Connect with us

Business & Technology

Being offensive in your defense

Published

on


These days, it’s not good enough to get the alert. The speed and sophistication of today’s attackers along with the growing number of insider-driven and data-handling risks demand that we find issues even before traditional detections trigger. Modern threats increasingly blend into normal user behaviour, especially when the activity involves sensitive data moving across cloud apps, browsers, and collaboration tools.  

AI-powered attackers and AI-enabled users are forcing defenders to rethink their approach. As we “shift left,” even the acceptable timeframe for discovering potential data exposure is shrinking. By the time a detection triggers, the data may have already been copied or shared outside approved channels. 

This is why proactive threat hunting is evolving into an essential discipline. In many organisations, that means focusing on the early indicators of data misuse, not just system compromise. Advancements in AI and automation now make it far more practical for security teams to identify patterns of risky data movement long before they escalate into incidents. 

In this article, I’ll explore the growing need for proactive threat hunting, the risks of relying on reactive alerts in 2026, and how modern capabilities are helping organisations pivot from being the hunted to becoming the hunter when it comes to protecting their most sensitive information. 

Explaining the Industry Shift Towards Proactive Threat Hunting

Rapid, AI-powered attacks are getting increasingly buried within legitimate business workflows. By the time SOCs or security teams receive a rule-based alert, a user may have already synced classified files to an unmanaged cloud drive, copied sensitive content into an AI tool, or moved high-value data in a way that appears benign on the surface.

These types of low-and-slow actions often evade traditional detection because they mimic normal productivity. Insider misuse and subtle forms of data leakage rarely trigger the same type of signatures as malware or command-and-control traffic. Even AI-driven social engineering attacks now create downstream data risks without necessarily involving a malicious link or attachment. 

Catching these scenarios requires looking directly at data interactions, not just at system events. Proactive threat hunting shifts the focus to understanding how, where, and why sensitive data is being accessed or moved and whether that behaviour aligns with what is expected.

For that, you need a certain set of skills.

Threat Hunting: Skills Required

The role of threat hunter has always been a hybrid one, combining technical expertise with strong analytical instincts. In a data-centric context, that combination becomes even more important.

Threat hunters must know how to gather and interpret telemetry related to data handling, such as file access, classification tags, transfer paths, browser activity, cloud sync behaviour, and anomalies in user behaviour patterns. They need to understand not only the technology but also the organisation’s workflows, so they can distinguish legitimate use from subtle misuse.  

The best hunters pick up on patterns: unusual volumes of data movement, access outside normal working hours, files moving to new destinations, or slowly escalating behaviours that wouldn’t trigger a single alert on their own. There’s still a human element of gut instinct and puzzle-solving, but now it’s applied to data behaviour rather than purely system-level indicators.  

How Much Automation and Agentic AI in Threat Hunting?

A lot, and more every day. Fortunately, automation and AI are stepping in to close the skills gap and augment human analysts, especially within data protection workflows. 

AI-powered threat hunting doesn’t replace expertise; it amplifies it. Think of it as a mech suit for data security teams. Many of the foundational tasks like collecting telemetry, enriching events, and correlating user actions across applications are already automated. Agentic AI systems can now evaluate data movement patterns, identify anomalies, and highlight situations that warrant closer human review.

Advancements in analytics, machine learning and threat intelligence are accelerating this trend, further improving the execution of autonomous threat hunting and helping teams surface early indicators of risky data behaviour with greater speed and accuracy.

What we’ll see going forward is an even tighter pairing between AI and human judgement. AI handles scale and pattern recognition; humans bring context, business understanding, and the ability to make nuanced decisions about risk.

Weighing the Benefits of Threat Hunting for Your Team

For many companies, proactive threat hunting may seem like a luxury reserved for the largest and most mature security programs. But the benefits, especially in a data-centric world, increasingly outweigh the costs.

There are certainly up-front investments: gaining visibility into data movement, deploying AI-enhanced tools, and ensuring the right people can interpret the signals. There are operational costs as well, such as maintaining policies, managing alerts, and training analysts to understand data behaviour.  

But the benefits are substantial. Attackers, insiders, and even well-meaning employees are increasingly operating below the threshold of traditional detections. Proactive threat hunting helps uncover these subtle patterns early, before sensitive information is exposed or exfiltrated. Many organisations are adopting specialised email and cloud-security controls for exactly this reason: reactive tools simply cannot keep up with the sophistication and subtlety of modern data risks.

By identifying issues closer to their origin point, security teams can minimise the potential impact or even avoid harm altogether. 

Conclusion

Attackers and users are interacting with data in ways that continue to evade traditional detection tools. In some ways, this is a testament to how effective we’ve become at catching the obvious threats. But it also means our strategies must evolve to stay ahead of the quieter, more nuanced risks that centre on data. 

Proactive threat hunting supports this shift. Whether focused on system compromise or on the behaviours that place data at risk, the principle remains the same: the best defence is a good offence. Understanding how sensitive information is accessed and moved allows security teams to act earlier, faster, and with far greater clarity.

And in today’s environment, that difference is often what determines whether an incident becomes a headline or just another day of good defence.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business & Technology

Rosa’s Thai is giving away 4000 free Pad Thais to students

Published

on



Celebrating both GCSE and A-Level Results Days, the chain will offer the popular dish to students who buy one of its bubble teas.

The free offer is available at all 42 Rosa’s Thai restaurants across England and Wales.

To avail of the free noodles, students need to register on Rosa’s Thai website for a unique code, which they should present at the restaurant together with a copy of their results.

Rosa’s Thai has a new range of bubble tea flavours, including Ube-Taro, Matcha-Coconut, Mango Sticky Rice, and Milo Chocolate Milk, as well as favourites like Home-brewed Thai Tea with Tapioca, and Lychee Mango with mango boba.

Students can sign up for their free Pad Thai at rosasthai.com/result-day-free-pad-thai and find their nearest restaurant at rosasthai.com/locations.





Source link

Continue Reading

Business & Technology

Historic coin company enters administration after 20 years

Published

on



The London Mint Office, which distributes commemorative coins and medals, appointed administrators on July 31 after 20 years in business.

The company’s website now displays a message confirming the appointment of Michael Magnay and Jonny Marston of Alvarez & Marsal Europe LLP as joint administrators.

A spokesman for Alvarez and Marsal said: “On July 31 2026, Michael Magnay and Jonny Marston of Alvarez & Marsal Europe LLP were appointed as Joint Administrators of The London Mint Office Limited in administration (the “Company”).

“Regrettably, the Company’s liquidity challenges have led to a number of immediate redundancies. We are supporting the affected employees through the redundancy process.


What Happens When a Company Goes Into Administration?


“The affairs, business and property of the Company are being managed by the Joint Administrators who act as agents of the Company and without personal liability.”

The announcement confirms that it is no longer possible to purchase coins or medals through the company’s website.

The London Mint Office operates a distribution centre in Tonypandy, Rhondda Cynon Taf, where it employs a significant number of people.

Administration is a formal insolvency process triggered when a business cannot meet its financial obligations.

An insolvency practitioner is appointed to manage the company’s affairs and may attempt to restructure the business or sell off assets to repay creditors.


What happens when a company goes into Liquidation?


Founded in 2006, The London Mint Office describes itself as “one of the UK’s most trusted suppliers of historic, commemorative, and collector coins.”

It is part of Samlerhuset AS, a Norwegian company based near Oslo and one of Europe’s largest distributors of commemorative coins and medals.

Samlerhuset’s website states that it offers “provide a wide range of coins from ancient to modern, originating from virtually every country in the world.”

The London Mint Office has advised anyone with an interest in the company’s assets to contact the administrators at INS_THLMOL@alvarezandmarsal.com.





Source link

Continue Reading

Business & Technology

Warning of new rules for Aldi and Lidl after watchdog review

Published

on



The Competition and Markets Authority (CMA) has provisionally decided that both discounters should be added to the Groceries Market Investigation (Controlled Land) Order 2010, which currently applies to Asda, Co-op, Marks and Spencer, Morrisons, Sainsbury’s, Tesco, and Waitrose.

This order is designed to prevent large grocery retailers from using land agreements to block competitors from opening nearby stores, often through restrictive covenants or exclusivity terms.

Juliette Enser, executive director of competition enforcement and markets at the CMA, said: “We want everyone to have the best choice of supermarket and range of prices when buying their groceries.

“To ensure this happens, we put rules in place to prevent big supermarket chains blocking rival stores from opening nearby – and now we propose applying those rules to Aldi and Lidl too.

“This is about allowing shoppers to choose where they spend their money and levelling the playing field for all major supermarkets.

“Today’s proposals are provisional and we welcome views before deciding the best way forward.”

The CMA’s review found that Aldi, Lidl GB, and Lidl NI now meet the criteria of ‘Large Grocery Retailers’ (LGRs) due to their store footprint, nationwide presence, procurement model, and the breadth of their grocery range.

Aldi and Lidl were originally excluded from the 2010 order as ‘limited assortment discounters’, offering a smaller selection of products compared to traditional supermarkets.

However, the CMA’s provisional findings indicate that this is no longer the case.

All three now operate large grocery stores, each with more than 1,000 square metres of shop floor space, and offer a full range of products, though with less category choice than some competitors.

They also purchase goods directly from suppliers through integrated wholesaling.

With the UK grocery market estimated to be worth £215 billion, Aldi and Lidl are now ranked among the top five retailers by market share.

The CMA is seeking feedback from stakeholders before reaching a final decision.

Aldi and Lidl could join the other supermarket chains later this year.

The CMA is inviting views until 5pm on Monday, September 7, 2026, and will issue its final decision in the autumn after reviewing responses.

If the discounters are included under the order, they will be prevented from using land agreements to limit competition from other supermarket chains.

The CMA aims to ensure competition across the grocery sector to give shoppers more choice and competitive pricing by removing obstacles to new store openings.





Source link

Continue Reading

Trending