Insights

Latest Articles

Cybersecurity

Scam impersonating Apple Support

A two-stage vishing operation impersonating Apple Support tried its luck this morning. Multiple US numbers, a bot qualifier, a human closer, and a URL that hinges on a single hyphen. The anatomy, and the four mistakes I made along the way.

Artificial Intelligence

AI on AI Part III: Convergence (Hacking the infra and Cracking the math)

Two weeks ago, an OpenAI agent broke into Hugging Face. Last week, an AI model killed HAWK, a PQC candidate designed to resist quantum computers, using classical mathematics. This convergence of AI accelerating both hacking and cracking the maths cannot be ignored. Until now, we were preparing for a predicted event in the future (Q-Day). Now, we must prepare for an unpredictable event that could happen anytime. Part III extends the CISO’s action plan from Part II with crypto-agility deliverables built to endure both threats.

Artificial Intelligence

Shared AI chats are like public GitHub repos

Hundreds of shared Claude conversations recently turned up in Google search results, joining earlier incidents with ChatGPT, Grok, Meta AI, and Bard. The lesson is the same one developers already learned, or should have, from public GitHub repos: a share button is not a privacy model. Exposure is a one-way ratchet.

Artificial Intelligence

AI on AI Part I: Overblown Headlines Likely to Spook Insurers

An OpenAI model broke out of its own test lab and hacked Hugging Face, unsupervised. Everyone is calling it unprecedented. It isn't. Two of the most sophisticated AI companies on the planet got caught out by security mistakes any first-year analyst would recognise, and the insurance market is already taking note.

Artificial Intelligence

Managing the Stubborn Residual Risks of AI Governance

An open-source tool that finds every cross-border AI data flow in a company's code before it ships. The kind of pre-deployment control regulated institutions actually need. Two adjacent stories in the news: Anthropic's recent allegations against Alibaba, and their decision to restrict Mythos to around 100 approved companies. Three connected problems at the heart of AI governance: 1. AI data residency and sovereignty, 2. AI theft, and 3. AI export control. Each carries residual risks that technology cannot fully eliminate. This piece walks through all three, what the tool addresses, and what boards and senior leaders can actually do.

Artificial Intelligence

The Four Laws and a Playbook for AI Agents

Singapore clearly leads on Agentic AI governance. The principle is plain: accountability rests with humans, not with code. Four laws for the institutions deploying AI agents, Identity, Scope, Accountability, Revocability. And the PETALS™ Framework for AI Governance with the Cyber Quadrilemma lens, together, as the Agentic AI Playbook for effective orchestration.

Artificial Intelligence

The Froth on the Frontiers: AI, Digital Currencies, Quantum

I read two articles this week about why AI has not replaced software engineers, and why it is unlikely to. Both resonated with me deeply. Reading them side by side opened a wider frame. I see the same froth across every frontier I touch. AI. Digital currencies. Quantum. Read on for how the froth saps the real essence from these frontiers, and what we as an industry should focus on instead.

Cybersecurity

An Attacker Quietly Read a Global Stock Exchange Executive’s Inbox for Five Months

For five months, an attacker silently read a senior executive’s Outlook mailbox at a major global stock exchange, exfiltrating in small batches through Dropbox and OneDrive. No CVE to hide behind. Five layers of defence were soft on the same endpoint, on both sides of the contract. The institution and its security vendor have questions to answer.

Artificial Intelligence

The PETALS™ Lens: AI Agent Governance in OpenClaw and Its Variants

An AI agent deleted an email server to protect a secret. Its justification: "The nuclear option is valid when no surgical solution exists." Three OpenClaw variants now compete in this space. This analysis applies the PETALS™ Framework to all three, with a scorecard and five questions boards should ask before adoption.

Cybersecurity

Beyond the Market Noise — Rethinking Cybersecurity Vendor Landscape in 2026

When Anthropic launched Claude Code Security last week, cyber stocks fell sharply. The narrative that followed was predictable. This analysis looks beyond the market noise — at what the shift means for CrowdStrike, Okta, SailPoint, Zscaler, Wiz, and others, and how technology and security leaders should think about their vendor landscape in 2026.