Business & Technology
Dropzone AI launches threat hunter for security teams
JOSEPH GABRIEL LAGONSIN
News Editor
Dropzone AI has launched general availability of its AI Threat Hunter product, aimed at enterprises, managed security service providers and government agencies.
The product is designed to make threat hunting a routine security operations task rather than an occasional specialist exercise. It runs scheduled hunts across security systems and produces findings for analysts to review and act on.
Threat hunting sits alongside conventional alerting in cybersecurity operations. Alerts are built to flag activity that matches known rules or suspicious patterns, while hunting looks for threats, risks and gaps that may not trigger those alerts.
That work has often been difficult to sustain. Security teams typically need experienced staff, tailored queries and long blocks of analyst time to carry out a single hunt, which can limit how often the work is done or stop it altogether.
AI Threat Hunter uses a library of more than 270 prebuilt hunt packs mapped to attacker behaviour and the MITRE ATT&CK framework. Each pack contains between five and 10 hunts, and the system can return results in around one to two hours for tasks that previously took far longer.
The product is already being used to run federated hunts across platforms including Splunk, Microsoft Sentinel, CrowdStrike NG-SIEM, Elastic and Panther. It also highlights visibility gaps, policy violations, misconfigurations and potential detection opportunities alongside active threats, according to Dropzone AI.
Broader push
The release extends Dropzone AI’s effort to build a broader set of automated security tools for security operations centres. More than 300 enterprises and managed security providers already use its platform, according to the company.
Among the customer examples it cited, Zapier reduced triage time from 10 to 15 minutes to under two minutes, UiPath saved more than 700 analyst hours and cut false positives by 86%, and Assala Energy achieved full alert investigation and faster response times with a smaller team.
Dropzone AI said beta use of AI Threat Hunter automated the equivalent of 200 years of hunting work. Further additions are planned, including custom hypothesis-based hunts, support for more data sources and closer links with its AI SOC Analyst product.
Cybersecurity vendors have increasingly focused on automation as defenders face growing alert volumes, broader attack surfaces and persistent staffing shortages. That has led many suppliers to pitch systems that can take on parts of triage, investigation and response that were previously handled manually.
Dropzone AI is positioning AI Threat Hunter for the less visible part of that workload. Rather than reacting to what detection rules already surface, the tool is intended to help teams systematically search for signs of compromise or weak points that might otherwise remain unnoticed.
Edward Wu, Founder and Chief Executive Officer of Dropzone AI, described the launch as a response to the imbalance between attackers and defenders.
“Attackers already operate at machine speed. Compute, not skill, is their bottleneck now, and defenders can’t out-hire that gap. AI Threat Hunter lets any team proactively identify undetected intrusions at the same speed, turning hunting from a once-a-year luxury into an operational habit and levelling a field that’s been tilting toward attackers for years. Analysts can now stay focused on the judgment only they can give rather than the mechanics of building and running hunts,” Wu said.
The company also pointed to feedback from early use in operational settings.
“AI Threat Hunter ran this without pulling a single person off their queue, and by the end of it we had a clear, evidence-backed finding we could take straight to leadership. That’s the kind of leverage a security team actually needs,” Spillman said.
Business & Technology
Phoenix Software staff win Broadcom VCF Knight status
JOSEPH GABRIEL LAGONSIN
News Editor
Phoenix Software has announced that two employees have achieved Broadcom VCF Knight status, Broadcom’s highest recognition for partner professionals.
Infrastructure Practise Lead Richard Worth and Senior Technical Consultant Robert Dent both received the Broadcom VCF Knight – Storage certification, recognising expertise in VMware Cloud Foundation-related storage.
The achievement strengthens Phoenix’s position within Broadcom’s partner network, where it holds UK Pinnacle and Expert Advantage status. It also reflects continued investment by the York-based business in technical staff with specialist VMware expertise.
Broadcom’s Knight programme identifies partner specialists with experience in the architecture, design, implementation and support of Broadcom technologies. In this case, the focus was on VMware Cloud Foundation and related storage work.
The process involves several stages rather than a single exam. Candidates must pass multiple advanced technical tests, submit evidence of customer designs, deliver a live technical demonstration to a Broadcom sponsor, and then undergo nomination and review by a Broadcom panel.
The certification typically takes several months to complete and requires periodic renewal, making it a relatively rare qualification within the VMware and Broadcom partner ecosystem.
Worth has worked in IT for more than 25 years, including nine at Phoenix, where he leads the infrastructure practice. His background spans networking, storage and virtualisation, all closely tied to the technologies covered by VMware Cloud Foundation.
Dent has worked with VMware technologies for more than 20 years, beginning during an early IT apprenticeship and later implementing virtualisation environments at the University of Hull. His experience also includes servers, storage, NetApp and vSAN, and he gained his first VMware certification while working at the university.
Technical route
The certifications come as many customers reassess their VMware environments following Broadcom’s acquisition of the software business. That has increased scrutiny on partners able to demonstrate deep product knowledge and delivery experience.
Both men completed the same rigorous process to secure the designation, which Phoenix described as evidence of its ability to support organisations running complex virtualised infrastructure.
Worth said: “The difference with the Knight programme is that it recognises not just what you know, but what you’ve actually delivered. It reflects real-world experience – designing, implementing, and solving problems for customers. For me, VCF brings together everything we do across networking, storage, and virtualisation into one cohesive platform.”
Dent linked the certification to customer expectations around complex infrastructure projects.
Dent said: “This is one of the highest standards a consultant can achieve. It’s exactly the level of expertise customers expect when they’re investing in complex platforms like VMware Cloud Foundation. For me, it’s also about continuing to learn and building environments where the wider team can develop their skills.”
Phoenix operates across software licensing, hardware, software asset management and managed IT services, and has been in the market for more than 30 years. It works with public and private sector customers on IT strategy, infrastructure design, deployment and software management.
The latest certifications suggest the company is seeking to deepen specialist skills in core infrastructure areas as customers continue to assess how they manage virtualisation, storage and networking in consolidated cloud environments.
Business & Technology
Connected building systems pose growing cyber risk
Restore Information Management has warned that connected building systems are becoming a cyber security risk for organisations, with many businesses failing to secure operational technology such as building management systems, access control and CCTV.
The warning comes as attackers expand their focus beyond traditional IT to target the technology that supports day-to-day building operations. These systems are increasingly internet-connected, remotely managed and linked to cloud services, widening the number of potential entry points for attackers.
Official figures underline the scale of the issue. The latest UK Government Cyber Security Breaches Survey found that 43% of UK businesses experienced a cyber security breach or attack in the past 12 months.
David Robinson, Head of Cybersecurity at Restore Information Management, said many organisations have basic weaknesses across their operational technology environments, particularly default settings and poor access controls.
“Many building systems still rely on default credentials straight out of the box. If these credentials aren’t changed, cyber criminals can gain access to critical systems with relative ease. As today’s digital building systems become increasingly connected, remotely managed and cloud-based, they are evolving faster than many organisations can secure them. Without the right controls, attackers could disrupt critical building systems, disable physical security measures or use them as a route into the wider corporate network,” Robinson said.
Attack surface
Robinson said one of the main steps organisations should take is to establish a full inventory of connected building systems, including building management systems, access control platforms, CCTV networks and environmental controls.
In practice, that means knowing what equipment is connected to the network, who is responsible for managing it and how users, contractors and suppliers can access it. Security teams often have a clearer view of laptops, servers and business applications than of operational technology embedded in buildings, creating a gap that can persist for years.
He also highlighted the risk posed by shared and default credentials. Manufacturer-set passwords remain common across a range of connected systems, and shared accounts can make it difficult to trace activity or remove access when a staff member or contractor leaves.
Restore urged organisations to replace default credentials as soon as systems are deployed, remove shared logins and ensure each employee or contractor has an individual account. That allows access to be monitored and withdrawn when required.
Remote access
Another area of concern is remote access for suppliers and maintenance providers. Building systems often rely on outside specialists for configuration, support and servicing, but these links can remain open long after a project has ended.
Robinson said access should be formally approved, reviewed regularly and removed once work is complete or contracts expire. Dormant contractor accounts, he added, should not remain active.
The issue has become more pressing as facilities technology has become easier to access from outside a site. Remote management can help operators maintain systems across multiple buildings, but it also creates another route that needs oversight from both facilities and cyber security teams.
Network separation
Restore also called for stronger segmentation between operational technology and corporate IT environments. Separating building systems from wider business networks can limit the damage if one part of the estate is compromised.
This matters because attackers who gain access to a connected operational system may try to move laterally into more sensitive parts of the organisation. Segmenting networks can make that movement harder and reduce the impact of a breach.
Security and facilities teams should work together to review legacy environments and identify where older systems can be better isolated. In many organisations, building technology has evolved in stages over a long period, leaving a mix of old and new equipment with varying security controls.
Strategic priority
Robinson’s final point was that operational technology should no longer sit outside mainstream cyber planning. He argued that connected building systems need to be included in an organisation’s wider security strategy, with regular reviews, staff awareness and stronger security design at the point of deployment.
That view reflects a broader shift in cyber risk management as physical infrastructure becomes more digital. Systems once treated mainly as facilities assets are now part of an organisation’s connected estate and can affect both physical security and business continuity if disrupted.
Restore Information Management is one of the UK’s larger information management providers and says it works with more than 6,000 clients, including more than 80% of NHS trusts. “Cyber security is no longer confined to servers and laptops. As buildings become smarter, the systems that control them require the same level of protection as every other critical asset,” Robinson said.
Business & Technology
Prince William-backed helicopter company profits rise
Airbus Helicopters opened a new £50m headquarters and factory facilities at Oxford Airport in Yarnton.
Opened in September 2024 by Prince William, Airbus Helicopters employs around 250 people in Oxford and has room for 32 helicopters.
New accounts published by the company shows the business reported an annual profit of £10.1m in the calendar year 2025 also its first full year from Oxford.
This was up 13 per cent from £8.9m the year before.
READ MORE: Jeremy Clarkson praised for his efforts as he admits ‘no feeling like it’
Airbus Helicopters said this profit was boosted by a £2.5m foreign exchange gain and was despite a drop in turnover.
“The company has now completed its first full year of operations at the new, larger hangar facility at London Oxford Airport, following the move in July 2024 and the commencement of a 25-year lease agreement,” said Yann Rozo of Airbus Helicopters in a report.
“The company would like to recognise the positive contribution of its customers, employees and other stakeholders in achieving the results of 2025 and looks to further enhance these relationships during 2026.”
Revenue for 2025 was at £138.9m compared with £158.6m the year before.
The decrease in turnover compared to the prior year has been attributed to the timing of aircraft deliveries and the expiry of a Ministry of Defence contract.
Airbus completes helicopters built in France and Germany at its Oxford site before selling on to customers including the National Police Air Service.
-
Business & Technology3 weeks agoHSBC UK & Visa test AI shopping with live payments
-
Business & Technology3 weeks agoValarian lands USD $50 million backing for sovereign AI
-
Oxford News4 weeks agoNew romantasy bookshop attracts queues of customers
-
Business & Technology4 weeks agoMouser warns against viral hacks to cool overheating phones
-
Business & Technology4 weeks agoSNP & Palantir launch AI tools for SAP transformations
-
Business & Technology4 weeks agoKane tops England influencer rankings after Mexico win
-
Traffic & Transport4 weeks ago‘I felt my spine and body split’: the woman who was hit by a child on a Lime bike – and denied compensation | Ebikes
-
Oxford News4 weeks agoDWP now checking bank accounts for Universal Credit and Pension Credit
