How did we get here, writing the last Cyber Security Insights of 2025? This year seems to have passed by in a flash. Probably because cybersecurity risk and threats have evolved rapidly during the year.
I am not going to do the norm for this time of year and make my predictions for 2026. This year the threat actors have got rich by stealing identities and access credentials. Why change what is working? Companies holding the front door open for threat actors and allowing them in with valid access credentials will continue in 2026.
This month we will talk about:
I wish you all a merry Christmas and a happy New Year free from cyber incidents.
AI isn’t just powering your business growth. It is also powering your enemies.
That is the stark truth facing every organisation right now from scaling fintechs and e-commerce players to global healthcare and legal teams, every organisation who generates and stores data.
In cybersecurity circles, we have always known that AI would transform the threat itself.
AI is not just a business tool. It’s been weaponised.
Attackers are building AI-powered phishing kits that adapt in real time to your tone of voice. They’re crafting deepfakes to bypass onboarding or identity checks. Deepfake videos are already holding rapidly arranged meetings with the "c-suite" to commit fraud. And they’re using automated vulnerability scanners that operate faster than most patch management cycles can handle.
These are just some of the ways threat actors are using AI:
We are not just facing more attacks. We are facing more convincing, more automated, and faster-moving attacks.
This is not theory. It is exposure and vulnerability.
Your attackers no longer need to be skilled coders. They just need prompts.
Meanwhile, your team may still be relying on:
All of which are sitting ducks in an AI-accelerated threat landscape.
Yes, AI also helps us detect patterns, automate response, triage incidents, and hunt threats.
But let’s not pretend we’re ahead.
If your AI use in cyber defence is limited to what came pre-packaged in a tool and is business focused … And your governance doesn’t account for the business risks AI introduces (bias, hallucinations, model drift, shadow AI, for example) and ignores the cyber security risks such as synthetic data abuse, deep fakes, model manipulation, data poisoning… Then you're not building resilience. You're building blind spots.
AI can help, but only with:
If you're a CISO, CTO, COO or Head of Risk reading this here’s my candid advice:
AI is no longer a future threat. It's today's reality on both sides of the battlefield.
You don’t have to fear it.
But you do have to understand it, govern it, and build a cyber strategy that reflects the new speed and scale of risk.
AI has changed the game. Time to change the rules you’re playing by.

It’s not just an IT problem. It never was.
Let’s stop treating cybersecurity like a back-office bolt-on. Or a cost centre. Or worse a line on the risk register that’s “covered by IT.”
In 2025, cyber risk is business risk.
It’s a reputational risk. A legal risk. A compliance risk. An operational continuity risk. And increasingly a deal-breaker. Just ask M&S and Jaguar Land Rover.
When an attack hits:
Just ask any business caught in the wake of a ransomware attack or supply-chain breach where the incident started with a compromised access credential, one compromised endpoint or one missed patch, and ended with:
None of that is "just IT".
Boardrooms are waking up, especially in the wake of M&S and JLR. Smart CEOs and CFOs aren’t asking, “How secure are we?” They’re asking, “What happens to our business if we get hit?”
The stakes aren’t theoretical:
Insecure = uninvestable. Insecure = uninsurable. Insecure = unreliable.
If you are an established business or a business scaling fast, big client deals in the pipeline, heavy on data or cloud here's what I would tell your leadership team:
The question isn’t if you'll face a cyber incident.
It’s whether your business is designed to survive it, recover from it and still grow.
If your cyber strategy is still locked in IT… It’s time to unlock it.
Move cyber out of the server room. Bring it into the boardroom.
Your growth and your survival depends on it.

Incident Response Burnout Is a Business Risk.
When a breach hits, most companies rush to recovery mode..
But few stop to ask: What’s happening to the people responding to it?
This isn’t just a technical fire. It’s a human burnout crisis.
And it’s costing you far more than you think.
Breaches are messy. The pressure is immense. But if your plan assumes:
…you are already behind.
What I’ve seen in incident response projects:
You patch the systems. But do you patch your people?
This is a governance issue not just an HR one.
The worst part? Most teams don’t talk about it.
They “white-knuckle” their way through the breach, then quietly burn out.
Or leave.
Your tools won’t save you if the humans behind them are already at breaking point.
If you're understaffed, undertrained, or unsupported that’s not resilience. That’s luck running out.
Burnout during or after breach isn’t just unfortunate. It’s a strategic weakness.
It shows your leadership didn’t plan for human limits. It proves your incident response is reactive, not resilient. It signals to regulators, clients and investors that you are unprepared.
Plan for fatigue. Build escalation paths, handover options, and team rotation into your IR plan.
Include wellbeing in your governance. Appoint a “human ops” lead during an incident someone to manage workloads, check-ins, and rest.
Debrief honestly. Not just what failed technically but what failed operationally, emotionally, and communicatively.
Run real simulations. Not just tabletop. Stress-test the humans, not just the tech.
Support after the breach. Time off. Psychological safety. Recognition. Lessons learned and not blame assigned.
When the breach hits, tech can help.
But people carry the load.
If you don’t build governance that protects them, supports them, and designs for their limits your incident response isn’t secure.
It’s a crisis waiting to happen.
Cyber resilience isn’t just about systems. It’s about sustainable response capacity built on human strength, not burnout.

