
THINKING
Plain-English views on security, regulation, and the widening gap between the two. Everything here is something we'd defend in front of your board.

Firms treating DORA as a compliance-mapping exercise are building a paper fortress. It's really a test of how your firm behaves under stress, and most operating models fail that long before the ICT register does.

The 2026 King's Speech carried far more cyber legislation than anyone expected — from the Cyber Security and Resilience Bill to reform of the Computer Misuse Act. What it contains, why now, and what it means in practice.

Length isn't rigour. When a control takes forty pages to explain, the document isn't describing it — it's hiding the fact that nobody ever agreed what it was for.

Time-to-exploit has collapsed from 771 days to hours, and AI has tilted the curve further. Patching faster isn't a game defenders can win. Five plays for a 'decoupled battlespace' where containment runs at minutes while patching runs at weeks.

The red-amber-green matrix is the most successful piece of assurance theatre ever staged. What to put in the board pack instead, and why your NEDs will thank you for it.

Over half of cyber security professionals report significant mental health impacts from work-related stress, and 28% of CISOs are thinking about leaving. What the data says, why the job is like this, and what leaders and individuals can actually do.

Networks of AI agents are about to get as tangled as microservices did — and we already know how that story went. The case for an orchestration layer that does for agents what the service mesh did for services, before the mess sets.

What the threat intelligence from Mandiant, Verizon, CrowdStrike, IBM and Microsoft actually says — and the five strategic priorities that fall out of it, with the evidence for each.

Quantum computers will break the one-way functions today's encryption depends on. The NCSC says migrate by 2035. Why that timeline is too relaxed, what 'cover period' means for your data, and three things to start now.

The UK's Blueprint for Modern Digital Government follows a path Estonia walked twenty years ago — including the part where a nation-state attacked. Why digital public services and cyber security can't be treated as separate issues, and two things within government's gift to fix.
The next position, in your inbox. One email a month. No funnel.
Subscribe