Upgrade to Pro — share decks privately, control downloads, hide ads and more …

ScotSecure West 2026 - Glasgow

Avatar for Ray Bugg Ray Bugg
September 22, 2026

ScotSecure West 2026 - Glasgow

Scotland’s largest annual cyber security summit will host a sister event in Glasgow, Scot-Secure West, for the 4th year running. The event brings together senior InfoSec personnel, IT leaders, academics, security researchers and law enforcement, providing a unique forum for knowledge exchange, discussion and high-level networking.

The programme is focused on improving awareness and best practices through shared learning: highlighting emerging threats, new research and changing adversarial tactics, and examining practical ways to improve resilience, detection and response.

This event is geared towards InfoSec & IT personnel and C-suite leaders.

Avatar for Ray Bugg

Ray Bugg

September 22, 2026

Other Decks in Technology

Transcript

  1. Secure by Design Putting People First Why secure by design

    programmes succeed or fail on human behaviour Kathryn Pimblett 1
  2. Secure by Design ‘An approach to incorporate cyber security practices

    into digital delivery from the start and consistently throughout the service lifecycle.’ UK Government Cyber Unit 94% 26% Secure by Design very or extremely important* Implementation too time consuming The theory is compelling, the tools are maturing, so why is implementation still so difficult? *Bitwarden Developer Survey 2024: Decoding Tomorrow: Developer Secrets, Security and the Future of Passkeys 2
  3. Hello! • Senior Cyber Manager • Cognitive and Organisational Psychologist

    • Former Defence and Security Analyst • 20+ years of experience applying behavioural science to solve complex problems 2
  4. The five things I’ve learned about making Secure by Design

    Work 01 Build capability 02 Design for reality 03 Make security actionable 04 Make the value visible 05 Measure and reward the behaviour you actually want 5
  5. The secure development skills gap Computer Science and Software Engineering

    education does not consistently equip graduates with the skills needed to develop secure software.* Implications: • Organisations need an honest appraisal of their developers’ security skills, and strategies to augment them (training; champions networks; outreach) • As an industry we should be lobbying academia to address this issue Don't blame the developer. Close the gap. *Lam et al., (2022), Identifying Gaps in the Secure Programming Knowledge and Skills of Students 7
  6. Design for the work people actually do* Delivery teams operate

    under deadlines, dependencies, legacy systems and competing priorities. Implications: • Observe the workflow. Talk to developers. Watch where people have to make choices and work around friction. • Remember that if telling the security team about a problem gets you in trouble, people will hide problems from the security team. Outreach isn’t a communications exercise. Trust is a security control. *Hollnagel, E. (2012), Resilience Engineering and the systemic view of safety at work. Why work-as-done is not the same as work as imagined. 10
  7. Communication must always answer 3 questions: 01 02 03 What

    do you want me to do? Why does it matter? How do I actually do it? “AI may expose confidential information and create regulatory, reputational and security risks.” + “Don't paste company data into public AI tools. Only use company data [definitions here] with our approved enterprise AI service [here] for” 14
  8. Frame the impact of security interventions around what people actually

    care about Security teams says: “This reduces cyber risk.” Delivery teams hear: “More work, more gates and slower delivery.” Instead try: 71% 599 $17K Fewer vulnerabilities introduced into repos post-training Hours of dev time per annum in subsequent vulnerability remediation Associated in-year cost saving
  9. 05 Measure and reward the behaviour you actually want Metrics

    don't just report behaviour — they drive it. 19
  10. What behaviour are your security metrics rewarding? The key question:

    If this metric became someone's target, what would they optimise for? Pitfalls to avoid: • Point in time metrics • Lack of triangulation • Closing the ticket vs fixing the problem 21
  11. Key take aways Secure by Design is a behavioural change

    programme disguised as a technology programme Set yourself up for success by: • Teaching people what good looks like and the hands-on skills to deliver it. • Understanding the environment in which they work. • Making the secure behaviour easy and actionable. • Showing why it matters to the business. • Rewarding and measuring the behaviour you actually want. 23
  12. FOLLOWING THE ELEPHANT LINES What cyber and information security can

    learn from how people actually work Stephanie Perry | Group CISO Babcock International
  13. THE CONCEPT Designed behaviour versus actual behaviour A desire line

    is a visible record of where design and human need diverge. DESIGNED PATH ELEPHANT LINE Policy Workaround Approved process Shortcut Intended workflow Operational reality Compliance view Human view Every elephant line tells a story about friction. FOLLOWING THE ELEPHANT LINES CY BER & INF O R M AT IO N S ECU R IT Y 28
  14. THE HUMAN CONTEXT Most people are not trying to do

    the wrong thing They are trying to deliver an outcome under pressure. 1 TIME PRESSURE Urgent delivery and fixed deadlines 2 PRODUCTIVITY A faster route to complete the task 3 SERVICE FRICTION Approvals, access or tooling that feel too hard 4 LOCAL OPTIMISATION Solving today’s problem without seeing enterprise risk WORKAROUND LIKELIHOOD = SECURITY FRICTION × BUSINESS PRESSURE FOLLOWING THE ELEPHANT LINES CY BER & INF O R M AT IO N S ECU R IT Y 29
  15. THE EVIDENCE Common cyber elephant lines These behaviours appear when

    the approved route does not meet the operational need. SHADOW IT PERSONAL DEVICES UNSANCTIONED AI SHARED ACCESS “The approved platform is too difficult.” “I need to finish this from home.” “The approved tool cannot do what I need.” “A common account keeps the shift moving.” A PROCESS PROBLEM → before it becomes → A SECURITY INCIDENT FOLLOWING THE ELEPHANT LINES CY BER & INF O R M AT IO N S ECU R IT Y 30
  16. THE TRADITIONAL RESPONSE Why fighting the line often fails More

    control can move the behaviour underground rather than remove the need. THE INSTINCT Add policy. Add approval. Add monitoring. Add enforcement. CONTROL MORE FRICTION LESS VISIBILITY WIDER WORKAROUND The organisation usually finds a way around badly designed security. FOLLOWING THE ELEPHANT LINES CY BER & INF O R M AT IO N S ECU R IT Y 31
  17. REFRAME THE SIGNAL Elephant lines are intelligence Move from asking

    who broke the rule to asking what the behaviour reveals. 01 USER EXPERIENCE Where is the secure route unnecessarily hard? 02 PROCESS Where do approvals or hand-offs create delay? 03 TECHNOLOGY What capability is missing or unsuitable? 04 RISK Which workarounds are becoming normalised? CONTROL OWNER → BEHAVIOUR OBSERVER → SERVICE DESIGNER FOLLOWING THE ELEPHANT LINES CY BER & INF O R M AT IO N S ECU R IT Y 32
  18. REGULATED ENVIRONMENTS Secure by design must also be usable by

    design A documented control is not effective if people cannot apply it in operational reality. MISSION OUTCOME RISK-INFORMED DECISIONS EFFECTIVE CONTROL PRACTICAL ADOPTION ASSURANCE EVIDENCE Designed for the threat, the obligation and the user. FOLLOWING THE ELEPHANT LINES CY BER & INF O R M AT IO N S ECU R IT Y 33
  19. REGULATED ENVIRONMENTS Secure by design in the real world You

    want your most secure business process to follow the concept of airport security control – appropriate control for the level of risk 1 RULES ARE CLEAR 2 NO DEVIATION FROM PROCESS 3 COMPLIANCE IS ENFORCED 4 CHECKS ENSURE ASSURANCE FOLLOWING THE ELEPHANT LINES CY BER & INF O R M AT IO N S ECU R IT Y 34
  20. REGULATED ENVIRONMENTS Secure by design in the real world You

    don’t want it to look like the front row of a festival …. FOLLOWING THE ELEPHANT LINES CY BER & INF O R M AT IO N S ECU R IT Y 35
  21. THE EMERGING TEST AI is creating new desire lines at

    pace Demand for speed and capability can outrun approved services and governance. T H E B U S I NE S S N E E D Summarise Research Draft Analyse IF THE APPROVED ROUTE CANNOT MEET IT Personal accounts • Sensitive prompts • Uncontrolled tools Build the safe path before the shadow path becomes normal. FOLLOWING THE ELEPHANT LINES CY BER & INF O R M AT IO N S ECU R IT Y 36
  22. LEADERSHIP RESPONSE Turn desire lines into a control improvement loop

    Observe the actual route, understand the need, then redesign and measure. 1 2 3 4 5 OBSERVE MEASURE FRICTION CO-DESIGN CREATE THE SAFE PATH MONITOR & ADAPT Use incidents, service data and frontline feedback. Identify delay, duplication and repeated exceptions. Build controls with the people who operate them. Make the secure route the easiest credible route. Test whether behaviour and risk actually change. SUCCESS = fewer hidden workarounds • faster secure delivery • improved control evidence FOLLOWING THE ELEPHANT LINES CY BER & INF O R M AT IO N S ECU R IT Y 37
  23. FOLLOW THE ELEPHANT LINES The most important security signals are

    not always in the dashboard. They are often in the shortcuts people take every day. ASK: Where are our elephant lines? What are they telling us? What should we redesign?
  24. Closing the Identity Blind Spots Across Humans, Machines, and AI

    Why a Privilege-Centric approach to Identity Security is needed. Lee Elliott – Dir, Solutions Engineering, BeyondTrust ©BEYONDTRUST 2026 | 40
  25. The Elephant Parable Man at Trunk Man at Tail Man

    at Leg Man at Body Each man holds a piece. No one holds the whole. With no common language the pieces don’t fit. ©BEYONDTRUST 2026 | 42
  26. Today’s Identity Reality Who is responsible for Identity Risk? IAM?

    PAM? Cloud? Security? ©BEYONDTRUST 2026 | 43
  27. The Identity Elephant IAM PAM Cloud Security Security Each team

    holds a piece. No one holds the whole. With no common language the pieces don’t fit. ©BEYONDTRUST 2026 | 44
  28. Everyone protects a piece. Nobody secures the whole. IAM protects

    Authentication PAM Secures Human Privileged Access IMPACT ELEVATION INITIAL ACCESS The gaps between silos are the attack surface. Cloud monitors Machine Identity Security reacts to Alerts ©BEYONDTRUST 2026 | 45
  29. The Triple Identity Threat Three identity types. Often siloed. Human

    Machine AI Employees Contractors Admins Third-Party Users Service Accounts API Keys Tokens Automation Autonomous Agents LLM Workflows AI Coworkers Orchestrators ©BEYONDTRUST 2026 | 47
  30. First Principles This chain explains most security outcomes. Identity Privilege

    Action Resource Who or what is requesting access? What privilege do they have? What command executes? Where does impact land? Breaches follow this sequence Clarity from seeing the whole system ©BEYONDTRUST 2026 | 49
  31. Closing Identity Blind Spots What are all my identities? Who

    has privileged access? How could they elevate access? Why does this identity need that privilege? ©BEYONDTRUST 2026 | 52
  32. Why it is better to see the whole elephant Privilege-Centric

    Identity Security allows you to: • See the reach and risk of all identities • Prioritise protection and investment Control the Privilege. Control the Risk. • Maximise security and efficiency ©BEYONDTRUST 2026 | 53
  33. Where to start Teams Terminology Technology Break the silos. Agree

    on common definitions of identity & privilege. Build on what you have. Get looking at the same data. Governance without shared accountability is just documentation. How do you talk human, machine and AI identity? How do you discuss across domains? Avoid the trap of point solutions that cause more silos. Combine visibility with intelligence to make data actionable. ©BEYONDTRUST 2026 | 54
  34. Final Thoughts 1 2 3 You probably don’t know your

    most privileged identities Most organizations cannot identify which identities, human or non-human, hold the highest levels of privilege across their environment. You certainly don’t know their true effective privilege Granted permissions rarely match actual usage. Shadow access, inherited roles, and stale entitlements create an invisible attack surface. You can’t see the elephant Without a holistic view of every identity type in a single pane, you’re managing fragments, not the full picture. ©BEYONDTRUST 2026 | 55
  35. When privileges are secure, identities are secure. Learn more about

    Privilege-Centric Identity Security at the BeyondTrust stand or visit BeyondTrust.com Thanks for listening ©BEYONDTRUST 2026 | 56
  36. From Principles to Practice - Embedding Responsible AI Governance Across

    the BBC Julie Macleod – Senior Responsible AI Manager
  37. BBC AI Principles We will act in the best interests

    of the public We will prioritise talent and creativity We will be open and transparent BBC Values Respecting Rights Transparency & Clear Explanations BBC Editorial Values Human Creativity Accountability Fairness Human Oversight Security & Robustness Responsible AI 63
  38. BBC AI Checklist 1 Complete training Responsible AI 2 Use

    approved tools 3 Agree accountability 4 Know when to seek advice
  39. Building Visibility of AI Risk (1) Guidance – what good

    looks like and when users can proceed (2) Project level risk – risks, mitigations, controls and accountability for higher risk use cases (3) Thematic risk – recurring and emerging AI risks consolidated into organisational themes and monitored via AI governance group (4) Organisational AI Risk – strategic oversight of key activity, actions and controls Responsible AI
  40. Building a culture of Responsible AI AI Reps Responsible AI

    AI Leads • Share what is happening locally • Support tool rollout • Encourage effective, responsible use Guidance • Set divisional direction • Approve AI use as required • Represent divisions in the network Responsible AI Coordination Oversight
  41. Lessons Learned….. (1) Principles need mechanisms – embed values in

    practical processes that change real decisions (2) Enable low-risk use – use training, guidance and local accountability with clear escalation points (3) Separate project and organisational risk – Individual assessments are not enough – identify themes and ensure strategic oversight (4) Build a capability, not a static framework – capabilities can evolve as technology, regulation and expectations change. Responsible AI
  42. This image by Jamillah Knowles / © We and AI

    / Better Images of AI / People and Ivory Tower AI / CC-BY 4.0 Thank you [email protected]
  43. whoami Cian Heasley Principal Consultant • • • • 6

    years working in CTI field ATT&CK, Sigma contributor Fascinated by geopolitics & cyber Hobbies: history, bowling & archery
  44. NCSC warns most “nationally significant” threats it deals with are

    nation state backed. Cyber risk is now more than ever a core business continuity issue 31st of August 2025, JLR shut down IT systems and halted production Halt lasted five weeks The most financially damaging cyber incident to ever hit the UK Scattered Lapsus$ Hunters claimed responsibility The details never seemed to make sense though
  45. DDoS is increasingly viewed as a minor nuisance NCSC released

    an alert in January “typically low in sophistication, a successful attack can disrupt entire systems”
  46. DDoS is increasingly viewed as a minor nuisance NCSC released

    an alert in January “typically low in sophistication, a successful attack can disrupt entire systems” 3 days before Christmas 2025, La Poste hit by DDoS attack Attack lasted 4 days – busiest postal period Package tracking, banking (11 million customers), Digiposte, payment processing offline
  47. Supply chain is where APTs & SMBs collide Companies may

    not be targets but are linked by: • Supply chains • Service providers • Technology vendors Nominet was breached on 30th of November, 2024 Hacked via an Ivanti Connect Secure zero-day Attack attributed to Chinese government linked APT Attackers hit trusted intermediaries Large & long-established suppliers have still proven vulnerable
  48. Russia August 2026 Microsoft disclosed “CaptiveCrunch” & attributed it to

    Cozy Bear CaptiveCrunch campaign compromised WiFi portals at hotels & conference centers DNS config changed to direct users to attacker-controlled infrastructure Compromised WiFi portals used AiTM to steal credentials Targeted sectors: Financial services, professional services, legal, healthcare, energy
  49. China Salt Typhoon (aka GhostEmperor) APT linked to China's Ministry

    of State Security Since September 2024 details of a Salt Typhoon telecom campaign have emerged Telecoms providers, ISPs & hosting suppliers targeted in espionage operations At least 600 organisations compromised worldwide
  50. Resilience is built on strong foundations NCSC’s 10 Steps to

    Cybersecurity: • Vulnerability Management • Identity & Access Management • Logging & Monitoring • Incident Management • Supply Chain Security Cyber Essentials is the practical baseline CE should be the floor though, not the ceiling!
  51. After 2025 retailer attacks the UK government warned companies that

    cybersecurity is an “absolute priority” Clients will start asking whether their providers are in scope, and whether they have the assurance to carry the reporting burden on their behalf Cyber Security and Resilience Bill extends mandatory security, incident reporting requirements to more organisations, sectors Businesses not in scope will still feel the effects, large clients will want to see: • Cyber Essentials certification • IR planning evidence • 3rd party secure access control mechanisms • Protection of shared data • Proactive threat hunting & monitoring
  52. NCSC now states explicitly that resilience is the defining requirement

    in today's threat landscape Adopt an assume-breach posture at leadership level Plan for degraded operations before full recovery Minimum Viable Operations (MVO) Practice your incident plans, don’t just document and forget them Assume you will need backups, and test the restore, not just the backup Treat communications resilience as a core capability Know your reporting obligations before the clock starts ticking
  53. Hacktivists have branched into ransomware Non-Russian ransomware operators have become

    more commonplace More APTs will adopt ransomware personas Physical convergence: attackers will increasingly close the physical distance to their targets Nation state hackers posing as hacktivists will become standard The speed of hacktivist mobilization around events will increase The technical ceiling for genuine hacktivist operations will rise Hacktivists are building infrastructure and using criminal marketplaces
  54. Agentic AI will move from advising to operating APT operations

    APTs will deploy AI integrated malware that adapts in real time Competent solo operators will achieve APT campaign results with commercial AI Attack chain compression with AI will massively impact detection windows State linked hacktivist personas will use AI to fake scale and credibility AI will structurally favor attackers in the short term
  55. Q&A

  56. Will the Cyber Security & Resilience Bill Improve Cyber Defences?

    Laura Irvine, Partner and Head of Regulatory Law September 2026
  57. Agenda ▪ The legal regime ▪ Expansion of regulated entities

    ▪ Changes to the requirements of incident reporting ▪ Increased regulatory powers – higher fines ▪ Comparison with NIS Directive 2022/2555 ▪ Timeline
  58. The Current UK/EU Regulatory Regime The Network and Information Systems

    Regulations 2018 SI 2018/506 (UK NIS) The EU has already moved from NIS1 to NIS2 — Directive (EU) 2022/2555 Cyber Security and Resilience (Network and Information Systems) Bill - Amends UK NIS
  59. The Network and Information Systems Regulations 2018 (UK NIS) Applies

    to organisations classified as operators of essential services: utilities, transportation and healthcare providers. The UK NIS applies to organisations classified as operators of essential services: utilities, transportation and healthcare providers.
  60. Expanded scope Section 2(2) a) extending the application of the

    NIS Regulations to persons providing data centres, persons providing services relating to load control, and persons providing managed services; b) providing for the designation of persons as critical suppliers in relation to persons regulated by the NIS Regulations; c) relating to the reporting of incidents; d) relating to the recovery of costs, the sharing and gathering of information, and enforcement.
  61. New regulated entities ▪ Section 4: Data centres to be

    regulated as essential services – in remit of Ofcom Applies to organisations classified as operators of essential services: utilities, transportation and healthcare providers. ▪ Section 9(4): Relevant Managed Service Provider (“RMSP”) (managed services in the UK) – in remit of the ICO ▪ Section 10: RMSPs under a duty to take “appropriate and proportionate measures” to manage cyber risk.” – in the remit of the ICO
  62. Critical suppliers Section 12: A supplier can be designated as

    “critical” where: a) it supplies goods or services directly to an OES, RDSP or RMSP; b) it relies on network and information systems for that supply; c) disruption could affect essential, digital or managed services; and d) the impact is likely to be significant for the economy or society.
  63. Incident reporting Section 15 changes the definition of “incident”: ▪

    Extended to beyond “actual” impact to “something capable of having” an impact on the operation or security of systems. The reporting model becomes: ▪ Initial notification: within 24 hours of awareness of incident ▪ Full notification: within 72 hours The regulated person must also send a copy to the NCSC at the same time as the regulator. This brings the UK into greater alignment with NIS2 EU regime.
  64. Future powers under the Bill ▪ Section 24 allows the

    Secretary of State to specify further Applies to organisations essential activities. classified as operators of essential services: utilities, transportation and healthcare providers. ▪ Section 29 gives a broad regulation-making power for security and resilience of network and information systems to allow secondary legislation.
  65. Expanded Regulatory Powers Section 21 sets two penalty levels: ▪

    Standard maximum: £10 million or 2% of worldwide turnover. ▪ Higher maximum: £17 million or 4% of worldwide turnover. The higher level applies to core failures, including security duties and incident-reporting failures. Discretionary power of Secretary of State to direct regulated entities to take steps to mitigate risks to national security.
  66. NIS2 - Directive (EU) 2022/2555 NIS2 applies to a broader

    range of sectors than the UK Bill. Key EU provisions: ▪ Article 20: management bodies must approve and oversee cybersecurity risk-management measures. ▪ Article 21: detailed cybersecurity risk-management measures. ▪ Article 23: incident reporting. ▪ Article 34: penalties. Member States were required to implement provisions by 17 October 2024.
  67. Timeline and what happens next? ▪ The Bill has not

    yet received Royal Assent - currently progressing through stageclassified at the House of Lords. The Bill could pass Applies to committee organisations as operators of essential into lawutilities, before the end of 2026. and healthcare providers. services: transportation ▪ The Bill allows flexibility for secondary legislation to be made under it. It is anticipated that the practical compliance measures will be introduced in secondary legislation.
  68. Intros Quantum Landscape PQC Research State of the Art Global

    PQC Standards Talk Structure Actionable advice on PQC transition
  69. Integrated Quantum Networks (IQN) Hub UK Quantum Missions UK National

    quantum strategy: A £2.5bn, 10-year strategy for the UK to be a leading quantum-enabled economy, recognising the importance of quantum technologies for the UK’s future prosperity and security.
  70. Integrated Quantum Networks (IQN) Hub The central vision of the

    IQN Hub is to establish quantum networks at all distance scales, from local networking of quantum processors to national scale entanglement networks for quantumsafe communication, distributed computing and sensing, all the way to intercontinental networking via low-earth orbit satellites. • 13 University partners plus RAL-Space and the National Physical Laboratory. • Director: Gerald Buller (Heriot-Watt). • Assistant Directors: Alessandro Fedrizzi (Heriot-Watt); Ciara Rafferty (Queen’s Belfast); Jason Smith (Oxford)
  71. “There is a 1 in 7 chance that some fundamental

    public-key crypto will be broken by quantum by 2026, and a 1 in 2 chance of the same by 2031.” –Dr. Michele Mosca, U. of Waterloo What happens if/when quantum computers become a reality? Commonly used public-key cryptographic algorithms (based on integer factorization and discrete log problem) such as: RSA, DSA, Diffie-Hellman Key Exchange, ECC, ECDSA will no longer be secure due to Shor’s algorithm. This Photo by Unknown Author is licensed under CC BY-SA
  72. Insert images of internet connections Alice and Bob…. Certificates… A

    reminder: Public Key cryptography is used everywhere
  73. Quantum-safe or Post-quantum cryptography (PQC) Cryptosystems from classical problems that

    are secure today, and should remain secure even after practical quantum computing becomes a reality
  74. Quantum-Safe Cryptography Quantum-Safe Cryptography Lattice based Code based Multivariate Isogeny

    based Examples of current PQC usage: • IBM offering quantum safe TLS option in IBM cloud • AWS offer hybrid post-quantum TLS with Kyber • Google using PQC (NTRU-HRSS) • Apple iMessage using hybrid PQC- classical • Cloudflare using PQC hybrid approaches… Hash based
  75. 118 Background: Summary of the NIST PQC Standards NIST PQC

    Standardization Contest (initiated in 2017) [2] winners NIST selected five Algorithms as Standards Key Encapsulation Mechanisms Security Strength Code Lattice Round 1 69 Algorithms Round 2 26 Algorithms Multivariate Isogeny Round 3 15 Algorithms Hash CRYSTALS-Kyber (2022) FIPS 203 Lattice-based HQC (2025) FIPS coming soon Code-based Digital Signature Algorithms CRYSTALS-Dilithium (2022) FIPS 204 Lattice-based FALCON (2022) FIPS coming soon Lattice-based SPHINCS+ (2022) FIPS coming soon Hash-based Five security levels: 1, 2, 3, 4 and 5 ❑ Levels 1, 3, & 5 (equivalent to security levels of AES-128, AES-192, & AES-256 bit key search) ❑ Levels 2 & 4 (equivalent to SHA3-256 & SHA3-384 bit collision search) [2] PQC Standardization Contest, [Online] available at: https://csrc.nist.gov/News/2022/pqc-candidates-to-be-standardized-and-round-4 Most PQC Algorithms are Lattice-based
  76. 119 Background: Summary of the NIST PQC Standards- Additional Signatures

    HAWK NIST Additional Digital Signatures Standardization Contest (initiated in 2023) [3] Lattice-based (1 algo) MQOM SDitH Security Strength Code Lattice MPC-in-the-Head Isogeny Multivariate MPC-in-the-Head (2 algos) Round 1 40 Algorithms Round 2 14 Algorithms Round 3 9 Algorithms SQIsign Isogeny-based (1 algo) Multivariate-based (4 algos) MAYO Symmetric-based (1 algo) QR-UOV SNOVA UOV Symmetric-based FAEST [3] PQC Standardization Contest, [Online] available at: https://csrc.nist.gov/Projects/pqc-dig-sig/round-2-additional-signatures
  77. What’s next? • Usability in application areas • Practicality •

    Latency • Throughput • Resource usage (hardware implementations) • Security • Algorithmic • Physical: timing analysis and side-channels • Parameters • Attack vectors
  78. Actions Know your systems Keep informed using reputable sources Think

    about your supply chain Follow your field/topic/region specific guidance Regular software and hardware updates
  79. Quantum Risk and Business Continuity: From Algorithms to Board-Level Resilience

    Aisling Dawson, Senior Analyst September 17, 2026 ©2026 ABI Research • www.abiresearch.com The material contained herein is for the individual use of the purchasing Licensee and may not be distributed to any other person or entity by such Licensee including, without limitation, to persons within the same corporate or other entity as such Licensee, without the express written permission of Licensor.
  80. AGENDA ▪ Defining the Quantum Threat ▪ The What: ▪

    Mapping Asset Exposure ▪ The Horizontal Nature of the PQC Threat ▪ Delimiting the Business Continuity Risk ▪ Sector-Specific Challenges ▪ The When: ▪ Q-Day Versus Quantum Migration Deadlines ▪ Regulatory and Standards Timelines ▪ The How: ▪ Practical PQC Roadmap ▪ Prioritization of Critical Assets ▪ Addressing Business Continuity Risks ▪ The Now: Status Report on Quantum Safe Resilience Across Sectors ▪ The Future: Expected Advancements in Quantum Safe Resilience Across Sectors ▪ Key Takeaways and Recommendations 126 www.abiresearch.com ©2026 ABI Research
  81. Defining the Quantum Threat The what, when, and how What?

    Cryptographically Relevant Quantum Computers (CRQCs) are coming! Most cryptographic algorithms (notably, public-key cryptosystems like RSA and ECC) will be vulnerable to breaking. Also, new government/federal timelines have a deprecation date for these, so CRQCs or not, a transition to new algorithms must happen. When? Estimates are that a CRQC will emerge between 2030 and 2035. This means that the transition should already be underway, especially for companies with long-life product offerings that will still be in use post-2030 to 2035 (automotive, utilities, and industrial sectors are in the cross-hairs today). How? Those developing products with cryptographic components will need to start integrating Post-Quantum Cryptographic (PQC) algorithms. Those using those products (or folding them into other solutions) will want to ensure that PQC support is available from their suppliers. 127 www.abiresearch.com ©2026 ABI Research
  82. The What: Mapping Asset Exposure What assets are most vulnerable

    to the quantum threat? Principal exposure is to asymmetric, public key cryptography, i.e., the vital communications layer underpinning: Transport Layer Security (TLS) and secure web services Code signing and secure software updates Virtual Private Networks (VPNs) and remote administration Public Key Infrastructure (PKI) and certificates Identity, authentication, and device trust Secure email and messaging Hardware Security Module (HSM)-backed key establishment and digital signatures Cloud, Application Programming Interface (API) and Machine-toMachine (M2M) communications Industrial control systems and field devices 128 www.abiresearch.com ©2026 ABI Research
  83. The What: The Horizontal Nature of the Quantum Threat How

    does PQC cut across security domains? PQC is a threat that presents horizontally within organizations because cryptography is embedded throughout the enterprise: ▪ ▪ ▪ ▪ ▪ ▪ ▪ Identity and access management ▪ ▪ ▪ ▪ ▪ ▪ ▪ 129 Workforce authentication Privileged access management Device certificates Federation and SSO FIDO & passkey ecosystems Service identities & workload credentials Smart cards, tokens & secure elements www.abiresearch.com TLS IPsec and VPNs Zero-trust access Service meshes API gateways Cloud key management Inter-region and hybrid-cloud links ▪ ▪ ▪ ▪ ▪ ▪ ▪ Network and cloud PKI and digital trust ▪ ▪ ▪ ▪ ▪ ▪ ▪ Enterprise CAs Publicly trusted certificates Root and intermediate certificates Certificate transparency and revocation Code-signing certificates Timestamping services Firmware-signing hierarchies Databases and backups Email and collaboration Messaging Data-at-rest encryption Digital signatures Long-term archives Inter-organizational data exchange Applications and data Operational technology ▪ ▪ ▪ ▪ ▪ ▪ ▪ Industrial control systems Safety systems Remote access gateways Field sensors Smart meters Renewable-generation assets Subsea, offshore, and distributed infrastructure ©2026 ABI Research
  84. The What: Delimiting the Business Continuity Risk What are the

    prospective consequences for business continuity borne out of the quantum threat ? Increased certificate and key sizes → TLS handshakes require additional packets & network round trips → customers unable to access online government services, e.g., regarding social benefits, council services & digital taxes. Higher bandwidth, memory & processing requirements → increased latency for authentication and session establishment → delays to large volume processing platforms in retail or banking. Protocol incompatibility → API authentication failures or broken mTLS → connections fail with suppliers or devices impacting remote access, telemetry, field systems, or control-plane communications in oil & gas. Devices that cannot be upgraded → isolating devices from upgraded systems or forcing premature rip and replace → replacement brings large costs or organization faces loss of functionality Unexpected fallback to classical crypto → exposing services to CRQCs or causing service unavailability → causing immediate operational outages or security breaches that lead to substantial financial loss or reputational damage. 130 www.abiresearch.com ©2026 ABI Research
  85. The What: Sector-Specific Challenges How does prioritization of assets and

    delimiting of continuity risk change across sectors? Financial Services, Banking & Insurance (BFSI) ▪ Assets: Payment gateways & infrastructure, card and mobile-payment ecosystems, and interbank connections. ▪ Business Continuity Risks: Disruption to payments, regional economies, trading, and confidence in systems. ▪ Sector-Specific Challenges: Highly interconnected ecosystems and third-party dependencies (clouds, HSMs, or Software-as-a-Service (SaaS) providers). Stringent policy and regulatory requirements. 131 www.abiresearch.com Central Government & Public Services ▪ Assets: Health, social care, and citizen records, intelligence and lawenforcement data, national/regional security information. ▪ Business Continuity Risks: private information exposure, loss of confidence in government, and political instability. ▪ Sector-Specific Challenges: Complex supply chains, dependency on legacy applications, requirement for cross-departmental risk assessment at local, regional, and national levels, and longlived sensitive data. Retail ▪ Assets: Point of Sale (POS) terminals, e-commerce platforms, paymentgateways, mobile applications, and customer loyalty systems. ▪ Business Continuity Risks: Reputational damage, fraud incidences, or customer data exposure. ▪ Sector-Specific Challenges: Large centralized and sensitive datasets, reliance on a broad range of providers (payment, identity, marketplace, logistics, cloud), weak signing infrastructure within warehouse systems/POS software/devices. Utilities (oil, gas, energy & renewables) ▪ Assets: Enterprise IT, SCADA or ICS, IoT devices/gateways, field sensors, and smart meters, legacy or proprietary equipment, remote terminal units, renewable-generation assets. ▪ Business Continuity Risks: Public safety hazards or physical damage. ▪ Sector-Specific Challenges: IT and OT silos, diverse assets, legacy industrial and niche proprietary equipment (memory and processing caps), long-lived devices, low latency requirements, OT knowledge gaps, and high risk aversion. ©2026 ABI Research
  86. The When: Q-Day Versus Quantum Migration Deadlines What timelines should

    enterprises adhere to? 132 Quantum Migration Deadlines: 2030 to 2035 Q-Day: 2030? 2035? 2040? Migration to PQC is largely being dictated by Western governments and their respective agencies/standards bodies with timelines between ~2030 and 2035. Unlike migration timelines, Q-day is an unavoidable checkpoint of quantum advancement. Migration timelines are not set in stone and can be subject to acceleration/deceleration. Date of its arrival is continually evolving, making it an unstable tool for mapping PQC migration deadlines. Consequences of Non-Compliance: Failed certification, safety testing or audits, potential regulatory penalties, and impacts on procurement and supply chain dependencies. Consequences of Falling Behind: Widespread security breaches, loss of sensitive data, financial loss, and system collapse. www.abiresearch.com ©2026 ABI Research
  87. KEM: Key Establishment Mechanism The When: Regulatory and Standards Compliance

    DSA: Digital Signing Algorithm How are regulation and standards impacting migration timelines? ▪ Three Official Standards Published by the National Institute of Standards and Technology (NIST) in 2024: ML-KEM, ML-DSA, and SLH-DSA. ▪ Two More Expected in 2026: FN-DSA and HQC. ▪ The standardization process is ongoing. Other rounds are still underway, at NIST and in other national Standards Developing Organizations (SDOs) (China, Korea, etc.). ▪ PQC development and integration into industry solutions will largely leverage NIST and Internet Engineering Task Force (IETF) standards. ▪ Industry- and sector-specific consortia will provide recommendations to optimize their own specifications and reference architectures based on published standards. ▪ The progress of work in these will be a sign of technology maturity and the goal will be to present “plug-and-play” types of technologies for specific industries, which enable easier commercial integration and adoption. Why It Matters: ▪ Future-proofing products, services, and internal systems requires compliance with emerging regulatory, national, regional, and sector expectations around PQC. ▪ Compliance with regulatory and standards regimes is also a key component to procurement requirements. ▪ The NIST timeline has begun for migration and, given the sector-specific challenges associated with transitioning to quantumsafe, starting earlier rather than later will help iron out any challenges that arise, limiting impact on uptime, availability, and reliability. 133 www.abiresearch.com ©2026 ABI Research
  88. The How: Practical PQC Roadmap What are the critical steps

    in migrating to PQC and integrating quantum resilience into systems? Phase 1: Crypto asset discovery, inventory management Phase 2: Remediation tools Phase 3: Interim and hybrid solutions Phase 4: Phasing out hybrid encryption for pure PQC Phase 5: PQC-only encryption 134 www.abiresearch.com ©2026 ABI Research
  89. The How: Prioritization of Critical Assets How can organizations across

    sectors in Scotland prioritize critical assets within systems? Asset prioritization should consider these metrics first and foremost when delegating asset priority: Information Sensitivity/Data Confidentiality ▪ Sensitive or confidential data present an attractive target, especially in harvest now, decrypt later attacks. ▪ Identifying location of sensitive data is critical. 135 www.abiresearch.com Device/Data Lifetime ▪ Confidentiality required beyond set migration windows. ▪ Devices in circulation for a lengthier period and are also often more difficult to upgrade (e.g., legacy systems). Standards & Safety/Legal Requirements ▪ PQC standards may mandate an upgrade of assets to ensure quantum resilience. ▪ Consequences of non-compliance: penalties and knock-on effect on procurement. Business-Critical Assets ▪ Upgrades to prevent severe financial losses or downtime. ▪ Overlaps with some of the other categories but also extends to those assets that are necessary for business needs e.g., profitmaking. Externally Exposed Communications Trust Anchors/Signing Operations ▪ More at risk of interception by malicious actors. ▪ Cryptographic underpinning securing the validity and integrity of assets. ▪ E.g. open ports, and service meshes, internetaccessible data flows, publicfacing network paths, public APIs, cloud connections. ▪ Prime target for hacking with impacts on digital trust downstream. ▪ For example: HSMs, root & intermediate CAs, code and firmware-signing keys, etc. ©2026 ABI Research
  90. The How: Addressing Business Continuity Risks How can organizations across

    sectors in Scotland address business continuity risks across systems? ▪ Beyond algorithms and cryptography, the quantum migration represents an overhaul of existing business practices and is thus not only a security issue but one of operational resilience. ▪ The U.K. National Cyber Security Centre (NCSC) explicitly advises organizations to plan for business continuity as part of the transition. ▪ To optimize business continuity and reduce disruptions to operations during the transition, organizations should integrate the following: Hybrid PQC, crypto-agility, automation & rollback processes Service-level impact assessments 136 www.abiresearch.com Testing, staging, and sandboxing environments for interoperability, capacity, and latency Integrated governance structure operating horizontally, across silos Cyclical and continuous feedback & improvement loops Contingency plans with compensating controls and defined tolerance levels for residual legacy risk/exposure or downtime ©2026 ABI Research
  91. The Now: Status Report on Quantum-Safe Resilience Across Sectors What

    is the current status of migration to quantum-safe resilience across markets and regions? Manufacturing Retail Healthcare Government Financial Services - Longer asset timespans and size-constrained devices Utilities - Growing dependency on e-commerce & online transactions - Data protection regulations related to healthcare data - OT security lags behind IT - Regulated sector with access to government funding - PQC policy announcements centered around public sector first - Supply chain optimization concerns - Longer asset timespans and size-constraints - Lack of specific regulatory guidance about quantum - Less regulatory impetus - Higher awareness but more relaxed timelines - Reliance on third parties and complex supply chains - U.K.-wide deadlines set by the NCSC (2028, 2031, 2035) - - Crypto inventory taking underway & PQC strategy implementation - Substantial investment support - POC planning and execution begun - Cyber Associates Group (NHS Futures) - Lack of clear financial impetus - Fears about losses and first-mover disadvantage - Legacy systems - Proof of Concept (POC) phase rather than practical deployments - Scotland: Clear in regional policies on importance of PQC - Security is market differentiator - Siloed estates complicate inventory-taking. - Significant variance in maturity Increasing uptake of PQC and maturity of quantum-readiness 137 www.abiresearch.com ©2026 ABI Research
  92. The Future: Expected Advancements in Quantum-Safe Resilience Across Sectors How

    is quantum resilience expected to progress across sectors over the next 5 years? 138 www.abiresearch.com Post-Quantum Cryptography Revenue by Vertical World Markets: 2025 to 2030 1,000 900 800 700 (US$ Millions) ▪ Banking, Financial Services, and Insurance (BFSI): Early movers in PQC expected to retain their lead. ▪ Information and Communications Technology (ICT): Reliance from other sectors provides impetus for resilience. ▪ Defense: Early adoption of beta solutions and pilots expected to continue. ▪ Government: Predefined national PQC policies and transition timelines help bolster growth. ▪ Healthcare: Infrastructure complexity and supplier dependence inhibit the market. ▪ Energy & Utilities and Manufacturing: Legacy, proprietary and air-gapped technologies restrict Total Addressable Market (TAM) in the short term. EU and U.S. legislation regarding IoT devices will bring growth. BFSI Defense Energy Government Healthcare ICT Manufacturing Other Utilities 600 500 400 300 200 100 0 2025 2026 2027 2028 2029 2030 ©2026 ABI Research
  93. Core Takeaways for CISOs, Information Security Leads & Cybersecurity Experts

    Visibility is key Quantum resilience is a horizontal effort Contextualization should be prioritized over perfection PQC ready is a continuous transition, not one and done Preparation must start now 139 www.abiresearch.com ©2026 ABI Research
  94. THANK YOU Aisling Dawson, Senior Analyst © 2026 ABI Research

    ABI Research is uniquely positioned at the intersection of end-market companies and technology solution providers, serving as the bridge that seamlessly connects these two segments by driving successful technology implementations and delivering strategies that are proven to attract and retain customers. +1.516.624.2500 in the Americas, +44.203.326.0140 in Europe, +65.6592.0290 in Asia-Pacific or visit www.abiresearch.com. www.abiresearch.com
  95. #ScotSecureWest26 BREAKFAST BRIEFING Jonathan Smith Business Unit DirectorCyber Security SWORD

    GROUP John Higginson Senior Consulting Director UNIT 42 PALO ALTO NETWORKS
  96. The Threat Landscape John Higginson Senior Consulting Director Unit 42

    © 2026 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
  97. The Motivation Behind Cyber Threats Remain Broad and Various 1

    - Financial Gain 22 -- State-Sponsored Nation-State Espionage Espionage 3 - Cyber Warfare 4 - Political or Idealistic Reasons 5 - Corporate Espionage Continual Change and Evolution Ransomware Fraud and Theft Crypto-Jacking Cyber Espionage Sabotage IP Theft © 2024 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information. Geopolitical Tensions Disinformation Campaigns Protests and Activism Competitor Sabotage Insider-Trading Disgruntled Insider
  98. Four major trends that will shape the threat landscape for

    2026 1 AI has become a force multiplier for threat actors 2 Identity has become the most reliable path to attacker success © 2026 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information. 3 Software supply chain risk has expanded beyond vulnerable code to the misuse of trusted connectivity 4 Nation-state actors are adapting stealth and persistence tactics to modern enterprise operating environments
  99. Bad Actors Increasingly Leveraging AI in Innovative and Sophisticated Ways

    Malware Enhancement Advanced Reconnaissance Evasion and Obfuscation Password Cracking and Credential Abuse Exploiting Enterprise AI Continual Change and Evolution • Polymorphic Malware • Intelligent Malware • AI-Driven OSINT • Social Media Mining © 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information. • Bypassing • AI-Assisted Brute Security Systems • Adversarial Machine Learning • Encrypted and Covert Channels Force • Credential Stuffing • Model Poisoning • AI Abuse
  100. Bad Actors Increasingly Leveraging AI in Innovative and Sophisticated Ways

    Various Supply-Chain Attacks Automated Phishing and Deep Fakes Fake Content and Disinformation Distributed Denialof-Service Attacks Real-Time Decision Making in Cyberattacks Continual Change and Evolution • AI-Assisted • AI-Powered Targeting Phishing • Deepfake Technology • Chatbots © 2025 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information. • Synthetic Media • Disinformation Campaigns • AI-Optimised Botnets • AI-Augmented Attacks
  101. The Entry Point Attackers continue to rely on dependable techniques

    to establish a foothold All Other Phishing 16% 22% Nearly half of incidents start with Phishing/Social Engineering or Software Vulnerabilities. Brute Force 8% Insider Threat Initial Access Vectors 8% Software/ API Vulnerabilities 22% Other Social Engineering 11% Previously Compromised Credentials 13% © 2026 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information. Attackers are pragmatic, they exploit human error and unpatched systems with equal frequency to force the door open.
  102. Surging SaaS Supply Chain Risk 3.8X Megalodon GitHub Attack Targets

    5,561 Repos with Malicious CI/CD Workflows 84 TanStack npm Packages Hacked in Ongoing Supply-Chain Attack… surge in attacks involving third-party SaaS applications; 23% of all attacks Nx Console VS Code Extension Compromised © 2026 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
  103. Attackers Succeed Because of Three Critical Gaps Complexity Missing context

    delays detection 87% correlated data across multiple disconnected sources Visibility Identity Inconsistency creates the path of least resistance Excessive trust leads to lateral movement 90% involved misconfigurations 89% saw identity play a material or security coverage gaps role in the attack success © 2026 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
  104. Frontier AI Creates Step-Change in Adversary Capabilities © 2026 Palo

    Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
  105. Unit 42 Is Finding Critical, Exploitable Exposure Full Server Takeovers

    Admin Account Forgeries © 2026 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information. Cross-Tenant Data Exposure Network-Wide Compromise Mass Database Exposure 159
  106. Unit 42 Frontier AI Defense Insights 97 45% 36% Exposures

    per enterprise Critical or High Severity Map to no known CVE Exposure At Scale Critical & Exploitable Hidden from Defenders Finding and Validating Exposure Adversaries Could Weaponize Across The Full Estate at Machine Speed Source: Unit 42 data from Frontier AI Defense deployments, as of August 5, 2026 © 2026 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
  107. Prioritising security outcomes, not technology Protect what matters. Prepare for

    resiliency. Invest where it changes the outcome. Jonathan Smith Sword
  108. Good security starts with the business outcome, not the technology.

    Business Risk Resilience What matters? What could disrupt it? How we withstand it?
  109. Start with the business outcome Technology is an enabler, not

    the objective. BUSINESS OUTCOME CRITICAL SERVICES RISKS CONTROLS INVESTMENT Work backwards from the outcome the organisation cannot afford to lose.
  110. Resilience is an operating capability ANTICIPATE DECIDE RESPOND RECOVER PEOPLE

    Recognise impact Make decisions Lead containment Confirm priorities PROCESS Define thresholds Escalate clearly Coordinate response Sequence recovery TECHNOLOGY Monitor exposure Create insight Contain threat Restore safely The outcome changes only when all three operate as one system. Operational Resilience People, process and technology must work through disruption together.
  111. Investment is not the same as capability Buying a product

    creates potential. Operating it well changes the outcome. MONEY TECHNOLOGY THE CAPABILITY PATH INVESTMENT OWNERSHIP PROCESS ADOPTION EXERCISE MEASUREMENT The value is not what we deployed. It is what changed as a result. OUTCOME
  112. Measure outcomes, not activity Metrics should show whether the organisation

    is safer and more resilient. ACTIVITY METRICS OUTCOME METRICS Vulnerabilities identified Critical exposure reduced Alerts generated Threats contained People trained Risky behaviour reduced Tools deployed Coverage improved Incidents recorded Recovery time improved Are we demonstrably safer or more resilient?
  113. The security leader's job Three questions turn complexity into deliberate

    business decisions. 01 02 03 WHAT MATTERS MOST? WHAT COULD MATERIALLY DISRUPT IT? WHAT WILL CHANGE THE OUTCOME? Identify the outcomes the organisation cannot afford to lose. Understand credible threats, exposure and dependencies. Direct people, process and technology where they matter. PRIORITISE ACT TEST MEASURE IMPROVE The objective is the right security, focused on the outcomes the organisation cannot afford to lose.
  114. Incident Response Proactive Services Managed Services Threat Intelligence 1,000+ 50+

    All IR matters per year countries major industries © 2026 Palo Alto Networks, Inc. All rights reserved. Proprietary and confidential information.
  115. Comprehensive, end-to-end cybersecurity coverage Preparedness Testing & Assessments Detection &

    Monitoring Incident Response & Recovery • Threat Profiling • IR Plan Review / • Offensive Security: ◦ Pentest ◦ Red Team ◦ Frontier AI testing • Defensive Security: ◦ Compromise Assessments ◦ Purple Team ◦ Attack Surface • Managed Threat • Ransomware, Hunting (MTH) APT, BEC, Cloud, +more Development • Incident / Crisis simulations Assessment • Managed Detection & Response (MDR) • Dark Web Scanning • Ransomware Negotiation • Forensic Investigation • Remediation Services © 2026 Palo Alto Proprietaryand andconfidential confidential information. © 2024 Palo AltoNetworks, Networks,Inc. Inc.All All rights rights reserved. reserved. Proprietary information. Security Strategy & Transformation • Post-Incident Transformation • Risk & Maturity Assessments • Threat Intel Maturity • SOC Maturity • Cloud Security • AI Security
  116. NEW 7 OCT 2026 | Edinburgh 7 OCT 2026 |

    Edinburgh 22 OCT 2026 | Cardiff 19 NOV 2026 | Edinburgh 25th FEB 2027 | Edinburgh 1st April 2027| Edinburgh
  117. Thieves Don’t Break In... They Login: Secure Your M365 In

    Minutes, Not Months Rob Butterworth Senior Solutions Architect, UK&I
  118. Identity is a primary target Identity helps us ensure who

    a user is Identity dictates any actions a user can take Identity is a primary target for criminals
  119. 32% rise in identity-based attacks in the first half of

    2025 and 38 million daily identity risk detections *Microsoft Digital Defense Report-2025
  120. Email is an easy entry point Compromise access Steal or

    encrypt data Malicious email Collaboration tools
  121. Impact compounded by Business Challenges Limited or no internal cybersecurity

    expertise / No response capabilities Slow responses → lengthier cybercriminal dwell times (expensive) Lack of centralized security visibility across many disparate systems Alert fatigue and false positives Regulatory and compliance requirements
  122. EvilProxy Unleashes a New Wave of Attack EvilProxy phishing attacks

    employ a reverse proxy configuration 1 User inputs User clicks link At-Risk User 5 When victims enter their credentials into the fake login page, their credentials are passed to the legitimate website Adversary-in-the-middle attack Phishing Website Phishing site proxies MFA to user Site returns 4 MFA screen Microsoft 365 7 MFA Confirmation Proxied 6 User confirms MFA Valid Session 8 cookie intercepted Malicious Proxy Server TLS Session Known as Phishing site proxies 3 request to actual site 2 credentials TLS Session
  123. Account Compromise without automation Target: Employee clicks on Phishing email

    link and gives away credentials Threat actor: Breached M365 through compromised account Attack starts Phishing email delivered to employee mailbox
  124. Account Compromise without automation Attack starts Phishing email delivered to

    employee mailbox Employee: Reacts to receiving the email Seconds later Employee reviews email, clicks link and signs into what they think is M365
  125. Account Compromise without automation Attack starts Phishing email delivered to

    employee mailbox Seconds later Employee reviews email, clicks link and signs into what they think is M365 Threat actor: Gains access & disguises the compromise Almost simultaneously Captured information used to access M365 account from unusual location and device Rule creation Attacker creates inbox rule to hide and filter data
  126. Account Compromise without automation Phishing campaign detection IT administrator works

    with support to disable account & remediate email Attack starts Phishing email delivered to employee mailbox Seconds later Employee reviews email, clicks link and signs into what they think is M365 Days later Attacker uses mailbox to send Phishing campaign to suppliers and customers Critical oversight Over-stretched IT administrator overlooks security alert Almost simultaneously Captured information used to access M365 account from unusual location and device Rule creation Attacker creates inbox rule to hide and filter data Activity triggers security alert Detection solution detects suspicious location, device and rule activity
  127. Gaps in the traditional approach Identify Protect Detect Recover Respond

    • Network Inventory • Security Policies • On Premises Backup • Vulnerability Scans • Access Controls • Cloud Backup • Risk Assessments • Patching • Data Archiving • Configurations • Security Training • Email, Network, & Endpoint Protections • Zero Trust Access • Data Loss Prevention Cybersecurity gap
  128. Cyber Resilience Strategy Enhance Email Protection Greater Detection & Response

    Implement Zero Trust Strategy Robust Resilient Recovery
  129. RESILIENCE RESILIENCE CYBER Email Data Network Applications 1 Easy Managed

    XDR FOUNDATION POWERED BY PEOPLE Risk & Threat Intelligence Threat Radar UX System Trust Center Partner Success Program Autonomous Self-Heal/Config Customer Success Program API Portal Support ECOSYSTEM ENHANCED BY AI INTELLIGENCE 2 Complete 3 Intelligent 4 Open
  130. Comprehensive data protection for Exchange Online, OneDrive, SharePoint Online, MS

    Teams and Entra ID from an easy to deploy and use platform OneDrive Exchange Teams SharePoint Groups Entra ID OneNote Automatic Daily backup On-demand recovery Quickly configure your M365 and Entra ID: zero to back up in 5 minutes No software or hardware to install or manage, SaaS service managed by Barracuda Granular restore of M365 data sources including Teams
  131. Barracuda Managed XDR VULNERABILITY SECURITY CLOUD SECURITY EMAIL SECURITY 24/7/365

    SOC Automation & AI 24/7/365 SOC 24/7/365 SOC coverage is critical for ensuring continuous threat detection, rapid response, and minimized risk from sophisticated attacks that can occur at any time. 24/7/365 SOC coverage is critical for ensuring Automation & AI in an XDR solution are crucial for continuous threat detection, rapid response, and swiftly identifying and neutralizing threats in real-time, minimized risk from sophisticated attacks that can reducing dwell time, and minimizing potential occur at any time. damage across the entire security environment. Centralized Data Proactive Threat Detection Centralized security data in a managed SIEM Proactive threat detection identifies and addresses provides comprehensive visibility, accelerated threat detection, and faster incident response through SERVER SECURITY ENDPOINT SECURITY potential cyber threats before they can cause harm. This proactive approach empowers organizations to integrated, real-time analysis across all security layers. stay ahead of evolving threats, ensuring robust NETWORK SECURITY protection and peace of mind.
  132. Impact of Automated Threat Response ATR for XDR Cloud Security

    Attack starts Phishing email delivered to staff member mailbox Unauthorised Log-in O365 mailbox Seconds later Employee reviews email, clicks link and signs into what they think is M365 Almost simultaneously Captured information used to access M365 account from unusual location and device XDR Cloud Security Automated Threat Response Over-stretched IT administrator free to focus on other security tasks Managed XDR Cloud Security Automated Threat Response (ATR) detects anomalies suspends account attack blocked
  133. To recap Enhance Email Protection Greater Detection & Response Implement

    Zero Trust Strategy Robust Resilient Recovery
  134. Secure by Design: Protecting Data Across the AI Lifecycle Dan

    Kendall - UK&I Solutions Strategy Group
  135. The Evolving Threat Landscape Threats to UK Organisations in 2026

    DSIT (DCMS) Cybersecurity Breaches Survey 2026 “We still see far too many significant incidents today that are possible because the fundamentals are not in place....” Richard Horne, NCSC CEO © Fortinet Inc. All Rights Reserved. 205
  136. Adopting AI: Double-Edged Sword You must do 87% Accuracy improvement

    in healthcare diagnostics Microsec Decisions in financial trading You must face Operational Efficiency and Productivity Shadow AI Enhanced decision making Data Leakage Innovation Mil. Miles Superior Customer Experience 95% Of Enterprise have Undiscovered AI $54M+ In lost revenue and legal fees in Manufacturing Security Risks Driven with selfdriving intelligence Regulatory Breaches €35M+ Max fine for noncompliance – EU AI Act, 8/26 AI and Security are Inseparable © Fortinet Inc. All Rights Reserved. 206
  137. AI is Weaponised AI-Generated Phishing Emails AI is being used

    to detect, deploy and exploit Deepfake Voice and Video Poisoning AI search engines and LLMs © Fortinet Inc. All Rights Reserved. 207
  138. The ‘New Normal’ Operating Environment TRADITIONAL APPROACH Context, Accuracy &

    Speed AI-Era Approach Predictable Processes The outcome is defined, not the path or the process Unpredictable, Non-Deterministic Rules Based Control Does what it’s doing help in achieving the intent? Behaviour Based Augmentation Manual Operation Machine-Speed is Essential, but how much do you trust AI? Human-in-the-Loop Automation © Fortinet Inc. All Rights Reserved. 208
  139. How is AI Changing The Environment AI for Security Security

    for AI Leveraging GenAI to improve Technology and Services Using Technology & Services to secure customer use of GenAI Unpredictable, NonDeterministic Behaviour Based Automated at Machine Speed The ‘Secure-by-Design’ Environment Should Now Support…. Unknown Behaviour Detection AI Agent Proliferation ‘Agent to Agent’ Networking Machine Speed Response Usage Tracking Modern threats bypass Rules and fixed signatures Expect to see significant increases in the number of Virtual Endpoints Support for evolving ‘Traffic Patterns with Low Latency and fluctuating flows Ability to Detect and mitigate against attacks in Real-Time Shadow AI, Excess Spend, Rogue Agents and more © Fortinet Inc. All Rights Reserved. 209
  140. Governing AI – With a Platform Based Approach 1 Observe

    Build Context – What Apps, What Data? 2 4 Learn Observe changes and iterate controls Continuous Contextualisation Iterative Control Control Build Policy, Enact Guardrails Automate Dynamically change control points based on context 3 © Fortinet Inc. All Rights Reserved. 210
  141. Governing AI – With a Platform Based Approach 1 Observe

    Build Context – What Apps, What Data? 2 4 Learn Observe changes and iterate controls Continuous Contextualisation Iterative Control Control Build Policy, Enact Guardrails Automate Dynamically change control points based on context 3 © Fortinet Inc. All Rights Reserved. 211
  142. Extend Fabric Possibilities with Industry-Leading Open Ecosystem Fabric Connectors +400

    other FabricReady Partners Ecosystem Breadth and Depth Fortinet delivers the most extensive partner ecosystem in cybersecurity Fabric APIs 3000+ integrations across 400+ technology partners 2x more integrations Fabric DevOps than competitors Figures as of July 29, 2025 - Logos are a representative subset of the Security Fabric Ecosystem © Fortinet Inc. All Rights Reserved. 213
  143. Platform Example: AI Agent Collaboration Solution Specs Agentic AI Frameworks

    enable complex event triage at scale and speed. Across both Network and Security usecases. Leveraging MCP to communicate, agentic agents can dynamically query and inform decision-making, amending output and input as responses come back throughout the framework. Modern Challenges Agentic Outcome Use-Cases • AI-Enabled Attacks • Vulnerability Exploits • ‘Hiding in Plain Sight’ • Deepfakes • Baseline Alerting • Multi-Product/Service Triage • Faster Detection & Response • Observability and Control • Automated Patching • Virtual Patching • Automated Threat Hunting at Scale • Self-Healing Networks • Agentic Detection & Mitigation © Fortinet Inc. All Rights Reserved. 214
  144. Risk Generated Through Perceived Productivity The Problem Anthropic SIEM/SOC OpenAI

    The proliferation of AI and the hype surrounding productivity gains for both employees and organisations has resulted in an explosion of Shadow AI use. Copilot Reporting Platform Reporting Platform Canva Ecosystem Edge SSE Platform Gartner reports that 95% of Enterprises have Shadow AI challenges. This lack of visibility into AI usage is a serious risk to organisations where sensitive data may get released by mistake or malicious intent. DLP / IRM Agent User Ecosystem Edge AI Agent The Visibility Problem Risk-Based Controls Fragmented Response Organisations’ fragmented approach to visibility means shadow AI use can proliferate with limited or no oversight. Organisations should implement riskbased controls based on a combination of identity and application. This is impossible for legacy ecosystems. Without deep visibility into AI use, organisations are forced to either allow or block, potentially impacting their ability to achieve efficiency gains. © Fortinet Inc. All Rights Reserved. 215
  145. Platform Example: Shadow AI Detection & Protection XDR Triage/Investigation Playbooks

    Solution Specs SIEM/SOC Observability of Agent and Human AI use is paramount for compliance and operational security. With the proliferation of local models and free services, organisations must be able to detect AI use wherever the agent or user resides and control at the point of use. Network DLP Application Control DNS Control MCP Observability In-Line CASB NGFW Remote Access ZTNA EPP EDR Data Protection API & MCP Enforcement Input Sanitisation WAF SSE Platform User End-Point Agent AI Agent MCP Protection Shadow AI is Here Reporting With users able to deploy MCP agents and integrations locally. Organisations must apply controls at the end-point. 95% of enterprises have AI running in their environment that IT has never approved and does not know about. Tools and Systems should integrate to detect and control malicious or unauthorised AI in real-time. © Fortinet Inc. All Rights Reserved. 216
  146. Traditional Data Tagging & Protection is Complex The Problem SIEM/SOC

    Reporting Platform Reporting Platform Traditional Data Classification & Control solutions often consist of fragmented tools designed to handle specific areas of an organisation's infrastructure. Reporting Platform DLP / IRM Agent Ecosystem Edge Ecosystem Edge DLP / IRM Agent SSE Platform In the modern enterprise this makes it difficult to effectively classify and control data as it moves between silos. User AI Agent Multiple Other Another Ecosystems Isolated Tools Broken Observability Fragmented Response Isolated Tools within disparate ecosystems breed complexity for organisations where data often lives into multiple silos. Having multiple tools, means multiple visibility touch points, making end-to-end observability a challenge. If observability is broken organisations struggle to understand context and therefore real risk associated with data use. © Fortinet Inc. All Rights Reserved. 217
  147. Platform Example: Data Detection & Protection XDR Triage/Investigation Playbooks Solution

    Specs SIEM/SOC ML | GenAI Combining integrated tool sets across a data journey means we can have consistent visibility of data and its use. Network DLP On-Prem FW Endpoint-based DLP / IRM Network DLP SSE Platform Mail Gateway DLP / IRM Agent ML | GenAI ML Systems should be open and extensible to ensure tool sets can collaborate in real-time to dynamically detect and mitigate risky user or system behaviour. Network DLP DLP feeds with common identifiers like NHS Numbers. Ability to add custom identifiers Data Classification Discovery and ML-enhanced Classification Data Classification Data Loss Prevention Reporting Data classification and labelling systems should be able to operate across on-premise and cloud stores. Layered data loss prevention for data in transit and in use. Integrated IRM provides extended visibility and context. SIEMs or XDR systems should consolidate data visibility and reporting per data type aligned to compliance frameworks. © Fortinet Inc. All Rights Reserved. 218
  148. Platform Example: Securing Cloud AI Workloads Solution Specs LLM DLP

    Response Protection Jailbreak protection Proxy Caching Rate Limiting AI Models require defence in depth to ensure every aspect of the model is secure. From configuration to runtime. The ecosystem should monitor permissions and runtime of the LLM while sanitising inbound and outbound flows to protect data and model information. MCP, Text and API are all methods of interfacing with a model and should be inspected and have guardrails. AI Gateway API & MCP Enforcement Input Sanitisation WAF User AI Runtime Protection Observability of pipelines, endpoints and flows LLM Permission Checking & Control CNAAP AI Agent Delivery and Optimisation Protect Input and Output Protect Runtime • • • • • API Protection • MCP Protection • Jailbreaking and Input Sanitisation • Exploit Protection • Container and Infra Protection • Permission Auditing • Model Runtime Scanning Secure LLM proxy Authentication and authorisation Caching and rate limiting Chaining and stitching of guardrails © Fortinet Inc. All Rights Reserved. 219
  149. Platform Example: LLM Protection o tiA low Solution Specs Raw

    input AI Models should be designed and deployed in a Secure by Design fashion where data is classified and inputs secured to protect against accidental or malicious exposure of data. FortiAIGate protects against threats such as prompt injection, data exfiltration, and model misuse by applying runtime guardrails and policies to every AI request and response. Saniti ed output App pti i e Application e o ance Detect ec it lock h eats o tiA ad Saniti ed input Raw output odel Delivery and Optimisation Protect Prompts Protect Responses • • • Detect prompt Injection • Fend jailbreaking off • Block excessive consumption • Prevent model theft • Prevent data leakage from LLM • Fact check LLM • Ensure LLM relevancy • Avoid harmful contents • • Secure LLM proxy Authentication and authorization Caching and rate limiting Chaining and stitching of guardrails © Fortinet Inc. All Rights Reserved. 220
  150. THANKS TO ALL OUR SPONSORS & EXHIBITORS #ScotSecureWest26 Breakfast Briefing

    Sponsor Drinks Reception Sponsor Badge & Lanyard Sponsor
  151. NEW 7 OCT 2026 | Edinburgh 7 OCT 2026 |

    Edinburgh 22 OCT 2026 | Cardiff 19 NOV 2026 | Edinburgh 25th FEB 2027 | Edinburgh 1st April 2027| Edinburgh
  152. NEW 7 OCT 2026 | Edinburgh 7 OCT 2026 |

    Edinburgh 22 OCT 2026 | Cardiff 19 NOV 2026 | Edinburgh 25th FEB 2027 | Edinburgh 1st April 2027| Edinburgh
  153. Unintended Insights: What We Give Away Online Professor Wendy Moncur

    University of Strathclyde linkedin.com/in/profwendymoncur
  154. 1. Personal data Talk structure 2. The part that people

    play in cybersecurity breaches 3. An example of a breach 4. Building digital resilience through people
  155. Background • Fragments of our professional and personal data are

    scattered across multiple platforms and across time by ourselves and others. • Almost impossible to erase once shared • Linking these fragments can afford significant and unintended insights to others—both human and AI. • This creates risks of reputational harm and security breaches to organisations and individuals • Awareness is crucial in training staff to consider what data they share about themselves and where
  156. Personal data shared online Intentional Unintentional Shared by you Shared

    by others Coconstructed Mundane Sensitive Personal life Work life Cookies/ trackers Civic AI generated
  157. Cybersecurity incidents and breaches • Incident • A security event

    that compromises the integrity, confidentiality or availability of an information asset. • Breach • An incident that results in the confirmed disclosure—not just potential exposure—of data to an unauthorized party.
  158. The part that people play Who? Who are the threat

    actors? How? How are attacks carried out? What? People as targets of attacks So what? What impact an incident has Source: Verizon 2026 Data Breach Investigations Report verizon.com/dbir
  159. Who are the threat actors? External: E.g., criminal groups, lone

    hackers, former employees and government entities. Internal: originating from within the organization. E.g., company employees, independent contractors. Partner: third parties sharing a business relationship with the organization. E.g., suppliers, vendors, hosting providers and outsourced IT support.
  160. How are attacks carried out? • Social: employ deception, manipulation,

    intimidation, coercion to exploit the human element, or users, of information assets. • Source: Verizon 2026 Data Breach Investigations Report verizon.com/dbir
  161. Coercion-based insider risk • Employees with susceptibility to coercion-based collaboration

    with External actors. • Availability of personal information → leverage against those highrisk individuals. • 1 in 500 employees accessed high-risk compromising materials on an enterprise device - extremism, promotion of bodily harm or exploitative materials not appropriate for the workplace • If those employees have any sort of privileged access in your organization, their trusted access could become externally leverageable. Source: Verizon 2026 Data Breach Investigations Report verizon.com/dbir
  162. Targets of attacks Person: Internal staff and third parties sharing

    a relationship with the organisation Source: Verizon 2026 Data Breach Investigations Report verizon.com/dbir
  163. Impacts in a cybersecurity breach/ incident Source: Verizon 2026 Data

    Breach Investigations Report verizon.com/dbir
  164. Impact: Confidentiality breach • Canadian-owned Pornhub received an extortion demand

    from ShinyHunters • > 200m data records hacked, including premium members’ email addresses, search and viewing activities and locations. Image: https://www.theguardian.com/technology/2025/dec/17/hackers-access-pornhub-premium-users-viewing-habits-and-search-history
  165. What happened? • Actor: Internal – crew member • Action:

    Error due to lax privacy settings on personal phone • Impact: loss of confidentiality – location of French aircraft carrier Charles De Gaulle on deployment revealed
  166. Strava reveals location of French warship after naval officer logs

    run on aircraft carrier deck Alex Blake Published 23 March 2026. TechRadar https://ukdefencejournal.org.uk/french-carrier-position-exposed-by-fitness-app/
  167. An isolated incident? YEAR INCIDENT IMPACT 2018 Strava Global Heatmap

    revealed secret US military bases Forward operating bases in Syria, Afghanistan and Djibouti exposed 2025 French submarine crew at Île Longue exposed patrol schedules Nuclear submarine patrol patterns revealed through running data Mar 2026 French naval officer revealed aircraft carrier position Active military deployment compromised via Strava activity Apr 2026 519 UK personnel exposed at nuclear and intelligence sites, including 110 at Faslane Pattern-of-life data for Trident base and command staff Source: https://www.cloudswitched.com/news/strava-uk-military-data-leak-fitness-apps-business-risk-2026
  168. How did this breach happen? Some possibilities… For BYOD (Bring

    Your Own Device): • Organisational culture ignores security risks • Lack of Impact Assessment for BYOD • Individual staff expected to manage own devices • No audit of BYOD privacy settings • Security policies outdated
  169. Building digital resilience through people Many opportunities to improve the

    human aspects of cyber security in 3 key areas: • People-centred design – designing technologies, policies and processes with people in mind • Education – train your personnel • Culture – create an environment where it’s safe to ask questions, report concerns and admit mistakes around cybersecurity issues https://www.ncsc.gov.uk/collection/cyber-security-culture-principles/putting-people-at-the-heart-of-an-organisations-approach-to-cyber-security
  170. People-centred design • Update your cybersecurity policy • Add a

    specific section on BYOD, privacy-settings and location-sharing • Update your processes: • Task staff to review BYOD app permissions quarterly • Task staff to disable background location access for non-essential apps • Prioritise staff whose movement patterns reveal the most – e.g. staff on deployment • Review contractor and visitor policies and processes • Third parties visiting your premises may also broadcast location data. Consider guidance on pausing fitness tracking during site visits, particularly for sensitive facilities.
  171. Education: Staff awareness training • Make sure security information is

    up-to-date, readily available, and to the point • Show staff how to check their own privacy settings — it makes the abstract risk tangible. • Enhance learning through safe practice environments • Train staff with real examples – e.g., use the Strava military leak as a concrete example in security awareness training. • When training doesn’t address insecure practices, find another way – e.g. BYOD clinics
  172. Culture • Define a collective understanding of what is normal

    and valued in the workplace with respect to cybersecurity. • Make it safe to ask questions, report concerns and admit mistakes around cybersecurity issues • Promote continuous improvement through a learning culture • Provide an expert contact point to support staff in setting appropriate BYOD app permissions • Review regularly – technology and associated cyberthreats change fast
  173. Summing Up Think holistically about cyberthreats and digital resilience Critical

    aspects of cybersecurity may rely on people and processes across actors, actions and impacts. Cutting-edge digital tech is not always the answer People-centred design, culture and training can build digital resilience.
  174. SCOT-SECURE WEST 2026 · HILTON GLASGOW · 17 SEPTEMBER The

    Identity Security Blueprint Human + Non-Human — Securing the Complete Identity Ecosystem A field guide to every identity in your estate — including the ones you’ve never met. Hariharan N Lead Technical Consultant · ManageEngine
  175. PART 01 · THE WALL Rome built a perimeter twenty

    minutes from this room. HE AN N NE WA · R E’ N R H-WEST FRONTIER Old Kilpatrick Bearsden Falkirk o’ness River Clyde bath-house & all central belt Firth of Forth GLASGOW — you are here, just behind the lines BUILT AD 142 60 KM, COAST TO COAST FORTS EVERY 3 KM ABANDONED BY ~AD 162 The most sophisticated perimeter in Britain lasted about twenty years. Historic Environment Scotland — Antonine Wall (UNESCO World Heritage Site, “Frontiers of the Roman Empire”). THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 02
  176. PART 01 · THE WALL e i ete s don’t

    ail lo dl . he j st stop 1 · BUILT 2 · BYPASSED atte ing. 3 · ABANDONED At enormous expense By anyone with a boat Quietly, without ceremony Engineering marvel. Budget line nobody questioned. Everyone slept better. The threat didn’t attack the wall. It sailed around it, walked through the gates, or was already inside. Not torn down — outgrown. The map changed and the wall stopped describing anything real. i ewalls. V N concent ato s. “ he co po ate netwo k.” Our turf wall — and the estate has already moved. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 03
  177. PART 01 · THE WALL Meanwhile, everything you defend moved

    out. THE MAP WE DEFEND THE MAP THAT EXISTS Multi-cloud + a few hundred SaaS apps Users at desks, on the LAN Hybrid work from Oban to Orkney Apps in the data centre Contractors, MSPs, outsourced help desks One front gate: the firewall & VPN Thousands of integrations, tokens & pipelines The wall still stands. The kingdom moved. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 04
  178. PART 01 · THE WALL Attackers noticed before we did.

    HOW THE BIGGEST ONES STARTED 204 nationally significant UK cyber incidents in one year — up 130% 18 of them “highly significant” — also a record. Roughly four national-level incidents a week. NCSC Annual Review 2025 M&S, spring 2025. A convincing phone call to an outsourced help desk. Passwords reset for the callers. Ransomware followed — weeks of dead online orders and a ~£300M hit to operating profit, on the company’s own estimate. Co-op was hit by the same playbook weeks later and had to pull its own systems offline to contain it. No zero-day. A password reset. Sources: NCSC Annual Review 2025 (Sep 2024–Aug 2025); M&S market updates & reporting on the 2025 retail intrusions (attributed to the “Scattered Spider” cluster). THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 05
  179. THE PREMISE OF THE NEXT 25 MINUTES Identity is the

    perimeter now. …and most of your identities aren’t people. 01 THE CENSUS 02 Meet the identities you already employ THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 THE BLUEPRINT Five layers, humans and machines alike 03 T H E M O N D AY P L AN What to do before Friday 06
  180. PART 02 · THE CENSUS Run the census: who actually

    holds keys to your estate? THE WORKFORCE YOU KNOW • Employees • Contractors & temps • Partners & suppliers • Admins & break-glass accounts Gets onboarding, training, MFA and a leaving do. HE W RK RCE Y U D N’ Service accounts API keys & OAuth tokens Workload identities Certificates & secrets Scripts, jobs & RPA bots AI agents & copilots Gets created on a Friday afternoon and remembered never. Every entry on this slide can open doors. Only the left column gets security training. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 07
  181. A LOCAL CASE STUDY IN UNVERIFIED IDENTITY cotland’s ost a

    o s non-human identity. IDENTITY DOSSIER — “NE E” First reported AD 565 — by a monk, allegedly Sightings since Thousands, enthusiasm undimmed Successful verifications Zero Access revoked Never — try suggesting it Annual attention & budget Considerable LOCH NESS · ARTIST’S IMPRESSION (THE ONLY KIND AVAILABLE) Your directory is full of Nessies — accounts everyone believes in and nobody has ever verified. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 08
  182. PART 02 · THE CENSUS The census result nobody is

    ready for. 80+ : 1 machine identities for every human in the enterprise 42% of machine identities hold sensitive or privileged access 88% of organisations still define “privileged user” as human-only Many × more identities typically surface in discovery audits than IT believed existed (Gartner) CyberArk Identity Security Landscape 2025 — survey of 2,600 security decision-makers Sources: CyberArk Identity Security Landscape 2025; Gartner IAM leaders research, 2025 (as reported). Vendor-survey figures — treat as directional. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 09
  183. PART 02 · THE CENSUS Why the non-human half out-risks

    the human half. No MFA Immortal secrets You cannot push-notify a script. Most NHI auth is a static secret. Keys minted years ago, still valid, still in a config file somewhere. Never offboarded A service account never resigns and never hands back its badge. Uncounted Not in the “privileged user” definition, so not in the reviews either. Over-privileged Granted admin “temporarily” during a 2021 golive. Still admin. Nobod ’s job Created by a project that ended. Owned, officially, by no one. OWASP’s Non-Human Identity Top 10 puts improper offboarding at #1 — the ghost problem, formalised. Source: OWASP Non-Human Identities Top 10 (2025). THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 10
  184. PART 02 · THE CENSUS · EXHIBIT A August 2025:

    one chatbot, seven hundred victims. 1 2 3 4 A marketing chat widget Its OAuth tokens stolen ~700 Salesforce estates read Tickets mined for more keys The Drift chatbot — a tool most CISOs had never risk-assessed Attackers compromised the vendor’s dev environment and took the integration tokens Tokens replayed for days: valid, trusted, MFA never in the conversation Support cases searched for the AWS keys and passwords pasted inside them NO PASSWORD USED NO MFA PROMPT VICTIMS INCLUDED SECURITY VENDORS ONE VICTIM ROTATED 104 EXPOSED TOKENS The most effective sign-in of 2025 never touched a password field. Salesloft Drift supply-chain incident, Aug 2025; actor tracked as UNC6395 (Google Threat Intelligence/Mandiant). Cloudflare publicly disclosed 104 of its own tokens exposed and rotated. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 11
  185. PART 02 · THE CENSUS · NEW ARRIVALS And now

    we’ e ass-hiring a third workforce. 1M+ 1 in 4 67% AI agents built on a single platform in one quarter — up 130% on the quarter before enterprise breaches predicted to trace back to AI-agent abuse by 2028 of AI access in real estates flows through personal, unmanaged accounts Microsoft Copilot Studio, 2025 Gartner prediction — treat as analyst view Verizon DBIR 2026 An AI agent is your keenest new hire: works nights, never complains, moves at machine speed — and never read the acceptable-use policy. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 12
  186. PART 02 · THE CENSUS · CALIBRATION The 2026 numbers,

    without the vendor gloss. 39% 31% 48% of breaches involve credential abuse somewhere in the chain of breaches now begin with a vulnerability exploit — up 55% in a year of breaches involve a third party — doubled year on year As the initial way in it’s 13% and falling — attackers are moving, not leaving Patching still matters. Identity is a perimeter, not the only control Vendors, integrations, tokens: identities that belong to someone else Attackers didn’t abandon identity. They moved to the identities nobody watches. Source: Verizon Data Breach Investigations Report 2026. Also: 73% of ransomware victims had a credential leak in the preceding year. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 13
  187. PART 02 · THE CENSUS · CLOSE TO HOME Not

    ancient history. This postcode. SEPA NHS Dumfries & Galloway Glasgow City Council CHRISTM AS EVE 2020 M ARCH 2024 JUNE 2025 Ransomware took out Scotland’s environment watchdog. SEPA refused to pay, rebuilt in the open, and reported recovery costs of ~£5.5M — still cited as the honourable way to lose a fight. Ransomware crew stole and later published ~3TB of data, including patient information — identity-led extortion at its cruellest. Intrusion via servers run by a third-party supplier; citizen services knocked offline for weeks. The trusted-vendor identity was the way in. Every organisation in this room is one unverified identity away from a very long Christmas. Sources: SEPA/Audit Scotland reporting; NHS D&G public statements & Police Scotland; Glasgow City Council incident updates, 2025. Attribution language: “widely reported”. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 14
  188. PART 03 · THE BLUEPRINT The Identity Security Blueprint. Five

    layers. Every layer applies to humans and machines alike — that’s the whole trick. 01 V I S I BI L I TY One living census. Every identity, a named owner, a stated purpose. 02 G O V E R N AN C E Least privilege by access held — not by whether it has a pulse. 03 L I F E C Y CL E Joiners, movers, leavers — and birth, rotation, retirement for machines. 04 AU T O M AT I O N & AD AP T I V E AC C E S S Rotation and revocation on autopilot; trust that shifts with context. 05 R E S I L I E N CE Zero-trust posture: assume breach, contain blast radius, measure, repeat. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 15
  189. LAYER 01 · VISIBILITY Yo can’t gove n what o

    haven’t et. THE CENSUS, PROPERLY W H ER E T H E M AR K ET I S G O I N G • Discover everywhere identities live: directories, cloud consoles, SaaS admin panels, CI/CD pipelines, code repos, vaults • Every identity gets a named owner and a written purpose — “unclaimed” is a finding, not a status • Continuous discovery, not an annual spreadsheet safari • One view across human and machine — separate inventories recreate the blind spot you started with 70% of CISOs expected to adopt identity visibility & intelligence tooling by 2028 — Gartner’s top IAM prediction for 2026 Translation: your peers are counting. Auditors will follow. Source: Gartner, Predicts 2026 — Identity & Access Management (as reported). THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 16
  190. LAYER 01 · FIELD NOTES A field guide to spotting

    Nessies in your directory. Nobody will claim it No sign-in for 90+ days Ask three teams. Watch all three point at each other. Yet somehow “business critical” the moment you propose deletion. Password older than a P7 Privileges nobody can explain Set once, by someone who has since had two other employers. Domain admin “for the migration”. The migration finished in 2019. Verdict: if nobody claims it, retire it. (Not an option for the original Nessie — the tourism board has views.) THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 17
  191. LAYER 02 · GOVERNANCE “ ivileged” is abo t access,

    not species. YOUR FREE CHECKLIST • Least privilege for every identity type — a token with tenant-wide read is a privileged user, whatever HR says • Access reviews that include service accounts, tokens and agents — certify or expire, on a schedule • Scope by default: read-only unless written otherwise, one purpose per identity, no shared “utility” accounts • Break-glass documented, sealed and alarmed — not a sticky note with a domain-admin password OWASP Non-Human Identities Top 10 (2025) Improper offboarding · secret leakage · overprivileged NHIs · long-lived secrets · insecure auth — ranked, with fixes. Run your estate against it this month. Recall: 88% of orgs still define “privileged” as human-only. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 18
  192. LAYER 03 · LIFECYCLE Machines never resign. Plan for it.

    HUMANS HAVE A LIFECYCLE JOIN → MOVE MACHINES NEED ONE TOO → LEAVE HR triggers it. IT executes it. Auditors check it. It (mostly) works. BIRTH → ROTATE → RETIRE Provision with an owner + expiry. Rotate on schedule. Retire when the project does — not never. Aged 18 years: a premium age statement for a single malt. A crime scene for an API key. Whisky improves with age. Credentials do the opposite. Set expiry dates like a distillery sets bottling dates: deliberately. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 19
  193. LAYER 04 · AUTOMATION ah an has to e e

    be it, it won’t happen. Rotate on schedule Just-in-time access Secrets, keys and certs rotated by machinery, not by calendar reminders and good intentions. Zero standing privilege: rights granted for the task, expiring with it. The default state is “no”. Deprovision on trigger Respond at machine speed Leaver event, project closure, 90-day silence — any of them auto-disables first, asks questions after. Token stolen at machine speed must be revoked at machine speed. Playbooks, not meetings. Automation is how five people govern eighty thousand identities without becoming the bottleneck — or the burnout. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 20
  194. LAYER 04 · ADAPTIVE ACCESS Access policy, Glasgow-weather edition. Four

    seasons in one day is not a bug here — it’s the climate. Static trust decisions are dressing for the morning and hoping. Adaptive access checks the sky every time. Context on every request Phishing-resistant MFA Harden the help desk Device health, location, time, behaviour, session risk — signals decide: allow, step-up, or deny. Passkeys / FIDO2 for the roles attackers actually target first: admins, execs, help desk. Gartner projects major breach reduction as adoption spreads by 2029. The M&S lesson: verified callbacks, no password resets on charm. Gartner predicts 30% of orgs will remove service-desk account recovery entirely by 2028. And yes — adaptive applies to machines too: a service account calling from a new country at 3am deserves suspicion, not a free pass. Source: Gartner, Predicts 2026 — IAM (as reported). THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 21
  195. LAYER 04½ · THE NEW JOINERS Give every AI agent

    a badge, a boss, and a leaving date. A badge A boss A scope A diary A leaving date Its own identity per agent. No shared “AI service account” — that’s a Nessie with ambitions. A named human owner accountable for what it does — and for switching it off. Task-shaped permissions with expiry. An agent that can “do anything” eventually will. Full audit trail of actions taken — agents act at machine speed; so must your forensics. Decommissioning wired in at creation. Pilots that ended still running is how shadow AI is born. Treat agents as your newest joiner class — because Gartner expects 1 in 4 breaches to trace back to them by 2028. Source: Gartner prediction (analyst view); DBIR 2026 on shadow-AI growth. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 22
  196. LAYER 05 · RESILIENCE Zero trust is a posture, not

    a purchase. R EG U L AT I O N I S C AT C H I N G U P • Verify explicitly, every time — identity signals feed every access decision (NIST SP 800-207 is the reference architecture) • Assume breach: design so one stolen credential or token is a contained incident, not a company announcement • Segment by identity, not just by network — blast radius is an identity property now • It’s a maturity curve: census → governance → lifecycle → automation → adaptive — walked in order, revisited forever The Cyber Security & Resilience Bill is in the Lords now — tighter duties, wider scope, faster reporting for essential services and their suppliers. Laura Irvine’s 13:35 session has the legal detail. The strategic point: every draft regulation now assumes you know your identities — human and machine. Sources: NIST SP 800-207 Zero Trust Architecture; UK Cyber Security & Resilience (NIS) Bill, before Parliament 2026. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 23
  197. LAYER 05 · PROOF Numbers your board can watch move.

    Orphaned identities Median secret age Count with no owner → trending to ero Measured in days, not distillery years Time-to-deprovision Ownership coverage Leaver or trigger → access gone, in hours % of ALL identities with a named owner MFA coverage 100% of admin paths — a third of orgs still leave cloud-admin gaps (DBIR 2026) Rotation compliance % of secrets rotated on schedule, automatically If you can’t measure it, it’s a Nessie: much discussed, never confirmed. DBIR 2026 reference: 37% of organisations had cloud-admin accounts without MFA enabled. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 24
  198. BEFORE YOU GO · THE PREMORTEM Where this blueprint goes

    to die. Bought a platform, skipped the census Nobody owns the programme Tooling deployed onto an unknown estate automates the blind spots. Inventory first, invoices second. Identity that belongs to “IT generally” belongs to no one. It needs a name, a mandate and a budget line. Ran it as a project Governed humans, ignored machines Projects end. Identities keep breeding. This is a lifecycle function, like payroll — permanent and boring. The comfortable 1% gets perfected while the 80× population stays feral. That’s where your next incident lives. Most identity programmes fail on ownership, not technology. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 25
  199. PART 04 · THE MONDAY PLAN onda o ning, be

    o e the co ee’s cold. 1 COUNT Pull every account, key and token from one domain — just one. Note how many surprise you. 2 N AM E Assign each an owner. The unclaimed pile is your real risk register. 3 RETIRE Kill one Nessie — start with anything last used before the pandemic. Quarantine 30 days, then delete. 4 R O T AT E Find your oldest secret and rotate it today. If something breaks, congratulations: you found a dependency. 5 VERIFY MFA every admin path — and script the help-desk callback so charm stops working. Five moves, one domain. By Friday you’ll have fewer identities than you had on Monday — progress you can put on a graph. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 26
  200. THE ANTONINE LESSON The Romans went home after twenty years.

    Attackers won’t. Stop rebuilding walls. Keep a living census, govern every identity — human or not — and let trust adapt like the weather does. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 27
  201. IF YOU REMEMBER THREE THINGS The blueprint on a beer

    mat. 01 02 03 Identity is the perimeter — and it’s ostl non-human now. More than 80 machine identities per human, and the growth is agents. Your riskiest employees don’t have pulses. Yo can’t gove n what o haven’t et. One census, every identity, a named owner. Unclaimed is a finding. Visibility precedes every other control. One blueprint for both halves. Governance, lifecycle, automation, adaptive access — applied to people AND machines. Start Monday, one domain, five moves. THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 28
  202. SOURCES & FURTHER READING Check my homework. • Verizon Data

    Breach Investigations Report 2026 — credential abuse, third-party involvement, exploit growth, shadow-AI figures • OWASP Non-Human Identities Top 10 (2025) — the free NHI governance checklist • NIST SP 800-207 — Zero Trust Architecture • NCSC Annual Review 2025 — UK incident volumes and severity (Sep 2024–Aug 2025) • Salesloft Drift incident reporting — Google Threat Intelligence / Mandiant; Cloudflare disclosure (Aug–Sep 2025) • CyberArk Identity Security Landscape 2025 — machine:human ratio (80+:1), privileged-definition and sensitive-access figures (vendor survey of 2,600) • M&S / Co-op 2025 intrusions — company statements & market updates; NCSC commentary • Gartner, Predicts 2026: Identity & Access Management — identity visibility, servicedesk recovery, phishing-resistant MFA; AI-agent breach prediction (2028) • SEPA (Audit Scotland), NHS Dumfries & Galloway and Glasgow City Council public incident statements • Historic Environment Scotland — the Antonine Wall (no identities were harmed) THE IDENTITY SECURITY BLUEPRINT · SCOT-SECURE WEST 2026 29
  203. Tapadh leibh. Questions — hard ones welcome. Hariharan N ·

    Lead Technical Consultant, ManageEngine Find me afterwards at the ManageEngine stand — I’ll be the carbon-based identity.
  204. 80% of ransomware attacks are AI-driven* “In 2024, 80.83 percent

    of recorded ransomware events were attributed to threat actors utilizing AI.” 2025 MIT Sloan and Safe Security *MIT Sloan has now withdrawn a working paper that made that eyebrow-raising claim
  205. Data exfiltration over time Reining In Ransomware, Vol. 2 |

    Cyentia Institute Is ransomware the top threat? What about simple extortion?
  206. Identify threats to the tangible and intangible assets Not a

    threat to an average business. Even if interested, will stay quiet to preserve access. Biggest threat. Only present if activists target the business Only present for some organisations or individuals They generally collaborate through criminal ecosystems
  207. First, stop them getting in • Phishing (voice and email)

    • External vulnerabilities • Stolen credentials
  208. Email Phishing - Kill chain elements • • • •

    • • • • • • • • • • • • • • • • • • DMARC – can you recognise your own domains if you have multiple Scan incoming email – scan , replace links, scan or replace files Remove junk – less stress on the users, more productivity Train the users – users should get phishing designed to improve report rate, not reduce the click rate Provide users with one-click means of report and instant feedback (especially for the exercises) Don’t punish users for clicking links this leads to hesitation On-click – get the link reviewed again – by the email tool Then access reviewed by the web filter Use a good EDR Get an Identity Protection platform (which observes AD and Entra) 24/7 triage, and response Move left Set up conditional access policy – e.g. managed devices, GeoBlocking Disable Device Code authentication Use phish resistant Multi Factor Authentication Disable access to command line and PowerShell Reduce standing access to data stores – review need-to-know Remove local admin rights and rotate local admin credentials automatically Prevent domain-wide administrator credentials from being used on an end-user devices. Give domain, etc admin users secondary account with no email capability Patching Local escalation pen. test
  209. Stolen credentials • • • • • • • •

    Use a good EDR Get an Identity Protection platform (which observes AD and Entra) 24/7 triage, and response Move left Set up conditional access policy – e.g. managed devices, GeoBlocking Disable Device Code authentication Use phish resistant Multi Factor Authentication HaveIBeenPwnd or similar If you run your own sites: • MFA (again) • Lockouts, CAPTCHAs • Web Application Firewall Same as for Phishing
  210. External vulnerabilities • • • • • • Get a

    free account on SecurityScorecard and add your IPs + domains Register with Early Warning from NCSC Deploy EASM Advertise a responsible disclosure address and policy (NCSC has a toolkit) Scan for vulnerabilities from outside Scan for vulnerabilities from inside (agent-based)
  211. Ransomware • Immutable backups • EDR everywhere • 24/7 response

    Same as for Phishing • Shift left • Network segmentation (userland vs. serverland) Cloud (e.g. M365 exfiltration) • SSO • Identity Protection platform • 24/7 response • Reduce access rights to need-to-know basis • Managed devices / ZTN / CASB • Data Loss Prevention if possible Servers: Web proxy + DLP Same as for Phishing
  212. Key Info for Securing Self - KISS Common ways for

    attackers getting in: -Insecure external infrastructure – scan and patch (or decommission) -Phishing – educate, scan incoming email, safe links, lock websites, lock privileges, deploy XDR -Stolen credentials – MFA, lost devices, HaveIBeenPwnd.com Avoid a soft middle: -Excessive admin permissions – analyse and restrict -Excessive data access permissions – analyse and restrict -Insecure internal infrastructure – shut down, or patch Prepare to prevent the most worrying outcomes -Ransomware – have a solid backup -Data Exfiltration – stop the data getting out Services you (likely) need from outside: -1st line SOC -IR retainer -Insurance -Pen. test - Run assumed breach exercise annually!!!
  213. Where to start!!! Start with the smallest scope possible: -Things

    that directly connect to the internet -CVSS may be tough, start with KEV then
  214. More detailed frameworks Fast Cyber Essentials Plus Small scope Continue

    covering the full killchain TI Informed Killchain Focus on initial access and attacker objectives first Slow Slow is smooth smooth is Fast
  215. Wire speed When Mythos Preview was tested: • network was

    deliberately vulnerable and undefended • It was not running endpoint security products, network security appliances, and did not have active defenders. Mythos failed 70% of the time, with a budget of 100 million tokens per attempt ($2,500–$12,500 per attempt). Around $8,000–$42,000 per successful compromise of an environment that was not protected. CrowdStrike-2026-Global-Threat-Report ChatGPT and OpenAI go mainstream https://malwaretech.com/2026/09/machine-speed-is-a-liestop-trying-to-fight-ai-with-ai.html Do we really?
  216. 80% of ransomware attacks are AI-driven* “In 2024, 80.83 percent

    of recorded ransomware events were attributed to threat actors utilizing AI.” 2025 MIT Sloan and Safe Security *MIT Sloan has now withdrawn a working paper that made that eyebrow-raising claim
  217. AI will RTFM and it won’t get tired Do you

    really need it on your network? Anywhere near your data? If you do – there are no easy options – dig deeper
  218. And Quantum? • SaaS – not a problem we will

    solve ourselves • Legacy software – get rid of it, or put in a ZTN(A) wrapper • Software we wrote: • Inventory • Crypto agility • Start implementing PQC NIST standards
  219. Threat actor space for a typical organisation over last few

    years Not a threat to an average business. Even if interested, will stay quiet to preserve access. Biggest threat. Only present if activists target the business Only present for some organisations or individuals They generally collaborate through criminal ecosystems
  220. Threat actor space for a typical organisation now? Not a

    threat to an average business. Even if interested, will stay quiet to preserve access. Biggest threat. Only present if activists target the business Only present for some organisations or individuals We may see a rise of a low skilled attackers
  221. More detailed frameworks Fast Cyber Essentials Plus Small scope Continue

    covering the full killchain TI Informed Killchain Focus on initial access, attacker objectives, but also elevation and resources Slow Slow is smooth smooth is Fast
  222. Key Info for Securing Self - KISS Common ways for

    attackers getting in: -Insecure external infrastructure – scan and patch (or decommission) -Phishing – educate, scan incoming email, safe links, lock websites, lock privileges, deploy XDR -Stolen credentials – MFA, lost devices, HaveIBeenPwnd.com Avoid a soft middle: -Excessive admin permissions – analyse and restrict -Excessive data access permissions – analyse and restrict -Insecure internal infrastructure – shut down, or patch Prepare to prevent the most worrying outcomes -Ransomware – have a solid backup -Data Exfiltration – stop the data getting out Services you (likely) need from outside: -1st line SOC -IR retainer -Insurance -Pen. test - Run assumed breach exercise annually!!! AI: -Provide sanctioned, secure access -Block other by category or warn users on-access -Prevent users from running their own apps -Enforce managed devices access to data -Monitor access and data movements -Form a registry of allowed uses -Set agents to use rights of the user who run them -Check for exceptions Quantum cryptography: -Inventory -Crypto agility -Start implementing PQC NIST standards
  223. Dr Zibby Kwecka Please feel free to connect and discuss

    further https://www.linkedin.com/in/zibbyk/
  224. THANKS TO ALL OUR SPONSORS & EXHIBITORS Breakfast Briefing Sponsor

    Drinks Reception Sponsor Registration Sponsor
  225. NEW 7 OCT 2026 | Edinburgh 7 OCT 2026 |

    Edinburgh 22 OCT 2026 | Cardiff 19 NOV 2026 | Edinburgh 25th FEB 2027 | Edinburgh 1st April 2027| Edinburgh
  226. THANKS TO ALL OUR SPONSORS & EXHIBITORS #ScotSecureWest26 Breakfast Briefing

    Sponsor Drinks Reception Sponsor Badge & Lanyard Sponsor
  227. NEW 7 OCT 2026 | Edinburgh 7 OCT 2026 |

    Edinburgh 22 OCT 2026 | Cardiff 19 NOV 2026 | Edinburgh 25th FEB 2027 | Edinburgh 1st April 2027| Edinburgh
  228. September 2026 Scaling AI with Confidence A Unified Security Model

    for Data, Identity, and Actions Yuri Duchovny Global Field CTO
  229. How AI Creates Enterprise Value Revenue Expansion Operational Efficiency Financial

    Resilience • Personalize at scale (offers, pricing, experiences) • Automate repetitive + knowledge work • Better predictability (fewer surprises; tighter planning) • Grow pipeline via smarter cross-sell/upsell • Accelerate decisions + cycle times • Stronger cash conversion (working capital + spend discipline) • Create new AI-powered products/services Faster growth • Higher Customer Lifetime Value • Market share gains © Cyera Confidential - 2026 - All rights reserved • Reduce errors, rework, and exceptions Lower cost-to-serve • Higher productivity • Fewer errors • Lower downside risk (fewer control gaps; fewer costly incidents) Predictable outcomes • Cash flow expansion • Lower risk
  230. Beyond Moore’s Law: AI Is Scaling on Multiple Curves Moore's

    Law Transistor count on an integrated circuit AI infrastructure Leading AI supercomputer performance AI Scaling Law Compute used to train notable AI models DOUBLING TIMEFRAME GENERATIONAL LEAP 24 months AI inference economics DOUBLING TIMEFRAME 10× higher throughput per watt 1/10 the cost per token ~9 Months DOUBLING TIMEFRAME ~5 Months in one platform generation* As intelligence becomes cheaper and more abundant, AI can reach more data and take more actions—faster than traditional controls can respond. © Cyera Confidential - 2026 - All rights reserved
  231. Data is the Fastest Growing Resource in Volume and Value

    Global data generated annually (data generated zettabytes) 660 zettabytes 600 500 400 300 181 zettabytes 200 © Cyera Confidential - 2026 - All rights reserved 2030* 2025* 2024 2023 2022 FUEL FOR AI 2021 DARK DATA 100 2016 Data is the 2015 Up to 80-90% is Dark Data 2020 is the fastest growing attack surface 2019 is the least mature area in Cyber 2018 DATA 2017 DATA SECURITY
  232. Private Data is the Multiplier — and the Risk More

    data → more power. If restricted data becomes retrievable, it becomes generatable. Public Web Pretraining JPMorgan Chase Enterprise Data Estate • GPT-3 (Common Crawl): 45 TB pre-filter → 570 GB post-filter (~400B tokens) • ~500 PB internal data estate • >1 EB/day data movement across the firm • GPT-4 / ChatGPT: not disclosed Power • • • • Recency - answers reflect today’s business Domain context - contracts, policies, tickets, code Workflow signals - CRM, finance, ops systems Proprietary advantage - unique data + processes © Cyera Confidential - 2026 - All rights reserved Risk • Sensitivity — restricted data in prompts, training data sets & RAG • Permissions — over-entitlement + shadow connectors • Actions — write/send/delete expands blast radius • Logging & memory — prompts, chunks, embeddings
  233. Understand the AI Adoption Paths Generative AI AI Agent Agentic

    AI GenAI creates unique probabilistic content from prompts, often wrapped in fully–featured services AI agents are goal-driven software entities that use AI to execute multiple tasks to achieve outcomes Agentic AI autonomously plans, call tools and take actions with minimal human input TRIGGER TRIGGER TRIGGER Prompt → generates response User assigns task → agent executes steps User sets outcome → system plans & acts end-to-end Unique Probabilistic Response (Human asks, Model answers) Usually single goal, limited agency. Multi-agent coordination across multiple systems and tasks, wide Autonomy and Agency to find path to deliver outcome. CORTEX AI © Cyera Confidential - 2026 - All rights reserved
  234. POCKETOS / RAILWAY | REPORTED INCIDENT Cursor Agent Goes Off

    the Rails A staging task. An account-wide token. A production deletion. A INTENDED TASK A valid credential. A crossed boundary. Fix staging B ACTUAL IMPACT Production data 01 Fix a staging issue 03 Use broad access Resolve a credential mismatch. Use an account-scoped Railway API token. DATABASE + VOLUME BACKUPS 02 04 Find another token Delete production Search local files for credentials. Call volumeDelete on the production volume. Affected by the production deletion THE CONTROL LESSON The token allowed it. The task did not call for it. Reported sequence from the supplied incident material; not independently verified. Source links and qualifications in speaker notes. REPORTED IMPACT 9 seconds 1 API call Data later recovered
  235. More Utility = Greater Risk How can we provide customers

    visibility and control on the usage of these three components Data More Data More Risk Incorrect Outputs More Access More Risk Increase Costs High Risk Tool Access More Action More Risk No oversight No guardians control © Cyera Confidential - 2026 - All rights reserved Identity and Access Action
  236. The AI Control Gap: AI Adoption Is Outpacing Control Enterprise

    AI is scaling faster than the visibility and governance designed to manage it. VISIBILITY GAP THE GOVERNANCE GAP 77% of surveyed technology leaders report that AI adoption is already outpacing current governance capabilities. 70% say business teams are deploying technology faster than IT can track. AI adoption AGENT READINESS Governance Control gap 11% Faster adoption increases both accountability and exposure. believe they are fully ready for the expected scale of AIagent deployment. The challenge is no longer whether enterprises will adopt AI. It is whether visibility, governance, and control can keep pace. © Cyera Confidential - 2026 - All rights reserved Source: IBM Institute for Business Value, Technology Leader Study 2026. Survey of 2,000 technology CxOs across 33 geographies and 19 industries, Jan–Apr 2026.
  237. The Global AI Compliance Landscape Regulation is catching up with

    innovation - fast. Global landscape • • No single global AI rulebook - compliance remains a jurisdictional patchwork OECD.AI tracks 2,500+ policy initiatives across 80+ jurisdictions and organisations Key regulatory milestones (2025-2028) • EU: AI Act became applicable 2 Aug 2026 and transparency rules are active; high-risk obligations phase in 2 Dec 2027 and 2 Aug 2028. • US: No single comprehensive federal AI statute; federal policy favors innovation and national consistency, while state and sector requirements continue. NIST AI RMF remains a common voluntary baseline. • UK: Principles-based, regulator-led and sectorspecific. The AI Security Institute evaluates advanced-model security risks and is not a regulator. Existing privacy & standards • • Existing privacy, consumer protection, employment, intellectual-property and sector laws continue to apply ISO/IEC 42001 | ISO/IEC 42005 | NIST AI RMF + GenAI Profile © Cyera Confidential - 2026 - All rights reserved Sources: OECD.AI; European Commission; White House; NIST; UK AI Security Institute; Australian Government; OAIC; ISO. • AU: Guidance for AI Adoption sets six voluntary practices; new Privacy Act transparency duties for significant automated decisions begin 10 Dec 2026.
  238. AI Needs New Tech Measures for Managing Trust, Risk and

    Security (AI TRiSM) “Strengthen information and access governance to protect AI data and access.” © Cyera Confidential - 2026 - All rights reserved
  239. AI Security Playbook: 5 Questions to Ask Now What do

    we need to know first? © Cyera Confidential - 2026 - All rights reserved 01 Where is AI running today and what is the intent: public AI, embedded copilots, and custom agents? 02 What sensitive or business-critical data can it reach, including through tools and connected knowledge sources? 03 Who or what is acting, on whose behalf, and with what authority? 04 What actions can AI take—and which should be allowed or require approval for the task? 05 How do we test, enforce and prove control—and stop unsafe activity when needed?
  240. Secure AI transformation One Platform.Three Pillars. One Control Plane. Data

    Identity Agents Discover Discover & Inventory Discover Agents Classify & Understand Govern & Control Understand Intent & Actions Protect & Govern Manage Access & Entitlements Secure & Control Agents Unified Observability Layer Unified visibility across data, identities, agents and interactions Data Context Layer Classification, Lineage, Ownership, Sensitivity Risk, Residency, Business Context Decision Engine Identity + Intent + Data Context + Behavior = Real-time, Risk-Aware Decisions Control & Enforcement Allow, Deny, Step-Up, Contain Govern Human & Agent Actions in Real Time Continuous Feedback Loop Insights drive better policies, stronger posture and better outcomes.
  241. AI Security Platform Enable AI at scale – with data

    secured everywhere Posture Identity Protection Data DSPM Identity & Access DLP AI AI Posture AI Agent Security AI User Security At Rest In Use In Motion Unified Platform LLM Classification Agentless Discovery © Cyera Confidential - 2026 - All rights reserved IaaS DBaaS Workflows SaaS Remediation On-Pem Email Insights Network Security Agents Endpoint Models Agents
  242. AI-Native Classification Employee Assessment Vulnerability Assessment Report Product Sheet Patent

    Option Plan Tax Forms Recipe Boarding Pass Data Elements in Unstructured Files Discover unique data classes in unstructured data - created using rule-based models Utility Statement Password Claim Number File-Level Classifications Revenue Lot Number Unique unstructured data classes, created using LLM-based + rule-based logic it. Sample Number Fee Amount Structured Learned Classifications Full Name Drug Spec © Cyera Confidential - 2026 - All rights reserved Email Address Address Employee ID Payment ID Unique structured data classes, created using ML-based grouping logic Bank Account Number SKU And Many More…
  243. Data Security is Foundational to Securing AI Password Bank Account

    Number And Many More… Address Email Address Revenue Fee Amount Full Name Vulnerability Assessment Report Boarding Pass SQL DB DWH NoSQL DB Product Sheet Tax Forms Option Plan Employee Assessment Document DB Self-hosted DB Microsoft Sharepoint AI-Native Classification © Cyera Confidential - 2026 - All rights reserved Drug Spec Utility Statement Payment ID Sample Number Claim Number Lot Number Employee ID SKU Structured Learned Classifications File-Level Classifications Data Elements in Unstructured Files Salesforce Recipe Patent Salesforce SQL DB DWH NoSQL DB Document DB
  244. Data Security is Foundational to Securing AI Okta Password Bank

    Account Number And Many More… Address AWS IAM Email Address Revenue Fee Amount Full Name Entra ID Vulnerability Assessment Report Boarding Pass SQL DB DWH NoSQL DB Product Sheet Tax Forms Option Plan Employee Assessment Document DB Self-hosted DB Microsoft Sharepoint AI-Native Classification © Cyera Confidential - 2026 - All rights reserved Drug Spec Utility Statement Unity Catalog Payment ID Sample Number Claim Number Lot Number Employee ID SKU Structured Learned Classifications File-Level Classifications Data Elements in Unstructured Files Salesforce Recipe Patent Google Cloud Identity Salesforce SQL DB DWH NoSQL DB Document DB
  245. Data Security is Foundational to Securing AI Password ChatGPT Azure

    AI Foundry MS Copilot Amazon Bedrock Pinecone Okta AWS IAM Entra ID Google Cloud Identity Unity Catalog Bank Account Number And Many More… Address Email Address Revenue Fee Amount Full Name Vulnerability Assessment Report Boarding Pass SQL DB DWH NoSQL DB Product Sheet Tax Forms Option Plan Employee Assessment Document DB Self-hosted DB Microsoft Sharepoint AI-Native Classification © Cyera Confidential - 2026 - All rights reserved Drug Spec Utility Statement Payment ID Sample Number Claim Number Lot Number Employee ID SKU Structured Learned Classifications File-Level Classifications Data Elements in Unstructured Files Salesforce Recipe Patent Salesforce SQL DB DWH NoSQL DB Document DB
  246. Cyera Agent Guardian: Unified control plane for Enterprise AI Cyera

    Agent Guardian DISCOVER Inventory AI surfaces, users & data access Sensitivity • Access • Intent SSE / Secure Web Gateway API GOVERN Define policy for AI data Policies • Data Access Scopes • Allowed Actions Browser / Endpoints Agent Access Management Google Drive Amazon S3 Slack Salesforce Servicenow IaaS/PaaS/SaaS data stores + identity permissions © Cyera Confidential - 2026 - All rights reserved Runtime Enforcement • Monitoring • Remediation Provider APIs + audit logs Enterprise data + identities SharePoint Enforce guardrails, monitor & remediate PROTECT Runtime Protection API AI apps + platforms + agents ChatGPT Amazon Bedrock Copilot Gemini Microsoft Foundry Perplexity Agentforce Sanctioned + unsanctioned, embedded copilots, and custom agents
  247. AI Asset Inventory Eliminate shadow AI Discover all AI use

    automatically Inventory all AI tools - Public, SaaS, or homegrown, including “Shadow AI” See the full data context Have DSPM precisely classify data used within each AI tool Govern access with precision Know all human, machine, and agentic identities accessing AI and your data © Cyera Confidential - 2026 - All rights reserved
  248. AI Runtime Security Monitor and stop risky AI behavior in

    the moment Monitor every prompt & action Log, monitor, and search all prompts, responses, and agent actions Detect abuse & policy drift fast Catch misuse, prompt injection, and data leakage–with clear context & severity score Stop unauthorized access real-time Block out of policy prompts & responses; stop dangerous agent actions © Cyera Confidential - 2026 - All rights reserved
  249. AI Agent Security Graph Connect agents, identities and sensitive data

    to reduce exposure and accelerate investigation Conn Unified agent visibility Turn fragmented agent architectures into a single visual map of every agent’s lineage, dependencies, and connections Data-centric risk prioritization Prioritize the highest-risk execution paths by identifying the agents that can access your most sensitive data Active investigation Go beyond static monitoring with an investigation workspace built for rapid triage and remediation © Cyera Confidential - 2026 - All rights reserved
  250. Capabilities Agentic NHI The credential layer underneath every AI agent

    Every agent authenticates as something Find the key, token, service account or service principal that each agent acts as. Full credential lifecycle Rotate, decommission and expire agent credentials from one place. Privilege follows the credential Scope down never-expiring, overprivileged and orphaned credentials before an agent uses them. Ownership you can attest to Assign an owner to every credential. Attestation and the action log carry the audit trail. © Cyera Confidential - 2026 - All rights reserved
  251. Capabilities – Agentic Access Management From standing access to intent

    and session based access Intent The agent asks for one specific action, such as reading a single file. It does not ask for a role. Evaluation One policy engine checks who is asking, what the action is, and what it can reach. Ephemeral access Credentials are minted for that task and that session, then they expire. Audit Every session records the human intent alongside the agent action it produced. © Cyera Confidential - 2026 - All rights reserved
  252. AI Security Playbook – Take it Home Cyera helps operationalize

    each step across data, identities, and AI tools. Now • Discover and classify sensitive data; map human and non-human identities and their access • Discover AI use, agents, tools and knowledge sources; connect them to the data and identities they use • • Reduce sensitive-data exposure by removing excess access and securing NHI credentials behind agents, tools and connectors Start runtime monitoring and baseline blocking for high-risk workflows; test containment © Cyera Confidential - 2026 - All rights reserved Next Later • Define and apply policies for permitted data use and actions by identity, request and agent intent • Expand runtime detection and enforcement; monitor policy drift across AI workflows • Establish approval and exception paths for agents, connectors, sensitive-data access and high-risk actions, with accountable owners • Automate access reviews, credential lifecycle and remediation • Scale and test kill-switch and incidentresponse workflows across agents, sessions and access paths • Repeat red teaming and control validation as agents, tools, data and permissions change • Mature toward an AI TRiSM operating model with measurable exposure reduction and evidence of control • • • Implement task-scoped, sessionbound access with real-time authorization Red-team high-risk AI workflows before production or expanded access Connect requests, identities, data access, actions and policy decisions for investigation and audit
  253. THANKS TO ALL OUR SPONSORS & EXHIBITORS #ScotSecureWest26 Breakfast Briefing

    Sponsor Drinks Reception Sponsor Badge & Lanyard Sponsor
  254. NEW 7 OCT 2026 | Edinburgh 7 OCT 2026 |

    Edinburgh 22 OCT 2026 | Cardiff 19 NOV 2026 | Edinburgh 25th FEB 2027 | Edinburgh 1st April 2027| Edinburgh