Back to all editions
Edition#110·

AI Accelerates. Resilience Must Be Proven.

Cyber This Week Edition 110 explores ransomware recovery, AI agents, bot activity, incident response, zero trust, security architecture, threat intelligence, satellite resilience, and crisis communication.

AI agents are expanding what technology can do—and what organisations must secure. This week’s stories examine rising bot activity, the limits of traditional zero trust, security architecture for autonomous agents, and the narrowing window for defenders to turn AI capability into operational advantage. Resilience also demands evidence. From ransomware recovery and complex breach investigations to ageing threat intelligence and satellite dependencies, organisations need controls that remain effective under pressure. Our ten stories connect these challenges with a shared priority: test recovery, refresh assumptions, maintain human oversight, and strengthen coordination between security and marketing teams before a crisis damages customer trust.

Cyber This Week Edition 110 — AI Accelerates. Resilience Must Be Proven.
September 27, 2026 10 articles

This Week's Articles

  1. 01
    Channel Dive

    Ransomware risks rise as enterprise recovery capabilities erode

    The article identifies backup compromise as a major issue: although most firms claim immutable storage, 83% acknowledge weaknesses that could permit alteration or deletion. Boards should test whether backups are genuinely isolated, recoverable, and resilient to privileged credential compromise.

    Why it matters

    Backups cannot support recovery if attackers can alter or delete them. Organisations need to test isolation, access controls and actual recoverability rather than relying on immutability claims alone.

  2. 02
    SecurityInfoWatch

    Bad Bots, AI Agents Push Deeper Into High-Risk Online Activity

    AI agents made 605.6 million requests to higher-risk functions including logins, account creation, carts, and payment flows with login traffic rising more than eightfold in six months. Testing found 65.3% of over 21,000 websites failed to block or challenge any assessed bot or AI traffic. The practical concern is fraud, account takeover, and revenue loss, requiring behaviour- and intent-based controls rather than reliance on static bot identifiers.

    Why it matters

    Automated activity is reaching the parts of websites where accounts and transactions are at risk. Security controls need to assess behaviour and intent, not simply whether traffic identifies itself as a bot.

  3. 03
    JD Supra

    How to Handle the Growing Data Complexity Challenge in Cyber Incident Response

    Modern breach response is increasingly constrained by complex, interconnected, multi-format data rather than data volume alone. The article notes 1,803 reported US data compromises and 471.2 million victim notices in the first half of 2026, placing pressure on organisations to make fast, defensible notification decisions. It advocates risk-based data mining across cloud, SaaS, structured databases, messaging, images, and audio; context-aware AI search; robust validation; audit trails; and cross-functional coordination between legal, forensics, privacy, and business teams.

    Why it matters

    Accurate breach decisions depend on understanding how information connects across systems and formats. Validated analysis, audit trails and coordination help teams identify affected data and make defensible notification decisions.

  4. 04
    Computer Weekly

    Zero-trust was built for people. Nobody told it about agents

    The article argues that zero-trust programmes must evolve because AI agents can autonomously access applications, retrieve data, invoke APIs, and execute actions. It recommends continuously discovering and classifying all AI assets, treating agents as high-risk machine identities, enforcing context-aware runtime permissions, and inspecting both prompts and outputs for manipulation or data leakage. The author cautions against building a parallel AI-security regime: firms should extend existing zero-trust controls while maintaining human oversight for material decisions.

    Why it matters

    AI agents can act across systems without a person approving every step. Zero-trust controls therefore need to cover agent discovery, machine identities, runtime permissions and human oversight.

  5. 05
    Security Magazine

    Redesigning Security Architecture in the Agentic AI Era

    The article argues that traditional security architecture was not designed for AI agents that can assume identities, chain tools, access data, and act at machine speed. It recommends three architecture pillars: unified runtime visibility across infrastructure, identity, and data; hard, adaptive access boundaries with sandboxing and kill-switch capability; and agent-aware incident response. Response teams must be able to rapidly isolate suspicious agents, replay sessions, trace tool calls, and identify downstream changes while retaining human oversight for consequential decisions.

    Why it matters

    Organisations need to understand and control what agents do across connected systems. Visibility, access boundaries and agent-aware response capabilities help teams contain suspicious activity and trace its effects.

  6. 06
    SC Media

    How threat intelligence decays and when to reassess it

    The article explains that threat intelligence loses value at different rates: indicators such as IP addresses and domains decay as attacker infrastructure rotates; TTPs change when adversaries re-tool; vulnerability intelligence changes with patches, public exploits, confirmed exploitation, or end-of-life events; and analytic judgements weaken as contradictory evidence appears. It recommends linking every intelligence-derived control to an explicit reassessment trigger, expiry condition, evidence record, and accountable owner. This reduces false positives, stale detections, and risk decisions based on outdated assumptions.

    Why it matters

    Intelligence that was once useful can become misleading as conditions change. Clear reassessment triggers, expiry conditions and accountable owners help keep detections and risk decisions relevant.

  7. 07
    CPO Magazine

    Why Prevention Alone Doesn’t Make an Organization Cyber Resilient

    The article distinguishes prevention from resilience: prevention lowers the probability of a cyber event, whereas resilience determines whether an organisation can sustain essential operations during disruption and recover afterwards. The argument is particularly relevant as no control environment can eliminate ransomware, third-party failure, cloud outages, or human error. Enterprises should complement preventive controls with tested recovery capabilities, operational continuity plans, crisis leadership, dependency mapping, and recovery measures tied to actual business outcomes rather than the restoration of individual systems.

    Why it matters

    Preventing incidents and recovering from them require different capabilities. Organisations need tested recovery and continuity plans that demonstrate how essential business operations will continue or return.

  8. 08
    CSO Online

    The Cyber-AI parity window now has a deadline

    The article argues that AI initially created a rare period in which defenders and attackers gained access to transformative capability at roughly the same time. It warns that this “parity window” is narrowing as adversaries operationalise AI faster and security teams struggle with fragmented data, legacy technology, skills shortages, and slow control deployment. Its strategic message is that organisations should use the current window to strengthen AI-enabled detection, response, identity controls, data governance, and operational resilience before attacker advantage becomes more entrenched.

    Why it matters

    Access to AI does not automatically translate into effective defence. Organisations need to turn available capabilities into practical improvements in detection, response, governance and resilience.

  9. 09
    World Economic Forum

    Why the satellite communications boom needs stronger cyber resilience

    With more than 18,000 active satellites, the article warns of greater exposure to jamming, eavesdropping, unauthorised access, malicious updates, and compromise of ground or endpoint infrastructure. Concentration in large commercial constellations may also create single points of failure. Organisations should assess satellite dependencies as part of critical-infrastructure, supply-chain, and cyber-physical resilience planning.

    Why it matters

    Satellite connectivity creates dependencies across space, ground infrastructure and connected services. Organisations need to include these dependencies and potential failure points in their resilience planning.

  10. 10
    Dark Reading

    How the CISO-CMO Alliance Builds Trust Before Crisis Strikes

    The article positions cyber incidents as brand and trust events, not merely technology failures. It recommends regular engagement between CISOs and CMOs, joint crisis-communications planning, and translation of technical risk into customer, reputational, and commercial consequences. Pre-agreed communication protocols can reduce inconsistent messaging and enable a more credible response during an incident. Although less technically focused than the other articles, it offers a useful governance perspective for organisations managing customer trust, regulatory scrutiny, and reputational exposure following a breach.

    Why it matters

    A cyber incident can damage customer trust as well as systems. Security and marketing leaders need shared communication plans and a common understanding of business impact before a crisis occurs.

Newsletter

Get the next edition every Sunday