Twenty years securing organisations that make physical things.
Most security advice assumes a greenfield estate and a team that can patch on Tuesday. Real estates have equipment older than the people running it.
This account is about the second kind.
The honest ledger on what AI changed for attackers.
Cheaper: reconnaissance, phishing that reads like a colleague wrote it, triaging vulnerabilities at scale.
Unchanged: initial access still needs a way in. Persistence is still noisy.
The autonomous hacker did not arrive. The volume did.
We built identity around one assumption: a credential belongs to a person who sleeps, forgets, and eventually gets fired.
Agents do none of those things. They do not go home. They do not get offboarded.
Your access model is running on assumptions that stopped being true.
Ask a mature security programme what actually moved their risk numbers. It is rarely the new tooling.
It is decommissioning the systems nobody would admit to owning.
No vendor sells it. No conference talk covers it. It works better than most things that do.
Building something real alongside a demanding job is an exercise in what you refuse to do.
No custom infrastructure. No clever architecture. No framework you have not shipped before.
The constraint is not a handicap. It is the only reason it ships at all.
Most OT security advice is written by people whose worst outage was a failed deploy.
The advice is not wrong. Patch promptly, segment, rotate credentials. It assumes a system you can restart.
A press line does not restart. That gap is where industrial programmes fail.
@PqShield A highly important topic to have on board level however I think there is a risk of it not surfacing on the agenda due to current AI related risks. Great content thanks!
Unfortunately one hears about these cases when reading threat actors comments in their hacks. Developers face requirements for high and “lean” pace in creating products and when internal processes and solutions do not support this in a secure way cases like these emerge in my opinion.
Five questions that reveal whether a crypto-agility claim is real:
1. Swap one algorithm in one product. How long?
2. Who owns that decision?
3. Where is the certificate inventory, and when was it last true?
4. What breaks in the field when you rotate?
5. Show me the last time you did it.
Most answers stop at 2.
Post-quantum migration is not a cryptography project. It is an inventory project.
You cannot rotate a key you do not know exists. Choosing algorithms takes an afternoon. Finding every place your organisation does cryptography takes years.
Everyone is doing the afternoon first.
I've spent months collecting the best AI cheat sheets.
Here are the top 8 AI cheat sheets that will save you hours of work (for free):
1. Ultimate ChatGPT cheat sheet
Thaye Dorje, His Holiness the 17th Gyalwa Karmapa, shares the following message regarding the Parinirvana of his teacher, His Holiness the 14th Kunzig Shamar Rinpoche.
https://t.co/1bZNsgypY2
6 months ago, I started working on a way to better map the #ransomware ecosystem and its evolution, including rebrands.🔎
I am really happy to share this handmade cartography, which is based on @orangecyberdef resources, #OSINT and reverse engineering.
➡️ https://t.co/cKK57AM07f
ChatGPT can supercharge your sales.
With just one prompt you can turn it into your personal sales coach.
Here's how to 10x your sales skills (using ChatGPT):
🚨 So much has happened in the world of AI these past 7 days.
It's going to change many industries you thought you knew.
12 recent AI developments that are not just reshaping the industry, but our everyday lives: