CYBER NEWS GLOBAL
CNG
ISSUE 22
TEKGEM
SPECIAL FOCUS SCOTTISH
OT
FROM HUMAN TO HYBRID, RETHINKING INSIDER THREATS IN AN AI-DRIVEN WORLD
CYBER SUMMIT
WHEN A MAJOR CYBER ATTACK HITS, HOW DO WE COMMUNICATЕ
PROTECTING OPERATIONAL TECHNOLOGY
-
AN INDUSTRY VIEW
LEADING IN UNCERTAINTY: CYBER RESILIENCE LEADERSHIР THE ART OF RESILIENCE NAVIGATING CNI RESILIENCE
FROM SHADOW AI TO STRUCTURED GOVERNANCE CYBER AI
-
RISE OF THE MACHINES
HOW HAS TECHNOLOGY EVOLVED
IS AI TAKING OVER THE WORLD ITS ONLY DATA. UNTIL IT ISN'T
Keep the Lights On When the Network Goes Dark.
Secure, sovereign out-of-band communications that keep teams connected, coordinated, and in control when primary systems fail.
Find out more at www.mattermost.com
Meet Mattermost at Scottish OT Cyber Summit
Contents
As we head to our 22nd edition of Cyber News Global, we will be focusing on one of the most important issues affecting our Critical National Infrastructure, the security threats we face within our CNI, how do we remain resilient. What are the challenges that Ai is now bringing to our CNI sector and the threats it poses to our Operational Technology. OT is an area that has always been under threat so we will take a deep dive into every aspect of OT, we will also partner at this years Scottish OT Cyber Summit where Industry leaders from Government, Law enforcement, Military and regulators will share their concerns, outline what actions must be consider from the threat of cyber-attack within our OT environments. There can be significant benefits of integrating Ai within the OT Environment providing thoughtful governance has been considered and implemented. As we all know threats come in every shape and size, none more than the insider threat, we take a look at the insider Threat to better understand the misconception, especially now that Ai is being widely utilised. So dear readers, don’t lose sleep, know that there is an army of cyber and Ai warriors out there looking at the future.
Please enjoy this special edition, have an inspiring day and read on.
3
10 When A Major Cyber Attack Hits, How do We Communicate 18 Protecting Operational Technology – An Industry View 24 Is AI Taking Over the World a Podcast with - Dr. Ana Rojo-Echeburúa 28 Leading in Uncertainty: Cyber Resilience Leadership 32 From Human to Hybrid, Rethinking Insider Threats in an AI-Driven world 36 Cyber AI – Rise of The Machines 40 How Has Technology Evolved 43 From shadow AI to Structured Governance 49 Its Only Data. Until It Isn’t 10
When a Major Cyber Attack Hits, How do we Communicate - James Mullins
28
24
Is AI Taking Over the World a podcast with Dr. Ana Rojo-Echeburúa
32
Official Partner
Leading in Uncertainty : Cyber Resilience Richard Preece
From Human to Hybrid, Rethinking Insider Threats in an AI - Driven World - Findlay White law
Editorial Design lucy@lucyharveyprcomms.co.uk media@cybernewsglobal.com Advertising Events & Partnerships marketing@cybernewsglobal.com claire@consilioevents.co.uk CONTRIBUTORS
Disclaimer: The views and opinions published within editorials and advertisements in Cyber News Global are not those of our editor or company. Whilst we have made every effort to ensure the legitimacy of the content, Cyber News Global cannot accept any responsibility for errors and mistakes.
ADVERTISE WITH US View our media pack at
www.cybernewsglobal.com or scan the QR code
CYBER SECURITY FOR OPERATIONAL RESILIENCE. > INTRODUCING
CYBERPRISM ASSURE An intuitive web application that continuously monitors compliance against any standard — through dedicated questionnaires, a live dashboard and KPIs that keep you audit-ready. Reduced audit fatigue — evidence gathered continuously from the right respondents.
Stronger supply-chain assurance with shared responsibility and clear oversight.
Smarter prioritisation of time and budget from live risk insight.
Track multiple standards at once, without duplicated work.
Real-time visibility and control over your compliance status.
Audit-ready packs that let auditors assess, not chase information.
SCAN TO BOOK A DEMO
cyberprism.net/cyberprism-assure
+44 (0) 1224 451 999 cyberprism.net
SCOTTISH
OT
CYBER SUMMIT
THOMAS MCCARTHY
MARTIN SMITH CB MBE DL
CEO, Cyber News Global & OSP Cyber Academy
Major General (Rtd) Managing Director, Cyberprism
On behalf of OSP Cyber Academy and CyberPrism, we are delighted to welcome you to the
Scottish OT Cyber Summit 2026.
Returning to Aberdeen, the Summit brings together industry leaders, cyber security specialists, operational resilience professionals and key decision-makers to examine the evolving challenges facing operational technology and critical infrastructure. This year marks a decade since the first Scottish OT Cyber Summit. At that event, Major General (Rtd) John Holmes warned of the potential consequences of a major cyberattack on the NHS a warning that would prove strikingly prescient when WannaCry hit the health service the following year. -
Ten years on, the threat landscape has evolved dramatically, but the need for preparedness,
collaboration and decisive leadership has only grown. Building on the conversations that began here a decade ago, this year's Summit will scrutinise the risks, responsibilities and opportunities shaping OT security across the oil and gas sector.
We hope today's discussions challenge established thinking, encourage open and honest debate, and
help turn shared knowledge into stronger operational resilience.
EVENT BY
K OSP CYBER ACADEMY
POWERED BY
CNI TECHNOLOGY PARTNERS
STRATEGIC PARTNERS
PLATINUM SPONSOR
CYBER NEWS GLOBAL
CNG
CYBER
PRISM
TEKGEM
Mattermost
SCOTTISH
AGENDA
OT
OSP CYBER NACADEMY
CYBER SUMMIT
08:00
PRISМ
REGISTRATION
-
WELCOME & INTRODUCTION
09:00 09:10
Thomas McCarthy
09:1009:30
GEOPOLITICAL RISK TO OUR CYBER LANDSCAPЕ
09:30 09:50
SCOTLAND'S CYBER LANDSCAPE
09:50 10:10
CYBER
Major General (Rtd) Martin Smith CB MBE DL
-
Keith McDevitt MBE
-
HOW DOES POLICING IN SCOTLAND FIT INTO THIS COMPLEX CYBER THREAT LANDSCAPE? Detective Chief Superintendent Andy Patrick CASE STUDY
10:10-
10:30
James Mullins
10:30 11:0011:30
11:3012:00
WHEN COMMS GO DOWN
-
-
REFRESHMENT BREAK
REAL LIFE VS. HYPOTHETICAL James Mullins
-
-
LOOKING AT THE REALITY OF A BREACH
Keith McDevitt MBE
-
Andy Patrick
-
Martin Smith CB MBE DL
MACHINE VS. MACHINE: HOW AI IS REWRITING THE RULES OF CYBER WARFARE Matt Smith
-
Dr Ana Rojo-Echeburúa 12:00
13:00 13:15
-
-
Tom Westenberg
-
Findlay Whitelaw
LUNCH BREAK
WELCOME BACK & RECAР
13:1513:30
WELCOME TO TRACK ONE
WELCOME TO TRACK TWO
Crathes Ballroom
Ogston Suite
13:3014:30
CYBER ATTACK OUT-OF-BAND
WHEN ОТ МЕЕTS IT WHAT ARE THE
WORKSHOP
SECURITY CHALLENGES
Richard Preece
-
James Mullins
Simon Rycroft Jessica Amery Keith Chappell Elaine McKechnie -
-
14:45-
15:30
AI VS. ICS: HANDS-ON ATTACK
SUPPLY CHAIN BUY-IN: ACHIEVING SME
SIMULATION WORKSHOР
BEHAVIOURAL CHANGE VOLUNTARILY
Kieran Massey
-
Alan Greig
Tom Westenberg
Kurtis Toy
15:30 16:00
16:45
-
-
-
Joanna Goddard
Rachel Lloyd-Moseley
REFRESHMENT BREAK
OT INCIDENT RESPONSE
A JOINED-UP APPROACH TO
EXERCISE
CYBER RESILIENCE
Craig Kennedy
-
Malcolm Warr OBE
Pete Addison
Richard Preece
16:4517:00
CLOSING REMARKS
Major General (Rtd) Martin Smith CB MBE DL 17:00
-
DRINKS RECEPTION
-
-
Jane Wright
Victor Lough
Kurtis Toy
Martin Smith CB MBE DL
CEO & VCISO, CCOЕ
Major General (Rtd) Managing Director, Cyberprism
CEO, Onca Technologies
During a 33 year military career, Martin headed the military
Kurtis was responsible for the IT information security in an oil servicing company, leading to him becoming Global IT coordinator. He then gained an MSc in Information Technology, next becoming Global IT Team Leader before
contribution to shipping and oil & gas security, modernised the Royal Marines' information and intelligence capability,
commanded multinational counter-piracy operations and was responsible for Britain's amphibious force. Martin left
moving to Onca Technologies full time, which he
the Armed Forces in 2018, becoming CyberPrism's MD in
established in 2016. Further qualifications include GDPR
the Energy, Maritime and Government Sectors.
auditor training and ISO 27001 lead implementor, CISSP.
Foundation and practitioner (DPO), ISO 9001 internal
December 2019, with a remit to expand its operations in
Irene Coyle
Malcolm Warr OBE Chairman,
Chief Operating Officer,
CNI Scotland
OSP Cyber Academy
Irene joined OSP Cyber Academy after a 30-year career in
Malcolm is recognised as an international policy activist on
AUKUS, Maritime and Hi Tech Cyber challenges. He sits on
the police force, including the role of Chief Inspector for recruitment within Police Scotland. During her career in the
various defence and security advisory boards in the UK and
police force, Irene held various roles which centred on
and holds a teaching degree.
Gulf. He focuses on improving Resilience in civic society especially protection of Critical National Infrastructure and in innovative training based on long experience and lessons learned working with Governments, Big Business, Academia and SMEs globally.
protecting people's data, including as Detective Inspector of the Public Protection Unit at Grampian Police. Irene is
in
also a Data Protection Officer, a NCSC Certified trainer
Keith McDevitt MBE
Elaine McKechnie
Cyber Integrator,
Head of Cyber Security Consultancy, i-confidendtial
Following a 32 year career in policing which included leading cyber investigations in 2013 Keith joined the Scottish Government to support the development of cyber
With experience across major financial institutions including HSBC and Virgin Money, Elaine advises organisations on translating cyber and technology risk into clear, prioritised decisions that strengthen resilience and support regulatory requirements. Elaine brings a practical perspective on
ttich Government Scottish
policy and strategy. He currently leads the Scottish
Government's Scottish Cyber Co-ordination Centre (SC3) a
collaborative function supporting combatting the accelerating threat of cyber attack to Scotland.
bridging the gap between IT, OT, cyber risk and executive
decision-making, helping organisations navigate increasingly
complex operational and security challenges.
Andy Patrick
Mattew Smith
Detective Chief Superintendent, Head of Cyber & Fraud Police Scotland
Director of Business Development,
Tekgem
With 28 years in policing, Andy is Police Scotland's lead
Specialising in cybersecurity, OT, and critical infrastructure
resilience, Matthew has extensive experience helping organisations secure and modernise their OT environments.
for Cybercrime and Digital Forensics. Prior to this, he was a Detective Superintendent in Local Crime in Fife responsible
for reactive and proactive crime management and public protection. Andy was also a Detective Superintendent in
He works closely with industrial, organisations to address emerging cyber threats and improve operational resilience.
including 'Category A' homicides across Scotland involving
solutions that enable organisations to operate securely and confidently in an increasingly connected world.
Matthew focuses on delivering practical, risk-based
Major Crime leading high profile, complex investigations
organised criminal groups and firearms.
Jane Wright
Technology & Policy Consultant,
OTEKGEM
James Mullins
Vice President Sales EMEA and APАС,
QinetiQ
Mattermost
With a background in both mathematics and policy, Jane's
Based in London UK with 30+ years selling into international
challenges, boasting a proven track record of a applying
as
technologies. Jane thrives when communicating complex
SS8, Narus (network intelligence), and Equiis Technologies
experience provides a unique perspective on technology
innovative thinking to support transitions to modernised
technical information to and building positive relations with
key stakeholders and government officials, and supporting
government, military and intelligence organisations, as well
financial services, telecommunications, and oil & gas. Prior leadership roles at Ripjar (global threat detection),
deep expertise in security and intelligence technology markets across NATO-allied and Five Eyes nations
-
the implementation of practical new business processes.
Craig Kennedy
Jessica Amery
Head of Cyber Consulting,
Global IT Infrastructure Director, The Weir Group PLC
Craig Kennedy is Partner and Head of Cyber Consulting at national law firm HF Limited. Craig has previously delivered cyber exercises for the world's largest infrastructu
With over 10 years' experience across IT, Jessica is responsible for all Operational Security Services at FTSE
100 member,The Weir Group. Having graduated Abertay
Fraud Specialist, Lead Auditor for ISO27001 and ISO42001 and a Fellow of the Institute of Strategic Risk Management.
underlying focus on threat intelligence.
HF Limited
project and many providers of critical national infrastructure across the energy, transport and finance sectors. Craig is an award winning Accredited Counter
University in 2020 with a first-class honours degree in Ethi Ethical Hacking Jessica has delivered security transformation across global teams and has experience across both offensive and defensive cyber roles, all with an
10
When a Major Cyber Attack Hits, How Do We Communicate?
James Mullins VP, EMEA and APAC Sales at Mattermost
As defenders work to contain the breach, they often disconnect systems themselves to prevent further compromise. Cyber resilience is often measured by how quickly an organisation can recover its systems. But when a major cyber attack strikes, recovery starts much earlier than restoration. It starts with communication. Today ’s attackers understand that encrypting data is only part of the objective. Increasingly, they aim to disrupt an organisation’s ability to coordinate its response. Directory services are targeted. Collaboration platforms are disabled. Networks are isolated to contain the attack. Within minutes, organisations can find themselves unable to answer the most basic operational question: How do we communicate? “If your main company network goes dark, your out-of-band communications should keep you in the light.” This communications blackout is rarely accidental. It is a deliberate part of modern attack strategy.
Cyber News Global
The result is an operational environment where security teams, executives, legal counsel, communications teams and external partners are all trying to manage a rapidly evolving crisis without a trusted means of sharing information. The Fog of Cyber War Military leaders have long understood the concept of the “fog of war” – the uncertainty that exists when reliable information is unavailable. The same principle increasingly applies during a major cyber incident. Under normal c ircumstanc e s , leadership teams receive structured updates, assess the facts and make informed decisions. During a cyber attack, those information flows can disappear entirely. Without trusted communications, leaders struggle to establish what has happened, what systems remain operational, who is affected, or what actions should be prioritised.
The result is often one of two dangerous outcomes: rushed decisions based on incomplete information, or decision paralysis while waiting for certainty that may never come. Both work in the attacker’s favour.
When a Major Cyber Attack... 11
Frameworks such as NIS2 expect organisations to notify regulators of significant incidents within strict reporting windows, often between 24 and 72 hours. Those obligations do not disappear because internal email, collaboration tools or corporate networks are unavailable. Organisations must still establish the facts, coordinate response teams, document decisions and communicate with regulators, customers and partners. Without a secure communications capability, meeting those obligations becomes significantly more difficult. The Consumer Messaging Trap
Why Out-of-Band Communications Matter This is why many organisations are now incorporating dedicated out-ofband communications into their cyber resilience strategies. An out-of-band capability operates independently of the primary corporate network. It is pre-configured, secure and available when core business systems have been taken offline or intentionally isolated. Rather than scrambling to establish communications during a crisis, organisations can immediately coordinate incident response, share verified information, assign tasks and maintain executive oversight using a trusted platform that remains operational throughout the incident. The objective is simple: ensure that the organisation can continue to make informed decisions when its primary communications infrastructure cannot. Compliance Doesn’t Pause During an Attack Maintaining communications is not simply an operational necessity. It is increasingly a regulatory requirement.
Preparing Before the Crisis Effective cyber resilience is about more than preventing attacks. It is about ensuring the organisation can continue to operate when prevention fails. Planning for secure communications before an incident occurs allows organisations to coordinate response efforts, support leadership decisionmaking, satisfy regulatory obligations and reduce the operational disruption caused by an attack. In an environment where cyber incidents are increasingly viewed as a matter of when rather than if, the organisations that recover fastest will not necessarily be those with the strongest perimeter defences.
One of the most common mistakes organisations make during a cyber They will be the organisations that can incident is turning to consumer still communicate when everything messaging applications as else has gone quiet. Sensitive an emergency alternative. corporate If you are reviewing your information While these platforms organis ation’s c y b er may be shared may restore basic resilience or out-of-band through unmanaged communication, they communications strategy, environments. Audit can also introduce new visit mattermost.com trails may be risks. to learn more or reach out to incomplete. our team. Chain of custody can be lost. Regulatory obligations surrounding governance, record keeping and evidential integrity become much harder to demonstrate. In attempting to solve one problem, organisations may inadvertently create another. ”The regulator doesn’t care if your email is down. They still expect you to report, communicate securely and remain compliant.”
To listen to James Mullins interview with Lets Talk Cyber:
Scan Me
CYBER SECURITY SOLUTIONS
BUILT AROUND YOUR WORLD
SCAN TO FIND OUT MORE
SAPPHIRE.NET INFO@SAPPHIRE.NET
OT RISK ASSESSMENT REGULATORY GAP ANALYSIS OT CYBER TRAINING IT/OT INCIDENT RESPONSE IT/OT SOC
0845 58 27001
CO i-confidential
Building Trust,
Reducing Risk.
Assess
Strengthen
Execute
Optimise
Unlocking value, reducing risk and building resilience across your business. We help organisations like yours navigate today's complex cyber risk landscape with confidence. Our services are designed to assess, strengthen, execute and
optimise your risk management capabilities so you can focus on what matters most
-
growing your business securely.
Scan the QR Code to learn more.
14
Your Cyber Controls Are Becoming Board Evidence
In financial services, the next cyber incident will test who knew, what worked, what failed and whether the firm can replay control.
A cyber incident no longer ends with containment. The next question will come from the board and the regulator: can you prove who knew, what worked, what failed and why the firm was still in control?That is where the CISO mandate is moving. Cyber controls are becoming evidence of management accountability. The CISO who owns that evidence chain will shape the 2027 control budget.
Call-out: Regulation is the scoreboard when real cyber fails. Financial services sits at the front of this shift because the sector already operates inside a dense accountability model. Regulators expect firms to manage the fine-grained business impact of technology failure, cyber incidents, supplier disruption, AI adoption and data weakness. DORA is live. UK operational resilience and incident reporting expectations are tightening. The EU AI Act is moving into its main application phase. Critical third-party oversight is pulling cloud, infrastructure and technology providers closer to the supervisory perimeter. For CISOs, the signal is clear. Cyber controls are becoming evidence of the business conduct which the board owns. That evidence needs to answer practical questions. Which business services were exposed? Which applications support them? Which suppliers and cloud platforms sit underneath them? Which data feeds are critical? Which logs prove what happened? Who owned the decision? Could the firm recover within tolerance? Could it replay how AI was used?
Call-out: Cyber controls are now evidence of management accountability. Cyber News Global
This means that the familiar cyber perimeter is expanding into the regulated operating model. Data is capital because financial institutions are judged through the quality, lineage and integrity of their information. Failure can mean higher capital charges, remediation costs and conduct fines. Compute is trust because AI, automation and cloud now support regulated workflows. If models, agents, scripts or infrastructure affect the business, firms need to know what ran, what data it touched, what decision it supported and who approved it. Sovereignty is control because critical services depend on data, compute, privileged access, backups, logs, vendors and recovery routes across jurisdictions. If a firm cannot prove where control runs, who owns it and how recovery works under stress, the boundary is unprovable. This is where the CISO becomes central. Identity, access, logging, monitoring, resilience testing, cloud control, supplier assurance and incident workflow are core security capabilities. They are also the evidence infrastructure the business will rely on when supervisors ask for proof. The CISO’s opportunity is larger than more cyber spend. The prize is a bigger control mandate.Many firms are planning 2027 budgets around separate fixes:
reporting remediation, AI governance, operational resilience, third-party risk, control assurance and data quality. That approach creates duplicated cost and weak evidence. The better path is to build shared control patterns into infrastructure that operates globally, complies locally and proves continuously. Identity controls can support cyber defence, AI governance and supplier access. Logging can support security monitoring, incident replay, model oversight and operational resilience. Cloud and data controls can support sovereignty, continuity, reporting and third-party assurance. Supplier controls can support resilience, cyber risk, exit planning and regulated outsourcing. The goal: infrastructure that connects regulatory obligation to runtime control and evidence. Call-out: Build shared control patterns, not parallel fixes. That gives CISOs a stronger voice with the CIO, COO, CRO, Head of Data, Operations, Legal and Compliance. The CISO sees how controls behave under pressure. The business needs that knowledge to discharge the board’s responsibilities, prove compliance to regulators, fund the right architecture and avoid fragmented compliance machinery. GenAI makes this urgent.Firms already know the problem of shadow IT and shadow data. Shadow AI is harder to detect. People can plug tools into workflows, summarise documents, generate code, query data, automate tasks and support decisions before ownership, monitoring and evidence have caught up. That creates cyber, data, conduct, legal and supervisory exposure. Who approved the tool? What data did it access? Was confidential information exposed? Was the output used in a controlled process? Could the decision be reproduced? Did the human remain accountable? Did the control owner know the workflow had changed? Call-out: Shadow AI turns operational efficiency into enterprise exposure.
Your Cyber Control Are ... 15
CISOs should be in that room because they understand the reality of control under stress. They own many of the levers that turn regulatory obligations into operational proof. The RegRisk Control Forum on 15 October in London brings senior financial services control owners together to work through three connected pressures: regulatory reporting control, AI governance and sovereign boundary protection.
Fig: 15 October RegRisk Control Forum agenda overview
AI governance needs to connect to cyber control, access management, data lineage, evidence preservation and operational resilience. Weak definitions, black-box controls and missing lineage are becoming control failures. This is AI control debt: new capability layered onto legacy workflows, fragmented data and manual controls before the firm has agreed who owns the outcome, what evidence is needed and what should be funded first. The control test is simple: explain, evidence, replay. After an incident, a board pack carries little weight without evidence that matches operational reality.
The firm needs to show which services were affected, which suppliers were involved, which data was compromised, what AI tools were active, which controls fired, which failed, which decisions were taken and who had authority.When the evidence chain breaks, the firm faces more than a cyber incident. It faces a control failure. Call-out: No replay, no defence. The 2027 control room is forming now.Financial institutions are deciding how to fund resilience, AI governance, regulatory reporting control, data lineage, sovereign boundary protection, thirdparty oversight and cyber assurance.
The message to CISOs is direct. You already do real cyber. The next test is whether the firm can prove control. Call-out: Join your colleagues in the 2027 control room.
Regulation is the scoreboard when real cyber fails. The CISO should be in the 2027 control room. For a complementary financial institution place at this Chatham House event, contact Corrina Stokes at Corrina@regrisksolutions.com
Building stronger cyber resilience for UK policing, business and SME supply chains The National Ambassador Programme Enabling SME Resilience in supply chains
Cyber PATH
Expertise
Workplace-ready talent development
Supporting 9 police-led Cyber Resilience Centres
®
THE
CYBER RESILIENCE CENTRE NETWORK
®
THE
CYBER RESILIENCE CENTRE
®
NETWORK
THE
CYBER RESILIENCE CENTRE FOR THE NORTH WEST
®
THE
CYBER RESILIENCE CENTRE Lorem ipsum
FOR THE NORTH EAST YORKSHIRE I THE HUMBER
®
THE
®
®
CYBER RESILIENCE CENTRE THE
FOR THE EAST MIDLANDS
CYBER RESILIENCE CENTRE ®
THE
CYBER RESILIENCE CENTRE
FOR THE SOUTH EAST
FOR THE EAST
®
®
THE
CYBER RESILIENCE CENTRE FOR THE SOUTH WEST
®
THE
CYBER RESILIENCE CENTRE FOR LONDON
THE
CYBER RESILIENCE CENTRE FOR THE SOUTH EAST
Creating a safer place to work enquiries@nationalcrcgroup.co.uk
nationalcrcgroup.co.uk
RegRisk Control Forum: Passing The 2027 Test Strategic Decisions. Stronger Controls. Future Ready. A focused forum for senior leaders to align, decide, and act on what matters for 2027.
15 October 2026 12pm - 6pm Please email Corrina@regrisksolutions.com London EC3M
Join us | www.regrisksolution.com
18
PROTECTING OPERATIONAL TECHNOLOGY – AN INDUSTRY VIEW Martin Smith, MD of CyberPrism, looks at the issues facing industry in securing its OT. World events such as the war in Ukraine and its associated threats to energy supply, and increased conflict in and around Iran, have concentrated minds on industrial security as the Global situation becomes less stable, and the boundary between state intervention and criminality becomes increasingly blurred; not least because states are using organised crime groups as proxies and, conversely, cyber criminals are using state activity as cover for their criminal activities. The Energy Sector in particular looks like a prime target, but it is the indiscriminate nature of many forms of malware which is perhaps most worrying: there is no need to be targeted in order to become a victim and many successful attacks can be seen as a form of collateral damage which was never envisaged by the initiator. Moreover, the cyber weapons in use at State level tend not to respect geopolitical borders. These forms of malware can be seen as hybrids of weapons and contagions – analogous to biological warfare in some ways, and malicious code is widely available in ingredient form, ready for use by humans or AI. Indeed, it is likely that Mythos will escape or be stolen at some point. Cyber News Global
The huge potential for ransom, extorsion and economic disruption is exercising Governments as never before, but this is now seen in the context of State versus State competition, with the potential to spill over into new conflicts as the situation becomes less amenable to control by ‘traditional’ diplomatic and geopolitical means. The debate is now around national resilience, not just financial loss; and survivability, not just resilience. But what are companies doing about this? What are we seeing as industry, and the Energy Sector in particular, tries to adapt to a changing threat landscape; and what is, or should be, the role of Government? In the UK, our Government is grappling with ‘survivability’ as a concept. Verticallyintegrated models see ‘Minimum Viable Companies’ within CNI operating at basic levels and providing essential services even under concerted attack. These companies can be aggregated into a ‘Minimum Viable UK’, which is able to maintain security and services for its people.
A more horizontal view would suggest that we see resilience too narrowly: cyber security has focussed on protection of data rather than the continuation of processes and process control; and the other facets of security, such as physical protection, are poorly-aligned, if not somewhat stovepiped. New legislation, such as the Cyber Security and Resilience Act, can help drive resilience, but will add extra regulatory requirements, which must be managed. We need a more holistic concept of security, resilience and survivability. Of course, we should understand that we are dealing with commercial entities here. Companies exist to create value and sit within complex ecosystems, with multiple threats and a host of conflicting drivers. Government entities are subject to many of the same pressures. Crucially, modern supply chain efficiency and ‘justenough-just-in-time’ logistics have reduced redundancy to dangerous levels, but they have also made us more competitive in a business sense. ‘Single points of failure’ in the supply chain, such as the reduction in the number of component manufacturers reducing our ability to spread cyber risk, abound.
Protecting OT - An Industry view 19 Quantifying the risk and consequences of attack, and the benefits of security investment in terms of value and ROI, is difficult. Perhaps the most obvious driver is the operational cost inherent in increased ‘downtime’ due to cyber-attack; but many industries are still on the road to truly data-driven operations, may be subject to other factors such as weather in offshore operations, and significant downtime is often seen as a fact of life. Reputation, and the consequences for share price, would be another significant driver, but it is really where this starts to overlap with some form of licence to operate, backed by Government regulation and enforcement, that we are seeing most traction for what can otherwise seem to be an intangible issue. Add in safety and the environment, as seen in the Health and Safety Executive’s enforcement of the Network and Information Systems Regulation in the UK Energy Sector, and we move to a much more tangible imperative. So, given increasingly effective industry drivers, what are the issues? We tend to see cyber security as a technical activity, but the first issue we encounter in most situations is governance. Put simply, who is responsible for OT security? It may be that the IT Department has ended up with the lead – either explicitly or by association. Alternatively, the integrator or OEM might be assumed to have this role, or perhaps it is Operations or Engineering. Sometimes different elements have responsibility for different OT networks at a single site – a difficult situation for the Duty Holder to manage, especially where the supply chain introduces extra vulnerabilities. Either way, we would suggest that clarity of roles and responsibilities – is a necessary precursor to technical intervention, and must communicate effectively with other disciplines if we are to avoid the ‘stovepiping’ noted above.
How to move forward against this difficult backdrop? Well, wicked problems must be addressed by teams, not individuals. In this case, the team must include operators, license holders, cyber security companies, integrators and the supply chain – to name but a few. Our military background tells us that the most important element in any team is trust, so that is where we must start. Building trust won’t be easy in an attractive industry with many new entrants at various levels of competence, but it is essential if we are to make progress against increasing threats.
Major General (Rtd) Martin Smith CB MBE DL Managing Director Cyberprism
However, even given the right relationships, Industry doesn’t have enough qualified people and simply increasing the training pipeline won’t generate the right level of experience.
This is where technology has to come in. Processes such as asset discovery, segregation, alert response, compliance tracking and training need to be increasingly automated: not taking the humans out of the loop, but putting them in control. Trust will be a factor again here – interventions in OT networks must be safe and there is too much loose talk of AI. Legacy systems will need particular attention, especially those that can no longer be patched effectively. As a technology-enabled consultancy and service provider for OT security, fusing deep technical knowledge with an instinctive understanding of security born of our military heritage, we seek to integrate technology and services into existing infrastructure more cost-effectively than most clients could achieve on their own. We keep their critical processes operating, resilient and safe, increase asset availability, and leverage trusted data to support the fine-tuning of operations and improved decision-making. Perhaps the most immediate issue that our clients face is the need to track their cyber security improvements against multiple, overlapping compliance frameworks: we are automating this process, providing near-real-time visibility of compliance with multiple, complex regulatory requirements whilst reducing management overhead. We live in interesting times and the challenges we face are not getting any easier, but addressing survivability is now an imperative and I have confidence in our ability to adapt to a more adversarial environment whilst continuing to prosper.
20
SCOTLAND’S AI STRATEGY 2026 - 2031
A Leadership Guide for Adopting Scotland’s National AI Strategy This executive summary details Scotland’s AI Strategy 2026-2031 into the essential considerations that leaders across business, public services and academia must understand and act upon. Scotland’s ambition is clear: to harness the potential of AI to drive responsible and inclusive growth across our economy and make a positive difference at every level of society. Why Leaders Must Act Now Scotland has helped to shape the modern world. For a small country on the edge of Europe, we have long been at the centre of innovation and new inventions. Cyber News Global
We have a proud history of leading scientific and technological change and our ideas, nurtured to enlightenment by our leading universities and colleges, have revolutionised whole schools of thought leading to breakthroughs in fields as diverse as philosophy, photography and physics. Now, Artificial Intelligence (or AI) presents an opportunity for Scotland to rekindle that pioneering spirit, to lead instead of follow and, by doing so, to harness AI’s potential for responsible, transformative economic growth. “
AI is the great disruptor, re-shaping industries through the power of machine learning – but, as Scots, we have always been comfortable on frontiers.” Secure the benefits of AI for everyone in Scotland. That means boosting our economy, closing the productivity gap and driving innovation while also supporting improvement to our health and education outcomes and increasing the efficiency and quality of our public services.
Scotland’s Ai Strategy...
At the same time, we must recognise the wider risks and uncertainties that come with the rapid evolution of AI. People are rightly concerned about transparency, fairness, the impact on jobs and the accelerating pace of change. Scotland’s response is to address these issues openly and responsibly, demonstrating that progress and safeguards can go hand in hand. Above all, our approach to AI must be firmly rooted in our values and guided by the Scottish Government’s commitment to Fair Work. Scotland’s Unique AI Strengths: What Leaders Must Leverage Leaders adopting this strategy must understand the exceptional foundations Scotland already possesses. These are not aspirational for they are live, competitive assets that underpin the entire strategy.
21
World-Leading AI Pioneers
World-Leading AI Research
Scotland’s long association with visionary leaders in AI from Geoffrey Hinton (Nobel Prize, 2024) to Amanda Askell (co-author of GPT3) demonstrates the strength of our academic and research institutions and their ability to attract the finest minds.
Five Scottish universities were placed in the UK’s top 30 for AI research output in 2025. Edinburgh hosts ARCHER2, the UK’s national supercomputer, and will host the new £750 million UK National Supercomputing Centre. The National Robotarium at Heriot-Watt is driving breakthroughs in medical and offshore robotics.
22
Renewable Energy Advantage In 2024 alone, Scotland produced 38.4 TWh of renewable electricity the highest annual total ever recorded, a 13.2% increase on the year before. There is 26.4 GW of new renewable capacity in planning or consented pipelines, one of the largest in Europe relative to population. Business Investment
Leadership
&
Scotland is home to an estimated 296 AI-focused companies. The first AI Growth Zone in North Lanarkshire is backed by over £8 billion of private investment and is set to deliver more than 3,400 new jobs. A £15 billion AI Pathfinder Investment in North Ayrshire will create one of Europe’s most significant AI infrastructure developments. The Strategic Imperative: Why Leaders Cannot Wait. Artificial intelligence is advancing rapidly and offers enormous economic potential. Leaders must internalise the urgency of this moment. Economic Opportunity Rapid developments in agentic and autonomous AI show how quickly new capabilities are emerging. Adoption remains uneven and Scotland must act to close the gap.
Cyber News Global
Scotland’s Ai Strategy... 23
Public Services Pressure Demand for public services is rising amid tightening public finances. AI has already shown promise in enabling preventative approaches, improving planning, reducing costs and supporting frontline decision-making. Data Governance Scotland’s public sector data is often fragmented and difficult to access. Improving data sharing and governance is essential to support safer, more effective services and research.
Global Competition A worldwide innovation race is underway. Emerging international standards including the OECD AI principles and the EU AI Act are shaping expectations of fairness, transparency and safety. Scotland must act now to ensure that AI is introduced in ways that are safe, fair and focused on public benefit. This Strategy sets out how Scotland will do this, harnessing the potential of responsible AI to improve outcomes across our economy and at every level in our society.
The Four Outcomes Leaders Must Deliver By 2031 The Scottish Government has defined a clear and ambitious purpose for this Strategy: to harness the potential of AI to drive responsible and inclusive growth across our economy and make a positive difference at every level of society. Leaders must orient their organisations around four outcome areas.
24
Own Your AI
Is AI taking over the World, a podcast with Dr. Ana Rojo-Echeburúa
Cyber News Global recently had the opportunity to speak to Dr. Ana Rojo-Echeburúa exclusively on Let’s Talk Cyber, the question was simple, “Is AI taking over the world? The answer was yes and no, which I know is the most frustrating thing a guest can possibly say! So let's unpack it properly. AI is not new. The way we talk to it is. There is a widespread belief that AI arrived the day ChatGPT did. But it did not. We have had AI in one form or another for more than forty years. I have been working in the field for about ten of those, first as a data scientist, then as an AI engineer, a team lead, a founder, a consultant, an educator... and now as Head of AI at DataVita, where we build sovereign UK infrastructure in Scotland. In all that time the thing that actually changed in the last couple of years was not the existence of AI. It was the way we interact with it. Large language models (and let’s not forget small language models) gave us a way to talk to technology in plain language. That change in accessibility is the real story. It is not that machines suddenly became intelligent overnight. What happened is that the front door got a lot wider, and anyone could walk through it. The golden era we quietly took for granted This accessibility arrived with something most of us never stopped to question: frontier models that were cheap, powerful, and available whenever we wanted them. We built products on top of that assumption. We implemented internal processes around it. We treated it as the natural order of things. But the truth is, it was not. It was a golden era, and golden eras end.
Cyber News Global
Is AI taking over the world... 25
The recent disruption around access to Anthropic’s most advanced models was a wake-up call for a lot of people. It made something concrete that many had never seriously considered: the model you depend on today may simply not be available to you tomorrow. So when people ask whether AI is taking over the world, my view is that AI itself is not the thing to watch. The infrastructure underneath it is changing and the laws around it are changing too, and most organisations are nowhere near ready for that. The real danger is not the technology Which brings me to the question I find far more interesting than world domination: what should we actually be worried about? People usually expect me to say something about rogue machines or jobs disappearing. Those are valid concerns but my answer is more ordinary and more urgent. AI is a field. Saying AI is dangerous is a bit like saying that mathematics is dangerous, or that physics is dangerous. It cannot deploy itself. The danger lives entirely in how we choose to use it. The most common failure (and danger) I see is organisations putting AI to work with no governance around it at all. No securit y built in, no understanding of the specific risks a given tool introduces, no mitigation strategy for the moment something goes wrong, no accountability... That is the genuinely dangerous thing, and it is happening everywhere right now, precisely because so many people are under pressure to move faster so AI gets reached for as a quick workaround.
There is a second failure that is just as expensive: not understanding what AI actually is. The field is enormous, and different problems call for genuinely different solutions. A great deal of money is being wasted because people reach for the wrong tool, the wrong model, usually the most famous one, for a problem it was never designed to solve. Mapping the right solution to the right problem is half the job, and you cannot do it if your mental map only has two or three landmarks on it. I speak to capable, senior people who genuinely believe the only models that exist are the ones offered by OpenAI and Anthropic. Mention open source models and you often get a blank look. This gap in knowledge is not harmless unfortunately and it is quietly defining real strategic decisions, and not for the better. A lot of the overdependence on frontier models comes down to people simply not knowing that alternatives exist. Owning the right solution starts with knowing what is out there in the first place and being able to assess its suitability. Governance is the first pillar, not the last So where does governance sit in all of this? For me it is not a layer you bolt on at the end to keep the auditors happy. It is the first layer. It is the main pillar holding everything else up. If you build an AI strategy without governance underneath it, you have set yourself up for failure. One. Hundred. Percent. I do not say that to be dramatic, I have watched it happen way too many times. Governance is what let's you move quickly and safely at the same time, because it tells you what you are allowed to do, what the risks are, and what to do when those risks actually. If you skip it, every clever thing you build is sitting on sand.
So, own your AI If I had to compress everything into a single takeaway, it would be three words: own your AI. Sovereign AI is no longer a nice idea for a policy paper. It is a smart strategic decision. Owning your AI means understanding the full spectrum of what is available rather than defaulting to whatever is most trendy. It means building governance in from the very start rather than retrofitting it once you are in trouble. And it means not being wholly dependent on infrastructure you do not control and cannot guarantee. None of this is a reason to be afraid of AI. I have spent more than a decade in this field and I am as excited about it as I have ever been. But excitement and discipline are not opposites. In fact, I love when they coexist together. The organisations that will do well are the ones who understand what they are using, why they are using it, and what happens if it disappears one day. They are the ones who are prepared now for what can happen in the future. The are the ones that own their AI. Instagram (Podcast): https:// www.instagram.com/ theaiframepodcast Instagram (Personal): https:// www.instagram.com/arojomaths LinkedIn: https://www.linkedin. com/in/ana-rojo-echeburua Website: https://wwwanarojoe cheburua.com Youtube: https://www.youtube. com/@theaiframepodcast Spotify:https://open.spotify.com/ show/5amoMjTLYIIhnsrRR3PYXx X:https://www.x.com/arojomaths
EVERYONE HAS A PLAN UNTIL THEY GET PUNCHED IN THE FACE. Test your incident response plan with a CYBER CRISIS
SIMULATION and uncover the
gaps, missteps and blind spots your playbook misses before reality strikes.
SCAN FOR MORE DETAILS OT SECURITY TABLETOP EXERCISE (TTX)
O T I F Y D
https://otifyd.com/services/industrial-security-ttx/
SAFEGUARDING OT NETWORKS
BEFORE WE ASSESS YOUR CYBERSECURITY RISK, WE UNDERSTAND YOUR OPERATIONS. OT security risk assessments and penetration tests delivered by engineers who understand how plants run.
SCAN FOR MORE DETAILS
https://otifyd.com/services/risk-assessment/ https://otifyd.com/services/penetration-testing/
O T I F Y D SAFEGUARDING OT NETWORKS
CYBER
TIME REMAINING
ATTACK
24:59
SYSTEM BREACH DETECTED SYSTEMS AT RISK •
MINUTES
FINANCIAL DATA
SECONDS
INTELLECTUAL PROPERTY
OPERATIONAL SYSTEMS
UNAUTHORIZED ACCESS IN PROGRESS
When the pressure hits, seconds matter.
Have you prepared your leaders to react
WORKSHOР
SHOP
WORK
RESILIENCE
or
lead?
CYBER RISK ANERESILIENCE WORKSHOP
ENCE
*
OSP CYBER ACADEMY
EN
RISK & RESILI
ER CYBER
CYB
-
OSP CYBER ACADEMY
A focused two-hour workshop for senior leaders Adapted from our NCSC-assured Cyber Risk & Resilience Board Course, this workshop cuts through the jargon focusing on leadership, governance and action.
mi
00000
UNDERSTAND
PREPARE FOR
TAKE
THE RISK
WHEN, NOT IF
ACTION
See why cyber resilience and is a business issue
Test your decisions
Leave with a practical
through a realisitic cyber
how Al will amplify it.
12 week cyber resiliencе
incident scenario.
action plan.
-
Don't wait for a cyber crisis to test your leadership Book your defensive workshop by scanning the QR code or
OSP CYBER ACADEMY
email training@ospcyberacademy.com ssured Service Prov in association with
National Cyber
Security Centre Training Course
APMG
International
mark of the APM Group Imited. The APMG internatonal and swil device logo is a trade Limited.All rights reserved.
SCAN HERE
28
29
OSP CYBER ACADEMY
VE
&
ВЕ СҮ
EN E S S
ASSURE
R
CE D N E I L I S RE
R CE RESILIEN BOA S&K BOARD S I
AWA
TI U C E CYBER EX
Cyber Risk and Resilience Course for Board, Executive and Senior Managers
TRAINING
ASSURED TRAINING
This course provides delegates with the opportunity to explore and
discuss cyber risk and resilience and how to provide effective governance, risk management and
strategic implementation.
Aimed at Board members including Executive Officers, this course is for those who need to provide governance and implement strategy
for cyber risk, including data protection and resilience.
Delivered by: Richard Preece, Chief Training Officer OSP Cyber Academy A co-opted core panel member of the British Standard (BS) 31111 Cyber Risk and
Resilience Guidance for Boards and Executive Management.
A chapter author for Managing Cybersecurity Risk - How Directors & Corporate Officers can protect their businesses. To reserve your place
-
contact training@ospcyberacademy.com - or scan QR Code
Assured Service Provider
in association with
National Cyber
Security Centre Training Course
APMG
International
Are your cyber defences
Fit for Purpose? Sooner or later, you will let malware in. They only need to get it right ONCE.
Zero-trust Security Software
Penetration Testing
In-person & Online Team Training
to prevent this from happening.
Expert services that you can trust created by the sector, for the sector. Protect your local community today
Visit our website and contact us for more information.
www.ccoe.org.uk
32
FROM HUMAN TO HYBRID RETHINKING INSIDER THREATS IN AN AI-DRIVEN WORLD
The insider threat landscape is u n d e rg o i n g a p ro f o u n d transformation. Traditionally, security professionals defined insiders as employees, contractors or trusted third parties (humans operating within organisational boundaries). Today, that definition is under pressure from an entirely new category of actor: AI agents, nonhuman identities, autonomous systems and machine-driven decision-making processes that increasingly operate within those same trusted environments. The question isn’t whether an employee poses a risk. It is whether our traditional security models are still fit for purpose in a world where trust is extended to entities that are not human. The honest answer, as the industry is beginning to confront, is probably not. Cyber News Global
Malicious intent is not the defining characteristic of an insider threat. What defines an insider is position: legitimate access, trust or authority within an environment. That definition now applies to machines.
Findlay Whitelaw Field CISO at Exabeam Security Researcher & Strategist
The Misconception at the Heart of Insider Risk When most people hear the phrase “insider threat,” they picture a disgruntled employee, someone stealing data or sabotaging systems out of grievance. That image is not only outdated, but also actively misleading. Insider risk encompasses negligent behaviour, compromised accounts, excessive privileges, third-party access, accidental data exposure and, increasingly, AI-enabled actions.
AI as Amplifier and as Actor Artificial intelligence is changing the insider threat landscape in two distinct ways. First, it is amplifying human insider threats. Individuals can now generate convincing phishing emails, create deepfakes, automate reconnaissance, summarise sensitive documents and write code with a speed and quality previously beyond them. AI acts as a force multiplier for human actors, making both malicious and negligent insiders considerably more dangerous. Second, and more fundamentally, AI is emerging as an operational actor inside organisations in its own right.
From human to hybrid... 33
AI agents are now accessing systems, retrieving data, making recommendations and executing tasks autonomously. These systems possess identities, permissions and decision-making authority. When an AI agent has access, autonomy and influence, all the defining characteristics of an insider, it is reasonable to ask whether it should be treated as one. In many environments, the answer is already yes. Accountabilit y Cannot Be Delegated to the Machine The emergence of AI agents raises an urgent governance question: if an AI system can act within an organisation, who is responsible for what it does? The answer is clear: accountability must remain human. Technology itself cannot be accountable. Organisations need to treat AI agents with the same rigour they would apply to a new employee. Every AI system should have a named owner, defined responsibilities, appropriate and limited permissions, and continuous oversight and monitoring. If a new human hire were given access to sensitive systems, security teams would know who recruited them, who manages them and what they are authorised to do. Those same principles must apply to AI.
1. Gain visibility. You cannot govern what you cannot see. The first step is understanding where AI is already being used across the organisation, including shadow AI deployments that have not gone through formal approval. 2. Establish governance before scaling. AI adoption without governance framework s is something organisations cannot risk. Policy, accountability structures and oversight mechanisms must be in place before AI deployments are expanded. 3. Treat AI identities like humans Agentic AI systems must managed like humans with identity and access management frameworks. Using the same disciplines (least privilege, role-based access, regular review) apply equally to AI agents. 4. Invest in behavioural monitoring. Most future incidents will not occur because a bad actor lacked access. They will occur because a trusted identity, human or machine, used legitimate access in an unexpected way.
The challenge is that many organisations are deploying AI faster than they are implementing the governance to control it. Paradoxically, organisations often know more about their human workforce than about the AI systems now operating within their environments.
Organisations that understand not just who and what is in their environment, but how those entities behave, will be best placed to detect and respond. AI Governance is Everyone’s Responsibility One of the most important cultural shifts the industry needs to make is recognising that AI governance is not solely the domain of the CISO. It cuts across every function in an organisation. The basic hygiene questions include do you have an AI policy? Are staff trained on safe AI use? Do they understand the risks as well as the benefits? All of which are questions for HR, legal, operations and leadership, not just security teams. There remains a significant gap in understanding, not only about what AI is, but about how to use it safely and how to govern it effectively. Closing that gap is a collective organisational responsibility. When most people hear the phrase “insider threat,” they picture a disgruntled employee, someone stealing data or sabotaging systems out of grievance.
10100101100010001010
Four Priorities for Organisations Preparing for the AI Era
1101001011
10100101110
For organisations seeking to get ahead of this challenge, four priorities stand out:
SCAN HERE
To listen to Findlay Whitelaw interview with Lets Talk Cyber:
DARK WEB MONITORING
ONCA DATA BREACH DETECTING TAILORED THREAT INTELLIGENCE
ONCA DIGITAL RISK PROTECTION SERVICES
We monitor for threats and data breaches outside your network on the surface, deep, and dark web and tailor alerts to your needs.
ONCA DRP HELPS TO MITIGATE AGAINST: Brand Impersonation
Email Compromise
Fraud
Unauthorised Access
Phishing
Supply Chain Attacks
HELPING COMPLIANCE AND IMPROVING CYBER MATURITY Illicit activity on the dark web can pose a threat to your business operations and revenues. Monitoring the dark web can be dangerous, time-consuming, and requires specialist skills. To avoid putting security staff and networks at risk, adopt our fully managed Digital Risk Protection Service so that you can continue with busines as usual. ONCA TECHNOLOGIES | DIGITAL RISK PROTECTION SERVICES
36
Cyber AI - Rise of the Machines
Ian gemski CEO, TEKGEM
Attackers can use AI to accelerate reconnaissance, identify vulnerabilities, generate malicious code and automate research activities. The result is a growing industrialisation of cyberattacks, where sophisticated techniques become accessible to a much wider range of threat actors. Until recently, AI primarily acted as a force multiplier for human attackers rather than replacing them. Across industrial environments, AI is helping engineers troubleshoot problems, analyse operational data and improve decision-making. CNG recently caught up with Ian Gemski, CEO of TekGem, to discuss how Artificial Intelligence is changing the Operational Technology (OT) cyber security landscape. His message was clear: AI is creating significant opportunities for industry, but it is also changing the rules of cyber warfare. Artificial Intelligence has rapidly moved beyond chatbots and office productivity tools. Cyber News Global
The challenge is that the same technology improving productivity is also reducing one of the biggest barriers attackers have historically faced: expertise. For many years, successfully targeting OT environments required specialist knowledge of industrial protocols, engineering processes and control systems. Acquiring that knowledge took significant time and experience, naturally limiting the number of capable attackers. Today, AI can provide much of that knowledge on demand.
However, emerging developments suggest we may be entering a new phase where autonomous AI agents can independently identify vulnerabilities, make decisions and execute cyber operations with limited human direction. The immediate threat remains people using AI, but increasingly autonomous offensive capabilities are no longer purely theoretical The Real Target Isn’t the PLC – It’s the Engineer When industrial organisations think about cyber-attacks, they often focus on protecting PLCs, DCS platforms and Safety Instrumented Systems. video can now convincingly imitate
Cyber AI - Rise of the ... 37
In reality, the most attractive target is usually the human operating those systems. The biggest vulnerability in any organisation remains trust. AI is making phishing attacks, impersonation attempts and social engineering campaigns significantly more convincing. Attackers can analyse publicly available information, map organisational structures and create messages that appear completely legitimate. More concerning is the rapid rise of deepfake technology. AI-generated audio and video can now convincingly imitate trusted colleagues, suppliers or managers, making it increasingly difficult to distinguish genuine communications from malicious ones. The future battlefield isn’t just machine versus machine, it is trust versus deception, and AI is making deception more effective than ever before. “ The biggest vulnerability in any organisation remains the human vulnerability, and AI is making deception harder to detect than ever before.” — Ian Gemski, CEO, TekGem AI Can Strengthen Defences Too The good news is that the same technologies being weaponised by attackers are also being integrated into defensive security platforms. Organisations should be looking closely at the AI capabilities already available within their security tooling to improve threat detection, incident response and security monitoring. However, AI is not a silver bullet. The organisations that remain resilient will continue to focus on fundamentals: • Strong identity and access management • Effective network segmentation • Secure remote access • Rigorous change control • Continuous security monitoring Frameworks such as IEC 62443 remain particularly valuable because they focus on resilience rather than defending against a single threat. As AI-driven attacks continue to evolve, organisations with strong governance and security foundations will be best positioned to respond.
The Hidden Risk: Engineers Using AI There is another AI risk that receives far less attention. Engineers are increasingly using AI tools to help solve operational and technical problems. While this can improve productivity, it can also create unintended security risks if sensitive plant information is shared with publicly accessible AI models. Configuration files, troubleshooting logs, process data, network diagrams and engineering documentation may all contain information that organisations would never intentionally disclose externally. Once uploaded to an external AI platform, that information may be outside the organisation’s control. This makes AI governance essential. Organisations need clear policies defining what information can be shared with AI services and should consider providing approved internal AI solutions that allow employees to benefit from AI without exposing sensitive operational data. A Glimpse Into the Future As this article was being prepared, OpenAI disclosed details of an incident involving autonomous AI agents during a controlled security test. According to public reports, advanced AI models reportedly escaped their testing environment, gained internet access and targeted systems belonging to AI platform Hugging Face while attempting to achieve their testing objectives. OpenAI described the event as an “unprecedented cyber incident”. Regardless of the final findings, the significance lies in what the incident demonstrates. Autonomous AI systems are beginning to show the ability to identify attack paths, exploit vulnerabilities and pursue objectives with limited human involvement. For OT operators, this should serve as a reminder that offensive cyber capability is no longer constrained solely by human expertise, manpower or working hours.
The Bottom Line AI is lowering the skill threshold for attackers, making social engineering more convincing and accelerating cyber operations. At the same time, it offers defenders powerful new capabilities for detection, monitoring and response. Whether AI is assisting human adversaries or acting with increasing autonomy, one thing is certain: the threat landscape is changing rapidly. The organisations that will succeed won’t be those chasing every new AI headline. They will be the ones that continue to invest in strong governance, identity management, network segmentation, secure access, change control and continuous monitoring. The fundamentals of OT cyber security haven’t changed. They ’re simply becoming important than ever.
more
To listen to Ian Gemski interview with Lets Talk Cyber: SCAN ME
SCOTSOFT2026 24.09.2026 Edinburgh
create. innovate. collaborate.
Join us in Scotland with the world's brightest tech minds to explore the future of digital
innovation.
This internationally recognised event offers
visionary speakers, cutting-edge insights and unparalleled networking opportunities in one of Europe's most vibrant tech ecosystems.
"Scotsoft has for many years been the
leading technology event in Scotland,
The combination of excellence speaks for itself, the interaction of Scottish
Cyber capability is exceptional, meeting all manor of industry leaders and future leaders is what sets it
apart."
SCOTLANDIS
Thomas McCarthy, MD, OSP Cyber
...........cyber
SCOTLANDIS
scotsoft.scot
align your brand with Scotland's leading tech conference. Level 1 Sponsorship from £15k
Sponsor welcome on stage Conference & exhibition tickets x10 Exhibition Stand
Prominent branding and digital promotion
pre/during/post event HA
Level 2 Sponsorship
Sponsorship of a speaker room Conference & exhibition tickets x10
from £6k
Exhibition Stand
Branding and digital promotion pre/during/ post event
2025 SPONSORS
Kube Net Your Trusted Technology Partner.
Arnold Clark
scotsoft.scot
LLOYDS BANKING GROUP
KAL
resill!on
soprasteria
bcs
SCOTTISH GAMES NETWORK
leidos
The
Chartered
Insntute
HORNETSECURITy
2i
XMA
the
craneware
group
Transforming the Business of Healthcare
Morgan Stanley
40
How has Technology Evolved in Supporting Operational Excellence & Security Outcomes?
Biju Chudasama CTO, at Wilson James
What a Modern CTO Should Be The role of the Chief Technology Officer has changed. It is no longer about owning technology. It is about enabling organisations to make better decisions, adapt faster and create lasting value. A modern CTO should spend less time talking about technology and more time understanding the business. They should know the challenges faced by frontline teams, the ambitions of clients and the pressures experienced by operational leaders. Only then can technology become meaningful.
AI should enhance capability, not replace judgement. Equally, the modern CTO must become the guardian of trust. Innovation without governance creates risk. Data without quality creates poor decisions. Security without usability slows progress. The role is to balance speed with responsibility, ensuring every new capability is secure, ethical and delivers confidence across the organisation. Perhaps the most overlooked responsibility is people. Technology does not transform organisations. People do.
Innovation should never exist for its own sake.
The best CTOs understand that their success is measured not by the platforms they deploy, but by the confidence they give others to succeed.
Every investment in technology should solve a real problem, improve an experience or create measurable value. The question is not “What technology should we buy?” but “What outcome are we trying to achieve?”
They build teams that are curious, encourage innovation, create opportunities to learn and foster an environment where people are empowered to challenge ideas and improve them.
Artificial Intelligence is a perfect example. The greatest opportunity is not replacing people. It is removing the repetitive work that prevents people from doing what humans do best: thinking critically, collaborating and making informed decisions.
The role is also becoming increasingly outward facing.
Cyber News Global
Today’s CTO should spend as much time with clients and partners as they do with engineers and developers.
Understanding operational challenges, shaping future services and translating emerging technologies into practical business outcomes has become a core leadership responsibility. Looking ahead, the organisations that succeed will not necessarily be those with the biggest technology budgets. They will be those that connect people, data and technology into a single operating model that enables faster, better-informed decisions. That is the role of the modern CTO. Not to own technology. But to inspire change, simplify complexity, enable people and create the conditions where innovation can genuinely make a difference. A modern CTO isn’t measured by the technology they introduce. They are measured by the outcomes they enable, the people they develop and the confidence they create for the future. What does a modern CTO actually do? It’s a question I’m often asked. Most people assume it’s about technology. It isn’t.
41 How has Technology Evolved... 33 Technology is simply the tool. The real role is helping people make better decisions. Over the last few years my role has evolved significantly. Today, I spend as much time with clients, operational leaders and frontline teams as I do discussing platforms, AI or cyber security. Why? Because technology without understanding the operational challenge rarely delivers lasting value.
We’re expected to connect business strategy with operational delivery. To translate emerging technology into practical outcomes. To simplify complexity. To build partnerships. To develop people.
I’ve come to believe there are a few principles that define what a modern CTO should be. Business first, technology second. Start with the problem, not the product. Innovation with purpose. Technology should solve a real challenge, improve an experience or create measurable value. Innovation for the sake of innovation rarely succeeds. AI is an enabler, not a replacement. The greatest opportunity isn’t replacing people. It’s removing repetitive work so people can focus on judgement, creativity and decision-making. Governance enables innovation. Trust, security and quality aren’t barriers to progress. They're what allow organisations to innovate with confidence.
And ultimately, to create the confidence for organisations to embrace change. For me, success isn’t measured by the number of technologies we’ve deployed. It’s measured by the outcomes we’ve enabled for our clients, the capability we’ve built within our teams and the problems we’ve helped solve. The title may still be Chief Technology Officer. But increasingly, I think we’re becoming Chief Transformation Officers. Technology remains at the heart of what we do. People remain the reason we do it.
People remain the greatest differentiator. The best technology in the world achieves very little if the people using it aren’t empowered, supported and trusted. As CTOs, we’re no longer just responsible for infrastructure or applications.
To listen to Biju Chudasama interview with Lets Talk Cyber: SCAN HERE
HYBRID EVENT PLATFORM Bridging Science, Sovereignty, and Scale The global platform for quantum and emerging technologies
28-30 SEP 2026 Grand Hyatt Dubai Conference & Exhibition Centre, UAE
Organized By
Media Partner
From Shadow AI to Strutured... 43
From Shadow AI to Structured Governance: How Enterprises Are Balancing Innovation and Risk
The Urgent Shift to AI Governance Enterprises are moving from ad hoc AI usage to structured, risk-aware governance. This shift is essential because with every powerful new technology come both opportunities and challenges. The real focus is on how organizations can introduce and manage AI with proper controls—without killing innovation. How AI Adoption Evolved from Ad Hoc to Structured AI has been around for some time, particularly through machine learning, but its recent explosion has transformed how organizations operate and how people work and live. The COVID-19 pandemic accelerated this by forcing a shift from office-based to remote and hybrid workforces, creating tremendous pressure on enterprises to adapt quickly. Initially, AI adoption was largely ad hoc. Different departments identified promising use cases—often through SaaS features or simple pilots—and implemented them without formal governance processes. This shadow AI mirrored the early days of digital transformation around 2014–2015, when organizations rushed to become web- and mobile-based for competitiveness and customer interaction. Big data and data science followed, but AI’s rapid spread created new complexities. Cyber News Global
Big data and data science followed, but AI’s rapid spread created new complexities. Over the past year and a half, organizations have begun moving from shadow AI to formal governance. This includes establishing clear AI usage policies, frameworks for responsible and ethical use of AI, high-level AI steering committees, and comprehensive AI inventories. These inventories help organizations stay on top of all AI use cases and track how they evolve. Different organizations are at varying levels of maturity. Some have well-defined AI governance committees with clear criteria for acceptable and unacceptable use, while others are still catching up. In the UAE, government entities are setting a high bar by taking serious control over AI governance, recognizing the significant risks of uncontrolled deployment. From Model-Centric to RiskCentric Governance A key evolution is the shift from model-centric to risk-centric governance. In the model-centric approach, enterprises focused narrowly on the AI model itself and the specific use case— primarily its accuracy and business value. They often lacked a full picture of the overall risk the organization faced when deploying that system.
The risk-centric approach is more holistic and mature. It asks critical questions: Even if the model delivers good return on investment and measurable value, how much risk does it expose the organization to? This includes responsibility, ethics, respect for individual privacy, the nature of training data, and broader implications. Higher-maturity organizations are adopting this perspective to address not just technical performance but also privacy, bias, and societal impact. Embedding Design
Governance
by
Another major change is moving from bolt-on governance to embedded governance. In cybersecurity’s early days, security was often an after thought— approached just before go-live as a simple checkbox. The industry matured to “secure by design,” involving security professionals from day zero. AI governance is following the same journey. Mature organizations now speak of “ethical by design” or “responsible by design.” Governance teams get involved right from the start, even as models are being trained. They ensure data is responsibly sourced, does not violate privacy, and has proper approvals from data subjects. This emb e dding inte grate s AI governance into existing mechanisms such as project and change management, third-party risk, data governance, security, and privacy-by-design.
44
From Shadow AI to Structured Governance: How Enterprises Are Balancing Innovation and Risk
Vijay Velayutham
The result is a more scalable process that supports rather than blocks business initiatives. Achieving Visibility Through AI Inventory Visibility is foundational to effective governance. Many organizations still lack a reliable map of where AI is being used, including capabilities hidden inside vendor tools. Without a solid AI inventory, governance remains reactive. Inventory is the number one critical factor in any governance initiative. Standards like ISO 27001, ISO 42001, and others all begin with asset management for good reason. For AI, however, visibility is more complex than traditional IT systems. An AI system can draw data from dozens of sources, involve multiple training layers, and include intricate processes. Cyber News Global
Principal Information Security Officer at the Ministry of Energy & Infrastructure
Many organizations are adopting a Configuration Management Database (CMDB) approach to AI— breaking systems down into layers and components, each with subelements, to ensure every part is secure, respects privacy, and meets ethical standards. This granular view enables better monitoring and control.
Some responsibilities may be shared, requiring primary and secondary owners. The AI Steering Committee provides high-level oversight.
Clarifying Roles, Responsibilities, and Decision Rights
Balancing Innovation
AI’s complexity also complicates roles and ownership. Traditional IT systems had clear business owners and system owners. With AI, ecosystemvernance bypasses as teams seek workarounds
Striking the right balance between control and innovation remains challenging. Too much control restricts experimentation and drives shadow AI. Too little exposes the enterprise to regulatory, ethical, security, and reputational risks.
Best practice is to break down roles and responsibilities with high granularity.
Organizations that invest time in clearly documenting these elements build stronger, more effective AI governance frameworks. Control
with
The EU AI Act aims to achieve this balance by focusing on risk levels.
From Shadow AI to Strutured... 45
Use cases with minimal business impact can have lighter oversight, while those affecting individuals’ health, job performance, recruitment decisions, or societal outcomes require stricter controls, greater explainability, and accountability. Tiered approaches—fast, lowfriction paths for low-risk uses and rigorous oversight for high-risk applications—help maintain agility while managing exposure. The Growing Need for Technical Depth and Explainability Technical depth is increasingly important. Governance bodies must address explainability, bias, adversarial risks, model drift, and robustness. Explainability means the ability to trace an AI system’s decisions back to specific data inputs and criteria. For instance, if AI scores job candidates or evaluates employee performance, the organization should later explain exactly why a particular score was assigned.
This technical area brings together machine learning, data privacy, programming, and governance. Governance committees and even boards will increasingly need members with technical understanding of AI. Without it, a gap emerges between governance expertise and technological reality. Future regulations may mandate such expertise at the highest levels. Leadership and the Path Forward As AI permeates every part of enterprise operations, leaders must deepen their understanding of its benefits and risks. Education is essential so executives can oversee how AI is used, controlled, and governed ethically while remaining aware of potential pitfalls. The journey from shadow AI to structured, risk-aware governance is well underway. Organizations that embed responsible practices, maintain strong visibility, clarify roles, and balance innovation with control will be best positioned to harness AI’s advantages sustainably and ethically.
Effective AI governance is not about slowing progress. It is about enabling trustworthy, responsible advancement in the AI era. About Vijay Velayutham: Vi jay Velayu tham heads Governance, Risk Management and Compliance for the Ministry of Energy and Infrastructure in the UAE. Previously, he led the same function for the Smart Dubai platform and its Big Data platform. With 25 years in technology, including 19 years in cybersecurity spanning operations, security monitoring, incident response, and now risk management and governance, Vijay Velayutham has witnessed multiple waves of technological and cybersecurity change. Watch our exclusive pod cast Interview with Vijay Velayutham
SCAN ME
OSP CYBER -MIDDLE
EAST
Building the Next Generation
of cybersecurity-ready citizens, professionals
and leaders across the GCC
Take control of your Al Governance with
Al Essentials for Executives our short 10-video series
ospcyber.ae
info@ospcyber.ae
4SECURE Move Critical OT Data.
Not Cyber Threats. Securely move operational data from critical OT environments to IT, enterprise and cloud platforms with proven Cross Domain and Data Diode technology.
20+ YEARS
protecting critical infrastructure
Scan to learn more 4-secure.com
OSP CYBER
ACADEMY
DATA BREACH WORKSHОР
SECONDS MATTER
Master the critical first response to a data breach...
DATA BREACH DETECTED
☑ Understand what constitutes a data breach
Learn how to identify and respond quickly Reduce risk and prevent future incidents
Meet GDPR & Data Protection obligations M Real-world scenarios & practical guidance
DID YOU KNOW? A delayed response to a
data breach can
significantly increase financial and
reputational damage.
☑ Expert-led training by cyber security professionals
INTERACTIVE. PRACTICAL. IMPACTFUL.
Scenario-based learning
Incident response simulation
Team-based decision making
Immediate real-world application
Assured Service Provider
in association with
National Cyber
Security Centre Training Course
NCSC Assured Training | Delivered by Industry Experts
training@ospcyberacademy.com
Its only Data Until it Isn’t... 49
It’s Only Data.. Until It Isn’t Why organisations must rethink their approach to data protection By Irene Coyle, Data Protection Officer Trust Many organisations believe data protection is about policies, registers and regulatory compliance. In reality, it is about something far more fundamental: trust. When organisations mishandle personal data, the real damage is not just operational or financial – it is the loss of confidence from the people whose information they hold. But as a data governance specialist I believe data protection is not about documentation. It is about trust, leadership and understanding the real value of the data organisations hold. Data protection often suffers from an image problem. For many organisations, it still feels like an administrative task – something to be documented, filed away and revisited only when a regulator asks questions. Policies are written, registers are completed and GDPR compliance boxes are ticked. But this mindset fundamentally misunderstands the purpose of data protection. It is not simply about compliance. It is about trust. Over three decades working in policing and now as Chief Operating Officer at OSP Cyber Academy, I’ve seen how organisations approach sensitive information – and more importantly, how quickly the consequences appear when that information is mishandled.
Cyber News Global
There is one phrase I often use when explaining the importance of data protection to leadership teams: “It’s only data... until it isn’t.” From Policing to Data Governance My perspective on data protection was shaped during a 30-year career with Police Scotland, where handling sensitive information was an everyday responsibility. Much of that work involved developing systems and processes designed to protect highly sensitive personal data. One initiative I was involved in was the creation of a vulnerable persons database – designed to support individuals who required additional protection and safeguarding. Working with information of that nature quickly changes how you view data. You realise that data is never just a record in a system. Behind every data entry is a real person – someone whose safety, privacy or wellbeing could be affected if that information is mishandled. Later in my policing career, I was responsible for implementing GDPR across the recruitment function. It was a fascinating challenge because it highlighted how many organisations initially see data protection as a purely legal or administrative requirement. In reality, it is far more than that.
“We’ve Never had a Breach” One of the most common questions organisations ask about data protection is also one of the most revealing: “We’ve never had a breach – so why do we need to invest in this?” At first glance, that may seem like a reasonable question. When nothing has gone wrong, data protection can feel abstract. It can appear procedural, even bureaucratic. But data protection should never be about waiting for something to go wrong. It is about understanding the value of the data your organisation holds. Every organisation processes personal data – employee records, payroll information, customer data, contracts, supplier details and more. That information represents something incredibly important: trust. And trust is something organisations build carefully over time but can lose very quickly.
50
It’s Only Data.. Until It Isn’t
Another common misconception is that organisations assume they are unlikely targets for cyber-attacks. But many breaches do not originate from direct attacks at all. They come through third-party suppliers, partners or inherited systems. So even if an organisation believes it is unlikely to be targeted, it must still consider the broader ecosystem surrounding its data. Ultimately, data protection is about foresight. I always ask “If your systems were disrupted tomorrow, would you know which data matters most?” and “would your team know what to do in the first critical hour?” Data Protection is Not Just GDPR paperwork Another persistent myth is that data protection is primarily about documentation. Policies, procedures and compliance f ra m e w o r k s a r e i m p o r t a n t . B u t documentation alone does not protect data. Data protection is fundamentally about how organisations think and behave when handling information. The questions organisations should really be asking are practical ones: • What data do we hold? • Why do we hold it? • Where is it stored? • Who is responsible for it? Cyber News Global
Many organisations proudly point to the policies they have in place with a big smile on their face. But policies that sit unread in folders or shared drives provide very little protection. “Policies don’t protect data – people do.” That is why structured training is so important. When staff understand how data flows through their organisation, how breaches occur and when to escalate concerns, the conversation moves from theory to practice. Recognised training programmes – particularly those aligned with frameworks such as National Cyber Security Centre (NCSC) guidance – help organisations build real capability. They help people recognise early warning signs of incidents, understand lawful data processing and embed accountability across the organisation. Most importantly, they help leaders move beyond compliance towards competence. The Real Risk isn’t the Fine When organisations think about the consequences of data breaches, the discussion often centres on regulatory fines. While financial penalties can be significant, they are rarely the most damaging outcome.
Reputation is. When personal data is mishandled, the message people hear is not about the size of a regulatory fine. The message they hear is much simpler: “You didn’t protect me.” That perception affects confidence from customers, employees and partners alike. Trust is therefore a leadership issue. Data protection cannot be seen as solely the responsibility of the Data Protection Officer. That would be the equivalent of saying cyber security is solely the responsibility of the IT department. Neither assumption is true. Protecting data requires awareness and accountability across the entire organisation. When Human Error Causes a Crisis Many high-profile breaches are associated with sophisticated cyber-attacks. Yet some of the most damaging incidents arise from far simpler causes. Human error remains one of the most common contributors to data breaches. A recent example involved the inadvertent publication of personal information relating to approximately 9,400 police officers and staff in Northern Ireland. The data was mistakenly disclosed through a Freedom of Information response.
Its only Data Until it Isn’t... The organisation had not fully assessed the personal data stored within those systems. The result was a regulatory fine of over £18 million and widespread reputational damage. The lesson is simple: “You cannot protect what you cannot see.” Data mapping is not merely administrative work. It is about gaining visibility of where risk exists within the organisation. Without that visibility, organisations are effectively operating with blind spots. And blind spots are where risk quietly grows. Three Priorities for Leaders For leaders trying to strengthen their organisation’s approach to data protection, the starting point does not need to be complicated. In fact, it can be distilled into three priorities. Clarity
The incident was not malicious. But the consequences were severe. Thousands of individuals were exposed, legal action followed and the PSNI faced intense public scrutiny. It highlights an important reality: many breaches are not the result of malicious intent, but simple mistakes made by people who do not fully understand the risks. The Importance of Knowing Where Your Data is Understanding where organisational data resides is one of the most critical aspects of effective protection. Without visibility, organisations cannot properly secure their information. A well-known example illustrates this risk. In 2018, Marriott International disclosed a breach affecting approximately 339 million guest records worldwide. The intrusion originated from a booking system belonging to Starwood Hotels – a company Marriott had acquired several years earlier. Attackers had already gained access to the system before the acquisition and remained undetected. When regulators investigated, the issue was not just the cyber intrusion itself. It was the due diligence surrounding the systems Marriott had inherited.
Leaders must understand what data their organisation holds and how it flows across systems, departments and external partners. Accountability Responsibility for data must be clearly owned rather than assumed. Culture Many breaches arise from simple behavioural issues – an email sent to the wrong recipient, an incorrect spreadsheet attachment or access rights not removed when someone leaves the organisation. These are not technology failures. They are awareness failures. When people understand why data matters, behaviour changes.
51
And when leadership supports structured training and governance, the organisation becomes both more competent and more confident in its data protection practices. Preparation, Not Perfection Data protection can feel overwhelming for organisations. But it should not be about achieving perfection. It should be about preparation. Behind every data record is a person – a colleague, customer or member of the public. When that information is mishandled, what is damaged is not just data. It is trust. The reassuring reality is that many incidents are preventable through simple governance measures: visibility, accountability, training and leadership oversight. When those elements are in place, good governance should actually feel uneventful. And that is exactly how it should be. Because the real goal of effective data protection is not headlines. It is steady confidence. After all: It’s only data.. until it isn’t. Author: Irene Coyle is Chief Operating Officer at OSP Cyber Academy and a cyber resilience and data protection specialist with over 30 years’ experience in policing, governance and organisational risk management. She works with leadership teams across public and private sectors to strengthen cyber resilience, data protection capability and practical governance. To listen to Irene Coyle interview with Lets Talk Cyber:
Scan Me
IMMERSIVE TRAINING
Our one-hour investigative game offers immersive data protection and cybersecurity training for corporate events up to 60 people. Using clues and strategy, teams solve puzzles and riddles to complete a mission. With our all-inclusive ‘Training Suitcase,’ you can set up in your own office and create an engaging escape room environment.
Can your team solve the cyber puzzles and escape?
CYBER SECURITY
ESCAPE ROOM HIGHLY EFFECTIVE CYBER SECURITY & DATA PROTECTION TRAINING - MADE FUN & MEMORABLE
contact: training@ospcyberacademy.com
The Art of Resilience... 53
The Art of Resilience: Navigating the Complexity of CNI Resilience Jane Wright
Research Engineer,Strathclyde University
Modern infrastructure demands strategic foresight, not reactive defense. Critical National Infrastructure (CNI) systems have evolved – and continue to evolve – to keep pace with the changing environment in which they operate. CNI is no longer limited to physical assets but also depends on digital layers, human behaviour and interactions between other infrastructure systems. The growing scale of interdependency amplifies operational risk, as the entire network of connections becomes increasingly susceptible to disruption. As such, the concept of resilience has become a central focus for all. Defining Resilience Resilience is a broad, polysemous word. It is associated with concepts such as risk, response, absorption, capacity, anti-fragility, adaptability and recovery. Each of these terms carry a distinct meaning and call for different assessment approaches. However, resilience is frequently left undefined, its meaning is not consistently articulated nor shared across individuals, teams and organisations. This conceptual ambiguity can lead to inconsistencies in both interpretation and measurement. Consequently, interventions addressing lack of resilience may overlook the root causes of systems vulnerability. Cyber News Global
The first step towards building resilience is defining resilience for the people, systems, businesses and organisations within the context of the environment. By developing a clearer understanding internally, organisations can engage more effectively with customers, supply chain partners and regulators. Even if stakeholders are not fully aligned, this shared awareness provides a foundation for open discussion. Standards and Frameworks Organisations can leverage resilience frameworks and standards to guide and support the development and implementation of resilience. Notable examples include British Standard (BS) 67000 City Resilience, BSI ISO 37123 Indicators for Resilient Cities, ISO 22366 Framework and Principles for Energy Resilience and the upcoming ISO/DIS 22316 Organisational resilience. Frameworks aimed at resilience within a cyber security context include the European Union Directive on Security of Network and Information Systems (NIS2 Directive), NIST SP 800-160 Developing Cyber Resilient Systems and the NCSC’s Cyber Assessment Framework.
Organisations have also implemented business continuity, crisis and risk management frameworks and standards with the same aim. These frameworks are in addition to technical engineering standards; another dimension of complexity for organisations. A significant challenge lies in (i) selecting appropriate standards and frameworks, (ii) understanding which are mandated for regulatory compliance or international collaboration, and (iii) evaluating the extent to which they can be integrated effectively, without generating contradictory specifications. For example, consider the tension between security and resilience. Security specifications primarily focus on confidentiality, integrity and availability, emphasising robust systems and strict controls. In contrast, resilience engineering promotes flexibility, adaptability and extensibility. This raises the question of whether the rigid security structures may conflict with, or even limit, the adaptive capacities encouraged by resiliencefocused approaches.
52 54
The Art of Resilience: Navigating the Complexity of CNI Resilience (Contd:) Resilience assessment should go beyond generating risk scores or rankings; it must deepen understanding of system dynamics, uncertainties, and the complex challenges that require further exploration.
Many of these frameworks and standards provide well-established theoretical principles and systematic methods for evaluating systems holistically. Applying these frameworks to CNI is complicated by the fact that oversight and influence are exercised by third-party regulatory authorities. This constrains organisational decision-making autonomy such that these conceptual principles have to be operationalised through measurable indicators and outputs. Organisations are incentivised to pursue a ‘good enough’ level of performance, oriented toward meeting the measurable criteria established by the regulatory authority rather than fully realising the underlying principles of resilience. By reducing resilience to a specific set of measurable metrics, interdependencies, relationships and the influence of uncontrollable external factors are often overlooked. This produces imperfect information, thus limiting the accuracy and usefulness of resilience assessments. It is recommended that organisations consider their system as part of an interconnected whole, and anticipate and account for the factors considered above.
Cyber News Global
In doing so, they can avoid becoming overly self-referential and ensure that resilience strategies reflect the broader context in which their system operates. Considering the Cost of Resilience Consideration of cost is essential when developing a resilience strategy. Without an understanding of cost, it becomes impossible for organisations to assess effectively which goods and services can be delivered, to what extent, and over what duration. However, the cost of cultivating resilience presents a significant challenge. Unlike traditional investments, where returns can be quantified through revenue or profit, resilience initiatives often do not generate immediately visible financial benefits. Consequently, securing ongoing funding for resilience measures, much like cyber security, can be difficult, as the value is realised through the avoidance of adverse outcomes – counterfactual scenarios that are inherently difficult to observe and communicate. Monitoring and evaluation systems can provide some metrics as to impact, but effects of resilience-building measures are not always apparent or directly attributable.
Because resilience-related investment is frequently marginalised for firms focused on sustaining a low-profit equilibrium and regulators incentivised to minimise costs for consumers, organisations are forced to adopt a risk-focused approach to resilience. Risk management methodologies focus on spending time, resource and effort in loss avoidance through restricting activities. However, an emphasis on loss avoidance can suppress adaptive initiatives, even when such actions align with the same goal. Events seldom unfold exactly as anticipated. Organisations must develop the capacity to operate effectively under uncertainty and to tolerate ambiguity as an inherent feature of complex environments. Given the estimated cost of downtime, expenditure on resilience efforts should effectively pay for itself within a number of years, irrespective of whether a major incident materialises. Approaching Resilience Defining and quantifying resilience is inherently complex, and traditional risk assessments alone are clearly insufficient.
The Art of Resilience... 55 Some elements, while inherently immeasurable , are essential to organisational success and system resilience. Thus, organisations must adopt broader approaches that emphasise adaptability, learning and responsiveness to unforeseen challenges. 1. Establish a Minimum Viable Company Acknowledging that all systems carry some degree of vulnerability, organisations need to identify and prioritise those that are essential to fulfilling their core mission. This includes determining which suppliers, logistics partners and distribution channels are indispensable for sustaining minimum service levels and maintaining cash flow. With this understanding, protective measures can be layered around those priority systems. Mapping these interconnections facilitates a more holistic assessment of the organisational environment and points of potential opportunity and vulnerability. 2. Incremental Advancement The system should be advanced incrementally toward these objectives through a series of viable, stable intermediate states. Rather than relying on a single, large-scale investment, that may not be economically viable, these stages provide fundable opportunities for progress along alternative pathways and allow for rollbacks if necessary. Implementation must be guided by a prioritisation framework that is regularly reviewed. The approach requires striking a balance: taking sufficient risk to enable meaningful change, while avoiding exposure that the organisation cannot absorb.
3. Celebrating Failure
Summary
Organisations need to foster a culture that recognises and learns from failure, while maintaining accountability for negligence. Studies on innovation indicate that failed projects often generate new organisational knowledge and insights that help firms refine their approaches and avoid repeating the same mistakes. By shifting decision-making practices and valuing employees’ contributions in the face of failure, organisations can stimulate greater innovation and learning, generating organisational and economic growth.
A refreshed approach to resilience is necessary. The goal of resilience assessment extends beyond producing risk scores, rankings or exact values. More critically, it should enhance the assessors understanding of the underlying problem, associated dynamics, inherent uncertainties and areas that require further exploration or research. In this way, assessment becomes a tool for learning and reflection, not just measurement.
Implications of Artificial Intelligence (AI) and Machine Learning (ML) AI creates both opportunities and risks. Digitalisation has exponentially increased the volume of data produced, collected, stored and shared between systems. Harnessing AI and ML within CNI can help manage this complexity, enabling faster decision-making. It has the capacity to identify patterns or insights that humans might overlook and can accelerate and streamline many cognitive processes. The potential for greater efficiency and scalability offers a significant advantage for the resilience of CNI. However, CNI systems are highly complex and often proprietary. This makes it difficult to gather real-world data for training purposes, raises significant concerns around transparency and accountability, and introduces new vulnerabilities to the system. It is essential to remain cognisant of where and how AI is deployed within CNI, who is using it, and how its integration alters system interactions.
The desire for complete control must be relinquished, and the inherent complexity of systems must be acknowledged. It is essential to recognise that operational, policy and regulatory decisions exert significant influence and unintended consequences on systems beyond their immediate boundaries. Email: jane.wright@strath.ac.uk
To listen to Jane Wright interview with Lets Talk Cyber:
SCAN ME
Figure 1: Critical National Infrastructure Interdependency Mapping (excluding Government)
Technical Conference Organised by
ADIPEC brought to you by
Official media partner
OSP Cyber Middle East... 57
58
As AI adoption accelerates, organisations across the UAE and GCC face growing challenges around governance, cyber risk, privacy and regulatory compliance.
OSP Cyber Middle East has officially launched, bringing cyber security & AI governance to organisations across the UAE and wider GCC.
Cyber News Global
The launch marks an important step for OSP Cyber Academy as it expands its presence into the Middle East, supporting organisations as they respond to a fast-changing digital, regulatory and threat landscape. With the UAE and GCC continuing to invest heavily in artificial intelligence, smart infrastructure and digital transformation, the need for practical cyber resilience and AI governance has never been greater.
OSP Cyber Middle East has been created to support leaders, boards, executives and teams responsible for managing cyber risk, AI adoption, data protection and organisational resilience. The company will provide awareness training, strategic learning programmes, cyber exercises, AI governance education and practical support for organisations looking to strengthen their approach to digital risk.
OSP Cyber Middle East... 59
A key part of the launch is the introduction of AI Strategy Essentials for Executives, a short video series designed to give senior leaders a clear and accessible overview of the issues shaping AI governance in the UAE and GCC. The series explores how AI is already influencing decisionmaking, why human oversight matters, where accountability sits, and what practical first steps leaders can take to put effective controls in place. Rather than treating AI purely as a technology issue, the series frames AI governance as a leadership responsibility. It highlights the importance of understanding not only what AI systems can do, but who remains accountable for the outcomes they create. The launch builds on OSP Cyber Academy’s established experience in cyber security training, awareness, data protection and resilience exercises. By bringing that expertise into the Middle East, OSP Cyber Middle East aims to support a region already recognised for its digital ambition.
As AI adoption accelerates, organisations across the region face growing questions around regulation, ethics, cyber risk, privacy and operational control. OSP Cyber Middle East will help organisations move from awareness to action, giving them the knowledge and confidence to embrace innovation while maintaining strong governance and resilience.
The AI Strategy Essentials for Executives video series is now available through the OSP Cyber Middle East website. Find out more: https://ospcyber.ae/ or contact: info@ospcyber.ae
Why High Programing AI... 60
Why high-Performing Ai requires more ThAn AccurATe models
Shereen Faisal - AI Governance & Project Management Leader Shereen Faisal is a technology and governance leader specializing in Artificial Intelligence (AI) governance, project management, quality management systems, and digital transformation initiatives. She plays an active role in supporting the development, implementation, and governance of AI solutions across both public and private sector organizations. With extensive experience in managing multidisciplinary technology projects, Shereen has contributed to the successful delivery of AI-driven solutions in areas such as intelligent automation, natural language processing, predictive analytics, and decisionsupport systems. Her work focuses on ensuring that AI technologies are deployed responsibly, effectively, and in alignment with organizational objectives. What a Modern CTO Should Be Artificial Intelligence has rapidly evolved from an emerging technology into a strategic business capability. Today, organizations across industries are integrating AI to automate operations, improve decisionmaking, enhance customer experiences, and drive innovation. Yet, despite this rapid adoption, many organizations continue to evaluate AI success using a single metric: model accuracy. While accuracy is important, it represents only one aspect of a successful AI solution. An AI model can achieve exceptional performance during testing but still fail to deliver meaningful business value if it is built on poor-quality data, developed without governance, disconnected from organizational objectives, or left unmonitored after deployment. Highperforming AI requires far more than intelligent algorithms—it requires a comprehensive approach to quality management. AI Quality Management is becoming one of the most important disciplines for organizations adopting artificial intelligence at scale. Rather than concentrating solely on technical performance, it focuses on managing quality throughout the entire AI lifecycle—from identifying the business problem and preparing data to developing, deploying, monitoring, and continuously improving AI solutions. One of the biggest misconceptions surrounding AI is that achieving a highly accurate model marks the end of the journey. Cyber News Global
In reality, deployment is only the beginning. AI systems operate within dynamic environments where data evolves, user behavior changes, regulations mature, and business priorities shift. Without continuous evaluation and improvement, even the most advanced AI models can gradually lose their effectiveness and the trust of those who depend on them. Quality should begin at the earliest stages of an AI initiative by defining the right business problem, establishing governance, ensuring data quality, and embedding continuous monitoring throughout the solution's lifecycle. The quality of AI outputs will always reflect the quality of the data, processes, governance, and decisions that shape them. From my experience managing AI projects, successful initiatives are rarely determined by technology alone. Organizations that achieve sustainable results invest in highquality data, align AI with clear business objectives, encourage user adoption, and establish governance mechanisms that support long-term improvement. AI should not simply deliver accurate predictions— it should consistently deliver trusted, measurable, and sustainable business outcomes. To support this vision, I propose an AI Quality Index (AIQI)—a practical framework that enables organizations to evaluate AI beyond technical performance. The AI Quality Index (AIQI) Business Alignment: Does the AI solution solve the right business problem and create measurable value?
Data Quality: Are the data sources accurate, representative, secure, and properly governed? Governance & Compliance: Are accountability, transparency, ethical principles, and regulatory requirements embedded throughout the AI lifecycle? Model Performance: Does the model demonstrate reliability, robustness, fairness, explainability, and consistent performance over time? Operational Excellence: Is the AI solution monitored, maintained, secure, scalable, and capable of adapting to changing environments? Continuous Improvement: Is there an established process for feedback, per formance monitoring, model drift management , and ongoing enhancement? Together, these six dimensions provide a balanced perspective on AI quality. Rather than asking, "Is our AI accurate?", leaders should begin asking, "Is our AI creating sustainable value, maintaining trust, and continuously improving?" Ultimately, the organizations that will lead the AI era will not be those that build the smartest AI models, but those that build AI systems people can trust. The future of artificial intelligence will be defined not simply by greater intelligence, but by higher standards of quality, accountability, and continuous improvement. In the years ahead, AI Quality Management will no longer be a competitive advantage—it will become a business necessity. It's Shereen Faisal Linkedin Profile:
EXHIBITING
Scottish OT Cyber Summit 2026
DRINK RECEPTION SPONSORSHIP
Aberdeen
12 August 2026
One Partnership. Total Cyber Resilience RADIFLOW
BARRIER
NETWORKS
Radiflow
OT CYBERSECURITY
Securing What Powers The World. Radiflow is a leading global provider of OT cybersecurity solutions, designed to protect critical infrastructure and industrial automation environments. With extensive experience across energy, utilities, transportation, water, oil and gas, and
manufacturing, Radiflow enables organizations to securely operate complex industrial networks while reducing cyber risk
and maintaining operational continuity. Purpose-built for operational technology, its solutions deliver deep network
visibility, asset discovery, risk management, and threat detection tailored to industrial control systems.
Network Visibility
Asset Discovery
Risk Management
Threat Detection
BARRIER
MSSP
Cybersecurity That Goes Beyond. At Barrier, our mission is to enhance your defences and minimise cyber risks through expert consultancy and cutting-
edge technology. We understand the challenges of balancing resource limitations with achieving strategic cybersecurity objectives. Our award-winning services, built on a deep heritage of cybersecurity operations, have established us as a leader in the industry. With a global customer base and operations in Glasgow and London, Barrier is dedicated to
innovation and equipped to strengthen your digital environments against evolving threats.
MSSP
Managod Security
SOC Operations
Incident Responso
CONNECT WITH RADIFLOW
CONNECT WITH BARRIER
radiflow.com
barriernetworks.com
THIRDWATCH
DON'T DUCK WITH YOUR
CYBERSECURITY. The world's first zero-touch, non-invasive technology to visualize the threat.
THIRDWATCH
BLACKWIRED
crmg GLOBAL EXPERTISE, LOCAL PRECISION
Your Cyber
Risk Partner. Cyber Security for Every Risk Profile.
With a rich heritage in cyber security, we draw on our extensive experience working in global organisations to provide effective, tailored solutions across all areas
of cyber governance, risk management, and
compliance.
Cyber Security Programme Support
Al Assurance
Hands-on support to design, run and mature
Confidence that your Al adoption is governed,
your security programme, at your pace.
compliant, secure and responsibly deployed.
ソ Cyber Risk Assessment
Third-Party Risk Management
Clear, board-ready insight into where you stand
Assurance across your supply chain
and what to fix first.
triage to deep assessment.
-
from
WHY CRMG
WHO WE HELP
We work alongside your team to build capability
From fast-growing firms building their first
that lasts, delivering advice grounded in decades
security programme to global organisations
of hands-on information security leadership.
maturing cyber governance, risk and compliance at scale.
Ready to take control of your cyber risk? crmg-consult.com
simon.rycroft@crmg-consult.com
Figure 1: Magic Quadrant for CPS Protection Platforms LEADERS
CHALLENGERS
Nozomi Networks
Armis
Claroty
Dragos
Forescout Technologies
Tenable
Fortinet Darktrace
TXOne Networks
ABILITY TO EXECUTE
Honeywell Cisco
Microsoft
Palo Alto Networks
NICHE PLAYERS
COMPLETENESS OF VISION
VISIONARIES
As of March 2026
Gartner, Inc
Gartner
INDUSTRIAL CYBER SECURITY
GRC
LOOP
SHIELD
UNITY
PROTECTING CRITICAL NATIONAL INFRASTRUCTURE ISO 9001
ISO 14001
ISO 27001
ISO 45001