3 related insights
Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.
Browse Attomus insight related to identity, with a focus on programme delivery, operational judgement, and professional execution in demanding environments.
Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.
A growing share of the traffic arriving at any organisation’s website is no longer human. Some of it is the familiar crawling of search engines. But an increasing fraction is something newer: AI agents acting on behalf of specific people – researching a purchase, evaluating a supplier, summarising a market, shortlisting firms for a piece of professional work. The recommendation that once came from a colleague’s memory or a page of search results now frequently comes from a model’s synthesis of what it read.
Read articleA zero-knowledge proof lets one party prove to another that a statement is true whilst revealing nothing beyond the truth of the statement itself: not the evidence, not the underlying data, not the working, only the fact. It sounds like a conjuring trick, and most people, hearing it described, assume it cannot be done. It can. The technique is not new. It was set out in a 1985 paper by Goldwasser, Micali and Rackoff; two of the three, Goldwasser and Micali, went on to receive the Turing Award, in 2012, for a body of work in cryptography of which this was a part. What has changed recently is practicality. Proofs that once demanded impractical amounts of computation can now be generated quickly enough for production systems, and the phrase has duly made its way from the journals onto the product brochures. That journey has not been kind to precision. What follows sets out what the technique actually offers, where it is earning its keep, and how to spot the cases where the phrase is carrying more weight than the mathematics.
Read articleFor years, security teams were taught to think in terms of edges, boundaries, and the network perimeter. That made sense when most users, systems, and data sat inside infrastructure the organisation owned and controlled. It makes far less sense now. Staff work remotely, applications live across cloud platforms, suppliers plug directly into shared systems, and automation now acts with privileges that used to belong only to people. In that world, identity has become the control point that matters most. If an attacker can authenticate successfully, or abuse an account that already has access, many traditional security layers become much less relevant. That helps explain why so many serious incidents now begin with a stolen credential, a weak service account, an over-privileged administrator, or a trust relationship nobody has reviewed in far too long.
Read article