
Cyber security threats have evolved dramatically in 2025. As AI advances AI powered threats are emerging. AI powered defence is also developing rapidly. However, the more traditional risks remain and need managing. This month we look at:
In 2025, the insider threat has evolved. And if your organisation is still only looking inward for malicious employees, you're missing the bigger picture.
The traditional image of an insider threat a disgruntled staff member downloading sensitive data on their way out the door is outdated. Today, insider threats are more complex, subtle, and often unintentional.

Adversaries don’t just exploit access they exploit assumptions. HR vetting, procurement workflows, and academic partnerships all become potential infiltration vectors.
Are you sure your remote interview using Teams and Zoom is actually interviewing a real employee? Nation state sponsored attacks from North Korea have successfully managed to get fake employees recruited into the technology sector. They then extract intellectual property (IP) to North Korea. Evidence shows this has been so successful in the tech sector it is now being widened to other sectors.
Using stolen identities to access organisations has been prolific in 2025. The last few months has seen employees selling their access credentials.
Someone on payroll sold their login. That’s it. That’s the breach.
It’s not about how good your firewall is. Or how clever your EDR is. If an employee chooses to sell their keys to the kingdom you are in trouble before your tools even blink.
And we’re not just talking about disgruntled tech staff. Some of the compromised accounts were low-paid workers, contractors, and even interns.
Economic pressure. Remote work. A lack of visibility. All of it fuels this new threat.
A meeting suddenly appears in your calendar at very short notice with the CEO.
The engineering consultancy Arup was hit by a highly sophisticated scam involving deepfake video calls. During the meeting, staff were instructed to transfer transfer $25m in 5 separate payments. And they did. Because why wouldn’t they? The CEO asked on a video call.
Except the CEO was never there.
This isn’t deepfake audio anymore. This is real-time deepfake video conferencing. And the tech is frighteningly good.
If your people aren’t trained to spot the signs or empowered to question “authority” in high-pressure situations you’re a sitting duck.
The insider threat has evolved. You are now facing:
Cybercrime has moved into the grey areas of psychology, economics, and AI-enabled deception.
And the old playbook password policies, VPNs, endpoint controls is not enough. Even zero trust must evolve.
Here’s what scaling businesses must do to stay ahead:
Insiders are not always villains. Sometimes they are victims of coercion, fraud, or desperation. Other times, they are targets of cutting-edge fake media attacks.
Either way, the impact is the same: your data, your reputation, your money gone.
So ask yourself:
If those questions make you uncomfortable, that’s a good thing. Discomfort sparks action.
And action is what we need.
Are insiders your biggest threat? DM me the word "insider" to understand and mitigate your insider threat.
You have heard of Shadow IT unapproved apps, tools and cloud services used without IT's knowledge.
Now meet its more dangerous cousin: Shadow AI.
And if you think it’s not happening in your organisation it is already too late.

AI used in your business that:
Examples?
None of it logged. None of it governed. None of it secure.
And it’s growing faster than your policies can keep up.
Shadow AI is not just a tech issue. It’s a data protection, reputational, and regulatory problem waiting to explode.
Here is why it should worry you:
Let’s not forget AI generated content can be confidently wrong, offensive, or discriminatory. If it goes out under your brand, you own it.
People are not trying to cause harm. They are trying to get work done faster.
They see AI as a competitive edge. In many cases it is.
But without guardrails, they end up:
All under the radar of governance, IT, legal and compliance.
Admit it is happening. Stop pretending you can block it completely. Start by discovering where AI tools are being used across the business formally and informally.
Create a simple AI Use Policy. Not a 40-page PDF. A one-pager that explains what is allowed, what is not, and when to escalate.
Implement AI tool reviews. Like vendor due diligence, but for AI models and services. Look at security, data handling, model risks and usage terms.
Train teams. Help staff understand the risks especially around data leakage, decision-making, and hallucinated outputs. Teach them how to ask better prompts and spot when something looks wrong.
Log usage. If teams are using AI tools, track it. You can’t govern what you don’t know exists.
Build secure alternatives. If you want to stop Shadow AI, offer secure, approved, and well-supported AI solutions internally.
Shadow AI is not a rogue actor in a hoodie. It is your top performing team trying to move faster. It’s your intern trying to impress. It’s your executive team experimenting without realising the risk.
You do not stop Shadow AI by banning it. You stop it by governing it, the same way you would any powerful tool.
And if you’re not sure where to start? DM me the word "shadow". We help scaling businesses get control of their AI risk before it controls them.
You can spend millions on technology. Deploy the latest AI tools. Hire certified talent.
And still suffer a catastrophic breach.
Why? Because cybersecurity is not just a technical challenge. It involves people. It starts and ends with culture and ethics.

Peter Drucker famously said:
“Culture eats strategy for breakfast.”
In cybersecurity, culture eats policies, frameworks and controls and sometimes, your business continuity.
An organisation with a strong culture of ethics, accountability and psychological safety is far more likely to:
You don’t need to be in the ethics department to be ethical. You just need to have clarity: What’s right? What’s wrong? What’s acceptable? What’s not?
The absence of ethical guidance creates ambiguity. And in cyber security, ambiguity is deadly.
Strong ethical foundations:
If your team is afraid to admit mistakes, they won’t report them. If they're ridiculed for clicking a phishing link, they’ll hide it.
Cybersecurity thrives when people feel safe to speak up.
Not pinging your staff with another 20-minute learning module. Not forcing a once-a-year training during Cyber Awareness Month.
But embedding security into how your team works, talks, and decides every day.
Ethical, secure culture isn't a checkbox exercise. It’s a competitive advantage.
In sectors like healthcare, finance, and professional services, trust is your most valuable asset. Lose it and clients, regulators and investors will lose confidence in you too.
You can’t firewall your way out of a culture problem. But you can lead your organisation to a safer, stronger future by building a culture where security and ethics are everyone’s responsibility.
Not just the CISO’s. Not just IT’s. Everyone’s.
Have you spent hard earned money on cyber security tech and still been hacked? Let’s talk. We help organisations align cybersecurity, ethics, and business strategy. Because compliance is the minimum. Trust is the goal. DM me the word "ethics".
