Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Prompt Data Leakage: How to Secure Sensitive Data in LLMs

As generative AI adoption surges, so does a dangerous new enterprise risk: AI prompt data leakage — the unintentional exposure of confidential corporate data to third-party Large Language Models via user prompts. Why does it happen? Driven by productivity pressure and the need to speed up their work, employees routinely bypass traditional DLP controls.

How to Set up Backup and Recovery on Your Own Kubernetes Cluster in 5 Minutes

Regulation is doing more to shape backup strategy right now than almost anything else. NIS2 requires organizations to document their risk management measures, keep an incident response plan on file, and report breaches within 24 hours, with fines that can reach €10 million or 2% of global turnover. DORA goes further for financial entities, requiring documented recovery objectives, regular resilience testing, and an audit trail that holds up to a regulator’s questions.

Maturity Is a Lagging Indicator. Here's a Leading One.

A maturity score answers where a program has been. It reports the state of documented process at the moment somebody assessed it, on a cadence measured in quarters or years, using a scale that describes organization rather than outcome. Every property that makes it useful for planning makes it useless as an early warning. ‍ The interesting question is what a leading indicator would look like instead, and the answer requires separating two problems that get treated as one.

What Counts as One AI Asset? Getting the Unit Right

Two teams inventory the same organization and return different numbers. One counts forty-one AI assets, the other counts one hundred and twelve. Neither is wrong, because they counted different things, and nobody had decided what a row represents. ‍ Guidance on building an AI inventory covers which fields a row should carry and skips what a row is. That question determines the count, the risk scores, the regulatory classification and whether two inventories can ever be reconciled.

Beyond the Compliance Snapshot: Why GRC Needs Continuous Evidence

I recently had the opportunity to speak at the ISACA GRC Conference in San Diego about a challenge I see becoming increasingly important for governance, risk, and compliance teams: How do you prove your controls are actually working in digital environments that never stop changing?

How autonomous pentesting kills false positives

Ask any security engineer what they actually think about their vulnerability scanner, and you will get a version of the same answer. They trust maybe 20% of what shows up in the patching queue. The rest gets a suspicious glance, and a slow death in a backlog. That is the real cost of a false positive. It is quiet, it compounds, and it hollows the tool out from the inside. It is also the reason autonomous pentesting came to replace hypotheses with confirmed exploits.

What does Cyber Essentials cover?

Cyber attacks cost UK businesses an estimated £14.7bn every year. The average cost of a significant breach for an individual business sits at almost £195,000. Half of all small businesses have experienced at least one attack in the past 12 months. For medium and large organisations, that figure rises to 82%. Those numbers should focus the mind.

How to Improve MTTR: A Practical Guide for Security Teams

A critical alert enters the SOC queue during the overnight shift. By morning, the dashboard shows an acceptable headline MTTR because the incident was closed quickly after an analyst finally picked it up. The timeline tells a different story: the alert sat unassigned for nine hours because severity routing sent it to the wrong queue. The team optimized the visible number while leaving the dangerous delay untouched.

How SLED can win the cybersecurity race with agentic AI

Adversaries are using AI to launch cyber attacks in record time, forcing security teams to measure responses in minutes instead of months. Phishing campaigns built with large language models (LLMs) achieve click-through rates 4.5 times higher than traditional methods,1 and the average time between initial compromise and lateral movement has fallen to just 29 minutes.2 This is a 65% increase from the prior year.2 State and local governments and higher education institutions are at an inflection point.