Commentary
Analysis, perspective, and informed opinion on the threats, trends, and decisions shaping cybersecurity for organisations that can't afford to get it wrong.
The Agentic Attack Surface: Your AI Assistant Is the New Endpoint
Enterprise AI assistants now hold privileged access to code repositories, cloud credentials, internal APIs, and production systems. Security teams are not monitoring them. This is a structural blind spot with material consequences — and it's arriving faster than most organisations realise.
The 2026 Iran Conflict and the Dawn of Cyber-Enabled Kinetic Targeting
Iran's conflict with the US and Israel in 2026 confirmed what threat analysts had long theorised: cyberspace is now inseparable from kinetic warfare. What the Iran war reveals about hybrid doctrine — and what it means for critical infrastructure operators.
The AI Patch Wave Is Already Here -- and Defenders Are Already Behind
The NCSC warned in May that AI-accelerated vulnerability discovery would create a forced correction of technical debt. One month later, Anthropic's Project Glasswing has already found over 10,000 critical vulnerabilities in open source. The bottleneck is no longer finding bugs. It's fixing them.
The Attack Is Coming From Inside the Country: China's Compromised-Device Networks and Why Your Perimeter Controls Miss Them
A joint advisory from CISA, NCSC, and ten allied nations describes how China-linked threat actors have abandoned dedicated attack infrastructure in favour of networks of compromised home routers and IoT devices. The implication for defenders is worse than it sounds.
The Data That Nation-States Actually Want Is Sitting in Your Document Management System
Law firms and professional services firms are among the most intelligence-rich targets in the UK economy. Understanding why clarifies the threat -- and why perimeter security alone is the wrong response.
The Public Sector Cyber Gap: Why Government's Security Posture Trails the Threat
The structural factors that make the UK public sector a persistently soft target -- fragmented IT estates, procurement cycles that optimise for cost over security, and a talent market that can't compete with private sector pay -- are not going away. Here's what the gap looks like and what's actually being done about it.
Why Ransomware Groups Don't Die When You Arrest Their Leaders
The ransomware-as-a-service model has created a resilient criminal infrastructure that survives law enforcement actions, FBI seizures, and individual prosecutions. Understanding why is the first step to defending against it.
The OT/ICS Blind Spot: Why Your Cyber Risk Picture Is Missing Half the Picture
Most boards have a reasonable grasp of IT cyber risk. Almost none have adequate visibility into the operational technology that runs their industrial processes, utilities, and physical infrastructure. This gap is exactly what state actors are exploiting.
Nation-State Threats: What Business Leaders Get Wrong and Why It Matters
Most executives conflate nation-state cyber activity with the ransomware threat they're more familiar with. They are different in purpose, method, and the defences required. Getting this wrong shapes your entire risk posture.
The Real Cost of a Critical Infrastructure Attack: Beyond the Ransom
When a critical infrastructure operator is hit, the ransom payment is usually the smallest line on the eventual damage assessment. The true costs -- operational, regulatory, reputational, and systemic -- are far larger and far longer-lasting.
No commentary matches this sector filter.
Twenty-Two Seconds: What M-Trends 2026 Says About Attacker Speed and Defender Reality
Mandiant's M-Trends 2026 report, grounded in over 500,000 hours of incident investigations, contains several findings that should recalibrate how security teams think about detection windows, initial access economics, and the real mechanics of ransomware recovery denial. The headline statistic — 22 seconds from initial access to secondary threat group handoff — isn't the most important one.