That Fraud Guy

111 Followers
11 Following
1.6K Posts
Global Cybersecurity expert of 30 years. British Computer Society Fellow, Member of the Ivor's Academy. Gartner Veteran. That Fraud Guy. Writer for Dark Reading

This is my ontology. 991 entities — threat actors, malware families, CVEs, relationships between them. Built over months, updated this morning with 14 new nodes from a single day's threat intel.

That's context engineering. The terminology has moved on from prompt engineering, but policy cycles haven't caught up.

The CISO who bans AI doesn't stop AI use. They stop visible AI use. Shadow AI is the direct result of prohibition, not permission.

Govern it. Don't wall it off.

The Pentagon declared Anthropic a supply chain risk.

Not for a breach. Not for a foreign ownership issue. Because Anthropic refused to remove safety guardrails from Claude.

The DoD wanted autonomous weapons decisions and mass surveillance capability. Anthropic said no. Hegseth invoked supply chain risk designation -- a tool previously reserved for Huawei.

For CISOs: your AI vendor's safety commitments are now subject to government compulsion. That belongs in your TPRM framework.

OpenAI signed a deal the same night. Their safety carve-outs are contractual, not technical. Harder to audit. Worth knowing.

Ransomware payments at 28% of attacks in 2026, per Chainalysis. Record low, attack volume still rising. Operators moved to exfiltration extortion. No encryption, no decryption key, no clear recovery path.

This week: NK actors used AI-generated fake developer job interviews to deliver in-memory malware with no disk artefacts. And Google/Mandiant closed a decade-long Chinese APT campaign that used Google Sheets as C2. Legitimate SaaS, trusted by default, for ten years.

Marquis v. SonicWall heads to trial. Seventy-four US banks, one breach pathway, one vendor in the dock. Vendor liability is becoming case law.

#infosec #CISO #ThreatIntel

Will Guardian Agents replace incumbent security tools? Wrong question.

Security behaviours don't come from a monitoring layer bolted on top. They emerge from how the agent is built.

The CISO question shouldn't be "which Guardian Agent do I buy?" It should be: does this agent have security properties intrinsic to how it's built, or does it need external supervision to behave?

Those are different problems.

Lucky Break

Chapter One - GOLDEN BALLS

Reality B-Sides
I'm pleased and proud to announce that @kuppingercole's Leadership Compass for Generative AI Defense is now available to members! Simply login and https://www.kuppingercole.com/research/lc81042/generative-ai-defense will give you one of the first analyst reports into this area, offering valuable advice to the CISO or security architects
Leadership Compass: Generative AI Defense

The Generative AI Defense (GAD) market addresses the emerging cybersecurity challenges posed by AI technologies. It focuses on security and compliance solutions that protect AI interactions,...

KuppingerCole
In today's SICO Intelligence Sunday Read: "It's pop-u-lar..."
https://www.cisointelligence.co/p/01f4d2ae-34a5-4142-84d0-045a86ef49f9/
What It Is to be In Demand. An Enlightening Read for Sunday, 23rd November 2025.

"It's pop-u-lar..."

CISO Intelligence.
In today's CISO Intelligence: Another digital tsunami, this new-fangled thing called progress, the lesson for today, keeping all bases covered, the party's over, and the same but different.
https://www.cisointelligence.co/grand-scale-deja-vu-dragging-systems-into-the-21st-century-how-to-handle-the-threat-landscape-painful-exposure-make-the-move-and-whos-doing-what-where-its-ciso-intelligence-for-wednesda/
Grand Scale Deja Vu, Dragging Systems into the 21st Century, How to Handle the Threat Landscape, Painful Exposure: Make the Move, Another Party's Over, and Who's Doing What Where. It's CISO Intelligence for Wednesday, 19th November 2025.

Another digital tsunami, this new-fangled thing called progress, the lesson for today, keeping all bases covered, the party's over, and the same but different.

CISO Intelligence.
In today's CISO Intelligence: The choreography doesn't always tell the story, when trust becomes a question mark, a dubious crown, a new use for a resurrected tool, not the Bond villain but close, and the red alerts we will all like.
https://www.cisointelligence.co/p/fc677655-54fc-436f-83bd-2b5f0298b4f6/
Dances in the Shadows, The Fault in Our Smart Machines, Ransomware That Multitasks, Retirement Revoked, Defense Under Attack, and Welcome Warnings. It's CISO Intelligence for Monday, 17th November 2025.

The choreography doesn't always tell the story, when trust becomes a question mark, a dubious crown, a new use for a resurrected tool, not the Bond villain but close, and the red alerts we will all like.

CISO Intelligence.
In today's CISO Intelligence: A very classy move.
https://www.cisointelligence.co/p/1d142642-f2d0-4a82-ba3b-23f0f37592f0/
The Soft Side of Cyber Warfare. A Heartwarming Read for Sunday, 16th November 2025.

A very classy move.

CISO Intelligence.