Insight
Articles on security as a leadership responsibility, written for the people who make the decisions, not the ones who run the systems.
These are lasting professional articles, written to stay relevant. Dated news is under News.
Security is decided in the boardroom, not the server room
In most organisations, information security is still something handled by somebody else, somewhere further down the structure. Responsibility, meanwhile, has moved upwards: regulation and owners now expect the board and the executive team to account for risk, priorities and control. Here is what owning security actually involves as a leader, and why it does not require you to become a technologist.
Operational security in the energy sector is national preparedness
In energy and other critical infrastructure, the cost of an outage is rarely measured in lost revenue alone. It is measured in what else stops working: water supply, payments, cold chains, care homes. This article looks at the IT/OT boundary, at plant designed to run for decades, at the supply chain, at what NIS2 actually asks of the board, and at what separates genuine preparedness from a preparedness document.
Under NIS2, the board's accountability is personal and documented
NIS2 places accountability for security where the decisions are made. The directive requires the management body to approve risk management, oversee it, undergo training itself, and be able to evidence what it has decided. This article sets out what that means in practice, and where the line runs between having documentation and having control.
AI in the business: how to make a safe start
Most organisations have already started using AI: rarely through a decision, more often through employees who found a tool that made the day easier. This article explains, calmly, what a language model is and is not, why that matters when you are trusted with confidential information, and how to begin in a way you can stand behind. It is written for leaders, not for developers.
AI governance: auditing what is not deterministic
For organisations already using AI in something that matters. On ISO/IEC 42001 as a management system, its relationship to ISO 27001, roles and duties under the EU AI Act, data governance and model risk. And on how to audit a system that does not give the same answer twice.
Latest news
Dated pieces on what is happening right now.
Records are being pulled from Salesforce and ServiceNow portals that need no login
Reco is tracking an ongoing campaign it calls City-Forum, in which a single tool written in Go pulls records from customer portals in Salesforce Experience Cloud and ServiceNow. All the traffic comes from one server that has been standing since March 2025, and the targets include telecoms, banks, software vendors and public sector portals.
New exploit is said to grant SYSTEM through Microsoft Defender
On 12 August 2026 the researcher known as Nightmare Eclipse released exploit code called ShieldBreak, said to grant SYSTEM privileges through Microsoft Defender on fully patched machines. The researcher describes it as a full bypass of the RoguePlanet fix, and Will Dormann states that the code works when Defender is enabled.
A signed kernel driver now hides the CoolClient backdoor on Windows
Kaspersky has analysed a new version of the CoolClient backdoor that installs a signed driver in the Windows kernel. The driver hides the malware process, its files and its registry keys, and the activity is attributed to HoneyMyte, also known as Mustang Panda.