AI Accelerates. Resilience Must Be Proven.
Cyber This Week Edition 110 explores ransomware recovery, AI agents, bot activity, incident response, zero trust, security architecture, threat intelligence, satellite resilience, and crisis communication.
AI agents are expanding what technology can do—and what organisations must secure. This week’s stories examine rising bot activity, the limits of traditional zero trust, security architecture for autonomous agents, and the narrowing window for defenders to turn AI capability into operational advantage. Resilience also demands evidence. From ransomware recovery and complex breach investigations to ageing threat intelligence and satellite dependencies, organisations need controls that remain effective under pressure. Our ten stories connect these challenges with a shared priority: test recovery, refresh assumptions, maintain human oversight, and strengthen coordination between security and marketing teams before a crisis damages customer trust.

This Week's Articles
- 01Channel Dive
Ransomware risks rise as enterprise recovery capabilities erode
The article identifies backup compromise as a major issue: although most firms claim immutable storage, 83% acknowledge weaknesses that could permit alteration or deletion. Boards should test whether backups are genuinely isolated, recoverable, and resilient to privileged credential compromise.
Why it mattersBackups cannot support recovery if attackers can alter or delete them. Organisations need to test isolation, access controls and actual recoverability rather than relying on immutability claims alone.
- 02SecurityInfoWatch
Bad Bots, AI Agents Push Deeper Into High-Risk Online Activity
AI agents made 605.6 million requests to higher-risk functions including logins, account creation, carts, and payment flows with login traffic rising more than eightfold in six months. Testing found 65.3% of over 21,000 websites failed to block or challenge any assessed bot or AI traffic. The practical concern is fraud, account takeover, and revenue loss, requiring behaviour- and intent-based controls rather than reliance on static bot identifiers.
Why it mattersAutomated activity is reaching the parts of websites where accounts and transactions are at risk. Security controls need to assess behaviour and intent, not simply whether traffic identifies itself as a bot.
- 03JD Supra
How to Handle the Growing Data Complexity Challenge in Cyber Incident Response
Modern breach response is increasingly constrained by complex, interconnected, multi-format data rather than data volume alone. The article notes 1,803 reported US data compromises and 471.2 million victim notices in the first half of 2026, placing pressure on organisations to make fast, defensible notification decisions. It advocates risk-based data mining across cloud, SaaS, structured databases, messaging, images, and audio; context-aware AI search; robust validation; audit trails; and cross-functional coordination between legal, forensics, privacy, and business teams.
Why it mattersAccurate breach decisions depend on understanding how information connects across systems and formats. Validated analysis, audit trails and coordination help teams identify affected data and make defensible notification decisions.
- 04Computer Weekly
Zero-trust was built for people. Nobody told it about agents
The article argues that zero-trust programmes must evolve because AI agents can autonomously access applications, retrieve data, invoke APIs, and execute actions. It recommends continuously discovering and classifying all AI assets, treating agents as high-risk machine identities, enforcing context-aware runtime permissions, and inspecting both prompts and outputs for manipulation or data leakage. The author cautions against building a parallel AI-security regime: firms should extend existing zero-trust controls while maintaining human oversight for material decisions.
Why it mattersAI agents can act across systems without a person approving every step. Zero-trust controls therefore need to cover agent discovery, machine identities, runtime permissions and human oversight.
- 05Security Magazine
Redesigning Security Architecture in the Agentic AI Era
The article argues that traditional security architecture was not designed for AI agents that can assume identities, chain tools, access data, and act at machine speed. It recommends three architecture pillars: unified runtime visibility across infrastructure, identity, and data; hard, adaptive access boundaries with sandboxing and kill-switch capability; and agent-aware incident response. Response teams must be able to rapidly isolate suspicious agents, replay sessions, trace tool calls, and identify downstream changes while retaining human oversight for consequential decisions.
Why it mattersOrganisations need to understand and control what agents do across connected systems. Visibility, access boundaries and agent-aware response capabilities help teams contain suspicious activity and trace its effects.
- 06SC Media
How threat intelligence decays and when to reassess it
The article explains that threat intelligence loses value at different rates: indicators such as IP addresses and domains decay as attacker infrastructure rotates; TTPs change when adversaries re-tool; vulnerability intelligence changes with patches, public exploits, confirmed exploitation, or end-of-life events; and analytic judgements weaken as contradictory evidence appears. It recommends linking every intelligence-derived control to an explicit reassessment trigger, expiry condition, evidence record, and accountable owner. This reduces false positives, stale detections, and risk decisions based on outdated assumptions.
Why it mattersIntelligence that was once useful can become misleading as conditions change. Clear reassessment triggers, expiry conditions and accountable owners help keep detections and risk decisions relevant.
- 07CPO Magazine
Why Prevention Alone Doesn’t Make an Organization Cyber Resilient
The article distinguishes prevention from resilience: prevention lowers the probability of a cyber event, whereas resilience determines whether an organisation can sustain essential operations during disruption and recover afterwards. The argument is particularly relevant as no control environment can eliminate ransomware, third-party failure, cloud outages, or human error. Enterprises should complement preventive controls with tested recovery capabilities, operational continuity plans, crisis leadership, dependency mapping, and recovery measures tied to actual business outcomes rather than the restoration of individual systems.
Why it mattersPreventing incidents and recovering from them require different capabilities. Organisations need tested recovery and continuity plans that demonstrate how essential business operations will continue or return.
- 08CSO Online
The Cyber-AI parity window now has a deadline
The article argues that AI initially created a rare period in which defenders and attackers gained access to transformative capability at roughly the same time. It warns that this “parity window” is narrowing as adversaries operationalise AI faster and security teams struggle with fragmented data, legacy technology, skills shortages, and slow control deployment. Its strategic message is that organisations should use the current window to strengthen AI-enabled detection, response, identity controls, data governance, and operational resilience before attacker advantage becomes more entrenched.
Why it mattersAccess to AI does not automatically translate into effective defence. Organisations need to turn available capabilities into practical improvements in detection, response, governance and resilience.
- 09World Economic Forum
Why the satellite communications boom needs stronger cyber resilience
With more than 18,000 active satellites, the article warns of greater exposure to jamming, eavesdropping, unauthorised access, malicious updates, and compromise of ground or endpoint infrastructure. Concentration in large commercial constellations may also create single points of failure. Organisations should assess satellite dependencies as part of critical-infrastructure, supply-chain, and cyber-physical resilience planning.
Why it mattersSatellite connectivity creates dependencies across space, ground infrastructure and connected services. Organisations need to include these dependencies and potential failure points in their resilience planning.
- 10Dark Reading
How the CISO-CMO Alliance Builds Trust Before Crisis Strikes
The article positions cyber incidents as brand and trust events, not merely technology failures. It recommends regular engagement between CISOs and CMOs, joint crisis-communications planning, and translation of technical risk into customer, reputational, and commercial consequences. Pre-agreed communication protocols can reduce inconsistent messaging and enable a more credible response during an incident. Although less technically focused than the other articles, it offers a useful governance perspective for organisations managing customer trust, regulatory scrutiny, and reputational exposure following a breach.
Why it mattersA cyber incident can damage customer trust as well as systems. Security and marketing leaders need shared communication plans and a common understanding of business impact before a crisis occurs.
