Making security understandable

Blog

Practical security insights for technology leaders.

March 2026

BSides Lancashire 2026: Red Teaming LLMs

We're speaking at BSides Lancashire on 26 March - "Red Teaming LLMs: A Practical Guide to Breaking AI Applications." Slides and write-up coming soon.


March 2026

Your AI Assistant Has a Shadow Audience

You installed a ChatGPT sidebar extension to be more productive. Someone else installed one to read everything you type. Over 900,000 installs across more than 20,000 enterprises -and the extensions did exactly what they promised, plus something else entirely.

Read more →


March 2026

The Security Boundary Isn't the AI App -It's the Interaction Layer

CISOs finally have AI security budget. But most are asking the wrong question. They're evaluating AI applications when they should be evaluating what flows between users and models.

Read more →


March 2026

Compliance Theatre: What the Delve Scandal Means for Your Security Reports

A YC-backed compliance startup has been accused of fabricating SOC 2, ISO 27001, and HIPAA reports for hundreds of companies. Five questions to ask your security provider - and what good looks like.

Read more →