Anything you can do, we can do worse!

‘On July 21, OpenAI disclosed that several of their models had broken out of an isolated test environment by exploiting a previously unknown (“zero-day”) vulnerability.’

But wait, it appears if one AI LAB having terrible security practices isn’t enough, we have another one now saying, after the Open AI incident, they have actually reviewed their logs, and they are terrible at security too!

Read more “Anything you can do, we can do worse!”

Vulnerabilities found with AI, oh my!

Ok, so the world is currently obsessed with AI (at least the digital world…) and with the latest Apple update releases we can see that LLMs have been used to help people find bugs! This is great news, finding bugs is better than not finding them!

The funny thing however is the obsession with CVE counts…. this is, honestly not a very useful metric to a defending org.. and I’ll try and explain why!

Read more “Vulnerabilities found with AI, oh my!”

You Cannot Block Infinity

We should block the RMM! We should block that IP! We should block that port! The trouble is; there’s 65535 ports per protocol (TCP/UDP), there’s billions of IPs (dynamic and rotating infra are a thing), and well that’s a lot of work, neve ending, in fact!!

This topic has come up a number of times recently so I thought I’d put it into a blog, so I had Claude generate this based on my quick fire views:

Read more “You Cannot Block Infinity”

You Can’t Defend Everything: Threat Modelling as an Economics…

In a world now seemingly filled with mad probability robots you might think this makes the world simpler, I’m not so sure…. More code, faster, more tools, faster, more technical debt, faster… and then what of the erosion of the human importance? Well human 2.0 is probably augmented not redundant… and who doesn’t love a bit of Deus Ex! Now full disclosure this blog is guided by me but written by Claude (mostly), why? Why not? I’m still here, guiding things, writing this intro by hand, but the concepts of cyber security, the foundations and underpinning logic, well they are probably older than me! I’m not talking about castles and moats, but even they play a part in our understanding of attack and defence. There’s even a bit of a public wifi link here if you read between the lines. Not every threat actors is all knowing and all powerful (in fact no one is!). So let’s see what Claude Opus 4.8 has to say about the topic:

Read more “You Can’t Defend Everything: Threat Modelling as an Economics Problem”

Cyber Myth: Attackers only have to be right once,…

Our cyber world is full of myths and FUD:

Attackers only have to be right once, Defenders have to be right all the time!

Firstly, let’s cut straight to the chase, I can only assume that someone who says this is ignoring or is unaware of how computer systems and intrusions work. But surely this is a true phrase, I’ve seen it repeated over and over again on LinkedIn, so it must be true right?

Read more “Cyber Myth: Attackers only have to be right once, Defenders have to be right all the time!”

Email Security: An Enablement Journey, Not a Maturity Ladder

Most organizations treat email authentication as a checkbox exercise. Deploy SPF, publish DMARC in reporting mode, call it done. But the real story isn’t about maturity tiers—it’s about what you unlock at each phase of implementation. And frankly, the gap between where organizations are and where they need to be is brutal.

This post outlines an enablement journey: each phase builds on the previous one and creates new capabilities that weren’t possible before.

Read more “Email Security: An Enablement Journey, Not a Maturity Ladder”

DNSSEC

‘You are totally compromised!’ because you don’t have DNSSEC configured on domain…..

The implication is that you’re one packet away from catastrophe. It’s alarming. It’s also, for the overwhelming majority of organisations, not true. I have been talking about this for years and years!

Here’s the quickest way to see through it. I scanned the Majestic Million – the top one million domains on the internet – for DNSSEC. About 6.75% were signed (around 8.2% if you only count domains that actually resolve). The .com zone, which is half the list, sits at 4.6%. And the unsigned set includes google.com, amazon.com and microsoft.com.

So if “no DNSSEC” means “totally compromised,” then the three most-attacked, best-defended companies on the planet are totally compromised, and have been for years, on purpose. They aren’t. The finding is measuring conformance to a checklist, not risk. Let’s understand why this is!

Read more “DNSSEC”

The danger of internet exposed RDP

There’s lots of things in cyber security to consider when looking at how to defend a network, and whilst the world goes mad about public wifi and juice jacking, the real threats are often far simpler. Imagine having say an Active Directory domain member, or even controller exposed to the internet with Remote Desktop Protocol? Might sound insane but this is a common route for entry for ransomware actors.

Read more “The danger of internet exposed RDP”

The cost of resetting a password

If someone asked you how much the cost of a task is, I bet you would struggle to given them an accurate response, the default position of most people is to underestimate a cost of doing something (but estimation science show’s us that it tends to vary based on role e.g. project managers are risk averse, engineers think they can solve things faster than they can and executives often just want it to be cheaper for the sake of it being cheaper – Parkinsons Squeeze I think that is called)

Years ago I stared looking at total cost of ownership (TCO) and Return on Investment modelling (I mean a lot of years ago….) and I’ve created a range of models for organisations for:

  • Sales Estimation
  • Business Cases
  • Budget Planning
  • Project Planning
  • System Optimisation Analysis
Read more “The cost of resetting a password”

Cybercrime and data theft

During an incident it’s one of the first questions people ask, what did the attacker do? Did they steal any data? How did they do it?

All of which are typically rather difficult to answer in the first, probably week of an incident (incidents vary, sometimes it’s very obvious, other times you can’t be 100% sure on some details!)

But recently I’ve been talking lots about the way organisations communicate during incidents to their customers and the public etc. I’ve been explaining that the day 0 comms of ‘no data was stolen’ followed by a ‘lots of data was stolen’ in say day zero plus five… well it doesn’t help with my my trust in the victim organisation. Which to me, seems like an odd strategy for organisations to take. They have options:

Read more “Cybercrime and data theft”