|
In this super-fast
Digital Age the single biggest source of confusion when it comes to
seeking effective cybersecurity is believing a vulnerability scan of an
organisation is as effective as a penetration test.
In an era led by innumerable artificial intelligent agents far too many
organisations are led to believe a scan is good enough as an assurance
to their client base, auditor or insurer. It isn't, reports JAG Secure.

Insider Threats
Unleashed
A warning from The Economist will come as a surprise to many: how AI
agents have "effectively unleashed a fleet of insider threats, operating
from within at speed, with legitimate access."
Perimeter walls were never built for this with such defence becoming
obsolete and a cyber breach a likelihood. In a nutshell "scaling agents
multiply risks."
Adding a quite startling statistic: "Ninety-eight per cent of
organisations have already experienced a disruptive agent-related
incident" and "nine-in-ten expect more disruptions regardless of the
safeguards currently in place."
The National Cyber Security Centre warns: "You must have a plan for
continuity. It is the strength of these pre-engineered solutions that
determines the ability to endure, respond, rebuild, survive."

Myth Laid Bare
Here, JAG Secure Founder & Principal Penetration Tester Jordan Glover,
awarded the Principal Cyber Security Professional (PriCSP) registration
by the UK Cyber Security Council, in the field of Security Testing, laid
to rest an enduring myth.
Following up from my interview on behalf of Edinburgh Chamber of
Commerce he warned that, unfortunately, many organisations still operate
under the illusion their cyber defence preparedness is adequate yet
acknowledge recovery targets are loosely defined.

Even more troubling is
far too many IT departments do not report this to senior leadership.
Coming at a time when boards make aggressive AI investments, without
knowing whether they could survive a ruinous breach.
What is a vulnerability scan? Solely automated a tool connects an
organisation's systems and findings compared against a database of known
issues and a list produced. Fast, often cheap and genuinely useful. But
as Glover points out: "It is also blind."
Such a scan cannot tell what actually matters in your environment, a
flaw is reachable or what an attacker might do next. "Most reports might
impress a client but do not contain a single critical vulnerability."
Onto Penetration Testing.
JAG Secure, a Chamber member, with offices in Edinburgh and London's
Covent Garden and a 2026 Scottish Cyber Awards Finalist, is increasingly
being hired by organisations across all sectors including financial
services, the public sector, defence and law enforcement, healthcare,
legal, retail and SMEs and scale-ups.
What JAG does is "break into" an organisation the way a real cyber
attacker would, then a business is shown what to fix before someone less
friendly finds the same gaps leading to a serious cyber breach.
Yes tools are employed but as a starting point - then, and crucially, a
HUMAN BEING does the actual work: the tester verifies what is real,
discards what is noise and chains the surviving issues together to see
how far they lead.
Output is NOT a list of alerts rather a set of findings, each one
confirmed and related to the risk it presents to your business with
clear guidance on the fix required.
End Result?
A pentest report that does two jobs at once because it has two
audiences.
The first section is for management explaining in plain language the
overall risk position and what this means for the business. No jargon,
no tool output, no vulnerability names.
"If your board cannot read it and understand where they stand, it has
failed, "Jordan says.
The rest is for the people to fix things: each finding rated by
severity, evidence that it is real, steps to reproduce it and guidance
specific enough to act on.
"Most of what we find is unglamorous and fixable," he adds. "A website
leaking more than it should, a guest wifi reaching further into the
network than anyone realises, a server no one wants to touch!"
You should also get a retest: confirming the fixes actually landed is
the step "that turns a report into assurance you can hand to a client,
an auditor or an insurer."
Testing without a retest tells you where you were, not where you are.
..
Best Leave Nothing To
Chance in this Uncertain AI-driven marketplace |