerating pace of technological change, particularly as
organisations advance their SaaS transformation initiatives and the speed at which new
technologies are adopted."
What the findings make clear is the urgency for better defence strategies - with this
pitted against the ongoing struggle that organisations now face in balancing risk
awareness against effective preparation. The fear is that the gap between these will
widen as deep fakes and AI increase their stranglehold.
We have always lived in uncertain times, as far as cybersecurity is concerned. The
challenge we now face is that this 'uncertainty' may be hardening and reshaping into
something much more menacing.
Brian Wall
Editor
Computing Security
brian.wall@btc.co.uk
EDITOR: Brian Wall
(brian.wall@btc.co.uk)
LAYOUT/DESIGN: Ian Collis
(ian.collis@btc.co.uk)
SALES:
Edward O’Connor
(edward.oconnor@btc.co.uk)
+ 44 (0)1883 38 00 54
+ 44 (0)1689 616 000
David Bonner
(dave.bonner@btc.co.uk)
+ 44 (0)1883 38 00 54
+ 44 (0)1689 616 000
Stuart Leigh
(stuart.leigh@btc.co.uk)
+ 44 (0)1883 38 00 54
+ 44 (0)1689 616 000
Fraser Owen
(fraser.owen@btc.co.uk)
+ 44 (0)1883 38 00 54
+ 44 (0)1689 616 000
PUBLISHER: John Jageurs
(john.jageurs@btc.co.uk)
Published by Barrow & Thompkins
Connexions Ltd. (BTC)
Suite 2, 157 Station Road East
Oxted. RH8 0QE
Tel: +44 (0)1689 616 000
Fax: +44 (0)1689 82 66 22
SUBSCRIPTIONS:
UK: £35/year, £60/two years,
£80/three years;
Europe: £48/year, £85/two years,
£127/three years
R.O.W:£62/year, £115/two years,
£168/three years
Single copies can be bought for
£8.50 (includes postage & packaging).
Published 6 times a year.
© 2026 Barrow & Thompkins
Connexions Ltd. All rights reserved.
No part of the magazine may be
reproduced without prior consent,
in writing, from the publisher.
www.computingsecurity.co.uk May/June 2026 computing security
@CSMagAndAwards
3
Secure systems, secure data, secure people, secure business
Computing Security May/June 2026
inside this issue
CONTENTS
Computing
Security
NEWS
OPINION
INDUSTRY
COMMENT
CASE STUDIES
PRODUCT REVIEWS
THE CHASE IS ON
FREE FALLING
AI is already in full pursuit of
Is AI Anthropic setting
us on a rocky path or a
becoming an irresistible force
force for future comfort?
ONE FALSE STEP...
Failure to embrace risk
management properly
can have devastating
consequences
COMMENT 3
Deepfake anxieties grow
THE HEAT IS ON
Advanced AI tools have the
power to blow the lid off
cybersecurity’s best efforts
NEWS 6
Product integration phase completed
Agentic AI and the path to resilience
Regulation and AI reshaping risk
Deep dive into AI partner ecosystem
Adopting Agentic AI is 'a priority'
Kiteworks and Kasm enter alliance
ARTICLES
QUANTUM QUANDRY 14
A programme worth up to £2 billion is
being invested in quantum computing
innovation - but is it too little, too late?
YEAR OF LIVING DANGEROUSLY 10
Is AI already hurtling down the path that
will see it become an irresistible force,
its power and influence accelerating at
a speed few might have scarcely imagined
a short time ago? And, if such is the case,
how are we to keep AI from spinning
totally out of control?
TRUST LEFT IN TATTERS 16
RISK'S ROCKY ROAD 20
Users are suffering from email fatigue as
cybercriminals wear down their defences.
Do organisations accurately measure the risks
How can they fight back?
to their operations and take all the necessary
steps to prevent/eliminate these? If not, how
QUANTUM OVERKILL 27
do they alter their world view,so as to protect
Managing cryptographic security without
themselves against the kinds of attacks that
the highest levels of oversight can create
are rapidly being scaled up and growing ever
operational overload that leaves many
more sophisticated?
organisations dangerously exposed
CLOSING IN FOR THE KILL? 31
Speculation abounds about what AI might
do next and - more specifically - which
LIVING ON THE EDGE 24
industries and disciplines it could kill off
After recent high-profile happenings, there
CRIME PAYS… AND PAYS 32
is deep and growing unease about Mythos'
Global cybercrime damage is projected to
capabilities - though one top cyber official
cost more than $12 USD trillion annually
believes advanced AI tools could be a "net
by 2031. Can that be halted?
positive", if the technology was secured
from misuse. How big an 'If' is that?
SEVEN DEADLY SINS 34
Seven operational failures that appear
repeatedly across investigations remain
largely preventable, it is claimed
IS THE TOP ABOUT TO BLOW? 28
A survey of 500 business leaders from across
EVENTS
the UK has revealed that, while cyberattacks
WHO DARES WINS AT INFOSEC 18
have increased for 54% of the respondents
From 'SAS: Who Dares Wins' star Jason Fox
(versus 45% two years ago), over 50% of
to England Rugby World Cup winner Maggie
companies say they are uncertain whether
Alphonsi, this year's Infosec will have a host
they have the expertise to prevent an AIpowered
attack.
of top speakers to inspire attendees
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
4
news...news...news
Spencer Starkey.
PRODUCT INTEGRATION PHASE COMPLETED
Jon Connet.
Wireless management platforms, security services and
connected vehicle programs company Aeris has
completed its product integration with Palo Alto Networks
Prisma SASE 5G.
The move combines Aeris IoT Watchtower with Prisma
SASE 5G to "transform how enterprises protect wireless IoT
deployments, providing a single point of control to extend
security to the wireless IoT edge". States Jon Connet,
chief product officer of Aeris: "This partnership enables
organisations to apply best-in-class security uniformly across
both IT systems and wireless connected devices, while
empowering Aeris' ecosystem of nearly 30 strategic mobile
network operator partners to leverage the global trust and
proven track record of one of the world's largest cybersecurity providers."
AT THE SPEED OF MIGHT
Threat actors are moving on average
four times faster than just a year
ago, by using AI to speed up and scale
cyber-attacks. That is the alarming
statistic from a report released by
Palo Alto. "In the most efficient attacks,
groups exfiltrate data just 72 minutes
after initial access," the company says.
Commenting on finding, Spencer
Starkey, executive VP at SonicWall, said:
"After 2025, the worst year on record
for cyber incidents, we know that in
2026 it will be even more severe. Particularly
with AI-enabled attacks accelerating
both the scale and sophistication
of threats.
"Organisations that remain dependent
on manual processes or legacy detection
models will struggle to maintain any
meaningful perimeter. The defining
security trend of 2026 will be the emergence
of continuous, AI-versus-AI conflict:
autonomous defensive models battling
autonomously evolving threats in real
time," he states.
AGENTIC AI AND THE PATH TO RESILIENCE
The CISO Report: From Risk to Resilience in the AI Era', which surveys 650 global chief
information security officers (CISOs), has been released. This, Splunk's annual report,
highlights CISOs' rapidly expanding role, their strategic approach to AI adoption and a
steadfast commitment to human talent, as they confront an increasingly complex landscape.
"CISOs operate in the eye of the storm, at the center of constant transformation.
Role responsibilities expand, threats evolve, and AI accelerates everything," says Michael
Fanning, CISO, Splunk. "This expanded mandate brings an exceptional level of pressure
and personal accountability.
"We are not just managing technology. We are managing risk, talent and the digital
resilience that drives critical business outcomes."
REGULATION AND AI RESHAPING MOBILE SECURITY RISK
Zimperium has released new analysis outlining how
regulatory changes and advances in artificial intelligence are
transforming the mobile threat landscape and creating new
challenges for enterprises. "Mobile security is entering a new
phase where both policy and technology are reshaping risk,"
said Krishna Vishnubhotla, vice president of Product Strategy at
Zimperium. "Organisations are shipping mobile software faster
than ever, while attackers are using AI to accelerate exploitation.
Security must evolve just as quickly."
Mobile devices and applications now represent one of the
largest attack surfaces in the enterprise. As cybercriminals adopt
a mobile-first attack strategy, the combination of new
regulatory policies and AI-driven development is accelerating
how mobile apps are built, distributed, and targeted by
attackers.
Krishna Vishnubhotla.
6
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
Layers aren’t just for cakes; they’re
essential in cybersecurity’s secret
recipe for protection!
Bake it happen with VIPRE Security Group. Secure your
bytes before you take a bite with Email Security, Endpoint
Security and User Protection
www.vipre.com
news...news...news
David Byrnes.
ADVANTECH GOES DEEP INTO AI PARTNER ECOSYSTEM
Advantech is partnering with
DEEPX, a leading Korean AI
ADV716 Advantech-DEEPX.
semiconductor innovator specialising
in NPU (Neural Processing Unit)
technology. The collaboration
expands Advantech's AI chipset
ecosystem and introduces the
company's first AI acceleration
solution powered by DEEPX
technology, the EAI-1961 series
Edge AI Acceleration Module.
"Advantech evaluates a broad range
of AI chip technologies to address
diverse industrial needs," says Joey Hsu, director of Advantech's Embedded Sector. "DEEPX
demonstrates commendable efficiency in power and thermal performance, which is essential
for reliable edge AI deployment.
KITEWORKS AND KASM ENTER
TECHNOLOGY ALLIANCE
Kiteworks has entered into a new
technology alliance with Kasm,
aimed at enhancing how organisations
securely interact with sensitive data.
"Organisations today face an escalating
challenge with sensitive data flows
across dozens of channels, systems and
partners with fragmented visibility and
inconsistent controls," says David Byrnes,
VP Global Channels, Kiteworks. "Every
file shared via email, file-sharing, SFTP,
managed file transfer, API or data form
represents potential exposure. Security
teams struggle with disparate logging
systems, compliance officers cannot
prove governance end to end and IT
administrators manage a patchwork
of point solutions that expand the
attack surface.
"At the same time, adversaries are
growing more sophisticated, regulatory
requirements are intensifying and the
emergence of AI is creating entirely
new data governance challenges that
existing approaches were never
designed to address."
IN THE ZONE
Infosecurity Europe, running from 2-4 June 2026 at
Excel London (see page 18), has announced the
renewal and expansion of its dedicated Channel Zone,
designed to connect vendors, MSPs, MSSPs,
distributors, resellers and integrators at a time when
partner resilience has become a board-level concern.
States Rob Tomlin, VP, Northern Europe, Exclusive
Networks: "Our channel community needs dedicated
environments, where vendors, MSPs, MSSPs and
resellers can engage commercially, share insight
and align around the technologies and services that
organisations increasingly depend on. It's a welcome
addition to see Infosecurity Europe create such space
with The Channel Zone."
ADOPTING AGENTIC AI IS 'A PRIORITY'
Ivanti's '2026 State of Cybersecurity Report: Bridging the Divide' reveals a rapidly
widening divide between escalating cyberthreats and organisations' ability to defend
against them. Drawing on insights from more than 1,200 cybersecurity professionals
worldwide, the report reveals a rapidly widening divide between escalating cyber threats
and organisations' ability to defend against them.
"Although defenders are optimistic about the promise of AI in cybersecurity, Ivanti's
findings also show companies are falling further behind in terms of how well prepared
they are to defend against a variety of threats," comments Daniel Spicer, chief security
officer at Ivanti.
8
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
artificial intelligence
YEAR OF LIVING DANGEROUSLY
BY THE END OF 2026, WHAT WILL AI LOOK LIKE - AND WHAT IMPACT WILL IT BE MAKING BY THEN ON
CYBERSECURITY AND THOSE SEEKING TO ENFORCE IT? COMPUTING SECURITY FINDS OUT
Jay Kaplan, Synack: organisations that come
out intact will have invested in security
programmes that move as fast as threats do.
Is AI already hurtling down the path that
will see it become an irresistible force, its
power and influence accelerating at a
speed few might have scarcely imagined a
short time ago? And, if such is the case, how
are we to keep AI from spinning totally out of
control? With the genie seemingly now out
of the bottle, we've been seeking opinion
from across the industry on this.
"By the end of 2026, the organisations that
come out intact will be the ones who invested
in security programmes that move as fast as
threats do," says Jay Kaplan, CEO and cofounder
of Synack. "Continuous adversarial
testing with humans in the loop has been the
right model for a long time. The
advancement of AI-enabled adversaries will
soon make it the only model. Here's what's
actually changing. AI is compressing the
timeline between exposure and exploitation
in ways that fundamentally break the
assumptions most security programmes are
built on. Anthropic's Mythos (see page 24)
makes this concrete - the model fully
autonomously identified and exploited a 17-
year-old remote code execution vulnerability
in FreeBSD, and separately chained four
vulnerabilities together to escape both
browser renderer and OS sandboxes. These
are documented capabilities and they're only
going to improve.
"Security programmes built around periodic
assessments and static playbooks are
operating on a different clock than their
adversaries. An annual penetration test tells
you what your environment looked like at a
single moment in time. That's not useful
intelligence when the threat landscape is
shifting daily. The data you need to stay
ahead has to be continuous and it has to
reflect how attackers are actually operating."
The human element matters here, adds
Kaplan. "AI scales the reconnaissance, surfaces
the attack paths and runs continuously
without fatigue. But human researchers bring
the contextual judgment that determines
what actually matters - the logic flaw that
automated tools miss, the chain of
vulnerabilities that looks low-risk in isolation,
but becomes critical when combined. That
combination is what makes continuous
adversarial testing the right answer for this
moment."
EMBEDDED EVERYWHERE
For Abba Abbaszadi. chief AI officer, MTI
Technology, the situation is all too clear. "By
the end of 2026, AI will not just be another
technology organisations need to secure. It
will be the least understood, and least
controlled, part of the enterprise attack
surface. That shift has happened faster than
10
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
artificial intelligence
most predicted. A year ago, organisations
were still defining AI strategies. Today, AI is
embedded across workflows, applications
and decision-making processes - often
without security teams having full visibility of
where or how it is being used."
For threat actors, AI has removed friction
entirely, he says. "Phishing can now be
generated, personalised and deployed at
scale in seconds. Deepfakes are convincing
enough to bypass human trust controls.
More importantly, AI is now being used to
identify vulnerabilities and automate
exploitation, compressing the time between
discovery and attack. Defenders have access
to the same technology, but this is not a
balanced fight. Attackers only need one
success. Security teams are being asked to
defend an expanding attack surface that they
do not fully see, let alone control."
The real issue, however, is not the models
themselves. It is how they are being used.
"Shadow AI is rapidly becoming one of the
most significant, and overlooked, risks in
cybersecurity. Employees are uploading
sensitive data into external tools, integrating
outputs into business processes and making
decisions based on AI-generated content, all
outside the visibility of IT and security teams.
In many organisations, this is happening at
scale."
From a security perspective, that means
uncontrolled data exposure, weakened
auditability and entirely new vectors for
prompt injection and data leakage, states
Abbaszadi. "In effect, organisations are
expanding their attack surface faster than
they are securing it. This is why the idea of AI
'spinning out of control' is misleading. The
models are not the problem. The lack of
governance is. The organisations that will
struggle are not those that adopt AI fastest,
but those that fail to control how it is used."
CONNECTIVE TISSUE
By the end of 2026, artificial intelligence will
likely feel less like an emerging capability and
more like embedded infrastructure across the
cybersecurity ecosystem, states Jeremy
Ventura, field CSO, Myriad360. "The shift is
already underway. AI is moving from isolated
point solutions into the connective tissue of
security operations, decision making and even
business workflows. The question is no longer
whether organisations will adopt AI, but how
deeply it will be integrated and how
responsibly it will be governed."
From a defender's perspective, AI is poised
to materially reshape security operations.
"Security teams are under constant pressure
to do more with less and AI is being
positioned as a force multiplier. We are seeing
early signs of this in areas such as alert triage,
automated investigation and workflow
orchestration. By 2026, it is reasonable to
expect AI-driven systems to handle a
meaningful portion of repetitive operational
tasks, allowing analysts to focus on higher
order decision-making. At the same time, this
introduces new dependencies. Overreliance
on AI without proper validation, visibility and
control mechanisms could create blind spots,
rather than eliminate them," he comments.
Where the conversation is evolving quickly is
in how AI is being operationalised beyond
traditional enterprise use. "Recent
developments, such as Anthropic Mythos,
and emerging open initiatives, like OpenClaw,
signal a shift toward more autonomous,
agent-driven systems that can act, not just
analyse. At the same time, rapid
advancements from players such as DeepSeek
highlight how global competition is
accelerating capability development,
particularly in model efficiency and
reasoning."
This, says Ventura, has direct implications for
vulnerability discovery and exploitation. "AI
models are already demonstrating the ability
to identify patterns in code,
misconfigurations and potential weaknesses
at scale. In a near-term horizon, this will
Jeremy Ventura, Myriad360: AI is moving
from isolated point solutions into the
connective tissue of security operations,
decision making and even business
workflows.
Tom Pepper, Avella Security: AI will soon be
the defining force shaping both attack and
defence.
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
11
artificial intelligence
Martin Walsham, AMR CyberSecurity: the
risks embedded in AI-generated software
itself need to be managed.
Merlin Gillespie, Cybanetix: we can expect
AI to have moved from a consultative to
an assistive technology by year end.
compress the time between vulnerability
disclosure and exploitation or even enable
discovery before traditional processes catch
up. Nation state actors are heavily investing
in these capabilities, using AI to enhance
offensive operations, automate
reconnaissance and refine targeting with
greater precision."
DEFINING FORCE
By the end of 2026, AI will not simply be an
emerging capability in cyber security," states
Tom Pepper, partner at Avella Security. "In my
opinion, it will be the defining force shaping
both attack and defence…. Phishing emails
arrive with flawless grammar, perfect tonematching
and highly personalised lures
scraped from open sources in seconds, while
deepfakes are becoming indistinguishable
from reality and have already been used to
extort tens of millions of pounds."
Ransomware operations are evolving at true
machine speed, with AI being used to profile
victims, script negotiations and automating
extortion end-to-end, he points out. At the
same time, organisations are beginning to
manage fleets of AI agents across coding,
workflow automation and customer
operations. "Whilst the productivity gains are
unquestionable, from a security perspective -
unless appropriate controls are considered -
the risks to organisations can be devastating.
Each agent effectively acts as a super-user,
expanding the attack surface and introducing
risks that can cascade silently across the
business. Shadow agentic AI operating
outside IT visibility will only compound this
challenge, making oversight and control
significantly harder."
In Pepper's view, the real challenge to AI
adoption is ensuring it does not spin out of
control without careful consideration of the
potential impacts. "That requires deliberate
action now: shifting to AI-aware defences,
such as behavioural analytics and phishingresistant
authentication, rigorously redteaming
not just systems, but AI models and
agents, and embedding governance
frameworks with clear oversight, guardrails,
kill switches and transparency. Aligning AI
adoption with recent European standards -
such at the ETSI Standard for AI Cyber
Security [ETSI EN 304 223] is a good place to
start."
SOFTWARE DANGERS
Alongside changing how we work, AI is
reshaping how the software we use is built.
And this may prove to be the biggest AI
cybersecurity risk of all, warns Martin
Walsham, director of AMR CyberSecurity
(part of Infinum) "Vibe coding - using AI tools
to generate applications quickly, often with
minimal oversight - has become a normal,
encouraged and increasingly expected part of
software development. The appeal is
obvious. But speed without scrutiny creates a
dangerous assumption: that code which
looks secure actually is secure.
"Our recent hands-on testing shows that,
even when AI is explicitly told to build secure
applications, there are still vulnerabilities.
While detailed prompts referencing bestpractice
guidelines certainly improved the
results, the apps still had critical flaws that
would have been trivial to exploit. The main
issue is that, although AI can reproduce
patterns that mimic secure coding, it does
not truly understand risk, context or intent.
"This means the AI security challenge is not
limited to defending against AI-powered
attackers; it is about managing the risks
embedded in AI-generated software itself. As
AI-driven development accelerates, these
vulnerabilities will be introduced earlier,
propagate faster and become harder to
detect. This is particularly true where outputs
are trusted without detailed review."
This also changes the traditional model of
accountability in software security, points out
Walsham. "Historically, responsibility was
relatively clear. The developers wrote code
and security teams reviewed it. In a vibe
12
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
artificial intelligence
coding environment, it's far less clear.
Responsibility is now shared between
humans and systems. Developers are no
longer writing every line of code; they are
prompting AI to generate it. This means
security depends on more than technical skill;
it also depends on how effectively those
prompts anticipate risk.
"More autonomous development workflows
are also emerging, where AI can generate,
modify and even deploy code with limited
human intervention. In these scenarios, the
window for traditional review shrinks and
security decisions are effectively made
upstream, and are embedded in prompts,
guardrails and system design."
So, how do we prevent this from spiralling
out of control? Walsham says the answer is
not to slow adoption, but to change how we
build. "Security must be included early in the
development lifecycle, embedded into
prompts, pipelines and architecture, rather
than layered on afterwards. AI-generated
code must be treated as untrusted by default,
requiring rigorous validation and human
oversight."
HIGHLY ACTIVE ROLE
Merlin Gillespie, CTO at Cybanetix, says AI is
making major evolutionary leaps every 3-
6months, so realistically we can expect AI to
have moved from a consultative to an
assistive technology by year end. "Rather than
purely translating natural language into
syntactical queries of the SIEM, AI will take a
more active role in assisting with the
processing, understanding and interpretation
of log data. Next-generation Agentic AI will
be more autonomous and able to carry out
tasks to achieve set goals, so it will soon be
building and running playbooks on the fly,
returning malicious or suspicious verdicts
from investigations, and remediating and
containing threats automatically."
AI will naturally become part of how SOC
analysts work, he states, effectively giving
them the power of a security cyborg. "They'll
be able to leverage the benefits of machine
learning and AI, while also applying human
ingenuity. We also expect AI to play a more
active role in assisting level one SOC analysts,
effectively upskilling and helping them to
'level up' more quickly. The best analogy is a
very bright team of juniors. They're fast,
capable and eager, but they need direction
and oversight. The manager who delegates
properly and checks the output will get
enormous value. The one who puts their feet
up and assumes the work is done will come
unstuck."
Gillespie singles out how Generative AI can
produce unpredictable and inconsistent
outcomes and remains weak at discerning
business context, while humans excel
through real-world experience. "Retaining a
human in the loop (HITL) with the knowledge
to validate and verify AI outputs is not
optional. We've been experimenting with
assistive AI in threat detection and response
and in one test a model misinterpreted the
threat and went on to produce a fictitious kill
chain and mitigation advice, all of which
would have taken the SOC analyst down a
rabbit hole they didn't need to go down. So,
retaining senior oversight is key."
THE TRUST FACTOR
By the end of 2026, AI in cybersecurity will be
increasingly embedded in day to day SOC
operations, but its success in the UK and
Europe may be defined less by speed and
more by trust, comments Brett Candon, VP
International at Dropzone AI. "Regulatory
frameworks, such as GDPR and NIS2, already
influence how security data can be accessed,
processed and reviewed, and those
constraints are expected to shape how
autonomous, agentic AI systems are
deployed as they move beyond proof of
concept into routine use.
"In practical terms, AI is likely to take on a
much greater share of routine investigative
work, including alert triage and first pass
analysis. However, European CISOs may
remain cautious about autonomy, unless it is
implemented with clear governance. Faster
outcomes are unlikely to build confidence, if
organisations cannot see what data was
examined, where processing occurred and
how conclusions were reached. In regulated
environments, trust may depend as much on
governance as on technical capability."
Explainability is therefore likely to become a
baseline requirement, rather than an optional
enhancement, adds Candon. "Going forward,
boards, auditors and regulators may
increasingly expect security leaders to justify
AI assisted decisions with evidence. That
suggests growing emphasis on investigation
outputs that document reasoning steps,
tested hypotheses and supporting artefacts,
rather than opaque outcomes delivered at
speed."
As European AI oversight moves toward
enforcement, the ability to retrospectively
defend decisions may become as important
as preventing incidents in the first place, he
adds. "Data sensitivity is also expected to
remain a central trust factor. SOC data often
includes personal or operationally sensitive
information, and UK and EU organisations
are likely to scrutinise where investigative
work is performed and whether human
access occurs outside approved jurisdictions.
Approaches that reduce opaque manual
handling may be viewed more favourably, if
they demonstrably lower privacy and
sovereignty risk rather than shifting it."
Strategically, AI day-to-day cybersecurity
operations will increasingly be positioned as a
mechanism to absorb repetitive investigative
workload, "freeing experienced analysts to
focus on judgement driven decisions and
incident response. Ultimately, AI systems that
are transparent in operation, verifiable in
performance and accountable in outcome
are the ones most likely to earn lasting trust
with UK and EU SOC teams".
Continued on Page 31
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
13
SCALING ON UP
Jason Soroko, senior fellow at Sectigo, is not
convinced by the government claims that
the UK will be the first country to roll out
quantum computers at scale. "In the context
of global deep-tech, £2 billion is de-risking
capital, not scale-up capital," he argues. "The
UK cannot win a brute-force hardware war
against the sheer capital expenditure ([CapEx]
of US hyperscalers or Chinese state funds. To
maximise this pledge, the UK must abandon
the vanity goal of building end-to-end sovquantum
computing
A PIONEERING UK GOVERNMENT PROGRAMME WORTH UP TO £2 BILLION IS BEING
INVESTED IN QUANTUM COMPUTING INNOVATION. BUT IS IT TOO LITTLE - AND IS IT TOO LATE?
Some £2 billion worth of UK government
investment in Quantum is aiming to
"ensure the UK stays at the forefront of
Quantum innovation". It adds: The UK will
become the first country to benefit from
revolutionary Quantum computers, sensors
and networks, and support the emergence
of the next generation of leading British
companies who will help shape the curve
of progress".
"As of today, the UK is the first country in
the world to commit to an advanced
procurement to build large-scale quantum
computers on our shores by the early 2030s,"
states the government. "Joining R&D,
manufacturing, software, hardware and
procurement into a single programme,
we will be world leaders in developing and
deploying large-scale Quantum computers."
These systems will be built in Britain, it adds,
"creating British jobs, new opportunities for
British businesses, and opening new routes of
investment to flow into our economy from all
over the world".
According to technology secretary Liz
Kendall: "Laying the foundations which will
give the UK a rich pool of Quantum talent,
the government's flagship TechFirst
programme will launch new partnerships
with companies in the sector - offering up to
100 fully-funded internships. This will give
people the tools they need to embark on
future, high-paying careers in the field.
"The UK is already a global powerhouse in
the technology, launching a first of its kind
National Quantum Technologies programme
in 2014, which has already been backed by
more than?£1 billion in public funding to
support skills, research and infrastructure.
Our credentials as a global magnet for private
investment are also thriving."
FROM EXPERIMENTAL
TO ACTION STATIONS
While WSO2's quantum expert Dr Frank
Leymann recognises that the UK's proposed
£2 billion investment in quantum computing
is "timely and necessary to maintain relevance
in what will become a foundational technology
landscape", he also has his reservations.
Arguing that "the real measure of success will
not be the scale of funding alone, but how
effectively it accelerates the transition from
experimental capability to enterprise-ready
systems".
Quantum computing is sometimes framed
in terms of hardware breakthroughs, but its
broader impact will depend on how well it
integrates into existing digital ecosystems,
Leymann points out. "This is where the
conversation needs to evolve. Enterprises will
not adopt quantum solutions in isolation, but
will require seamless integration with cloud
platforms, AI systems, data pipelines and
existing applications. Without this connective
layer, even the most advanced quantum
capabilities risk remaining confined to
research environments."
From this perspective, investment must
extend beyond quantum processors to
include the middleware, APIs and orchestration
frameworks that make hybrid
computing models viable. "The future is not
purely quantum; it is hybrid mostly, and
quantum systems work together with
classical software, as well as AI. Enabling this
requires solid integration infrastructure, governance
and identity-aware access control to
ensure these systems operate securely, at
scale."
There is also a strong link between quantum
computing and AI, he points out. "As AI
systems become more autonomous, they
will increasingly seek out advanced computational
resources to optimise decisionmaking.
In time, quantum computing will
become one such resource. But for this to
happen, organisations need platforms that
can intelligently navigate between AI agents
and diverse compute backends, ensuring
observability, policy enforcement, and trust.
"To this end, strategic focus is essential.
Investments must prioritise not only scientific
advancement, but also the infrastructure
that makes quantum computing usable,
governable and accessible within real-world
enterprise environments. Ultimately, the
winners in the quantum era will not be
those who build the most powerful machines
alone, but those who make them usable at
scale.
14
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
quantum computing
ereign mainframes. Instead, this capital
should be ruthlessly concentrated on
monopolising critical, high-margin
bottlenecks in the global supply chain -
such as cryogenic control chips, integrated
photonics foundries and error-correction
middleware."
By dominating these indispensable "pickand-shovel"
layers, the UK can force the
global ecosystem to license British IP, using
the £2bn as leverage to crowd-in the massive
private institutional capital required for
true commercialisation, he continues. "It is
technically plausible for localised sovereign
prototypes, but commercially optimistic for
widespread enterprise deployment.
"The industry has exited the 'physics era'
and collided with the 'systems engineering
era'. The primary hurdles to an early 2030s
deployment are no longer theoretical;
they are brutal, unglamorous hardware
constraints. Scaling to the millions of physical
qubits required for fault tolerance hinges on
solving massive thermal dissipation issues in
dilution refrigerators, ultra-dense microwave
cabling bandwidth and silicon fabrication
yields. If these deep-tech manufacturing
bottlenecks persist, seamless enterprise
deployment slips into the late 2030s."
QUANTUM RISK AWARENESS 'PATCHY'
Daryl Flack, partner at Avella Security,
wonders if organisations themselves are
moving fast enough to address the risks
already taking shape. "Across industries,
awareness of quantum risk remains patchy.
While some sectors, particularly critical
national infrastructure, are beginning to
engage, many organisations are still at a very
early stage of understanding what quantum
capability means for their environments.
"For decades, cryptography has been the
quiet constant of digital infrastructure. That
stability has created a false sense of security,
an assumption that encryption 'just works'
or that it is a problem for the future."
The reality is more immediate. "The greatest
exposure lies in long-lived and confidential
data: legal records, medical research, state
secrets and sensitive corporate archives that
must remain secure for decades. Adversaries
are already pursuing 'harvest now, decrypt
later' strategies, exfiltrating encrypted data
today with the expectation it can be unlocked
when quantum capabilities mature. The
countdown has already started."
This is why the question of investment
cannot be viewed in isolation, adds Flack.
"Even with government backing, the
transition to quantum-safe cryptography
represents a once-in-a-generation shift and
one that is deeply complex. Cryptography is
embedded across applications, networks,
devices and operational systems, often with
limited visibility. Many organisations simply
do not know where it exists within their
estate."
The UK's National Cyber Security Centre
has set out a clear roadmap - discovery
and planning by 2028, migration of priority
systems by 2031 and full transition by 2035.
"Those milestones may appear distant, but
the reality is that the discovery and implementation
effort will take years.
"Waiting is not a viable strategy.
Responsibility cannot be outsourced. While
vendors will play a role, cryptographic
resilience must sit with each organisation.
This means starting now: identifying where
cryptography is used, prioritising long-lived
data and designing systems with cryptoagility
at their core."
Quantum computing will unlock enormous
innovation, particularly alongside AI, but it is
a double-edged sword, Flack adds. "The same
capability that drives breakthroughs also
threatens the trust underpinning the digital
economy. The organisations that act decisively
today will be the ones that carry trust,
resilience and competitive advantage into
the quantum future."
Daryl Flack, Avella Security: across
industries, awareness of quantum risk
remains patchy.
Frank Leymann, WSO2: the winners
will not be those who build the most
powerful machines alone, but those
who make them usable at scale.
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
15
email focus
TRUST LEFT IN TATTERS
USERS ARE SUFFERING FROM EMAIL FATIGUE AS CYBERCRIMINALS
WEAR DOWN THEIR DEFENCES. HOW CAN THEY FIGHT BACK?
Cybercriminals are stealing trust by
exploiting legitimate sites, systems
and ecosystems to bypass defences
more easily and maximise attack success.
The findings form part of VIPRE Security
Group's 'Q1 2026 Email Threat Trends
Report'. Processing 1.8 billion emails in
the first quarter of this year, this in-depth
survey highlights the struggles that many
organisations face, signalling a number
of areas where they must strengthen
email defences in the coming months.
Commercial spam takes up the lion's
share at 46%, delivered via compromised
accounts (33%) and free email services
(32%). "This illustrates trusted platforms
and free services as criminals' favoured
Usman Choudhary, VIPRE.
attack vectors," states VIPRE. "Commercial
spam wears down users with email
fatigue, increasing their chances of being
phished, while the technique itself assists
cybercrime through misleading subject
lines, aggressive language and act-fast
promotions." Nearly two-thirds of spam
came from US-based infrastructure,
followed by Ireland and the UK. The US
was also the top target of commercial
spam at 60%, followed by the UK at
12% and Canada at 6%.
Cybercriminals are increasingly relying
on familiar, reputable platforms to carry
out their attacks. Phishing made up
25.87% of all spam, with malicious links
remaining the weapon of choice. "During
the first quarter of 2026, embedded links
appeared in 50.59% of phishing emails,
while 26.69% included attachments,
19.17% used callback schemes and 3.55%
relied on QR code-based phishing." Of
those most in the firing line, Microsoft
continues to be the top brand targeted
for spoofing, "and '.com' domains remain
the primary infrastructure for sending
these attacks," adds VIPRE.
Furthermore, attackers favour 'open
redirects' that begin with the legitimate
domain and then end with a parameter
routing to a malicious site. Abused URLs
accounted for over 89% of phishing
URLs.
Many cybercriminals leverage Cloudflare
to conceal their phishing links. By taking
advantage of the platform's CAPTCHA
and bot-protection mechanisms, they
prevent security scanners from accessing
the actual malicious landing pages. This
tactic not only allows more phishing
emails to bypass defences and reach
users, but also increases the perceived
legitimacy and quality of these emails.
Meanwhile, callback phishing remains
a strong trend. "Common tactics include
fake invoices, subscription renewals
and account status alerts. Microsoft
accounted for 41% of all spoofed brands
in callback campaigns, followed by
PayPal (17%) and Geek Squad (15%).
Runners-up include McAfee, Amazon,
Norton and eBay. Interestingly, to allay
suspicion, these callback campaigns
were sent from authenticated Microsoft
infrastructure, all passing SPF, DKIM and
DMARC checks," reveals VIPRE.
While the C-suite continues to be
the primary impersonation focus for
cybercriminals, its popularity dropped
from 73% (in Q1 2025) to 54% in Q1
2026. This shift suggests attackers are
adjusting to more realistic behaviours -
for example, executives follow a chain of
command and don't always reach out
directly to the C-suite.
"Attackers are boldly using
sophisticated techniques to evade
detection, alongside resorting to
emotional triggers to manipulate and
breach trust," says Usman Choudhary,
general manager, VIPRE Security Group.
"Organisations must strengthen email
defences and rethink how trust is
established across every channel to
combat these threats. The landscape
demands vigilance and a proactive
approach to security. There is no room
for complacency."
16
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
Computing
Security
Secure systems, secure data, secure people, secure business
e-newsletter
Are you receiving the Computing Security
monthly e-newsletter?
Computing Security always aims to help its readers as much as possible to do
their increasingly demanding jobs. With this in mind, we've now launched a
Computing Security e-newsletter which is produced every month and is available
free of charge. This will enable us to provide you with more content, more
frequently than ever before.
If you are not already receiving this please send your request to
christina.willis@btc.co.uk and advise her of the best email address for the
newsletter to be sent to.
events
WHO DARES WINS AT INFOSEC
FROM 'SAS: WHO DARES WINS' STAR JASON FOX TO ENGLAND RUGBY WORLD CUP WINNER MAGGIE
ALPHONSI, THIS YEAR'S INFOSEC SHOW WILL HAVE A HOST OF TOP SPEAKERS TO INSPIRE ATTENDEES
England Rugby World Cup winner
Maggie Alphonsi will bring lessons
from elite sport to the cyber security
community.
Infosecurity Europe, the information
security event running from 2-4 June at
Excel London, has lined up a stellar cast
of keynote speakers for its 2026 conference
programme, including former Special Boat
Service (SBS) sergeant and 'SAS: Who Dares
Wins' star Jason Fox.
Bringing together expertise from cyber
security, law enforcement, elite sport and
the military, the keynote line-up will explore
leadership, resilience and innovation, and
how this is applied to the cyber security
industry.
Fox has spent his career operating in some
of the world's most hostile environments as
part of the UK Special Forces. On Thursday, 4
June, from 10:05-10:45, he will translate the
principles that underpin elite military teams
into the digital domain, exploring how cyber
security professionals can adopt Special
Forces approaches to resilience, decisionmaking
and leadership under pressure.
Drawing on real-world operational
experience, he will share practical mental
models and strategies designed to help
cyber leaders and teams maintain clarity,
build trust and perform effectively when
navigating complex and high-stakes
environments.
Cyber security titan, Shlomo Kramer, one of
the most influential figures in the global
cyber industry, will take the stage on Tuesday,
2 June. As a founder and investor behind
pioneering companies including Check Point,
Palo Alto Networks, Imperva, Cato Networks
and Sumo Logic, Kramer has helped shape
the modern cyber security landscape. He
will join a keynote 'fireside' chat, sharing
his perspective on the technology trends,
investment dynamics and innovation cycles
shaping the future of cyber security.
He will also judge Infosecurity Europe's
'Dragons' Den'-style cyber start-up competition,
helping to spotlight emerging
innovation and the next generation of
cyber entrepreneurs.
Also on Tuesday, 2 June, Cynthia Kaiser,
former deputy assistant director of the FBI's
Cyber Division and now leading ransomware
research at Halcyon, will offer a rare insider
perspective on the cyber-criminal economy.
Drawing on years of experience investigating
sophisticated cybercrime operations, Kaiser
will explore how analysing activity across
the dark web and the wider cyber-criminal
network can help organisations better
understand emerging ransomware tactics
and anticipate the behaviour of threat
actors.
She will also contribute her expertise to
the event's Women in Cybersecurity panel
18
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
events
Cynthia Kaiser will offer a rare insider
perspective on the cyber-criminal
economy.
Jason Fox has operated in some of the
world's most hostile environments as
part of the UK Special Forces.
Cyber security titan Shlomo Kramer is
one of the most influential figures in
the global cyber industry.
session, sharing insights on leadership,
representation and the evolving role of
women across the cyber industry.
Former athlete and England Rugby World
Cup winner Maggie Alphonsi will take to
the stage on Wednesday, 3 June, to bring
lessons from elite sport to the cyber security
community, exploring what it takes to lead
in high-performing environments. Having
broken barriers, smashed stereotypes and
changed the game on and off the field,
becoming a respected voice in leadership
and performance, Alphonsi now works with
organisations around the world to help
individuals and teams unlock their full
potential. Her keynote will focus on developing
a winning mindset, encouraging leaders
to step outside their comfort zones, embrace
their strengths and build the confidence that
is required to perform at the best.
A WIZ SESSION LINED UP
The conference programme will also feature
a keynote session on Tuesday, 2 June from
13:50-14:20, Ron Leizrowice, AI researcher
at Wiz, who will deliver 'The Infosec Big Fat
Cloud Update of the Year', exploring how
the rapid adoption of AI is transforming
the cloud security landscape. Drawing on
frontline research into cloud-native threats,
Leizrowice will outline how AI is compressing
the window between misconfiguration
and exploitation while expanding the attack
surface around cloud control planes, identities
and automated workflows. The session
will outline how to reduce AI-driven attack
paths while enabling teams to move fast and
build securely.
Meanwhile, on Wednesday, 3 June, from
11:00-11:35, Rik Ferguson, vice president
of Security Intelligence at Forescout and
an Infosecurity Hall of Fame inductee, will
present 'Quantum is still far off, we can wait
- can't we?', examining why organisations
should already be preparing for the transition
to post-quantum cryptography.
With technology procurement and
depreciation cycles as the countdown clock,
Ferguson will explore the risks posed by
crypto-fragile components and share
practical steps organisations can take and
insight into the industries that are leading
the pack and what we can learn from them.
Brad Maule-ffinch, event director at
Infosecurity Europe, comments: "This year's
keynote speakers bring insight and experience
from some of the most demanding
environments imaginable, from Special
Forces operations and international law
enforcement to elite sport and global cyber
innovation. Their perspectives will provide
our audience with a refreshing view and
awareness into how resilience, mindset and
forward-thinking leadership can help organisations
navigate current and evolving cyber
security challenges."
LEADING INSIGHTS
The Global Threat Landscape will also be
examined, with insights from leaders that
include former Ukrainian Foreign Minister
Dmytro Kuleba and the NCSC. They will
explore the realities of state-backed cyber
conflict and its implications for government,
industry and national resilience.
Infosecurity Europe will bring together
thousands of cyber security professionals
to discover emerging technologies, share
expertise and connect with peers across the
global security community.
Registration for Infosecurity Europe is open.
Entry cost includes access to the exhibition
show floor and the many theatres where
visitors can hear from some of the biggest
names in the industry.
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
19
risk management
RISK'S ROCKY ROAD
FAILURE TO EMBRACE RISK MANAGEMENT IN A CAREFULLY PLANNED-OUT MANNER CAN HAVE
DEVASTATING CONSEQUENCES. WHY THEN DO MANY ORGANISATIONS FAIL TO FOLLOW THIS PATH?
Risk management means assessing
threats to measure their possible
impact, likelihood of occurring, ability
of an organisation to recover and developing
the best protective strategies. That said,
do organisations typically - and accurately -
measure the risk to their operations and take
all the necessary steps to prevent/eliminate
that risk? If not, how do they alter their world
view to protect themselves against the kinds
of attacks that are rapidly being scaled up
and growing ever more sophisticated?
"Measuring your overall risk profile is often
hindered by a fragmented security tech stack
that fails to give a unified view into security
posture," says David Koke, head of marketing
at Intruder. "It's difficult to stitch together
a complete picture of your security posture
when your insights come from a variety of
sources. Relying on discrete insights from
different security tools can also have unintended
knock-on effects, creating a false
sense of confidence in controls and distorting
views of risk amongst senior security decision
makers."
It's difficult to say if enough is being done to
control risk, he adds, and this comes down
to a variety of reasons. "The reality is that
every single security team will be in the same
boat when it comes down to their to-do list;
there will always be more things they wish
they could be doing. Security exists on
a spectrum, so the checklist will never be
fully complete."
Controlling risk comes down to how
effectively security teams can balance
priorities, states Koke. "This means knowing
how to divide your attention between issues
like zero-days and critical vulnerabilities
that need urgent attention, and proactive
measures like thinking about attack surface
reduction. Solving these challenges starts with
a unified security platform that provides a
holistic overview of risk across your digital
estate, automates key parts of the exposure
management lifecycle and integrates with the
workflow tools you're already using to remove
friction when human involvement is required."
CHANGING TIMES
In 2025, 82% of threat detections were
malware-free (CrowdStrike, 2026).
Adversaries primarily operated through
valid credentials, trusted identity flows and
legitimate system tools. "They did not need
malware," says Josh Taylor, lead cybersecurity
analyst at Fortra, "because the environment
gave them everything they needed. Business
email compromise and investment fraud,
both executed without malware, accounted
for $7.5 billion in FBI-reported losses [FBI IC3,
2023]. Yet, most risk management frameworks
still assume that attacks involve exploitable
software and detectable payloads."
This is a structural failure in how organisations
model threats, he points out.
"Traditional risk assessment
inventories assets, scores
vulnerabilities by
severity and
prioritises remediation based on what scanners
find. That works when the threat is a known
CVE with a patch available. It does not work
when the threat is a legitimate login from a
compromised credential, a spoofed vendor
invoice routed through a real email platform
or a supply chain partner whose environment
was silently accessed months ago. The adversaries
are not breaking in. They are simply
logging in."
The consequence is a risk view anchored
to the wrong baseline. "Organisations will
invest heavily in perimeter controls and their
endpoint detection, then discover the breach
came through a trusted third party, an employee
who clicked a credential harvesting link
hosted on a legitimate cloud service or an AI
coding tool whose authentication helper
executed arbitrary commands, because no
one assessed it as an attack surface. None of
these threats will trigger a vulnerability scan."
Altering this view requires three shifts, says
Taylor. "Risk assessments must account for
identity-based attack paths with the same
rigor applied to software vulnerabilities; if
82% of intrusions avoid malware, then 82%
of the threat surface is invisible to tools that
look for malicious code. Organisations must
extend risk modelling to the trust relationships
Image courtesy of ????
20
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
risk management
they depend on vendors, SaaS platforms,
supply chain partners and the AI tools
now embedded in development pipelines.
Detection strategies must move from
signature-based approaches that identify
known-bad artifacts to behavioural
approaches that identify anomalous access
patterns. The attacks being scaled tomorrow
will not look like attacks. They look like normal
business operations conducted by the wrong
person."
THE RIGHT CONNECTIONS
Sam Peters, chief product officer, IO, says
effective risk management increasingly
depends on an organisation's ability to take
a connected, enterprise-wide view of risk,
rather than addressing issues in isolated silos.
"In today's digital environment, risks rarely
exist independently. Instead, they overlap
and interact across multiple domains. For
example, information security, AI governance
and data privacy risks are deeply interconnected.
A vulnerability in one area can quickly
cascade into another, making it essential for
organisations to coordinate their efforts and
avoid duplication of controls, processes and
resources."
To achieve this, organisations should ensure
that compliance, legal and senior leadership
teams maintain clear oversight across all
risk domains. "Regular, cross-functional risk
reviews enable better visibility of emerging
threats and will help organisations boost
overall business resilience. This integrated
approach not only improves efficiency,
but also strengthens decision-making
and accountability at every level of the
organisation."
Adopting recognised standards further
supports this cohesive strategy. "Frameworks
such as ISO 27001 for information security,
ISO 27701 for data privacy and ISO 42001
for AI governance provide structured, bestpractice
guidance. When implemented
together, they form a robust Integrated
Management System [IMS] that enables
organisations to manage risk holistically,
rather than in fragmented ways. This alignment
reduces gaps, enhances consistency
and promotes a culture of continuous
improvement."
Industry trends reinforce the value of this
approach, adds Peters. "Findings from our
recent State of Information Security Report
indicate that 76% of organisations have
consolidated or simplified their technology
stack and security tools over the past year to
reduce complexity. Additionally, 80% have
achieved or maintained key cybersecurity
certifications such as ISO 27001 and SOC 2,
demonstrating a strong commitment to
structured risk management and regulatory
compliance.
"Leveraging a dedicated compliance platform
can significantly enhance both proactive
risk management and regulatory alignment.
Such platforms centralise risk data and
streamline reporting, allowing organisations
to respond more effectively to evolving
threats. In combination, these practices help
build resilience, ensuring organisations are
better prepared to navigate an increasingly
complex risk landscape."
GETTING THE MEASURE
Many organisations claim to manage risk,
but few actually measure it, states Roger
Greyling, information security senior
consultant at Xcina Consulting, a division
of Brookcourt Solutions. "Even fewer challenge
the assumptions behind their sense of
security. In an age of automated cyberattacks,
AI-enabled fraud, supply-chain
compromises and operational disruptions,
the greatest risk is not external, but the
belief that yesterday's controls still work."
Conventional risk management relies on
periodic assessments, static risk registers
and qualitative scoring. "This model assumes
threats evolve slowly. They do not. Attackers
iterate daily, automate reconnaissance and
exploit small gaps across interconnected
Josh Taylor, Fortra: there's a structural
failure in the way many organisations
model threats.
Sam Peters, IO: risks rarely exist
independently. Instead, they overlap
and interact across multiple domains.
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
21
risk management
Marcten Eikelder, Kiteworks: altering the
worldview starts with accepting that risk
management must become continuous,
data-aware and AI-literate.
Tuukka Tiainen, Recast: a risk without
an accountable owner and a concrete
treatment plan is just a statement.
systems. A compromised vendor or leaked
credential can cascade into a full operational
outage. In several recent ransomware
incidents in the UK, hospitals were forced to
divert emergency patients, cancel surgery
and revert to paper-based care, not because
clinical systems were directly targeted,
but because supporting IT services were
disrupted. What begins as a small foothold
now routinely escalates into an organisationwide
impact," cautions Greyling.
The problem isn't a lack of frameworks, but
a worldview anchored in compliance, rather
than resilience. "Risk management becomes
a checkbox exercise. Organisations optimise
to pass audits instead of survive disruption.
They measure what is easy including controls,
certifications and policies, instead of what
matters: time to detect, respond, and recover.
Risk thinking must shift from probability to
impact. The question is no longer, 'How likely
is this?' but 'Are we prepared for when we're
wrong, and will we survive?' This perspective
prioritises business continuity over theoretical
scoring, and investment in detection, containment
and recovery over prevention alone."
Organisations that adapt make three critical
mindset shifts, he advises. "First, they assume
compromise. Rather than building impenetrable
walls, they design systems that limit
blast radius, including segmentation, least
privilege and zero trust architectures. Secondly,
they test recovery, not just protection.
Back-ups are verified, incident playbooks
rehearsed and crisis decision-making
practised. Resilience becomes a capability,
not a document. Thirdly, they treat risk as
dynamic. Continuous monitoring, threat
intelligence and red-team testing replace
annual reviews. Risk becomes a living signal,
not a static report."
Sophisticated attacks are scaling, because
defenders remain predictable, he adds.
"Organisations must stop asking whether
they're compliant and start asking whether
they'll survive."
WHERE’S MY DATA?
Risk management, in theory, is straightforward,
says Marc ten Eikelder, senior
director at Kiteworks. "Assess threats,
quantify their likelihood and impact, gauge
the business' capacity to recover and deploy
proportionate defences. In practice, most
organisations are nowhere close. Recent
industry research found that only 33% of
organisations have complete knowledge
of where their data resides. Meaning twothirds
are running risk models against an
incomplete picture of what they're even
protecting. When an organisation can't see
the full attack surface, every risk calculation
carries a built-in margin of error that
compounds silently. A significant share of
organisations still rely on fragmented,
manual processes for compliance evidence,
and a pattern emerges. Risk management
frameworks are often measuring what's
convenient, not what's consequential."
The more urgent problem is that the threat
landscape is evolving faster than most risk
models can accommodate, he continues.
"Threat intelligence data from earlier this year
documents an 89% increase in AI-enabled
adversary attacks and an average eCrime
breakout time of just 29 minutes. A pace
that renders quarterly risk reviews dangerously
out of date. Meanwhile, AI adoption
inside organisations is creating entirely new
risk vectors that traditional frameworks
weren't designed to capture. Shadow AI
has been identified as the top driver of
negligent insider incidents, yet only 13%
of organisations have integrated AI into
their security strategy. Organisations are
simultaneously accelerating AI deployment
and failing to govern the data those AI
systems access. A gap that compliance
frameworks like DORA, NIS 2, and CMMC
2.0 in the defence industrial base are now
explicitly targeting."
Altering the worldview starts with accepting
the fact that risk management must become
continuous, data-aware and AI-literate,
22
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
risk management
Eikelder concludes. "Organisations need
unified visibility across every channel through
which sensitive data moves, whether that be
email, file sharing, APIs, MFT, data forms or,
increasingly, AI agents. Without a compliant
AI approach that enforces granular access
policies, maintains tamper-evident audit trails
and encrypts data throughout its lifecycle,
the risk model itself becomes the risk. The
question isn't whether organisations can
afford to overhaul their approach, it's
whether they can quantify the cost of not
doing so."
PROACTIVE APPROACH
Tuukka Tiainen's information security background
is in unified endpoint management
and cloud technologies. "This world has
always run on best practices,"states the lead
security engineer at Recast. "Most seasoned
professionals default to risk-driven thinking,
looking to information security frameworks
like ISO/IEC 27001:2022, which are built
around identifying and addressing vulnerabilities.
But what happens if you don't
approach risk identification and remediation
proactively? Well, it depends. You might get
lucky and have smooth sailing for years. Or
you might have a security incident and wish
you had tried to identify and treat the risk
before it became a true threat."
The fact is, even the greatest enterprise risk
management programs can't completely
prevent problems from happening, he adds.
"But a well-thought-out risk programme
should be able to tell you which risk to
address first and where to direct your treatment
efforts. Risk management will look very
different for every organisation and it's not
always possible to chart a perfect course. I
would recommend just starting somewhere.
Don't let perfect be the enemy of good."
Threats evolve, systems change weekly
and the same weakness can have different
consequences, depending on context.
"Instead of chasing precision, focus on
consistency and decision usefulness," Tiainen
advises. "Define a shared scoring model for
impact and likelihood. Keep it simple and
leaders will use it. Document assumptions, so
you can revisit them later. Most importantly,
make risk ownership real. A risk without an
accountable owner and a concrete treatment
plan is just a statement.
"In my experience, the effort that matters
most is moving from bottom up to top
down. Bottom-up input from engineering,
IT and security is essential, because it reflects
the reality of systems and controls. But topdown
input from leadership is what aligns
risk work to business priorities."
Organisations that do this well treat the risk
register as a living management tool, he says.
"They refresh it on a regular cadence, update
it after major changes and incidents, and
track risk treatment like any other delivery
work. They also validate assumptions by
exercising the plan: incident response drills,
recovery tests and tabletop scenarios. That
is how risk management keeps up with
sophisticated attacks."
CRITICAL STEPS
"Risk management doesn't start with evaluating
all the threats to an organisation, but
by understanding what is at risk, states Ian
Robinson, chief product officer, Titania.
"What are the most critical assets and which
devices on the network protect them? What
systems are necessary to the business
function? What are the consequences,
if something goes wrong?"
Creating a taxonomy of critical assets is
the vital first step of proactive risk reduction.
"Once this is done, then you can look
outwards at the tactics, techniques and
procedures (TTPs) that are being used
most often by threat actors in your sector.
If, instead, you look across the whole
network and decide to fix every critical issue,
that means spending valuable time fixing
issues an attacker simply isn't interested
in exploiting."
A change in view that needs to happen is
not just the risk of a successful attack, but
the aftermath. "We've seen attacks where
problems have dragged on for months -
assembly lines down, online shopping
disrupted - because the businesses weren't
able to recover quickly," adds Robinson.
"Resilience and recovery are key parts of risk
management. There needs to be a good
understanding of what defines a critical
system. For example, for a manufacturer,
the assembly line is clearly critical and
the IT infrastructure that manages the
line must be high priority. But the IT infrastructure
that manages the supply chain is
just as critical and any attack that disrupts
the supply of materials will halt production
just as effectively as an attack on the
assembly line itself."
Therefore, to accurately understand risk,
you need to understand the consequences
of a successful attack on these systems,
says Robinson. "From this understanding,
organisations can better prioritise their
attention on where they are most vulnerable.
This understanding can also help
organisations make better decisions when
it comes to day-to-day operational details,
such as user permissions, firewall rules,
and network segmentation. Understanding
the risks means this lens can be applied to
understanding if a network is too flat, or if
certain users have more access to systems
than is necessary. By applying network
segmentation and least privilege access
principles, this provides assurances that,
in the case of a breach or a threat gaining
a foothold, the spread is contained and
does not impact identified critical business
functions."
This lens is especially critical when
businesses grow and their systems scale
and become more complex. "Having
visibility of the entire network becomes
more difficult, making prioritisation of
critical systems vital to maintaining
security."
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
23
AI angst
LIVING ON THE EDGE
A SMALL GROUP OF PEOPLE, IT IS CLAIMED, GAINED ACCESS TO ANTHROPIC'S CLAUDE
MYTHOS MODEL - A TOOL SAID TO BE TOO POWERFUL TO RELEASE TO THE PUBLIC
Anthropic is investigating a report of
unauthorised access to the company's
Claude Mythos Preview through one of
its third-party vendor environments. This was
in response to a Bloomberg report that users
in a private forum managed to access the
model without the normal permissions.
There is deep unease about Mythos'
capabilities - though one top cyber official
believes advanced AI tools could be a "net
positive", if the technology was secured from
misuse. There is currently no suggestion that
malicious actors have managed to get hold
of the model and Anthropic says it does not
have evidence its systems are affected,
according to Bloomberg.
Raluca Saceanu, chief executive of cybersecurity
company Smarttech247, is of the
opinion that this was most likely through
misuse of access, rather than a classic hack.
"When powerful AI tools are accessed or used
outside their intended controls, the risk is not
just a security incident, but the spread of
capabilities that could be used for fraud,
cyber abuse or other malicious activity."
Under the banner 'Project Glasswing',
Anthropic has released the Mythos model to
some tech and financial companies, in order
to help them secure their systems against its
reported ability to exploit vulnerabilities. This
is a tightly controlled effort to use Mythos to
help secure critical software before comparable
models become more widely available.
The person already had permission to view
Anthropic's AI models through work they
had done for a third-party contractor,
according to Bloomberg. The outlet also
reported the group has been using the
model since it gained access - although not
for hacking, because they do not want to
be detected.
But that highlights the larger issue at hand,
says Stefanie Schappert, a senior journalist at
Cybernews, namely that "the industry knows
what is coming and is still scrambling to build
that much-needed playbook in time to
defend against larger threats, such as nationstate
or ransomware attackers." And she
adds: "If a group of AI nerds could get into
Mythos - allegedly without malicious intent -
imagine the fallout if the next ones to slide
through that door were actual criminals."
WATERSHED MOMENT
"If the early reporting is right, Mythos could
be a watershed moment," says Brian Fox,
co-founder and CTO, Sonatype. "What is not
new is the reality it is forcing people to
confront. Beneath the AI framing sits the
same software supply chain reality we have
been discussing for years: dependencies,
build pipelines, third-party software and
infrastructure remain the attack surface.
What changed is speed. AI can now find and
operationalise weaknesses across that stack
faster than most organisations can inventory,
prioritise and patch them."
What we are seeing in response to the
Mythos news is many organisations coming
to terms with a reality that has existed for a
long time: they are not actually in control
of their software supply chains, he adds.
"A lot of security programmes looked effective
mostly because the clock was slow. Now
the clock is fast and suddenly everyone gets
to find out whether they built a security
programme or just a very polite waiting room.
The winners won't be the companies with
the flashiest AI narrative. They'll be the ones
with real software intelligence, real policy
enforcement and real control over what
enters the pipeline and gets shipped
downstream."
FREE FALLING
It all adds to a growing sense of unease,
around Anthropic AI and AI in general,
cautions Kara Sprague, CEO of HackerOn,
claiming that the window between
vulnerability discovery and exploitation has
collapsed with advancements in frontier AI
24
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
AI angst
model capabilities. "What used to take
attackers days or weeks to do now happens
in hours and increasingly minutes." To
understand where this goes next, we can
examine two scenarios, she adds:
Scenario 1: "Each advance in frontier models
uncovers a commensurate wave of new
vulnerabilities. No surface is ever truly
hardened and we're in continuous free-fall."
Scenario 2: "Discovery eventually plateaus.
As systems and tooling improve, entire
classes of vulnerabilities get reduced and
we approach a [messy] equilibrium."
"Right now, facing down what some
are calling the 'vulnpocalypse', it feels like
Scenario 1," says Sprague. "Attackers can
already use frontier models to discover
exposures, validate exploitability and chain
attacks faster than most teams can triage
a single critical alert. What Anthropic has
disclosed on Mythos indicates that it further
advances those capabilities multi-fold and
Project Glasswing will give defenders a head
start."
"But zoom out," she adds. "It's true, the raw
state space of modern software is massive;
so large it behaves like it's unbounded. There
will always be new edges to explore. But
vulnerabilities don't emerge randomly from
that space. They cluster into recurring
patterns, such as injection flaws, memory
safety issues, auth gaps and misconfigurations.
And, historically, we've seen entire
classes get systematically reduced through
better languages, frameworks and secure
defaults. AI accelerates both sides, expanding
discovery across that vast state space and
compressing the elimination of vulnerability
classes. "So 'what happens next' won't play
out as simply one scenario, but more like
a phased transition."
Phase 1 (now): explosive discovery, collapsing
exploit timelines
Phase 2: systematic reduction of vulnerability
classes
Phase 3: plateau in which rarer, more
complex, bugs dominate.
"We're currently in Phase 1," she states.
"Which is why Scenario 1 feels true today
and likely will be for several years to come.
But I believe the long-term trajectory looks
much closer to Scenario 2. Here's the catch:
even if discovery plateaus, time-to-exploit
won't. That means the bottleneck for
defenders has shifted permanently. It's
not about finding vulnerabilities; it's about
eliminating exposure before exploitation.
That's the new battleground. And it's why
retooling find-to-fix workflows for speed is
existential."
NEW FRONTIERS
Frontier AI is reshaping how organisations
must think about cyber risk. "Frontier models
are a new class of highly capable AI systems
that can reason across complex tasks, analyse
software, identify vulnerabilities, accelerate
exploit development and support increasingly
sophisticated security workflows," comments
Crowdstrike.
Anthropic's Claude Mythos and OpenAI's
GPT-5.4-Cyber are early examples of this shift,
showing how quickly AI is expanding both
offensive and defensive capability. "As
vulnerabilities are discovered and exploited
on shorter timelines, traditional security
approaches built on periodic assessments,
severity scores and human-paced response
are becoming less effective. Defenders
need a new model centred on exploitability,
continuous validation of exposure, stronger
prevention, cross-domain visibility, decisive
response and governed use of AI."
This shift changes what defenders need to
do. The challenge is no longer just finding
vulnerabilities faster than adversaries. It is
figuring out which weaknesses are truly
exploitable, reducing the conditions that turn
them into real risk and responding as quickly
as attackers can move. "As AI speeds up both
discovery and exploitation, organisations
Kara Sprague, HackerOne: no surface is
ever truly hardened and we're in continuous
free-fall.
Brian Fox, Sonatype: The winners won't be
the companies with the flashiest AI narrative,
but the ones with real software intelligence,
real policy enforcement and real control
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
25
AI angst
Raluca Saceanu, Smarttech247: this was
most likely through misuse of access,
rather than a classic hack.
Darren Williams, BlackFog: rapidity with
which AI tools can attack and infect an
organisation is now at 'wire speed'.
need to move from periodic assessment to
continuous, intelligence-driven exposure
management," adds Crowdstrike, "so they can
determine what really matters, prioritise real
risk and quickly coordinate remediation."
RESILIENCE IS THE KEY
They must also prepare for a surge in
vulnerability discovery and patch activity that
many organisations are not operationally
prepared to absorb. "The goal is no longer
just better hygiene. It is resilience in an
environment where offensive capability is
improving faster than traditional security
programmes were built to handle. Organisations
do not need to wait to improve
readiness. They can act now by tightening
remediation and recovery workflows, running
regular validation exercises, reducing attack
surface and telemetry blind spots and
improving how risk is prioritised."
That means focusing less on severity scores
alone and more on exploitability, business
impact, adversary behaviour and attack
path relevance, Crowdstrike advises. "Most
importantly, leaders should treat this as a
business resilience issue, not just a security
issue, and align security, IT, engineering,
and executive teams around timely decisions,
clearer ownership and tighter coordination."
RESPONSIBLE CALL
Tristan Watkins, director of services innovation
at Advania UK, believes Anthropic is holding
back Mythos from public release "because it's
already surfaced thousands of vulnerabilities
and organisations need time to respond
before wider exposure. That's a genuinely
responsible call, one that requires real
commercial restraint. Meanwhile, Project
Glasswing brings together the world's major
device, cloud and security players to start
hardening systems now, before even more
capable AI arrives from Anthropic or another
vendor. Anthropic is backing the project with
$100 million." Serious, coordinated work.
One detail worth sitting with, he adds, is
that Mythos wasn't trained for cybersecurity.
"It got those capabilities as a byproduct of
coding improvements and better longrunning
execution. Capability doesn't always
come labelled. The larger System Card will
take time to fully digest, but the short version
is this: cybersecurity as a discipline needs to
change immediately and at scale. We've
barely scratched the surface of what's in
there."
OPEN SEASON
With AI moving faster than any technology
before, predictions must be tempered,
says Dr Darren Williams, CEO and founder,
BlackFog. "Even the AI leaders are cautious
about predictions. There is no doubt that AI
has dramatically changed the landscape for
attack vectors and the defence posture of
organisations. If companies have not adopted
some form of protection and monitoring,
especially around Shadow AI and Agentic AI,
it will be open season on these companies.
"The imminent release and delay of Anthropic
Mythos shows clearly that no one is ready
for this sort of exposure of vulnerabilities,
and this has only been exposed to the main
technology vendors. We cannot even imagine
what this is going to uncover in less technical
sectors, specifically those highly targeted ones
like government, healthcare and education."
The rapidity with which these AI tools can
attack and infect an organisation is now at
"wire speed", so any technology that has
hopes of stopping it has to operate real time,
adds Williams. "Having adequate monitoring
of AI use is essential and the lack of visibility
is currently the biggest problem. We need
to first discover what is going on and then
provide oversight, risk and governance over
the use of AI to have any chance of ensuring
responsible use of AI. It is not only about
what individuals are doing with AI, but also
what the fully autonomous Agentic AI tools
like OpenClaw and other tools with embedded
AI are doing, and what data exfiltration is
really going on."
26
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
cryptographic security
QUANTUM OVERKILL
MANAGING CRYPTOGRAPHIC SECURITY CAN CREATE OPERATIONAL OVERLOAD
THAT LEAVES ORGANISATIONS DANGEROUSLY EXPOSED TO THREATS
Managing cryptographic security -
from technology like PKI and
HSMs, to keys, certificates and
secrets, to the compliance layer - can
create an outcome where operational
overload results for enterprises preparing
for quantum computing, according to
Entrust.
That is why the company has partnered
with Ponemon Institute to gather insights
from 4,000 global IT, security and risk
leaders to better understand how organisations
are preparing for post-quantum.
"From shortened certificate lifecycles
to expanding cryptographic sprawl, our
report reveals where readiness is advancing,
where it's falling behind and why
Robert Hann,
Entrust.
crypto-agility is critical for resilience in
the years ahead," it states.
On the matter of certificate lifecycles,
the maximum lifespan of SSL certificates
will be reduced in stages over the next
few years. Validity periods will gradually
become shorter and shorter, with an
eventual target of 47 days by March
2029. Here's the timeline you need to
be aware of, according to managed IT
services company Solsoft:
15 March 2026: maximum validity
of newly issued public certificates was
reduced from 398 days to a maximum
of 200 days
15 March 2027: maximum lifespan
of newly issued public certificates will
be lowered from 200 to 100 days
15 March 2029: lifespan of newly
issued certificates expected to be
reduced again to a maximum of 47
days.
"These changes are being phased
in over a three-year period to avoid
foisting any sudden transitions on
users and make the process more
manageable," says Solsoft. "Nevertheless,
certificates that once lasted for
more than a year will soon need to
be renewed several times annually."
Why is it that the industry has decided
to make this change? "Security is the
major consideration behind the move
to shorter SSL/TLS certificate lifespans.
Shorter validity periods limit the window
in which attackers can exploit a compromised
or mis-issued certificate, or one that
uses cryptography that later becomes
vulnerable. In addition, shorter lifespans
are intended to foster better hygiene
when it comes to certificate management.
This nudges organisations to adopt
more modern approaches, such as
automated issuance and renewal, instead
of relying on long-lived certificates that
can go unchanged for months."
The challenge for organisations
concerns how the shift to shorter validity
periods is handled. "More frequent
renewals mean a higher likelihood of
expired certificates. This can lead to
broken websites, service outages and
failed integrations, which can all cause
customers to lose trust as a knock-on
effect. Even short disruptions can have
real financial and reputational effects."
Robert Hann, global VP of technical
solutions at Entrust, comments: "Shorter
lifecycles will ultimately add unwelcome
pressure to organisations already struggling
to manage cryptographic sprawl,
fragmented ownership and the quantum
safe transformation. This is validated by
just 43% of leaders saying they have
sufficient visibility of their own certificate
estate.
The good news, Hann goes on to say,
s that security standards are evolving to
make things easier. "Default use of ACME
protocols is fast becoming the norm,
helping organisations automate previously
manual verification and installation
processes for certificates.
"The great thing about that is organisations
will be building the crypto-agility
required for the post-quantum era.
Future threats will evolve fast, so automating
early will provide a significant
competitive advantage."
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
27
attacks round-up
IS THE TOP ABOUT TO BLOW?
WITH CYBER-ATTACKS ON THE RISE AND ADVANCED AI TOOLS ACCELERATING THE THREAT, ORGANISATIONS
ARE COMING UNDER EXTREME PRESSURE IN THEIR ATTEMPTS TO KEEP THEIR BUSINESSES SECURE
More than half of UK business leaders
are unprepared for threats posed
by advanced AI-powered cyber
threats, according to new research from
Hornetsecurity by Proofpoint, a leading
cybersecurity firm. A survey of 500 business
leaders from across the UK revealed that,
while cyberattacks have increased for 54%
of the respondents (versus 45% two years
ago), over 50% of companies say they are
uncertain whether they have the expertise to
prevent an AI-powered attack. The findings
also highlight that more than half of UK
business leaders have been victims of a
cyberattack and 79% of respondents said
they think AI has increased the sophistication
of cybersecurity attacks.
Daniel Hofmann, CEO of Hornetsecurity
by Proofpoint, comments: "Cyber-attacks
are on the rise and advanced AI tools are
only accelerating the threat. While 69%
of businesses are integrating AI into their
defences, it's highly concerning that a third
have yet to do so. Now more than ever, it's
critical for businesses to recognise the need
to integrate AI in their own security strategies,
so they can stay ahead of increasingly
sophisticated AI attacks."
Despite AI defence technologies sitting at
the cutting edge of cybersecurity, a critical
adoption gap remains: businesses are not
yet fully leveraging these advanced defences
available to them. Alarmingly, according to
the survey, over a quarter of UK business
leaders (26%) are still not using AI to enhance
their cybersecurity defences. Meanwhile,
cyber-attackers are using the latest AI to their
advantage, effectively lowering the barrier to
entry and driving an increase in sophisticated
attacks.
Hofmann adds: "Alongside working with
trusted vendors and managed service
providers, continuous employee training
helps organisations stay prepared against
evolving threats. AI-powered training can
further enhance this by automating and
personalising the experience, making it more
engaging, efficient and effective. In today's
threat landscape, continuous investment
in new technologies and strengthening
defences is not optional, it's essential."
CHANGING NATURE OF RISK
Meanwhile, Megha Kumar, chief product
officer and head of geopolitical risk, Cyxcel,
has been responding to the recently
announced Global Cybersecurity Outlook
2026 from the World Economic Forum,
calling it a "timely reminder of the changing
nature of risks in cyber space, especially the
impact of rapid deployment and innovation
of AI, geopolitical fragmentation and
vulnerability of supply chains".
She points to how technology supply chains
are globally integrated and the hostile cyber
market also operates from across multiple
national borders. "This requires cross-nation
cooperation, but the response is going in
the opposite direction. Growing geopolitical
division between the United States and
Western democracies, in particular, is
impeding joint defensive action against
cyberattacks and policy harmonisation on
technologies, such as social media and AI."
Kumar describes this geopolitical divergence
as especially problematic in the case of AI.
"Leading AI technologies are being developed
in the United States, but the UK and EU, for
example, favour regulation, whereas the US
federal administration is determined to
prioritise innovation and economic growth.
The UK-US dispute over Grok AI is an example
of that divergence. Both sides appreciate
the social damage caused by the misuse
of AI tools, and recognise this damage will
increase, but what we are seeing is a response
on a case-by-case basis, rather than an
integrated approach."
BIG GAME HUNTING
SonicWall has released its UK cyber threat
data from 2025, revealing that the number
of UK organisations successfully compromised
rose by 20%, even as overall ransomware
volume fell by 87%. SonicWall's data stems
from measuring network-perimeter detections:
threats identified and blocked by
SonicWall firewalls at the point of delivery.
The findings point to a potential move
away from high-volume 'spray-and-pray'
ransomware campaigns towards more
targeted, human-operated 'big game
hunting' attacks that are designed to
maximise impact against fewer victims.
Experts at SonicWall pinpointed the issue
to outdated infrastructure compounding
the problem, fuelling what it describes as
28
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
attacks round-up
a growing 'Zombie Tech' crisis. A single
decade-old vulnerability in widely deployed
Hikvision IP cameras accounted for 67 million
attack attempts in the UK, more than 20%
of all serious intrusion activity observed.
Hikvision is the world's largest CCTV/video
surveillance equipment supplier by revenue
and unit share in recent years.
Says Spencer Starkey, executive VP, EMEA,
SonicWall: "On the surface, the 87% drop
in overall attack volume might look like
progress, but the reality is more alarming.
More organisations are being successfully
hit, and attackers are doing it with far greater
precision."
ALERT FATIGUE
Three-quarters (75%) of UK IT teams say
they've experienced outages as a result
of missing alerts in 2025, according to
research from Splunk. The global State of
Observability 2025 report, which surveyed
1,855 ITOps and engineering professionals,
including 300 in the UK, reveals that alert
fatigue is fast becoming one of the most
pressing challenges to operational resilience.
Alert fatigue is particularly pronounced
in the UK, where over half (54%) of
respondents say false alerts are harming
morale, and 15% admit to deliberately
ignoring or suppressing alerts - higher
than the global average (13%).
UK IT teams point to tool sprawl (61%),
false alerts (54%), and the overall volume
of alerts (34%) as some of the greatest
contributors to their stress. These pressure
points suggest growing frustration within IT
departments, where constant interruptions
are taking a toll and creating an environment
where critical security alerts could be missed.
A lack of clear ownership in incident
response also appears to be compounding
the issue. Just 21% of respondents say they
regularly isolate incidents to a specific team -
a key marker of maturity in incident response
- while 36% admit that they rarely isolate
them. This ambiguity increases the risk that
important security alerts are left unaddressed,
leaving organisations more vulnerable to
attacks and exposing them to avoidable
breaches and downtime.
By bridging silos across teams and
strengthening observability practices,
organisations can help boost resilience
while protecting both their systems and their
people. "IT teams are drowning in noise.
Every day they're hit with alerts, but without
the right context or ownership, it's almost
impossible to know which ones really matter.
This lack of clarity puts a lot of pressure on
teams and slows response times." says Petra
Jenner, SVP & general manager, EMEA,
Splunk. "When critical alerts get lost in that
noise, organisations risk downtime and
customer disruption, which can quickly
translate into revenue loss and lasting
reputational damage.
ACCESS AND RESILIENCE
The estimated 270 million Apple devices
that were targeted by a new hacker tool
called DarkSword stirs up worrying
associations for Kamran Bahdur, chief
information Officer at cybersecurity firm FLR
Spectron. "What this highlights for businesses
is that mobile risk is now an access and
resilience issue, not just a handset issue."
A smartphone may hold access to email,
collaboration platforms, saved credentials,
MFA prompts and cloud services. "Once
that device is compromised, the issue can
move quickly into wider business systems.
The practical response is disciplined mobile
security, including patching, device compliance,
access controls, monitoring, and
a clear incident response path, if a device is
suspected to be compromised."
Kamran also recommends that businesses
protect their systems by making sure devices
are updated quickly and consistently. "Delays
in patching create an opportunity for attack-
Petra Jenner, Splunk: when critical alerts
get lost in the noise, organisations risk
downtime and customer disruption.
Kamran Bahdur, FLR Spectron: mobile risk
is now an access and resilience issue, not
just a handset issue.
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
29
attacks round-up
Iain Wham, Innovec: cyber security
remains a significant business resilience
challenge.
Benny Czarny, OPSWAT: organisations
should treat every file entering their
systems as untrusted until verified as
safe.
ers, especially when threats are designed to
move fast. It also means improving visibility
across organisations' device estates, so that
businesses have clear visibility as to which
devices can access company data, whether
they are compliant and where risks exist.
"Most importantly, businesses need layered
protection that reduces exposure and supports
continuity when new threats emerge,"
he cautions. "That includes 24/7 monitoring,
threat detection and incident response, endpoint
protection and policies that protect
access to business system,s in the event
a device is compromised."
CRITICAL BREACH FEARS
One in eight small businesses have experienced
a cyber-attack and more than half fear
they would be vulnerable to a critical data
breach in the future, according to a new
study The survey of 500 businesses found
that, while many small-and-medium sized
enterprises (SMEs) have implemented basic
cyber security measures, critical gaps remain
in training, incident response planning and
strategic preparedness that could prove
catastrophic in the event of a serious breach.
Most respondees said they lacked the
resilience to withstand a prolonged operational
shutdown, fewer than one in ten
provide regular cyber security awareness
training for staff and less than a third have
invested more in cyber security in the past
two years.
Of the businesses that responded, 12.5%
said they had experienced a cyber security
breach in the past. Incidents included
ransomware attacks, compromised email
leading to financial loss (phishing), theft of
customer and employee data and denial-ofservice
attacks. A greater number said they
felt their company was vulnerable to a future
attack, with most indicating they would face
critical financial pressure. if they had to close
operations. One in eight respondents said
their company would be unable to survive
a complete shutdown lasting 48 hours or
more, while almost a third estimated their
maximum survival window in such
circumstances would be three to seven days.
Iain Wham, managing director of Innovec,
said the findings served as a reminder that
cyber security remains a significant business
resilience challenge to a large proportion
of the UK's SME community.
"As threats continue to evolve, and attackers
increasingly target smaller businesses as
entry points into larger supply chains, the
need to act has never been greater. The
question for SMEs and business support
organisations is whether current levels of
awareness, investment, and preparedness
are sufficient to combat the next, inevitable
wave of attacks."
UPSIDE DOWN, INSIDE OUT
In his newly released book 'Cybersecurity
Upside Down, OPSWAT founder Benny
Czarny is calling on organisations to rethink
their cybersecurity strategies. The book
tackles long-standing assumptions about
defending against cyber threats and seeks
to educate readers on the importance of
a prevention-first mindset, he says.
Czarny argues that many modern
cyberattacks succeed because security
strategies focus on detecting threats after
they enter a system. AI is adding to the
challenge, as threats are evolving faster than
traditional detection tools can keep pace. In
'Cybersecurity Upside Down', he argues that
cybersecurity should be approached based
on the principle that organisations should
treat every file entering their systems as
untrusted until verified as safe.
"For years the cybersecurity industry tried to
achieve prevention through detection, which
worked for a time," he adds. "But that model
is broken. Attackers can now generate new
threats faster than we can detect them and
AI is accelerating the problem."
30
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
AI insights
YEAR OF LIVING DANGEROUSLY
CONTINUED FROM PAGE 13
Speculation abounds about what AI
will do and - more specifically - which
industries and disciplines it will kill off,
notes Neil Roseman, CEO, Invicti. "Most
recently, the announcement of Claude Code
has prompted speculation that LLMs [Large
Language Models] of this kind might get
rid of AppSec entirely. LLMs like these will
supposedly check code to find vulnerabilities,
then challenge their own code review to
delimit false positives. They will then be able
to devise fixes and issue patches."
Neil Roseman.
Simon Hunt.
That might seem game-changing, he says,
but the reality will be far more nuanced. "In
reality, LLMs are unlikely to replace humans
and their tools, but they will change the way
we do AppSec. First, announcements and
product demos are not security tools. LLMs
can do some security analysis and work with
code rather well, but an AppSec tool needs
to be able to work reliably in constantlychanging
environments to produce repeatable,
trustworthy results. Currently, LLMs
cannot do this at the scale or cost required
to accommodate real AppSec needs for
businesses. Recent work - for example, this
recent post by Dawn Song at Berkeley - cast
doubt on the ability to assess these systems
for accuracy at all, which will again limit
their utility.
"Moreover, while automated detection and
remediation will be useful, checking source
code for bugs is only one part of AppSec.
Indeed, modern threats aren't explicitly
targeting source code - they're attacking
weaknesses in misconfigured environments
and running applications."
LLMs cannot yet validate vulnerabilities in
runtime or understand the nuances of a
complex environment, Roseman points out.
"Yet that's exactly what's required for effective
AppSec: a strategic perspective that shows
how vulnerabilities behave when deployed
and affect overall organisational risk. That
part of AppSec will remain solidly in the
hands of human experts and their tools.
And a trend we are already seeing is an
increase in potentially exploitable defects
as more semi-skilled developers deploy AI
generated code they don't fully understand.
"In fact, as other parts of AppSec are
automated, validating those vulnerabilities
within live applications will become the
central AppSec concern. The same goes for
LLMs' fixes, which will have to be independently
verified to ensure they address a
vulnerability's root cause, don't introduce
further security issues and deploy safely."
ESSENTIAL ROLE
Simon Hunt, who is chief product officer at
Securonix, points to how AI is becoming part
of how modern security operations function.
"It helps streamline triage, adds context to
detections and supports faster decisions
across environments that are only getting
more complex. Most security leaders already
see AI-driven automation as essential to how
their teams operate. At the same time, there
is a gap between capability and confidence."
AI can do more, he adds, but trust in the
outcomes has not kept pace. That gap will
define the next phase of adoption. "The
question is not how much AI can do. It is
how confidently teams can rely on it when
decisions matter. That is why design matters.
Systems need to be transparent, explainable
and grounded in policy. Human-in-the-loop
models are critical, not as a constraint, but
as a way to ensure that speed does not come
at the cost of control."
From a defensive standpoint, AI will
continue to act as a force multiplier, states
Hunt. "It helps teams manage alert volume,
reduce manual effort and operate more
effectively with limited resources. But attackers
are using the same capabilities to scale
reconnaissance, accelerate development and
bypass controls. Speed and adaptability are
becoming the deciding factors on both
sides."
Keeping AI from drifting out of bounds will
come down to discipline. "Strong guardrails,
clear accountability and well-defined decision
logic need to be built into the system from
the start. The checks an experienced analyst
would apply cannot disappear. They need to
be encoded and enforced."
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
31
cybercrime
CRIME PAYS… AND PAYS
GLOBAL CYBERCRIME DAMAGE IS PROJECTED TO COST MORE THAN $12 USD
TRILLION ANNUALLY BY 2031. HOW CAN THAT PROFLIGATE WASTE BE HALTED?
Global cybercrime damage is projected
to cost more than $12 USD trillion
annually by 2031, according to
Cybersecurity Ventures. In the face of such
a threat, how do organisations evolve at
the highest levels to become capable of
understanding context, detecting intent and
predicting threats? And who within those
organisations should be driving the changes
needed to get there - and how is that to be
achieved to best effect?
In response, Peter Smails, SVP, general
manager, cloud native, SUSE, says
organisations can't afford incremental
improvements; they need a fundamental
shift in how they secure cloud environments.
"Modern infrastructure is dynamic, distributed
and API driven. Workloads spin up and
down in seconds. Identities outnumber
humans and attackers increasingly exploit
misconfigurations, over permissioned roles
and exposed control planes, rather than
traditional network perimeters."
To understand context, detect intent and
predict threats, organisations must move
toward a continuous, cloud native security
operating model, he insists. "That starts
with unifying telemetry across identities,
workloads, clusters and services, so signals
aren't analysed in isolation. Threats in the
cloud rarely look like 'events'; they look like
subtle deviations in behaviour, privilege or
configuration. Only correlated, real time
context can surface intent early enough
to act."
"Who drives this evolution? "It requires
CISOs, CTOs and platform engineering leaders
working as co owners of the cloud operating
model," states Smails. "Security can't sit on
the outside of delivery anymore. It has to be
embedded into the platform: policy driven,
automated and enforced through the same
pipelines that ship code. Identity becomes
the control plane. Automation becomes the
default. Drift becomes observable and
correctable.
"Boards also have a critical role. Cloud risk is
now business continuity risk. When attackers
target identity providers, SaaS admins and
cloud backups, resilience becomes a strategic
priority, not just a technical one. The organisations
that succeed won't be the ones
with the most tools. They'll be the ones with
a cloud native security model capable of
understanding context, inferring intent and
predicting threats before they materialise."
"
TRUST UNDERMINED
Despite the billions invested in cybersecurity
across the world, breaches still dominate the
headlines, comments Dave Silke, managing
director, EMEA & APAC Centripetal. "And
when they happen, the impact is deeply felt,
not just by systems and balance sheets, but by
people, teams and the impact on everyone's
trust. Breaches at organisations like Marks
& Spencer and Jaguar Land Rover are not
outliers; they reflect a familiar pattern.
Security models are built to react, rather than
anticipate. Overstretched teams are doing
their best within constraints, but there is a
quiet acceptance that breaches are simply
part of modern life. That belief sits at the
heart of the problem."
Boards approve budgets with compromise
assumed. CISOs plan around detection and
response, and SOCs are left carrying the
weight when things go wrong. "Over time,
this creates a sense of inertia, a feeling across
CISOs and IT teams that there is little more we
can do. Everywhere, we are reminded of the
when, not the if, of a cyber breach. Success is
measured by the speed of response, rather
than the calm confidence of prevention."
But adding more tools to an already crowded
stack doesn't change this trajectory, says Silke.
"Today's SOCs are overwhelmed by tens of
thousands of alerts each day, many of which
are false. Even AI, for all its promise, is often
applied simply to optimise an unsustainable
system, rather than to reimagine it. To evolve,
organisations must reconnect with proactive
intelligence. Proactive threat intelligence has
32
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
cybercrime
long been relied upon by governments and
defence communities, and offers a fundamentally
different mindset. By identifying
and blocking known bad activity before it
ever reaches the stack, we reduce noise,
restore focus and give teams space to think,
not just react.
Most cyberattacks are not new. "They are
old threats, repeated and amplified through
automation and scale. That makes them
predictable, and crucially, preventable when
intelligence is applied with intent. When
known bad traffic is stopped upstream,
alert volumes fall dramatically, lifting the
fog of fatigue that clouds today's SOCs."
This is an invitation for CISOs to pause,
reflect, and challenge familiar assumptions.
To look beyond traditional metrics. And to
rebalance investment away from constant
reaction, towards intelligence led capabilities
that return a sense of control. Ransomware
does not have to remain a cost of doing
business, and the future doesn't have to
feel this reactive."
KEY SHIFTS
To address the damage threat, organisations
need to constantly evolve, comments Mihai
Popa, chief information security officer,
Bridgeworks. "This requires the capability to
understand context, detect intent and predict
threats. In fact, organisations need to move
beyond reactive security models to adopt
a context-drive, intelligence-led approach."
This means correlating data across networks,
endpoints and cloud environments to build
a real-time understanding of behaviour -
not just events. "At the highest level, this
evolution requires three key shifts: from
siloed visibility to unified observability across
hybrid and multi-cloud environments; from
signature-based detection to behavioural
analytics and AI-driven insights; and from
perimeter defence to data-centric security."
Equally important, add Popa, "is the ability
to securely move and analyse data at speed.
If organisations cannot efficiently transport
large datasets between environments, their
ability to detect patterns and predict threats
is severely constrained. This is where WAN
performance and security converge - enabling
fast, secure data movement ensures that
threat intelligence is both timely and
actionable".
BOARD-LEVEL IMPETUS
He continues: "Transformation must be
board-level driven, with accountability sitting
across the CISO for security, risk and governance;
the CTO and CIO for architecture and
technology enablement; and the CEO, as well
as the board for prioritisation, investment
and organisational culture. This is because
cybersecurity is no longer an IT issue; it is
a business risk issue."
Cloud security, networking and infrastructure
teams must operate as a single, aligned
function, particularly in cloud environments
where performance and security are tightly
interdependent. "This requires a layered,
integrated approach that involves zero trust
architectures, encryption in transit and at rest,
cloud native security tools, such as CSPM,
CWPP workload protection, advanced threat
detection that leverage artificial intelligence
and machine learning for anomaly detection."
Security tools are only effective, if they can
inspect, analyse and act on data promptly.
Poor network performance creates blind
spots. "With WAN Acceleration, organisations
enhance cloud security by reducing exposure
windows, improving backup and recovery
times, while enabling faster forensic analysis,"
Popa states.
"WAN Acceleration plays a critical - and often
underestimated - role in cloud security.
Deploying it mitigates WAN latency and
packet loss - expediting encrypted data
transfers without compromising on cloud
security controls, so that organisations can
detect cloud threats sooner, respond faster
and recover more effectively."
David Silke, Centripetal: CISOs plan
around detection and response; and
SOCs are left carrying the weight when
things go wrong.
Mihai Popa, Bridgeworks: transformation
must be board-level driven, with
accountability sitting across the CISO
for security, risk and governance.
www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security
33
operational failures
SEVEN DEADLY SINS
A NEW THREAT REPORT REVEALS A LANDSCAPE THAT'S GROWING MORE PRECISE AND RELENTLESS
WITH HIGH AND MEDIUM SEVERITY ATTACKS SURGING BY 20.8% TO 13 BILLION-PLUS HITS
Most SMBs aren't losing ground to
sophisticated attacks: they're losing
ground to seven predictable, preventable
gaps that SonicWall has named the
'Seven Deadly Sins of Cybersecurity'.
The SonicWall 2026 Cyber Protect Report,
says the company, signals "a landmark
reframing from traditional threat reporting,
in favour of the protection outcomes that
matter most to business leaders".
The 2026 report again draws on data from
SonicWall's global network of more than
one million security sensors to reveal a
threat landscape that is growing more
Michael Crean,
SonicWall.
precise and more relentless, it states.
Statistical findings include:
High and medium severity attacks surged
20.8% to 13+ billion hits. Attackers
aren't just striking more often, they're
striking smarter
Automated bots now generate more
than 36,000 vulnerability scans per
second, accounting for more than half
of all internet traffic. Bad bot traffic
alone has surged to 37% of all global
internet traffic
IoT attacks climbed 11% to 610 million
hits; Log4j alone generated 824.9
million IPS (intrusion prevention system)
hits in 2025, four years after disclosure.
"SonicWall data reveals attacks are getting
faster and, in some instances, they're getting
a little more sophisticated," says Michael
Crean, SVP and GM of Managed Security
Services at SonicWall. "But the vast majority
of the attacks that we're seeing and investigating
are basic fundamentals that continue
to be missed. The danger isn't that AI isn't
working; it's that we're using it as an excuse
not to do the things we already know we
should."
SEVEN DEADLY SINS
Rather than attributing breach risk to exotic
or emerging attack methods, the 2026
Protect Report identifies seven operational
failures that appear repeatedly across
investigations and that remain largely
preventable:
1. Ignoring the Fundamentals: Weak
authentication, unpatched systems
and excessive admin privileges remain
the primary attack surface
2. False Confidence: Believing you're too
small to be targeted, overestimating
control effectiveness and assuming
resilience without testing it create
dangerous blind spots
3. Overexposed Access: Overly permissive
rules, flat networks and implicit trust
after authentication give attackers
an unobstructed path once inside
4. Reactive Security Posture: Without
24/7 monitoring and proactive threat
hunting, attackers set the timeline.
The average breach goes undetected
for 181 days
5. Cost-Driven Security Decisions: Deferring
investment based on short-term budget
pressure creates costs that arrive later,
with interest. A single SMB breach can
exceed $4.91 million when downtime
and recovery are included
6. Reliance on Legacy Access Models: VPNs
that authenticate once and grant broad
network access remain a highly exploited
entry points in enterprise security. VPN
CVEs grew 82.5% over the analysed
period
7. Chasing Hype Over Execution: Buying
the latest tools without deploying them
completely and expecting technology to
compensate for process gaps is its own
form of vulnerability. Tools don't create
outcomes, execution does.
"The organisations that suffer the most are
not failing because of sophisticated attacks;
they're failing because of predictable, preventable
gaps," Crean continues. "SMBs
are the backbone of the US economy,
representing 99% of all US businesses and
nearly half of private sector employment.
Protecting them protects entire communities.
That's why this report is designed
around protection outcomes, not just
threat statistics."
34
computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk
Computing
Security
Secure systems, secure data, secure people, secure business
Product Review Service
VENDORS – HAS YOUR SOLUTION BEEN
REVIEWED BY COMPUTING SECURITY YET?
The Computing Security review service has been praised by vendors and
readers alike. Each solution is tested by an independent expert whose findings
are published in the magazine along with a photo or screenshot.
Hardware, software and services can all be reviewed.
Many vendors organise a review to coincide with a new launch. However,
please don’t feel that the service is reserved exclusively for new solutions.
A review can also be a good way of introducing an established solution to
a new audience. Are the readers of Computing Security as familiar with
your solution(s) as you would like them to be?
Contact Edward O’Connor on 01689 616000 or email
edward.oconnor@btc.co.uk to make it happen.
ACCORDING TO JAMF 2024:
Security
Trends Report
39 % of
organisations
had at least one device
with known vulnerabilities
40 % of
mobile users
were running a device
with known vulnerabilities
9 % of
users fell for
a phishing attack
Manage and Secure
Apple at work
With Jamf Trusted Access, you ensure
that only authorised users, on enrolled
devices that are secure and compliant,
can access sensitive data.
REQUEST
Y O U R
FREE
T R I A L
TODAY
www.jamf.com