Volume 9 (2025-26)

Each volume of Cyber Security: A Peer-Reviewed Journal consists of four quarterly 100-page issues. The articles published in Volume 9 will be listed here in due course.

You can see a list of the forthcoming scheduled content for Volume 9 of the journal here.

 

Volume 9 Number 4

Editorial
Beckett, Simon

Papers
From reactive to resilient: Cyber security in the age of AI
Lesley Kipling, Chief Security Advisor, Microsoft, UK

Abstract ▼

The world of cyber security is moving at breakneck speed. To keep up — or, even better, to get ahead of the curve — security leaders must do more than just react to threats as they appear. With the rapid advancement of technology, modern security strategies should look to weave together the strengths of detection engineering, predictive analytics and preventive engineering into a unified, adaptive approach. By embracing this integrated feedback loop and harnessing the power of artificial intelligence (AI), integrated threat intelligence (TI) and comprehensive observability, organisations can move beyond merely identifying and responding to attacks. They can outpace adversaries, anticipate threats and engineer resilience at every layer of the organisation, predicting, adapting and stopping adversaries before they cause harm, intentionally designing controls to limit the blast radius of any successful attack. This paper explores the strategic imperative of moving from reactive to resilient, offering a new vision for cyber security in a world where attackers are relentless and innovation is essential. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: preventive engineering; predictive shielding; observability; graph technology; automated remediation; disruption

Case study: Converging physical and cyber security — lessons from the protective security assessment framework
Shane Brady, Associate Director, Strategic Security, NSW Premier’s Department, Australia

Abstract ▼

As digital transformation accelerates across government and critical infrastructure, the convergence of physical, information and personnel security has emerged as a strategic imperative. This paper explores the evolving landscape of security risk management, where traditionally siloed functions are increasingly integrated to counter hybrid threats, foreign interference and insider risks.1,2 Drawing on contemporary frameworks, including the NSW Premier’s Department Protective Security Assessment Framework3 and international guidance from agencies such as Cybersecurity and Infrastructure Security Agency (CISA), the paper examines how convergence enhances resilience, streamlines governance and fosters a unified security culture. Through analysis of operational models, governance structures and a case example, it highlights the benefits of cross-functional collaboration, executive sponsorship and shared accountability. It argues that convergence is not merely a structural adjustment, but a paradigm shift in how security is conceptualised, coordinated and executed. The findings support a proactive, intelligence-led approach to protective security that aligns with national critical functions and reinforces public trust in institutional integrity. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: security risk convergence; risk management; function integration; connected vehicles; media sanitisation

Integrating quantitative and qualitative reasoning to mitigate threats
Frank L. Greitzer, Chief Behavioural Scientist, Cogility Software, USA

Abstract ▼

Traditional threat assessment approaches used by insider threat hubs and law enforcement are primarily reactive, focusing on the response to an incident and collecting forensic data to support the investigation. More mature, proactive programmes aim to prevent or mitigate risks with specialised behavioural threat assessment analysts, who use multidisciplinary approaches to identify and manage at-risk individuals before an incident occurs. Threat assessment methods range from the use of individual, unstructured clinical judgments to formal qualitative models that provide structured guidelines, to predictive analytic models. This paper describes the aims and characteristics of qualitative and quantitative models to anticipate insider threats and discusses the integration of these traditionally divergent threat assessment methods, highlighting the importance of combining human judgment, data science and artificial intelligence (AI) to develop holistic risk management strategies. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: behavioural threat assessment; insider threat; insider risk; structured professional judgment; violence risk assessment

Sizing up the quantum threat to cyber security: Making sense of quantum computing headlines
Briana D. Bowen, Co-founder and Adjunct Faculty, Utah State University, USA and Keith Martin, Professor, Information Security Group, Royal Holloway, University of London, UK

Abstract ▼

Quantum computing is predicted to pose a critical threat to traditional public-key cryptography and weak forms of symmetric cryptography if a massive-scale ‘cryptographically relevant’ quantum computer (CRQC) is successfully developed at some future point. Sensationalised headlines reflect fluctuating hype over these emerging technologies and present a distinct challenge for cyber security professionals outside the quantum computing research and development (R&D) space to rationalise. This paper offers a practical scaffold for making sense of headlines about quantum computing progress and its potential significance for cyber security. Context is offered on the wide range of quantum computers being developed and key challenges they have yet to surmount, the ambiguous terminology and uncertain milestones benchmarking quantum computing progress to date, key assumptions that underpin the spectre of a so-called ‘Q-day’ cyber security crisis scenario, and the wide distribution of expert opinion about the quantum computing future. Cyber security professionals are counselled to exercise a healthy caution in their read of quantum computing headlines, but to pursue prompt migration towards quantum-safe standards as part of a broader focus on system-wide cyber resilience. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: quantum computing; cyber security; cryptography; post-quantum; quantum-safe; Q-day

Enhancing organisational cyber security resilience: A human-centric approach
Jonas Rendahl, Chief Information Security Officer, Consilium Safety Group, Sweden

Abstract ▼

This paper discusses how to build an effective ‘human firewall’ and foster cyber awareness within organisations. The paper moves beyond traditional technical safeguards and emphasises the indispensable role of human behaviour, decision making and organisational culture in cyber security. It highlights the ineffectiveness of one-off compliance training and advocates for continuous, adaptive, psychologically informed strategies such as gamification, nudging and storytelling. The paper underscores the critical influence of leadership, accountability and psychological safety in cultivating a resilient security posture. Practical recommendations are provided for integrating behavioural science into training programmes, establishing clear accountability and utilising exercises such as tabletop simulations to translate knowledge into actionable defence mechanisms, ultimately transforming the human element from a potential vulnerability into a formidable asset. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: human factor; behavioural science; organisational culture; cyber resilience; training and habit formation

Usable technology for non-experts: Bridging the cyber security expertise gap for low resource organisations
Sarah Powazek, Program Director of Public Interest Cybersecurity, UC Berkeley Center for Long-Term Cybersecurity, USA

Abstract ▼

Cyber security has a complexity problem; most products require a baseline level of knowledge about cyber security controls to be used effectively, but many small organisations, such as non-profits, rural hospitals, utilities, cooperatives and cities, lack the staff to adequately protect themselves from common cyber incidents. Similarly, these small organisations cannot afford to hire or contract managed services, as human expertise is expensive and difficult to scale. This paper highlights the cyber security expertise gap for small, low-resource organisations and why the ‘cyber poverty line’ will not disappear without technological innovation. It then analyses existing market and non-market solutions, including managed services, cyber insurance, cyber volunteering, training and education, and identifies remaining gaps. Finally, the paper highlights an emerging group of usable technology products designed for non-experts and proposes interventions to encourage the further development of usable technology to serve small to mid-sized organisations. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: small and medium-sized organisations; technology; EDR; products; critical infrastructure; SLTT

SOC 2.0: Less triage, more treachery
Yashwanth Reddy Mallu, Cyber Security Engineer, India

Abstract ▼

The landscape of cyber security is locked in a symmetric and rapidly accelerating artificial intelligence (AI) arms race. This paper examines the paradigm shift away from traditional, human-centric security operations centres (SOCs), which are untenable against machine-speed threats, towards an AI-augmented model. For defenders, AI is a core requirement for resilience, enabling automated alert triage and behavioural analytics that reduce costs and analyst burnout. Concurrently, adversaries weaponise AI for adaptive malware and, most critically, adversarial machine learning (AdML) attacks designed to corrupt defensive models. The paper posits that the most effective operational model is a human–machine teaming paradigm where AI amplifies human expertise. Navigating this new era requires a governance-first approach, and the paper concludes by recommending the adoption of frameworks such as the NIST AI Risk Management Framework (AI RMF) and MITRE ATLAS to ensure the secure and sustainable integration of AI in cyber security. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: cyber security; artificial intelligence; security operations centre; adversarial machine learning; NIST AI RMF; MITRE ATLAS

Volume 9 Number 3

Editorial
Beckett, Simon

Papers
Blurred lines: The expanding role of the private sector in wartime cyber operations — the case of the Russia–Ukraine war
Noya Peer, Senior Consultant and Project Manager, Konfidas – Cyber Security & Crisis Management Company, Israe and Gil Baram, Non-Resident Research Fellow, University of California, USA

Abstract ▼

Recent years have witnessed a significant increase in the scale and sophistication of global cyberattacks, highlighting the urgent need for clearly defined norms of responsible behaviour among nation-states in cyberspace. Traditionally, governments have dominated discussions on international cyber norms; however, the prominence of private sector involvement during wartime necessitates re-evaluation of conventional state-centric frameworks. Using the Russia–Ukraine conflict as a pivotal case study, this paper examines the increasingly integral role that private companies play in the strategic and operational dimensions of contemporary warfare. Through an analysis of documented instances from the Russia–Ukraine war, the paper examines how private sector entities have transcended traditional support roles by actively engaging in critical cyber security activities. These include protecting critical infrastructures, conducting independent attribution of cyber incidents and influencing public perceptions through strategic disclosures. The paper further identifies and analyses ambiguities and tensions arising from the sometimes blurred boundaries between public and private sector responsibilities, highlighting gaps in existing international norms and policy frameworks. As the private sector takes on a growing role in cyber operations during conflict and war, this paper examines potential future conflicts — particularly the escalating tensions between China and Taiwan — providing insights that will benefit policy makers, cyber security practitioners and academics alike. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: cyber operations; cyber warfare; conflict; private sector; Russia; Ukraine

Compliance beyond good practices: What regulators see as ‘appropriate’ security measures
Peter Craddock, Partner, Keller and Heckman, Belgium

Abstract ▼

This paper explores enforcement trends regarding cyber security under the General Data Protection Regulation (GDPR) and other European laws. Drawing on decisions by data protection authorities in the UK, Sweden, Spain, Belgium and Greece, the paper analyses how fines are not imposed for cyber security breaches alone but for the broader structural failures and lapses in compliance that they can reveal. This underlines the fact that cyber security is not a fixed state but a continuous process of risk assessment, mitigation and documentation. Leveraging case studies, the paper examines requirements from regulators, such as documented risk assessments, timely patching and software upgrades, regular employee training, incident response planning, effective user authentication and system logging. One notable lesson is the importance of organisations providing evidence of why certain security measures were either taken or omitted, especially when deviating from best practice. The paper stresses the importance of ensuring that written rules are not only well designed but effectively implemented and monitored, as well as the growing emphasis on proportionality in enforcement. It stresses the broader implications of GDPR enforcement decisions regarding cyber security, as the legislative standard used in the GDPR, ‘appropriate technical and organisational measures’, also appears in identical or similar form in other laws, such as the Digital Services Act or the NIS2 Directive. The paper encourages organisations to treat cyber security as an evolving process, to stay up to date and to document decisions, but also to defend well-founded choices even in the face of regulatory scrutiny. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: GDPR; cyber security; fines; data breach; best practices

Emerging issues and trends in cyber security in the Swiss financial sector
Fabian Muhly, Partner, Leo & Muhly Cyber Advisory, Switzerland and Emanuele Chizzoni, Junior Researcher, Leo & Muhly Cyber Advisory, Switzerland

Abstract ▼

This paper presents the results of an empirical study on emerging issues and trends in cyber security for the Swiss financial sector. Six main themes emerged from 14 interviews with practitioners and academics. Improved and more sophisticated training, information sharing, third-party risk assessment, enhanced organisational capabilities, regulatory compliance and the use and implementation of new technologies were identified as critical themes for participants and the industry. In addition, these critical themes represent key areas where both practitioners and academics are calling for further investigation and attention in order to effectively address the emerging challenges that the financial sector is expected to face in the coming years. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: Swiss financial sector; cyber security trends; supply chain risk; human factor; compliance; information sharing

Us and them: Group dynamics as a lens for understanding cyber security beliefs and behaviours in organisations
Marco Cinnirella, Professor of Applied Social Psychology, Royal Holloway University of London, UK and Inbal Iahr, Research Assistant, Royal Holloway University of London, UK

Abstract ▼

Group dynamics is a sub-field of social psychology that explores both intragroup and intergroup processes and how they affect attitudes and behaviours. As a psychology-based lens for understanding cyber security beliefs and behaviours, the group dynamics literature offers largely untapped insights. Its neglect is partly due to the inadequacies of many existing quantitative tools used in cyber security practice when it comes to capturing group processes. This paper explores some ways in which the group dynamics literature can be leveraged to illuminate end-user cyber security beliefs and behaviours in organisations, focusing on research about social identity, intergroup relations and group decision making. Practical implications of this body of work are discussed in relation to prominent and topical behavioural cyber security challenges such as the use of phishing simulations, red teaming, punishment regimes, communications and training, and hybrid working. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: cyber security; employee behaviour; behaviour; groups; group dynamics; psychology

Streamlining user access reviews for disconnected applications: A scalable framework
Vatsal Gupta, Senior Identity and Access Management (IAM) Architect, Apple, USA

Abstract ▼

In large organisations, managing user access reviews for hundreds of disconnected applications (applications not integrated with central identity governance and administration [IGA] solutions) remains a daunting challenge. Traditional role-based access control models ensure authorisation but often fail to maintain least privilege for disconnected systems due to integration complexities.1 This paper proposes a scalable and customisable framework for user access reviews for disconnected applications that bypasses the time-consuming and arduous task of application integration. The framework is split into pre-certification, certification and post-certification stages and leverages Python scripts to streamline reviews. The tool is deployable with or without an IGA solution, reduces risk and meets audit needs, offering identity and access management practitioners an efficient path to govern access across diverse systems. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: user access reviews; IGA; disconnected applications; IAM; access management

Leadership strategies for building psychological resilience
Vicky Laurens, Vice President, Security Engineering and Deployment, Scotiabank, Canada

Abstract ▼

As the global cost of data breaches continues to rise annually and cybercrime ranks among the largest economies worldwide, cyber security leaders and teams are facing escalating and unsustainable stress levels, leading to burnout becoming a significant unspoken threat within the industry. It is imperative to implement strategies for preventing burnout at both the organisational and individual levels. Establishing psychological resilience within teams should commence with leaders developing their own personal psychological resilience, thereby laying the foundation for creating psychologically safe work environments. This paper outlines a people-centric and value-driven leadership framework that employs a polarity mindset to build psychological resilience, fostering innovation and combating burnout. Personal resilience does not imply the avoidance of stress; rather, it equips individuals to adapt to and recover from stress more effectively. The framework serves as a guide to living a value-driven life and career. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Keywords: cyber security; leadership framework; polarity mindset; psychological resilience; innovation; preventing burnout

Volume 9 Number 2

Editorial
Beckett, Simon

Papers
Integrating identity and access management and privileged access management for enhanced identity security in financial institutions: A zero-trust approach
Felix Behringer, Senior Manager, Cybrex, Germany and Patrick Baumann, Senior Manager, Assurance, Technology Risk, EY, Germany

Abstract ▼

This paper explores the critical role of identity and access management (IAM) and privileged access management (PAM) in securing the digital identities of employees within financial institutions. It emphasises identity-centric security as the first line of defence in protecting sensitive data and IT assets, especially in legacy IT environments where technological constraints and regulatory demands pose unique challenges. The paper outlines how integrating IAM and PAM supports compliance with industry regulations and enforces zero-trust principles, ensuring continuous verification and control of privileged accounts. Key concepts such as the confidentiality, integrity and availability (CIA) triad, least privilege and need-to-know principles are examined in relation to data classification and risk management. The paper further introduces a practical framework for transforming legacy IT systems through comprehensive organisational and technical measures. Readers will gain insight into the core PAM controls essential for safeguarding privileged access, including account discovery, session isolation, behavioural monitoring, audit trails and risk-based remediation. By following these strategies, financial institutions can enhance transparency, reduce attack surfaces and maintain full control over privileged activities. This paper equips IT and security professionals with a clear understanding of how to implement robust identity-centric security frameworks tailored to complex legacy environments, supporting operational continuity and regulatory compliance in an evolving threat landscape.
Keywords: identity and access management; IAM; privileged access management; PAM; legacy IT systems; zero-trust security; data classification and protection; clean state approach; identity security; account privileges

AI with humans in mind: The importance of human behavioural considerations in AI design and adoption
Hanah-Marie Darley, Director, Security & AI Strategy, Field Chief Information Security Officer, Darktrace, UK

Abstract ▼

It is essential to design technology not just with security in mind but with a recognition of the essential tenets of human behaviour. Humans are the core of every societal system and designing technology without understanding the biological and psychological realities of implementing that technology is a critical error. Artificial intelligence (AI) technology is designed to mimic human thinking and decision-making so designing it with the practicalities of human cognition and trust at the forefront is essential. Applying AI to cyber security can have massive benefits. However, solutions that do not consider the human element but rather just implement new AI for the art of it tend to have troublesome consequences and clash with user behaviour. In order to affect lasting change in security operations, especially via the implementation of AI to problem-solve and increase efficiency, it is critical that the AI techniques leveraged are designed around the realities of human behaviour and psychological realities. This paper explores psychological realities such as cognitive biases, reactions to stress and crisis and implicit trust in technology, how they can be made worse if technology, especially AI technology, is not designed with those realities at the forefront and how AI can instead be built to complement human behaviour.
Keywords: artificial intelligence; cognitive biases; psychology; human behaviour; AI; cyber security; security operations; risk; AI adoption

Securing identities in software development life cycles
Maya Neelakandhan, Vice President Engineering, BlueFlag Security, USA, Guruprasad Ramprakash, Senior Product Manager, BlueFlag Security, USA and Deepika Gautam, Co-Founder/Head of Security Engineering and Strategy, Aplima Solutions, USA

Abstract ▼

Security within the software development life cycle (SDLC) has traditionally focused on safeguarding code — through secret scanning, open-source package vetting, and code analysis. While this has strengthened application-level security, the assumption that code security alone is sufficient to prevent breaches has proven inadequate. This paper explores the processes, tools, and best practices involved in the code-to-cloud journey, with a particular focus on a frequently overlooked aspect of SDLC: identity management, encompassing both human developers and non-human identities. Through a case study, it demonstrates why identity threats must be treated with the same urgency as code and infrastructure vulnerabilities. The paper presents a framework for establishing a secure software development process, offering end-to-end protection that includes both tooling and identity governance.
Keywords: SDLC security; CI/CD best practices; identity security; insider threat; source code breaches; DevSecOps

Creating an effective cyber security culture in regulated financial services companies
Rupert Lee-Browne, Chairman, Caxton, UK

Abstract ▼

Technology-based protections are making businesses more resilient to cyberattacks. However, the rapidly improving ability for bad actors to mimic real customers and contacts across multiple vectors highlights the important role a company’s employees must play in protecting against a wide range of threats. It is not enough for staff to simply rely on robust password hygiene and the ability to spot relatively obvious inconsistencies in the approaches they attract. Today’s businesses need to make cyber security a core part of the culture of their companies so that continuous vigilance becomes an operational default. Of course, changing an existing culture is no easy undertaking. This paper analyses the issues facing one financial services business and explores step-by-step what the company did to establish and reinforce a culture of security.
Keywords: cyber security; financial services; company culture; case study; simulated attack

Practical cyber security architecture: Introducing a practical model for resilience
Eleni Richter, Chief Architect IDM, EnBW Energie Baden-Württemberg, Germany

Abstract ▼

The move to the cloud raised expectations to finally leave behind on-premises silos and all the issues that accompany them. The complexity of hybrid scenarios, cloud provider lock-in situations and heavy dependencies on centralised cloud services take problems to a next level. Large and complex cyber systems, often encompassing both legacy and cloud, are difficult to maintain and operate, particularly in terms of cyber security. Investing in cyber resilience brings benefits not only in cyber security but also in building, maintaining and operating these systems. This paper introduces a practical model for building resilience within cyber system architectures. The main goal of the model is to reduce complexity and keep distributed large cyber environments manageable. As an architectural approach, the structure of the model extends from the enterprise level through the system level to the component level. The model is accompanied by a selection of basic patterns for building robust and resilient cyber systems. Its applicability is illustrated by some practical use cases in typical on-premises and cloud scenarios.
Keywords: resilience; cyber security; loose coupling; robustness; reduction of complexity and dependencies

A holistic approach to cyber security in local government: A practice-based perspective
Mark Brett, Research Fellow, London Metropolitan University and Associate Professor De Montfort University, UK

Abstract ▼

The UK local government landscape is grappling with evolving cyber threats and the complexities of ensuring effective cyber security. This paper analyses the need to move away from policy-driven compliance towards principles-led information assurance. It presents a framework to support local authorities contextualise and implement a holistic approach to information governance, assurance and resilience. The research project uses a practice-based method, working with a wide range of local authorities across the UK and especially in Wales. The work also recognises the need for knowledge sharing. The Local Authority Cyber Eco-System framework is presented in the paper.
Keywords: practice-based; LACES; IMAG; local authority; local government; cyber security; information governance; information assurance; resilience; principles led; policy; rule based; knowledge sharing

Examining generational impacts of machine learning, artificial intelligence, generative AI and deepfake-based social engineering cybercrime
Christopher S. Kayser, Founder, President and Chief Executive Officer, Cybercrime Analytics, Canada

Abstract ▼

Social engineering (SE) has been used as an effective technique for decades to extract information from individuals for malicious purposes. Machine learning (ML), artificial intelligence (AI), generative AI (GenAI) and deepfakes provide advanced technologies and tools for cybercriminals to increase the probability of a successful cyberattack. Our ability to detect that we are being maliciously manipulated is becoming increasingly difficult as these technologies are incorporated into SE-based cyberattacks. This paper examines the positive and negative aspects of ML, AI and GenAI, reviews existing literature about these technologies and presents a brief introduction of the technical aspects of ML, AI and deepfakes. The decision model Required Elements for a Social Engineered Cyber Attack Theory examines our decision processes when confronted by a SE-based cyberattack, and how simple decisions can become more complicated when influenced by AI. Examples of generation-specific AI-based scams are examined to describe techniques bad actors are using to victimise specific age groups. The conclusion offers recommendations that technology users can adopt to reduce their exposure of being victimised by AI-based SE cyberattacks.
Keywords: artificial intelligence; AI; decision processing; deepfakes; generative AI; GenAI; machine learning; ML; RESCAT; social engineering; SE

Volume 9 Number 1

Editorial
Beckett, Simon

Papers
Is it time to consider a radical change in the way we organise and manage the response to cybercrime?
Simon Newman, Co-Founder, Cyber London, UK

Abstract ▼

The growth of cybercrime continues to be a major threat to national security. With high-profile cyberattacks disrupting supply chains around the world, policy makers are constantly looking at ways to tackle it effectively using the levers available to government. But as we have seen over the last few years, the problem continues to grow, forcing policy makers to reconsider their thinking in how to reduce the threat and impact of cybercrime. The election in the UK of a new Labour Government in July 2024 with a large majority provides an opportunity to review the existing approach and implement a more radical solution, informed by best practice elsewhere. The challenge, however, is in building a model that not only brings together a complex group of stakeholders across government and beyond, but which also improves accountability and transparency while future-proofing the response to a rapidly changing policy area.
Keywords: cybercrime; strategy; coordination; international; accountability

Rethinking user password management
Bryan Christ, Chief Information Officer and Chief Technology Officer, Bravura Security, USA

Abstract ▼

This paper critically examines the continued reliance on passwords despite its flaws. It explores how the inherent cognitive limitations of users — exemplified by Miller’s Law and the challenges of short-term memory — contribute to insecure practices such as password reuse and reliance on easily remembered, yet predictable, password structures. The paper reviews historical and contemporary research on user behaviour in password creation, highlighting how increasing complexity requirements often lead users to adopt counterproductive shortcuts and coping mechanisms. In addition to dissecting the cognitive challenges, the paper evaluates current security practices including multi-factor authentication (MFA) and highlights some prominent weaknesses. The paper proposes abandoning current password practices, which are user-centric, and adopting a new paradigm. In this model, principles are drawn from solutions in the privilege access management (PAM) and password manager realms to craft an architecture that balances security and convenience while eliminating cognitive burden. Readers will take away a comprehensive understanding of the limitations of traditional password systems, insights into modern authentication methods, and a roadmap for adopting more user-friendly and robust security practices that shift the responsibility of password complexity away from the end user.
Keywords: password management; password fatigue; password hygiene; forgetting passwords; password rotation; password complexity

Developing cyber resilience through cyber incident response capability improvement: Presenting the cyber incident response capability development life cycle model
Murray Goldschmidt, Executive Director for Cyber Capability, Education and Training, CyberCX, Australia

Abstract ▼

In the face of a deteriorating cyber threat landscape, it has never been more important for entities to prepare for a cyber incident. This paper presents the cyber incident response capability development life cycle, a cumulative and iterative approach to considering cyber threats from multiple dimensions to identify capability gaps and providing the opportunity for focused skill uplift. The life cycle addresses all aspects of cyber incidents and provides innovative approaches to accommodating the needs of all stakeholders across all roles in an entity, from simplified exercises to complex simulated events. Exercising incident response plans and the associated playbooks is a feature of all standards and frameworks, and consistently recommended through government and regulatory advice.
Keywords: cyber resilience; incident response; threat actors; nation state threats; organised crime; ransomware; cyber extortion; insider threats; board and director duties; first responders; incident response plan; playbooks; runbooks; crisis communications; critical infrastructure; cross domain threat hunting; cyber security framework; cyber security incident; cyber security risk management; incident handling; incident management; incident response

SPOT: A data-driven threat detection framework with knowledge-enhanced scoring
Derek Lin, Chief Data Scientist, Exabeam, USA

Abstract ▼

In an era when digital threats are becoming increasingly sophisticated and pervasive, the need for robust cyber security measures has never been more critical. Traditional methods based on fact or correlation rule matching are insufficient. Machine learning (ML) for dynamic behaviour modelling and automated scoring is now crucial for effective threat detection. This paper introduces SPOT, a practical threat detection and scoring framework and system for user and entity behaviour analytics (UEBA). The framework comprises layered modules: data-driven ML for event scoring; event organisation into meaningful threats; and threat re-prioritisation based on business knowledge factors. The system architecture supporting this framework leverages a stream-based distributed computing platform enabling Cloudscale processing for high-fidelity threat identification.
Keywords: threat detection; scoring; prioritisation; machine learning; UEBA

Govern once/comply many: Leveraging cyber security framework experience to support AI governance
F. Paul Greene, Partner, Harter Secrest & Emery, USA

Abstract ▼

Data protection is notoriously complex and artificial intelligence (AI) has only added to that complexity. In addition, many organisations are floundering as they seek to adopt AI in an ethical and trustworthy manner. This paper addresses skill sets and frameworks familiar to IT and cyber security professionals that can be leveraged to help build a robust approach to AI governance. Adopting the maxim of ‘govern once/comply many’, the paper compares and contrasts existing cyber security frameworks and approaches that address the governance concerns that arise with AI. It also uses the National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework as a lens through which to assess the utility of cyber security frameworks to inform AI governance efforts. Generally, the map, measure, manage and govern functions of the NIST Artificial Intelligence Risk Management framework align well with the confidentiality, integrity, and availability foci of established cyber security frameworks, forming the beginnings of a common language, when it comes to issues of data protection and AI governance.
Keywords: artificial intelligence; cyber security; governance; framework

The art of cyber war: Sun Tzu’s ancient wisdom in modern threat intelligence
Lior Arbel, Ex-Chief Executive Officer, Elemendar, UK

Abstract ▼

This paper explores the enduring relevance of Sun Tzu’s The Art of War, written in the 5th century bc, to modern cyber security practices. It examines how the ancient strategist’s principles can be applied to enhance threat intelligence and cyber defence strategies in the digital landscape. The paper discusses five key principles from Sun Tzu’s work: knowing oneself and the enemy, the use of deception, winning without combat, the importance of speed and adaptability, and the use of alliances. Each principle is contextualised within current cyber security challenges and illustrated with real-world examples and case studies. The paper emphasises the critical importance of making cyber threat intelligence more accessible and actionable. It concludes by highlighting the enduring value of combining timeless strategic wisdom with cutting-edge technology to create more robust and effective cyber defences.
Keywords: Sun Tzu; cyber security; threat intelligence; cyber defence; strategy; deception; proactive defence; information sharing

Security audits on artificial intelligence systems
Robert Kemp, Senior Security Manager, University of Portsmouth, UK

Abstract ▼

Auditing is important for ensuring security and compliance for artificial intelligence (AI) systems. Unlike traditional software security audits that primarily address well-documented vulnerabilities, AI systems introduce distinctive challenges due to their reliance on complex machine learning (ML) models and expansive data pipelines. This paper presents key considerations for a security audit specifically tailored for AI systems, emphasising core components such as model robustness, adversarial defences, penetration testing, data privacy compliance and continuous monitoring. It systematically identifies crucial areas of focus, including data sources, ML models and application interfaces, while also detailing specialised security tools such as the IBM Adversarial Robustness Toolbox and Microsoft Counterfeit. Furthermore, the paper integrates established security standards and methodologies, including the MITRE Adversarial Threat Landscape for AI Systems (ATLAS) and the NIST AI Risk Management Framework, to address the unique threats posed by AI technologies. By adopting this holistic auditing approach, organisations can enhance the resilience of their AI systems against evolving cyber threats, thereby ensuring their operational reliability and compliance with regulatory standards.
Keywords: artificial intelligence; audits; cyber security; assurance; frameworks

Why failure to comply with state contract cyber security and privacy requirements is increasingly likely to result in State Attorneys General enforcement
Ashley L. Taylor, Jr.,Partner, Troutman Pepper, USA, Gene Fishel, Counsel, Troutman Pepper, USA and Dan Waltz, Associate, Troutman Pepper, USA

Abstract ▼

State Attorneys General (AGs) are increasingly leveraging state false claims laws to enforce cyber security and privacy requirements in government contracts. This shift poses significant risks for state and local government contractors, as non-compliance can lead to penalties exceeding the contract’s value. Following the Department of Justice’s (DOJ) success with the False Claims Act and the Cyber Fraud Initiative, State AGs are recognising the potential for substantial revenue and public approval through these statutes. Traditionally used for Medicare and Medicaid violations, state false claims acts are now being applied to a broader range of contractual obligations, including cyber security. Recent DOJ settlements with contractors highlight the serious consequences of non-compliance. Contractors must be proactive in ensuring compliance with cyber security requirements to mitigate the risk of false claims litigation. This involves robust compliance policies, clear communication channels and thorough documentation of efforts to meet contractual obligations.
Keywords: state false claims laws; cyber security requirements; privacy obligations; government contractors; qui tam provision; data breach notification; civil cyberfraud initiative; compliance programme

The AI security zugzwang
Lampis Alevizos, Head of Cyber Defence, Volvo Group, The Netherlands

Abstract ▼

In chess, zugzwang describes a scenario where any move worsens the player’s position. Organisations face a similar dilemma right now at the intersection of artificial intelligence (AI) and cyber security. AI adoption creates an inevitable paradox: delaying it poses strategic risks, rushing it introduces poorly understood vulnerabilities, and even incremental adoption leads to cascading complexities. In this paper we formalise this challenge as the AI security zugzwang — a phenomenon whereby security leaders must make decisions under conditions of inevitable risk. Grounded in game theory, security economics and organisational decision theory, we characterise AI security zugzwang through three key properties: forced movement, predictable vulnerability creation and temporal pressure. Additionally, we develop a taxonomy to categorise forced-move scenarios across AI adoption, implementation, operational and governance contexts and provide corresponding strategic mitigations. Our framework is supported by a practical decision flowchart, demonstrated through a real-world example of Copilot adoption, thereby showing how security leaders can manage zugzwang positions balancing risk and innovation.
Keywords: AI cyber security; zugzwang; security decision making; cyber security strategy; forced security moves; innovation