Skip to content
Secure And Assure Logo
  • Home
  • Services
  • News
  • About
  • Contact
  • Book a Free Consultation
Cyber 3-2-1Sam Glynn2026-06-13T17:38:53+01:00
  • Yay! Thanks to AI, Humans are no longer your weakest security link.
    June 14, 2026
    This week: Your reputation depends on your suppliers, your AI chatbot may be your weakest security link, and US Gov tells Anthropic to block access to its latest AI model only days after its release.
  • CBoI on DORA: Great paperwork. But where's the proof of your actual work?
    June 7, 2026
    This week: Three stories from three different regulators.
  • Your Staff Already Use AI, And Probably Not The AI You Approved
    June 1, 2026
    This week in 10 seconds: Your suppliers are your weak point, your staff are using unapproved AI tools, and don’t worry about advanced AI threats if you aren’t even doing the basics right.
  • Stop sharing photos of children online.
    May 24, 2026
    This week: The kids in a school photo end up in deepfake images. People are giving AI their bank details. And regulators remind us that the basics still matter.
  • The ROI of AI is not (just) efficiency
    May 16, 2026
    This week: A State body loses € 2.5 million through a phishing scam, kids defeat Age Verification with a marker, and we struggle to prove AI value because we're measuring the wrong thing.
  • AI regulation can't keep up with AI capabilities.
    May 12, 2026
    This week: Regulators struggle to keep up with the latest AI developments, an Irish bank is fined for getting the basics wrong, and it’s time to start planning for WHEN attackers have broken in.
  • AI doesn't need 'guard rails'. It needs a padded cell.
    May 2, 2026
    This week: An AI agent deleted a production database in seconds, “smart” AI can also be pretty “stupid”, and ransomware gangs may now target ‘little old you’ just because of the type of ‘security door
  • Your Governance Model is no match for Autonomous AI
    April 26, 2026
    This week: Europe launches a new DPIA template. Can your staff hand out door keys to anyone who asks? And your Governance Model is no match for Autonomous AI.
  • AI is now the world's fastest hacker.
    April 17, 2026
    This week: The world's fastest hacker may now be AI. Your CRM system may be a thing of the past. And confirmation that your AI chats are not confidential or legally-privileged.
  • That AI tool of the future? It might be gone tomorrow.
    March 29, 2026
    This week: €19 million shows the old scams still work, another bailout causes another moral hazard, and OpenAI says sayonara to Sora.
  • All it takes is one compromised password or AI tool
    March 21, 2026
    This week: One compromised password compromises 200,000 devices. One compromised AI chatbot compromises 700 organisations. And one helpful AI agent compromises Meta's internal systems.
  • The biggest threat to your privacy? It's you!
    March 15, 2026
    This week: A cyber attack on Stryker is rumoured to have wiped 200,000 devices. And two stories to demonstrate why 'smart' devices are really surveillance devices.
  • LinkedIn Verification: Don't Trust. Don't Verify.
    February 22, 2026
    This week: LinkedIn Verification is a verified privacy disaster; The EU Parliament blocks the AI barn door after the horse has bolted; And how one error cost a crypto firm $120 million.
  • Something big is happening and it's faster than we expected.
    February 15, 2026
    This week: An Outlook add-in that opened the door for an attacker, Google's insights into how attackers are really using AI, and a viral post on how AI is a major risk to our livelihoods.
  • When your anti-virus software becomes the virus
    February 9, 2026
    This week: Anti-virus software becomes the virus, a parent's guide to Generative AI is a great guide for all of us, and what the arrival of ads on ChatGPT could mean for users.
  • Apple Intelligence will be Google's Intelligence
    February 1, 2026
    This week: Apple chooses Google Gemini for Apple Siri. Browser extensions are an open door for attackers. And GDPR hasn't gone away, you know.
  • AI: Financial firms are balancing FOMO with FORI
    January 24, 2026
    This week: Snapchat buys its way out of a court case, AI may not be impacting entry-level jobs (yet), and financial services firms remain cautious about AI adoption.
  • AI in 2026: Don't worry about AI stealing your data. Worry about AI revealing it.
    January 18, 2026
    This week: I seem to have written 'Cyber 3-2-1: The AI Edition'. In truth, it's simply because the 3 stories that caught my attention this week all happen to relate to AI risk.
  • QR Codes, Browser Extensions, and the difference between DR and BCP
    January 11, 2026
    This week: Why QR Codes should be called RQ Codes, why you need to think about browser extensions, and why you can't insure your way out of doing the real work.
  • 2025: End Of Year Review
    December 21, 2025
    This week: In the last Cyber 3-2-1 of 2025, I look back over the most popular topics of the newsletter this year.

Cyber 3-2-1 moved to Substack in September 2025.
Issues from before this date are available in a separate archive.

View all issues since September 2025 View all issues before September 2025

Search

Topics

abuse accenture accountability ai aib airtag alexa analogy android apache apple appropriate security artificial intelligence assessment authenticator auto-forwarding availability avg aws azure backups bank bank of ireland basics bbc bitdefender blockchain bny mellon board board of directors browser budget budgets business continuity business impact assessment byod cbdc CBI central bank central bank of ireland certification change charities charity checklist children china chrome cirp CIS cisa cisco cloning clop cloud cloud security cloud services Cloud Systems cmmc cofence compliance compliance institute conti contract cookies cost of attacks cpd crisis PR crown jewels cryptocurrency crypto fraud cryto crytocurrency csf cve cvss cyber321 cyber attack cyber essentials cyber insurance cyber ireland cyberireland cyberquest cybersafekids cybersecurity cyber skills Cyber Through Crappy Graphics cyber vitals checklist cyber warfare daily dao DarkReading dark web data breach data protection data retention data wiper deepfake deepfakes deepseek defender defi dell democracy digital business ireland digital services act disaster recovery dns doj dora dpc drone duckduckgo dynamics employment encryption enisa enterprise ireland eset ethics EU events evidence example extortion facebook fathom analytics FBI fintech forrester fortinet framework frameworks fraud FSB ftc gaming Gardai gdpr godaddy google Google Workspace heineken hiscox home security hse hubspot human defence iaf ico IE image incident response incident response plan incident response planning information security insurance insuretech interpol interview invoice redirection fraud iob iphone ireland irisscon isaca isc2 ISO 27001 itgovernance IT MSP kev laptops LastPass law firms legal linkedin log4j malware managed service provider meta meta data metaverse Microsoft microsoft 365 microsoft teams mindset money laundering Money Mules MSP Multi-Factor Authentication Multi-Factor Authenticationpasswords mvsp mysecurityguide ncsc negotiating nis2 nis directive NIST north korea norton notpetya noyb NSA office365 oil opendns operational resilience operational technology password passwordless password manager password managers passwords patching patch management payment fraud PDP perception pestle phishing phishing email phishing emails phishing tests phone pirates plan b plugins police policy politicians pragmatic security controls privacy privacy shield privileged access privileged accounts professional services firms protection qnap qr codes quad9 ransomware ranwsomware rdp regtech regulation regulations regulator regulators regulatory compliance remote access remote working rep report risk management robotics romance fraud russia saas safe harbor salesforce santa scam phone calls scc sdlc sear SEC second opinion securethevillage security questionnaires self-driving cars self-employed senior executives service provider shodan sim swap sim swap fraud siteground skills shortage small bets small teams smart contracts smart glasses smart tech SME smishing sms social engineering social media software updates solo solo professionals sophos special category data staff staff awareness staff awareness training staff training startups statistics stolen credentials supply chain supply chain risk surveillance survey surveys test your defences the basics third third party risk management tiktok too big to understand tprm training uber uk uk ncsc uk post office ukraine unknown number updates US USB valuation vbir vendor vendor management verify victim video voicemail vulnerable users wannacry water treatment webinar website what whathasthisgottodowithcyber whathasthisgottodowithcybersecurity whatsapp white house whitelisting windows Windows 7 wordfence wordpress x zero days zscaler
Strategic advice and support for the executive held accountable for cyber security, data protection, and AI risk.
Data Protection Policy
Page load link
Go to Top