Showing posts with label cyber recovery. Show all posts
Showing posts with label cyber recovery. Show all posts

Daily Tech Digest - September 27, 2026


Quote for the day:

"The distance between insanity and genius is measured only by success." -- Bruce Feirstein

🎧 Listen to the audio debrief on YouTube

▶ Play Audio Digest

Duration: 23 mins • Perfect for listening on the go.


Digital Twin Technology: A Comprehensive Guide

A digital twin is a dynamic, data-driven virtual replica of a physical object, process, or system. Unlike a static 3D model or a traditional one-time simulation, a digital twin continuously receives real-time data from sensors attached to its physical counterpart. This steady flow of information ensures the digital version mirrors the actual, current behavior of the real-world entity rather than just its original design specifications. The technology relies on three core components: the physical entity equipped with sensors, the virtual model, and the continuous data connection linking them. By maintaining this active connection, organizations can run highly accurate simulations, test new scenarios, and predict failures without risking the actual physical asset. The applications are broad and scalable, ranging from tracking a single component like an engine bearing to managing complex networks like a manufacturing production line or an entire modern city's infrastructure. While the technology offers incredibly powerful predictive capabilities, building an effective digital twin comes with several practical challenges. Organizations must manage data quality, handle complex modeling requirements, and navigate security concerns carefully. Because of this inherent complexity, experts recommend starting with a single, well-defined use case before attempting to scale up to larger, interconnected systems.


Three Hidden Traps That Shape Software Engineering Decisions

Engineering leaders face more than just technical challenges; they must also navigate human behaviors and cognitive biases that heavily influence software design and quality. The article outlines three common traps that developers and technical leaders fall into. The first is the "status quo bias," where teams stick to familiar tools or methods simply because "we've always done it this way," often ignoring newer, more suitable options for current requirements. The second trap is "complexity bias," which tempts engineers to overengineer solutions by adding unnecessary layers, abstractions, or services under the false assumption that complex designs are inherently more robust. This often leads to systems that are harder to maintain and prone to failure. Finally, the "broken windows" effect describes how an environment of poor code quality or neglected technical debt silently lowers a team's engineering standards. When developers see messy code or ignored warnings, they are more likely to introduce new shortcuts, gradually degrading the entire system. Recognizing and naming these biases helps teams pause, ask the right questions, and make more deliberate, evidence-based decisions rather than relying on flawed mental shortcuts.


How can boards gain confidence in their organization’s AI adoption?

Many corporate boards believe that establishing policies and risk frameworks is the key to governing artificial intelligence. However, Michael Covington argues that effective AI governance is impossible without first achieving comprehensive visibility into where and how AI is actually being used within the organization. Just as with the adoption of SaaS, cloud computing, and mobile technologies, companies are rushing to implement AI policies while lacking a basic inventory of their AI assets. Currently, over 70% of organizations deploy AI, yet more than 80% feel exposed to AI-related risks because adoption has vastly outpaced governance. This visibility gap is particularly dangerous because AI capabilities are increasingly embedded into routine software updates, meaning new tools can enter the corporate environment without any formal procurement or approval processes. This unchecked expansion poses risks beyond just security, potentially leading to unauthorized data access or widespread system disruptions. To solve this, leadership must treat AI like any other core technology asset. By integrating AI tracking into existing hardware, software, and cloud service inventories, boards can achieve continuous visibility. This foundational step transforms AI from an unmanaged liability into a measurable asset, allowing security, compliance, and finance teams to govern its usage with confidence.


The Factory Can Survive the Cyberattack. Can It Survive the Recovery?

Manufacturers have spent years investing in their ability to detect cyber threats, but detecting an attack is really only the beginning of the battle. In a factory setting, recovering from a cyber incident is far more complex than simply restoring digital assets or standard computer applications. It requires carefully bringing operational technology, such as programmable logic controllers and industrial machinery, back online in the correct sequence to avoid further issues. A technically successful software restoration can still result in operational failure if physical processes are restarted incorrectly or unsafely. To build true recovery readiness, manufacturers must map production dependencies outward from the physical process rather than inward from the network. This means identifying which critical operations must return first and defining the specific utilities, vendors, and human approvals required to support them. Organizations should assign recovery authority across tech, operations, and management teams ahead of time to prevent decision bottlenecks during an emergency. Finally, factories must practice realistic recovery scenarios where ideal conditions, such as the availability of key personnel or clean backups, are deliberately removed. Ultimately, a resilient manufacturer treats operational recovery as a designed and measured production capability, ensuring a safe, controlled return to dependable operations across the entire plant.


Why Enterprise AI ROI Is An Architecture Problem

Many companies struggle to see a positive financial return from their artificial intelligence efforts because of flawed system architecture, rather than the raw cost of the intelligence itself. Most organizations mistakenly build these capabilities by attaching them to disjointed legacy systems, forcing every new project to recreate rules and data connections from scratch. This fragmentation scatters information and makes proving economic value nearly impossible. To solve this and improve financial outcomes, businesses must adopt four core architectural changes. First, they should mandate a shared knowledge foundation to centralize enterprise data, eliminating the need to repeatedly rebuild integrations for each new tool. Second, they need to route tasks to the appropriate model based on complexity; simple tasks should use smaller, less expensive models, reserving advanced systems only for complex, high-value reasoning. Third, companies should prioritize groups of specialized tools over a single, massive program. Breaking tasks down into narrower, focused parts reduces the data processed at each step, significantly cutting costs and improving speed. Finally, organizations must build security and compliance directly into the core platform rather than adding them to individual applications, ensuring controls remain reusable and highly transparent. Ultimately, centralized architecture lowers deployment costs and clarifies actual value for the overall business.


Website Tracking Technologies Face Growing Litigation and Regulatory Scrutiny

Many companies use website tracking technologies like pixels, software development kits, session replay scripts, and chat tools to better understand how visitors interact with their pages. Working quietly behind the scenes, these tools gather data when a person clicks a button, views a product, or fills out a form. They then share this activity with third-party analytics and advertising companies. For years, businesses have relied on these insights to measure website traffic, track the effectiveness of marketing campaigns, and personalize the user experience. However, this routine data collection has recently become the center of a rapidly expanding wave of legal and regulatory action. Because these tools frequently transmit visitor information automatically and often before a user formally agrees to share their data, they have drawn severe scrutiny from privacy advocates and government agencies. Regulators and plaintiffs' attorneys are now scrutinizing exactly what information gets shared, with whom, and whether proper consent was obtained. In many recent lawsuits, these common marketing tools are being classified as wiretapping and eavesdropping devices that unlawfully disclose personal information. Ultimately, while tracking technologies provide businesses with valuable insights into customer behavior, they are now introducing substantial legal risks that demand careful oversight and strict compliance.


Clean Architecture: 5 Layers Every Developer Should Understand in 2026

Clean Architecture provides a structured way to build software by firmly separating core business rules from external details like databases, user interfaces, and frameworks. This approach relies on a central principle called the Dependency Rule, which dictates that source code dependencies must only point inward. The architecture is typically divided into five distinct layers to manage these boundaries. At the very center are Entities, which represent pure, framework-independent business logic that rarely changes. Surrounding them are Use Cases, which define application-specific rules and coordinate data flow without knowing about the database or web framework. Next are Interface Adapters, such as controllers and presenters, which carefully translate data between the inner core and the outside world. Further out is the Infrastructure layer, containing concrete implementations like third-party libraries and database adapters. Finally, the outermost layer consists of Frameworks and Drivers, which act as the basic glue holding the application together at startup. By strictly enforcing this inward dependency throughout the codebase, developers can ensure their applications remain completely testable and highly adaptable over time. This clear structure allows teams to comfortably swap out databases or web interfaces down the line without ever risking the fundamental logic that makes the product work.


The duality nobody priced in: The changing landscape of enterprise tech architecture and Agentic AI era

Enterprise technology is currently undergoing its most significant architectural shift in thirty years, driven primarily by the transition to agentic artificial intelligence. For decades, traditional enterprise systems were designed to standardize business processes, keeping core operations highly structured while placing customizations and early AI tools safely at the outer edges. Generative AI fundamentally breaks this familiar pattern by moving from transaction-driven operations to intent-driven software. Instead of following rigid, pre-defined rules, agentic applications accept a specific goal and determine their own path, effectively shifting business logic into a complex central orchestration layer. While this promises considerably faster software production, it introduces substantial new challenges in data governance, cost management, system testing, and operational oversight. Organizations now face a choice in how to integrate this technology: replacing old automation, layering agents over existing systems, running them in parallel, or embedding them deeply into core frameworks. Ultimately, true success requires much more than just launching rapid prototypes to showcase capabilities. The enterprises that will thrive in the coming decade are those that resist the urge to rush and instead focus on building robust architectural foundations, carefully balancing the speed of new technology with necessary operational reliability and long-term security.


With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance

The rapid adoption of AI agents is exposing significant blind spots in traditional SOC 2 compliance frameworks. Originally designed with human actors in mind, SOC 2 controls rely on foundational assumptions that do not apply to machine identities. Because the framework does not explicitly mandate treating AI agents as a distinct class of users, organizations can pass audits while harboring unrecognized security risks. Specifically, four core assumptions are now breaking down. First, unlike human users who require formal approval before account creation, agents are often spawned automatically or indirectly. Second, determining the true owner of an agent is frequently a matter of guesswork rather than a clear record. Third, because AI agents often operate using borrowed human credentials, access logs cannot reliably distinguish between human and machine activity. Finally, traditional least-privilege principles limit an agent's reach but fail to explain its actual intended purpose. These gaps weaken critical controls, such as offboarding processes that overlook active agents tied to former employees, and change management where agents bypass genuine segregation of duties. To maintain true security, organizations must look beyond the compliance checklist, intentionally track machine identities, and match an agent's access directly to its specific purpose.


Your architecture diagram is not your resilience

An architecture diagram represents a system as it was intended to be, but it cannot prove whether that system is truly resilient today. Microsoft emphasizes that resilience is no longer a one-time project you can set and forget. Instead, it is an ongoing property you must actively maintain. Over time, architectures drift as systems change. For instance, a database might support failover, but an application's connection string could remain pinned to a single region. Because diagrams lack timestamps and operational reality, they often fail to capture this drift. Furthermore, the nature of dependencies is evolving. While traditional disaster recovery focuses on infrastructure, modern systems increasingly depend on AI models and inference endpoints. These dependencies introduce new risks, as AI can produce varying responses and may become unavailable or capacity-constrained. To manage these shifts, organizations must move beyond relying on static diagrams and adopt a continuous validation approach. Microsoft recommends designing resilience from the beginning, defining clear recovery objectives, and understanding your actual blast radius. Tools like the Azure Infrastructure Resiliency Manager and fault injection through Azure Chaos Studio can help teams test failover paths and measure their posture, ensuring that their intended resilience matches reality.

Daily Tech Digest - September 23, 2026


Quote for the day:

"Every great story on the planet happened when someone decided not to give up, but kept going no matter what." -- Spryte Loriano

🎧 Listen to the audio debrief on YouTube

▶ Play Audio Digest

Duration: 26 mins • Perfect for listening on the go.


Observability should start with business outcomes, not infrastructure

The article, "Observability should start with business outcomes, not infrastructure" by Vjacheslav Mikitjuk, argues that technical metrics alone are inadequate for understanding the actual performance of IT systems. The article points out that while an engineering dashboard might show a system running efficiently, it could simultaneously be experiencing a serious customer-facing failure. Therefore, IT teams need to translate technical severity into business severity to provide management with a clear picture of the impact on customers, transaction values, and overall business operations. Mikitjuk suggests that observability needs to follow a chain starting from business outcomes down to telemetry. This approach involves defining service objectives based on user experience rather than just infrastructure metrics. He emphasizes that the translation between technical and business performance should be a shared responsibility across the organization, involving business leadership, product owners, and engineering teams. Furthermore, he advises that business observability must be designed proactively during the service and product design phases, rather than being an afterthought during an incident. The article also highlights that observability priorities should be determined by business criticality, focusing efforts where degradation would have the most significant consequences. Finally, while AI can assist in interpreting data, it requires the foundational context of business goals to be truly effective.


Redefining Cyber Recovery Requirements in the Era of Modern Cyberattacks

Cyber recovery is fundamentally different from traditional disaster recovery, requiring a practical approach to combat modern threats. While disaster recovery focuses on quickly restoring the most recent backup after an outage, cyber recovery prioritizes data integrity. Because attackers often dwell inside networks for days or weeks before causing damage, the newest backup is usually infected. Therefore, IT teams must work backward to find a genuinely clean copy. This process is complicated by the fact that the vast majority of modern intrusions leave no malicious files behind. Instead, attackers use stolen credentials and existing administrative tools to move silently. As a result, standard antivirus scans on powered-off backups are no longer sufficient. To ensure a backup is truly safe, organizations must power it on and carefully observe its behavior over time to detect hidden threats. Because powering on a compromised system risks reinfecting the entire network, this behavioral analysis must happen inside a strictly isolated clean room. Solutions like VMware Cloud Foundation and Advanced Cyber Compliance automate this critical testing environment. By integrating secure, quarantined recovery workflows, organizations can confidently identify uncorrupted data and restore operations safely, moving beyond outdated backup strategies to address the reality of modern fileless attacks.


Data embassies and sovereign dispersion

Data embassies and sovereign dispersion present a new approach to managing the trade-off between data residency and resilience, moving beyond traditional data localization. Driven by geopolitical instability and cyber threats, governments—particularly smaller, highly digitized nations like Estonia—are establishing legally protected digital enclaves on foreign soil. Unlike multi-region cloud backups subject to host nation laws, genuine data embassies operate under bilateral treaties granting them diplomatic immunity. They maintain an active "digital twin" to ensure core civic services, like tax systems and central bank ledgers, run smoothly during domestic crises such as cyberattacks or power failures. Gartner anticipates that by 2029, 15% of nations in unstable regions will have formalized data embassy agreements. Estonia established the first in 2015, partnering with Luxembourg for its Tier IV data centers, setting a precedent that requires specific intergovernmental contracts. Security relies on principles like "encryption as a border," ensuring the origin state retains decryption keys. While replicating this model is challenging for private enterprises, IT leaders can adopt similar technical resilience strategies. By decoupling encryption keys from cloud providers and avoiding over-reliance on a single vendor or location, businesses can enhance their operational continuity and mitigate risks associated with physical data concentration.


How to Handle the Growing Data Complexity Challenge in Cyber Incident Response

The article explains that cyber incident response has become far more complicated than simply handling large volumes of data after a breach. Modern organizations generate information across cloud platforms, collaboration tools, mobile devices, enterprise applications, and third‑party services, creating a sprawling and interconnected data environment. Regulators now expect investigators to identify and analyze a wider range of sensitive information, from traditional personal data to device identifiers, geolocation details, and behavioral patterns. The piece highlights how today’s breaches often involve structured and unstructured data, multimedia files, and systems that store overlapping records, making it difficult to determine what truly matters. Traditional keyword‑based search methods are no longer enough, especially when investigators must uncover “unknown unknowns” hidden across diverse systems. AI‑assisted tools can help by recognizing entities, relationships, and context, but the article stresses that any AI‑driven process must remain legally defensible through documented workflows, validation, and human oversight. Notification decisions—often the hardest part—require consolidating identities, applying jurisdictional rules, and ensuring accuracy at scale. The author concludes that organizations need a disciplined, context‑aware approach to data mining, combining technology, expertise, and defensible processes to understand risk and respond confidently under tight timelines.


7 decisions that make an Azure landing zone enterprise-ready

Creating an effective, enterprise-ready Azure landing zone requires thinking beyond basic reference architectures to build a platform that supports engineering teams rather than hindering them. The article highlights seven key design decisions to achieve this balance between security and developer autonomy. First, treat the landing zone as an operating model—not just a network—by separating platform resources from application workloads using management groups and subscriptions to create clear governance boundaries. Second, opt for Azure Virtual WAN over a self-managed hub-and-spoke setup to simplify cross-region connectivity and route management. Third, integrate your security model, such as a next-generation firewall, directly into the routing architecture from day one rather than bolting it on later. Fourth, implement governance as guardrails that manage risk without turning routine engineering tasks into a constant exception process. Fifth, separate your observability tools for operational health from your SIEM tools for security monitoring to reduce noise and clarify responsibilities. Sixth, treat CI/CD networking as a core platform component, using solutions like private GitHub runners to securely deploy to isolated resources. Finally, ensure an active-active architecture truly works by making both regions fully production-ready and capable of independently supporting the workload during a failure.


AI adoption in OT security accelerates as legacy infrastructure and poor data expose readiness gaps

Many industrial organizations are eager to implement AI for operational technology (OT) security, but their current infrastructure often isn't ready. A recent survey highlights that while nearly 88% of organizations are using or planning to use AI, under 8% have deployed it across multiple functions. The main hurdles are poor data quality and the challenges of integrating AI with legacy systems. Most industrial facilities were built long before AI was a consideration, resulting in control systems that produce inconsistent data. Experts point out that legacy environments frequently lack the necessary identity and access management infrastructure and cloud connectivity required for modern AI models. This gap is especially problematic because AI depends on high-quality data and complete asset context to function accurately. Without these, AI tools can produce incorrect assumptions, leading to false positives or missed threats. Furthermore, poor data quality in OT can have serious physical consequences, including equipment damage or safety incidents. To make AI work effectively and safely in these environments, organizations must first focus on improving their architectural foundations. This includes better data normalization, consistent telemetry, and modernized security architectures that provide a stronger base for AI-enabled tools.


Operational Technology Scope Expands as Security Matures

The article describes how operational technology (OT) security has matured as industrial organizations face more frequent and costly cyber incidents. According to Honeywell’s 2026 OT Cybersecurity Benchmark Report, major attacks now cause an average of 16 hours of downtime, with losses reaching up to $500,000 per hour. As a result, companies across energy, manufacturing, healthcare, maritime, and other critical sectors are shifting from a narrow, technology‑centric mindset to a broader focus on business resilience. Leaders increasingly view OT security as essential to safety, uptime, and service continuity, especially as digital connectivity expands across industrial control systems, field devices, building management systems, IoT sensors, and medical equipment. The report shows that organizations with mature programs detect and respond to threats faster, largely because they maintain strong asset inventories and continuous monitoring. Yet visibility remains a major gap: only one‑third have integrated OT systems into a centralized SOC, and just one‑fifth continuously monitor IoT devices. Legacy systems, staffing shortages, and budget constraints add further strain. Many organizations are adopting AI for detection and monitoring, though fully autonomous decision‑making remains rare. The article concludes that resilience depends on extending security across every connected system and closing visibility gaps that still hinder effective response.


I Wasn’t Trying to Predict the Future. I Was Trying to Build One I Could Tolerate

The article is a reflective piece in which the author explains that his work with AI did not begin as an attempt to predict the future but as a practical response to a narrowing set of acceptable options. He frames his journey not as a heroic narrative but as a form of “niche construction,” a security practice focused on shaping an environment that can support more viable futures. Throughout his career in cybersecurity, supply‑chain assurance, information sharing, and industrial systems, he learned that security is rarely about protecting a single object. Instead, it is about maintaining the conditions that allow systems to survive and adapt. He illustrates this through stories of living on self‑built boats, where survival depended on constant maintenance, awareness, and the ability to respond to change. When his own circumstances tightened in 2025, he turned to a large language model as one of the few available tools and began a sustained, iterative collaboration that produced frameworks, documents, code, and new institutional structures. He describes this as building a generative set—an evolving system that creates new possibilities rather than following a fixed plan. The article concludes that meaningful security often comes from constructing environments where better futures can emerge, not from defending the present in isolation.


CISOs can no longer ignore the nation-state threat

The accelerating use of AI by nation-state actors is forcing Chief Information Security Officers (CISOs) to rethink their threat models and treat geopolitical threats as urgent enterprise risks. Historically, CISOs focused on quickly expelling adversaries from networks, while government agencies preferred to monitor them for intelligence. However, AI is now lowering the barrier to entry, allowing even amateur cybercriminals to launch sophisticated attacks that mimic nation-state activity. This shift blurs the line between national security threats and ordinary business risks. A major challenge for organizations is recognizing their own strategic value to foreign adversaries. Companies in seemingly benign industries, such as agriculture, can become targets if they possess valuable intellectual property or supply chain access. AI worsens this by compressing the time between a vulnerability's discovery and its exploitation to mere seconds, making traditional patching processes insufficient. To adapt, security leaders must recognize that AI enables faster, broader pre-positioning by attackers within organizational assets. Experts advise CISOs to prepare for fully autonomous attacks, plan to operate through compromises during major disruptions, and focus on core security controls like zero trust and multi-factor authentication. Crucially, CISOs need board-level support and funding to implement these necessary resilience measures.


AI slop is creating more work, not less. Here’s why

The rise of generative AI in the workplace was promised to boost productivity, but it is increasingly resulting in "AI slop"—low-quality, generic, and often unverified content that shifts the workload onto other employees. In a recent Today in Tech episode, host Keith Shaw and Commvault’s Chris Bevil discussed how tools that instantly generate emails, reports, and presentations create a hidden "review tax." While an executive might save time using AI to summarize a long document or draft a memo, the receiving employees must often spend significant time fact-checking, correcting context, and deciphering vague, polished-but-empty drafts. This disconnect explains why executives frequently report high productivity gains from AI, while non-managers feel bogged down by new verification processes. AI slop resembles a "first draft wearing a tie"—it looks professional and confident on the surface but lacks underlying substance or clear judgment. As this unverified content spreads rapidly across organizations, it risks becoming accepted corporate knowledge. To truly benefit from AI, companies must move beyond simply generating more content and emphasize proper governance, human review, and clear workflows to prevent productivity gains at the top from becoming a burden at the bottom.

Daily Tech Digest - September 21, 2026


Quote for the day:

“The two most important days in your life are the day you are born and the day you find out why.” -- Mark Twain

🎧 Listen to the audio debrief on YouTube

▶ Play Audio Digest

Duration: 22 mins • Perfect for listening on the go.


Engineering trust at scale: Building the infrastructure behind global payments

The provided article discusses the complex engineering required to build trust and reliability in global payment systems. The core challenge lies in simplifying the user experience while managing the intricate underlying infrastructure, which involves multiple banks, currencies, compliance checks, and domestic payment schemes. Trust is essential, encompassing not just cybersecurity, but also operational resilience, effective transaction routing, and settlement. Payment architectures must handle high transaction volumes without compromising reliability or creating friction for users. As businesses expand globally, payment systems need to connect local networks smoothly, rather than attempting to create a single universal system. Regulatory compliance must be integrated directly into the transaction process, adapting to different regional requirements without adding unnecessary hurdles for businesses. Artificial intelligence is highlighted as a key tool for managing this complexity, especially in detecting fraud and recognizing legitimate behavior to reduce false positives. Finally, the article emphasizes the importance of interoperability. A unified technology layer and tools like Open Finance can help businesses access local payment methods globally without needing to rebuild their systems for each new market. Ultimately, the goal is for the underlying payment infrastructure to manage the complexity so effectively that the end-user experience remains simple and trustworthy.


Google’s open source EnvHarness lets AI agents train against environments that evolve with them

Google has introduced EnvHarness, an open-source framework designed to solve a major problem in AI agent training: static simulators. Usually, when agents practice tasks like software engineering or web navigation, the training environments remain fixed. If an agent repeatedly struggles with a specific step, the environment cannot adapt to help it practice that weakness. Building new environments and testing rules from scratch is costly and time-consuming. EnvHarness addresses this by wrapping a programmable layer around existing simulators. Instead of replacing the original setup or its success checkers, it modifies how the environment interacts with the agent. The framework uses three main components. "Stage" changes the starting conditions of a task. "Contract" adjusts the rules, such as filtering actions or altering what the agent can see. "Chain" links multiple tasks together into a longer sequence. A companion system called EnvRigger automatically analyzes an agent's failures and suggests these modifications to target specific weaknesses. In tests across five major benchmarks, agents trained using EnvHarness saw success rates improve by up to nine percentage points compared to those trained in standard environments. They also completed tasks in fewer steps. By allowing training grounds to evolve alongside the agent, EnvHarness makes learning significantly more efficient.


Why Australian businesses are still underestimating the time it takes to recover from a cyberattack

Many Australian organizations invest heavily in cyber defenses but fail to understand the true timeline for recovering from a system breach. According to recent findings, company leaders often expect normal operations to resume within a few days of an incident, whereas the actual recovery process frequently takes weeks. This disconnect is driven by the growing complexity of modern technology environments, which now span multiple cloud platforms, software services, and vast data systems. Every new layer adds dependencies that must be carefully restored and verified before services can resume. Recognizing that disruptions are inevitable, regulators are shifting their focus from merely preventing attacks to ensuring operational resilience. Rules now require organizations to identify their critical services and prove they can maintain them during severe incidents. To achieve this, companies should focus on defining their essential functions by identifying the minimum people, processes, and technology needed to survive a crisis. Rather than waiting for an emergency to test their systems, organizations must make recovery readiness a continuous, daily practice. By actively aligning their security, technology operations, and data management around clear recovery goals, businesses can build genuine confidence. Ultimately, understanding exactly how and when you can restore critical services is a highly meaningful competitive advantage.


Navigating training, improving and competition restrictions in generative artificial intelligence (AI) agreements

This article explores the complexities of generative AI software license agreements, particularly concerning restrictions on using AI tools and their generated output to develop competing products. It highlights a critical distinction between the use of an AI platform itself and the use of the content it produces. While traditional software agreements limit the use of the software to prevent the development of competitive offerings, generative AI introduces output (like text, code, or images) that users often want to leverage for their own business purposes. The core issue is that AI providers want to protect their models and data, so they often include non-compete clauses. However, these restrictions can be overly broad, potentially hindering users from utilizing the AI-generated output as intended. The article notes that market approaches vary significantly; some providers restrict only the platform's use, while others strictly limit how the output can be used downstream. Due to the lack of clear consensus among providers and uncertainty about how US courts might interpret vague restrictions, the authors emphasize the need for clear, specific language in contracts. Providers need to define the scope of restrictions carefully, and users must ensure the agreements permit their intended use of both the AI platform and its output.


Defenders Think In Lists. Attackers Think In Graphs

Cybersecurity defenders often rely on creating lists to manage their environments, focusing on inventories of assets, known vulnerabilities, and compliance rules. In contrast, attackers think in graphs, looking closely at how these individual assets connect. Once attackers find an entry point, their primary goal is to move laterally by exploiting relationships, permissions, and network pathways to reach critical data. Modern enterprise environments have expanded across cloud platforms, third-party integrations, and AI services, making cyber risk a problem of context rather than simple inventory. An isolated vulnerability matters less than the specific pathway it opens to valuable systems. Furthermore, AI has heavily accelerated the speed at which attackers can map and exploit these complex networks, allowing them to rapidly evaluate thousands of potential attack paths simultaneously. To effectively protect their environments, organizations must stop looking at security controls in isolation. Instead, defenders need to adopt an attacker's mindset by deeply understanding their network's topology and the connections between different systems. By focusing on reachability and context, security teams can successfully bridge the gap between technical data and true business risk. The future of defense lies in understanding how everything connects and quickly anticipating exactly where an attacker might go next.


When Does AI Stop Needing Us?

The recent article from the Communications of the ACM thoughtfully examines how artificial intelligence is moving steadily toward greater independence. It looks at the practical and theoretical limits of these tools, asking if we will eventually reach a point where human guidance is no longer necessary. By reviewing recent progress in computing, the author offers a grounded, realistic look at what the technology can and cannot do right now, deliberately avoiding any dramatic or exaggerated claims. For the everyday professional, this shift means that standard, repetitive tasks are increasingly likely to be handled by machines in the near future. As a result, human skills like deep reasoning, ethical decision making, and navigating complex problems will only become more valuable. The focus moves away from simply processing data and toward interpreting the results that computers provide. Workers are encouraged to understand the boundaries and potential errors of these systems rather than ignoring them. The most practical path forward is to steadily build skills that rely on human connection, understanding, and strategic thought, areas where machines still struggle. Taking time to review which parts of a job are easily automated allows individuals to adapt smoothly, maintaining their value by leaning into genuine human insight.


What Does Day Four Cost? Rethinking How Organizations Measure Resilience

Traditional resilience programs often measure disruptions using operational labels like high, medium, or low risk, which fail to capture the true financial impact over time. As a business interruption stretches from hours into days, the consequences compound, affecting suppliers, customers, and overall revenue. To make informed decisions, organizations need to move beyond static risk ratings and their disconnected spreadsheets. A mature approach evaluates exactly how financial exposure changes over the entire lifespan of a disruption. Rather than viewing business processes in isolation, companies should map their operations to understand how value actually reaches the customer. This means tracking dependencies across technology, facilities, and personnel. By calculating gross exposure, factoring in existing mitigation efforts, and determining the net financial impact, leaders can better justify recovery investments. Furthermore, continuity plans cannot remain static documents updated only once a year. They must evolve as the business changes. While artificial intelligence can help streamline data collection and highlight inconsistencies, it should support rather than replace human judgment. Experienced professionals are still necessary to validate strategies and make final decisions. Ultimately, an effective resilience program connects operational risks to financial realities, giving executives a clear picture of exactly what prolonged downtime will cost the business.


Cyber Defense Alone Can't Keep Critical Services Running

The article explains that states cannot rely on cyber defense alone to keep essential services such as water systems and hospitals running. State CIOs are increasingly responsible for protecting a patchwork of local utilities that depend on digital systems to deliver basic physical services. Survey data shows that most CIOs worry about cyberattacks on critical infrastructure, but budgets and staffing often fall short. The piece argues that states must first identify which facilities would cause the greatest harm if disrupted and then map the dependencies that keep them functioning. Experts quoted in the article stress that availability, not just confidentiality, is the real challenge. Many utilities have become so dependent on internet connectivity that they may not be able to operate manually during an outage. The article highlights “cyber‑informed engineering,” an approach that assumes attackers will eventually breach digital defenses and therefore builds physical safeguards—such as pressure‑reduction valves or time‑delay relays—to limit damage. These measures are often inexpensive but require coordination across water operators, hospitals, and emergency managers. The author concludes that states must prioritize the highest‑consequence risks, run realistic tabletop exercises, and focus resources on the systems that support the most vulnerable communities, because they cannot fix everything at once.


Can AI Safety Evaluators Really Stay Independent?

The article discusses a new proposal backed by Anthropic and OpenAI to allow independent AI safety evaluators closer access to their model development process. As advanced artificial intelligence systems grow more capable, there are increasing concerns about verifying their safety. Traditionally, external evaluations occurred just before a model's public release. However, researchers worry this approach is no longer sufficient, as highly advanced models might learn to recognize testing environments and temporarily hide dangerous behaviors. To address this, researchers are demanding deeper access throughout the entire training process. They want to examine early model versions, training logs, and internal checkpoints to see when concerning behaviors emerge and how they are handled. Anthropic's CEO proposed embedding evaluators directly inside companies with the freedom to investigate incidents and publish findings without corporate editorial control. OpenAI's CEO also expressed support for this approach. Despite these commitments, independent researchers remain cautious. They emphasize that true independence requires more than just access; it demands freedom from company control over information, timing, and publication. The key challenge lies in the implementation details, which have not yet been fully defined by either company. Researchers stress the need for transparent rules to ensure evaluators aren't restricted by narrow scopes or strict nondisclosure agreements, allowing them to effectively hold frontier AI companies accountable.


Architecting Secure and Scalable Facial Verification Systems

The article "Architecting Secure and Scalable Facial Verification Systems" from InfoQ explains the challenges and solutions in building enterprise-grade facial verification systems. The author shares experiences from scaling a prototype into a robust architecture capable of handling high concurrency, such as thousands of employees clocking in simultaneously. Key takeaways emphasize that facial verification must be treated as a distributed systems challenge, not just a simple API integration. Synchronous calls fail under heavy load, so asynchronous queues and circuit breakers are essential to handle traffic spikes. Additionally, decoupling immediate detection tasks from the stateful verification process prevents system bottlenecks. The author also stresses the importance of pushing data quality checks—like adjusting for lighting or blur—to the client device to reduce latency and cloud costs. For privacy and security, the system must enforce strict zero-trust principles, using short-lived tokens instead of raw personal data and implementing aggressive data retention policies. Finally, the article advises using a risk-based decision engine rather than static thresholds, treating confidence scores as probabilistic inputs to maintain accuracy across various transaction types.

Daily Tech Digest - February 20, 2025


Quote for the day:

"Increasingly, management's role is not to organize work, but to direct passion and purpose." -- Greg Satell


The Business Case for Network Tokenization in Payment Ecosystems

Network tokenization replaces sensitive Primary Account Numbers with tokens, rendering stolen data useless to fraudsters and addressing a major area of fraud: online payments. "Fraud rates are seven times higher online than in physical stores, as criminals exploit exposed card numbers," Mastercard's chief digital officer Pablo Fourez told Information Security Media Group. Shifting to tokenization protects businesses from financial losses and safeguards reputation and customer trust. ... But adoption of network tokenization does come with challenges including issuer readiness, regulatory hurdles and inconsistent implementations. Integrating network tokenization across multiple card networks requires multiple integrations, ensuring interoperability and maintaining high security standards, Fourez said. Compliance with varying regulatory requirements and achieving scalability without performance issues can be resource-intensive, he said. Ramakrishnan points to delays in token provisioning that may slow the speed of transactions if the technology is not scalable. Situations in which one entity in the payment ecosystem does not use network tokens can be major failure points that can lead to transaction failure and cart abandonment.


The hidden gap in cyber recovery: What happens when roles and processes are overlooked

There’s a big difference between disaster recovery (DR) and cyber recovery. For DR, infrastructure and backup teams are the central players and an organization can be up and running in no time. Cyber recovery, however, involves the entire business — backup teams, network teams, cloud personnel, incident response teams from security, teams that are validating the active directory before restores, as well as the application owners and business owners that depend on those functions. ... “There are bigger questions that you only get to by testing your process,” Grantham says. “Whatever your business is, it’s about looking at that data and saying, how do I provide access in this modified environment? For every one of the applications supporting that, having a run book to say, this is the people, the process, linked to the technology to get me to a user in the system performing their daily function because they need to be able to do their job. That run book gets them there. If your data is just sitting on a hard drive in the middle of a data center, how does that help your business?” ... “The idea that cyber recovery strategies require continual evolution, just like zero trust is an evolution of different identity standards, is not something that a lot of businesses have accepted yet,” Grantham says. 


Microsoft Makes Quantum Computing Breakthrough With New Chip

While it’s been working on its own quantum computing hardware, Microsoft has also been building out a quantum computing stack, with its Q# development language and quantum algorithms that can run on the quantum hardware from IonQ, Pasqal, Quantinuum, QCI, and Rigetti that’s available through Azure — but the most powerful systems so far are still in the 20-30 qubit range. ... A prototype fault-tolerant quantum computer will be available “in years, not decades,” promised Chetan Nayak, Microsoft’s VP of quantum hardware. The potential of topological qubits is why DARPA announced earlier this month that Microsoft is one the first two companies to be invited to join its rigorous program for investigating whether it’s possible to build a useful quantum computer — where the value of the computing it can do is worth more than what it costs to build and run — by 2033, using what the agency calls underexplored systems. ... Initially, there are just eight physical qubits in the Majorana 1 QPU, which Microsoft can assign in different ways to get the number of logical qubits it wants. Calling it a QPU is a reminder that there will probably be a lot of different kinds of quantum computer, and that researchers will pick the one that suits them — like choosing a different GPU for a specific workload.


CISO Conversations: Kevin Winter at Deloitte and Richard Marcus at AuditBoard

A CISO can only be as good as the security team. Assembling a strong team requires good selection and effective management: that is, who do you recruit, and how do you maintain top efficiency? Recruitment is a balance between multiple individual rock stars and a single cohesive team. That’s a personal choice for each CISO, but usually involves a compromise: the best possible individuals with the widest possible range of diversity that will still make a single team. Having recruited the team, the CISO must help them excel both as individuals and one team. “I love the Japanese concept of ‘ikigai’,” said Marcus. Ikigai can be defined as finding your life’s purpose – the meeting point of personal passion, skills, mission, and vocation. “I think you need to deliver an experience for the security team that checks all these boxes. They need to have interesting problems. They need to be using modern technology with some autonomy over what they use. You need to provide a sense of purpose – that what they’re doing is not just about the immediate technical work, but will have a broader impact on the company, the industry, and the world at large. And of course, you must pay them what they’re worth. I think if you do all these things, you’ll have a very happy and motivated and engaged team.”


Will AI destroy human creativity? No - and here's why

Today's AI models do more than automate. They engage. They understand user input conversationally, simulate thought processes, and adapt to preferences. AI's ability to adapt comes from machine learning constantly improving by analyzing huge amounts of data. This has made AI smarter and easier for people and businesses to use. The impact is undeniable in creative industries as AI tools can design logos, generate intricate artwork, and write compelling narratives, offering creators new possibilities. These advancements are transforming how people work, create, and innovate. Generative AI is now the focus of business strategies, with companies using these technologies to enhance efficiency and engage with their audiences in new ways. ... That said, the role of human creativity isn't being erased; it's evolving. Perhaps the designers and writers of tomorrow aren't disappearing but transforming into prompt engineers and crafting ideas in collaboration with these tools, mastering a new kind of artistry. Let's face it: Just because AI creates something doesn't mean it's good. The ability to discern, curate, and refine that intangible "eye" for greatness will always remain profoundly human. Unless, of course, Skynet becomes a reality.


Unknown and unsecured: The risks of poor asset visibility

Asset visibility remains a critical issue because organizations often lack a real-time, unified view of their IT, OT, and cloud environments. Shadow IT, unmanaged endpoints, remote work and third-party integrations create blind spot which increases attack vectors. Without complete visibility, security teams struggle to detect and respond to threats effectively, leaving organizations vulnerable to breaches and compromises. Good visibility across enterprise assets is no longer just a nice to have, it’s a necessity to survive in the digital world. ... Improving visibility of digital assets is critical for all organizations, otherwise, blind spots will exist in networks which criminals can exploit. Organizations must treat every endpoint as a potential entry point, ensuring it is seen and secured. It’s also important to remember that perfect technology doesn’t exist, vulnerabilities will always surface in products, so organizations must not only have an inventory of their assets, but also the ability to apply patches and security updates automatically, without necessarily having to pull all systems down. Improving OT visibility requires a specialised approach due to the sensitive nature of legacy and ICS systems.


Hacking Cybersecurity Leadership

Cybersecurity culture often fosters a sense of individualism that lends itself to operating in isolation—individual interest in areas of cybersecurity lead to individually-driven projects, individual certifications, etc. That being said, being siloed is not a sustainable mode of operation. For most cyber professionals, the challenges are too complex to resolve individually and negative experiences (failure, shame, guilt, embarrassment, etc.), when experienced alone, are likely to take an even greater toll than when those experiences are shared with others. ... In order to boost a sense of competence at the individual level, leaders need to create a learning-oriented environment that provides opportunities for individuals to explore, gather, and practice applying new information. There are specific strategies to build or strengthen these aspects of the work environment. ... Leaders can also embrace a growth-mindset culture whereby mistakes do not equate to failures; rather, mistakes are repositioned as learning opportunities to develop and grow. This allows individuals to safely explore and practice various aspects of their work. It’s important to note that this approach also requires a shift toward more developmental, rather than punitive or evaluative, feedback.


Real-World AppSec Priorities Observed in BSIMM15

Many organizations are still in the nascent stages of defining AI-specific attack surfaces and integrating security mechanisms. To stay ahead of these emerging risks, organizations should proactively gather intelligence on AI-related threats, establish secure design patterns for AI models, and ensure that AI security is seamlessly integrated into existing policies and frameworks. Proactivity is key here — a well-rounded strategy to leverage the potential AI can offer must be accompanied by strategic approaches to counter risks and threats it introduces. The use of adversarial testing, which involves simulating potential attacks to identify vulnerabilities, has more than doubled over the past year. This trend indicates a growing recognition among companies of the importance of continuously testing AI models to prevent them from being exploited by malicious actors. While it is not yet possible to definitively attribute the rise in these BSIMM activities to AI-specific concerns, it is evident that these practices will play a crucial role in addressing the emerging risks associated with AI. ... The decline does raise a red flag around the preparedness of organizations to defend against the evolving threat landscape. It also illustrates a need for security education and awareness initiatives. 


Why Best-of-Breed Security Is Non-Negotiable for SIEM

With cyber threats evolving at an unprecedented pace, security leaders can no longer afford to treat SIEM as just another layer in a bloated security stack. Instead, they must take a strategic approach, ensuring that their SIEM leverages truly best-of-breed security—one that enhances integration, streamlines operations, and delivers actionable threat intelligence. So, is more always better? Or is it time to redefine what best-of-breed really means for SIEM? ... The appeal of best-of-breed security is clear: superior threat detection, deeper visibility, and greater flexibility to adapt to evolving threats. However, this approach also introduces complexity. Managing multiple vendors, ensuring seamless integration, and avoiding operational inefficiencies can quickly become overwhelming. So, how do security leaders strike the right balance? Success lies in strategic selection, integration, and optimization—choosing tools that complement each other and enhance Security Information and Event Management (SIEM) rather than adding more noise. Adopting a best-of-breed security approach within a SIEM framework offers several advantages. By integrating specialized security solutions, organizations can optimize threat detection, improve agility, and reduce reliance on a single vendor. 


Digital twins and transitioning to a greener, safer industrial sector

Shah finds the term digital twins is often misunderstood. “Digital twins are not a single technology and standalone solution, but a strategic framework – one that combines and leverages multiple technologies. This can include AI, reality capture, 3D reality models and advanced web technologies which create a virtual 3D replica of an industrial site and its facilities.” Aiming to be the first climate-neutral continent by 2050, Europe has set some aspirational goals and according to Shah, digital twins could be a real game-changer in how the world could future-proof its industrial sites and transition to net zero. ... She noted many industrial sites struggle with issues related to technical documents and on the ground conditions, and this is an issue because inaccurate information can cause accidents to occur. AI and 3D rendered models enable experts to envision a scene in real time, allowing for greater accuracy than is often permitted by a physical walk-through of a facility. “What’s more, site personnel can also simulate processes like ‘lockout tagout’ safely, where machines are isolated and shut down for maintenance, without real-world risks and predict what could go wrong if an asset was isolated incorrectly, for example.