Perspectives from practice.
Points of view from practitioners on the security decisions enterprise leaders are making now, across our eight capabilities.
AI agents need identity, policy and evidence
Enterprise AI is moving from answering questions to taking actions. The security model has to follow.
AI agents need identity, policy and evidence
Enterprise AI is moving from answering questions to taking actions. The security model has to follow.
You can’t defend what you haven’t classified
Why asset clarity is a board-level risk decision: visibility, ownership and accountability before tools.
Secure by design: start left, then shift left
Security that begins in the planning room costs a fraction of security that begins in the incident room.
The modern SIEM is a decision system, not a log repository
Drowning in alerts is not a detection strategy: five deployment mistakes and what SIEM plus SOAR changes.
A penetration test is a snapshot. Resilience requires continuous validation
Functional testing proves the application works. Security testing proves it survives.
900 million requests later: a year at the edge
What a year of running a machine-learning WAF at the load-balancer layer taught us about hardening as a lifecycle.
Security is not a firewall. It is seven stacked decisions
The control existed, just not at the layer that got hit. Defence in depth is seven audits.
Trust is built one query at a time
Every access to sensitive data is a silent contract: secure, justified, logged. Observability is how you keep it.
If audits need a war room, you have a panic programme
Compliance is not an audit activity. It is a system that runs every day: seven layers from the estate to the regulator, with evidence that generates itself.
Know what you ship: the SBOM as a security control
When Log4j broke, some organisations knew their exposure in hours and others took weeks. The difference was a list.
Banning is not a strategy. It is a confession
Samsung, JPMorgan, Apple and Verizon restricted public AI tools. Their people kept using them. What a shadow-AI problem actually is.
Segmentation is the control you already own
Most estates already have the primitives to cut off the attack path that matters most. The gap is topology visibility and a rollback plan the team trusts.
Every red-team finding should become a detection
A report gets filed and three months later nobody knows if the technique still works. The fix is a rule: every finding becomes a detection, or a documented reason why not.
Hardening is a lifecycle, not a project
A hardening score is a photograph. The moment it is taken, a patch, a package, a reverted setting starts ageing it. What CIS Controls v8 actually asks for.
Dashboards are not evidence
A dashboard proves the system is fine right now. A regulator asks about a specific moment weeks ago. What monitoring has to produce before it can prove anything afterwards.
The board's next question just changed
OWASP Top 10:2025 is the biggest rewrite in years. Three of its ten shifts are not about code: supply chain, misconfiguration and how systems fail.
AI security is a loop, not a checklist
Secure the model, test it, deploy, move on: that approach is already out of date. AI systems evolve and drift after they ship.
Attacks don't break systems. They break trust
Ransomware, phishing and DDoS look like different problems. They all resolve to the same three failures: confidentiality, integrity or availability.
Threat hunting is what alerts can't do
An alert fires only when activity matches a rule someone already wrote. Hunting starts from a hypothesis, and every hunt ends in a finding, a documented negative or a logged gap.