- This week: the DPC fines the HSE as much for keeping files as for losing track of them, the UK FCA reminds us that the basics matter, and why AI is not your BFF.
- Why ‘exit planning’ and ‘substitutability’ are more than just regulatory tickboxes
- This week: AIB reports a sharp rise in payment fraud, attackers take over the remote control software IT providers use, and Copilot can speed up the impact of a breach.
- This week: Compliance Institute's views on the most prevalent scams, Claude public links are more public than you think, and AI adoption may be slower than we're led to believe.
- This week: How AI escaped its masters, how China's AI helped the victim, and why I struggle to understand why this is just a marketing story.
- This week: An AI survey of Ireland's public sector, the DPC's growing problem of AI-powered complaints, and transferring personal data to the US just got difficult (again).
- This week: Most firms roll out AI and then roll it back, the world’s top cyber agencies say the boring basics still win, and why you need to worry about your non-human users.
- This week: The average cost of a data breach for an SME, the real pricing for AI is starting to emerge, and why florists have been way ahead of AI's algorithmic pricing.
- This week: Your reputation depends on your suppliers, your AI chatbot may be your weakest security link, and US Gov tells Anthropic to block access to its latest AI model only days after its release.
- This week: Three stories from three different regulators.
- This week in 10 seconds: Your suppliers are your weak point, your staff are using unapproved AI tools, and don’t worry about advanced AI threats if you aren’t even doing the basics right.
- This week: The kids in a school photo end up in deepfake images. People are giving AI their bank details. And regulators remind us that the basics still matter.
- This week: A State body loses € 2.5 million through a phishing scam, kids defeat Age Verification with a marker, and we struggle to prove AI value because we're measuring the wrong thing.
- This week: Regulators struggle to keep up with the latest AI developments, an Irish bank is fined for getting the basics wrong, and it’s time to start planning for WHEN attackers have broken in.
- This week: An AI agent deleted a production database in seconds, “smart” AI can also be pretty “stupid”, and ransomware gangs may now target ‘little old you’ just because of the type of ‘security door
- This week: Europe launches a new DPIA template. Can your staff hand out door keys to anyone who asks? And your Governance Model is no match for Autonomous AI.
- This week: The world's fastest hacker may now be AI. Your CRM system may be a thing of the past. And confirmation that your AI chats are not confidential or legally-privileged.
- This week: €19 million shows the old scams still work, another bailout causes another moral hazard, and OpenAI says sayonara to Sora.
- This week: One compromised password compromises 200,000 devices. One compromised AI chatbot compromises 700 organisations. And one helpful AI agent compromises Meta's internal systems.
- This week: A cyber attack on Stryker is rumoured to have wiped 200,000 devices. And two stories to demonstrate why 'smart' devices are really surveillance devices.
Cyber 3-2-1 moved to Substack in September 2025.
Issues from before this date are available in a separate archive.