Connect with us

Science & Technology

UK Companies Face Increasing Cyber Security Risks Across a Range of Threats, New Report Reveals

Published

on

[ad_1]

  • ‘Cyber Security Report 2024/2025’ by Horizon3.ai for the United Kingdom
  • “Thinking that software can be made completely invulnerable or that conventional cyber security defences are sufficient is a common misjudgement,” warns cyber security expert Keith Poyser. “Most organisations today use dozens, if not hundreds, of software applications and solutions, creating an expansive attack surface. A vulnerability remains harmless only until a hacker uncovers how to exploit it. Real world exploitable vulnerabilities are chained together to form effective attack paths, with clear business impact. This very real risk presents numerous potential threats, underscoring the importance for companies to strengthen their defences before an attack occurs, across all attack surfaces…and that means testing from an attacker’s perspective.”

London, December 16 2024 – Hackers employ a wide range of tactics, techniques, and procedures to exploit vulnerabilities in software. At the same time, they use targeted phishing attacks, third-party data breaches, and open-source information (OSINT) to gain access to a user’s credentials, which can provide the much needed gateway to valuable systems and data. This is a key takeaway from the “Cyber Security Report UK 2024/25” by Horizon3.ai, which surveyed 150 organisations across the United Kingdom. The findings reveal that almost half of these organisations (48%) regard stolen user and admin credentials as one of the most significant cyber security threats they face. Additionally, an overwhelming 42% of respondents (who could select multiple threats) identify insufficiently secured data and/or unknown data stores as a significant potential risk to their organisations.

Another key finding reveals that more than a quarter (29%) of companies consider attacks via unpatched but known security vulnerabilities in corporate networks to be a major threat. These are software vulnerabilities that are already known, with a patch available from the vendor, but have yet to be patched by the companies using the software. An additional 27% are concerned about incorrectly configured software and/or hardware devices as a source of potential risk to their organisations. “These issues are a prime opportunity for cybercriminals. At the end of the day, a considerable proportion of the successful cyberattacks are the result of human error,” Keith Poyser, Vice President for EMEA at cyber security company Horizon3.ai, explains.

Penetration Testing as a Solution to Cyber Threats

“With hundreds of programmes in use, most organisations can no longer keep up with the vulnerabilities being discovered in the software they use, plus the other security gaps that emerge almost daily,” says Poyser. To address this, he recommends continuous penetration testing—self-assessments of an organisation’s infrastructure to identify vulnerabilities and other weaknesses in advance. According to the survey, nearly a third of organisations (32%) do not conduct penetration tests. “Autonomous penetration tests are easy to implement, cost-effective, and most importantly, proactively test your environment from an attacker’s perspective —exactly what is needed in the face of the rapidly increasing cybercrime threat,” argues Poyser.

The “Cyber Security Report UK 2024/25” underscores the growing severity of cyber threats: 69% of the companies surveyed revealed they had fallen victim to a cyberattack at least once in the past two years. The survey, which gathered insights from 150 executives and IT professionals, covers a diverse range of industries and critical infrastructures, including telecommunications, manufacturing, automotive, healthcare, education, and research.

Diverse Cyber Threats Pose Growing Challenges to Organisations

Other potential threats identified by the surveyed executives include: Zero-day and/or N-day vulnerabilities (20%), poor or inadequate security controls (16%), shadow IT—using software or hardware unknown to the company’s IT team (14%), weak and/or unenforced security policies (5%), insufficient security budgets (4%), and little or no attention to security (2%).

“Managers are recognising that a combination of cyber risks within their organisations is becoming increasingly difficult to manage,” says security expert Keith Poyser. In his view, a a solution is clear: “Companies must regularly test the security of their IT infrastructures through self-initiated attacks in the form of continuous, autonomous penetration testing that focuses on real world exploitable attack paths, prioritises, shows remediation and then verifies that the attack path is fixed. Simulation and vulnerability scanning had their place, but real world, production environment testing is what is needed for modern threats.”

Cyberattacks Threaten Business Continuity and Financial Stability

“It is no surprise that Richard Horne of the NCSC recently issued such a stark warning on cyber security,” says Poyser. The new CEO of the National Cyber Security Centre (NCSC) said in a recent speech that cyber risk in the UK is “widely underestimated” and that the gap between the exposure and threat we face and the defenses that are in place to protect us is widening. “The increasing frequency and complexity of these attacks highlights the urgent need for organisations to strengthen their cyber security defences and remediate exploitable weaknesses to protect themselves from financial and reputational damage,” adds Poyser.

If critical data falls into the hands of cybercriminals, it can result in major outages and significant financial losses. This is evident as 62% and 54% of surveyed companies reported experiencing downtime and ransom demands, respectively. Additionally, the costs associated with data recovery are considerable, alongside the extra workload and potential legal ramifications for the business. Data breaches are especially damaging to critical infrastructures, as they can compromise the functionality of vital systems.

Majority of Companies Underequipped Against Attacks

Shocking 66% of the surveyed companies admitted that they have little to no adequate protection against cyberattacks, while only 17% have taken measures but consider them insufficient. Just 9% were confident that their protection against cyberattacks is complete.

“These results show that while awareness of the importance of robust protection against cyberattacks is growing, resources to meet the challenge are often lacking. For years, cyber security has been defined by defensive and reactive measures that are simply too slow in an environment of aggressive, increasingly AI-driven cyberattacks,” says Keith Poyser. Instead, the security expert is urging organisations to adopt a more proactive approach in order to stay one step ahead of cybercriminals. This is the only way companies can effectively protect their systems and deal with the ever-growing threats in cyberspace.

About Horizon3.ai and NodeZero: Horizon3.ai provides a cloud-based platform, NodeZero, enabling organisations and public authorities to simulate self-assessments on their IT infrastructure to assess their cyber resilience through penetration testing (pentesting). Thanks to its cloud model, the platform offers affordable, regular pentesting, making it accessible to mid-sized companies. Horizon3.ai continuously monitors the cybercrime landscape to ensure that newly discovered vulnerabilities are swiftly integrated into the cloud system. NodeZero not only identifies security flaws but also offers tailored recommendations for remediation. Through this platform, Horizon3.ai helps organisations meet rising regulatory demands for cyber resilience in Governance, Risk & Compliance (GRC), with guidelines recommending an internal self-assessment at least once a week.

Trademark notice: NodeZero is a trademark of Horizon3.ai

Further information:
Horizon3.AI Europe GmbH, Sebastian-Kneipp-Str. 41, 60439 Frankfurt am Main, Web: www.horizon3.ai

PR Agency: euromarcom public relations GmbH, Tel. +49 611 973150, Web: www.euromarcom.de, E-Mail: [email protected]

[ad_2]

Source link

Science & Technology

Breakthroughs and Challenges: The Latest in Scientific Advancements

A roundup of the latest scientific advancements, exploring breakthroughs and the challenges that lie ahead.

Published

on

In a notable development, Dr. Emily Carter, a leading researcher at the National Institute of Health, announced a significant breakthrough in the field of gene therapy. On September 10, 2026, she revealed that her team successfully edited genes in living organisms to eliminate hereditary diseases. This advancement holds the potential to revolutionize medical treatment, offering hope to millions suffering from genetic disorders. However, it also raises ethical concerns about the extent of human genetic modification and its long-term impacts.

Simultaneously, the European Space Agency (ESA) has made strides in space exploration with the launch of its latest satellite, Euclid. Launched on September 8, 2026, Euclid aims to map the universe’s dark matter and dark energy, key components that constitute most of the cosmos. This mission could unravel the mysteries of the universe’s expansion and provide insights into the fundamental nature of existence. The ESA emphasizes the importance of international collaboration in this endeavor, as understanding dark matter and energy requires global scientific cooperation.

In the realm of renewable energy, SolarTech Innovations reported a breakthrough in solar panel efficiency on September 12, 2026. Their new technology purportedly increases the energy conversion rate by 25%, potentially transforming the solar energy industry. This advancement could accelerate the shift towards sustainable energy sources, reducing reliance on fossil fuels. However, questions remain about the scalability of this technology and its economic viability for widespread adoption.

Meanwhile, the agricultural sector witnessed a milestone with AgriBio’s development of drought-resistant crops. Announced on September 7, 2026, these genetically engineered plants could enhance food security in regions prone to extreme weather conditions. The company states that these crops can withstand prolonged periods without water, ensuring stable yields. Critics, however, caution about the ecological implications and the potential for unintended consequences on biodiversity.

Lastly, the tech industry is abuzz with the unveiling of QuantumNext’s quantum computing system. Revealed on September 11, 2026, this system reportedly performs calculations at unprecedented speeds, paving the way for advancements in fields like cryptography and complex data analysis. While the potential applications are vast, experts debate the readiness of existing infrastructure to support such technology and the security challenges it may pose.

These scientific advancements highlight the dynamic nature of innovation and the diverse challenges accompanying progress. Each breakthrough presents a spectrum of opportunities and ethical dilemmas that require careful consideration. As these developments unfold, stakeholders from various sectors must engage in dialogue to navigate the complexities they entail.

Looking forward, the scientific community faces the task of addressing the practical and ethical questions these innovations raise. Continued research, open discourse, and policy-making will be crucial in harnessing the benefits of these advancements while mitigating their risks. The next few months will likely see increased scrutiny and discussion as these technologies move from the laboratory to real-world applications.

Continue Reading

Science & Technology

Momentum Builds to Curb AI Development Amid Safety Concerns

Tech leaders advocate for slowing AI progress to mitigate risks and ensure safety.

Published

on

On September 13, 2026, Elon Musk made headlines once more, but this time it wasn’t about electric cars or space exploration. Musk, along with OpenAI co-founder Sam Altman and Anthropic CEO Dario Amodei, has taken a stand urging for a slowdown in the rapid development of artificial intelligence. The trio’s call to action reflects a burgeoning movement within the technology community. The aim is to ensure that AI advancement does not outpace the necessary safety measures that must be in place to protect society. Musk, known for his outspoken concerns regarding AI, has been vocal about the potential existential threats posed by unchecked AI development. His stance is not without precedent. In past years, he has been an advocate for AI regulation, emphasizing the importance of establishing robust safety protocols. Sam Altman shares this concern. As a key figure in AI innovation, Altman’s support for decelerating AI progress highlights the industry’s internal awareness of its own vulnerabilities. Altman has been instrumental in shaping AI discussions, both as a developer and a policymaker. His involvement underscores a critical shift in perspective among those who once championed AI’s limitless potential.

Dario Amodei’s call for a slowdown adds another layer of urgency. As CEO of Anthropic, Amodei’s insights into AI’s capabilities are profound. He has long advocated for responsible AI development, emphasizing research into AI safety and alignment. His company, Anthropic, is at the forefront of AI safety research, making his voice particularly influential. Amodei’s concerns are grounded in the belief that AI systems need to be designed with alignment and transparency as core principles. The consensus among these leaders is clear. The pace of AI development must be moderated to prevent potential societal disruptions. The public discourse around AI safety has evolved significantly over the past few years. Initially, concerns were often dismissed as speculative or alarmist. However, as AI systems become more integrated into daily life, their impact is undeniable. From autonomous vehicles to intelligent personal assistants, AI technologies influence countless aspects of modern existence. The rapid integration has outpaced regulatory frameworks, leaving gaps that could potentially be exploited.

This movement to slow AI development is gaining traction within the tech community. It reflects a deeper understanding of the potential risks and ethical considerations that come with advanced AI systems. Industry leaders are increasingly aware of their responsibility to mitigate these risks. There is a growing consensus that more comprehensive safety measures and regulatory oversight are necessary. The call for a slowdown is not a demand to halt innovation. Rather, it is a plea for a more deliberate approach to AI development. The goal is to establish a regulatory framework that prioritizes safety, ethical considerations, and long-term societal impact. This approach seeks to ensure that AI technologies are developed responsibly and with foresight. The motivation behind this push is multifaceted. At its core is the desire to prevent unintended consequences that could arise from unchecked AI advancement. These include potential job displacement, privacy concerns, and the risk of AI systems being used for malicious purposes. The tech industry is increasingly aware that the societal implications of AI are vast and complex. There is a recognition that addressing these challenges requires collaboration across sectors and disciplines.

The momentum to slow AI development also reflects a shift in how technology leaders view their role in society. There is a growing acknowledgment that technological innovation must be balanced with ethical responsibility. This recognition is driving the call for more stringent safety protocols and regulatory oversight. As the debate around AI continues, the voices advocating for caution are becoming more prominent. The movement is gaining momentum, supported by influential figures and organizations committed to ensuring that AI development proceeds safely and responsibly. The challenge now is translating this momentum into actionable policies and frameworks. Governments and regulatory bodies must work closely with industry leaders to develop comprehensive guidelines that address the unique challenges posed by AI. This collaboration is essential to fostering innovation while safeguarding societal interests. The path forward requires a collective effort to balance progress with prudence. As AI continues to evolve, the need for thoughtful and responsible development becomes increasingly critical. The calls to slow down AI development are a testament to the industry’s commitment to navigating this complex terrain with care.

The journey ahead is not without challenges. Implementing effective regulatory measures will require cooperation and consensus among diverse stakeholders. However, the growing momentum to address AI safety concerns offers hope for a future where technological advancement is aligned with societal well-being. As industry leaders and policymakers work together, there is potential to shape a future where AI technologies enhance, rather than disrupt, the fabric of society. The commitment to responsible AI development is key to ensuring that AI technologies are harnessed for the greater good. This forward-thinking approach will be crucial in defining the next chapter of AI innovation. The momentum to slow down AI development is more than a precautionary measure. It is a strategic decision to prioritize safety, ethics, and long-term impact. As the conversation around AI continues to evolve, the focus on responsible development will remain at the forefront. The future of AI depends on the choices made today. By embracing a more measured approach, the tech community can pave the way for a future where AI serves humanity’s best interests.

Continue Reading

Science & Technology

Quantum Computing Breakthrough: Data Security Implications

MIT’s new quantum algorithm could revolutionize data processing, posing significant challenges for current cryptographic systems. This article explores the implications for data security and potential solutions to counteract quantum threats.

Published

on

The recent breakthrough in quantum computing by researchers at MIT marks a pivotal moment in the field of data security. On August 19, 2026, Nature published the details of a new quantum algorithm capable of processing data at speeds previously unimaginable. While this innovation holds enormous potential for advancing machine learning and other computational fields, it simultaneously presents a formidable challenge to the current cryptographic systems relied upon to safeguard sensitive information.

At the core of contemporary data security is the reliance on encryption techniques that depend on the complexity of certain mathematical problems, such as the factoring of large numbers, which are currently infeasible for classical computers to solve within a practical timeframe. However, quantum computers, with their ability to perform calculations exponentially faster than traditional machines, threaten to render these encryption methods obsolete. This development could have profound implications for sectors that prioritize data security, including finance, healthcare, and government, where sensitive data is at risk of exposure.

The immediate concern for cybersecurity experts is the potential for quantum computers to crack widely used encryption protocols, such as RSA and ECC, which form the backbone of secure internet communications. The computational power unleashed by quantum algorithms could theoretically decrypt encrypted data in a fraction of the time required by classical computers, leaving digital communications vulnerable to interception and exploitation.

In response to this looming threat, researchers and industry experts are actively exploring the development of quantum-resistant algorithms. These algorithms are designed to withstand the capabilities of quantum computing, ensuring the confidentiality and integrity of data even in a post-quantum world. Efforts in this direction include the study of lattice-based cryptography, hash-based signatures, and multivariate polynomial equations as potential foundations for secure encryption systems.

The urgency to develop and implement quantum-resistant cryptography is underscored by the rapid pace of advancements in quantum technology. Tech companies, governments, and academic institutions are investing heavily in research to safeguard their data infrastructures against quantum threats. The transition to quantum-resistant systems, however, is not without its challenges. It requires a comprehensive overhaul of existing cryptographic frameworks and widespread adoption across industries, a process that demands both time and resources.

Despite these challenges, the potential benefits of quantum computing in fields such as artificial intelligence, pharmaceuticals, and materials science cannot be overlooked. The same capabilities that pose a threat to data security also offer the promise of unprecedented advancements in computational power, enabling breakthroughs that were previously beyond reach.

As the world stands on the brink of a quantum revolution, the dual-edged nature of this technological leap is clear. While the security of our digital world faces new threats, the opportunity for innovation and progress is equally profound. The path forward will require a concerted effort to balance the risks and rewards of quantum computing, ensuring that the transformative potential of this technology is harnessed responsibly and securely.

In the coming years, as quantum technologies continue to evolve, the focus will be on developing robust standards for quantum-resistant cryptography and fostering collaboration between academia, industry, and government to navigate this new frontier. The race to secure our digital future in the face of quantum capabilities is not just a technical challenge but a strategic imperative that will shape the landscape of cybersecurity for decades to come.

Continue Reading

Trending