<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RANT Community</title>
	<atom:link href="https://rantcommunity.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://rantcommunity.com/</link>
	<description>Better Cyber Security Through Shared Opinions</description>
	<lastBuildDate>Wed, 30 Sep 2026 07:17:14 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.3</generator>

<image>
	<url>https://rantcommunity.com/wp-content/uploads/2023/09/cropped-favicon-32x32.png</url>
	<title>RANT Community</title>
	<link>https://rantcommunity.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Time To Settle The Score: Why Your TPRM Strategy Needs More Than Questionnaires And Tick-Boxes</title>
		<link>https://rantcommunity.com/resources/time-to-settle-the-score-why-your-tprm-strategy-needs-more-than-questionnaires-and-tick-boxes/</link>
		
		<dc:creator><![CDATA[Galena]]></dc:creator>
		<pubDate>Mon, 05 Oct 2026 09:15:21 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<guid isPermaLink="false">https://rantcommunity.com/?p=3240</guid>

					<description><![CDATA[<p>It&#8217;s hardly a novel observation to suggest that we live in confusing and contrary times. Lots of things about our</p>
<p>The post <a href="https://rantcommunity.com/resources/time-to-settle-the-score-why-your-tprm-strategy-needs-more-than-questionnaires-and-tick-boxes/">Time To Settle The Score: Why Your TPRM Strategy Needs More Than Questionnaires And Tick-Boxes</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>It&#8217;s hardly a novel observation to suggest that we live in confusing and contrary times. Lots of things about our present shared environments make very little sense, so singling any one tiny example out might seem pointless. But there is something emblematic of our socio-political-cultural moment in the strange way we all seem to react to questionnaires.</p>
<p>As consumers we appear to love them. As attention spans atrophy and an audience for traditional written &#8220;content&#8221; becomes ever harder for publishers to find, no online resource is going to struggle for clicks and eyeballs when it posts some kind of &#8220;what Pokémon character/domesticated animal/type of cheese/superhero&#8217;s sidekick are you?&#8221; quizlet. Everyone wants to have a go, regardless of whether there&#8217;s any kind of prize involved, and completely oblivious to small print that may say, by participating, we&#8217;re giving permission for 174 tracking services to monitor our web browsing activity for the next 100 years. But when it&#8217;s our job to fill in questionnaires sent by our suppliers or our customers, and quizzing us on our risk appetite, our security processes and policies, and on how safe and reliable a partner we may be in an ongoing and mutually beneficial business relationship, questionnaires seem to become the last thing anybody wants to have anything to do with.</p>
<p>And yet, according to many views expressed by a high-level group of CISOs, BISOs and other senior cybersecurity leaders called together by risk-management specialists Diligent for a RANT roundtable in Manchester, questionnaires remain the first and best option for many businesses when it comes to assessing and assuring the security of their usually extensive supply chains. But why is that? Surely there&#8217;s got to be something out there that works better, is more effective, more responsive, less arduous and should be more reliable a gauge of a partner&#8217;s security policies and practices than the much-decried and almost entirely unloved extended tick-box exercises that most businesses insist on their suppliers submitting to?</p>
<p>&#8220;My perspective on all this has grown over the years,&#8221; said RANT&#8217;s guest-host for the evening, Colin Farrell, currently head of security audit at the Office for National Statistics but who, in previous roles, has worked extensively in regulatory audit capacities and spent time on staff at the Information Commissioner&#8217;s Office. As such, his overview of supply-chain risk is extensive and his perspective broad. The trends he&#8217;s noticed are therefore noteworthy.</p>
<blockquote><p>   &#8220;The interesting thing about third-party risk management is that it&#8217;s the only aspect of security I can think of where everybody&#8217;s basically doing the same thing,&#8221; he said. &#8220;It&#8217;s different shades of grey &#8211; but everyone uses supplier questionnaires. They look a bit different, the processes are different, and I&#8217;m sure there are examples of industries this doesn&#8217;t apply to. But questionnaires exist for a reason &#8211; they work. So what interests me tonight is, what are those different methods? And has anyone found anything that works better?&#8221;</p></blockquote>
<h4><strong>Ready Or Not</strong></h4>
<p>The first theme to emerge from the discussion was that questionnaires, like any tool, work best when deployed with precision, care and planning, rather than reflexively reached for as a blunt solve-it-all-somehow instrument. And while some attendees flagged up exceptions, and some suggested a few ways of obtaining the necessary assurance that may not use questionnaires as the sole or central means of obtaining information, for most security and audit managers, the best way of making questionnaires work well lies in ensuring they&#8217;re sent out &#8211; and/or responded to &#8211; only after first asking and answering some simple, basic and internal questions.</p>
<blockquote><p>   &#8220;When you onboard a new supplier you need to understand the service they&#8217;re supplying &#8211; and you need to have an exit plan, because without one you can&#8217;t even onboard them,&#8221; one security leader argued. &#8220;To me, that&#8217;s proper risk management. It shouldn&#8217;t be, &#8216;Have you got this policy and that policy? Yeah? Then we&#8217;ll onboard you.&#8217; No. It&#8217;s not about a tick in a box.&#8221;</p>
<p>&#8220;Not all suppliers are equal, are they?&#8221; another leader mused, pointing out that a firm that supplies pens to an office will not need to demonstrate the same kind of security assurance as a financial partner or a company whose systems are required to connect to the corporate network. &#8220;What we try to do,&#8221; they added, &#8220;is not ask everyone the same questions. There are screening questions, then what we ask after those is different.&#8221;</p></blockquote>
<p>Very quickly, the conversation turned to not just understanding the nature of the relationship between the companies and appreciating the differences between different kinds of suppliers, but to means and methods of accurately and sensibly assessing risk in the round.</p>
<blockquote><p>   &#8220;What are the things on top that you need to do to understand what the true risk is?&#8221; one expert asked, partly rhetorically, partly genuinely and literally. &#8220;You need an external view of how controls are working, and you need that on a continuous basis. Then you&#8217;ve got to understand different suppliers depending on the risk they represent to you based on who they are and what they do for you. You should,&#8221; they added, &#8220;ask the same questions to all of them. [But] what do you want to get out of it? The questionnaire gives you something, but you need an assessment of what they&#8217;re actually doing.&#8221;</p></blockquote>
<h4><strong>The Mask</strong></h4>
<p>At the end of the discussion, Diligent&#8217;s governance, risk and compliance sales director, Tom Ryan, humble-bragged that neither he nor his colleague, director of sales Chlōe Dellow, had mentioned AI once. But it wouldn&#8217;t be a cybersecurity conversation in 2026 without someone raising the spectre of autonomous agents, large-language models and generative so-called &#8220;artificial intelligence&#8221; &#8211; and, inevitably, this contentiously inescapable technology was evoked quite early in the evening. But for once, the impact it seems to be having &#8211; at least for some businesses &#8211; has been positive in terms of how it has redirected discussions within companies during examinations of supply-chain risk.</p>
<blockquote><p>   &#8220;AI has helped in this respect with us,&#8221; one attendee said, noting that their product is software, most of their suppliers supply software, and AI is contained within most of those supplied software products. &#8220;It has forced governance across the whole company. Now we&#8217;ve got people who are looking at the impact across the whole enterprise. Legal are doing a deeper dive on terms and conditions, and security is now a part of that process. We&#8217;re not driving it anymore &#8211; which is nice. There&#8217;s no escaping it, so it&#8217;s going through a more rigorous compliance process.&#8221;</p></blockquote>
<p>But in other sectors &#8211; perhaps particularly those where the product or service being sold is not software &#8211; such deepened corporate understanding may be slower to coalesce. And, in any case, it will still be necessary to ask the right questions if anyone hopes to obtain answers that are accurate, insightful and reliable. Understanding the nature of the relationship remains fundamental and unavoidable.</p>
<blockquote><p>   &#8220;You&#8217;ve got to look at the non-standard supplier,&#8221; one security leader, who works in a regulated industry, said. &#8220;We have to break things down to: What companies am I mandated to use? What are the regulated companies I have to work with? And who is there outside of that who I still need to be on top of? It&#8217;s all about piecing that all together to get a fuller view. What risks are you willing to take? That&#8217;s not just cybersecurity risks &#8211; it&#8217;s all the other risks too.&#8221;</p></blockquote>
<h4><strong>Freestyle Interlude</strong></h4>
<p>One of those other risks &#8211; unavoidably, if somewhat metatextually &#8211; lies in whether or not you can trust the responses you get from your questionnaires.</p>
<blockquote><p>   &#8220;Sometimes,&#8221; one CISO suggested, people give certain answers because &#8220;they want to keep the business on side. Whereas in your head you&#8217;re thinking, &#8216;This is complete BS, and if the regulator were to come along and look at this, we&#8217;d be screwed.&#8217; The biggest problem we see is people being able to explain to the business what the risk is, in language they understand. And what do you do next with all that information? You&#8217;ve got it, but often, it just drops down a hole.&#8221;</p></blockquote>
<p>And of course, the questionnaire experience usually works in two directions, not just one: most firms, as well as attempting to ensure adequate and acceptable security policies are in place with suppliers, will be on the receiving end of similar approaches, responding to similar concerns, from the companies they supply their products and services to. Making sure the business can do that is just as important, and the theme of responses being coloured by the likely perceptions of the intended audience is resonant here too.</p>
<blockquote><p>   &#8220;I want to get away from the idea that [adhering to standards such as the ISO&#8217;s] 27001 is the minimum viable product,&#8221; one CISO said. &#8220;I try to underline how we sell ourselves to our customers. We have a competitor who got popped, and they have a similar name to our business, so we have to be able to explain why we&#8217;re better than that. That changes the model. At the moment, [most companies seem] to be keeping the barrier at, &#8216;What&#8217;s the bare minimum we expect?&#8217; We need to do better than that. And then we can change the model.&#8221;</p></blockquote>
<h4><strong>Cowboys</strong></h4>
<p>Another set of tools that are widely used to help companies assess supply-chain risk are scorecards produced by companies who offer the chance to take up some of the burden of information-gathering for client firms, and put what is known about a supplier&#8217;s risk and compliance into a single, updated, easy-to-understand format. Most leaders in the room seemed to use scorecards, but few seemed particularly happy with what they were getting out of them. And the CISO at the firm who has a competitor with a similar business name was certainly not a fan.</p>
<blockquote><p>   &#8220;We get called after a competitor gets breached, because we&#8217;ve got a similar name &#8211; and then we get scores that aren&#8217;t for us, because the [scorecard vendors] are following the wrong firm,&#8221; they said. &#8220;It puts us at risk. We have people who say that our score will affect our contract, but they&#8217;re following the wrong firm. We have to tell them who we are and what [standards and certifications] we&#8217;ve got, because if we don&#8217;t, they&#8217;ll get the wrong picture.&#8221;</p>
<p>&#8220;Do you not think you need to change the name of the business?&#8221; one wag asked, cheekily.</p>
<p>&#8220;We did!&#8221; came the resigned reply.</p>
<p>&#8220;This is an interesting point,&#8221; Dellow said. &#8220;People are trying to monitor their suppliers but they don&#8217;t necessarily have the right tools or resources to do it accurately.&#8221;</p>
<p>&#8220;They&#8217;re chasing the minimum,&#8221; one leader argued. &#8220;They&#8217;re using scorecards to monitor the supply chain, and getting it wrong.&#8221;</p>
<p>&#8220;I&#8217;m sorry,&#8221; another attendee responded, &#8220;but that&#8217;s their problem.&#8221;</p></blockquote>
<p>Maybe, others acknowledged. However, as the security leader at the firm with the similarly named competitors noted: &#8220;It becomes ours.&#8221;</p>
<p>Dellow had some optimism to offer to this beleaguered CISO, and to any others who may find themselves in similar situations.</p>
<blockquote><p>   &#8220;We help end to end, and we come across companies like yours all the time,&#8221; she said. &#8220;The business will go out, pop a domain name in [to the scorecard system], not even validate that it&#8217;s the correct one. That shouldn&#8217;t be down to you to resolve, but it comes up again and again. The questionnaire [responses represent] very much a fixed point in time, so these tools do provide something; there is some value. But, a), it doesn&#8217;t flag if it&#8217;s the correct domain, and b) doesn&#8217;t tell you how the score is relevant to the service that provider supplies to you. That relationship between you and the vendor is unique. If we rely too much on these scores &#8211; just like if we rely too much on the questionnaires &#8211; there will be problems.&#8221;</p></blockquote>
<h4><strong>How Hard Is It?</strong></h4>
<p>There is clearly much dissatisfaction, both with the tried-and-tested traditional questionnaire-based method of gathering an informational baseline about supplier security and compliance, and with some of the additional tools and techniques that have been developed to try to help expand upon that. Clearly there is a widespread need for something that goes beyond these most prevalent of extant approaches. Diligent believe they have a compelling product set to help the many businesses clearly struggling in this area, but talking about it, their staffers said, is a necessary, and positive, first step.</p>
<blockquote><p>   &#8220;We&#8217;re trying to solve those issues we&#8217;ve been circling round tonight,&#8221; Ryan said. &#8220;We built a platform that allows customers to monitor lots of different sources every minute, every day. Scorecards, but also the dark web, news forums &#8211; any place that could point to stress that would bring risk to your business. And then building a risk profile. We&#8217;re getting you to the point where you continuously monitor many, many different sets of data, and we help you proactively manage and mitigate risk.&#8221;</p></blockquote>
<p>As to where these approaches may lead in the future, the discussion, Farrell said, had proved instructive.</p>
<blockquote><p>   &#8220;One of the most interesting things said here was that AI has helped,&#8221; he said. &#8220;I&#8217;m very critical and dubious about it, but I liked how we heard that it has got other groups within the business involved. The importance of the rest of the business being involved in third-party risk management &#8211; of it not just being a security problem &#8211; is vital. You need interest from the board, and if it&#8217;s just a security problem you don&#8217;t get resources, so we end up with it being just questionnaires.&#8221;</p>
<p>&#8220;It&#8217;s clear no one approach works for everyone,&#8221; Dellow summed up. &#8220;We might all have similar roles, but we&#8217;re all in different businesses with different strategies. We&#8217;re all reliant on suppliers, and the questionnaires all look very different. And the risks are very different. We see more and more organisations looking to explore transparency on data provided, and how it&#8217;s validated. There are number of different ways of doing that but as we all grow and scale up it becomes more complex. Ultimately, you have to identify your biggest challenges, and how you can address them. We&#8217;d be more than happy to show you how we can help, but also to share what we&#8217;re hearing from other customers. We&#8217;re always happy to help connect the dots.&#8221;</p></blockquote>
<p>The post <a href="https://rantcommunity.com/resources/time-to-settle-the-score-why-your-tprm-strategy-needs-more-than-questionnaires-and-tick-boxes/">Time To Settle The Score: Why Your TPRM Strategy Needs More Than Questionnaires And Tick-Boxes</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Damage limitation mode engaged: How CISOs are managing agentic AI, one control at a time</title>
		<link>https://rantcommunity.com/resources/damage-limitation-mode-engaged-how-cisos-are-managing-agentic-ai-one-control-at-a-time/</link>
		
		<dc:creator><![CDATA[Galena]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 09:48:15 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[Mimecast]]></category>
		<guid isPermaLink="false">https://rantcommunity.com/?p=3231</guid>

					<description><![CDATA[<p>There was a time when insider threats moved at the speed of humans. When they were centred around relatively predictable</p>
<p>The post <a href="https://rantcommunity.com/resources/damage-limitation-mode-engaged-how-cisos-are-managing-agentic-ai-one-control-at-a-time/">Damage limitation mode engaged: How CISOs are managing agentic AI, one control at a time</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>There was a time when insider threats moved at the speed of humans. When they were centred around relatively predictable individuals. And attribution and intent were fairly easy to discern. Unfortunately for CISOs, that era is fast receding. The one that comes to replace it will be more chaotic, more complex and potentially more dangerous.</p>
<p>Today, AI agents dominate discussion of insider risk. They’re unpredictable, resourceful and move at machine speed. Just witness the growing roll call of sandbox escapes and rogue attacks by frontier AI systems. If left unmanaged, the technology could open the door to significant financial, reputational and regulatory risks.</p>
<p>So what’s the answer? To find out more, Mimecast recently brought together a bunch of harried cybersecurity leaders for another fascinating RANT roundtable.</p>
<blockquote><p>“What we don’t know is the real challenge. Our ability to understand and visualise the data, have orchestration around data in motion, and know which humans are tethered to which agents,” argued Mimecast SVP EMEA, James Morgan. “Where is the balance between security and productivity? We want to make sure security teams don’t continue to have that reputation of blocking everything.”</p></blockquote>
<h4><strong>The bane of our lives</strong></h4>
<p>It was pretty clear from the outset of the discussion that there are no easy answers. One CISO described agentic AI as “the bane of my life”. Another admitted: “we’re in damage limitation mode”. A third said: “I’ve given up trying to pretend I know what’s going on.” Yet another attendee noted how difficult it is to “convey risk to stakeholders” when IT is often one step behind the business in understanding the scale of adoption across the enterprise.</p>
<p>Several CISOs round the table bemoaned this lack of visibility. How can security leaders be expected to manage the risks associated with agentic AI when they don’t even know the size of the problem? One government security boss estimated that there may be as many as one agent per employee, across a department of 18,000 workers.</p>
<blockquote><p>“My concern is we’re allowing it to create policy,” he said. “Would we be able to switch it off? We are watching from a distance as the world allows this thing to get out of control.”</p></blockquote>
<p>The risk is far from theoretical. One CISO explained that his team is already seeing advanced prompt injection attacks where threat actors are hiding malicious instructions in emails read by agents. Part of the risk stems from “permissions given to agents irresponsibly”, he argued. But it’s also down to attacker sophistication.</p>
<blockquote><p>“You think you have guardrails in place, but a clever chain of prompting can circumvent them,” he warned. “The prompts can be constructed in such a way that they create a narrative, spinning a story to the AI that works.”</p></blockquote>
<h4><strong>A message to vendors: step up or get lost</strong></h4>
<p>Threat actors should therefore take some of the blame for agentic AI risk. But the most ire on the night was reserved for the vendor community. Security leaders were particularly displeased at third-party SaaS products with AI baked in.</p>
<blockquote><p>“We have SaaS tools that look innocuous, but then vendors introduce AI capabilities we weren’t aware of,” said one. “You do your risk assessment but then it’s added at a later date.”</p></blockquote>
<p>The message was loud and clear: vendors must be more transparent about the AI they build into products, and pure-play AI makers must take on more responsibility for the security of their offerings.</p>
<blockquote><p>“They need to apply guardrails out of the box,” said one CISO. “I get that they want to push the envelope [with features]. But they’re effectively asking us to create guardrails. There needs to be a joint level of responsibility.”</p></blockquote>
<p>Another argued: “They often say ‘we don’t switch anything on by default because we don’t know your organisation. Well, they need to reconsider what is the default.”</p>
<p>Many were frustrated at the lack of industry regulation and accountability for frontier model makers. “There’s a big elephant in the room,” said one. “The guys who created the models haven’t created the guardrails.” However, a peer sitting opposite admitted that the tech is moving so fast that it’s almost impossible for regulators to keep up.</p>
<h4><strong>Just one more thing</strong></h4>
<p>Ever the optimist, Mimecast CMO, Adenike Cosgrove, asked the assembled cybersecurity leaders to name a single action they’re taking to secure AI.</p>
<p>Some said they have AI champions in their organisation that help to disseminate knowledge and best practice internally. Another claimed she has blocked all shadow deployments “so we know exactly how many agents we have”. A third said his team has put in place governance frameworks to slow down adoption and “arrest the proliferation of AI so we can address it”.</p>
<p>However, governance looks different to different CISOs and in different contexts. Another attendee on the night said they use DLP and allowlisting to manage risks related to LLM-powered chatbots. But that for the agents used by development teams it’s about focusing on permissions. And for third-party SaaS they use procurement as a way to move governance and risk management upstream.</p>
<blockquote><p>“You should be tracking usage rather than the tools themselves,” he said. “If use changes, it needs to go back through the approval process.”</p></blockquote>
<p>Yet another CISO said she’s putting more effort into explaining to the company the “what and why” of AI so business users better understand the risks. “Awareness and education is sometimes overlooked, but it’s so important,” she argued.</p>
<h4><strong>Rotting our brains and corrupting our youth</strong></h4>
<p>The night ended with a lengthy detour into whether AI is slowly eroding our attention span and critical thinking skills. Millennials squared off against Gen Z-ers. But bubbling under the surface was a tension familiar to most CISOs: if an organisation becomes too dependent on a specific technology, it is more exposed to potential failure, compromise or disruption.</p>
<blockquote><p>“What happens when AI is no longer a choice but is fully integrated everywhere?” asked one CISO. “We’re already there,” replied another fatalistically.</p></blockquote>
<p>It was left to Cosgrove to round off the discussion on a more positive note by explaining how vendors can help.</p>
<blockquote><p>“Someone has to enable an agent, put data into an LLM, or leverage a SaaS app,” she said. “We can tell you who’s doing what with AI, and how data is flowing through it.”</p></blockquote>
<p>That’s as good a foundation for effective governance as any, as we enter a new era of agentic risk.</p>
<h4>Mimecast secures humans, data &amp; AI to protect your work. To learn more, head to <a href="https://www.workprotected.com/" target="_blank" rel="noopener">www.workprotected.com</a></h4>
<p>The post <a href="https://rantcommunity.com/resources/damage-limitation-mode-engaged-how-cisos-are-managing-agentic-ai-one-control-at-a-time/">Damage limitation mode engaged: How CISOs are managing agentic AI, one control at a time</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Caught in the headlights: how can CISOs manage a problem like agentic AI?</title>
		<link>https://rantcommunity.com/resources/caught-in-the-headlights-how-can-cisos-manage-a-problem-like-agentic-ai/</link>
		
		<dc:creator><![CDATA[Galena]]></dc:creator>
		<pubDate>Mon, 21 Sep 2026 09:08:53 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[RecoAI]]></category>
		<guid isPermaLink="false">https://rantcommunity.com/?p=3221</guid>

					<description><![CDATA[<p>CISOs have been managing a continually shifting technology landscape all their careers. It comes with the territory. But few could</p>
<p>The post <a href="https://rantcommunity.com/resources/caught-in-the-headlights-how-can-cisos-manage-a-problem-like-agentic-ai/">Caught in the headlights: how can CISOs manage a problem like agentic AI?</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>CISOs have been managing a continually shifting technology landscape all their careers. It comes with the territory. But few could argue that the speed of AI’s rise has been dizzying for many in the industry. <a href="https://www.pwc.co.uk/services/alliances/insights/real-change-agents-reimagining-business-with-agentic-ai.html">PwC reckons</a> 61% of CEOs are actively investing in the technology today, although the real figure is likely to be higher. Now the next stage in AI’s inexorable advance is here, and it’s making security leaders nervous.</p>
<p>Several of them gathered together for a RANT roundtable recently to discuss all things agentic AI.</p>
<blockquote><p>“I don’t think there’s a bigger, more impactful mainstream problem,” said Bob Horn, CRO of our hosts for the evening, Reco. “We’ve seen a lot of technology shifts, but I don’t think we’ve seen one move this fast with this much uncertainty for the world.”</p></blockquote>
<p>Horn opened proceedings by describing the three different ways that CISOs are responding to this disruption. First is the security leader who says, “I’m too old for this” and refuses to change. Second is the CISO who mistakenly believes that their current playbook will still be effective in managing agentic AI risk. And third is the one who understands that people, process and technology must change.</p>
<h4><strong>Can someone please turn the lights on?</strong></h4>
<p>Fortunately, no cybersecurity leaders around the table seemed to fall into the first category. Their mere attendance was proof of that. But there was a certain amount of despair on show at the speed, scale and complexity of the challenge.</p>
<p>Our speaker for the evening, IP Finance International CISO, Nick Jones, bemoaned the fact that cyber leaders increasingly seem out of the loop.</p>
<blockquote><p>“We have unsupervised interns; AI agents in charge of AI agents. It’s shadow IT on steroids,” he argued. “I need an inventory and I need visibility. I need the lights turned on.”</p></blockquote>
<p>Others agreed that visibility is a key challenge as agents begin proliferating in the enterprise. “We have internal AI, external AI and no doubt there’s shadow AI too,” said one.</p>
<p>Several others expressed alarm that the business is moving too quickly, but also that blocking their projects outright is not an option.</p>
<blockquote><p>“The problem is we’re back to the old days of the ‘department of no’,” said one. “We’ve become the speed bump again and that’s a difficult PR thing to manage.”</p></blockquote>
<h4><strong>Overprivileged and over here</strong></h4>
<p>Various views were shared as to why agentic AI poses such a threat to organisations. They boil down to: visibility, identity and connectivity. Reco’s Horn suggested that there may be tens of thousands of agents running in an enterprise, but only a small number have access to sensitive environments. That makes tracking and managing everything critically important. “Every agent could be a crown jewel,” he argued.</p>
<p>Others aired concerns about over-privileged agents, unmanaged plugins, and the potential for autonomous machines to cause irreversible damage.</p>
<blockquote><p>“The attack vectors haven’t fundamentally changed. It’s the speed and broadening of the attack surface that have,” said one CISO. “They can be profoundly dangerous if we don’t manage what they’re capable of doing.” Another agreed that the velocity of change is causing sleepless nights. “We’re not prepared for the aftermath,” they warned.</p></blockquote>
<p>One CISO raised a red flag over MCP. Having just got a handle on securely managing the organisation’s APIs, he fretted that the protocol could open up a new attack surface and route to data exfiltration.</p>
<h4><strong>Where resilience meets regulation</strong></h4>
<p>Several attendees shared their anxieties over regulatory scrutiny, and how the complexity of agentic environments makes it difficult to answer auditor’s questions.</p>
<blockquote><p>“They’ll ask you a simple question like ‘can you see what’s doing what?’ But you’ll need to connect to 25 different systems to give them an answer,” said one CISO.</p></blockquote>
<p>IP Finance International’s Jones explained that regulators are looking for better governance and monitoring; the latter because “guardrails you use today may need to look different tomorrow”. However, if those controls are too rigorous, “people will just work around them”, argued another attendee.</p>
<p>Others were sceptical about whether regulators are even sufficiently clued up to know what questions to ask.</p>
<blockquote><p>“Regulators want to address AI and quantum but they’re struggling with how they keep pace,” said one CISO. “The speed of regulation is actually slowing.”</p></blockquote>
<p>However, that doesn’t mean companies will be let off the hook. Jones confided that a recent regulatory letter had been “quite punchy”. He added: “they might not know what they’re looking for but they’re coming.”</p>
<p>As agentic projects expand, resilience is likely to be top of the agenda for auditors, Jones continued. Others around the table sounded the alarm around similar themes &#8211; such as what happens if critical business services come to rely on agents, but then underlying models change or are replaced by vendors.</p>
<h4><strong>Back to basics, to the future</strong></h4>
<p>Despite the general wringing of hands, some CISOs were bold enough to suggest some approaches to securely managing the growing agentic fleet in many enterprises. One advocated a “back-to-basics” approach, acknowledging that agentic AI amplifies existing risks rather than creates new ones.</p>
<blockquote><p>“In the cloud identity is everything-it’s your perimeter-and I think with AI it’s the same,” he said. “Fundamentally we need to go back to basics. Get your hygiene; sort your IAM.”</p></blockquote>
<p>However, Reco’s Horn pointed out that there are “toxic combinations” that may complicate this approach, citing the challenge of managing connected AI systems such as Copilot and Agentforce. In this way, one AI could expose data associated with another to attackers if not properly configured.</p>
<p>Others suggested a human in the loop was a useful approach, although some attendees warned that we’re fast approaching a time when the sheer volume of data and decisions presented to humans may make such a model unworkable.</p>
<p>Which brings us back to Reco’s Horn, who ended proceedings with a checklist for CISOs to work through. As a starting point, they need to understand what they have, who’s using it, what it’s connected to and what it’s doing, he said. Then comes the hard part: figuring out what to do about it.</p>
<p>As tough as today’s agentic environment is to manage, CISOs must also think about what’s coming down the track. “This is not a destination, this is a journey,” Horn concluded. “You’ve got to catch up. And whatever vendor you choose; buy for the future as well as the present.”</p>
<p dir="ltr"><span class="x_561081196highlight"><span class="x_561081196colour"><span class="x_561081196font"><span class="x_561081196size">See every agent. Know what it can reach. Fix the risk before it becomes an incident.</span></span></span></span></p>
<p dir="ltr"><span class="x_561081196highlight"><span class="x_561081196colour"><span class="x_561081196font"><span class="x_561081196size">Reco discovers every agent and identity across your environment, scores real risk instead of raw alert volume, and remediates by routing findings, scoping access, and revoking what shouldn&#8217;t exist. One platform, complete agent security. Demo Reco today [<a href="https://www.reco.ai/demo-request" target="_blank" rel="noopener">https://www.reco.ai/demo-request</a>]</span></span></span></span></p>
<p>The post <a href="https://rantcommunity.com/resources/caught-in-the-headlights-how-can-cisos-manage-a-problem-like-agentic-ai/">Caught in the headlights: how can CISOs manage a problem like agentic AI?</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Back To The Old School? Why Mapping Your Ancient Active Directory Might Be The Best Way Of Disrupting Novel Threats</title>
		<link>https://rantcommunity.com/resources/back-to-the-old-school-why-mapping-your-ancient-active-directory-might-be-the-best-way-of-disrupting-novel-threats/</link>
		
		<dc:creator><![CDATA[Galena]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 10:53:49 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[SpecterOps]]></category>
		<guid isPermaLink="false">https://rantcommunity.com/?p=3216</guid>

					<description><![CDATA[<p>Speed is an intriguing concept when we&#8217;re talking about cybersecurity. Firstly, whose pace should we be most concerned about? Is</p>
<p>The post <a href="https://rantcommunity.com/resources/back-to-the-old-school-why-mapping-your-ancient-active-directory-might-be-the-best-way-of-disrupting-novel-threats/">Back To The Old School? Why Mapping Your Ancient Active Directory Might Be The Best Way Of Disrupting Novel Threats</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Speed is an intriguing concept when we&#8217;re talking about cybersecurity. Firstly, whose pace should we be most concerned about? Is it the developers of new business-enabling digital tools, and the rate at which they go from being nice-to-haves to business-critical technologies? Is it the alacrity with which the organisation&#8217;s leaders rush to embrace developments that promise to enhance productivity and profitability, regardless of their impact on data security? Is it the breathless dashes through defences that attackers increasingly seem able to make, and how fast they can move laterally within the organisation&#8217;s carefully structured information silos? Or is it all of that and more &#8211; the relentless, unceasing waves of change, the ebb and flow of risk, and the fact that the average CISO has no means whatsoever of slamming on the brakes even if they knew which bit they wanted to try to slow down?</p>
<p>Sometimes, it seems, the best way to disrupt the most furiously focused and speed-enhanced attacks might be to return to some of the forgotten corners of the corporate network and take some time &#8211; not loads of it, either &#8211; to understand exactly what&#8217;s going on. This was the perhaps paradoxical lesson that leaped out of a recent RANT roundtable held in London where a selection of harried senior cybersecurity leaders engaged in a lively discussion with staff from SpecterOps. The company, which offers a wide range of security consultancy services, including Red Teaming and penetration testing, as well as the open-source and enterprise versions of a tool called BloodHound, has extensive experience working with some of the most demanding and technologically advanced organisations in the world.</p>
<p>When SpecterOps lets BloodHound off the leash in a large business, it romps through the active directory and worries away at the problem. It produces a graph, showing the myriad ways an attacker could move laterally, vertically and undetectably through the nodes of an organisation&#8217;s network. How shall they Pwn thee? BloodHound counts the ways. In one recently mapped financial-services giant &#8211; around four billion viable pathways that an attacker could use to reach the crown jewels. BloodHound doesn&#8217;t fix anything &#8211; but it shows users the pathways attackers could use, enabling network defenders to dynamite the road underneath an adversary&#8217;s digital army and deny them access to what they&#8217;re seeking.</p>
<h4><strong>Turbo Charged</strong></h4>
<p>In those businesses with huge numbers of attack paths, not only will many pass through the active directory, but most will be faster to travel down in organisations which give largely free rein for so-called &#8220;AI&#8221; agents to operate without direct human oversight or instruction. So it was little wonder that AI should surface very early in the evening&#8217;s discussion, as the advent of machine-speed automated tools has raised the stakes in identity and access control circles.</p>
<blockquote><p>   &#8220;We&#8217;ve got an early ringside seat to AI,&#8221; Mark Wilson, SpecterOps&#8217; senior sales engineer, told the gathering. &#8220;We&#8217;re building cyber ranges for Open AI, Anthropic, the UK AI institute. We&#8217;ve got access to models that haven&#8217;t been released yet. So we&#8217;ve had a lot of early insight into what that means.&#8221;</p></blockquote>
<p>Largely, what it means is that everything &#8211; for good, or for ill &#8211; is happening faster.</p>
<blockquote><p>   &#8220;The principle of assume-breach has moved to a point of certainty &#8211; we&#8217;ve absolutely seen that,&#8221; he continued, referring to the mindset advocated in hitherto forward-leaning companies, to forget about keeping attackers out, and work out how to deal with them once they get inside. &#8220;The other thing is machine-speed lateral movement. All the high-profile companies who&#8217;ve been compromised in the last few months, they all have the latest EDR, they have their own SOC, 24-7 monitoring, and they still got hit really quickly.&#8221;</p></blockquote>
<p>And this, he noted, is &#8211; if not always because of; but certainly increased by &#8211; the ways agentic AI systems work. To properly benefit from the machine-speed enhancements these tools and technologies promise, a business has to allow them to not just create and deploy agents autonomously: but to ensure that those agents are given access to the other parts of the system they need in order to carry out their promised functions. Even if a tool is working entirely benignly, and only carrying out the tasks its makers and users intend, the knock-on effect on access management is profoundly unsettling. New identities, created by automatic processes, authorised to access disparate parts of the corporate infrastructure, and not just operating but being created without any awareness from the security teams &#8211; it drives the proverbial coach and horses through most organisations&#8217; access-management processes. And once those are disrupted, disturbed, destroyed, then attackers will find it far easier not just to get in &#8211; because we know that they&#8217;re going to get in anyway &#8211; but to operate inside the enterprise without much danger of being discovered, never mind ejected.</p>
<blockquote><p>   &#8220;The thinking needs to change,&#8221; Wilson said. &#8220;The reason adversaries use identity is because it&#8217;s very difficult to pick up a signal you can respond to. We take the approach of not trying to have that fight. We change the focus. Our red team don&#8217;t use a single vulnerability, ever. It&#8217;s the quickest way to get picked up.&#8221;</p></blockquote>
<h4><strong>Get Into Something</strong></h4>
<p>There were those in the room who seemed to still cling to the hope that some form of machine-speed agentic responses may help solve this burgeoning identity crisis. Though even those who voiced these thoughts did so in a way that implicitly acknowledged the almost magical thinking &#8211; or belief in the supernatural &#8211; that perhaps lies behind them.</p>
<blockquote><p>   &#8220;For me, if I had a magic wand&#8230;&#8221; one CISO began, before essaying a different analogy.</p>
<p>&#8220;Imagine you have a house and you keep building it,&#8221; they posited. &#8220;You keep on adding extensions. And if I want to know whether it leaks, I pour water over the top, and I see where it comes out. If I transfer that idea to IT, this is the policy area we&#8217;re supposed to be in. I&#8217;d love to have an AI agent based on that. Regardless of any access privileges, what should we have access to? The agent could help you determine which people shouldn&#8217;t have access, all based on the policy. So what I&#8217;m looking for, one day, is an application that can do that. Whether an identity is coming from AI, an API, a misconfiguration, won&#8217;t matter &#8211; if says you shouldn&#8217;t have access, so you don&#8217;t have access.&#8221;</p></blockquote>
<p>Reactions to this proposal were ruminative, respectful, and reflective. But there was little sign of anyone in the room sharing any sincere belief that such a tool might soon exist.</p>
<blockquote><p>   &#8220;If you take away the hype around the Open AI breakout and the Hugging Face debacle, all this is about behaviour,&#8221; one security leader said. &#8220;Will we really be able to rely on policy when agents will work together, and find ways of circumventing policy? And will we ever get to a policy that&#8217;s that granular? When you&#8217;re issuing policies, a human is still making a decision about what&#8217;s right or wrong. You can set technical policy guardrails, but when you give an agent an objective, it&#8217;ll work out how to get around them.&#8221;</p>
<p>&#8220;Agents don&#8217;t have the context,&#8221; said another leader, evidently struggling to balance optimism and cynicism but giving it a good go. In response to another attendee, who had noted that, in most contexts, access is conditional, this leader agreed: but wasn&#8217;t convinced this would ultimately make much difference to the challenges posed by agentic systems. &#8220;If you look at policy without conditions you&#8217;re probably playing 3D chess,&#8221; the suggested. &#8220;And the machine will be better at playing it than you are.&#8221;</p></blockquote>
<h4><strong>Going Way Back</strong></h4>
<p>Perhaps, other attendees mused, the conversation &#8211; as so many in cybersecurity at the moment &#8211; had become dominated by AI concerns, when the nub of the matter was something more fundamental and less troublingly novel.</p>
<blockquote><p>   &#8220;We talk a lot about AI, but users are far better at circumventing things than agents,&#8221; they argued. &#8220;Of our top 100 users who are using things they shouldn&#8217;t, they&#8217;re not using AI to do them &#8211; they&#8217;re using platforms. Our backup has been around for so long, and no-one&#8217;s found a better solution. The requirement hasn&#8217;t changed, but the products haven&#8217;t matured. Some organisations now are looking at completely de-coupling identity [and considering it as] a completely separate layer: with the identity enabled for the service.&#8221;</p>
<p>&#8220;When we talk about policy and zero-trust, those are what we think we&#8217;ve applied permissions to,&#8221; Wilson said. &#8220;We think of them as vertical silos &#8211; and when you look at them in a silo, they&#8217;re alright. But there&#8217;s integrations; and you move laterally through them. When you think about those silos, there are going to be collisions. When we&#8217;ve compromised clients, it&#8217;s where we&#8217;ve moved things over. The attacker lives in that space, and they don&#8217;t care about governance or policy.&#8221;</p></blockquote>
<p>It&#8217;s a recipe for, if not disaster, then something seriously unappetising, as Wilson&#8217;s colleague, Europe, Middle East and Africa region sales director Colin Makin, pithily put it.</p>
<blockquote><p>   &#8220;It&#8217;s like cooking,&#8221; he said. &#8220;You can have the very best ingredients, but the meal may still end up being terrible.&#8221;</p></blockquote>
<p>Stepping away from metaphor, Wilson sketched out a real-world example of how lateral movement through and between vertical silos can be conducted easily by adversaries, with devastating responses. His vignette came from some recent Red Team work with a large software vendor.</p>
<blockquote><p>   &#8220;They said, &#8216;We&#8217;ll give you a Git user account &#8211; do your worst&#8217;,&#8221; he recalled. &#8220;Their expectation was that we&#8217;d quickly get stuck, but that wasn&#8217;t the case at all. Just using that identity we were able to move into the Git repository, elevated our access, and within a short space of time, finding stuff that had been forgotten about, we&#8217;d gained control of their tenant and could have compromised 5,000 other organisations through a supply-chain attack. The reason we could do that is because everyone&#8217;s thinking about a least-privilege model. But the attacker&#8217;s mindset is: &#8216;If you give a non-human identity or an agent Slack access, what can it get to through those channels?'&#8221;</p></blockquote>
<h4><strong>Cold Gettin&#8217; Dumb</strong></h4>
<blockquote><p>&#8220;I think we&#8217;ve known this is a challenge for a very long time, and we&#8217;re always trying to chip away at it,&#8221; RANT&#8217;s guest host for the evening, Paul Griffiths, CISO of financial data and publishing business Delinean, said in his summation. &#8220;But it&#8217;s been bare bones, almost &#8211; just what we&#8217;ve needed to get through audits. Now, I think it&#8217;s become an insurmountable problem. We&#8217;ve used the old-school approach of doing policy and compliance, and increasingly we&#8217;re moving into activity monitoring. But AI is increasing the identity requirement. This is a real problem, not an invented problem.&#8221;</p></blockquote>
<p>Underlining that assessment, Makin pulled few punches. The companies represented round the room ranged from relatively small to globally significant, yet were all experiencing these problems. None of these entities, he stressed, should feel as though they were on their own in this regard. SpecterOps&#8217; clients include giant firms whose products sit at the heart of the majority of the world&#8217;s digitally enabled businesses, and even <em>they</em> don&#8217;t really know how to respond.</p>
<blockquote><p>   &#8220;Microsoft are one of our biggest customers &#8211; they can&#8217;t solve the problem that AD has created,&#8221; he said. A chilling revelation, met with stunned silence &#8211; but help is at hand, he promised. BloodHound, he said, &#8220;is the cheat code. If your Blue Team uses it, they can get rid of not just the quickest routes, but all the routes.&#8221;</p></blockquote>
<p>SpecterOps issued an open invitation to those around the table: let the firm loose in your active directory for a few hours, and BloodHound will lead your business to the sunlit uplands of cybersecurity heaven. Well, maybe not exactly &#8211; but they&#8217;ll at least promise to point you on your way.</p>
<blockquote><p>   &#8220;If you want to know how big the problem is, rather than taking the narrow view &#8211; this is what we do,&#8221; Wilson said.</p>
<p>&#8220;Give us the lowest identity possible, and an hour and a half, and we&#8217;ll show you how many attack paths you&#8217;ve got,&#8221; Makin added.</p>
<p>&#8220;If you want to find out what the risk looks like,&#8221; Wilson said, &#8220;let us know.&#8221;</p></blockquote>
<p>The post <a href="https://rantcommunity.com/resources/back-to-the-old-school-why-mapping-your-ancient-active-directory-might-be-the-best-way-of-disrupting-novel-threats/">Back To The Old School? Why Mapping Your Ancient Active Directory Might Be The Best Way Of Disrupting Novel Threats</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Don&#8217;t Fear The Future: How To Prepare For The Post-Quantum World</title>
		<link>https://rantcommunity.com/resources/dont-fear-the-future-how-to-prepare-for-the-post-quantum-world/</link>
		
		<dc:creator><![CDATA[Galena]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 09:10:29 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[One Intelligence]]></category>
		<guid isPermaLink="false">https://rantcommunity.com/?p=3157</guid>

					<description><![CDATA[<p>You&#8217;ve got to feel for the average (or even the well-above-average) cybersecurity leader. Assailed from all sides by threat actors</p>
<p>The post <a href="https://rantcommunity.com/resources/dont-fear-the-future-how-to-prepare-for-the-post-quantum-world/">Don&#8217;t Fear The Future: How To Prepare For The Post-Quantum World</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>You&#8217;ve got to feel for the average (or even the well-above-average) cybersecurity leader. Assailed from all sides by threat actors turbocharged and enabled by large language model so-called &#8220;AI&#8221; tools, expected to achieve perfect defence of the enterprise and its crown-jewel data even against first-of-a-kind or hitherto unforeseeable attacks, they also have to ensure the company complies with a plethora of different security standards and, depending on the industry, state-mandated regulations. Like everyone else in the enterprise, they&#8217;re used to being told to &#8220;do more with less&#8221;, but to make matters worse, whenever they go to the board to ask for more money for tooling they believe is essential to carry out these missions successfully, they have a total absence of the definitive metrics that would help them make a business case &#8211; because in security, your most important statistic is the zero in the box that tallies the number of incidents the company has experienced.</p>
<p>So you could forgive the cyber leadership cohort if they&#8217;d maybe not got much remaining bandwidth to spend time planning for notional threats that may arise a year or two down the line. But the coming post-quantum world &#8211; in which quantum chips arrive in the commercial realm, exponentially increasing the computational power available to all kinds of miscreant, and in the process obliterating the encryption that secures data, connections and identities &#8211; is the kind of existential threat that no prudent security manager can afford to ignore. Even postponing thinking about it could leave CISOs open to criticism that they&#8217;d been guilty of dereliction of a core duty.</p>
<p>This is no idle concern. Today&#8217;s encryption standards are not based on perfect mathematical solutions, but on making the mathematical problems encryption relies on too difficult to solve using current computing capability. Quantum chips will reduce the time that would be required to solve those problems from centuries to seconds &#8211; meaning not only that access controls cease to provide any protection, but also that encrypted documents that might have been stolen in the past can be opened and read in the future.</p>
<p>But the post-quantum threat is difficult enough to wrap your head around even if you&#8217;re comfortable thinking about encryption, keys and quantum computing theory. Explaining to the board why they need to devote time, internal resource, and &#8211; likely &#8211; significant money <em>right now</em> to addressing a problem that may not start to bite for a few years is another matter entirely.</p>
<p>This, though, is where startup One Intelligence have decided to park their tanks. The company, founded by mathematicians and cryptographers, reckons it has a solution that will quantum-proof businesses, with minimal downside, no new kit, and no specialist cryptographic knowledge needed. And in the process, it will also solve some of the biggest challenges that are already being faced by networked businesses, and which are already understood &#8211; and budgeted for &#8211; by responsible corporate leaderships.</p>
<p>After deciding they were ready to emerge from stealth mode, the newly de-cloaked One made their first public pitch to cybersecurity professionals via a RANT roundtable held in London in mid-July. The ensuing discussion proved eye-opening, sobering and &#8211; perhaps &#8211; encouraging, in more or less equal measure.</p>
<h4><strong>Severed Crossed Fingers</strong></h4>
<blockquote><p>&#8220;I&#8217;d like to ask you, as we go through this tonight, that if you only remember one thing, it would be trust,&#8221; Brett Nakfoor, One&#8217;s global vice president of sales and marketing, said at the outset. &#8220;How do you solve for quantum, ransomware and AI attacks? Trust. We decided to solve the problem of quantum security &#8211; and we did, with a new class of math. We can mathematically prove that we can prevent quantum-computer and AI attacks. We are provably secure.&#8221;</p></blockquote>
<p>Just as importantly, Nakfoor added, the solution One have come up with can be quickly and easily integrated into existing technology stacks and will not require customers to spin up new departments of specialist mathematicians, cryptographers or quantum experts to be able to successfully deploy it and manage it.</p>
<blockquote><p>   &#8220;We found out, luckily, that with this new math we could create a solution at the transport layer,&#8221; he explained. &#8220;Instead of putting security in afterwards, we decided to invert that. You can put more information into a packet, and deliver it all the way up from the transport layer &#8211; layer 3 &#8211; up to the human layer &#8211; level 7. But we&#8217;re all adding an eighth layer now &#8211; the AI agents.&#8221;</p></blockquote>
<p>One&#8217;s concept solves that problem, too, Nakfoor said. The solution allows the user to &#8220;embed trust objects into an interaction before it starts,&#8221; he added.</p>
<blockquote><p>   &#8220;This opens up a whole new world of how you deliver solutions to your business,&#8221; he said. &#8220;What we&#8217;re positing is that we&#8217;ve commoditised the delivery of quantum security in our delivery of the software, and you can control all forms of AI in doing that. That&#8217;s a bold statement, but we&#8217;re happy to answer questions &#8211; and if you want to give us real-world examples, we&#8217;ll talk about how we can help fix them.&#8221;</p></blockquote>
<p>What followed was an absorbing exercise in just that &#8211; as a high-level group of CISOs, BISOs and other senior security leaders outlined their current concerns and future fears, and, either directly or by implication, sought to discover how the One proposition might help them realign their businesses for this coming new world.</p>
<h4><strong>Pay Your Way In Pain</strong></h4>
<p>Rob Black, RANT&#8217;s host for the evening, opened up the discussion by asking attendees to describe the issues that were top-of-mind for them about post-quantum security. These early exchanges ran the gamut between immediate worries and long-term headaches, but also surfaced some scepticism over the extent to which specific companies or sectors might be exposed to certain dangers. As so often in cybersecurity, some argued, these ostensibly new and novel concerns may well just serve to remind organisations of the necessity of looking after some long-established basics.</p>
<blockquote><p>   &#8220;We have long-lived data, and shorter-lived data,&#8221; one security leader began. &#8220;If it&#8217;s only relevant and used for a short time then that&#8217;s OK &#8211; but we don&#8217;t have a solution for securing that long-lived data. We know we have to figure it out, but we don&#8217;t know how yet. And we don&#8217;t know how to work out how long that data might be of value to somebody.&#8221;</p>
<p>&#8220;We&#8217;re tackling that question as well,&#8221; another attendee said. &#8221; It&#8217;s driven out of historic issues people have around data security. Without a decent understanding of what data you hold, and the metadata associated with it, you&#8217;d have a lot of work to do.&#8221;</p></blockquote>
<p>There was also clear interest in one class of attack that, in a way, defies the passage of time. A patient attacker, able to identify data with a long useful lifespan, could steal or copy encrypted files now, and wait until quantum technology is available, and then decrypt it. Even businesses that may consider themselves to have little information that falls into that category may still have to consider it, as a third leader, whose company manufactures specialist physical devices, noted.</p>
<blockquote><p>   &#8220;Our own products are very cutting-edge technology &#8211; so we don&#8217;t have a massive issue [with harvest-now/decrypt-later] because the pace of change is very rapid: one of today&#8217;s blueprints, by the time you&#8217;ve figured out what to do with it, we&#8217;ve moved on,&#8221; they said. &#8220;However, our customers may take a different view. If they need to maintain their blueprints, those need to be retained securely for a very, very long time. So the data we collect for our customers is very important. And the moment you lose trust, the whole model evaporates.&#8221;</p></blockquote>
<h4><strong>Hell Is Near</strong></h4>
<p>The issue of organisational or institutional awareness was also front-and-centre of mind for many in the room. Some felt the problem would be addressed in time, because a sense of urgency would emerge at corporate decision-making levels before too long, but organisations which tend to wait until they&#8217;re forced to change might struggle.</p>
<blockquote><p>   &#8220;Constantly having to explain the complexity of cryptography to the organisation is an issue,&#8221; one CISO said. &#8220;I think it&#8217;s an ongoing thing. Post-quantum will get everyone&#8217;s attention, from the CEO down, so everyone will be interested. Education goes hand in hand with it. I&#8217;m lucky enough to have a great crypto manager who manages this for us, but not everyone does. And &#8211; not wishing to tar everyone with the same brush &#8211; quite often those people who are good at crypto aren&#8217;t good at board presentations.&#8221;</p>
<p>&#8220;We&#8217;ve got people whose job is post-quantum, and people who manage crypto &#8211; they understand it really well. But is the organisation ready to understand? No,&#8221; agreed another senior security leader.</p></blockquote>
<p>Black asked those around the table where they felt post-quantum security sat in their own, and their organisation&#8217;s, list of priorities. The first answer was, perhaps, a surprise.</p>
<blockquote><p>   &#8220;I was talking to someone from a regulator,&#8221; this security leader began. &#8220;They said it&#8217;s not a priority for them at the moment. There was a bunch of stuff they said we should be looking at, but they said that this isn&#8217;t in focus at the moment. Now, we don&#8217;t do things just because regulators tell us!&#8221; they laughed. &#8220;But it was an interesting observation.&#8221;</p></blockquote>
<p>That good old favourite non-scientific data-gathering exercise &#8211; a quick show of hands &#8211; revealed that, among those in the room, no organisations currently viewed post-quantum security as their biggest concern, and a majority of those represented in the room worked for businesses which considered the threats posed by AI as their most urgent priority.</p>
<blockquote><p>   &#8220;The board&#8217;s got their hair on fire about it,&#8221; groaned one CISO. &#8220;At the moment, it&#8217;s all: &#8216;What are you doing about Mythos?'&#8221;</p>
<p>&#8220;A lot of board-level individuals can&#8217;t comprehend the impact post-quantum will have, but they can comprehend what AI can do,&#8221; another leader lamented. &#8220;It&#8217;s almost a race to the bottom &#8211; you must be doing better if you&#8217;re burning more tokens. Post-quantum is still abstract for them.&#8221;</p>
<p>&#8220;It won&#8217;t be tangible until someone gets badly burned,&#8221; another agreed.</p></blockquote>
<h4><strong>Digital Witness</strong></h4>
<p>Mo Ali, One&#8217;s CEO, was peppered with questions about what One&#8217;s proposition entailed, how it worked, and where it ought to sit in security teams&#8217; thinking. He stressed that a key challenge has been that, to date, cryptographic standards have relied on the mathematical problems inherent in them being too difficult for current computing capabilities to crack, whereas One&#8217;s approach has been not just to make the maths difficult to solve, but to ensure there is a known solution. Some attendees expressed concerns that, perhaps, One were seeking to alter some of the fundamentals on which current cryptographic solutions are based, but Ali was quick to correct this. The company isn&#8217;t changing anything, he argued: instead, they are &#8220;gluing things together.&#8221;</p>
<blockquote><p>   &#8220;The formal definition of &#8216;hardness&#8217; is the problem,&#8221; he said. &#8220;We say, &#8216;This cipher can&#8217;t be broken because computing is not strong enough,&#8217; then a couple of years later we say it can be broken. We&#8217;re defining post-quantum in a different way to what [U.S.-based standards body] NIST has done, but we&#8217;re still relying on the same fundamentals.&#8221;</p></blockquote>
<p>Expanding on the point, he explained a little further about the approach the firm has taken. The company&#8217;s founders include people with backgrounds in quantitative trading, and some of their approach flows from that world.</p>
<blockquote><p>   &#8220;The quants said we need to rely on math,&#8221; Ali said, &#8220;but in cryptography, we don&#8217;t have quantitative cryptography. We need to know the force required to break it. Mathematically deterministic cryptography is harder, but that’s what we do. For years we&#8217;ve been using 128-bit blocks to encrypt &#8211; that means that the more we encrypt, the larger the keys, and the larger the key-management systems you need. We can encrypt an entire object &#8211; a database, a data centre &#8211; in one go. We made a programmable handshake, and we can embed policies in that handshake. We&#8217;re calling it Generative Trust Infrastructure.&#8221;</p></blockquote>
<p>The terminology is important. Security specialists have long been aware of the concept of Zero Trust &#8211; and how difficult (if not impossible) it is to implement in any complete way. Generative Trust, ask Nakfoor pointed out, solves the problems Zero Trust implies because the &#8220;trust&#8221; element is &#8220;generated&#8221; at the inception, and baked in to the data at the point where it is created. And this means that the solution will work for agents created by AI tools, and every other entity or process, be it human or non-human.</p>
<blockquote><p>   &#8220;Machines have their own language, which is code,&#8221; Ali said. &#8220;Because we come from the high-frequency trading space, we really care about where information pops out for the first time. When it forms, we&#8217;re sitting there. That&#8217;s the intelligence part. You can&#8217;t solve Zero Trust because it&#8217;s assumption-based. We call it Generative Trust, because it&#8217;s generating trust across interactions.&#8221;</p></blockquote>
<p>And by making it programmable &#8211; and easy to program &#8211; the company believes it has a solution not just to the post-quantum challenge, but to a host of current information-security problems, including securing AI systems and combatting ransomware.</p>
<blockquote><p>   &#8220;With a Generative Trust infrastructure, you can program &#8216;This is what I can do with this object&#8217;,&#8221; Nakfoor said. &#8220;If you&#8217;ve sent a document to me, I either obey your instructions [embedded in the document] or it isn&#8217;t usable. We can ensure it&#8217;s sent to the right person: you think you&#8217;re sending to me, but it goes to someone else &#8211; they wouldn&#8217;t be able to open the document because they don&#8217;t have the authorisation.&#8221;</p>
<p>&#8220;What we&#8217;re doing is building the world&#8217;s first foundational crypto model at the transport layer,&#8221; Ali explained. &#8220;It&#8217;s almost like an LLM &#8211; you can communicate with it using a prompt. You can write a command in plain English. If you have an AI at the application layer, and you want to encrypt all your databases, while leaving one cluster alone &#8211; just writing that prompt does it. You can create your own instructions. It controls LLMs in a formal, proofed way. It doesn&#8217;t hallucinate, or have the limits LLMs have. You can use version controlling, and encrypt infrastructure in real time.&#8221;</p></blockquote>
<p>The post <a href="https://rantcommunity.com/resources/dont-fear-the-future-how-to-prepare-for-the-post-quantum-world/">Don&#8217;t Fear The Future: How To Prepare For The Post-Quantum World</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Speak Ya Clout: Straight-Shooting CISOs Trade Real Talk On AI Security With Cisco</title>
		<link>https://rantcommunity.com/resources/speak-ya-clout-straight-shooting-cisos-trade-real-talk-on-ai-security-with-cisco/</link>
		
		<dc:creator><![CDATA[Galena]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 09:30:39 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[Cisco]]></category>
		<guid isPermaLink="false">https://rantcommunity.com/?p=3140</guid>

					<description><![CDATA[<p>Language is important. Understanding depends on having a shared frame of reference, and in a field like cybersecurity &#8211; littered</p>
<p>The post <a href="https://rantcommunity.com/resources/speak-ya-clout-straight-shooting-cisos-trade-real-talk-on-ai-security-with-cisco/">Speak Ya Clout: Straight-Shooting CISOs Trade Real Talk On AI Security With Cisco</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Language is important. Understanding depends on having a shared frame of reference, and in a field like cybersecurity &#8211; littered with acronyms, buzzwords, marketing hype and nerdy tech-speak &#8211; communicating critically important ideas requires practitioners, leaders and rank-and-file members of every organisation to be able to speak clearly to one another if problems are ever going to be solved. And at RANT events, we&#8217;re always keen to encourage plain speaking: the more down-to-earth the words used, the less chance there is of anyone missing the point.</p>
<p>But still, sometimes the community can surprise us. Such was the case with one &#8211; notably droll &#8211; contributor to a discussion convened in Manchester by Cisco, who were keen to hear about the challenges organisations are dealing with around adoption of so-called artificial intelligence. It was very early in the evening, and RANT&#8217;s guest host &#8211; Nnamdi Ozonma, information security officer for the UK and Nordic regions at Bilfinger &#8211; had asked what seemed a fairly innocuous, get-the-ball-rolling question. Among those businesses represented around the table that had chosen to adopt AI tools, did their security leaders feel that the organisation had also adopted suitable controls?</p>
<blockquote><p>   &#8220;We&#8217;re currently in a phase we call &#8216;f&#8212;ing around and finding out&#8217;,&#8221; our admirably relaxed CISO reported. There was, of course, a chorus of barking laughter &#8211; but, just as evident, a widespread sense of rueful identification with the sentiment, even if the rest of the attendees may have phrased the response somewhat differently.</p>
<p>&#8220;It&#8217;s moving so fast, and it&#8217;s so new, that the only way to know how to secure it is to use it and work it out,&#8221; the f-bomb detonator continued. They represented a company with a series of semi-autonomous internal divisions, each able to set its own individual risk-acceptance/risk-avoidance levels, but with one shared security team and a single board overseeing everything. This puts our friend in a somewhat invidious position.</p>
<p>&#8220;The mandate across everything is &#8216;We should use AI and we have to adopt it&#8217;,&#8221; they said of the edicts issued across the organisation by the board. &#8220;It&#8217;s measured, and we&#8217;re trying to put guardrails in place. We&#8217;re letting staff use AI to help with their jobs, but not to export files. To find out how we can benefit, we have to use it.&#8221;</p></blockquote>
<p>This early insight proved to be a key theme of an involving and wide-ranging hour of robust dialogue. How do you securely deploy a technology you can&#8217;t understand the security implications of until after you deploy it? But &#8211; spoiler alert! &#8211; it will come as little surprise to anyone who&#8217;s been watching the AI security picture evolve that even as high-level and highly experienced a group as the baker&#8217;s dozen CISOs, BISOs and other senior security leaders were unable to unpick this particular Gordian knot.</p>
<h4><strong>Who&#8217;s Gonna Take The Weight?</strong></h4>
<blockquote><p>&#8220;There&#8217;s so much enthusiasm from the higher echelons to use it and benefit from it, so experimentation is what we&#8217;re all having to do,&#8221; another security leader agreed. &#8220;But has anyone actually done what you would do if you were carrying out a scientific experiment, which would be to set a hypothesis and then test it?&#8221;</p></blockquote>
<p>Not yet, was the widespread answer. And this revealed another, underlying, potentially more subtly disturbing, conundrum: the benefits of AI deployment are assumed to be so significant that those deployments are not only arriving without tested hypotheses to confirm security, but without even any metrics by which to assess the expected benefits. Board-level FOMO means staff are being encouraged to use AI tools to develop agents to carry out tasks in the hope that benefits will accrue &#8211; but without being given a framework against which success can be measured.</p>
<blockquote><p>   &#8220;I think  the issue at the moment is people have a solution but not a problem,&#8221; another CISO argued. &#8220;There&#8217;s the drive, the push, but the use case isn&#8217;t there. What are we building these agents for? What are the guardrails? What are the outcomes?&#8221;</p></blockquote>
<p>It isn&#8217;t just the benefits that aren&#8217;t quantified yet, either &#8211; the risks, crucially, are often yet to be adequately assessed, or limits placed on their acceptability.</p>
<blockquote><p>   &#8220;How are we quantifying what&#8217;s going wrong? Ozonma asked. &#8220;Is it security incidents? Operational value is tangible,&#8221; he added, but the implication of the opposite was clear: if security&#8217;s success is measured by absence of incidents, then it&#8217;s not provable or demonstrable. And when the tools are changing and evolving at such rapid pace, even a successful attempt at conducting such measurements risks being out of date before it&#8217;s ready to report internally.</p></blockquote>
<p>Another option, one CISO argued, is to take a step back from trying to implement technical controls, and to look instead to shore up the organisation on  a more deeply embedded, cerebral level.</p>
<blockquote><p>   &#8220;I wouldn&#8217;t go for technical controls,&#8221; they said. &#8220;I&#8217;d want to enhance our culture around use of AI. If you can build a secure culture in how your staff engage with AI, then when things move and change, the culture should give you some measure of protection. It&#8217;s harder to build a culture than to write a policy, but that&#8217;s where I&#8217;d want to spend the money. If you build a culture, you&#8217;ll get much more benefit and far fewer problems.&#8221;</p></blockquote>
<h4><strong>Soliloquy Of Chaos</strong></h4>
<p>Technical controls and pragmatic, use-case-specific restrictions can, of course, be put in place by individual businesses, divisions or departments. These may help to limit risk, although they may also restrict benefits. The trouble, attendees seemed to mostly agree, is there&#8217;s no way of knowing in advance where the most prudent place to draw those lines might be. A lack of advice from governments, regulators and other central sources of knowledge and expertise was cited as an issue here &#8211; only for one CISO to push back on the assertion.</p>
<blockquote><p>   &#8220;I&#8217;m going to disagree that there&#8217;s no standard advice,&#8221; they argued. &#8220;There is: there&#8217;s governance. It&#8217;s not perfect, and people are often fumbling in the dark. Two years ago it was true that there were no guardrails, but we&#8217;ve come a long way since then.</p>
<p>&#8220;We&#8217;ve got standards we&#8217;ve been working with for decades that will work with this,&#8221; they continued. &#8220;We just have to find out where the gaps are. If we focus on those deltas we&#8217;ll get value from our human decision-making.&#8221;</p>
<p>&#8220;There&#8217;s some frameworks, and there are some flaws,&#8221; another security leader (partly) agreed. The problem, they suggested, was making sure those frameworks were understood throughout the business, and could be applied uniformly and consistently. The reason this rarely happens is no real surprise: it&#8217;s because this technology has users &#8211; who, being human, tend to resist being shoved into a limited number of restrictive categories.</p>
<p>&#8220;We think we&#8217;ve got three types of users,&#8221; this leader continued. &#8220;There are ones who go, &#8216;We&#8217;ve got to use AI now!&#8217; And then you ask them, &#8216;What do you want to use it for? And they say, &#8216;Don&#8217;t know!&#8217; Then there&#8217;s those who want to use it to speed up their basic daily tasks. But it&#8217;s the third type that are the big headache. We used to have colleagues making bonkers decisions but having to go through gatekeepers &#8211; and now they&#8217;ve got tools they can use to go out and do those bonkers things invisibly.&#8221;</p></blockquote>
<p>Regulations, frameworks and best-practice guidance do exist, Cisco&#8217;s solutions engineering manager, Bradley Rossi, noted: but they don&#8217;t apply in all instances, and even in the scenarios where they do notionally have an impact, there are gaps.</p>
<blockquote><p>   &#8220;There are things like the European Union AI Act,&#8221; he acknowledged, &#8220;but there are complete sectors where it doesn&#8217;t apply &#8211; like healthcare. It&#8217;s scary. People want to use AI because it&#8217;ll cut waiting lists and get faster first opinions on the results of CT scans &#8211; so there&#8217;s a push from the public to use it, but no set framework to specify what you&#8217;re allowed to do.&#8221;</p>
<p>&#8220;It&#8217;s true,&#8221; another veteran security leader lamented. &#8220;People have had the opportunity to learn, but in my experience, a lot of them haven&#8217;t.&#8221;</p>
<p>&#8220;A lot of people who are in positions where they could show leadership haven&#8217;t learned,&#8221; another CISO said. &#8220;They&#8217;re saying, &#8216;We must use AI&#8217; and have charged ahead because of what it might deliver, without clearly defining anything, and whilst often shutting down discussion of possible risks.</p>
<p>&#8220;Virtually everyone I know who works in a private company who has engaged with AI has a story of someone in their organisation who has done something really bad with it,&#8221; they added. &#8220;Often it gets caught; sometimes it doesn&#8217;t, but things get smoothed over. But everyone I know in a private company knows someone in that position &#8211; and that tells me this problem is widespread.&#8221;</p></blockquote>
<h4><strong>Moment Of Truth</strong></h4>
<p>Cisco doesn&#8217;t have a whizz-bang AI-security solution it&#8217;s trying to sell. Rossi and his colleague, technical solutions specialist Regan Newman, were keen to highlight the operating concept they call UZTNA &#8211; universal zero-trust network access. The last four letters of that acronym &#8211; what Rossi calls &#8220;the low-hanging fruit&#8221; &#8211; is stuff that most businesses already do, or try to do. Universalising it, though, &#8220;really does change the game,&#8221; he argued.</p>
<blockquote><p>   &#8220;With non-human identities involved, and with nation-state interest in some of your intellectual property, you need to be really sure what permissions you&#8217;re giving these agents,&#8221; Rossi said.</p>
<p>&#8220;The whole idea isn&#8217;t new,&#8221; Newman added. &#8220;ZTNA isn&#8217;t one thing you can achieve &#8211; you don&#8217;t suddenly say, &#8216;Hey, I&#8217;m ZTNA-compliant.&#8217; You need to work out what zero-trust means in your environment, and what your priorities are.&#8221;</p></blockquote>
<p>Several businesses represented in the room were somewhere on their ZTNA journey, but the zero-trust element appeared to be tripping some of them up.</p>
<blockquote><p>   &#8220;I think it&#8217;s an impossible target,&#8221; one leader said. &#8220;We can&#8217;t get over the line on being perfectly zero-trust. We have very tight controls and we&#8217;ve done pretty well in red-team exercises, but it&#8217;s not perfect.&#8221;</p>
<p>&#8220;It&#8217;s a myth that you can every achieve 100% perfect zero trust,&#8221; another leader agreed. A short discussion followed about what achieving perfect zero trust actually means.</p>
<p>&#8220;I think it means that we have a fair level of trust that in most situations, zero trust is going to be effective,&#8221; one leader said, carefully. &#8220;We have mostly effective controls &#8211; by which I mean, our controls are fully effective in most situations. We rely on technological, governance and cultural controls. But there&#8217;ll always be things that slip between those.&#8221;</p>
<p>&#8220;It&#8217;s best endeavours, isn&#8217;t it?&#8221; another CISO suggested.</p>
<p>&#8220;Exactly,&#8221; Ozonma agreed. &#8220;It&#8217;s based on the risk tolerance within your organisation. Tomorrow it&#8217;s going to change. As security professionals, our job is to consistently make sure we&#8217;re providing that level of assurance. Fundamentally, everything we do is based on risk management. Is it acceptable, tolerable, or a flat-out &#8216;No&#8217;?&#8221;</p></blockquote>
<p>Which seemed to bring us back to where we came in, and the need to experiment. Also, Newman suggested, the need to share the results of those experiments.</p>
<blockquote><p>   &#8220;Don&#8217;t let this knowledge be kept exclusive,&#8221; he said. &#8220;Leverage each others&#8217; experience: there&#8217;s lots of lessons to learn. That f&#8212;ing around and finding out? There&#8217;s plenty that can be learned from that experience.&#8221;</p></blockquote>
<p>The post <a href="https://rantcommunity.com/resources/speak-ya-clout-straight-shooting-cisos-trade-real-talk-on-ai-security-with-cisco/">Speak Ya Clout: Straight-Shooting CISOs Trade Real Talk On AI Security With Cisco</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI Security: Control, Chaos, or Catch-Up?</title>
		<link>https://rantcommunity.com/resources/ai-security-control-chaos-or-catch-up/</link>
		
		<dc:creator><![CDATA[Galena]]></dc:creator>
		<pubDate>Mon, 13 Jul 2026 08:17:22 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[Cybanetix/Noma]]></category>
		<guid isPermaLink="false">https://rantcommunity.com/?p=3114</guid>

					<description><![CDATA[<p>AI is moving from personal experimentation to enterprise-wide adoption at pace. However, security strategies are reportedly struggling to keep up.</p>
<p>The post <a href="https://rantcommunity.com/resources/ai-security-control-chaos-or-catch-up/">AI Security: Control, Chaos, or Catch-Up?</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>AI is moving from personal experimentation to enterprise-wide adoption at pace. However, security strategies are reportedly struggling to keep up.</p>
<p>At a recent roundtable held in Manchester on the hottest day of the year, attendees were asked why they had come along, and the responses reflected the wide range of concerns organisations currently have around AI:</p>
<ul>
<li>See use of AI across estates, do assurance and help people understand risks</li>
<li>Squeeze AI into everything, consider what to give access to</li>
<li>Everyone wants to use AI, but have optimistic dread</li>
<li>We are implementing it</li>
<li>Worried AI will replace jobs; my job is to make sure there is assurance</li>
<li>Concerned about what employees and contractors do with AI</li>
<li>How can I use AI for what I do, while managing, protecting and defending against AI threats?</li>
<li>How everyone else approaches AI adoption and deals with access requests</li>
</ul>
<p>Opening the discussion, Merlin Gillespie, director at Cybanetix, said there is a vested interest in securing technology, which is difficult enough, while also developing policies that encourage innovation. Meanwhile, Tim Gibbs, director of sales for EMEA at Noma Security, said he was relatively new to the security space but had spoken to hundreds of organisations about AI adoption and the security challenges they face every day. &#8220;We strive to keep up with the agents of change,&#8221; he said.</p>
<p>He noted that AI adoption continues to rise, although organisations are at very different stages of maturity. Some are well advanced, while others are only beginning their AI journey, yet all are faced with managing hundreds, if not thousands, of AI agents.</p>
<p>Chair Rob Black asked the table where they were with AI adoption. One attendee said they were trying to &#8220;wrap guardrails&#8221; around AI while running at &#8220;1,000mph&#8221;, while others commented that they did not want to stifle innovation but instead wanted to understand how to control AI while continuing to use the models available.</p>
<p>Others observed that some organisations simply &#8220;want to be the first to do everything and implement it&#8221;, while another attendee questioned who is responsible when AI does something unexpected.</p>
<p>The discussion centred on the theme that AI is moving from experimentation to enterprise-wide adoption at pace, but security strategies are struggling to keep up, with many organisations still grappling with what that means in practice.</p>
<h4><strong>Restrict and Manage Risk</strong></h4>
<p>Moving the discussion on, Black asked how organisations can define and manage their risk appetite without simply restricting AI altogether.</p>
<p>The conversation quickly turned to how AI is being used, whether internally or externally, and the implications of what external tools can ingest and what internal tools may inadvertently disclose. One attendee described AI as &#8220;the Wild West&#8221;, suggesting that some organisations are willing to be first movers, while others are happy to accept the associated risks.</p>
<p>Another attendee argued that business leaders are under pressure but are not necessarily discussing AI strategically. Instead, CIOs and CTOs are expected to improve productivity, while CISOs are expected to remain cautious, restrictive and sensible.</p>
<p>Others noted that developers are already downloading and training models, with several admitting to using tools such as Claude and Gemini. One attendee explained that AI had already helped respond to client audit requests and could &#8220;chop time from the process&#8221;.</p>
<p>The discussion highlighted a familiar dilemma: restrict AI and risk falling behind, or open the floodgates and attempt to retrofit controls later. Alongside this are the practical challenges of preventing sensitive data leakage, securing AI models themselves and enforcing policy-driven controls.</p>
<p>This is why there needs to be a broader conversation about the real challenges behind AI security in modern enterprises, cutting through market noise to explore practical approaches that enable organisations to use public AI securely.</p>
<p>Another attendee argued that organisations should learn from history. They pointed out that industries have successfully introduced controls around mobile banking, cloud computing and internet usage, so there is no need to overcomplicate AI governance. Instead, organisations should build on the controls and lessons that already exist.</p>
<p>Gillespie added that the pace of change has accelerated dramatically over the past five years and that AI is now approaching a tipping point. Organisations can almost guarantee they are using AI every day, yet the speed of adoption remains difficult to measure.</p>
<p>Others described AI as &#8220;more of a black box&#8221;, questioning what happens inside the models and whether they can truly be trusted.</p>
<h4><strong>How Do You Use It?</strong></h4>
<p>Asked by Black how organisations are using AI today, one attendee said behavioural AI can monitor business activity, identify anomalies and alert users. AI can then summarise those alerts, providing context around what constitutes normal behaviour.</p>
<p>Another attendee said AI can provide an overview of key information and help pull together sources, allowing users to generate an initial statement or draft much more quickly. However, everyone agreed that there must always be a human element involved.</p>
<p>On the subject of trust, Black asked where attendees were in their AI journey. One participant said they had no inherent trust in AI and instead approached it with a &#8220;zero trust&#8221; mindset, reviewing and understanding each tool before deployment. Without properly assessing and accepting the risks, they argued, users would inevitably find ways around the controls.</p>
<p>Another attendee said the situation is made more complicated because every AI platform is different, with no standardised set of effective controls that organisations can consistently apply.</p>
<p>Others noted that mapping AI outputs back to existing security controls requires considerable time and effort. While AI can often complete tasks faster than an individual, it is only trustworthy when organisations understand how it arrived at its conclusions and can validate the results.</p>
<p>Another attendee said AI often falls down on explainability. Organisations need to be able to ask why an AI made a particular decision and determine whether its reasoning can be trusted. AI models require tuning, and anyone expecting immediate results should instead expect improvements over several months.</p>
<p>Ultimately, one attendee concluded that organisations should embrace AI and innovate with it, but treat anyone using generative AI as if they were a developer.</p>
<h4><strong>Who Owns AI?</strong></h4>
<p>In the final section, Black asked who is driving AI adoption within organisations.</p>
<p>The discussion focused on how organisations are structuring ownership, including whether responsibility for AI security should sit with the CISO or whether new roles, such as Chief AI Officer, are beginning to emerge.</p>
<p>One attendee said the pressure comes from two directions: CEOs looking to improve workflows and software developers eager to adopt AI as quickly as possible.</p>
<p>Another argued that organisations should first identify where AI genuinely delivers efficiencies and assess whether it is appropriate for each team. They also stressed the importance of understanding where AI provides value, where it does not, and communicating those decisions in business language.</p>
<p>Others said organisations must determine who the users are, how AI will improve their work and why it should be used in the first place. One attendee suggested that many boards see AI as a panacea, failing to understand its limitations and associated risks. Instead, there is an expectation that AI will simply make everything better, and organisations are often expected to deliver on that belief.</p>
<p>Concluding the discussion, Gillespie said there is ultimately a question of trust: organisations need to get more value out of AI than they put into it, while ensuring a human remains involved. He admitted that &#8220;the world moves on&#8221; and described this as &#8220;the most interesting time in the technology landscape&#8221;. Regardless of whether AI proves to be wholly good or bad, he said, it is certainly interesting.</p>
<p>Gibbs said he had listened closely to the discussion around leveraging AI within the SOC, particularly the points raised around trust, data security and the rise of agentic AI. He stressed that he was not dismissing the technology, but organisations need to understand which AI agents are legitimate, what capabilities they have and how they are being used.</p>
<blockquote><p>&#8220;The only thing is no one knows where we&#8217;re going,&#8221; he said. Although he personally vets everything AI produces, he concluded that it is &#8220;fantastic&#8221; and that he &#8220;cannot live without it&#8221;.</p></blockquote>
<p>The post <a href="https://rantcommunity.com/resources/ai-security-control-chaos-or-catch-up/">AI Security: Control, Chaos, or Catch-Up?</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Impatient Leaders And Troublesome Priests: Why Security Leaders Really Worry About AI</title>
		<link>https://rantcommunity.com/resources/impatient-leaders-and-troublesome-priests-why-security-leaders-really-worry-about-ai/</link>
		
		<dc:creator><![CDATA[Galena]]></dc:creator>
		<pubDate>Sat, 11 Jul 2026 08:01:43 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[Cisco]]></category>
		<guid isPermaLink="false">https://rantcommunity.com/?p=3103</guid>

					<description><![CDATA[<p>It was billed as a conversation about how, notwithstanding the pace of adoption of so-called &#8220;AI&#8221; systems, the fundamentals of</p>
<p>The post <a href="https://rantcommunity.com/resources/impatient-leaders-and-troublesome-priests-why-security-leaders-really-worry-about-ai/">Impatient Leaders And Troublesome Priests: Why Security Leaders Really Worry About AI</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>It was billed as a conversation about how, notwithstanding the pace of adoption of so-called &#8220;AI&#8221; systems, the fundamentals of cybersecurity haven&#8217;t changed all that much. So those of us attending a RANT roundtable in London, sponsored by Cisco, had perhaps been expecting a few time-served examples, war stories or talking points that dug fairly deeply into the past to emerge during the evening. But we were expecting that past to be rather more recent than turned out to be the case.</p>
<p>One veteran security leader at the table thought it was important to go back beyond not just the growth of cloud computing, the work-from-home revolution kick-started by COVID, or even the birth of digital networks entirely. No: there are things that haven&#8217;t changed since at least the year 1170, when one senior executive who viewed their job as being to warn those at the top of the enterprise of when too much risk was being accepted paid the ultimate price.</p>
<blockquote><p>&#8220;In Canterbury Cathedral there&#8217;s a shrine to Thomas Becket,&#8221; our beleaguered CISO friend said, initially to some bemusement around the room. &#8220;He told the king &#8211; his C-suite &#8211; that something wasn&#8217;t a good thing to do. Then the king said, &#8216;Can someone please get rid of him&#8217;? so a bunch of knights martyred him. And that&#8217;s what&#8217;s happening to security people.&#8221;</p></blockquote>
<p>Tellingly, while many around the table smiled, perhaps in recognition that the analogy was rather extreme &#8211; after all, we&#8217;ve not heard of any security leaders being hacked to death on the orders of their CEOs (well, not yet, anyway) &#8211; nobody took issue with the basic truth outlined. When it comes to generative AI, the kings of the business &#8211; the executives, the board, the elites at the top of the organisation &#8211; are gung-ho for these new tools to be deployed within the organisation, so place implied or sometimes explicit pressure on the senior leadership who report to them to get things moving, and fast. But when the security specialists point out the risks involved, and advocate for taking time to get the deployment right so they can ensure that the business can remain as secure as possible &#8211; or, failing that, to at least be demonstrably resilient when the eventual attacks hit &#8211; the kings just don&#8217;t want to know.</p>
<blockquote><p>&#8220;The C-suite are saying, &#8216;I&#8217;ve read about all this in the FT or Forbes&#8217;,&#8221; our student of the medieval world continued. &#8220;It&#8217;s FOMO,&#8221; they added, demonstrating their linguistic and conceptual agility by switching from 12th century history to 21st century vernacular in a heartbeat. &#8220;A huge amount of FOMO from executives. There are senior members of management who are going backwards.&#8221;</p></blockquote>
<h4><strong>When Will We Learn</strong></h4>
<p>This contribution came nearer the end of the discussion than the start, but &#8211; despite how striking and unexpected the imagery may have been &#8211; it tapped in to one of the key themes of the evening. That was that the pace of adoption of AI is not being matched by growth in maturity of organisations when it comes to understanding and managing the risks that potentially transformative new technologies introduce. And, while nobody in the room seemed to have made a conscious decision to pile in on Microsoft, a lot of this part of the discussion came out in the form of complaints about the software giant&#8217;s chatbot, Copilot.</p>
<blockquote><p>&#8220;I have friends,&#8221; one leader with a particular animus against this particular Redmond product recalled, &#8220;who say that Microsoft gives you access to the Foot Gun &#8211; Copilot; then they give you a bulletproof shield, called Purview, to stop yourself shooting yourself in the foot.&#8221;</p></blockquote>
<p>It is, many attendees acknowledged, a powerful tool. &#8220;Prior to Copilot, finding information was difficult &#8211; but now, if you want to find something on your own corporate environment, Copilot will find it,&#8221; one leader said. But, many also agreed, it will find things that, on balance, you would probably prefer that no tool could.</p>
<blockquote><p>&#8220;We&#8217;ve enabled Copilot for corporate access &#8211; [it can access] Sharepoint, emails and so on,&#8221; one senior security leader said. &#8220;But we realised that, in Sharepoint, it&#8217;ll have access to&#8230;&#8221; They paused, working out how best to explain the situation.</p>
<p>&#8220;My boss, the CTO, asked Copilot, &#8216;What&#8217;s the salary for everyone in the C-suite?&#8217;, and they got it,&#8221; they said. &#8220;We&#8217;re now looking at a technology where you create a digital twin &#8211; you get your own personal assistant living in the cloud. It copies all the documents you&#8217;ve access to in Sharepoint. We can put in restrictions on Sharepoint , but the twin can bypass them. It takes one copy of everything you&#8217;ve got access to. We all know that the attacker just has to be right once, and we have to be right all the time &#8211; but we now have to be right all the time on multiple fronts. If it was easy we&#8217;d do it ourselves and there&#8217;d be no risk &#8211; but the balance of power has shifted.&#8221;</p></blockquote>
<h4><strong>Profits Paradise</strong></h4>
<p>Optimism has been expressed that generative AI will help defenders, and to a degree this sentiment was shared by attendees during the discussion &#8211; despite the view expressed by one CISO that AI &#8220;is like a four-year-old child: all it wants to do is please&#8221;. But the focus was very much on the risks that these technologies are adding to the enterprise. And, in large part, these risks are mounting because of the pressure being exerted by business leaders on the rest of the staff to leverage the productivity gains and work-speed improvements LLMs appear to offer.</p>
<blockquote><p>&#8220;I&#8217;m hearing you say that Copilot is the problem,&#8221; Cisco&#8217;s global security technologist, Ant Ducker, said. &#8220;But we&#8217;re also being asked to be creative with AI. Is <em>that</em> the problem? [Business leaders say] &#8216;Here&#8217;s Copilot &#8211; we&#8217;re not going to give you any definitions, we&#8217;re asking you to figure out how to use it.&#8217; Shouldn&#8217;t the business be saying, &#8216;Here are the things you should be looking to use it for, to increase productivity&#8217;?&#8221;</p>
<p>&#8220;We&#8217;re playful animals, and we learn by playing,&#8221; one security leader replied. &#8220;You don&#8217;t read documentation or worry about obeying rules &#8211; you just play with it.&#8221;</p></blockquote>
<p>Fortunately, there are a few businesses where limits are imposed amid what otherwise appears to be a headlong dash toward AI adoption. But even in those organisations, security leaders are being put under pressure to do more, and do it faster.</p>
<blockquote><p>&#8220;We&#8217;ve got a very well-defined process for cloud services and new emergent technologies,&#8221; one CISO said. &#8220;Our average time from the business saying &#8216;I want to use this new service&#8217; to getting something in production is probably a couple of weeks. But for anything involving AI&#8230;? Copilot took us 18 months. We needed to put a harness around the harness &#8211; we have to put controls around it, and figure out how to make sure that all the regulations and expectations are met if we&#8217;re going to let it into the wild and have our population use it.&#8221;</p></blockquote>
<h4><strong>It&#8217;s A Gamble</strong></h4>
<p>This talk of an additional harness raised some questions around the guardrails supposedly built into Copilot, and other LLMs, and to what extent they are effective or reliable (general consensus: not very). All of this means that internal policies and controls become ever more vital &#8211; as does having a maturity within the organisation when it comes to considering risk.</p>
<blockquote><p>&#8220;We all seek to gain advantage,&#8221; one security leader said. &#8220;We&#8217;re all risk advisors. And certainly, in my experience, that means a whole host of different risks, including risk to life. We do a layered approach: it&#8217;s not risk removal, it&#8217;s risk reduction. And this is down to the CEO. This is what we need to realise &#8211; what and who we are. We&#8217;re risk advisors in a risk environment, and what we do is risk reduction, not risk removal.&#8221;</p></blockquote>
<p>There was agreement with this point of view, but also some additional nuance that another leader wanted to inject into the conversation. Most risks, they argued, could be mitigated with some element of care around introduction of the new product, service or tool. The additional risk with generative AI tools seems to come, they argued, from the pace at which business leaders want to introduce them, and the circumvention of normal processes that meeting these aggressive timetables requires.</p>
<blockquote><p>&#8220;I&#8217;ve worked in a hazardous environment,&#8221; they said, &#8220;and when you&#8217;re working in an environment where there&#8217;s extremely high risk, the idea that you&#8217;d go along with vibecoding, or would say &#8216;Well, there&#8217;s going to be vulnerabilities, we might as well just go with it&#8217;&#8230;&#8221; They stopped and shook their head at the sheer folly of such a notion. &#8220;No, that&#8217;s a really bad idea. You need to choose an environment &#8211; sandboxing or whatever &#8211; where you have an ability to control things and test things.</p>
<p>&#8220;This is the worst thing about AI being pushed in so fast,&#8221; they continued. &#8220;Dev environments have been around a long time, but at the moment they&#8217;re being short-cut. Things go straight into production.&#8221;</p></blockquote>
<h4><strong>Heavy Mental</strong></h4>
<p>Ultimately, everyone seemed to agree, the only thing that&#8217;s changed thanks to LLMs is the pace with which everything happens. That covers not just the alacrity that senior corporate management seems to have for deploying the technology, but the speed with which it can wreak havoc in businesses that have failed to prepare for its arrival.</p>
<blockquote><p>&#8220;I deal with simulation &#8211; redteaming, threat intel,&#8221; another senior practitioner said. Throughout their time in this role, they pointed out, &#8220;none of that has ever touched a vulnerability &#8211; it&#8217;s always touched a human. Can I find the human who can get me in to whatever it is I&#8217;m trying to get? With AI, now we&#8217;re going at speed. We all need to be cognisant. In organisations we&#8217;re going to see a lot of collateral damage. As people who convey risk, we need to convey it in a balanced way.&#8221;</p>
<p>&#8220;We need a central management pane &#8211; one pane of glass to manage everything,&#8221; Cisco&#8217;s Ducker suggested. &#8220;And in that place, that&#8217;s where we use AI for good. We create an army of agents that are network security specialists, identity specialists: we can monitor what&#8217;s happening across all the domains in our infrastructure, and we can collaborate. Rather than having four teams using their own UI [user interface], they&#8217;re all running from a dynamically generated UI.&#8221;</p></blockquote>
<p>These capabilities, Ducker said &#8211; almost apologetically, as, he stressed, the company were not hosting the conversation as an opportunity to push a product or service, but to hear from senior practitioners about the challenges they were facing and how they were tackling them &#8211; fall within the bounds of the Hybrid Mesh Firewall concept that Cisco have adopted. A term coined in 2024 by Gartner, it &#8220;describes a central management pane that can manage a consistent security policy across multiple platforms,&#8221; he added. Cisco&#8217;s implementation of it goes further, &#8220;using the network as security fabric, and blending different kinds of security and enforcement capabilities right across the stack.&#8221;</p>
<blockquote><p>&#8220;Listening to this, we still get back to &#8211; if you get the fundamentals right, you&#8217;re in a really, really good position,&#8221; one of the attendees said. &#8220;That hasn&#8217;t changed since the Orange Book,&#8221; they added, referring to the U.S. Department of Defense&#8217;s Trusted Computer System Evaluation Criteria standard, published in 1983. &#8220;Although it does look scary, I&#8217;m starting to think more and more &#8211; what does it change?&#8221;</p></blockquote>
<p>The post <a href="https://rantcommunity.com/resources/impatient-leaders-and-troublesome-priests-why-security-leaders-really-worry-about-ai/">Impatient Leaders And Troublesome Priests: Why Security Leaders Really Worry About AI</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Respond/React: Resilience And Recovery Dominate RANT&#8217;s Ransomware Roundtable</title>
		<link>https://rantcommunity.com/resources/respond-react-resilience-and-recovery-dominate-rants-ransomware-roundtable/</link>
		
		<dc:creator><![CDATA[Galena]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 08:51:34 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[Halcyon]]></category>
		<guid isPermaLink="false">https://rantcommunity.com/?p=3099</guid>

					<description><![CDATA[<p>&#8220;I don&#8217;t want to dismiss prevention,&#8221; one CISO said early during a RANT roundtable hosted by Halcyon in London in</p>
<p>The post <a href="https://rantcommunity.com/resources/respond-react-resilience-and-recovery-dominate-rants-ransomware-roundtable/">Respond/React: Resilience And Recovery Dominate RANT&#8217;s Ransomware Roundtable</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></description>
										<content:encoded><![CDATA[<blockquote><p>&#8220;I don&#8217;t want to dismiss prevention,&#8221; one CISO said early during a RANT roundtable hosted by Halcyon in London in early June, convened to discuss responses to the deepening ransomware epidemic. &#8220;But the biggest thing to focus on is recovery.&#8221;</p></blockquote>
<p>The sentiment proved to be something of a lodestar for the evening, as a group of senior cybersecurity leaders and practitioners dug deep into the topic of ransomware response &#8211; with resilience clearly front of mind for businesses of all shapes, sizes and sectors. A high-level delegation from Halcyon &#8211; including director of solution architecture Ross Asquith, regional director of enterprise sales Chris Lewis, and the director of the firm&#8217;s Ransomware Research Centre, the former FBI cyber division deputy assistant director Cynthia Kaiser &#8211; contributed occasionally, but for the most part sat back and listened as those on the front line of these digital battles traded war stories and drilled down into the detail of how best to configure companies to tackle the ever-changing and existential threat of a complete loss of access to data and networks.</p>
<h4><strong>Step Into The Realm</strong></h4>
<p>An early topic for discussion turned out &#8211; perhaps surprisingly &#8211; to be hardware. There were two reasons for this. Many large enterprises &#8211; and probably quite a few smaller ones &#8211; will have built around and on top of predecessor systems, as the business has evolved over time, needing to retain existing capacity and capability while acquiring new tools and technologies. This means that the business will have some degree of reliance on old and partially obsolete systems &#8211; and staff who mainly work with newer tools may lack awareness of them, never mind the skills to solve problems that may crop up inside them. Second, ransomware by its very nature poses questions about hardware inside the enterprise: if an attacker can move laterally and paralyse all systems, then not only do backups need to be offline or airgapped from the network: but any attempt at restoring services after a successful attack could make greater demands on IT capacity. Then there&#8217;s the investigative element.</p>
<blockquote><p>&#8220;If we suffered a ransomware incident, and we needed to keep all the encrypted servers for forensic analysis, do we have the hardware to keep the encrypted stuff and restore somewhere else?&#8221; the CISO who&#8217;d rated recovery as the prime concern said. The business, he suggested, might even require a separate, mirrored, hardware laydown, ready to spin up a new network using backups, allowing the contaminated systems to be pored over. This question had preoccupied their enterprise, they said &#8211; and that had been helpful. &#8220;For us, that spurred more investment, and a lot of changes in how we did things,&#8221; they said. &#8220;Would we have capacity to restore all the servers again, while keeping what was there?&#8221;</p>
<p>&#8220;In terms of ransomware, I&#8217;ve prioritised identifying the really old legacy stuff, that we have no ability to redo,&#8221; another CISO said. &#8220;I read the reports on the British Library hack, and the biggest thing was the legacy systems. They had bespoke code that was old and out of date. They could recover a lot of the modern systems, but it was those old code bases they couldn&#8217;t fix. So we have a lot of backup procedures. Ransomware is not our main problem &#8211; but the responses to those main problems will fit ransomware.&#8221;</p></blockquote>
<h4><strong>You Got Me</strong></h4>
<p>These questions, of course, presuppose that the enterprise has correctly identified what constitutes its key critical systems.</p>
<blockquote><p>&#8220;Technical recovery is pretty straightforward, but identifying the three pieces of tech that would hurt you the most&#8230;? That may not be,&#8221; one senior security leader suggested. &#8220;DNS isn&#8217;t going to make your top three &#8211; but if it isn&#8217;t there, everything dies.&#8221;</p>
<p>&#8220;We looked at what was the minimum viable product that keeps us trading,&#8221; another CISO said. &#8220;What are those products? What are the interdependencies? And which ones have to come back up first?&#8221;</p></blockquote>
<p>An important point, all agreed, given that certain services will rely on other, underlying, capabilities, and so will not operate correctly if restarted in the wrong sequence.</p>
<p>And then there&#8217;s the nature of such analyses. It&#8217;s all well and good knowing what&#8217;s important to the business, understanding the sequence for re-establishing the service, and having these processes and procedures mapped out and promulgated around the workforce: but if people aren&#8217;t well practiced in carrying out these often complicated tasks, and are practiced at doing so under the kind of pressure that would attend a real incident, true resiliency will be impossible to achieve.</p>
<blockquote><p>&#8220;There&#8217;s no point just having it on paper,&#8221; one veteran security staffer said. &#8220;How many times a year do you test? And do you always test the same people? You shouldn&#8217;t.&#8221; Their business, they said, runs tests several times per year, using different staff, to see if they can recover the business from the documentation that exists. If they can&#8217;t do it, the exercise is marked as a fail, and would need to be re-run.</p>
<p>&#8220;That scares me,&#8221; another leader admitted. &#8220;I&#8217;m down to one person on a lot of key systems. I know that the person who knows how to get it all back up is Mike &#8211; but if Mike&#8217;s not there, how do we do it?&#8221;</p></blockquote>
<h4><strong>Double Trouble</strong></h4>
<p>As had been previously touched on, sometimes, resiliency will mean having a completely separate alternative ready to go if the worst comes to pass. This need not be as prohibitively expensive as permanently maintaining a complete replica of the existing systems.</p>
<blockquote><p>&#8220;We have a waterproof case with a phone in it and a flash key. We&#8217;ve worked out, on our business-continuity plan, that that&#8217;s what we need,&#8221; one pragmatic CISO said. &#8220;We&#8217;re having to put in whole systems on standby &#8211; full email, and other systems, that we can switch to &#8211; because with the cloud, the extraction cost of data is massive; that won&#8217;t work for us as we can&#8217;t afford it.&#8221;</p></blockquote>
<p>That CISO&#8217;s enterprise had reached this conclusion after realising that, due to specific concerns with the nature of the threat they were exposed to, and how their business was organised and its data stored, a strategy built around even the most frequent and diligently executed of backups simply would not work. There are dangers in relying on backups, particularly as ransomware groups evolve their tactics and procedures. One recent example Halcyon had dealt with proved instructive, where a patient adversary used a company&#8217;s well-implemented backup strategy against it.</p>
<blockquote><p>&#8220;This blew my mind &#8211; and it takes a lot to shock me,&#8221; Kaiser said. &#8220;We&#8217;ve seen an actor recently who sat on a network for 31 days. They gained access to the systems, and saw that the backups were done on a 31-day cycle &#8211; cancelled the backup services, waited, then attacked. And the organisation didn&#8217;t know.&#8221;</p>
<p>&#8220;We had to develop an out-of-band &#8211; out of current systems &#8211; means of comms and co-ordination to bring every office up to a standard where they can operate,&#8221; another security manager said. &#8220;It&#8217;s meant putting in almost a full shadow IT, because there&#8217;s no other way we&#8217;ve currently found, within our budget. We&#8217;ve contracted for shadow IT services we can put data into.&#8221;</p></blockquote>
<p>While this option, as they explained, was adopted for budgetary reasons, it is still by no means a low-cost solution. It will only work if all the necessary staff are trained and ready; and achieving and maintaining that level of readiness places significant demands on internal resources.</p>
<h4><strong>Dynamite!</strong></h4>
<p>An interesting side-discussion blew up around insurance &#8211; with some leaders arguing it was a pointless waste of money, impossible to be sure that coverage would work until after an attack, and that being the worst time to find out that some loophole or other had been found in the coverage; while others strongly advocated for the forensic capability and expertise that cyberinsurance providers are able to deploy, at no cost to the business, in the aftermath of an attack. But another topic that provoked lively exchanges was on when, and to what extent, ransomware attacks could stray from being a threat to businesses, and into territory where states may start to think about designating them as terrorism.</p>
<blockquote><p>&#8220;All ransomware is a crime, and some of it is terrorism,&#8221; Kaiser said. &#8220;In U.S. law, and the definitions there, we believe it would meet the threshold for terrorism if ransomware was targeting a hospital.&#8221;</p></blockquote>
<p>But designating ransomware as terrorism &#8211; even if it was something that cybersecurity leaders were in a position to do; which, of course, they are not &#8211; is by no means a straightforwardly beneficial proposition. As Kaiser noted, doing so might well provoke attack groups to &#8220;change their calculus.&#8221;</p>
<p>If a ransomware attack on a particular industry or sector were to be considered terrorism, and the individuals who carried it out were to be charged with that crime, perhaps the efforts put in to identifying and apprehending suspects would be intensified, cross-border law-enforcement collaboration might be given a higher priority, and the penalties for those caught and tried would be significantly increased. But it is unlikely that a threat actor would respond to that by ceasing operations completely: more likely, they would redirect their efforts onto sectors where an attack would not be considered terrorism. So while there would be clear social benefits, there would also be considerable costs &#8211; which would fall on businesses operating outside critical services and infrastructure.</p>
<p>Additionally, as other attendees argued, the detail of any such designation would be key &#8211; both for any deterrent effect to prove meaningful, and to ensure that increased risk outside critical sectors wouldn&#8217;t end up having knock-on effects that were just as disruptive.</p>
<blockquote><p>&#8220;We&#8217;ve designated more and more operators as being &#8216;essential services&#8217;,&#8221; one security leader said, referring to consideration given to what constitutes critical national infrastructure in the UK.</p>
<p>&#8220;There used to be a line that was clear &#8211; &#8216;We are CNI, you aren&#8217;t,&#8217;,&#8221; another leader said. &#8220;Smaller organisations would wonder, &#8216;Why would anybody attack us?'&#8221;</p></blockquote>
<p>The answer, a third leader suggested, was pretty obvious:</p>
<blockquote><p>&#8220;If you&#8217;re very well hardened, the attackers go a level down.&#8221;</p></blockquote>
<p>Then risk there may well be greater, even if the initial reward in cash terms for the ransomware gangs is going to be smaller. But one of the big changes Kaiser says Halcyon are seeing is that threat actors are targeting small and medium-sized firms more often than they once were &#8211; four times as many SMEs are getting hit now compared to large businesses, she said. And if a sub-supplier to a CNI entity gets taken down, the ripple effects on their CNI customer could be just as damaging as if the critical industry had been targeted in the first place.</p>
<h4><strong>Livin&#8217; In A New World</strong></h4>
<p>If the considerations that need to be assessed before a nation decides to designate ransomware attacks as terrorism are complicated, so too are the decisions each of us make in how we talk about the topic. One CISO spoke about how their enterprise has benefitted hugely from having internal presentations made by a few brave souls whose companies were hit by ransomware, and who have chosen to share their experiences with others as a means to &#8211; hopefully &#8211; helping ensure what happened to them is not repeated elsewhere. That kind of behaviour should be considered heroic: yet, as the CISO noted, so often the response towards victims of ransomware is very different. &#8220;When people get mugged, everyone is sympathetic,&#8221; they pointed out. &#8220;But when you get hit by ransomware, they&#8217;re not.&#8221;</p>
<blockquote><p>&#8220;It&#8217;s important to treat victims as victims,&#8221; Kaiser agreed, her years in law-enforcement adding considerable weight to the observation. &#8220;It&#8217;s a really hard conversation, though,&#8221; she continued. &#8220;Some boards and C-suites ignore security advice &#8211; so perhaps it&#8217;s a reasonable feeling in those cases. We know adversaries are relentless, so if they want to get in, they will do eventually. But it&#8217;s up to us to hold people responsible if they haven&#8217;t done the easy things.&#8221;</p></blockquote>
<p>Other leaders recognised that the tone of these conversations is very important, and can make a big difference &#8211; not just to managing relationships in the supply chain, but to achieving the best possible security for the business itself.</p>
<blockquote><p>&#8220;We&#8217;ve spoken to our vendors on resilience quite a lot, and we keep saying we don&#8217;t want to blame anyone, but that we want to know what happened so we can fix it and prevent it happening again,&#8221; another security leader said. &#8220;With suppliers, this usually is OK: but if their business culture is different, it may not roll down the rest of the supply chain the way you would want it to.&#8221;</p></blockquote>
<p>Use of language is important, too. Returning to the conundrum of whether or not to designate ransomware as a form of terrorism, one CISO noted that, particularly in sectors such as healthcare or social services, terrorism may be received as &#8220;an angry, noisy word&#8221; which would perhaps end up closing conversations rather than causing people outside the SOC to think more about their physical and digital security.</p>
<blockquote><p>&#8220;It&#8217;s very similar in the U.S.,&#8221; Kaiser acknowledged. &#8220;If I start talking about threat actors as terrorists, some people think it absolves them from doing better. We should dissuade ransomware groups from targeting life-critical entities, but it&#8217;s impossible to separate physical risk from cyber risk. To me, you have to make sure that if you&#8217;re using these words, it&#8217;s not going to allow anyone to think it lets them off from doing the basics.&#8221;</p></blockquote>
<p>The post <a href="https://rantcommunity.com/resources/respond-react-resilience-and-recovery-dominate-rants-ransomware-roundtable/">Respond/React: Resilience And Recovery Dominate RANT&#8217;s Ransomware Roundtable</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Supplier risk management can be “mind bogglingly” complicated: where do we go from here?</title>
		<link>https://rantcommunity.com/resources/supplier-risk-management-can-be-mind-bogglingly-complicated-where-do-we-go-from-here/</link>
		
		<dc:creator><![CDATA[Galena]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 09:35:25 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[Diligent]]></category>
		<guid isPermaLink="false">https://rantcommunity.com/?p=3111</guid>

					<description><![CDATA[<p>“Who still relies on spreadsheets to manage their suppliers? Who only performs third-party risk management once a year? And who</p>
<p>The post <a href="https://rantcommunity.com/resources/supplier-risk-management-can-be-mind-bogglingly-complicated-where-do-we-go-from-here/">Supplier risk management can be “mind bogglingly” complicated: where do we go from here?</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></description>
										<content:encoded><![CDATA[<blockquote><p>“Who still relies on spreadsheets to manage their suppliers? Who only performs third-party risk management once a year? And who finds it challenging to engage business stakeholders throughout the process?”</p></blockquote>
<p>These three questions from Diligent’s Jelle Groenendaal, Co-founder of the firm’s 3rdRisk business, elicited raised hands and nods all round during another fascinating RANT roundtable. No one likes managing suppliers. But it’s an increasingly critical endeavour. An <a href="https://www.bluevoyant.com/resources/the-state-of-supply-chain-defense-2025">estimated</a> 97% of global organisations experienced at least one supply chain breach in 2025  up from 81% the prior year.</p>
<h4><strong>Managing nuclear-grade risk</strong></h4>
<p>The stakes don’t come much higher than the supply chain of a nuclear submarine. That’s the world that guest speaker Helen Quinlan, Head of Cyber Risk at BAE Systems, lives in. She admitted that it can be “mind bogglingly” complex.</p>
<blockquote><p>“We have a large and complex supply chain. One of the main complexities is around the continuous monitoring of suppliers,” she said. It would be a matter of national security if the ownership of a key supplier was transferred to a hostile nation, for example, Quinlan explained.</p></blockquote>
<p>It’s not just about the ownership of vendor partners but also access to critical services that security leaders must consider when evaluating suppliers, suggested another attendee.</p>
<blockquote><p>“There’s a lot more geopolitical instability than we’ve had in my lifetime; so every company from a resilience perspective has an interest in considering what happens if a critical service or resource or component is suddenly denied for geopolitical reasons,” he argued. “The supply chain plays a significant part in an organisation’s resilience.”</p></blockquote>
<p>The security leaders around the table shared various approaches to TPRM. One said he builds disclosure rules regarding “material changes” into contracts &#8211; which meant that, when a legal supplier was hit by ransomware, they had to disclose.</p>
<p>Another advocated “defence in depth”, including questionnaires, continuous monitoring, contractual clauses and incident response testing. Diligent GRC Sales Director, Tom Ryan, added that sentiment analysis is useful because scorecard-based systems often don’t pick up the reality of what’s happening inside a supplier.</p>
<blockquote><p>“Everything looked really good, but our AI monitoring found employees complaining about the culture, about the practices of their information security team, on a forum,” he explained of one customer engagement. “That’s not what the company is showing to the world.”</p></blockquote>
<p>Another CISO sat around the table bemoaned the “scorecard complacency” of many organisations. “Scorecards look wonderfully green until you cut through and they’re red in the middle,” he said.</p>
<p>Most attendees agreed that questionnaires should just be the starting point; a first stage in a multi-layered TPRM process. But they can be made more insightful with the additional of AI tooling to analyse not just the answers themselves but also how questions were answered to flag risk indicators.</p>
<blockquote><p>“It’s not perfect, but if you’re able to capture the data there are ways to be able to spot indications of misinformation and fake evidence,” said one CISO.</p></blockquote>
<h4><strong>Get out of the cupboard and talk to the business</strong></h4>
<p>Engagement was a recurring theme on the night &#8211; both in terms of communicating with the business and reaching out to suppliers. One security leader complained that his suppliers are mainly “one-man bands” with limited cyber awareness, which makes it difficult to gain true visibility into risk. Another, who works in manufacturing, said it’s also challenging to engage when faced with a culture of “I know how to run my factory”.</p>
<p>A third CISO argued that collaboration with business leaders internally is essential.</p>
<blockquote><p> “You can’t do it if you’re locked in a cupboard all day. They’re the only ones who can assess how critical a supplier is,” he said.</p></blockquote>
<p>However, sometimes suppliers are so big that they refuse to engage with questionnaire-led TPRM efforts. Several security leaders bemoaned the larger SaaS players that simply direct such requests to their “trust centre”. “It’s hard to get the nuanced answers I need this way,” said one. Another suggested “It’s not necessarily the big [SaaS] suppliers I worry about, it’s the next tier down.”</p>
<h4><strong>Testing times for risk managers</strong></h4>
<p>However, if the big SaaS players don’t answer, you can always work out a backup plan, suggested one senior security leader, explaining that IR tabletop and real-time simulation exercises are often offered as part of their engagement. Among other things, this can help find the gaps between what a supplier expects a partner will do during an incident and vice versa, one attendee said.</p>
<p>However, another bemoaned tabletop exercises featuring overzealous participants with a “Tom Clancy complex” that try to create impossible series of events to wargame. This ultimately undermines business confidence in the exercise, he argued, adding: “It has to be within the realms of possibility. It has to have value.”</p>
<p>Another said that, partly for these reasons, the security team clearly establishes up front an important rule: “Don’t challenge the scenario, take it as real.”</p>
<p>Yet most seemed to approve of the idea of incident response testing as a way to lower third-party risk.</p>
<blockquote><p>“The problem is we’re never going to solve this problem because we’ll never have anything other than an opaque boundary with our suppliers. It comes down to trust, and the fact is we trust our suppliers far too much,” argued one CISO. “When we’re looking at our resilience, we don’t look at the ‘what-ifs’ and contingencies that we need to be able to deal with enough, particularly for the minimum viable business.”</p></blockquote>
<h4><strong>Getting the board on board</strong></h4>
<p>Perhaps most important to effective TPRM is getting engagement from senior management, because if the board isn’t on board, money simply will not be made available for these initiatives. BAE Systems’ Quinlan asked how those around the table approach this.</p>
<p>One lesson that emerged from the discussion is that visibility must be the first step to driving this type of engagement. “We see near misses every other day,” shared one CISO. “We collect a lot of data which goes up to the board, so they are throwing money at it.”</p>
<p>Another argued that regulators make it important for the board, as does “brand reputation and “how seriously the entity takes its business”. A £30m bank that “can’t afford to go down” is more likely to have a boards receptive to TPRM as a critical exercise than smaller players, he suggested.</p>
<p>However, this isn’t always easy in larger conglomerates. One complained of “mixed signals” from the corporate group leadership and at the individual company level.</p>
<blockquote><p>“At a group level it’s a huge focus. But the people that are paying for it on the ground say ‘we know it’s really important, but we don’t have any money’,” he explained.</p></blockquote>
<p>The good news is that tooling is improving to the point where AI can do much of the heavy lifting for teams, concluded Diligent’s Groenendaal. The right tools can remove the pain of spreadsheets, help risk leaders engage business executives through things like customised chatbots, and benefit from a “continuous multi-disciplinary overview of risk”, he said.</p>
<blockquote><p>“I’ve worked with many systems myself and they’re all boring. You feel like you’re going back to the 90s,” he added. “But with AI there are so many things we can improve.”</p></blockquote>
<p>The post <a href="https://rantcommunity.com/resources/supplier-risk-management-can-be-mind-bogglingly-complicated-where-do-we-go-from-here/">Supplier risk management can be “mind bogglingly” complicated: where do we go from here?</a> appeared first on <a href="https://rantcommunity.com">RANT Community</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
