04.06.2026 Views

CS2605

  • No tags were found...

Transform your PDFs into Flipbooks and boost your revenue!

Leverage SEO-optimized Flipbooks, powerful backlinks, and multimedia content to professionally showcase your products and significantly increase your reach.

Computing

Security

Secure systems, secure data, secure people, secure business

THE CHASE IS ON

AI is already in full pursuit of

becoming an irresistible force

NEWS

OPINION

INDUSTRY

COMMENT

CASE STUDIES

PRODUCT REVIEWS

FREE FALLING

Is AI Anthropic setting

us on a rocky path or a

force for future comfort?

ONE FALSE STEP...

Failure to embrace risk

management properly

can have devastating

consequences

THE HEAT IS ON

Advanced AI tools have the

power to blow the lid off

cybersecurity’s best efforts

Computing Security May/June 2026


Privacy-First AI Protects

If email isn’t private,

it’s not secure

Libraesva’s privacy-first AI analyses all messages locally in your environment, so no

content is ever sent to third-party clouds or external services.

Layered security defends your business against spam, malware, phishing, email

fraud, spoofing, zero-day threats, account takeover, social engineering, business

email compromise, inadvertent disclosure of sensitive information and more.

Test your security for FREE with our Email Security Tester

emailsecuritytester.com

libraesva.com


comment

DEEPFAKE ANXIETIES GROW

Daniel Spicer, Ivanti.

UK CEOs are dangerously unprepared

for the deepfake era.

That is the major finding of research

carried out by Ivanti. Its 2026 State of

Cybersecurity Report: Bridging the Divide

report draws on insights from more than

1,200 cybersecurity professionals

worldwide to reveal a rapidly widening

divide between escalating cyberthreats and

the ability of organisations to defend

against them.

AI is reshaping cybersecurity for both

defenders and attackers, but - on the plus

side - defenders believe they are gaining

the edge. Indeed, the report finds that

security professionals are 2.7x more likely

to believe defenders use AI as effectively as threat actors, if not more so. That

confidence level grows to 7.3x in favour of defenders using AI as effectively or more

effectively than threat actors over the next 24 months.

But here's the rub. Says Daniel Spicer, chief security officer at Ivanti: "Although

defenders are optimistic about the promise of AI in cybersecurity, Ivanti's findings also

show companies are falling further behind, in terms of how well prepared they are to

defend against a variety of threats. This is what I call the 'Cybersecurity Readiness Deficit'

- a persistent, year-over-year widening imbalance in an organisation's ability to defend

their data, people and networks against the evolving threat landscape. This challenge is

intensified by the accelerating pace of technological change, particularly as

organisations advance their SaaS transformation initiatives and the speed at which new

technologies are adopted."

What the findings make clear is the urgency for better defence strategies - with this

pitted against the ongoing struggle that organisations now face in balancing risk

awareness against effective preparation. The fear is that the gap between these will

widen as deep fakes and AI increase their stranglehold.

We have always lived in uncertain times, as far as cybersecurity is concerned. The

challenge we now face is that this 'uncertainty' may be hardening and reshaping into

something much more menacing.

Brian Wall

Editor

Computing Security

brian.wall@btc.co.uk

EDITOR: Brian Wall

(brian.wall@btc.co.uk)

LAYOUT/DESIGN: Ian Collis

(ian.collis@btc.co.uk)

SALES:

Edward O’Connor

(edward.oconnor@btc.co.uk)

+ 44 (0)1883 38 00 54

+ 44 (0)1689 616 000

David Bonner

(dave.bonner@btc.co.uk)

+ 44 (0)1883 38 00 54

+ 44 (0)1689 616 000

Stuart Leigh

(stuart.leigh@btc.co.uk)

+ 44 (0)1883 38 00 54

+ 44 (0)1689 616 000

Fraser Owen

(fraser.owen@btc.co.uk)

+ 44 (0)1883 38 00 54

+ 44 (0)1689 616 000

PUBLISHER: John Jageurs

(john.jageurs@btc.co.uk)

Published by Barrow & Thompkins

Connexions Ltd. (BTC)

Suite 2, 157 Station Road East

Oxted. RH8 0QE

Tel: +44 (0)1689 616 000

Fax: +44 (0)1689 82 66 22

SUBSCRIPTIONS:

UK: £35/year, £60/two years,

£80/three years;

Europe: £48/year, £85/two years,

£127/three years

R.O.W:£62/year, £115/two years,

£168/three years

Single copies can be bought for

£8.50 (includes postage & packaging).

Published 6 times a year.

© 2026 Barrow & Thompkins

Connexions Ltd. All rights reserved.

No part of the magazine may be

reproduced without prior consent,

in writing, from the publisher.

www.computingsecurity.co.uk May/June 2026 computing security

@CSMagAndAwards

3


Secure systems, secure data, secure people, secure business

Computing Security May/June 2026

inside this issue

CONTENTS

Computing

Security

NEWS

OPINION

INDUSTRY

COMMENT

CASE STUDIES

PRODUCT REVIEWS

THE CHASE IS ON

FREE FALLING

AI is already in full pursuit of

Is AI Anthropic setting

us on a rocky path or a

becoming an irresistible force

force for future comfort?

ONE FALSE STEP...

Failure to embrace risk

management properly

can have devastating

consequences

COMMENT 3

Deepfake anxieties grow

THE HEAT IS ON

Advanced AI tools have the

power to blow the lid off

cybersecurity’s best efforts

NEWS 6

Product integration phase completed

Agentic AI and the path to resilience

Regulation and AI reshaping risk

Deep dive into AI partner ecosystem

Adopting Agentic AI is 'a priority'

Kiteworks and Kasm enter alliance

ARTICLES

QUANTUM QUANDRY 14

A programme worth up to £2 billion is

being invested in quantum computing

innovation - but is it too little, too late?

YEAR OF LIVING DANGEROUSLY 10

Is AI already hurtling down the path that

will see it become an irresistible force,

its power and influence accelerating at

a speed few might have scarcely imagined

a short time ago? And, if such is the case,

how are we to keep AI from spinning

totally out of control?

TRUST LEFT IN TATTERS 16

RISK'S ROCKY ROAD 20

Users are suffering from email fatigue as

cybercriminals wear down their defences.

Do organisations accurately measure the risks

How can they fight back?

to their operations and take all the necessary

steps to prevent/eliminate these? If not, how

QUANTUM OVERKILL 27

do they alter their world view,so as to protect

Managing cryptographic security without

themselves against the kinds of attacks that

the highest levels of oversight can create

are rapidly being scaled up and growing ever

operational overload that leaves many

more sophisticated?

organisations dangerously exposed

CLOSING IN FOR THE KILL? 31

Speculation abounds about what AI might

do next and - more specifically - which

LIVING ON THE EDGE 24

industries and disciplines it could kill off

After recent high-profile happenings, there

CRIME PAYS… AND PAYS 32

is deep and growing unease about Mythos'

Global cybercrime damage is projected to

capabilities - though one top cyber official

cost more than $12 USD trillion annually

believes advanced AI tools could be a "net

by 2031. Can that be halted?

positive", if the technology was secured

from misuse. How big an 'If' is that?

SEVEN DEADLY SINS 34

Seven operational failures that appear

repeatedly across investigations remain

largely preventable, it is claimed

IS THE TOP ABOUT TO BLOW? 28

A survey of 500 business leaders from across

EVENTS

the UK has revealed that, while cyberattacks

WHO DARES WINS AT INFOSEC 18

have increased for 54% of the respondents

From 'SAS: Who Dares Wins' star Jason Fox

(versus 45% two years ago), over 50% of

to England Rugby World Cup winner Maggie

companies say they are uncertain whether

Alphonsi, this year's Infosec will have a host

they have the expertise to prevent an AIpowered

attack.

of top speakers to inspire attendees

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk

4



news...news...news

Spencer Starkey.

PRODUCT INTEGRATION PHASE COMPLETED

Jon Connet.

Wireless management platforms, security services and

connected vehicle programs company Aeris has

completed its product integration with Palo Alto Networks

Prisma SASE 5G.

The move combines Aeris IoT Watchtower with Prisma

SASE 5G to "transform how enterprises protect wireless IoT

deployments, providing a single point of control to extend

security to the wireless IoT edge". States Jon Connet,

chief product officer of Aeris: "This partnership enables

organisations to apply best-in-class security uniformly across

both IT systems and wireless connected devices, while

empowering Aeris' ecosystem of nearly 30 strategic mobile

network operator partners to leverage the global trust and

proven track record of one of the world's largest cybersecurity providers."

AT THE SPEED OF MIGHT

Threat actors are moving on average

four times faster than just a year

ago, by using AI to speed up and scale

cyber-attacks. That is the alarming

statistic from a report released by

Palo Alto. "In the most efficient attacks,

groups exfiltrate data just 72 minutes

after initial access," the company says.

Commenting on finding, Spencer

Starkey, executive VP at SonicWall, said:

"After 2025, the worst year on record

for cyber incidents, we know that in

2026 it will be even more severe. Particularly

with AI-enabled attacks accelerating

both the scale and sophistication

of threats.

"Organisations that remain dependent

on manual processes or legacy detection

models will struggle to maintain any

meaningful perimeter. The defining

security trend of 2026 will be the emergence

of continuous, AI-versus-AI conflict:

autonomous defensive models battling

autonomously evolving threats in real

time," he states.

AGENTIC AI AND THE PATH TO RESILIENCE

The CISO Report: From Risk to Resilience in the AI Era', which surveys 650 global chief

information security officers (CISOs), has been released. This, Splunk's annual report,

highlights CISOs' rapidly expanding role, their strategic approach to AI adoption and a

steadfast commitment to human talent, as they confront an increasingly complex landscape.

"CISOs operate in the eye of the storm, at the center of constant transformation.

Role responsibilities expand, threats evolve, and AI accelerates everything," says Michael

Fanning, CISO, Splunk. "This expanded mandate brings an exceptional level of pressure

and personal accountability.

"We are not just managing technology. We are managing risk, talent and the digital

resilience that drives critical business outcomes."

REGULATION AND AI RESHAPING MOBILE SECURITY RISK

Zimperium has released new analysis outlining how

regulatory changes and advances in artificial intelligence are

transforming the mobile threat landscape and creating new

challenges for enterprises. "Mobile security is entering a new

phase where both policy and technology are reshaping risk,"

said Krishna Vishnubhotla, vice president of Product Strategy at

Zimperium. "Organisations are shipping mobile software faster

than ever, while attackers are using AI to accelerate exploitation.

Security must evolve just as quickly."

Mobile devices and applications now represent one of the

largest attack surfaces in the enterprise. As cybercriminals adopt

a mobile-first attack strategy, the combination of new

regulatory policies and AI-driven development is accelerating

how mobile apps are built, distributed, and targeted by

attackers.

Krishna Vishnubhotla.

6

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


Layers aren’t just for cakes; they’re

essential in cybersecurity’s secret

recipe for protection!

Bake it happen with VIPRE Security Group. Secure your

bytes before you take a bite with Email Security, Endpoint

Security and User Protection

www.vipre.com


news...news...news

David Byrnes.

ADVANTECH GOES DEEP INTO AI PARTNER ECOSYSTEM

Advantech is partnering with

DEEPX, a leading Korean AI

ADV716 Advantech-DEEPX.

semiconductor innovator specialising

in NPU (Neural Processing Unit)

technology. The collaboration

expands Advantech's AI chipset

ecosystem and introduces the

company's first AI acceleration

solution powered by DEEPX

technology, the EAI-1961 series

Edge AI Acceleration Module.

"Advantech evaluates a broad range

of AI chip technologies to address

diverse industrial needs," says Joey Hsu, director of Advantech's Embedded Sector. "DEEPX

demonstrates commendable efficiency in power and thermal performance, which is essential

for reliable edge AI deployment.

KITEWORKS AND KASM ENTER

TECHNOLOGY ALLIANCE

Kiteworks has entered into a new

technology alliance with Kasm,

aimed at enhancing how organisations

securely interact with sensitive data.

"Organisations today face an escalating

challenge with sensitive data flows

across dozens of channels, systems and

partners with fragmented visibility and

inconsistent controls," says David Byrnes,

VP Global Channels, Kiteworks. "Every

file shared via email, file-sharing, SFTP,

managed file transfer, API or data form

represents potential exposure. Security

teams struggle with disparate logging

systems, compliance officers cannot

prove governance end to end and IT

administrators manage a patchwork

of point solutions that expand the

attack surface.

"At the same time, adversaries are

growing more sophisticated, regulatory

requirements are intensifying and the

emergence of AI is creating entirely

new data governance challenges that

existing approaches were never

designed to address."

IN THE ZONE

Infosecurity Europe, running from 2-4 June 2026 at

Excel London (see page 18), has announced the

renewal and expansion of its dedicated Channel Zone,

designed to connect vendors, MSPs, MSSPs,

distributors, resellers and integrators at a time when

partner resilience has become a board-level concern.

States Rob Tomlin, VP, Northern Europe, Exclusive

Networks: "Our channel community needs dedicated

environments, where vendors, MSPs, MSSPs and

resellers can engage commercially, share insight

and align around the technologies and services that

organisations increasingly depend on. It's a welcome

addition to see Infosecurity Europe create such space

with The Channel Zone."

ADOPTING AGENTIC AI IS 'A PRIORITY'

Ivanti's '2026 State of Cybersecurity Report: Bridging the Divide' reveals a rapidly

widening divide between escalating cyberthreats and organisations' ability to defend

against them. Drawing on insights from more than 1,200 cybersecurity professionals

worldwide, the report reveals a rapidly widening divide between escalating cyber threats

and organisations' ability to defend against them.

"Although defenders are optimistic about the promise of AI in cybersecurity, Ivanti's

findings also show companies are falling further behind in terms of how well prepared

they are to defend against a variety of threats," comments Daniel Spicer, chief security

officer at Ivanti.

8

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk



artificial intelligence

YEAR OF LIVING DANGEROUSLY

BY THE END OF 2026, WHAT WILL AI LOOK LIKE - AND WHAT IMPACT WILL IT BE MAKING BY THEN ON

CYBERSECURITY AND THOSE SEEKING TO ENFORCE IT? COMPUTING SECURITY FINDS OUT

Jay Kaplan, Synack: organisations that come

out intact will have invested in security

programmes that move as fast as threats do.

Is AI already hurtling down the path that

will see it become an irresistible force, its

power and influence accelerating at a

speed few might have scarcely imagined a

short time ago? And, if such is the case, how

are we to keep AI from spinning totally out of

control? With the genie seemingly now out

of the bottle, we've been seeking opinion

from across the industry on this.

"By the end of 2026, the organisations that

come out intact will be the ones who invested

in security programmes that move as fast as

threats do," says Jay Kaplan, CEO and cofounder

of Synack. "Continuous adversarial

testing with humans in the loop has been the

right model for a long time. The

advancement of AI-enabled adversaries will

soon make it the only model. Here's what's

actually changing. AI is compressing the

timeline between exposure and exploitation

in ways that fundamentally break the

assumptions most security programmes are

built on. Anthropic's Mythos (see page 24)

makes this concrete - the model fully

autonomously identified and exploited a 17-

year-old remote code execution vulnerability

in FreeBSD, and separately chained four

vulnerabilities together to escape both

browser renderer and OS sandboxes. These

are documented capabilities and they're only

going to improve.

"Security programmes built around periodic

assessments and static playbooks are

operating on a different clock than their

adversaries. An annual penetration test tells

you what your environment looked like at a

single moment in time. That's not useful

intelligence when the threat landscape is

shifting daily. The data you need to stay

ahead has to be continuous and it has to

reflect how attackers are actually operating."

The human element matters here, adds

Kaplan. "AI scales the reconnaissance, surfaces

the attack paths and runs continuously

without fatigue. But human researchers bring

the contextual judgment that determines

what actually matters - the logic flaw that

automated tools miss, the chain of

vulnerabilities that looks low-risk in isolation,

but becomes critical when combined. That

combination is what makes continuous

adversarial testing the right answer for this

moment."

EMBEDDED EVERYWHERE

For Abba Abbaszadi. chief AI officer, MTI

Technology, the situation is all too clear. "By

the end of 2026, AI will not just be another

technology organisations need to secure. It

will be the least understood, and least

controlled, part of the enterprise attack

surface. That shift has happened faster than

10

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


artificial intelligence

most predicted. A year ago, organisations

were still defining AI strategies. Today, AI is

embedded across workflows, applications

and decision-making processes - often

without security teams having full visibility of

where or how it is being used."

For threat actors, AI has removed friction

entirely, he says. "Phishing can now be

generated, personalised and deployed at

scale in seconds. Deepfakes are convincing

enough to bypass human trust controls.

More importantly, AI is now being used to

identify vulnerabilities and automate

exploitation, compressing the time between

discovery and attack. Defenders have access

to the same technology, but this is not a

balanced fight. Attackers only need one

success. Security teams are being asked to

defend an expanding attack surface that they

do not fully see, let alone control."

The real issue, however, is not the models

themselves. It is how they are being used.

"Shadow AI is rapidly becoming one of the

most significant, and overlooked, risks in

cybersecurity. Employees are uploading

sensitive data into external tools, integrating

outputs into business processes and making

decisions based on AI-generated content, all

outside the visibility of IT and security teams.

In many organisations, this is happening at

scale."

From a security perspective, that means

uncontrolled data exposure, weakened

auditability and entirely new vectors for

prompt injection and data leakage, states

Abbaszadi. "In effect, organisations are

expanding their attack surface faster than

they are securing it. This is why the idea of AI

'spinning out of control' is misleading. The

models are not the problem. The lack of

governance is. The organisations that will

struggle are not those that adopt AI fastest,

but those that fail to control how it is used."

CONNECTIVE TISSUE

By the end of 2026, artificial intelligence will

likely feel less like an emerging capability and

more like embedded infrastructure across the

cybersecurity ecosystem, states Jeremy

Ventura, field CSO, Myriad360. "The shift is

already underway. AI is moving from isolated

point solutions into the connective tissue of

security operations, decision making and even

business workflows. The question is no longer

whether organisations will adopt AI, but how

deeply it will be integrated and how

responsibly it will be governed."

From a defender's perspective, AI is poised

to materially reshape security operations.

"Security teams are under constant pressure

to do more with less and AI is being

positioned as a force multiplier. We are seeing

early signs of this in areas such as alert triage,

automated investigation and workflow

orchestration. By 2026, it is reasonable to

expect AI-driven systems to handle a

meaningful portion of repetitive operational

tasks, allowing analysts to focus on higher

order decision-making. At the same time, this

introduces new dependencies. Overreliance

on AI without proper validation, visibility and

control mechanisms could create blind spots,

rather than eliminate them," he comments.

Where the conversation is evolving quickly is

in how AI is being operationalised beyond

traditional enterprise use. "Recent

developments, such as Anthropic Mythos,

and emerging open initiatives, like OpenClaw,

signal a shift toward more autonomous,

agent-driven systems that can act, not just

analyse. At the same time, rapid

advancements from players such as DeepSeek

highlight how global competition is

accelerating capability development,

particularly in model efficiency and

reasoning."

This, says Ventura, has direct implications for

vulnerability discovery and exploitation. "AI

models are already demonstrating the ability

to identify patterns in code,

misconfigurations and potential weaknesses

at scale. In a near-term horizon, this will

Jeremy Ventura, Myriad360: AI is moving

from isolated point solutions into the

connective tissue of security operations,

decision making and even business

workflows.

Tom Pepper, Avella Security: AI will soon be

the defining force shaping both attack and

defence.

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

11


artificial intelligence

Martin Walsham, AMR CyberSecurity: the

risks embedded in AI-generated software

itself need to be managed.

Merlin Gillespie, Cybanetix: we can expect

AI to have moved from a consultative to

an assistive technology by year end.

compress the time between vulnerability

disclosure and exploitation or even enable

discovery before traditional processes catch

up. Nation state actors are heavily investing

in these capabilities, using AI to enhance

offensive operations, automate

reconnaissance and refine targeting with

greater precision."

DEFINING FORCE

By the end of 2026, AI will not simply be an

emerging capability in cyber security," states

Tom Pepper, partner at Avella Security. "In my

opinion, it will be the defining force shaping

both attack and defence…. Phishing emails

arrive with flawless grammar, perfect tonematching

and highly personalised lures

scraped from open sources in seconds, while

deepfakes are becoming indistinguishable

from reality and have already been used to

extort tens of millions of pounds."

Ransomware operations are evolving at true

machine speed, with AI being used to profile

victims, script negotiations and automating

extortion end-to-end, he points out. At the

same time, organisations are beginning to

manage fleets of AI agents across coding,

workflow automation and customer

operations. "Whilst the productivity gains are

unquestionable, from a security perspective -

unless appropriate controls are considered -

the risks to organisations can be devastating.

Each agent effectively acts as a super-user,

expanding the attack surface and introducing

risks that can cascade silently across the

business. Shadow agentic AI operating

outside IT visibility will only compound this

challenge, making oversight and control

significantly harder."

In Pepper's view, the real challenge to AI

adoption is ensuring it does not spin out of

control without careful consideration of the

potential impacts. "That requires deliberate

action now: shifting to AI-aware defences,

such as behavioural analytics and phishingresistant

authentication, rigorously redteaming

not just systems, but AI models and

agents, and embedding governance

frameworks with clear oversight, guardrails,

kill switches and transparency. Aligning AI

adoption with recent European standards -

such at the ETSI Standard for AI Cyber

Security [ETSI EN 304 223] is a good place to

start."

SOFTWARE DANGERS

Alongside changing how we work, AI is

reshaping how the software we use is built.

And this may prove to be the biggest AI

cybersecurity risk of all, warns Martin

Walsham, director of AMR CyberSecurity

(part of Infinum) "Vibe coding - using AI tools

to generate applications quickly, often with

minimal oversight - has become a normal,

encouraged and increasingly expected part of

software development. The appeal is

obvious. But speed without scrutiny creates a

dangerous assumption: that code which

looks secure actually is secure.

"Our recent hands-on testing shows that,

even when AI is explicitly told to build secure

applications, there are still vulnerabilities.

While detailed prompts referencing bestpractice

guidelines certainly improved the

results, the apps still had critical flaws that

would have been trivial to exploit. The main

issue is that, although AI can reproduce

patterns that mimic secure coding, it does

not truly understand risk, context or intent.

"This means the AI security challenge is not

limited to defending against AI-powered

attackers; it is about managing the risks

embedded in AI-generated software itself. As

AI-driven development accelerates, these

vulnerabilities will be introduced earlier,

propagate faster and become harder to

detect. This is particularly true where outputs

are trusted without detailed review."

This also changes the traditional model of

accountability in software security, points out

Walsham. "Historically, responsibility was

relatively clear. The developers wrote code

and security teams reviewed it. In a vibe

12

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


artificial intelligence

coding environment, it's far less clear.

Responsibility is now shared between

humans and systems. Developers are no

longer writing every line of code; they are

prompting AI to generate it. This means

security depends on more than technical skill;

it also depends on how effectively those

prompts anticipate risk.

"More autonomous development workflows

are also emerging, where AI can generate,

modify and even deploy code with limited

human intervention. In these scenarios, the

window for traditional review shrinks and

security decisions are effectively made

upstream, and are embedded in prompts,

guardrails and system design."

So, how do we prevent this from spiralling

out of control? Walsham says the answer is

not to slow adoption, but to change how we

build. "Security must be included early in the

development lifecycle, embedded into

prompts, pipelines and architecture, rather

than layered on afterwards. AI-generated

code must be treated as untrusted by default,

requiring rigorous validation and human

oversight."

HIGHLY ACTIVE ROLE

Merlin Gillespie, CTO at Cybanetix, says AI is

making major evolutionary leaps every 3-

6months, so realistically we can expect AI to

have moved from a consultative to an

assistive technology by year end. "Rather than

purely translating natural language into

syntactical queries of the SIEM, AI will take a

more active role in assisting with the

processing, understanding and interpretation

of log data. Next-generation Agentic AI will

be more autonomous and able to carry out

tasks to achieve set goals, so it will soon be

building and running playbooks on the fly,

returning malicious or suspicious verdicts

from investigations, and remediating and

containing threats automatically."

AI will naturally become part of how SOC

analysts work, he states, effectively giving

them the power of a security cyborg. "They'll

be able to leverage the benefits of machine

learning and AI, while also applying human

ingenuity. We also expect AI to play a more

active role in assisting level one SOC analysts,

effectively upskilling and helping them to

'level up' more quickly. The best analogy is a

very bright team of juniors. They're fast,

capable and eager, but they need direction

and oversight. The manager who delegates

properly and checks the output will get

enormous value. The one who puts their feet

up and assumes the work is done will come

unstuck."

Gillespie singles out how Generative AI can

produce unpredictable and inconsistent

outcomes and remains weak at discerning

business context, while humans excel

through real-world experience. "Retaining a

human in the loop (HITL) with the knowledge

to validate and verify AI outputs is not

optional. We've been experimenting with

assistive AI in threat detection and response

and in one test a model misinterpreted the

threat and went on to produce a fictitious kill

chain and mitigation advice, all of which

would have taken the SOC analyst down a

rabbit hole they didn't need to go down. So,

retaining senior oversight is key."

THE TRUST FACTOR

By the end of 2026, AI in cybersecurity will be

increasingly embedded in day to day SOC

operations, but its success in the UK and

Europe may be defined less by speed and

more by trust, comments Brett Candon, VP

International at Dropzone AI. "Regulatory

frameworks, such as GDPR and NIS2, already

influence how security data can be accessed,

processed and reviewed, and those

constraints are expected to shape how

autonomous, agentic AI systems are

deployed as they move beyond proof of

concept into routine use.

"In practical terms, AI is likely to take on a

much greater share of routine investigative

work, including alert triage and first pass

analysis. However, European CISOs may

remain cautious about autonomy, unless it is

implemented with clear governance. Faster

outcomes are unlikely to build confidence, if

organisations cannot see what data was

examined, where processing occurred and

how conclusions were reached. In regulated

environments, trust may depend as much on

governance as on technical capability."

Explainability is therefore likely to become a

baseline requirement, rather than an optional

enhancement, adds Candon. "Going forward,

boards, auditors and regulators may

increasingly expect security leaders to justify

AI assisted decisions with evidence. That

suggests growing emphasis on investigation

outputs that document reasoning steps,

tested hypotheses and supporting artefacts,

rather than opaque outcomes delivered at

speed."

As European AI oversight moves toward

enforcement, the ability to retrospectively

defend decisions may become as important

as preventing incidents in the first place, he

adds. "Data sensitivity is also expected to

remain a central trust factor. SOC data often

includes personal or operationally sensitive

information, and UK and EU organisations

are likely to scrutinise where investigative

work is performed and whether human

access occurs outside approved jurisdictions.

Approaches that reduce opaque manual

handling may be viewed more favourably, if

they demonstrably lower privacy and

sovereignty risk rather than shifting it."

Strategically, AI day-to-day cybersecurity

operations will increasingly be positioned as a

mechanism to absorb repetitive investigative

workload, "freeing experienced analysts to

focus on judgement driven decisions and

incident response. Ultimately, AI systems that

are transparent in operation, verifiable in

performance and accountable in outcome

are the ones most likely to earn lasting trust

with UK and EU SOC teams".

Continued on Page 31

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

13


SCALING ON UP

Jason Soroko, senior fellow at Sectigo, is not

convinced by the government claims that

the UK will be the first country to roll out

quantum computers at scale. "In the context

of global deep-tech, £2 billion is de-risking

capital, not scale-up capital," he argues. "The

UK cannot win a brute-force hardware war

against the sheer capital expenditure ([CapEx]

of US hyperscalers or Chinese state funds. To

maximise this pledge, the UK must abandon

the vanity goal of building end-to-end sovquantum

computing

A PIONEERING UK GOVERNMENT PROGRAMME WORTH UP TO £2 BILLION IS BEING

INVESTED IN QUANTUM COMPUTING INNOVATION. BUT IS IT TOO LITTLE - AND IS IT TOO LATE?

Some £2 billion worth of UK government

investment in Quantum is aiming to

"ensure the UK stays at the forefront of

Quantum innovation". It adds: The UK will

become the first country to benefit from

revolutionary Quantum computers, sensors

and networks, and support the emergence

of the next generation of leading British

companies who will help shape the curve

of progress".

"As of today, the UK is the first country in

the world to commit to an advanced

procurement to build large-scale quantum

computers on our shores by the early 2030s,"

states the government. "Joining R&D,

manufacturing, software, hardware and

procurement into a single programme,

we will be world leaders in developing and

deploying large-scale Quantum computers."

These systems will be built in Britain, it adds,

"creating British jobs, new opportunities for

British businesses, and opening new routes of

investment to flow into our economy from all

over the world".

According to technology secretary Liz

Kendall: "Laying the foundations which will

give the UK a rich pool of Quantum talent,

the government's flagship TechFirst

programme will launch new partnerships

with companies in the sector - offering up to

100 fully-funded internships. This will give

people the tools they need to embark on

future, high-paying careers in the field.

"The UK is already a global powerhouse in

the technology, launching a first of its kind

National Quantum Technologies programme

in 2014, which has already been backed by

more than?£1 billion in public funding to

support skills, research and infrastructure.

Our credentials as a global magnet for private

investment are also thriving."

FROM EXPERIMENTAL

TO ACTION STATIONS

While WSO2's quantum expert Dr Frank

Leymann recognises that the UK's proposed

£2 billion investment in quantum computing

is "timely and necessary to maintain relevance

in what will become a foundational technology

landscape", he also has his reservations.

Arguing that "the real measure of success will

not be the scale of funding alone, but how

effectively it accelerates the transition from

experimental capability to enterprise-ready

systems".

Quantum computing is sometimes framed

in terms of hardware breakthroughs, but its

broader impact will depend on how well it

integrates into existing digital ecosystems,

Leymann points out. "This is where the

conversation needs to evolve. Enterprises will

not adopt quantum solutions in isolation, but

will require seamless integration with cloud

platforms, AI systems, data pipelines and

existing applications. Without this connective

layer, even the most advanced quantum

capabilities risk remaining confined to

research environments."

From this perspective, investment must

extend beyond quantum processors to

include the middleware, APIs and orchestration

frameworks that make hybrid

computing models viable. "The future is not

purely quantum; it is hybrid mostly, and

quantum systems work together with

classical software, as well as AI. Enabling this

requires solid integration infrastructure, governance

and identity-aware access control to

ensure these systems operate securely, at

scale."

There is also a strong link between quantum

computing and AI, he points out. "As AI

systems become more autonomous, they

will increasingly seek out advanced computational

resources to optimise decisionmaking.

In time, quantum computing will

become one such resource. But for this to

happen, organisations need platforms that

can intelligently navigate between AI agents

and diverse compute backends, ensuring

observability, policy enforcement, and trust.

"To this end, strategic focus is essential.

Investments must prioritise not only scientific

advancement, but also the infrastructure

that makes quantum computing usable,

governable and accessible within real-world

enterprise environments. Ultimately, the

winners in the quantum era will not be

those who build the most powerful machines

alone, but those who make them usable at

scale.

14

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


quantum computing

ereign mainframes. Instead, this capital

should be ruthlessly concentrated on

monopolising critical, high-margin

bottlenecks in the global supply chain -

such as cryogenic control chips, integrated

photonics foundries and error-correction

middleware."

By dominating these indispensable "pickand-shovel"

layers, the UK can force the

global ecosystem to license British IP, using

the £2bn as leverage to crowd-in the massive

private institutional capital required for

true commercialisation, he continues. "It is

technically plausible for localised sovereign

prototypes, but commercially optimistic for

widespread enterprise deployment.

"The industry has exited the 'physics era'

and collided with the 'systems engineering

era'. The primary hurdles to an early 2030s

deployment are no longer theoretical;

they are brutal, unglamorous hardware

constraints. Scaling to the millions of physical

qubits required for fault tolerance hinges on

solving massive thermal dissipation issues in

dilution refrigerators, ultra-dense microwave

cabling bandwidth and silicon fabrication

yields. If these deep-tech manufacturing

bottlenecks persist, seamless enterprise

deployment slips into the late 2030s."

QUANTUM RISK AWARENESS 'PATCHY'

Daryl Flack, partner at Avella Security,

wonders if organisations themselves are

moving fast enough to address the risks

already taking shape. "Across industries,

awareness of quantum risk remains patchy.

While some sectors, particularly critical

national infrastructure, are beginning to

engage, many organisations are still at a very

early stage of understanding what quantum

capability means for their environments.

"For decades, cryptography has been the

quiet constant of digital infrastructure. That

stability has created a false sense of security,

an assumption that encryption 'just works'

or that it is a problem for the future."

The reality is more immediate. "The greatest

exposure lies in long-lived and confidential

data: legal records, medical research, state

secrets and sensitive corporate archives that

must remain secure for decades. Adversaries

are already pursuing 'harvest now, decrypt

later' strategies, exfiltrating encrypted data

today with the expectation it can be unlocked

when quantum capabilities mature. The

countdown has already started."

This is why the question of investment

cannot be viewed in isolation, adds Flack.

"Even with government backing, the

transition to quantum-safe cryptography

represents a once-in-a-generation shift and

one that is deeply complex. Cryptography is

embedded across applications, networks,

devices and operational systems, often with

limited visibility. Many organisations simply

do not know where it exists within their

estate."

The UK's National Cyber Security Centre

has set out a clear roadmap - discovery

and planning by 2028, migration of priority

systems by 2031 and full transition by 2035.

"Those milestones may appear distant, but

the reality is that the discovery and implementation

effort will take years.

"Waiting is not a viable strategy.

Responsibility cannot be outsourced. While

vendors will play a role, cryptographic

resilience must sit with each organisation.

This means starting now: identifying where

cryptography is used, prioritising long-lived

data and designing systems with cryptoagility

at their core."

Quantum computing will unlock enormous

innovation, particularly alongside AI, but it is

a double-edged sword, Flack adds. "The same

capability that drives breakthroughs also

threatens the trust underpinning the digital

economy. The organisations that act decisively

today will be the ones that carry trust,

resilience and competitive advantage into

the quantum future."

Daryl Flack, Avella Security: across

industries, awareness of quantum risk

remains patchy.

Frank Leymann, WSO2: the winners

will not be those who build the most

powerful machines alone, but those

who make them usable at scale.

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

15


email focus

TRUST LEFT IN TATTERS

USERS ARE SUFFERING FROM EMAIL FATIGUE AS CYBERCRIMINALS

WEAR DOWN THEIR DEFENCES. HOW CAN THEY FIGHT BACK?

Cybercriminals are stealing trust by

exploiting legitimate sites, systems

and ecosystems to bypass defences

more easily and maximise attack success.

The findings form part of VIPRE Security

Group's 'Q1 2026 Email Threat Trends

Report'. Processing 1.8 billion emails in

the first quarter of this year, this in-depth

survey highlights the struggles that many

organisations face, signalling a number

of areas where they must strengthen

email defences in the coming months.

Commercial spam takes up the lion's

share at 46%, delivered via compromised

accounts (33%) and free email services

(32%). "This illustrates trusted platforms

and free services as criminals' favoured

Usman Choudhary, VIPRE.

attack vectors," states VIPRE. "Commercial

spam wears down users with email

fatigue, increasing their chances of being

phished, while the technique itself assists

cybercrime through misleading subject

lines, aggressive language and act-fast

promotions." Nearly two-thirds of spam

came from US-based infrastructure,

followed by Ireland and the UK. The US

was also the top target of commercial

spam at 60%, followed by the UK at

12% and Canada at 6%.

Cybercriminals are increasingly relying

on familiar, reputable platforms to carry

out their attacks. Phishing made up

25.87% of all spam, with malicious links

remaining the weapon of choice. "During

the first quarter of 2026, embedded links

appeared in 50.59% of phishing emails,

while 26.69% included attachments,

19.17% used callback schemes and 3.55%

relied on QR code-based phishing." Of

those most in the firing line, Microsoft

continues to be the top brand targeted

for spoofing, "and '.com' domains remain

the primary infrastructure for sending

these attacks," adds VIPRE.

Furthermore, attackers favour 'open

redirects' that begin with the legitimate

domain and then end with a parameter

routing to a malicious site. Abused URLs

accounted for over 89% of phishing

URLs.

Many cybercriminals leverage Cloudflare

to conceal their phishing links. By taking

advantage of the platform's CAPTCHA

and bot-protection mechanisms, they

prevent security scanners from accessing

the actual malicious landing pages. This

tactic not only allows more phishing

emails to bypass defences and reach

users, but also increases the perceived

legitimacy and quality of these emails.

Meanwhile, callback phishing remains

a strong trend. "Common tactics include

fake invoices, subscription renewals

and account status alerts. Microsoft

accounted for 41% of all spoofed brands

in callback campaigns, followed by

PayPal (17%) and Geek Squad (15%).

Runners-up include McAfee, Amazon,

Norton and eBay. Interestingly, to allay

suspicion, these callback campaigns

were sent from authenticated Microsoft

infrastructure, all passing SPF, DKIM and

DMARC checks," reveals VIPRE.

While the C-suite continues to be

the primary impersonation focus for

cybercriminals, its popularity dropped

from 73% (in Q1 2025) to 54% in Q1

2026. This shift suggests attackers are

adjusting to more realistic behaviours -

for example, executives follow a chain of

command and don't always reach out

directly to the C-suite.

"Attackers are boldly using

sophisticated techniques to evade

detection, alongside resorting to

emotional triggers to manipulate and

breach trust," says Usman Choudhary,

general manager, VIPRE Security Group.

"Organisations must strengthen email

defences and rethink how trust is

established across every channel to

combat these threats. The landscape

demands vigilance and a proactive

approach to security. There is no room

for complacency."

16

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


Computing

Security

Secure systems, secure data, secure people, secure business

e-newsletter

Are you receiving the Computing Security

monthly e-newsletter?

Computing Security always aims to help its readers as much as possible to do

their increasingly demanding jobs. With this in mind, we've now launched a

Computing Security e-newsletter which is produced every month and is available

free of charge. This will enable us to provide you with more content, more

frequently than ever before.

If you are not already receiving this please send your request to

christina.willis@btc.co.uk and advise her of the best email address for the

newsletter to be sent to.


events

WHO DARES WINS AT INFOSEC

FROM 'SAS: WHO DARES WINS' STAR JASON FOX TO ENGLAND RUGBY WORLD CUP WINNER MAGGIE

ALPHONSI, THIS YEAR'S INFOSEC SHOW WILL HAVE A HOST OF TOP SPEAKERS TO INSPIRE ATTENDEES

England Rugby World Cup winner

Maggie Alphonsi will bring lessons

from elite sport to the cyber security

community.

Infosecurity Europe, the information

security event running from 2-4 June at

Excel London, has lined up a stellar cast

of keynote speakers for its 2026 conference

programme, including former Special Boat

Service (SBS) sergeant and 'SAS: Who Dares

Wins' star Jason Fox.

Bringing together expertise from cyber

security, law enforcement, elite sport and

the military, the keynote line-up will explore

leadership, resilience and innovation, and

how this is applied to the cyber security

industry.

Fox has spent his career operating in some

of the world's most hostile environments as

part of the UK Special Forces. On Thursday, 4

June, from 10:05-10:45, he will translate the

principles that underpin elite military teams

into the digital domain, exploring how cyber

security professionals can adopt Special

Forces approaches to resilience, decisionmaking

and leadership under pressure.

Drawing on real-world operational

experience, he will share practical mental

models and strategies designed to help

cyber leaders and teams maintain clarity,

build trust and perform effectively when

navigating complex and high-stakes

environments.

Cyber security titan, Shlomo Kramer, one of

the most influential figures in the global

cyber industry, will take the stage on Tuesday,

2 June. As a founder and investor behind

pioneering companies including Check Point,

Palo Alto Networks, Imperva, Cato Networks

and Sumo Logic, Kramer has helped shape

the modern cyber security landscape. He

will join a keynote 'fireside' chat, sharing

his perspective on the technology trends,

investment dynamics and innovation cycles

shaping the future of cyber security.

He will also judge Infosecurity Europe's

'Dragons' Den'-style cyber start-up competition,

helping to spotlight emerging

innovation and the next generation of

cyber entrepreneurs.

Also on Tuesday, 2 June, Cynthia Kaiser,

former deputy assistant director of the FBI's

Cyber Division and now leading ransomware

research at Halcyon, will offer a rare insider

perspective on the cyber-criminal economy.

Drawing on years of experience investigating

sophisticated cybercrime operations, Kaiser

will explore how analysing activity across

the dark web and the wider cyber-criminal

network can help organisations better

understand emerging ransomware tactics

and anticipate the behaviour of threat

actors.

She will also contribute her expertise to

the event's Women in Cybersecurity panel

18

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


events

Cynthia Kaiser will offer a rare insider

perspective on the cyber-criminal

economy.

Jason Fox has operated in some of the

world's most hostile environments as

part of the UK Special Forces.

Cyber security titan Shlomo Kramer is

one of the most influential figures in

the global cyber industry.

session, sharing insights on leadership,

representation and the evolving role of

women across the cyber industry.

Former athlete and England Rugby World

Cup winner Maggie Alphonsi will take to

the stage on Wednesday, 3 June, to bring

lessons from elite sport to the cyber security

community, exploring what it takes to lead

in high-performing environments. Having

broken barriers, smashed stereotypes and

changed the game on and off the field,

becoming a respected voice in leadership

and performance, Alphonsi now works with

organisations around the world to help

individuals and teams unlock their full

potential. Her keynote will focus on developing

a winning mindset, encouraging leaders

to step outside their comfort zones, embrace

their strengths and build the confidence that

is required to perform at the best.

A WIZ SESSION LINED UP

The conference programme will also feature

a keynote session on Tuesday, 2 June from

13:50-14:20, Ron Leizrowice, AI researcher

at Wiz, who will deliver 'The Infosec Big Fat

Cloud Update of the Year', exploring how

the rapid adoption of AI is transforming

the cloud security landscape. Drawing on

frontline research into cloud-native threats,

Leizrowice will outline how AI is compressing

the window between misconfiguration

and exploitation while expanding the attack

surface around cloud control planes, identities

and automated workflows. The session

will outline how to reduce AI-driven attack

paths while enabling teams to move fast and

build securely.

Meanwhile, on Wednesday, 3 June, from

11:00-11:35, Rik Ferguson, vice president

of Security Intelligence at Forescout and

an Infosecurity Hall of Fame inductee, will

present 'Quantum is still far off, we can wait

- can't we?', examining why organisations

should already be preparing for the transition

to post-quantum cryptography.

With technology procurement and

depreciation cycles as the countdown clock,

Ferguson will explore the risks posed by

crypto-fragile components and share

practical steps organisations can take and

insight into the industries that are leading

the pack and what we can learn from them.

Brad Maule-ffinch, event director at

Infosecurity Europe, comments: "This year's

keynote speakers bring insight and experience

from some of the most demanding

environments imaginable, from Special

Forces operations and international law

enforcement to elite sport and global cyber

innovation. Their perspectives will provide

our audience with a refreshing view and

awareness into how resilience, mindset and

forward-thinking leadership can help organisations

navigate current and evolving cyber

security challenges."

LEADING INSIGHTS

The Global Threat Landscape will also be

examined, with insights from leaders that

include former Ukrainian Foreign Minister

Dmytro Kuleba and the NCSC. They will

explore the realities of state-backed cyber

conflict and its implications for government,

industry and national resilience.

Infosecurity Europe will bring together

thousands of cyber security professionals

to discover emerging technologies, share

expertise and connect with peers across the

global security community.

Registration for Infosecurity Europe is open.

Entry cost includes access to the exhibition

show floor and the many theatres where

visitors can hear from some of the biggest

names in the industry.

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

19


risk management

RISK'S ROCKY ROAD

FAILURE TO EMBRACE RISK MANAGEMENT IN A CAREFULLY PLANNED-OUT MANNER CAN HAVE

DEVASTATING CONSEQUENCES. WHY THEN DO MANY ORGANISATIONS FAIL TO FOLLOW THIS PATH?

Risk management means assessing

threats to measure their possible

impact, likelihood of occurring, ability

of an organisation to recover and developing

the best protective strategies. That said,

do organisations typically - and accurately -

measure the risk to their operations and take

all the necessary steps to prevent/eliminate

that risk? If not, how do they alter their world

view to protect themselves against the kinds

of attacks that are rapidly being scaled up

and growing ever more sophisticated?

"Measuring your overall risk profile is often

hindered by a fragmented security tech stack

that fails to give a unified view into security

posture," says David Koke, head of marketing

at Intruder. "It's difficult to stitch together

a complete picture of your security posture

when your insights come from a variety of

sources. Relying on discrete insights from

different security tools can also have unintended

knock-on effects, creating a false

sense of confidence in controls and distorting

views of risk amongst senior security decision

makers."

It's difficult to say if enough is being done to

control risk, he adds, and this comes down

to a variety of reasons. "The reality is that

every single security team will be in the same

boat when it comes down to their to-do list;

there will always be more things they wish

they could be doing. Security exists on

a spectrum, so the checklist will never be

fully complete."

Controlling risk comes down to how

effectively security teams can balance

priorities, states Koke. "This means knowing

how to divide your attention between issues

like zero-days and critical vulnerabilities

that need urgent attention, and proactive

measures like thinking about attack surface

reduction. Solving these challenges starts with

a unified security platform that provides a

holistic overview of risk across your digital

estate, automates key parts of the exposure

management lifecycle and integrates with the

workflow tools you're already using to remove

friction when human involvement is required."

CHANGING TIMES

In 2025, 82% of threat detections were

malware-free (CrowdStrike, 2026).

Adversaries primarily operated through

valid credentials, trusted identity flows and

legitimate system tools. "They did not need

malware," says Josh Taylor, lead cybersecurity

analyst at Fortra, "because the environment

gave them everything they needed. Business

email compromise and investment fraud,

both executed without malware, accounted

for $7.5 billion in FBI-reported losses [FBI IC3,

2023]. Yet, most risk management frameworks

still assume that attacks involve exploitable

software and detectable payloads."

This is a structural failure in how organisations

model threats, he points out.

"Traditional risk assessment

inventories assets, scores

vulnerabilities by

severity and

prioritises remediation based on what scanners

find. That works when the threat is a known

CVE with a patch available. It does not work

when the threat is a legitimate login from a

compromised credential, a spoofed vendor

invoice routed through a real email platform

or a supply chain partner whose environment

was silently accessed months ago. The adversaries

are not breaking in. They are simply

logging in."

The consequence is a risk view anchored

to the wrong baseline. "Organisations will

invest heavily in perimeter controls and their

endpoint detection, then discover the breach

came through a trusted third party, an employee

who clicked a credential harvesting link

hosted on a legitimate cloud service or an AI

coding tool whose authentication helper

executed arbitrary commands, because no

one assessed it as an attack surface. None of

these threats will trigger a vulnerability scan."

Altering this view requires three shifts, says

Taylor. "Risk assessments must account for

identity-based attack paths with the same

rigor applied to software vulnerabilities; if

82% of intrusions avoid malware, then 82%

of the threat surface is invisible to tools that

look for malicious code. Organisations must

extend risk modelling to the trust relationships

Image courtesy of ????

20

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


risk management

they depend on vendors, SaaS platforms,

supply chain partners and the AI tools

now embedded in development pipelines.

Detection strategies must move from

signature-based approaches that identify

known-bad artifacts to behavioural

approaches that identify anomalous access

patterns. The attacks being scaled tomorrow

will not look like attacks. They look like normal

business operations conducted by the wrong

person."

THE RIGHT CONNECTIONS

Sam Peters, chief product officer, IO, says

effective risk management increasingly

depends on an organisation's ability to take

a connected, enterprise-wide view of risk,

rather than addressing issues in isolated silos.

"In today's digital environment, risks rarely

exist independently. Instead, they overlap

and interact across multiple domains. For

example, information security, AI governance

and data privacy risks are deeply interconnected.

A vulnerability in one area can quickly

cascade into another, making it essential for

organisations to coordinate their efforts and

avoid duplication of controls, processes and

resources."

To achieve this, organisations should ensure

that compliance, legal and senior leadership

teams maintain clear oversight across all

risk domains. "Regular, cross-functional risk

reviews enable better visibility of emerging

threats and will help organisations boost

overall business resilience. This integrated

approach not only improves efficiency,

but also strengthens decision-making

and accountability at every level of the

organisation."

Adopting recognised standards further

supports this cohesive strategy. "Frameworks

such as ISO 27001 for information security,

ISO 27701 for data privacy and ISO 42001

for AI governance provide structured, bestpractice

guidance. When implemented

together, they form a robust Integrated

Management System [IMS] that enables

organisations to manage risk holistically,

rather than in fragmented ways. This alignment

reduces gaps, enhances consistency

and promotes a culture of continuous

improvement."

Industry trends reinforce the value of this

approach, adds Peters. "Findings from our

recent State of Information Security Report

indicate that 76% of organisations have

consolidated or simplified their technology

stack and security tools over the past year to

reduce complexity. Additionally, 80% have

achieved or maintained key cybersecurity

certifications such as ISO 27001 and SOC 2,

demonstrating a strong commitment to

structured risk management and regulatory

compliance.

"Leveraging a dedicated compliance platform

can significantly enhance both proactive

risk management and regulatory alignment.

Such platforms centralise risk data and

streamline reporting, allowing organisations

to respond more effectively to evolving

threats. In combination, these practices help

build resilience, ensuring organisations are

better prepared to navigate an increasingly

complex risk landscape."

GETTING THE MEASURE

Many organisations claim to manage risk,

but few actually measure it, states Roger

Greyling, information security senior

consultant at Xcina Consulting, a division

of Brookcourt Solutions. "Even fewer challenge

the assumptions behind their sense of

security. In an age of automated cyberattacks,

AI-enabled fraud, supply-chain

compromises and operational disruptions,

the greatest risk is not external, but the

belief that yesterday's controls still work."

Conventional risk management relies on

periodic assessments, static risk registers

and qualitative scoring. "This model assumes

threats evolve slowly. They do not. Attackers

iterate daily, automate reconnaissance and

exploit small gaps across interconnected

Josh Taylor, Fortra: there's a structural

failure in the way many organisations

model threats.

Sam Peters, IO: risks rarely exist

independently. Instead, they overlap

and interact across multiple domains.

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

21


risk management

Marcten Eikelder, Kiteworks: altering the

worldview starts with accepting that risk

management must become continuous,

data-aware and AI-literate.

Tuukka Tiainen, Recast: a risk without

an accountable owner and a concrete

treatment plan is just a statement.

systems. A compromised vendor or leaked

credential can cascade into a full operational

outage. In several recent ransomware

incidents in the UK, hospitals were forced to

divert emergency patients, cancel surgery

and revert to paper-based care, not because

clinical systems were directly targeted,

but because supporting IT services were

disrupted. What begins as a small foothold

now routinely escalates into an organisationwide

impact," cautions Greyling.

The problem isn't a lack of frameworks, but

a worldview anchored in compliance, rather

than resilience. "Risk management becomes

a checkbox exercise. Organisations optimise

to pass audits instead of survive disruption.

They measure what is easy including controls,

certifications and policies, instead of what

matters: time to detect, respond, and recover.

Risk thinking must shift from probability to

impact. The question is no longer, 'How likely

is this?' but 'Are we prepared for when we're

wrong, and will we survive?' This perspective

prioritises business continuity over theoretical

scoring, and investment in detection, containment

and recovery over prevention alone."

Organisations that adapt make three critical

mindset shifts, he advises. "First, they assume

compromise. Rather than building impenetrable

walls, they design systems that limit

blast radius, including segmentation, least

privilege and zero trust architectures. Secondly,

they test recovery, not just protection.

Back-ups are verified, incident playbooks

rehearsed and crisis decision-making

practised. Resilience becomes a capability,

not a document. Thirdly, they treat risk as

dynamic. Continuous monitoring, threat

intelligence and red-team testing replace

annual reviews. Risk becomes a living signal,

not a static report."

Sophisticated attacks are scaling, because

defenders remain predictable, he adds.

"Organisations must stop asking whether

they're compliant and start asking whether

they'll survive."

WHERE’S MY DATA?

Risk management, in theory, is straightforward,

says Marc ten Eikelder, senior

director at Kiteworks. "Assess threats,

quantify their likelihood and impact, gauge

the business' capacity to recover and deploy

proportionate defences. In practice, most

organisations are nowhere close. Recent

industry research found that only 33% of

organisations have complete knowledge

of where their data resides. Meaning twothirds

are running risk models against an

incomplete picture of what they're even

protecting. When an organisation can't see

the full attack surface, every risk calculation

carries a built-in margin of error that

compounds silently. A significant share of

organisations still rely on fragmented,

manual processes for compliance evidence,

and a pattern emerges. Risk management

frameworks are often measuring what's

convenient, not what's consequential."

The more urgent problem is that the threat

landscape is evolving faster than most risk

models can accommodate, he continues.

"Threat intelligence data from earlier this year

documents an 89% increase in AI-enabled

adversary attacks and an average eCrime

breakout time of just 29 minutes. A pace

that renders quarterly risk reviews dangerously

out of date. Meanwhile, AI adoption

inside organisations is creating entirely new

risk vectors that traditional frameworks

weren't designed to capture. Shadow AI

has been identified as the top driver of

negligent insider incidents, yet only 13%

of organisations have integrated AI into

their security strategy. Organisations are

simultaneously accelerating AI deployment

and failing to govern the data those AI

systems access. A gap that compliance

frameworks like DORA, NIS 2, and CMMC

2.0 in the defence industrial base are now

explicitly targeting."

Altering the worldview starts with accepting

the fact that risk management must become

continuous, data-aware and AI-literate,

22

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


risk management

Eikelder concludes. "Organisations need

unified visibility across every channel through

which sensitive data moves, whether that be

email, file sharing, APIs, MFT, data forms or,

increasingly, AI agents. Without a compliant

AI approach that enforces granular access

policies, maintains tamper-evident audit trails

and encrypts data throughout its lifecycle,

the risk model itself becomes the risk. The

question isn't whether organisations can

afford to overhaul their approach, it's

whether they can quantify the cost of not

doing so."

PROACTIVE APPROACH

Tuukka Tiainen's information security background

is in unified endpoint management

and cloud technologies. "This world has

always run on best practices,"states the lead

security engineer at Recast. "Most seasoned

professionals default to risk-driven thinking,

looking to information security frameworks

like ISO/IEC 27001:2022, which are built

around identifying and addressing vulnerabilities.

But what happens if you don't

approach risk identification and remediation

proactively? Well, it depends. You might get

lucky and have smooth sailing for years. Or

you might have a security incident and wish

you had tried to identify and treat the risk

before it became a true threat."

The fact is, even the greatest enterprise risk

management programs can't completely

prevent problems from happening, he adds.

"But a well-thought-out risk programme

should be able to tell you which risk to

address first and where to direct your treatment

efforts. Risk management will look very

different for every organisation and it's not

always possible to chart a perfect course. I

would recommend just starting somewhere.

Don't let perfect be the enemy of good."

Threats evolve, systems change weekly

and the same weakness can have different

consequences, depending on context.

"Instead of chasing precision, focus on

consistency and decision usefulness," Tiainen

advises. "Define a shared scoring model for

impact and likelihood. Keep it simple and

leaders will use it. Document assumptions, so

you can revisit them later. Most importantly,

make risk ownership real. A risk without an

accountable owner and a concrete treatment

plan is just a statement.

"In my experience, the effort that matters

most is moving from bottom up to top

down. Bottom-up input from engineering,

IT and security is essential, because it reflects

the reality of systems and controls. But topdown

input from leadership is what aligns

risk work to business priorities."

Organisations that do this well treat the risk

register as a living management tool, he says.

"They refresh it on a regular cadence, update

it after major changes and incidents, and

track risk treatment like any other delivery

work. They also validate assumptions by

exercising the plan: incident response drills,

recovery tests and tabletop scenarios. That

is how risk management keeps up with

sophisticated attacks."

CRITICAL STEPS

"Risk management doesn't start with evaluating

all the threats to an organisation, but

by understanding what is at risk, states Ian

Robinson, chief product officer, Titania.

"What are the most critical assets and which

devices on the network protect them? What

systems are necessary to the business

function? What are the consequences,

if something goes wrong?"

Creating a taxonomy of critical assets is

the vital first step of proactive risk reduction.

"Once this is done, then you can look

outwards at the tactics, techniques and

procedures (TTPs) that are being used

most often by threat actors in your sector.

If, instead, you look across the whole

network and decide to fix every critical issue,

that means spending valuable time fixing

issues an attacker simply isn't interested

in exploiting."

A change in view that needs to happen is

not just the risk of a successful attack, but

the aftermath. "We've seen attacks where

problems have dragged on for months -

assembly lines down, online shopping

disrupted - because the businesses weren't

able to recover quickly," adds Robinson.

"Resilience and recovery are key parts of risk

management. There needs to be a good

understanding of what defines a critical

system. For example, for a manufacturer,

the assembly line is clearly critical and

the IT infrastructure that manages the

line must be high priority. But the IT infrastructure

that manages the supply chain is

just as critical and any attack that disrupts

the supply of materials will halt production

just as effectively as an attack on the

assembly line itself."

Therefore, to accurately understand risk,

you need to understand the consequences

of a successful attack on these systems,

says Robinson. "From this understanding,

organisations can better prioritise their

attention on where they are most vulnerable.

This understanding can also help

organisations make better decisions when

it comes to day-to-day operational details,

such as user permissions, firewall rules,

and network segmentation. Understanding

the risks means this lens can be applied to

understanding if a network is too flat, or if

certain users have more access to systems

than is necessary. By applying network

segmentation and least privilege access

principles, this provides assurances that,

in the case of a breach or a threat gaining

a foothold, the spread is contained and

does not impact identified critical business

functions."

This lens is especially critical when

businesses grow and their systems scale

and become more complex. "Having

visibility of the entire network becomes

more difficult, making prioritisation of

critical systems vital to maintaining

security."

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

23


AI angst

LIVING ON THE EDGE

A SMALL GROUP OF PEOPLE, IT IS CLAIMED, GAINED ACCESS TO ANTHROPIC'S CLAUDE

MYTHOS MODEL - A TOOL SAID TO BE TOO POWERFUL TO RELEASE TO THE PUBLIC

Anthropic is investigating a report of

unauthorised access to the company's

Claude Mythos Preview through one of

its third-party vendor environments. This was

in response to a Bloomberg report that users

in a private forum managed to access the

model without the normal permissions.

There is deep unease about Mythos'

capabilities - though one top cyber official

believes advanced AI tools could be a "net

positive", if the technology was secured from

misuse. There is currently no suggestion that

malicious actors have managed to get hold

of the model and Anthropic says it does not

have evidence its systems are affected,

according to Bloomberg.

Raluca Saceanu, chief executive of cybersecurity

company Smarttech247, is of the

opinion that this was most likely through

misuse of access, rather than a classic hack.

"When powerful AI tools are accessed or used

outside their intended controls, the risk is not

just a security incident, but the spread of

capabilities that could be used for fraud,

cyber abuse or other malicious activity."

Under the banner 'Project Glasswing',

Anthropic has released the Mythos model to

some tech and financial companies, in order

to help them secure their systems against its

reported ability to exploit vulnerabilities. This

is a tightly controlled effort to use Mythos to

help secure critical software before comparable

models become more widely available.

The person already had permission to view

Anthropic's AI models through work they

had done for a third-party contractor,

according to Bloomberg. The outlet also

reported the group has been using the

model since it gained access - although not

for hacking, because they do not want to

be detected.

But that highlights the larger issue at hand,

says Stefanie Schappert, a senior journalist at

Cybernews, namely that "the industry knows

what is coming and is still scrambling to build

that much-needed playbook in time to

defend against larger threats, such as nationstate

or ransomware attackers." And she

adds: "If a group of AI nerds could get into

Mythos - allegedly without malicious intent -

imagine the fallout if the next ones to slide

through that door were actual criminals."

WATERSHED MOMENT

"If the early reporting is right, Mythos could

be a watershed moment," says Brian Fox,

co-founder and CTO, Sonatype. "What is not

new is the reality it is forcing people to

confront. Beneath the AI framing sits the

same software supply chain reality we have

been discussing for years: dependencies,

build pipelines, third-party software and

infrastructure remain the attack surface.

What changed is speed. AI can now find and

operationalise weaknesses across that stack

faster than most organisations can inventory,

prioritise and patch them."

What we are seeing in response to the

Mythos news is many organisations coming

to terms with a reality that has existed for a

long time: they are not actually in control

of their software supply chains, he adds.

"A lot of security programmes looked effective

mostly because the clock was slow. Now

the clock is fast and suddenly everyone gets

to find out whether they built a security

programme or just a very polite waiting room.

The winners won't be the companies with

the flashiest AI narrative. They'll be the ones

with real software intelligence, real policy

enforcement and real control over what

enters the pipeline and gets shipped

downstream."

FREE FALLING

It all adds to a growing sense of unease,

around Anthropic AI and AI in general,

cautions Kara Sprague, CEO of HackerOn,

claiming that the window between

vulnerability discovery and exploitation has

collapsed with advancements in frontier AI

24

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


AI angst

model capabilities. "What used to take

attackers days or weeks to do now happens

in hours and increasingly minutes." To

understand where this goes next, we can

examine two scenarios, she adds:

Scenario 1: "Each advance in frontier models

uncovers a commensurate wave of new

vulnerabilities. No surface is ever truly

hardened and we're in continuous free-fall."

Scenario 2: "Discovery eventually plateaus.

As systems and tooling improve, entire

classes of vulnerabilities get reduced and

we approach a [messy] equilibrium."

"Right now, facing down what some

are calling the 'vulnpocalypse', it feels like

Scenario 1," says Sprague. "Attackers can

already use frontier models to discover

exposures, validate exploitability and chain

attacks faster than most teams can triage

a single critical alert. What Anthropic has

disclosed on Mythos indicates that it further

advances those capabilities multi-fold and

Project Glasswing will give defenders a head

start."

"But zoom out," she adds. "It's true, the raw

state space of modern software is massive;

so large it behaves like it's unbounded. There

will always be new edges to explore. But

vulnerabilities don't emerge randomly from

that space. They cluster into recurring

patterns, such as injection flaws, memory

safety issues, auth gaps and misconfigurations.

And, historically, we've seen entire

classes get systematically reduced through

better languages, frameworks and secure

defaults. AI accelerates both sides, expanding

discovery across that vast state space and

compressing the elimination of vulnerability

classes. "So 'what happens next' won't play

out as simply one scenario, but more like

a phased transition."

Phase 1 (now): explosive discovery, collapsing

exploit timelines

Phase 2: systematic reduction of vulnerability

classes

Phase 3: plateau in which rarer, more

complex, bugs dominate.

"We're currently in Phase 1," she states.

"Which is why Scenario 1 feels true today

and likely will be for several years to come.

But I believe the long-term trajectory looks

much closer to Scenario 2. Here's the catch:

even if discovery plateaus, time-to-exploit

won't. That means the bottleneck for

defenders has shifted permanently. It's

not about finding vulnerabilities; it's about

eliminating exposure before exploitation.

That's the new battleground. And it's why

retooling find-to-fix workflows for speed is

existential."

NEW FRONTIERS

Frontier AI is reshaping how organisations

must think about cyber risk. "Frontier models

are a new class of highly capable AI systems

that can reason across complex tasks, analyse

software, identify vulnerabilities, accelerate

exploit development and support increasingly

sophisticated security workflows," comments

Crowdstrike.

Anthropic's Claude Mythos and OpenAI's

GPT-5.4-Cyber are early examples of this shift,

showing how quickly AI is expanding both

offensive and defensive capability. "As

vulnerabilities are discovered and exploited

on shorter timelines, traditional security

approaches built on periodic assessments,

severity scores and human-paced response

are becoming less effective. Defenders

need a new model centred on exploitability,

continuous validation of exposure, stronger

prevention, cross-domain visibility, decisive

response and governed use of AI."

This shift changes what defenders need to

do. The challenge is no longer just finding

vulnerabilities faster than adversaries. It is

figuring out which weaknesses are truly

exploitable, reducing the conditions that turn

them into real risk and responding as quickly

as attackers can move. "As AI speeds up both

discovery and exploitation, organisations

Kara Sprague, HackerOne: no surface is

ever truly hardened and we're in continuous

free-fall.

Brian Fox, Sonatype: The winners won't be

the companies with the flashiest AI narrative,

but the ones with real software intelligence,

real policy enforcement and real control

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

25


AI angst

Raluca Saceanu, Smarttech247: this was

most likely through misuse of access,

rather than a classic hack.

Darren Williams, BlackFog: rapidity with

which AI tools can attack and infect an

organisation is now at 'wire speed'.

need to move from periodic assessment to

continuous, intelligence-driven exposure

management," adds Crowdstrike, "so they can

determine what really matters, prioritise real

risk and quickly coordinate remediation."

RESILIENCE IS THE KEY

They must also prepare for a surge in

vulnerability discovery and patch activity that

many organisations are not operationally

prepared to absorb. "The goal is no longer

just better hygiene. It is resilience in an

environment where offensive capability is

improving faster than traditional security

programmes were built to handle. Organisations

do not need to wait to improve

readiness. They can act now by tightening

remediation and recovery workflows, running

regular validation exercises, reducing attack

surface and telemetry blind spots and

improving how risk is prioritised."

That means focusing less on severity scores

alone and more on exploitability, business

impact, adversary behaviour and attack

path relevance, Crowdstrike advises. "Most

importantly, leaders should treat this as a

business resilience issue, not just a security

issue, and align security, IT, engineering,

and executive teams around timely decisions,

clearer ownership and tighter coordination."

RESPONSIBLE CALL

Tristan Watkins, director of services innovation

at Advania UK, believes Anthropic is holding

back Mythos from public release "because it's

already surfaced thousands of vulnerabilities

and organisations need time to respond

before wider exposure. That's a genuinely

responsible call, one that requires real

commercial restraint. Meanwhile, Project

Glasswing brings together the world's major

device, cloud and security players to start

hardening systems now, before even more

capable AI arrives from Anthropic or another

vendor. Anthropic is backing the project with

$100 million." Serious, coordinated work.

One detail worth sitting with, he adds, is

that Mythos wasn't trained for cybersecurity.

"It got those capabilities as a byproduct of

coding improvements and better longrunning

execution. Capability doesn't always

come labelled. The larger System Card will

take time to fully digest, but the short version

is this: cybersecurity as a discipline needs to

change immediately and at scale. We've

barely scratched the surface of what's in

there."

OPEN SEASON

With AI moving faster than any technology

before, predictions must be tempered,

says Dr Darren Williams, CEO and founder,

BlackFog. "Even the AI leaders are cautious

about predictions. There is no doubt that AI

has dramatically changed the landscape for

attack vectors and the defence posture of

organisations. If companies have not adopted

some form of protection and monitoring,

especially around Shadow AI and Agentic AI,

it will be open season on these companies.

"The imminent release and delay of Anthropic

Mythos shows clearly that no one is ready

for this sort of exposure of vulnerabilities,

and this has only been exposed to the main

technology vendors. We cannot even imagine

what this is going to uncover in less technical

sectors, specifically those highly targeted ones

like government, healthcare and education."

The rapidity with which these AI tools can

attack and infect an organisation is now at

"wire speed", so any technology that has

hopes of stopping it has to operate real time,

adds Williams. "Having adequate monitoring

of AI use is essential and the lack of visibility

is currently the biggest problem. We need

to first discover what is going on and then

provide oversight, risk and governance over

the use of AI to have any chance of ensuring

responsible use of AI. It is not only about

what individuals are doing with AI, but also

what the fully autonomous Agentic AI tools

like OpenClaw and other tools with embedded

AI are doing, and what data exfiltration is

really going on."

26

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


cryptographic security

QUANTUM OVERKILL

MANAGING CRYPTOGRAPHIC SECURITY CAN CREATE OPERATIONAL OVERLOAD

THAT LEAVES ORGANISATIONS DANGEROUSLY EXPOSED TO THREATS

Managing cryptographic security -

from technology like PKI and

HSMs, to keys, certificates and

secrets, to the compliance layer - can

create an outcome where operational

overload results for enterprises preparing

for quantum computing, according to

Entrust.

That is why the company has partnered

with Ponemon Institute to gather insights

from 4,000 global IT, security and risk

leaders to better understand how organisations

are preparing for post-quantum.

"From shortened certificate lifecycles

to expanding cryptographic sprawl, our

report reveals where readiness is advancing,

where it's falling behind and why

Robert Hann,

Entrust.

crypto-agility is critical for resilience in

the years ahead," it states.

On the matter of certificate lifecycles,

the maximum lifespan of SSL certificates

will be reduced in stages over the next

few years. Validity periods will gradually

become shorter and shorter, with an

eventual target of 47 days by March

2029. Here's the timeline you need to

be aware of, according to managed IT

services company Solsoft:

15 March 2026: maximum validity

of newly issued public certificates was

reduced from 398 days to a maximum

of 200 days

15 March 2027: maximum lifespan

of newly issued public certificates will

be lowered from 200 to 100 days

15 March 2029: lifespan of newly

issued certificates expected to be

reduced again to a maximum of 47

days.

"These changes are being phased

in over a three-year period to avoid

foisting any sudden transitions on

users and make the process more

manageable," says Solsoft. "Nevertheless,

certificates that once lasted for

more than a year will soon need to

be renewed several times annually."

Why is it that the industry has decided

to make this change? "Security is the

major consideration behind the move

to shorter SSL/TLS certificate lifespans.

Shorter validity periods limit the window

in which attackers can exploit a compromised

or mis-issued certificate, or one that

uses cryptography that later becomes

vulnerable. In addition, shorter lifespans

are intended to foster better hygiene

when it comes to certificate management.

This nudges organisations to adopt

more modern approaches, such as

automated issuance and renewal, instead

of relying on long-lived certificates that

can go unchanged for months."

The challenge for organisations

concerns how the shift to shorter validity

periods is handled. "More frequent

renewals mean a higher likelihood of

expired certificates. This can lead to

broken websites, service outages and

failed integrations, which can all cause

customers to lose trust as a knock-on

effect. Even short disruptions can have

real financial and reputational effects."

Robert Hann, global VP of technical

solutions at Entrust, comments: "Shorter

lifecycles will ultimately add unwelcome

pressure to organisations already struggling

to manage cryptographic sprawl,

fragmented ownership and the quantum

safe transformation. This is validated by

just 43% of leaders saying they have

sufficient visibility of their own certificate

estate.

The good news, Hann goes on to say,

s that security standards are evolving to

make things easier. "Default use of ACME

protocols is fast becoming the norm,

helping organisations automate previously

manual verification and installation

processes for certificates.

"The great thing about that is organisations

will be building the crypto-agility

required for the post-quantum era.

Future threats will evolve fast, so automating

early will provide a significant

competitive advantage."

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

27


attacks round-up

IS THE TOP ABOUT TO BLOW?

WITH CYBER-ATTACKS ON THE RISE AND ADVANCED AI TOOLS ACCELERATING THE THREAT, ORGANISATIONS

ARE COMING UNDER EXTREME PRESSURE IN THEIR ATTEMPTS TO KEEP THEIR BUSINESSES SECURE

More than half of UK business leaders

are unprepared for threats posed

by advanced AI-powered cyber

threats, according to new research from

Hornetsecurity by Proofpoint, a leading

cybersecurity firm. A survey of 500 business

leaders from across the UK revealed that,

while cyberattacks have increased for 54%

of the respondents (versus 45% two years

ago), over 50% of companies say they are

uncertain whether they have the expertise to

prevent an AI-powered attack. The findings

also highlight that more than half of UK

business leaders have been victims of a

cyberattack and 79% of respondents said

they think AI has increased the sophistication

of cybersecurity attacks.

Daniel Hofmann, CEO of Hornetsecurity

by Proofpoint, comments: "Cyber-attacks

are on the rise and advanced AI tools are

only accelerating the threat. While 69%

of businesses are integrating AI into their

defences, it's highly concerning that a third

have yet to do so. Now more than ever, it's

critical for businesses to recognise the need

to integrate AI in their own security strategies,

so they can stay ahead of increasingly

sophisticated AI attacks."

Despite AI defence technologies sitting at

the cutting edge of cybersecurity, a critical

adoption gap remains: businesses are not

yet fully leveraging these advanced defences

available to them. Alarmingly, according to

the survey, over a quarter of UK business

leaders (26%) are still not using AI to enhance

their cybersecurity defences. Meanwhile,

cyber-attackers are using the latest AI to their

advantage, effectively lowering the barrier to

entry and driving an increase in sophisticated

attacks.

Hofmann adds: "Alongside working with

trusted vendors and managed service

providers, continuous employee training

helps organisations stay prepared against

evolving threats. AI-powered training can

further enhance this by automating and

personalising the experience, making it more

engaging, efficient and effective. In today's

threat landscape, continuous investment

in new technologies and strengthening

defences is not optional, it's essential."

CHANGING NATURE OF RISK

Meanwhile, Megha Kumar, chief product

officer and head of geopolitical risk, Cyxcel,

has been responding to the recently

announced Global Cybersecurity Outlook

2026 from the World Economic Forum,

calling it a "timely reminder of the changing

nature of risks in cyber space, especially the

impact of rapid deployment and innovation

of AI, geopolitical fragmentation and

vulnerability of supply chains".

She points to how technology supply chains

are globally integrated and the hostile cyber

market also operates from across multiple

national borders. "This requires cross-nation

cooperation, but the response is going in

the opposite direction. Growing geopolitical

division between the United States and

Western democracies, in particular, is

impeding joint defensive action against

cyberattacks and policy harmonisation on

technologies, such as social media and AI."

Kumar describes this geopolitical divergence

as especially problematic in the case of AI.

"Leading AI technologies are being developed

in the United States, but the UK and EU, for

example, favour regulation, whereas the US

federal administration is determined to

prioritise innovation and economic growth.

The UK-US dispute over Grok AI is an example

of that divergence. Both sides appreciate

the social damage caused by the misuse

of AI tools, and recognise this damage will

increase, but what we are seeing is a response

on a case-by-case basis, rather than an

integrated approach."

BIG GAME HUNTING

SonicWall has released its UK cyber threat

data from 2025, revealing that the number

of UK organisations successfully compromised

rose by 20%, even as overall ransomware

volume fell by 87%. SonicWall's data stems

from measuring network-perimeter detections:

threats identified and blocked by

SonicWall firewalls at the point of delivery.

The findings point to a potential move

away from high-volume 'spray-and-pray'

ransomware campaigns towards more

targeted, human-operated 'big game

hunting' attacks that are designed to

maximise impact against fewer victims.

Experts at SonicWall pinpointed the issue

to outdated infrastructure compounding

the problem, fuelling what it describes as

28

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


attacks round-up

a growing 'Zombie Tech' crisis. A single

decade-old vulnerability in widely deployed

Hikvision IP cameras accounted for 67 million

attack attempts in the UK, more than 20%

of all serious intrusion activity observed.

Hikvision is the world's largest CCTV/video

surveillance equipment supplier by revenue

and unit share in recent years.

Says Spencer Starkey, executive VP, EMEA,

SonicWall: "On the surface, the 87% drop

in overall attack volume might look like

progress, but the reality is more alarming.

More organisations are being successfully

hit, and attackers are doing it with far greater

precision."

ALERT FATIGUE

Three-quarters (75%) of UK IT teams say

they've experienced outages as a result

of missing alerts in 2025, according to

research from Splunk. The global State of

Observability 2025 report, which surveyed

1,855 ITOps and engineering professionals,

including 300 in the UK, reveals that alert

fatigue is fast becoming one of the most

pressing challenges to operational resilience.

Alert fatigue is particularly pronounced

in the UK, where over half (54%) of

respondents say false alerts are harming

morale, and 15% admit to deliberately

ignoring or suppressing alerts - higher

than the global average (13%).

UK IT teams point to tool sprawl (61%),

false alerts (54%), and the overall volume

of alerts (34%) as some of the greatest

contributors to their stress. These pressure

points suggest growing frustration within IT

departments, where constant interruptions

are taking a toll and creating an environment

where critical security alerts could be missed.

A lack of clear ownership in incident

response also appears to be compounding

the issue. Just 21% of respondents say they

regularly isolate incidents to a specific team -

a key marker of maturity in incident response

- while 36% admit that they rarely isolate

them. This ambiguity increases the risk that

important security alerts are left unaddressed,

leaving organisations more vulnerable to

attacks and exposing them to avoidable

breaches and downtime.

By bridging silos across teams and

strengthening observability practices,

organisations can help boost resilience

while protecting both their systems and their

people. "IT teams are drowning in noise.

Every day they're hit with alerts, but without

the right context or ownership, it's almost

impossible to know which ones really matter.

This lack of clarity puts a lot of pressure on

teams and slows response times." says Petra

Jenner, SVP & general manager, EMEA,

Splunk. "When critical alerts get lost in that

noise, organisations risk downtime and

customer disruption, which can quickly

translate into revenue loss and lasting

reputational damage.

ACCESS AND RESILIENCE

The estimated 270 million Apple devices

that were targeted by a new hacker tool

called DarkSword stirs up worrying

associations for Kamran Bahdur, chief

information Officer at cybersecurity firm FLR

Spectron. "What this highlights for businesses

is that mobile risk is now an access and

resilience issue, not just a handset issue."

A smartphone may hold access to email,

collaboration platforms, saved credentials,

MFA prompts and cloud services. "Once

that device is compromised, the issue can

move quickly into wider business systems.

The practical response is disciplined mobile

security, including patching, device compliance,

access controls, monitoring, and

a clear incident response path, if a device is

suspected to be compromised."

Kamran also recommends that businesses

protect their systems by making sure devices

are updated quickly and consistently. "Delays

in patching create an opportunity for attack-

Petra Jenner, Splunk: when critical alerts

get lost in the noise, organisations risk

downtime and customer disruption.

Kamran Bahdur, FLR Spectron: mobile risk

is now an access and resilience issue, not

just a handset issue.

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

29


attacks round-up

Iain Wham, Innovec: cyber security

remains a significant business resilience

challenge.

Benny Czarny, OPSWAT: organisations

should treat every file entering their

systems as untrusted until verified as

safe.

ers, especially when threats are designed to

move fast. It also means improving visibility

across organisations' device estates, so that

businesses have clear visibility as to which

devices can access company data, whether

they are compliant and where risks exist.

"Most importantly, businesses need layered

protection that reduces exposure and supports

continuity when new threats emerge,"

he cautions. "That includes 24/7 monitoring,

threat detection and incident response, endpoint

protection and policies that protect

access to business system,s in the event

a device is compromised."

CRITICAL BREACH FEARS

One in eight small businesses have experienced

a cyber-attack and more than half fear

they would be vulnerable to a critical data

breach in the future, according to a new

study The survey of 500 businesses found

that, while many small-and-medium sized

enterprises (SMEs) have implemented basic

cyber security measures, critical gaps remain

in training, incident response planning and

strategic preparedness that could prove

catastrophic in the event of a serious breach.

Most respondees said they lacked the

resilience to withstand a prolonged operational

shutdown, fewer than one in ten

provide regular cyber security awareness

training for staff and less than a third have

invested more in cyber security in the past

two years.

Of the businesses that responded, 12.5%

said they had experienced a cyber security

breach in the past. Incidents included

ransomware attacks, compromised email

leading to financial loss (phishing), theft of

customer and employee data and denial-ofservice

attacks. A greater number said they

felt their company was vulnerable to a future

attack, with most indicating they would face

critical financial pressure. if they had to close

operations. One in eight respondents said

their company would be unable to survive

a complete shutdown lasting 48 hours or

more, while almost a third estimated their

maximum survival window in such

circumstances would be three to seven days.

Iain Wham, managing director of Innovec,

said the findings served as a reminder that

cyber security remains a significant business

resilience challenge to a large proportion

of the UK's SME community.

"As threats continue to evolve, and attackers

increasingly target smaller businesses as

entry points into larger supply chains, the

need to act has never been greater. The

question for SMEs and business support

organisations is whether current levels of

awareness, investment, and preparedness

are sufficient to combat the next, inevitable

wave of attacks."

UPSIDE DOWN, INSIDE OUT

In his newly released book 'Cybersecurity

Upside Down, OPSWAT founder Benny

Czarny is calling on organisations to rethink

their cybersecurity strategies. The book

tackles long-standing assumptions about

defending against cyber threats and seeks

to educate readers on the importance of

a prevention-first mindset, he says.

Czarny argues that many modern

cyberattacks succeed because security

strategies focus on detecting threats after

they enter a system. AI is adding to the

challenge, as threats are evolving faster than

traditional detection tools can keep pace. In

'Cybersecurity Upside Down', he argues that

cybersecurity should be approached based

on the principle that organisations should

treat every file entering their systems as

untrusted until verified as safe.

"For years the cybersecurity industry tried to

achieve prevention through detection, which

worked for a time," he adds. "But that model

is broken. Attackers can now generate new

threats faster than we can detect them and

AI is accelerating the problem."

30

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


AI insights

YEAR OF LIVING DANGEROUSLY

CONTINUED FROM PAGE 13

Speculation abounds about what AI

will do and - more specifically - which

industries and disciplines it will kill off,

notes Neil Roseman, CEO, Invicti. "Most

recently, the announcement of Claude Code

has prompted speculation that LLMs [Large

Language Models] of this kind might get

rid of AppSec entirely. LLMs like these will

supposedly check code to find vulnerabilities,

then challenge their own code review to

delimit false positives. They will then be able

to devise fixes and issue patches."

Neil Roseman.

Simon Hunt.

That might seem game-changing, he says,

but the reality will be far more nuanced. "In

reality, LLMs are unlikely to replace humans

and their tools, but they will change the way

we do AppSec. First, announcements and

product demos are not security tools. LLMs

can do some security analysis and work with

code rather well, but an AppSec tool needs

to be able to work reliably in constantlychanging

environments to produce repeatable,

trustworthy results. Currently, LLMs

cannot do this at the scale or cost required

to accommodate real AppSec needs for

businesses. Recent work - for example, this

recent post by Dawn Song at Berkeley - cast

doubt on the ability to assess these systems

for accuracy at all, which will again limit

their utility.

"Moreover, while automated detection and

remediation will be useful, checking source

code for bugs is only one part of AppSec.

Indeed, modern threats aren't explicitly

targeting source code - they're attacking

weaknesses in misconfigured environments

and running applications."

LLMs cannot yet validate vulnerabilities in

runtime or understand the nuances of a

complex environment, Roseman points out.

"Yet that's exactly what's required for effective

AppSec: a strategic perspective that shows

how vulnerabilities behave when deployed

and affect overall organisational risk. That

part of AppSec will remain solidly in the

hands of human experts and their tools.

And a trend we are already seeing is an

increase in potentially exploitable defects

as more semi-skilled developers deploy AI

generated code they don't fully understand.

"In fact, as other parts of AppSec are

automated, validating those vulnerabilities

within live applications will become the

central AppSec concern. The same goes for

LLMs' fixes, which will have to be independently

verified to ensure they address a

vulnerability's root cause, don't introduce

further security issues and deploy safely."

ESSENTIAL ROLE

Simon Hunt, who is chief product officer at

Securonix, points to how AI is becoming part

of how modern security operations function.

"It helps streamline triage, adds context to

detections and supports faster decisions

across environments that are only getting

more complex. Most security leaders already

see AI-driven automation as essential to how

their teams operate. At the same time, there

is a gap between capability and confidence."

AI can do more, he adds, but trust in the

outcomes has not kept pace. That gap will

define the next phase of adoption. "The

question is not how much AI can do. It is

how confidently teams can rely on it when

decisions matter. That is why design matters.

Systems need to be transparent, explainable

and grounded in policy. Human-in-the-loop

models are critical, not as a constraint, but

as a way to ensure that speed does not come

at the cost of control."

From a defensive standpoint, AI will

continue to act as a force multiplier, states

Hunt. "It helps teams manage alert volume,

reduce manual effort and operate more

effectively with limited resources. But attackers

are using the same capabilities to scale

reconnaissance, accelerate development and

bypass controls. Speed and adaptability are

becoming the deciding factors on both

sides."

Keeping AI from drifting out of bounds will

come down to discipline. "Strong guardrails,

clear accountability and well-defined decision

logic need to be built into the system from

the start. The checks an experienced analyst

would apply cannot disappear. They need to

be encoded and enforced."

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

31


cybercrime

CRIME PAYS… AND PAYS

GLOBAL CYBERCRIME DAMAGE IS PROJECTED TO COST MORE THAN $12 USD

TRILLION ANNUALLY BY 2031. HOW CAN THAT PROFLIGATE WASTE BE HALTED?

Global cybercrime damage is projected

to cost more than $12 USD trillion

annually by 2031, according to

Cybersecurity Ventures. In the face of such

a threat, how do organisations evolve at

the highest levels to become capable of

understanding context, detecting intent and

predicting threats? And who within those

organisations should be driving the changes

needed to get there - and how is that to be

achieved to best effect?

In response, Peter Smails, SVP, general

manager, cloud native, SUSE, says

organisations can't afford incremental

improvements; they need a fundamental

shift in how they secure cloud environments.

"Modern infrastructure is dynamic, distributed

and API driven. Workloads spin up and

down in seconds. Identities outnumber

humans and attackers increasingly exploit

misconfigurations, over permissioned roles

and exposed control planes, rather than

traditional network perimeters."

To understand context, detect intent and

predict threats, organisations must move

toward a continuous, cloud native security

operating model, he insists. "That starts

with unifying telemetry across identities,

workloads, clusters and services, so signals

aren't analysed in isolation. Threats in the

cloud rarely look like 'events'; they look like

subtle deviations in behaviour, privilege or

configuration. Only correlated, real time

context can surface intent early enough

to act."

"Who drives this evolution? "It requires

CISOs, CTOs and platform engineering leaders

working as co owners of the cloud operating

model," states Smails. "Security can't sit on

the outside of delivery anymore. It has to be

embedded into the platform: policy driven,

automated and enforced through the same

pipelines that ship code. Identity becomes

the control plane. Automation becomes the

default. Drift becomes observable and

correctable.

"Boards also have a critical role. Cloud risk is

now business continuity risk. When attackers

target identity providers, SaaS admins and

cloud backups, resilience becomes a strategic

priority, not just a technical one. The organisations

that succeed won't be the ones

with the most tools. They'll be the ones with

a cloud native security model capable of

understanding context, inferring intent and

predicting threats before they materialise."

"

TRUST UNDERMINED

Despite the billions invested in cybersecurity

across the world, breaches still dominate the

headlines, comments Dave Silke, managing

director, EMEA & APAC Centripetal. "And

when they happen, the impact is deeply felt,

not just by systems and balance sheets, but by

people, teams and the impact on everyone's

trust. Breaches at organisations like Marks

& Spencer and Jaguar Land Rover are not

outliers; they reflect a familiar pattern.

Security models are built to react, rather than

anticipate. Overstretched teams are doing

their best within constraints, but there is a

quiet acceptance that breaches are simply

part of modern life. That belief sits at the

heart of the problem."

Boards approve budgets with compromise

assumed. CISOs plan around detection and

response, and SOCs are left carrying the

weight when things go wrong. "Over time,

this creates a sense of inertia, a feeling across

CISOs and IT teams that there is little more we

can do. Everywhere, we are reminded of the

when, not the if, of a cyber breach. Success is

measured by the speed of response, rather

than the calm confidence of prevention."

But adding more tools to an already crowded

stack doesn't change this trajectory, says Silke.

"Today's SOCs are overwhelmed by tens of

thousands of alerts each day, many of which

are false. Even AI, for all its promise, is often

applied simply to optimise an unsustainable

system, rather than to reimagine it. To evolve,

organisations must reconnect with proactive

intelligence. Proactive threat intelligence has

32

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


cybercrime

long been relied upon by governments and

defence communities, and offers a fundamentally

different mindset. By identifying

and blocking known bad activity before it

ever reaches the stack, we reduce noise,

restore focus and give teams space to think,

not just react.

Most cyberattacks are not new. "They are

old threats, repeated and amplified through

automation and scale. That makes them

predictable, and crucially, preventable when

intelligence is applied with intent. When

known bad traffic is stopped upstream,

alert volumes fall dramatically, lifting the

fog of fatigue that clouds today's SOCs."

This is an invitation for CISOs to pause,

reflect, and challenge familiar assumptions.

To look beyond traditional metrics. And to

rebalance investment away from constant

reaction, towards intelligence led capabilities

that return a sense of control. Ransomware

does not have to remain a cost of doing

business, and the future doesn't have to

feel this reactive."

KEY SHIFTS

To address the damage threat, organisations

need to constantly evolve, comments Mihai

Popa, chief information security officer,

Bridgeworks. "This requires the capability to

understand context, detect intent and predict

threats. In fact, organisations need to move

beyond reactive security models to adopt

a context-drive, intelligence-led approach."

This means correlating data across networks,

endpoints and cloud environments to build

a real-time understanding of behaviour -

not just events. "At the highest level, this

evolution requires three key shifts: from

siloed visibility to unified observability across

hybrid and multi-cloud environments; from

signature-based detection to behavioural

analytics and AI-driven insights; and from

perimeter defence to data-centric security."

Equally important, add Popa, "is the ability

to securely move and analyse data at speed.

If organisations cannot efficiently transport

large datasets between environments, their

ability to detect patterns and predict threats

is severely constrained. This is where WAN

performance and security converge - enabling

fast, secure data movement ensures that

threat intelligence is both timely and

actionable".

BOARD-LEVEL IMPETUS

He continues: "Transformation must be

board-level driven, with accountability sitting

across the CISO for security, risk and governance;

the CTO and CIO for architecture and

technology enablement; and the CEO, as well

as the board for prioritisation, investment

and organisational culture. This is because

cybersecurity is no longer an IT issue; it is

a business risk issue."

Cloud security, networking and infrastructure

teams must operate as a single, aligned

function, particularly in cloud environments

where performance and security are tightly

interdependent. "This requires a layered,

integrated approach that involves zero trust

architectures, encryption in transit and at rest,

cloud native security tools, such as CSPM,

CWPP workload protection, advanced threat

detection that leverage artificial intelligence

and machine learning for anomaly detection."

Security tools are only effective, if they can

inspect, analyse and act on data promptly.

Poor network performance creates blind

spots. "With WAN Acceleration, organisations

enhance cloud security by reducing exposure

windows, improving backup and recovery

times, while enabling faster forensic analysis,"

Popa states.

"WAN Acceleration plays a critical - and often

underestimated - role in cloud security.

Deploying it mitigates WAN latency and

packet loss - expediting encrypted data

transfers without compromising on cloud

security controls, so that organisations can

detect cloud threats sooner, respond faster

and recover more effectively."

David Silke, Centripetal: CISOs plan

around detection and response; and

SOCs are left carrying the weight when

things go wrong.

Mihai Popa, Bridgeworks: transformation

must be board-level driven, with

accountability sitting across the CISO

for security, risk and governance.

www.computingsecurity.co.uk @CSMagAndAwards May/June 2026 computing security

33


operational failures

SEVEN DEADLY SINS

A NEW THREAT REPORT REVEALS A LANDSCAPE THAT'S GROWING MORE PRECISE AND RELENTLESS

WITH HIGH AND MEDIUM SEVERITY ATTACKS SURGING BY 20.8% TO 13 BILLION-PLUS HITS

Most SMBs aren't losing ground to

sophisticated attacks: they're losing

ground to seven predictable, preventable

gaps that SonicWall has named the

'Seven Deadly Sins of Cybersecurity'.

The SonicWall 2026 Cyber Protect Report,

says the company, signals "a landmark

reframing from traditional threat reporting,

in favour of the protection outcomes that

matter most to business leaders".

The 2026 report again draws on data from

SonicWall's global network of more than

one million security sensors to reveal a

threat landscape that is growing more

Michael Crean,

SonicWall.

precise and more relentless, it states.

Statistical findings include:

High and medium severity attacks surged

20.8% to 13+ billion hits. Attackers

aren't just striking more often, they're

striking smarter

Automated bots now generate more

than 36,000 vulnerability scans per

second, accounting for more than half

of all internet traffic. Bad bot traffic

alone has surged to 37% of all global

internet traffic

IoT attacks climbed 11% to 610 million

hits; Log4j alone generated 824.9

million IPS (intrusion prevention system)

hits in 2025, four years after disclosure.

"SonicWall data reveals attacks are getting

faster and, in some instances, they're getting

a little more sophisticated," says Michael

Crean, SVP and GM of Managed Security

Services at SonicWall. "But the vast majority

of the attacks that we're seeing and investigating

are basic fundamentals that continue

to be missed. The danger isn't that AI isn't

working; it's that we're using it as an excuse

not to do the things we already know we

should."

SEVEN DEADLY SINS

Rather than attributing breach risk to exotic

or emerging attack methods, the 2026

Protect Report identifies seven operational

failures that appear repeatedly across

investigations and that remain largely

preventable:

1. Ignoring the Fundamentals: Weak

authentication, unpatched systems

and excessive admin privileges remain

the primary attack surface

2. False Confidence: Believing you're too

small to be targeted, overestimating

control effectiveness and assuming

resilience without testing it create

dangerous blind spots

3. Overexposed Access: Overly permissive

rules, flat networks and implicit trust

after authentication give attackers

an unobstructed path once inside

4. Reactive Security Posture: Without

24/7 monitoring and proactive threat

hunting, attackers set the timeline.

The average breach goes undetected

for 181 days

5. Cost-Driven Security Decisions: Deferring

investment based on short-term budget

pressure creates costs that arrive later,

with interest. A single SMB breach can

exceed $4.91 million when downtime

and recovery are included

6. Reliance on Legacy Access Models: VPNs

that authenticate once and grant broad

network access remain a highly exploited

entry points in enterprise security. VPN

CVEs grew 82.5% over the analysed

period

7. Chasing Hype Over Execution: Buying

the latest tools without deploying them

completely and expecting technology to

compensate for process gaps is its own

form of vulnerability. Tools don't create

outcomes, execution does.

"The organisations that suffer the most are

not failing because of sophisticated attacks;

they're failing because of predictable, preventable

gaps," Crean continues. "SMBs

are the backbone of the US economy,

representing 99% of all US businesses and

nearly half of private sector employment.

Protecting them protects entire communities.

That's why this report is designed

around protection outcomes, not just

threat statistics."

34

computing security May/June 2026 @CSMagAndAwards www.computingsecurity.co.uk


Computing

Security

Secure systems, secure data, secure people, secure business

Product Review Service

VENDORS – HAS YOUR SOLUTION BEEN

REVIEWED BY COMPUTING SECURITY YET?

The Computing Security review service has been praised by vendors and

readers alike. Each solution is tested by an independent expert whose findings

are published in the magazine along with a photo or screenshot.

Hardware, software and services can all be reviewed.

Many vendors organise a review to coincide with a new launch. However,

please don’t feel that the service is reserved exclusively for new solutions.

A review can also be a good way of introducing an established solution to

a new audience. Are the readers of Computing Security as familiar with

your solution(s) as you would like them to be?

Contact Edward O’Connor on 01689 616000 or email

edward.oconnor@btc.co.uk to make it happen.


ACCORDING TO JAMF 2024:

Security

Trends Report

39 % of

organisations

had at least one device

with known vulnerabilities

40 % of

mobile users

were running a device

with known vulnerabilities

9 % of

users fell for

a phishing attack

Manage and Secure

Apple at work

With Jamf Trusted Access, you ensure

that only authorised users, on enrolled

devices that are secure and compliant,

can access sensitive data.

REQUEST

Y O U R

FREE

T R I A L

TODAY

www.jamf.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!