Insights Topic

Risk Management

Browse Attomus insight related to risk management, with a focus on programme delivery, operational judgement, and professional execution in demanding environments.

Topic summary

5 related insights

Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.

Post-Quantum Cryptography: A Migration Guide for People Who Dislike Panic

The short answer first: the quantum threat to public-key cryptography is real, it is not imminent, and almost everything needed to deal with it in an orderly fashion already exists. That combination is rare in security. One audience is told the sky is falling and sold “quantum-safe” products of uneven seriousness; another decides the whole business is decades away and files it under someone else’s problem. Both are wrong, and the material needed to see why is all in the public record.

Read article

Trust Through Mathematics, Not by Contract

Ask most organisations why they trust a supplier with their data, and the answer, once unpacked, is a stack of paper. A contract with a confidentiality clause. A SOC 2 report. An ISO 27001 certificate. A data processing agreement. Perhaps a redacted penetration-test summary. Each of those documents says, in essence, the same thing: we promise to behave. Promises are not worthless. Commercial law exists, breach of contract carries consequences, and certification regimes do raise the floor of acceptable practice. But be clear-eyed about what a promise actually protects you from. A contract does not prevent a breach; it allocates liability after one. A certification does not stop an insider; it confirms that, at the time of audit, certain processes existed. Terms of service can be changed, acquired companies can be re-platformed, and well-intentioned suppliers can be compelled by courts or governments to do the very things they assured you they never would.

Read article

Shadow AI in the Enterprise: The Security and Data Risks of Unapproved GenAI Use

Generative AI is already part of day-to-day business. Staff use it to summarise meetings, draft documents, write code, analyse data, speed up research, and automate routine tasks. Some of that use is sanctioned. Some of it is not. That is the problem with shadow AI. It gives employees a useful shortcut, but it can also move client information, source code, personal data, and internal decision-making into services the organisation has not assessed.

Read article

Why Identity Is the New Perimeter, and How IAM Still Lets Organisations Down

For years, security teams were taught to think in terms of edges, boundaries, and the network perimeter. That made sense when most users, systems, and data sat inside infrastructure the organisation owned and controlled. It makes far less sense now. Staff work remotely, applications live across cloud platforms, suppliers plug directly into shared systems, and automation now acts with privileges that used to belong only to people. In that world, identity has become the control point that matters most. If an attacker can authenticate successfully, or abuse an account that already has access, many traditional security layers become much less relevant. That helps explain why so many serious incidents now begin with a stolen credential, a weak service account, an over-privileged administrator, or a trust relationship nobody has reviewed in far too long.

Read article

The Cybersecurity Paradox: Investing in What Organisations Hope to Never Need

A peculiar tension plays out in boardrooms across every sector: cybersecurity represents one of the most critical investments an organisation can make, yet it delivers none of the excitement that typically drives corporate spending decisions. This paradox has become a defining challenge for modern corporate governance, particularly as cyber threats continue to escalate in sophistication and frequency. When a company invests in product development, marketing infrastructure or operational technology, stakeholders can point to tangible outcomes — new features customers will value, expanded market reach, or efficiency gains that boost the bottom line. These investments generate enthusiasm amongst executive teams and shareholders alike because they promise growth, competitive advantage, and visible returns. Cybersecurity, by contrast, promises only that things will continue to function as they currently do. There are no new capabilities to demonstrate, no flashy innovations for the next AGM, no features that will delight customers or differentiate the organisation from its competitors.

Read article