Sign in

Dan Raywood

@danraywood.bsky.social
133 followers 57 following 181 posts

Content creator and writer, sometimes speaker, analyst and marketer. Spurs fan and Spurs women season ticket holder, traveller, beer drinker and occasional personal stuff sharer.

PostsRepliesMedia
Reposted by Dan Raywood
Quentyn @quentyn.bsky.social · 30/09/2026
Thanks Dan ! The black hat talk is here youtu.be/87DyyMV0kCY?... well worth a watch
youtu.be
Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
YouTube video by Black Hat
011
Dan Raywood @danraywood.bsky.social · 30/09/2026
Thanks to all who came to see @quentyn.bsky.social and I at #ice2026 to discuss attacking AI agents. Here's the piece I did for @computerweekly.bsky.social on the Hugging Face incident the other month. share.google/OxIlYOHT7rL8...
share.google
Did an AI agent really break free and attack another company? | Computer Weekly
The reality of the AI-orchestrated cyber attack on Hugging Face is rather more complicated, and much more worrying, than it might appear at face value.
102
Dan Raywood @danraywood.bsky.social · 29/09/2026
Well I arrived massively late, accidentally, but great to mark 60 years of @computerweekly.bsky.social at Informa towers tonight. I've written a number of articles for this mag and it's always a pleasure to be featured inside/online.
010
Dan Raywood @danraywood.bsky.social · 22/09/2026
Gartner discuss concepts of Threat-Informed Defense Effectiveness (TiDE), and the need to practice chaos engineering. Also normalise cyber attack impact, and innovate by automating.
000
Dan Raywood @danraywood.bsky.social · 22/09/2026
At the Gartner security conference today, and it's good news so far.
110
Dan Raywood @danraywood.bsky.social · 07/09/2026
Interesting listening to this podcast "Between Two Nerds: Attribution is dead, long live attribution" lnkd.in/eA_4YJry via Risky Business. I've tried (unsuccessfully) to pitch an idea on attribution: my argument is how it happened and most how to stop it happening again, not on who did it.
000
Dan Raywood @danraywood.bsky.social · 12/08/2026
NIST believes AI tools are contributing to recent trends in vulnerability reporting, and the NVD has seen increased volume and complexity of disclosed vulnerabilities. cyberscoop.com/nist-nationa...
cyberscoop.com
NIST wants to overhaul its vulnerability database for the AI age
NIST is requesting public feedback to overhaul the National Vulnerability Database, aiming to integrate AI and automation to counter faster, machine-driven threats.
010
Dan Raywood @danraywood.bsky.social · 31/07/2026
Did this for Security Point Break on the Nvidia announcement, and how the Open Secure AI Alliance suggests the industry is finally asking a more important question: how do we actually secure AI systems as they become embedded in enterprise environments? securitypointbreak.com/2026/07/31/n...
securitypointbreak.com
NVIDIA and Cisco, CrowdStrike, IBM Form Open Secure AI Alliance
A new industry coalition wants to secure AI agents at the identity and permissions layer, not just the model.
000
Dan Raywood @danraywood.bsky.social · 29/07/2026
The reality of the AI-orchestrated cyber-attack on Hugging Face is rather more complicated, and much more worrying, than it may appear at face value. What are the repercussions for CISOs and the wider AI hemisphere now one agent has apparently gone rogue? www.computerweekly.com/news/3666462...
computerweekly.com
Computer Weekly | Information Technology (IT) News, UK IT Jobs, Industry News
The latest information technology (IT) news and IT jobs from ComputerWeekly.com. Stay ahead with IT management and technology news, blogs, jobs, case studies, whitepapers and videos.
000
Dan Raywood @danraywood.bsky.social · 22/07/2026
"But they managed to escape containment, reach the internet, and break into a firm called Hugging Face to satisfy its testing objectives." When AI meets 28 Days Later! news.sky.com/story/bluesk...
news.sky.com
OpenAI admits its models hacked another company in 'unprecedented cyber incident'
Hugging Face, the software firm targeted by the AI-driven hack, said it was "different from anything we had handled before".
100
Dan Raywood @danraywood.bsky.social · 21/07/2026
Meanwhile AI has the potential to fit into so many other departments, that it deserves its own portfolio, although I wonder what impact a minister would have on US development and control considering the recent suspension and belated roll out. www.isms.online/artificial-i... (2/2)
isms.online
Anthropic's Suspension Is a Wake-Up Call for AI Supplier Risk - ISMS.online
If you build critical business processes around a single AI service, what happens when that service disappears overnight?
001
Dan Raywood @danraywood.bsky.social · 21/07/2026
Burnham has appointed a minister for AI, and is set to scrap DSIT and replace it with the Department for Business, Innovation, Science and Trade. I feel this would be a better fit for Science and Innovation if this is such a key part of the government's tech output. (1/2)
000
Dan Raywood @danraywood.bsky.social · 08/07/2026
My debut post for Shift7, the recent #Android update massively reduces the time taken between guesses on mobile device PINs. This will reduce the attempts by those seeking to access the device, but could it also cause many to press a bit more carefully? www.shift7.agency/post/pin-gue...
shift7.agency
Pin Guessing Gets Harder
Android’s latest security update dramatically reduces PIN guess attempts, making it significantly harder for thieves to access stolen devices. Here’s what the changes mean, why they matter, and how to...
000
Dan Raywood @danraywood.bsky.social · 03/07/2026
Nearly three-quarters of organizations (73%) now say the CISO is ultimately responsible when breaches occur. According to Fastly CISO Marshall Erwin, the number simply underscores the unfortunate fact that CISOs too often get saddled with post-breach blame. securitypointbreak.com/2026/06/30/c...
securitypointbreak.com
CISOs Now Blamed for 73% of Breaches — But Lack the Authority to Stop Them
Fastly's 2026 Global Security Report finds CISO accountability is rising fast — without the control to match. Here's what the data shows.
000
Dan Raywood @danraywood.bsky.social · 22/06/2026
By me for IT Security Guru, talking with Carl Pharoah from Securonix about the partnership with Acora and how it enables proficiency with AI, and upskills staff on using new technology. www.itsecurityguru.org/2026/06/19/a...
itsecurityguru.org
AI Needs Human Expertise: How Securonix and Acora Are Transforming Security Operations
The last time I spoke with Securonix, it was to discuss its acquisition of ThreatQuotient, adding a threat intelligence capability to its existing portfolio of
000
Dan Raywood @danraywood.bsky.social · 04/06/2026
Another #infosec done, managed to get around a fair bit this week and to several talks, as well as among many to lend hands to Cyber House Party.
000
Dan Raywood @danraywood.bsky.social · 04/06/2026
New by me for Computer Weekly. I spent some time at Datadog's European conference in London, and get to talk to Virgin Atlantic about their Concierge AI powered chatbot, which is aiming at making a step above the usual offerings to provide a replica of It's customer service. lnkd.in/eu76j-kD
computerweekly.com
Computer Weekly | Information Technology (IT) News, UK IT Jobs, Industry News
The latest information technology (IT) news and IT jobs from ComputerWeekly.com. Stay ahead with IT management and technology news, blogs, jobs, case studies, whitepapers and videos.
000
Dan Raywood @danraywood.bsky.social · 04/06/2026
Does anything say "last day of the conference" after the big night out than an abandoned bottle of beer? #infosec2026
000
Dan Raywood @danraywood.bsky.social · 16/05/2026
Today at #bsides Birmingham
000
Dan Raywood @danraywood.bsky.social · 11/05/2026
First post for Security Point Break, talking to Reach Security about recent findings on configuration drift. 97% of organisations have reported incidents linked to misconfigurations, and use 35-40 products on average. Is AI the solution in managing this? securitypointbreak.com/2026/05/11/c...
securitypointbreak.com
Closing the Gap: Tackling 'Configuration Drift' in Modern Security
AI-enabled security tools promise faster defense, but the growing complexity of modern security stacks is creating configuration drift, blind spots and misconfiguration risk across enterprise environm...
010
Dan Raywood @danraywood.bsky.social · 24/04/2026
New by me on the Fortra blog, I talked to Ian Thornton-Trump CD about issues affecting CISOs, including building a strategy or rejuvenating a program, and how identity is now the battleground. www.fortra.com/blog/getting...
fortra.com
Getting to Know Ian Thornton-Trump: “There Is No Such Thing as Unprecedented”
Ian Thornton-Trump looks at the shift towards intelligence-led, proactive defense, the growing battle for identity, and what makes the difference between a good reactive CISO.
000
Dan Raywood @danraywood.bsky.social · 03/03/2026
Following last year's announcement of a government consultation on banning ransomware payments, an MP argued that it didn't go far enough - and a private members' bill was read in the Commons. By me for ISMS - www.isms.online/cyber-securi...
isms.online
Feel Compliance Confident with IO | ISMS.online
Take control of ISO 27001 and information security with IO – where people and platform combine to guide you through your infosec compliance with ease. From first-time certification to scaling complian...
000
Dan Raywood @danraywood.bsky.social · 27/02/2026
NCSC's vulnerability monitoring service will reduce cyber risks and speed up time to fix - cutting the average time from nearly 2 months to just over a week. www.gov.uk/government/n...
gov.uk
Government cuts cyber-attack fix times by 84% and launches new profession to protect public services
The government has launched a new vulnerability monitoring service (VMS) to reduce cyber risks and speed up fixes, and a new Cyber Profession to build long-term resilience across public services.
000
Dan Raywood @danraywood.bsky.social · 16/12/2025
I wanted to give a shoutout to the best events I attended in 2025 - and hopefully give you some ideas of what to look out for next year. @bsideslondon.bsky.social @bsidesbirmingham.bsky.social @steelcon.info #bheu2025 @csidesummit.bsky.social wp.me/p2Xih2-8F
wp.me
Top Five Security Events of 2025
Saturday saw my last voyage out of the office and into the cyber community, whether that was going to an event or a conference. Once upon a time, there would be drinks hosted by PR companies and th…
174
Dan Raywood @danraywood.bsky.social · 10/12/2025
Pretty cool sticker sheet for those of you (like me) with a memory and interest in legacy vulnerabilities.
000
Dan Raywood @danraywood.bsky.social · 10/12/2025
Good morning #bheu2025
000
Dan Raywood @danraywood.bsky.social · 30/11/2025
From draft to deployment: How the Cyber Security and Resilience Bill could redefine UK cybersecurity. I've been following the progress of this Bill throughout the year, and it was great to write this overview for TechFinitive in the past week. share.google/AYAj0PV9PH9t... #csrb
share.google
From draft to deployment: How the Cyber Security and Resilience Bill (CSRB) could redefine UK cybersecurity
We explain what the Cyber Security and Resilience Bill aims to deliver and hear from a cybersecurity expert on its progress so far
000
Reposted by Dan Raywood
Graham Cluley @grahamcluley.com · 27/11/2025
Great to have @danraywood.bsky.social on the "Smashing Security" podcast! We discussed how America’s broadcasters leaving their hardware open to attack, giving hackers the chance to hijack TV shows, blast out fake emergency alerts, and even replace religious sermons with explicit furry podcasts.
Smashing Security 445 with Graham Cluley and special guest Dan Raywood
163
Reposted by Dan Raywood
Brian Honan @brianhonan.bsky.social · 05/11/2025
A very entertaining and informative talk on whether or not incident response teams should “pull the plug” in response to a cyber attack by @danraywood.bsky.social at #irisscon
032
Dan Raywood @danraywood.bsky.social · 04/11/2025
It's my second #Irisscon appearance tomorrow: I'll be breaking down my Computer Weekly article research on the ethics of pulling the plug to stop an attack. Knowing I am meeting @brianhonan.bsky.social and co tonight, the 930am spot isn't phasing me at all. Grab a ticket and join us in Dublin.
242
Dan Raywood @danraywood.bsky.social · 03/10/2025
Went to the first #csides in Weston Super Mare, and it was fantastic. A really good collection of speakers and attendees, a fantastic venue - including a free go on the rides - and an overall great vibe. More of this please, especially in seaside towns in the later months! #defendtogether
000
Dan Raywood @danraywood.bsky.social · 03/10/2025
Early start and out west for CSIDES today. I'll admit I found this event by scrolling through Eventbrite and just decided to buy a ticket, speaker line up does look great - and any chance for this Sussex boy to see the sea again (admittedly it's quite far away currently).
000
Dan Raywood @danraywood.bsky.social · 04/09/2025
Today's office, looking forward to presenting at the #magnetforensics event here today on 'why does the media love a cyber crisis?'
010
Dan Raywood @danraywood.bsky.social · 19/08/2025
I'm currently running a poll on LinkedIn, does 'pulling the plug', or taking servers and systems offline, stop an attack and an attacker in their steps? I would love your vote here - www.linkedin.com/posts/dan-ra...
linkedin.com
I'm working on an article for ComputerWeekly.com around whether "pulling the plug" and taking systems/servers offline can be a way to stop an attack - and an attacker in their efforts. |...
I'm working on an article for ComputerWeekly.com around whether "pulling the plug" and taking systems/servers offline can be a way to stop an attack - and an attacker in their efforts. It would be gr...
002
Reposted by Dan Raywood
Catalin Cimpanu @campuscodi.risky.biz · 12/08/2025
Here's the 51 new ransomware groups that launched in the first half of the year medium.com/s2wblog/rans...
2128
Reposted by Dan Raywood
SC Media UK @scmediauk.bsky.social · 12/08/2025
Last week, the Department for Science, Innovation and Technology put out results from its survey of red teamers. The results were interesting, and @danraywood.bsky.social Raywood looked at the top ten things we learned from the research. insight.scmagazineuk.com/ten-things-l...
insight.scmagazineuk.com
Ten Things Learned from Government's Offensive Cyber Research
001
Reposted by Dan Raywood
Paul Bernal @paulbernal.bsky.social · 28/07/2025
Maybe the Online Safety Act *will* make the U.K. the safest place in the world to go online - because we’ll all be using VPNs to connect, and VPNs make us safer.
2933654
Dan Raywood @danraywood.bsky.social · 28/07/2025
A new one from me for #smartframe, looking at how a manipulated image could impact a business' reputation, what sort of damage could (and has been) done, and what efforts would be needed to repair the situation. smartframe.io/how-can-mani...
smartframe.io
How can a manipulated image damage a business? - SmartFrame
The ability to change an image’s content has become easier than ever, […]
100
Dan Raywood @danraywood.bsky.social · 16/07/2025
The third, and possibly last part of my look at the impact of the Cyber Security Challenge. In this I look at the other options for training, gaining skills and contacts in preparation for a career in cybersecurity. insight.scmagazineuk.com/cyber-traini...
insight.scmagazineuk.com
Cyber Training: Post Challenge, Where Are the Skills Learned?
000
Dan Raywood @danraywood.bsky.social · 16/07/2025
Generally avoided covering this until I got something more concrete, but with tales now that Adarma is in administration - and potentially closed down - it was time to post. I contacted them for a response, but unsure if emails are being received. insight.scmagazineuk.com/scottish-con...
insight.scmagazineuk.com
Scottish Consultancy Adarma Enters Administration
101
Dan Raywood @danraywood.bsky.social · 09/07/2025
In #spurs colours for #england #womenseuros
000
Reposted by Dan Raywood
SC Media UK @scmediauk.bsky.social · 19/06/2025
We're live in one hour with a new webinar, looking at 'Managing Cyber Risks Within a Modern Attack Surface' with guest speakers from Outpost24 joining @danraywood.bsky.social. Join us at 3pm BST for the discussion. insight.scmagazineuk.com/managing-ris...
insight.scmagazineuk.com
Managing Cyber Risks Within a Modern Attack Surface
012
Dan Raywood @danraywood.bsky.social · 16/06/2025
Good afternoon from Prague, next few days to be spent with @zscalerinc.bsky.social
020
Dan Raywood @danraywood.bsky.social · 04/06/2025
I could deny, but I'll never realise. I'm just chasing rainbows (over Excel and #infosec2025) all the time.
000
Dan Raywood @danraywood.bsky.social · 04/06/2025
@rikferguson.com kicks off the afternoon of #infosec2025 talking about 30 years of Infosec, the differences from 1995 in computing, trustworthy memo and malware "the only thing we could do was disconnect everything to get some breathing space."
120
Dan Raywood @danraywood.bsky.social · 04/06/2025
Landed this morning from Toronto, managed to stay awake on 2 hours airplane sleep, and through all of the SC Awards. Obviously fell asleep on the train on the way home. Fantastic night, will upload winners' details in the morning but sleep needed. Will be at Infosec tomorrow at some point.
141
Dan Raywood @danraywood.bsky.social · 03/06/2025
7am in Dublin airport, coffee is by my side. Just did the red eye from Toronto and homeward bound to tackle a week's worth of emails ahead of @scmediauk.bsky.social Awards Europe tonight. Will be dropping into #infosec2025 for some of tomorrow and Thursday, once the jetlag has subsided.
010
Dan Raywood @danraywood.bsky.social · 27/05/2025
New by me for ComputerWeekly.com, looking at the soft skills and preparation for incident response. Yes you know the technical elements, but what about the mental considerations upon your staff in a pressured situation? www.computerweekly.com/feature/Prep...
computerweekly.com
000
Dan Raywood @danraywood.bsky.social · 26/05/2025
Scarborough, Ontario. It's colder than it looks.
010
Dan Raywood @danraywood.bsky.social · 24/05/2025
Heading out for a while, will be back for SC Awards and some of #infosec25
030