Search just our sites by using our customised search engine

Unique Cottages | Electric Scotland's Classified Directory
 

Click here to get a Printer Friendly PageSmiley

Bill Magee
Scots Cybersecurity Expert Clears up Global AI Confusion


In this super-fast Digital Age the single biggest source of confusion when it comes to seeking effective cybersecurity is believing a vulnerability scan of an organisation is as effective as a penetration test.

In an era led by innumerable artificial intelligent agents far too many organisations are led to believe a scan is good enough as an assurance to their client base, auditor or insurer. It isn't, reports JAG Secure.

Insider Threats Unleashed

A warning from The Economist will come as a surprise to many: how AI agents have "effectively unleashed a fleet of insider threats, operating from within at speed, with legitimate access."

Perimeter walls were never built for this with such defence becoming obsolete and a cyber breach a likelihood. In a nutshell "scaling agents multiply risks."

Adding a quite startling statistic: "Ninety-eight per cent of organisations have already experienced a disruptive agent-related incident" and "nine-in-ten expect more disruptions regardless of the safeguards currently in place."

The National Cyber Security Centre warns: "You must have a plan for continuity. It is the strength of these pre-engineered solutions that determines the ability to endure, respond, rebuild, survive."

Myth Laid Bare

Here, JAG Secure Founder & Principal Penetration Tester Jordan Glover, awarded the Principal Cyber Security Professional (PriCSP) registration by the UK Cyber Security Council, in the field of Security Testing, laid to rest an enduring myth.

Following up from my interview on behalf of Edinburgh Chamber of Commerce he warned that, unfortunately, many organisations still operate under the illusion their cyber defence preparedness is adequate yet acknowledge recovery targets are loosely defined.

Even more troubling is far too many IT departments do not report this to senior leadership. Coming at a time when boards make aggressive AI investments, without knowing whether they could survive a ruinous breach.

What is a vulnerability scan? Solely automated a tool connects an organisation's systems and findings compared against a database of known issues and a list produced. Fast, often cheap and genuinely useful. But as Glover points out: "It is also blind."

Such a scan cannot tell what actually matters in your environment, a flaw is reachable or what an attacker might do next. "Most reports might impress a client but do not contain a single critical vulnerability."

Onto Penetration Testing.

JAG Secure, a Chamber member, with offices in Edinburgh and London's Covent Garden and a 2026 Scottish Cyber Awards Finalist, is increasingly being hired by organisations across all sectors including financial services, the public sector, defence and law enforcement, healthcare, legal, retail and SMEs and scale-ups.

What JAG does is "break into" an organisation the way a real cyber attacker would, then a business is shown what to fix before someone less friendly finds the same gaps leading to a serious cyber breach.

Yes tools are employed but as a starting point - then, and crucially, a HUMAN BEING does the actual work: the tester verifies what is real, discards what is noise and chains the surviving issues together to see how far they lead.

Output is NOT a list of alerts rather a set of findings, each one confirmed and related to the risk it presents to your business with clear guidance on the fix required.

End Result?

A pentest report that does two jobs at once because it has two audiences.

The first section is for management explaining in plain language the overall risk position and what this means for the business. No jargon, no tool output, no vulnerability names.

"If your board cannot read it and understand where they stand, it has failed, "Jordan says.

The rest is for the people to fix things: each finding rated by severity, evidence that it is real, steps to reproduce it and guidance specific enough to act on.

"Most of what we find is unglamorous and fixable," he adds. "A website leaking more than it should, a guest wifi reaching further into the network than anyone realises, a server no one wants to touch!"

You should also get a retest: confirming the fixes actually landed is the step "that turns a report into assurance you can hand to a client, an auditor or an insurer."

Testing without a retest tells you where you were, not where you are.

..

Best Leave Nothing To Chance in this Uncertain AI-driven marketplace


Return to Bill Magee's Index Page


 


This comment system requires you to be logged in through either a Disqus account or an account you already have with Google, X, Facebook or Yahoo. In the event you don't have an account with any of these companies then you can create an account with Disqus. All comments are moderated so they won't display until the moderator has approved your comment.

comments powered by Disqus

Quantcast