As the record hot UK summer of 2025 quietly slips into Autumn we have 3 articles to keep the temperatures hot!

AI agents are already inside your network. They’ve got valid credentials. Some have privileged access.
They’re querying your databases, pulling sensitive files, committing code, and triggering workflows. Most security teams aren't monitoring them properly because these AI agents aren’t human. They are seen as tools.
They’re invisible insiders.
We’ve historically built our insider threat models around people:
But AI agents change the game.
They're not malicious. They don’t have motive. But they can still expose data, take unapproved actions, or be manipulated, especially if they’re running without proper governance.
Most of them are running with:
This is not innovation. It’s exposure.
If your business is deploying AI agents as part of strategy (or your teams are doing it quietly - shadow AI risk), you need to reframe how you think about identity, access, and control.
Prompt injection = the new phishing
AI should never act alone
Would you give a junior hire root access on day one, with no supervision, no audit trail, and no formal role description?
No? Then why are you doing that with your AI agents?
It just needs: access, autonomy and a blind spot in your security model.
If it's not in your governance model an AI agent with access is not a tool. It’s a colleague you didn’t interview, didn’t train properly, and after something goes wrong its too late to investigate. Your reputation is already damaged.
If you wouldn’t give a junior hire unrestricted system access on day one don’t give it to an LLM-driven agent either.
Start treating your AI as part of your threat model.
Not doing so won’t just expose your systems it could become the next breach headline you’re explaining to the board.
It’s time to bring AI agents into your insider threat framework. Before your next breach comes from the inside and you didn’t even see it coming.
If you’re building or buying AI tools with access to sensitive systems or data, you need a governance model in place now.
Need help building it? Let’s talk. DM me "AI Governance" to bring your AI under control.
Why SMEs Must Reframe Cybersecurity as a Growth Enabler & Not a Back Office Burden

The boardroom still sees cybersecurity as a cost centre. Something to “fix” after growth is achieved. Or after an attack. But that mindset is putting your business on the fast track to reputational damage, legal exposure, and stalled investment.
You've got the strategy and funding allowing you to scale fast and not treating cybersecurity as critical, you're gambling with your future.
The stats are unforgiving:
And still, many execs think, "We haven’t been hit yet." That’s like saying, "We haven’t had a fire, so let’s skip the insurance."
So, what’s the real blocker? Cybersecurity is still being pitched to business leaders in technical language. Firewalls. SOCs. CVEs. It sounds expensive. It sounds complex. It sounds like something for “later”.
We translate cybersecurity into business impact:
Security isn’t the brakes it’s the steering wheel. If you want to grow sustainably, build security into the foundations. Not as an afterthought. As an advantage.
Are you still thinking "we haven't been hit yet" or "why would they attack us?" If that is your cybersecurity strategy you will be attacked.
Start with a board-level cybersecurity risk assessment mapped directly to business goals, not just checklists. If your current provider isn’t doing that, they’re selling fear and a non-existent silver bullet.
You need strategy. DM me the word "strategy" and we'll build cyber security into your strategy aligned with your growth.
Third-Party Risk in 2025: What Businesses Keep Missing Until It's Too Late

SolarWinds, MOVEit, Okta, NHS, Marks & Spencer, Air France KLM. The list goes on. And still, many businesses think: “Our suppliers are secure. We’ve done our due diligence.”
But third-party risk isn’t just a box-ticking exercise.
It’s an ongoing, dynamic threat surface that most businesses are failing to monitor. Why? Because we trust too easily. Or we don’t have the resource to validate and challenge what vendors claim.
Your weakest link is outside your business.
The cost? Reputational damage, threat of regulatory fines, loss of trust, loss of contracts, lawsuits and massive incident response bills.
It’s not an Excel sheet with expiry dates. It’s a living ecosystem.
Good vendor management isn't bureaucracy it’s resilience. You’re only as secure as the third party that forgot to patch last week.
Our advice: Build third-party risk into your overall cyber strategy. Don’t isolate it. Treat vendors like you treat internal teams: assess their risk, train, test, and verify.
Don't wait for a supply chain incident to force your hand. Let's start building a third-party risk strategy that’s proportionate, practical, and regulator-ready? DM me the word "third-party" so you are not the next headline.
In the 1980's Anguilla, a tiny Caribbean island, was handed the internet extension .ai. The internet was in its infancy and countries were being handed their own unique website addresses, the UK got .UK. In 2024 Anguilla earned nearly £30m from people registering domains with a .ai extension. Revenue from selling .ai domains now accounts for 23% of total revenues for the country. This year Anguilla expects the revenue from .ai domains to grow to £36m.
