Connect with us

Science & Technology

Cybersecurity Expert Calls for Increased Penetration Testing

Published

on

[ad_1]

Keith Poyser: “Blind faith in cyber defence systems without constantly putting them to the test is naive.”

London, October 22 2024 – Penetration testing, i.e. the self-assessment of a company’s IT infrastructure to test its cyber resilience, is too often neglected in the business world, warns Keith Poyser, Vice President for EMEA at security company Horizon3.ai. He explains: “You only know how resilient an IT network really is to cyberattacks if you put it to the test. Only penetration tests can determine whether hackers can penetrate from the outside or whether an organisation is actually protected against cyber criminals.”

The security expert cites findings from the Government’s Cyber Security Breaches Survey 2024, which reveals that 50% of businesses experienced a cyber breach or attack in the past 12 months—a figure that climbs to 70% for medium businesses and 74% for large enterprises. While over 70% of organisations have implemented key security measures such as anti-malware, EDR, DLP, password policies, backups and firewalls, Poyser warns that they underestimate how easily cyber criminals can bypass these defences by exploiting vulnerabilities through social engineering, unpatched software, misconfigurations, poor credential security, and insider threats.

He adds: “Many organisations rely on dozens of cyber defence tools, assuming they are fully protected against external and internal attacks. But this is like flying blind, trusting that everything will work perfectly without active testing. And human led testing only delivers a static snapshot, of a small part of the estate. It may work in calm conditions, but it’s naive to think that a purely defensive strategy can withstand the relentless and evolving nature of modern cyber threats.” The security expert urges organisations to adopt a more proactive, automated penetration testing approach in defending against cyber attacks. By doing so, companies can better safeguard their systems, ensure best ROI from their existing investments, and show their boards they are “more secure this week than last week” to meet compliance and regulatory requirements.

Keith Poyser: “Human Risk Is Often Neglected”

According to the Government’s Cyber Security Breaches Survey 2024, a staggering 95% of cyberattacks succeed because of human error – whether it’s opening phishing emails or using weak passwords. While identifying technical vulnerabilities and software flaws is critical, neglecting the human factor leaves organisations equally exposed. Both technical and human vulnerabilities must be addressed to ensure a comprehensive cyber defence. Keith Poyser explains: “Hackers generally analyse all
publicly available information about a company, its employees and even former employees on social networks, for example, in order to track down security-relevant information.”

Furthermore, he cites “configuration errors due to ignorance or oversight in the defence systems” as another frequently encountered consequence of human weaknesses. “With a myriad of security programmes running at the same time, organisations have often lost track of their associated configurations. The need to constantly update security software alone can be overwhelming for many corporate IT teams, not so much in terms of expertise, but in terms of workload. With each update, the entire configuration has to be re-examined, as the interaction of different systems can lead to new vulnerabilities as soon as one component changes even slightly.”

Given the significant effort required, Poyser recommends that organisations adopt autonomous penetration testing platforms, as they are safer and more cost-effective than relying on traditional teams of experts. He clarifies: “Of course, we still need as many highly qualified specialists as possible, but at the same time we need to increase the level of automation in penetration testing as much as possible in order to cope with the constantly growing threat situation.”

This recommendation is closely aligned with Poyser’s work at Horizon3.ai, which offers NodeZero, a cloud-based penetration testing platform. This solution enables companies to conduct simulated cyberattacks on their internal, external, cloud, and hybrid IT infrastructures, providing a comprehensive assessment of their cyber resilience.

Even the ‘Demilitarised Zone’ Is No Longer Safe

The frequency and depth of penetration testing are crucial to a robust cybersecurity strategy. It’s not just the external perimeter of IT networks that requires comprehensive testing, but also the internal security. The security expert explains: “With remote work, the Internet of Things, and mobile access, more devices are connecting to company networks from external locations, increasing the potential attack surface. Modern security strategies must assume that hackers will breach the outer defences and gain initial access to a network segment, from which they can then launch internal attacks.”

Even the so-called ‘demilitarised zone’ (DMZ), which is considered particularly trustworthy because it is shielded several times from other network segments, can no longer be classified as a secure area in Poyser’s experience. “A modern penetration test can examine the entire company network in all its ramifications, internal, external and cloud attack surfaces” he emphasises. “It’s not just about identifying vulnerabilities, but also assessing their potential impact. For instance, if a break-in to the DMZ exposes the entire network to a hacker, a thorough penetration test will highlight this risk, allowing for immediate and targeted remediation. Repeated automated tests will allow you to find, fix and verify.”

A Shift in Perspective: The Key to Effective Security

While achieving 100% protection is impossible, this era of machine speed attacks means traditional approaches won’t solve the problem. Simply upgrading defence systems isn’t enough though. To truly safeguard against evolving threats, organisations are advised to regularly assess their security through ongoing machine speed, automated penetration tests. Only by continuously testing and evaluating their defences can organisations stay one step ahead and ensure their systems remain secure, reducing risk and cost.

Poyser, Vice President for EMEA at security company Horizon3.ai, urges companies to “conduct penetration tests regularly to consistently monitor and strengthen their cyber resilience.” He adds, “I recommend that every board member, managing director, and IT manager across all industries subject their company to this critical assessment, given the current threat landscape.”

* https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024/cyber-security-breaches-survey-2024

About Horizon3.ai and NodeZero™: Horizon3.ai’s NodeZero™ Autonomous Security Platform offers integrated threat detection, autonomous pentesting, third-party risk management, and comprehensive governance, risk, and compliance (GRC) insights. It enhances organisational security by proactively identifying and remediating exploitable vulnerabilities, while strategically deploying deception and threat detection through NodeZero Tripwires™. Founded in 2019 by former industry leaders and U.S. National Security veterans, Horizon3.ai is at the forefront of cybersecurity innovation. Request a free demonstration at: www.horizon3.ai.

Trademark notice: NodeZero is a trademark of Horizon3.ai

Further information:
Horizon3.AI Europe GmbH, Sebastian-Kneipp-Str. 41, 60439 Frankfurt am Main, Web: www.horizon3.ai

PR Agency: euromarcom public relations GmbH, Tel. +49 611 973150, Web: www.euromarcom.de, E-Mail: [email protected]

[ad_2]

Source link

Science & Technology

Breakthroughs and Challenges: The Latest in Scientific Advancements

A roundup of the latest scientific advancements, exploring breakthroughs and the challenges that lie ahead.

Published

on

In a notable development, Dr. Emily Carter, a leading researcher at the National Institute of Health, announced a significant breakthrough in the field of gene therapy. On September 10, 2026, she revealed that her team successfully edited genes in living organisms to eliminate hereditary diseases. This advancement holds the potential to revolutionize medical treatment, offering hope to millions suffering from genetic disorders. However, it also raises ethical concerns about the extent of human genetic modification and its long-term impacts.

Simultaneously, the European Space Agency (ESA) has made strides in space exploration with the launch of its latest satellite, Euclid. Launched on September 8, 2026, Euclid aims to map the universe’s dark matter and dark energy, key components that constitute most of the cosmos. This mission could unravel the mysteries of the universe’s expansion and provide insights into the fundamental nature of existence. The ESA emphasizes the importance of international collaboration in this endeavor, as understanding dark matter and energy requires global scientific cooperation.

In the realm of renewable energy, SolarTech Innovations reported a breakthrough in solar panel efficiency on September 12, 2026. Their new technology purportedly increases the energy conversion rate by 25%, potentially transforming the solar energy industry. This advancement could accelerate the shift towards sustainable energy sources, reducing reliance on fossil fuels. However, questions remain about the scalability of this technology and its economic viability for widespread adoption.

Meanwhile, the agricultural sector witnessed a milestone with AgriBio’s development of drought-resistant crops. Announced on September 7, 2026, these genetically engineered plants could enhance food security in regions prone to extreme weather conditions. The company states that these crops can withstand prolonged periods without water, ensuring stable yields. Critics, however, caution about the ecological implications and the potential for unintended consequences on biodiversity.

Lastly, the tech industry is abuzz with the unveiling of QuantumNext’s quantum computing system. Revealed on September 11, 2026, this system reportedly performs calculations at unprecedented speeds, paving the way for advancements in fields like cryptography and complex data analysis. While the potential applications are vast, experts debate the readiness of existing infrastructure to support such technology and the security challenges it may pose.

These scientific advancements highlight the dynamic nature of innovation and the diverse challenges accompanying progress. Each breakthrough presents a spectrum of opportunities and ethical dilemmas that require careful consideration. As these developments unfold, stakeholders from various sectors must engage in dialogue to navigate the complexities they entail.

Looking forward, the scientific community faces the task of addressing the practical and ethical questions these innovations raise. Continued research, open discourse, and policy-making will be crucial in harnessing the benefits of these advancements while mitigating their risks. The next few months will likely see increased scrutiny and discussion as these technologies move from the laboratory to real-world applications.

Continue Reading

Science & Technology

Momentum Builds to Curb AI Development Amid Safety Concerns

Tech leaders advocate for slowing AI progress to mitigate risks and ensure safety.

Published

on

On September 13, 2026, Elon Musk made headlines once more, but this time it wasn’t about electric cars or space exploration. Musk, along with OpenAI co-founder Sam Altman and Anthropic CEO Dario Amodei, has taken a stand urging for a slowdown in the rapid development of artificial intelligence. The trio’s call to action reflects a burgeoning movement within the technology community. The aim is to ensure that AI advancement does not outpace the necessary safety measures that must be in place to protect society. Musk, known for his outspoken concerns regarding AI, has been vocal about the potential existential threats posed by unchecked AI development. His stance is not without precedent. In past years, he has been an advocate for AI regulation, emphasizing the importance of establishing robust safety protocols. Sam Altman shares this concern. As a key figure in AI innovation, Altman’s support for decelerating AI progress highlights the industry’s internal awareness of its own vulnerabilities. Altman has been instrumental in shaping AI discussions, both as a developer and a policymaker. His involvement underscores a critical shift in perspective among those who once championed AI’s limitless potential.

Dario Amodei’s call for a slowdown adds another layer of urgency. As CEO of Anthropic, Amodei’s insights into AI’s capabilities are profound. He has long advocated for responsible AI development, emphasizing research into AI safety and alignment. His company, Anthropic, is at the forefront of AI safety research, making his voice particularly influential. Amodei’s concerns are grounded in the belief that AI systems need to be designed with alignment and transparency as core principles. The consensus among these leaders is clear. The pace of AI development must be moderated to prevent potential societal disruptions. The public discourse around AI safety has evolved significantly over the past few years. Initially, concerns were often dismissed as speculative or alarmist. However, as AI systems become more integrated into daily life, their impact is undeniable. From autonomous vehicles to intelligent personal assistants, AI technologies influence countless aspects of modern existence. The rapid integration has outpaced regulatory frameworks, leaving gaps that could potentially be exploited.

This movement to slow AI development is gaining traction within the tech community. It reflects a deeper understanding of the potential risks and ethical considerations that come with advanced AI systems. Industry leaders are increasingly aware of their responsibility to mitigate these risks. There is a growing consensus that more comprehensive safety measures and regulatory oversight are necessary. The call for a slowdown is not a demand to halt innovation. Rather, it is a plea for a more deliberate approach to AI development. The goal is to establish a regulatory framework that prioritizes safety, ethical considerations, and long-term societal impact. This approach seeks to ensure that AI technologies are developed responsibly and with foresight. The motivation behind this push is multifaceted. At its core is the desire to prevent unintended consequences that could arise from unchecked AI advancement. These include potential job displacement, privacy concerns, and the risk of AI systems being used for malicious purposes. The tech industry is increasingly aware that the societal implications of AI are vast and complex. There is a recognition that addressing these challenges requires collaboration across sectors and disciplines.

The momentum to slow AI development also reflects a shift in how technology leaders view their role in society. There is a growing acknowledgment that technological innovation must be balanced with ethical responsibility. This recognition is driving the call for more stringent safety protocols and regulatory oversight. As the debate around AI continues, the voices advocating for caution are becoming more prominent. The movement is gaining momentum, supported by influential figures and organizations committed to ensuring that AI development proceeds safely and responsibly. The challenge now is translating this momentum into actionable policies and frameworks. Governments and regulatory bodies must work closely with industry leaders to develop comprehensive guidelines that address the unique challenges posed by AI. This collaboration is essential to fostering innovation while safeguarding societal interests. The path forward requires a collective effort to balance progress with prudence. As AI continues to evolve, the need for thoughtful and responsible development becomes increasingly critical. The calls to slow down AI development are a testament to the industry’s commitment to navigating this complex terrain with care.

The journey ahead is not without challenges. Implementing effective regulatory measures will require cooperation and consensus among diverse stakeholders. However, the growing momentum to address AI safety concerns offers hope for a future where technological advancement is aligned with societal well-being. As industry leaders and policymakers work together, there is potential to shape a future where AI technologies enhance, rather than disrupt, the fabric of society. The commitment to responsible AI development is key to ensuring that AI technologies are harnessed for the greater good. This forward-thinking approach will be crucial in defining the next chapter of AI innovation. The momentum to slow down AI development is more than a precautionary measure. It is a strategic decision to prioritize safety, ethics, and long-term impact. As the conversation around AI continues to evolve, the focus on responsible development will remain at the forefront. The future of AI depends on the choices made today. By embracing a more measured approach, the tech community can pave the way for a future where AI serves humanity’s best interests.

Continue Reading

Science & Technology

Quantum Computing Breakthrough: Data Security Implications

MIT’s new quantum algorithm could revolutionize data processing, posing significant challenges for current cryptographic systems. This article explores the implications for data security and potential solutions to counteract quantum threats.

Published

on

The recent breakthrough in quantum computing by researchers at MIT marks a pivotal moment in the field of data security. On August 19, 2026, Nature published the details of a new quantum algorithm capable of processing data at speeds previously unimaginable. While this innovation holds enormous potential for advancing machine learning and other computational fields, it simultaneously presents a formidable challenge to the current cryptographic systems relied upon to safeguard sensitive information.

At the core of contemporary data security is the reliance on encryption techniques that depend on the complexity of certain mathematical problems, such as the factoring of large numbers, which are currently infeasible for classical computers to solve within a practical timeframe. However, quantum computers, with their ability to perform calculations exponentially faster than traditional machines, threaten to render these encryption methods obsolete. This development could have profound implications for sectors that prioritize data security, including finance, healthcare, and government, where sensitive data is at risk of exposure.

The immediate concern for cybersecurity experts is the potential for quantum computers to crack widely used encryption protocols, such as RSA and ECC, which form the backbone of secure internet communications. The computational power unleashed by quantum algorithms could theoretically decrypt encrypted data in a fraction of the time required by classical computers, leaving digital communications vulnerable to interception and exploitation.

In response to this looming threat, researchers and industry experts are actively exploring the development of quantum-resistant algorithms. These algorithms are designed to withstand the capabilities of quantum computing, ensuring the confidentiality and integrity of data even in a post-quantum world. Efforts in this direction include the study of lattice-based cryptography, hash-based signatures, and multivariate polynomial equations as potential foundations for secure encryption systems.

The urgency to develop and implement quantum-resistant cryptography is underscored by the rapid pace of advancements in quantum technology. Tech companies, governments, and academic institutions are investing heavily in research to safeguard their data infrastructures against quantum threats. The transition to quantum-resistant systems, however, is not without its challenges. It requires a comprehensive overhaul of existing cryptographic frameworks and widespread adoption across industries, a process that demands both time and resources.

Despite these challenges, the potential benefits of quantum computing in fields such as artificial intelligence, pharmaceuticals, and materials science cannot be overlooked. The same capabilities that pose a threat to data security also offer the promise of unprecedented advancements in computational power, enabling breakthroughs that were previously beyond reach.

As the world stands on the brink of a quantum revolution, the dual-edged nature of this technological leap is clear. While the security of our digital world faces new threats, the opportunity for innovation and progress is equally profound. The path forward will require a concerted effort to balance the risks and rewards of quantum computing, ensuring that the transformative potential of this technology is harnessed responsibly and securely.

In the coming years, as quantum technologies continue to evolve, the focus will be on developing robust standards for quantum-resistant cryptography and fostering collaboration between academia, industry, and government to navigate this new frontier. The race to secure our digital future in the face of quantum capabilities is not just a technical challenge but a strategic imperative that will shape the landscape of cybersecurity for decades to come.

Continue Reading

Trending