5 related insights
Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.
Browse Attomus insight related to cybersecurity, with a focus on programme delivery, operational judgement, and professional execution in demanding environments.
Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.
Every conversation about data security eventually arrives, or should arrive, at the same place. Not “is the data encrypted?” – almost everything is encrypted now, in some sense, somewhere. The question that actually determines your position is: who can use the keys without your participation? It is striking how much architectural and marketing complexity exists to avoid answering that question plainly. This post is an attempt to answer it plainly.
Read articleFew phrases in technology have travelled as far from their technical meaning as “end-to-end encrypted”. It now appears on platforms whose architectures differ so fundamentally that the shared label conveys almost nothing. For an organisation deciding where its sensitive communication should live, the label is the start of the inquiry, not the end of it. This post sets out, as precisely as a general audience allows, what end-to-end encryption guarantees, the conditions attached to that guarantee, and the substantial ground it does not cover.
Read articleAsk most organisations why they trust a supplier with their data, and the answer, once unpacked, is a stack of paper. A contract with a confidentiality clause. A SOC 2 report. An ISO 27001 certificate. A data processing agreement. Perhaps a redacted penetration-test summary. Each of those documents says, in essence, the same thing: we promise to behave. Promises are not worthless. Commercial law exists, breach of contract carries consequences, and certification regimes do raise the floor of acceptable practice. But be clear-eyed about what a promise actually protects you from. A contract does not prevent a breach; it allocates liability after one. A certification does not stop an insider; it confirms that, at the time of audit, certain processes existed. Terms of service can be changed, acquired companies can be re-platformed, and well-intentioned suppliers can be compelled by courts or governments to do the very things they assured you they never would.
Read articleGenerative AI is already part of day-to-day business. Staff use it to summarise meetings, draft documents, write code, analyse data, speed up research, and automate routine tasks. Some of that use is sanctioned. Some of it is not. That is the problem with shadow AI. It gives employees a useful shortcut, but it can also move client information, source code, personal data, and internal decision-making into services the organisation has not assessed.
Read articleFor years, security teams were taught to think in terms of edges, boundaries, and the network perimeter. That made sense when most users, systems, and data sat inside infrastructure the organisation owned and controlled. It makes far less sense now. Staff work remotely, applications live across cloud platforms, suppliers plug directly into shared systems, and automation now acts with privileges that used to belong only to people. In that world, identity has become the control point that matters most. If an attacker can authenticate successfully, or abuse an account that already has access, many traditional security layers become much less relevant. That helps explain why so many serious incidents now begin with a stolen credential, a weak service account, an over-privileged administrator, or a trust relationship nobody has reviewed in far too long.
Read article