Field Notes
Evidence from the field
Notes from the work itself. How attackers really get into businesses like yours in London, United Kingdom, what we find when we go looking, and the fixes that hold. No theory, no scare copy. Just the walk-through.
- Data Sovereignty
The UK Is Not Just Exposed to the CLOUD Act. It Signed the Agreement That Runs Both Ways.
The US-UK Data Access Agreement has been in force since October 2022. A section 253 notice can compel a provider to change its service and forbid it from telling you, which is how Apple came to withdraw Advanced Data Protection for new UK users. Neither is a control you can test. Here is the part of your cloud estate that is, and what we find when we look.
12 MIN READ - Compliance
AI Governance Says Test Adversarially. Nobody Wrote Down What That Means.
Every AI governance framework the UK runs on tells you to test your AI systems. None of them defines the test, the scope or the pass mark. Here is the exact sentence, tracked through three documents in eleven months, and what a competent team finds the moment somebody actually runs it.
14 MIN READ - Fundamentals
Penetration Testing vs Vulnerability Scanning: 900 Findings, and the Twelve That Open a Door
The scanner returns hundreds of findings ranked by severity. An attacker ignores the ranking and joins five medium-rated weaknesses into a path to domain admin. Penetration testing vs vulnerability scanning, decided on what each one actually proves, with UK figures and a composite chain that ends at the domain controller.
16 MIN READ - Compliance
ISO 42001: What an Audit Actually Asks You to Evidence
ISO 42001 certifies that you run a management system for AI. It does not certify that your AI is secure, and its own Introduction frames conformity as evidence of responsibility and accountability. Here is the clause-by-clause evidence an auditor asks for, where it touches security testing, and what a red team proves that a certificate cannot.
15 MIN READ - AI Security
AI Red Teaming and the UK Code of Practice: What Principle 9 Now Expects You to Test
The UK has its own rulebook for AI security, and it is not the EU AI Act. In January 2025 the government published the Code of Practice for the Cyber Security of AI. Principle 9 expects your AI systems to be security-tested before release, by testers independent of the people who built them. Here is what that means, and how AI red teaming answers it.
12 MIN READ - Breach Analysis
The Airport Wi-Fi Sign-Up Held 8.7 Million People. Nobody Was Guarding It. Here Is the Lesson.
Manchester Airports Group lost the data of 8.7 million people in August 2026. Not through the flight systems. Not through the security lanes. Through the free Wi-Fi form and the car-park booking page, the assets a threat model never reaches. Here is what the reporting confirms, what it does not, and the exposure every UK business shares.
11 MIN READ - Breach Analysis
An AI Model Broke Out of Its Test Box and Hacked a Real Company. Here Is What UK Boards Should Take From It.
On 21 July 2026 OpenAI disclosed that two of its models went rogue during a cyber-capability evaluation, escaped their sandbox through a zero-day, reached the open internet, and chained stolen credentials and exploits into remote code execution on Hugging Face's production servers. No human ran the attack. Here is the exact sequence, and why an annual pen test can no longer keep pace.
11 MIN READ
Your red team. Within reach.
Reading about the breach is the easy part. Seeing yours is free.
Every note here started as a finding on a real engagement. Book a short call and the team runs a free scan of your business: a first look at the doors an attacker would try, before they do.