
Two weeks on from CYBERUK in Glasgow, and as promised, a few thoughts.
But honestly, the one thing that cut through everything?
Get the basics right.
With National Cyber Security Centre marking its 10th anniversary, it didn’t feel like a year for big new ideas.
It felt like a year for some fairly uncomfortable truths.
1) Cyber isn’t a tech problem, it’s a leadership problem. Most of the issues aren’t because a tool is missing, they are because ownership isn’t clear, decisions aren’t challenged and people don’t speak up.
For me, that’s culture and governance.
2) AI isn’t changing the rules, it’s accelerating the consequences. There’s a lot of noise around tools like Mythos just now, but in my mind the risk hasn’t materially shifted, it’s just speeding everything up, and if our processes are slow or fragmented, AI just makes that gap wider…faster.
3) The fundamentals still win. This is the bit we keep coming back to. It’s not expensive, it’s not complicated. It’s just not consistently done well.
The message is clear, patching that actually happens, visibility you can trust, access properly controlled and the likes of MFA fully rolled out (not “almost there”).
I firmly believe our biggest vulnerability (and our biggest control) is our people. Let’s also get the identity plane right, by design.
4) We all love a wee stat, and this one stuck with me. 85% of people don’t raise concerns because they think it wont make a difference. That surprised me, but also didn’t, and for me that’s not a tooling issue, that’s a leadership signal.
In summary what's our strongest defence?
A human firewall, where people feel safe to challenge, and believe something will actually happen when they do so.
In broad Scots language it's Culture with a capital "K"
Stay updated with our latest posts
Discuss this topic