Savount
Research and analysis on cyber conflict, artificial intelligence and the powers behind them, from APOLLOSEC.
Securing New Agentic Workers
A practical hardening guide for desktop AI agents: sandboxing, allow-lists, secrets, logging, and keeping work and personal contexts apart.
Latest
Securing New Agentic Workers
A practical hardening guide for desktop AI agents: sandboxing, allow-lists, secrets, logging, and keeping work and personal contexts apart.
AIAI agents are powerful. Are they secure?
Securing agentic AI before it becomes your biggest attack surface: prompt injection, memory poisoning, tool misuse and the defences that work.
GeopoliticsLessons From Recent Cyberattacks
M&S, Co-op and Harrods, Cartier and Coinbase: what recent attacks have in common, the techniques used, and what defenders should take from them.
CyberHow to Secure Your DevOps Pipeline: Risks, Tools, and Best Practices
The risks in modern CI/CD pipelines, the tools that help, and the practices that keep secrets, dependencies and build systems away from attackers.
CyberReplacing Annual Penetration Testing with Continuous Pen Testing
Why a yearly penetration test describes a system that no longer exists, and how continuous penetration testing closes the gap.
Field notesEmulating the Enemy – How Adversary Emulation is Elevating Offensive Security
How adversary emulation moved offensive security beyond the annual penetration test, and how to use real attacker behaviour to test your defences.
Threat actorsLessons from Hellcat’s Jira breaches
No zero-days and no novel malware: how the Hellcat crew breached enterprise Jira with stolen credentials, and the identity defences that stop it.
CyberCritical Vulnerabilities Keep Coming: The Urgency of Proactive Security
The gap between disclosure and exploitation keeps shrinking. Why critical vulnerabilities demand continuous, proactive security, not a yearly test.
CyberThe Costly Reality of Cybersecurity Gaps for SMBs
What security gaps really cost small and mid-sized businesses, from breaches and downtime to ransomware and fines, and how to build resilience on a budget.
CyberFrom Perimeter to Identity: The New SaaS Attack Frontier
Single sign-on, session tokens and MFA fatigue: why identity is now the main attack surface for SaaS, and how to defend it.
Threat actorsThreat Actors TTPs You Need to Watch in 2025
Five attacker techniques to watch: non-human identity attacks, pass-the-hash, supply chain compromise, Golden SAML and stolen remote access credentials.
GeopoliticsNavigating Supply Chain Risks
Why a supplier’s weakness becomes yours: lessons from SolarWinds, Log4Shell and Okta, and how to protect your organisation from supply chain attacks.
GeopoliticsPreparing for the Digital Operational Resilience Act (DORA): How Financial Services Can Comply with New EU IT Resilience Legislation
Who the EU Digital Operational Resilience Act applies to, what it asks of financial services firms, and how to prepare for it.
CyberCyber Breach Survey Insight: The Need to Know for UK Businesses and Charities
Key findings from the UK Cyber Security Breaches Survey 2024: what breaches cost, why phishing leads, and where boards stand on cyber risk.
CyberEnhancing Cloud Security: A Multi-Layered Approach
How attackers exploit cloud storage, web applications and deployments, and a layered approach to securing them, from zero trust to data security.
Field notesLiving on the Edge: An Adversary Playground
A walk through an engagement: how edge devices, leaked cloud keys and an open Trello board gave an attacker a path in, one step at a time.
CyberThe Essential Guide to Penetration Testing for SMBs
What penetration testing is, why small and mid-sized businesses are targeted, what testing gives you, and how often to do it.
CyberOffense is The Best Form of Defense
Why thinking like an attacker is the most effective way to defend, and the case for offensive security over checkbox compliance.
CyberThe 2024 Cyber Landscape: Insights and Strategies
The 2024 threat landscape in brief: the attack trends that shaped the year and the strategies organisations can use to respond.
CyberThe Key to Robust IT Security
The basics that stop most attacks: least privilege, password hygiene, patching, email controls and training, and why regular testing matters.
CyberSBOMs: Essential for Modern Software Security
What a software bill of materials is, why transparency in software matters, and how SBOMs help secure the software supply chain.
Nothing here yet. Interviews are in production for the first issue.
Cyber. AI. Power.
The magazine
A quarterly collection of the best research, interviews and field notes, written to be read at length. Join the list to receive the first issue.