Skip to content
Steelwise
  • Services
  • About
  • Filings
  • Contact

Filings

Practical thinking on security, infrastructure, and AI. No thought leadership for the sake of it.

All Security Commentary Infrastructure Deep dive AI
  • What's your answer to the patch tsunami? 15 July 2026 · Security Commentary

    AI is finding and weaponising vulnerabilities faster than any manual process can triage them. Around 900 new CVEs a day, and only a handful that actually matter. This is a genuine question to other teams: what are you doing about it? Here are the things we do, and where you can tell us yours.

  • The UK just named its cloud concentration risk 14 July 2026 · Infrastructure Commentary

    The Treasury has designated four cloud and technology providers as Critical Third Parties to UK finance: Amazon, Google, Microsoft, and Oracle. The same four that dominate the market. The state has effectively named the concentration risk, and that changes the questions your customers ask about lock-in.

  • The Cyber Resilience Pledge is really about your suppliers 13 July 2026 · Security Commentary

    A voluntary pledge for big firms sounds like it isn't your problem. But one of its three asks is Cyber Essentials across the supply chain, and that supply chain is you. Here's what to do, and why a certificate is not the same as security.

  • The quiet tribunal that ran the .uk internet for 25 years 4 July 2026 · Deep dive Commentary

    Nominet's Dispute Resolution Service decided 5,525 fights over .uk domain names across 25 years. We analysed every published decision. This is the story they tell, from the first land-grab to the WIPO handover.

  • The .uk domain dispute service changes hands on Tuesday 4 July 2026 · Deep dive Infrastructure

    From 7 July 2026, disputes over .uk domain names are filed with WIPO in Geneva, not Nominet. What changes for anyone who owns a .uk domain, what stays the same, and the one deadline before the switch.

  • The case law nobody voted for 4 July 2026 · Deep dive Commentary

    With no statute and no judges, .uk domain disputes grew a genuine body of precedent: 3,365 citations anchored on a dozen home-grown decisions. And the foundations are the cases the brands lost.

  • The .uk land-grab happened twice, and the second one was scheduled 4 July 2026 · Deep dive Infrastructure

    When Nominet opened direct .uk names in 2014, the obvious ones were reserved for their .co.uk holders for five years. The month that protection lapsed, disputes surged, and they were overwhelmingly naked brand grabs.

  • A quarter of a century of .uk dispute records is moving to Geneva 4 July 2026 · Deep dive Commentary

    From Tuesday, the public record of every .uk domain dispute is hosted by WIPO, Nominet's own search tool is on a retirement path, and the data protection basis for the move is a question nobody has publicly answered.

  • What decides a .uk domain dispute: the story, not the paperwork 4 July 2026 · Deep dive Security

    Typosquatters lose 98% of .uk disputes. Holders of ordinary dictionary words usually keep them. Three-letter domains are a coin flip. What 5,525 decisions reveal about how domain cases are actually won and lost.

  • Who wins the fight for a .uk name (and the man who never lost) 4 July 2026 · Deep dive Commentary

    Big brands win .uk domain disputes 95% of the time or better. Individuals win 64%. And one respondent faced 28 complaints across 14 years and won every single one. What 25 years of decisions say about power in the naming system.

  • If your website runs this plugin, it could be the thing attacking your staff 2 July 2026 · Security Infrastructure

    A critical flaw in W3 Total Cache, a caching plugin on over 900,000 WordPress sites, lets an attacker run code on the server with no login. The real danger is not your site going down. It is your own site being turned into the thing that attacks everyone who visits it, including your staff. Update to 2.10.0.

  • Chrome is the keys to your castle, and it just shipped 382 fixes. Update it. 1 July 2026 · Security Commentary

    Chrome 150 fixes 382 security flaws, 15 critical, including sandbox escapes and remote code execution. None are being exploited yet, and there is no public proof of concept, which is exactly the window to patch in. For most businesses the browser holds every login that matters, so update it before that window closes.

  • The website your AI invents, and the attacker waiting to register it 1 July 2026 · AI Security

    AI assistants confidently hand back web addresses that do not exist. Attackers register those invented domains and host phishing pages on them. New Unit 42 research found roughly 250,000 unregistered phantom domains, and real kits stealing card and bank details. Here is how the attack works and what to tell your team.

  • The average attacker is inside your network for two and a half weeks before you notice 1 July 2026 · Security Commentary

    New research shows attackers now sit undetected on a network for an average of two and a half weeks, and nearly half of firms only find out once data has been stolen. Set against fresh UK police figures on ransomware losses, the lesson is that detection, not just prevention, is where most SMEs are exposed.

  • The sovereignty tax: why UK firms want off US cloud and cannot move 1 July 2026 · Infrastructure Commentary

    A new Civo study finds two-thirds of UK businesses could ditch US cloud providers over sovereignty concerns, yet only 15% have actually moved. The gap is a lock-in problem, and the practical lesson for smaller firms is to make switching possible before you ever need to switch.

  • When the attacker doesn't want a ransom 29 June 2026 · Security Commentary

    Most continuity plans quietly assume a ransomware attacker wants paying, which gives you something to negotiate. The Jaguar Land Rover attribution shows an attack dressed as ransomware that wanted no money at all, just the company on the floor. That changes what recovery has to plan for.

  • Why UK ransomware victims stay silent, and what it costs the rest of us 29 June 2026 · Security Commentary

    UK Report Fraud figures show only 323 organisations reported a ransomware attack in a year, with £270,000 in losses between them. The real number is far higher. Most victims stay quiet because being named feels like an admission of failure. That silence skews the threat picture everyone relies on, and it is worth deciding your reporting path before an incident, not during one.

  • You can't blame the AI 29 June 2026 · AI Security Commentary

    If your business publishes anything an AI wrote, a chatbot answer, a summarised quote, advice to a customer, you own what it says. 'The AI got it wrong' is not turning out to be a defence, and a German court has just said so about Google.

  • Five Eyes says the AI timeline is months, not years 28 June 2026 · Security AI

    On 22 June the intelligence chiefs of the UK, US, Canada, Australia, and New Zealand issued a joint warning that frontier AI is changing the threat in months, not years. The actions they ask for are not new. They are now urgent.

  • The HTTPS padlock is about to need renewing eight times a year 28 June 2026 · Infrastructure Security

    The certificate behind your website's padlock used to last a year. By 2029 it lasts 47 days, renewed eight times a year. Websites cope automatically. The systems you still renew by hand are the problem.

  • The US just put a 2030 deadline on post-quantum, and it is worth having on your radar 28 June 2026 · Security Commentary

    On 22 June a US executive order set hard deadlines for federal agencies and their contractors to move to post-quantum cryptography. The interesting part is not the deadline. It is the one task it forces everyone to do first.

  • UK museums ignored the British Library warning, and the lesson is not about museums 28 June 2026 · Security Commentary

    The Public Accounts Committee says UK cultural institutions have failed to learn from the British Library attack and remain highly vulnerable. The interesting failure is not technical. It is the belief that being low-profile is a form of protection.

  • When the source goes quiet: a side project, a free feed, and one bad week 8 June 2026 · Infrastructure Commentary

    A side project that grew into a million requests a day sits on one free Companies House feed. When that feed paused this month, it was a lesson in supply-chain dependency, and in what good engineering does about it.

  • What Lloyds Bank actually does when it deploys an AI agent 7 June 2026 · AI Security

    Lloyds Banking Group's security director shared at Infosecurity Europe how the bank actually deploys agentic AI in production. Eleven 'AI bets', a twelfth dedicated to security. Signed tools the agents cannot create. An internal agent marketplace. The world's first production red-team environment using OWASP Top 10 for agentic AI. They saw agent hijack.

  • Attackers are using Claude as the bait 6 June 2026 · Security AI

    Microsoft's threat intelligence team has tracked phishing campaigns built around ChatGPT, Claude, DeepSeek, and Copilot. A South African ChatGPT-themed wave hit 100,000 mailboxes a day. A Claude-themed wave reached 2,000 organisations across the US, UK, and India. The brand is the lure, the payload is the same old stealer.

  • The FBI counted $20 billion of internet crime. Look where it actually was. 5 June 2026 · Security Commentary

    The FBI's 2025 internet crime report logged $20.9 billion of reported losses, a 26% rise on 2024. Investment fraud is the largest category at $8.6 billion. Business email compromise is the largest enterprise threat at $3 billion. Ransomware, by reported loss, is smaller than either. The shape of the numbers is the story.

  • 68% of UK firms will spend more on cyber. Fewer than 30% feel ready. 4 June 2026 · Security Commentary

    Barclays surveyed 1,000 UK business leaders in April. Sixty-eight per cent plan to spend more on cyber security in the next year. Twenty-six per cent say AI brings new risks they cannot answer. Average spend hits £505,000, but a micro business spends £15,000 and a large one spends £1.3 million. The numbers underneath the headline are the more useful ones.

  • Zero-copy data, and the bank spending €2 million a year on moving data around 3 June 2026 · Infrastructure Commentary

    BNP Paribas spent up to €2 million a year on data copying, transformation, and reconciliation across 64 countries. Adding a new data source took more than a year. The fix, announced this month, was to stop copying the data and let consumers query it where it lives. The principle scales down to any SME with more than one system.

  • Killing the card: what UKPI means for UK SMEs 2 June 2026 · Infrastructure Commentary

    On 2 June the UK launched its first new payment scheme since Faster Payments in 2008. Thirty-one founding members, the big nine banks, GoCardless, TrueLayer, Token.io, Yapily. The target is the £1.5 billion a year that UK merchants pay Visa and Mastercard. Wave one is utilities, government, and charities. Wave two is the rest of e-commerce.

  • The UK just spent £7 billion on AI. Here's the bit for SMEs. 1 June 2026 · AI Commentary

    London Tech Week 2026 closed with around £7 billion of announced AI investment, £1.1 billion of it a government hardware plan, £200 million for adoption and skills, and £150 million tied to a fund managed by a former Intel CEO. Most of it goes to large companies. A useful slice is reachable by smaller ones.

  • Cloud bill shock and the quiet return of on-prem 31 May 2026 · Infrastructure Commentary

    Railway, a developer platform spending $24 million a year on Google Cloud, was switched off without warning for eight hours. Uber burned through its 2026 AI budget by mid-April. One Dell employee racked up $3,400 of token costs in a day. The numbers behind 'post-cloud' are real, even if the term is over-marketed.

  • The Computer Misuse Act fix that isn't 30 May 2026 · Security Commentary

    The government finally announced a statutory defence for security researchers under the Computer Misuse Act. The defence covers around 300 people. The UK has 70,000 cybersecurity professionals. The number you remember from this filing is 0.4%.

  • MFA prompt bombing, or when the attacker just asks nicely 29 May 2026 · Security

    The attacker already has the password. They press the login button. Your phone buzzes. They press it again. It buzzes again. Five times. Twenty. Two hundred. At three in the morning. Eventually somebody taps approve, just to make it stop. That's how Uber lost its single-sign-on, and it's how a lot of UK firms will lose theirs.

  • The EU Cyber Resilience Act is coming for your software 28 May 2026 · Security Commentary

    Two-thirds of open-source maintainers do not know the Cyber Resilience Act exists. Most UK firms shipping software into the EU haven't checked whether it applies to them. The deadline is December 2027 and the obligations include something most SMEs do not yet produce: a software bill of materials.

  • Your staff are using AI. You're paying twice. 27 May 2026 · AI

    UK workers use AI for almost everything and report it saves them twelve hours a week. They also spend 6.4 hours a week fixing what it produced. Eighty per cent of UK IT leaders just had an unplanned AI cost increase. The numbers underneath the productivity story are sharper than the headlines.

  • Patching by severity is over. Here's what replaces it. 26 May 2026 · Security

    Vulnerability exploitation is now the leading cause of breaches. AI is finding bugs faster than anyone can triage them. Time-to-exploit has gone from 840 days to under two. CISA has rewritten the federal patching rules. If your patching process still runs off CVSS scores, it is solving last year's problem.

  • What NCSC said this month: agentic AI and zero trust 25 May 2026 · Security AI

    The NCSC published two pieces of guidance in a fortnight that an SME owner can actually use. One is about agentic AI, the kind that takes actions on your behalf. The other is about zero trust network access. Both share the same underlying advice: the user's location stopped being a security signal a while ago.

  • Gov.uk Pay swapped Stripe for Adyen. Read the exit clause. 24 May 2026 · Infrastructure Commentary

    Gov.uk Pay is switching its payment processor from Stripe to Adyen for around 1,000 services. The interesting thing is not which provider won. It is that £9 billion of public-sector payments can be moved across at all, because the contract was designed for it.

  • When the IT guy turns up, and isn't the IT guy 23 May 2026 · Security

    The FBI has warned that the Silent Ransom Group is now sending people into law firm offices, claiming to be IT, then plugging a USB drive into a partner's machine. The script is short, reception lets them through, and the data leaves the building. The fix is mostly process, not technology.

  • GCHQ's narrowing window and the five-year cyber shield 22 May 2026 · Security Commentary

    From Bletchley Park on 27 May, the GCHQ director said the UK has a narrowing window to keep its technological edge, and announced a blueprint for an AI-driven national cyber defence. Read between the speech lines: the supply chain into critical infrastructure is the lever they actually have.

  • The Bank of England just named frontier AI as a stability risk 21 May 2026 · AI Commentary

    On 18 May the Bank of England, the FCA, and the Treasury jointly told regulated firms that frontier AI now exceeds what a skilled attacker can do. If you sell into financial services, the diligence questions you get this year are going to look different.

  • The VS Code extension that emptied GitHub's repos 20 May 2026 · Security Infrastructure

    A single GitHub employee installed a trojanised Nx Console extension and around 3,800 internal repositories walked out. The interesting question isn't what GitHub will do next. It's what your editor and browser extensions can already reach.

  • Subscription bombing: the distraction is the attack 19 May 2026 · Security

    Your inbox fills up with 2,000 newsletter confirmations in an hour. None of them are malicious. That's the point. The attacker is using the noise to hide a password reset, a fraudulent purchase, or a fake IT support call that lands moments later. A new EPFL paper has the data.

  • Business as code, not AI as business 18 May 2026 · AI Commentary

    A new wave of startups is publishing 'AI-native' org charts where seven named LLM agents do most of the work. The first step isn't restructuring around agents. It's making your business legible enough that anything, a new hire, an auditor, or eventually an agent, could read it and act on it. AI can help you get there. Future agent costs are a reason not to skip past it.

  • Your AI policy should say something 17 May 2026 · AI Security Commentary

    Most AI policies are vendor templates with the company name swapped in. They ban the obvious, permit the vague, and tell you nothing about how the business actually wants AI used. A coherent policy is a short one that takes a position.

  • Computer Misuse Act reform is finally on the bill 16 May 2026 · Security Commentary

    The 1990 Computer Misuse Act predates the public web. Reform has been promised for six years. The May 2026 King's Speech finally put it in a bill, bundled into the National Security Bill. Here's what's likely to change and what's still vague.

  • No, you don't need a web form for data complaints 15 May 2026 · Security Commentary

    A lot of guidance is telling UK businesses they need an electronic complaint form by 19 June 2026. The statute doesn't say that. It says facilitate, and gives a form as one example. Here's what's actually required and what isn't.

  • The real bill from the M&S and Co-op attacks 14 May 2026 · Security Commentary

    A year on from the April 2025 retail attacks, the numbers are in. M&S has posted £101.6 million in direct costs and a 16.4% fall in fashion sales. The Cyber Monitoring Centre put the combined bill at £270 million to £440 million. The useful lessons for an SME are the unglamorous ones.

  • The stuff you stopped using is still attacking you 13 May 2026 · Security Infrastructure

    The NCSC has published guidance on decommissioning assets. The headline is simple: things you no longer use stop being assets and start being liabilities. The boring work of switching them off is one of the highest-value security jobs most businesses skip.

  • Insider fraud is mostly the people you already hired 12 May 2026 · Security Commentary

    Cifas surveyed 2,000 UK employees at large companies. Nearly a quarter know someone who has fiddled expenses. One in eight know someone who has sold a login. Insider risk is a culture problem before it is a tooling problem.

  • The NCSC says brace for a patch wave. The NHS is pulling the curtains. 3 May 2026 · Security AI Commentary

    The NCSC has told UK organisations to prepare for a wave of urgent patches as AI accelerates vulnerability discovery. The same week, NHS England decided the answer was to make its open source repositories private. Only one of those approaches actually fixes anything.

  • Copy Fail: 732 bytes to root on every Linux server you forgot about 30 April 2026 · Security

    CVE-2026-31431 lets any local user become root on Ubuntu, RHEL, Debian, SUSE, Amazon Linux, and most other distros. The exploit fits in 732 bytes of Python. The bug has been there since 2017.

  • cPanel auth bypass: ask your host what they've done about it 30 April 2026 · Security

    CVE-2026-41940 lets an unauthenticated attacker take root on a cPanel or WHM server. It was being exploited for around a month before the patch landed. If your website lives on shared hosting, this affects you.

  • Phishing still works, AI just made it cheaper 29 April 2026 · Security

    The 2026 UK Cyber Security Breaches Survey says 43% of businesses had an incident in the past year. Phishing was involved in 85% of those. AI hasn't changed what works, it's just lowered the price of doing it at scale.

  • GoDaddy handed out a 27-year-old domain to a stranger in four minutes 28 April 2026 · Security Infrastructure

    Two-step verification on. Domain ownership protection on. GoDaddy transferred a non-profit's 27-year-old domain to a stranger in four minutes. The lesson is about the registrar layer most businesses never think about.

  • AI agents and the shadow AI you already have 26 April 2026 · AI Security

    Two thirds of UK organisations cannot account for what staff share with AI tools. Now agentic AI is being deployed faster than anyone can govern it. The two problems are the same problem.

  • Sovereign AI is only sovereign if you can actually switch 24 April 2026 · AI Infrastructure Commentary

    Two-thirds of UK IT leaders say they have an AI exit plan. Nearly half admit switching would seriously disrupt the business. A plan you can't execute is not a plan.

  • NCSC says passkeys first, passwords second 23 April 2026 · Security Commentary

    The NCSC has flipped its authentication advice at CYBERUK 2026. Passkeys are now the recommended default, and password plus two-step verification is the fallback. The reasoning is worth understanding.

  • The only SOC metric that matters, according to the NCSC 12 March 2026 · Security Commentary

    Tickets closed. Rules written. Logs ingested. The NCSC's Dave Chismon argues most security operations metrics actively make detection worse. The one that counts is whether you spot attacks in time.

  • The ICO is becoming the Information Commission 19 February 2026 · Security Commentary

    The UK's data protection regulator is being restructured under the Data (Use and Access) Act 2025. New board, new CEO, new statutory objectives. The name is the least interesting part.

  • What the Cyber Security and Resilience Bill actually means 19 February 2026 · Security Commentary

    The biggest overhaul of UK security regulation since 2018 is in committee. MSPs are in scope, incident reporting gets a 24-hour clock, and fines go up to £17 million. Here's what it means in practice.

  • The free security awareness campaign you didn't know existed 18 February 2026 · Security

    The NPSA gives away a complete, professionally designed security awareness campaign kit. Posters, booklets, checklists, and a full starter guide. Most organisations don't know it exists.

  • Chrome's first zero-day of 2026: update now, don't wait 17 February 2026 · Security Commentary

    CVE-2026-2441 is actively being exploited in the wild. A use-after-free bug in CSS handling means a crafted webpage is all it takes. Push the update now.

  • AI just claimed your spinning disks too 16 February 2026 · Infrastructure Commentary

    Western Digital's entire HDD capacity for 2026 is sold out. Cloud is 89% of their revenue. HDD prices are up 46% since September. The window for sensible storage pricing is closing.

  • Prompt injection is not the new SQL injection 16 February 2026 · AI Security Commentary

    Schneier and co have reframed prompt injection as 'promptware': a full 7-stage kill chain. The uncomfortable truth: LLMs can't distinguish instructions from data. This isn't a bug you can patch.

  • The first five minutes of incident response 15 February 2026 · Security

    Containment over correctness, reversibility over impact, protecting state before touching services. What your first five minutes should actually look like.

  • When your payment processor can't send a valid email 13 February 2026 · Infrastructure Commentary

    Viva.com sends verification emails missing the Message-ID header. Google Workspace and Zoho reject them. The fix is one line of code.

  • Microsoft is a cloud company that also makes Windows 12 February 2026 · Commentary

    Microsoft's FY2025 numbers tell a clear story. Azure and M365 are two-thirds of revenue. Windows is about 6%. This is a cloud and productivity company.

  • Patch your text editors 11 February 2026 · Security Commentary

    Notepad++ had its update service hijacked by state-sponsored attackers. Windows Notepad got a CVSS 8.8 command injection. Two editors, two attack vectors, same lesson.

  • Insecure defaults have a long half-life 10 February 2026 · Security Commentary

    Global Telnet scanning dropped overnight in January 2026. Days later, a critical telnetd authentication bypass was disclosed. The protocol is old. The lesson is current.

  • What Cyber Essentials actually involves 7 February 2026 · Security

    A plain-English walkthrough of the five Cyber Essentials controls, what the assessment looks like, and what it does and doesn't prove about your security.

Steelwise

A trading name of Technical Director Ltd (company number 08512222).

Technology advisory, based in Sheffield.

[email protected]

0114 376 7987

  • Contact
  • Filings
  • RSS
  • Privacy
  • Terms

We use cookies to understand how visitors use this site. More information.