How Axenic manages AI risk

Over the last several months, our team has been having some (occasionally vigorous) conversations about AI. Not whether to use it, but how to use it well. Through our early experiments with AI, we had proven to ourselves that its use brings significant benefits when combined with cybersecurity expertise. However, AI also introduces new risks that need to be carefully managed. I wanted to share where we’ve landed so far. Read More

The Changing Face of Jurisdictional Risk

I recently had a chat with Hannah Betts about national data sovereignty and AI sovereignty. I’m sceptical about much of the discussion about this topic. Mostly because there is very little evidence that it is a real (rather than theoretical) problem, and because most of the responses confuse the physical location of the data with the jurisdiction that applies to that data. But recent events with Anthropic and Fable have forced me to rethink this.


Stay ahead: Strengthen your business with third-party risk management

Third Party Risk Management

With the fast-paced business style, organisations nowadays heavily rely on third parties such as vendors, suppliers, logistics partners, cloud services providers, etc. These partnerships can offer great benefits but also could expose your organisation to risks. That’s where third-party risk management (TPRM) comes into play. TPRM provides a structured approach to evaluating and mitigating these potential risks.

Ready to take control and protect your business? Let’s dive into the world of TPRM!

Read More

Warning – Geeky Insurance Debate

Recently I’d been helping a customer negotiate their cyber security insurance – which turned out to be trickier than I expected. This got me thinking about the role that insurance played in cyber security. Then – coincidentally – I was reading a book on security (Paul Martin’s great “The Rules of Security”) and came across this sentence: “Insurance is sometimes described as a means of transferring risk, but it is really more of a mechanism for softening the financial impact of a loss.” (p 73). It got me wondering – at Axenic have we been thinking about insurance all wrong? Read More


From Chaos to Conformance: 4 Context of the organisation

Information security is all about context!

In my previous two articles in this series focused on developing an Information Security Management System (ISMS) based on ISO 27001:2013, I presented the common myths associated with the standard. In this article, I am going to provide an overview of the standard and section 4 Context of the organisation.

Read More

Rapid Reaction: Detecting or Reporting Information Security Incidents

This is the fourth article in a series that aim to help organisations build and maintain their information security incident management and response capability.

In the previous article I provided a bird’s eye view of the standard incident handling process. As noted previously, the incident handling process is triggered either by detecting or reporting security events. A number of security professionals believe that detecting an incident means looking for failure logs such as failed login, failed resource access etc.

Read More