Cyber Security Insights September 2025

Cyber Security Insights September 2025

Written by Bryan Altimas

As the record hot UK summer of 2025 quietly slips into Autumn we have 3 articles to keep the temperatures hot!

  • The Insider Threat You're not Watching: AI Agents With Access Credentials
  • Business as Usual Is a Breach Waiting to Happen
  • Your Supply Chain Is Your Biggest Unseen Threat

The Insider Threat You’re Not Watching: AI Agents with Access

Ai agents insider threat

AI agents are already inside your network. They’ve got valid credentials. Some have privileged access.

They’re querying your databases, pulling sensitive files, committing code, and triggering workflows. Most security teams aren't monitoring them properly because these AI agents aren’t human. They are seen as tools.

They’re invisible insiders.

AI agents = non-human insiders with real power

We’ve historically built our insider threat models around people:

  • The disgruntled employee
  • The negligent contractor
  • The rogue developer

But AI agents change the game.

They're not malicious. They don’t have motive. But they can still expose data, take unapproved actions, or be manipulated, especially if they’re running without proper governance.

Real-world scenarios we’re already seeing:

  • AI agents in finance reconciling payments across systems
  • HR bots pulling sensitive employee records
  • Developer assistants pushing code with access to secrets
  • Customer service AI agents connected to CRMs, email, and cloud storage

Most of them are running with:

  • API keys that never expire
  • Access logs no one reviews
  • Privileged access credentials that are not needed
  • No clear owner

This is not innovation. It’s exposure.

Security teams must adapt and fast

If your business is deploying AI agents as part of strategy (or your teams are doing it quietly - shadow AI risk), you need to reframe how you think about identity, access, and control.

  • AI agents must be treated like internal users
  • Create identities for them
  • Apply least privilege
  • Log every action they take
  • Set expiry and rotation for their credentials
  • Monitor their behaviour as you would a human insider

Prompt injection = the new phishing

  • Attackers can manipulate input to make the agent leak data, delete files, or call functions it shouldn’t
  • Model validation, prompt sanitisation, and testing for abuse must become normal

AI should never act alone

  • Don’t give agents full system access from prompt to production
  • Insert human review where it matters—especially in legal, financial, and security workflows

Think of it this way:

Would you give a junior hire root access on day one, with no supervision, no audit trail, and no formal role description?

No? Then why are you doing that with your AI agents?

AI doesn’t need malice to be a threat

It just needs: access, autonomy and a blind spot in your security model.

If it's not in your governance model an AI agent with access is not a tool. It’s a colleague you didn’t interview, didn’t train properly, and after something goes wrong its too late to investigate. Your reputation is already damaged.

If you wouldn’t give a junior hire unrestricted system access on day one don’t give it to an LLM-driven agent either.

Start treating your AI as part of your threat model.

Not doing so won’t just expose your systems it could become the next breach headline you’re explaining to the board.

It’s time to bring AI agents into your insider threat framework. Before your next breach comes from the inside and you didn’t even see it coming.

If you’re building or buying AI tools with access to sensitive systems or data, you need a governance model in place now.

Need help building it? Let’s talk. DM me "AI Governance" to bring your AI under control.

Business as Usual Is a Breach Waiting to Happen

Why SMEs Must Reframe Cybersecurity as a Growth Enabler & Not a Back Office Burden

Cybersecurity business enabler

The boardroom still sees cybersecurity as a cost centre. Something to “fix” after growth is achieved. Or after an attack. But that mindset is putting your business on the fast track to reputational damage, legal exposure, and stalled investment.

You've got the strategy and funding allowing you to scale fast and not treating cybersecurity as critical, you're gambling with your future.

The stats are unforgiving:

  • 60% of SMEs hit by a cyberattack close within 6 months (source: Cybersecurity Ventures).
  • Increasingly ransomware attacks now target SMEs because attackers know your defences are weaker than the big players.

And still, many execs think, "We haven’t been hit yet." That’s like saying, "We haven’t had a fire, so let’s skip the insurance."

So, what’s the real blocker? Cybersecurity is still being pitched to business leaders in technical language. Firewalls. SOCs. CVEs. It sounds expensive. It sounds complex. It sounds like something for “later”.

We translate cybersecurity into business impact:

  • How secure systems reduce downtime, ensuring business continuity
  • How good governance protects intellectual property, enabling safer deals and partnerships
  • How demonstrating compliance unlocks contracts and investor confidence
  • How privacy builds customer trust and trust builds revenue.

Security isn’t the brakes it’s the steering wheel. If you want to grow sustainably, build security into the foundations. Not as an afterthought. As an advantage.

Are you still thinking "we haven't been hit yet" or "why would they attack us?" If that is your cybersecurity strategy you will be attacked.

Start with a board-level cybersecurity risk assessment mapped directly to business goals, not just checklists. If your current provider isn’t doing that, they’re selling fear and a non-existent silver bullet.

You need strategy. DM me the word "strategy" and we'll build cyber security into your strategy aligned with your growth.

Your Supply Chain Is Your Biggest Unseen Threat

Third-Party Risk in 2025: What Businesses Keep Missing Until It's Too Late

Third party risk

SolarWinds, MOVEit, Okta, NHS, Marks & Spencer, Air France KLM. The list goes on. And still, many businesses think: “Our suppliers are secure. We’ve done our due diligence.”

But third-party risk isn’t just a box-ticking exercise.

It’s an ongoing, dynamic threat surface that most businesses are failing to monitor. Why? Because we trust too easily. Or we don’t have the resource to validate and challenge what vendors claim.

Your weakest link is outside your business.

What We Have Seen

  • A partner at a law firm’s email account gets breached. Confidential documents exposed and fraudulent payments attempted.
  • A CRM system has an API misconfiguration and attackers exfiltrate sensitive client data.
  • A vendor you dropped two years ago still has access to your cloud instance.

The cost? Reputational damage, threat of regulatory fines, loss of trust, loss of contracts, lawsuits and massive incident response bills.

What does modern third-party risk management look like?

It’s not an Excel sheet with expiry dates. It’s a living ecosystem.

  • Risk-tiering your suppliers based on what access to data they have, not spend
  • Regular security posture reviews at a minimum annually
  • Contractual obligations to report incidents immediately
  • Offboarding access which is automated and verified
  • Vendor breach simulations in your incident response plan.

Good vendor management isn't bureaucracy it’s resilience. You’re only as secure as the third party that forgot to patch last week.

Our advice: Build third-party risk into your overall cyber strategy. Don’t isolate it. Treat vendors like you treat internal teams: assess their risk, train, test, and verify.

Don't wait for a supply chain incident to force your hand. Let's start building a third-party risk strategy that’s proportionate, practical, and regulator-ready? DM me the word "third-party" so you are not the next headline.

And finally, an interesting fact

In the 1980's Anguilla, a tiny Caribbean island, was handed the internet extension .ai. The internet was in its infancy and countries were being handed their own unique website addresses, the UK got .UK. In 2024 Anguilla earned nearly £30m from people registering domains with a .ai extension. Revenue from selling .ai domains now accounts for 23% of total revenues for the country. This year Anguilla expects the revenue from .ai domains to grow to £36m.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right