Connect with us

Science & Technology

Cybersecurity Expert Calls for Increased Penetration Testing

Published

on

[ad_1]

Keith Poyser: “Blind faith in cyber defence systems without constantly putting them to the test is naive.”

London, October 22 2024 – Penetration testing, i.e. the self-assessment of a company’s IT infrastructure to test its cyber resilience, is too often neglected in the business world, warns Keith Poyser, Vice President for EMEA at security company Horizon3.ai. He explains: “You only know how resilient an IT network really is to cyberattacks if you put it to the test. Only penetration tests can determine whether hackers can penetrate from the outside or whether an organisation is actually protected against cyber criminals.”

The security expert cites findings from the Government’s Cyber Security Breaches Survey 2024, which reveals that 50% of businesses experienced a cyber breach or attack in the past 12 months—a figure that climbs to 70% for medium businesses and 74% for large enterprises. While over 70% of organisations have implemented key security measures such as anti-malware, EDR, DLP, password policies, backups and firewalls, Poyser warns that they underestimate how easily cyber criminals can bypass these defences by exploiting vulnerabilities through social engineering, unpatched software, misconfigurations, poor credential security, and insider threats.

He adds: “Many organisations rely on dozens of cyber defence tools, assuming they are fully protected against external and internal attacks. But this is like flying blind, trusting that everything will work perfectly without active testing. And human led testing only delivers a static snapshot, of a small part of the estate. It may work in calm conditions, but it’s naive to think that a purely defensive strategy can withstand the relentless and evolving nature of modern cyber threats.” The security expert urges organisations to adopt a more proactive, automated penetration testing approach in defending against cyber attacks. By doing so, companies can better safeguard their systems, ensure best ROI from their existing investments, and show their boards they are “more secure this week than last week” to meet compliance and regulatory requirements.

Keith Poyser: “Human Risk Is Often Neglected”

According to the Government’s Cyber Security Breaches Survey 2024, a staggering 95% of cyberattacks succeed because of human error – whether it’s opening phishing emails or using weak passwords. While identifying technical vulnerabilities and software flaws is critical, neglecting the human factor leaves organisations equally exposed. Both technical and human vulnerabilities must be addressed to ensure a comprehensive cyber defence. Keith Poyser explains: “Hackers generally analyse all
publicly available information about a company, its employees and even former employees on social networks, for example, in order to track down security-relevant information.”

Furthermore, he cites “configuration errors due to ignorance or oversight in the defence systems” as another frequently encountered consequence of human weaknesses. “With a myriad of security programmes running at the same time, organisations have often lost track of their associated configurations. The need to constantly update security software alone can be overwhelming for many corporate IT teams, not so much in terms of expertise, but in terms of workload. With each update, the entire configuration has to be re-examined, as the interaction of different systems can lead to new vulnerabilities as soon as one component changes even slightly.”

Given the significant effort required, Poyser recommends that organisations adopt autonomous penetration testing platforms, as they are safer and more cost-effective than relying on traditional teams of experts. He clarifies: “Of course, we still need as many highly qualified specialists as possible, but at the same time we need to increase the level of automation in penetration testing as much as possible in order to cope with the constantly growing threat situation.”

This recommendation is closely aligned with Poyser’s work at Horizon3.ai, which offers NodeZero, a cloud-based penetration testing platform. This solution enables companies to conduct simulated cyberattacks on their internal, external, cloud, and hybrid IT infrastructures, providing a comprehensive assessment of their cyber resilience.

Even the ‘Demilitarised Zone’ Is No Longer Safe

The frequency and depth of penetration testing are crucial to a robust cybersecurity strategy. It’s not just the external perimeter of IT networks that requires comprehensive testing, but also the internal security. The security expert explains: “With remote work, the Internet of Things, and mobile access, more devices are connecting to company networks from external locations, increasing the potential attack surface. Modern security strategies must assume that hackers will breach the outer defences and gain initial access to a network segment, from which they can then launch internal attacks.”

Even the so-called ‘demilitarised zone’ (DMZ), which is considered particularly trustworthy because it is shielded several times from other network segments, can no longer be classified as a secure area in Poyser’s experience. “A modern penetration test can examine the entire company network in all its ramifications, internal, external and cloud attack surfaces” he emphasises. “It’s not just about identifying vulnerabilities, but also assessing their potential impact. For instance, if a break-in to the DMZ exposes the entire network to a hacker, a thorough penetration test will highlight this risk, allowing for immediate and targeted remediation. Repeated automated tests will allow you to find, fix and verify.”

A Shift in Perspective: The Key to Effective Security

While achieving 100% protection is impossible, this era of machine speed attacks means traditional approaches won’t solve the problem. Simply upgrading defence systems isn’t enough though. To truly safeguard against evolving threats, organisations are advised to regularly assess their security through ongoing machine speed, automated penetration tests. Only by continuously testing and evaluating their defences can organisations stay one step ahead and ensure their systems remain secure, reducing risk and cost.

Poyser, Vice President for EMEA at security company Horizon3.ai, urges companies to “conduct penetration tests regularly to consistently monitor and strengthen their cyber resilience.” He adds, “I recommend that every board member, managing director, and IT manager across all industries subject their company to this critical assessment, given the current threat landscape.”

* https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024/cyber-security-breaches-survey-2024

About Horizon3.ai and NodeZero™: Horizon3.ai’s NodeZero™ Autonomous Security Platform offers integrated threat detection, autonomous pentesting, third-party risk management, and comprehensive governance, risk, and compliance (GRC) insights. It enhances organisational security by proactively identifying and remediating exploitable vulnerabilities, while strategically deploying deception and threat detection through NodeZero Tripwires™. Founded in 2019 by former industry leaders and U.S. National Security veterans, Horizon3.ai is at the forefront of cybersecurity innovation. Request a free demonstration at: www.horizon3.ai.

Trademark notice: NodeZero is a trademark of Horizon3.ai

Further information:
Horizon3.AI Europe GmbH, Sebastian-Kneipp-Str. 41, 60439 Frankfurt am Main, Web: www.horizon3.ai

PR Agency: euromarcom public relations GmbH, Tel. +49 611 973150, Web: www.euromarcom.de, E-Mail: [email protected]

[ad_2]

Source link

Science & Technology

Quantum Computing Breakthrough: Data Security Implications

MIT’s new quantum algorithm could revolutionize data processing, posing significant challenges for current cryptographic systems. This article explores the implications for data security and potential solutions to counteract quantum threats.

Published

on

The recent breakthrough in quantum computing by researchers at MIT marks a pivotal moment in the field of data security. On August 19, 2026, Nature published the details of a new quantum algorithm capable of processing data at speeds previously unimaginable. While this innovation holds enormous potential for advancing machine learning and other computational fields, it simultaneously presents a formidable challenge to the current cryptographic systems relied upon to safeguard sensitive information.

At the core of contemporary data security is the reliance on encryption techniques that depend on the complexity of certain mathematical problems, such as the factoring of large numbers, which are currently infeasible for classical computers to solve within a practical timeframe. However, quantum computers, with their ability to perform calculations exponentially faster than traditional machines, threaten to render these encryption methods obsolete. This development could have profound implications for sectors that prioritize data security, including finance, healthcare, and government, where sensitive data is at risk of exposure.

The immediate concern for cybersecurity experts is the potential for quantum computers to crack widely used encryption protocols, such as RSA and ECC, which form the backbone of secure internet communications. The computational power unleashed by quantum algorithms could theoretically decrypt encrypted data in a fraction of the time required by classical computers, leaving digital communications vulnerable to interception and exploitation.

In response to this looming threat, researchers and industry experts are actively exploring the development of quantum-resistant algorithms. These algorithms are designed to withstand the capabilities of quantum computing, ensuring the confidentiality and integrity of data even in a post-quantum world. Efforts in this direction include the study of lattice-based cryptography, hash-based signatures, and multivariate polynomial equations as potential foundations for secure encryption systems.

The urgency to develop and implement quantum-resistant cryptography is underscored by the rapid pace of advancements in quantum technology. Tech companies, governments, and academic institutions are investing heavily in research to safeguard their data infrastructures against quantum threats. The transition to quantum-resistant systems, however, is not without its challenges. It requires a comprehensive overhaul of existing cryptographic frameworks and widespread adoption across industries, a process that demands both time and resources.

Despite these challenges, the potential benefits of quantum computing in fields such as artificial intelligence, pharmaceuticals, and materials science cannot be overlooked. The same capabilities that pose a threat to data security also offer the promise of unprecedented advancements in computational power, enabling breakthroughs that were previously beyond reach.

As the world stands on the brink of a quantum revolution, the dual-edged nature of this technological leap is clear. While the security of our digital world faces new threats, the opportunity for innovation and progress is equally profound. The path forward will require a concerted effort to balance the risks and rewards of quantum computing, ensuring that the transformative potential of this technology is harnessed responsibly and securely.

In the coming years, as quantum technologies continue to evolve, the focus will be on developing robust standards for quantum-resistant cryptography and fostering collaboration between academia, industry, and government to navigate this new frontier. The race to secure our digital future in the face of quantum capabilities is not just a technical challenge but a strategic imperative that will shape the landscape of cybersecurity for decades to come.

Continue Reading

Science & Technology

AI-Driven Tools Propel Mars Exploration to New Heights

NASA’s latest Mars mission features AI-driven tools in its rover, enabling autonomous navigation and faster data transmission, marking a significant advancement in space exploration technology.

Published

on

NASA’s latest mission to Mars has captivated both scientific communities and the public, as the new rover equipped with AI-driven exploration tools begins its journey across the Martian landscape. Wired’s August 2026 report highlights the rover’s ability to autonomously navigate the challenging terrain while making real-time decisions, significantly enhancing the efficiency of data collection. This innovation is poised to revolutionize the way robotic missions are conducted in space.

The rover’s sophisticated communication systems represent another leap forward, allowing for faster and more reliable data transmission back to Earth. These advancements mean that scientists can receive critical information more swiftly, enabling them to adjust mission parameters as needed. According to Wired, this capability is essential for responding to unexpected findings and maximizing the scientific value of each mission.

Moreover, the integration of AI tools in the rover’s design marks a pivotal shift towards reducing dependence on Earth-based commands. As Wired notes, this development could pave the way for future missions that operate with greater autonomy, setting the stage for more complex and prolonged explorations of Mars. The implications of this technology extend beyond current missions, suggesting a future where human exploration of Mars is supported by highly capable robotic counterparts.

As NASA continues to push the boundaries of space exploration, the success of this mission will likely influence the design and execution of future endeavors. The potential for these AI-driven tools to transform space exploration is immense, promising a new era of discovery and innovation on the red planet and beyond.

Continue Reading

Science & Technology

Quantum Computing Breakthroughs: Disrupting Industries with Oxford’s Innovations

A recent breakthrough in quantum computing at the University of Oxford promises to disrupt multiple industries by significantly enhancing computational capabilities. Explore the technological implications and potential disruptions poised to redefine sectors.

Published

on

In May 2026, the University of Oxford announced a significant breakthrough in the field of quantum computing, unveiling an advanced error correction algorithm that has the potential to transform computational capabilities. This development is not just a scientific triumph; it heralds a new era of technological disruption across multiple industries. Quantum computing, long anticipated as the next frontier in technology, promises to solve complex problems beyond the reach of classical computers, and Oxford’s latest advancement brings this closer to reality.

At the core of this breakthrough is the enhancement in quantum error correction, a critical component that addresses the inherent instability of qubits, which are the fundamental units of quantum information. Traditional computers use bits of 0s and 1s, but quantum computers operate on qubits, which can exist in multiple states simultaneously. This superposition allows quantum computers to process information exponentially faster than classical computers. However, qubits are notoriously prone to errors due to environmental noise and operational inaccuracies. Oxford’s new algorithm significantly improves the error correction process, maintaining qubit stability longer and allowing extended computational tasks to be performed accurately.

The implications of this are profound. Industries ranging from pharmaceuticals to finance stand on the cusp of disruption as quantum computing offers the ability to model complex molecular structures, optimize large-scale financial portfolios, and even revolutionize artificial intelligence algorithms. In pharmaceuticals, for example, quantum computing can expedite drug discovery by accurately simulating molecular interactions, potentially reducing the time and cost associated with bringing new drugs to market. Similarly, in finance, quantum algorithms can optimize trading strategies and risk management with a precision unattainable by current technologies.

Moreover, the ripple effects of such a leap in computational power extend to data encryption and cybersecurity. Quantum computers possess the potential to decrypt classical encryption methods, prompting a race for quantum-resistant cryptography. This necessitates a paradigm shift in how we secure digital information, affecting every sector that relies on data security.

Despite the tremendous promise, the transition to quantum computing is not without its challenges. The infrastructure required to support quantum technologies is expensive and complex. There is also a significant skills gap; experts in quantum computing are scarce, and training a new generation of scientists and engineers is imperative. Furthermore, ethical considerations regarding the power of quantum computing must be addressed, particularly in terms of privacy and security.

Looking forward, as quantum computing continues to evolve, industries will need to adapt swiftly to harness its capabilities. Early adopters who invest in quantum technologies and develop quantum-ready strategies will likely dominate in the coming decade. As Oxford’s breakthrough demonstrates, the race is on to fully realize the potential of quantum computing and redefine the boundaries of what is technologically possible.

Continue Reading

Trending