Month: July 2026

AI – truly intelligent or over hyped?

I have commented before on the AI discussions that appear periodically on social media and do so with some trepidation because there are so many opinions.  And I must put my hands up and say I am not an expert although I do use AI in my everyday work.  I’m not against it but it must be used intelligently and seen for what it is, not what the hype says it is.  This is particularly true of generative AI, which is the type of AI that is most known about and discussed.  Generative AI is a branch of AI that focuses on creating new content, such as text, images, audio etc, by learning patterns from vast datasets and generating output that resembles human-created work.  Of course, to generate this content, you must define clearly what outcome you are looking for.

Over the years, I’ve seen change happening because of innovation within IT, much of which has forecast the end of the workforce.  It has streamlined many processes and taken a lot of drudgery away.  I’ve been involved in mapping out working practices and designing/implementing management processes using IT.  I’ve seen the development of relational databases and search engines, both of which have done much to increase the speed and access to information that is required.  Is AI doing anything different in the workplace?  Or is it just the next somewhat inevitable step up?

I have to say though, that during the years when I was working with management information systems, whilst they did improve speed and efficiency, they never really achieved the manpower savings they were advertised to do.  One claim about AI, that it will achieve those manpower reductions seem a little excessive, in fact one forecast I read by a CEO was that it would have a devastating effect.  It makes me wonder who is going to buy these wonderful goods that are being so efficiently produced if the unemployment rate is through the roof and no one can afford to buy them?  Just a thought.

But getting back to AI itself, is it truly intelligent?  This is where a lot of misunderstanding and indeed, misinformation, can be found.  What forms of AI are there?  And what forms of AI are available now to business and the public.  There are about 7 categories of AI, not types i.e. marketed under a trade name, but categories.

TypeExists today?Purpose
Narrow AI✅ YesPerforms specific tasks
General AI (AGI)❌ NoHuman-level intelligence across many tasks
Superintelligent AI (ASI)❌ NoExceeds human intelligence
Reactive AI✅ YesNo memory, responds to inputs
Limited Memory AI✅ YesUses past information
Theory of Mind AI❌ NoUnderstands emotions and intentions
Self-Aware AI❌ NoConscious, self-aware intelligence

Categories of AI

As we sit here today, virtually all AI systems, including the most well-known such as ChatGPT, are forms of Narrow AI. They can be highly capable within their domains, but they do not possess human-like general intelligence or consciousness.  Narrow AI (and yes, I did use it to create the graphic above), is characterised by:

  • Designed for specific tasks.
  • Cannot think generally outside its training or purpose.
  • Examples:
    • ChatGPT
    • Siri and Alexa
    • Google Translate
    • Image generators
    • Recommendation systems (Netflix, Spotify)
    • Etc

I have said that I use AI, but I struggle to think of it as intelligent, but I do recognise that it is all about how you define that intelligence.  I use it mostly in my managed service, to monitor clients’ systems and keep them as safe as is possible.  Prior to moving into the SME space, I worked for some major clients, both public and private sectors and built several security operations centres.  Back then most of these were centred on SIEM systems, which used correlation engines to correlate the results gathered from several other systems, such as anti-malware, firewalls, intrusion detection systems etc.  The system would then produce results, and those results would be viewed by an analyst before pronouncing them real or a false positive, or whatever.  That was always way too expensive for an SME.  Using AI systems, that cost has now been reduced to a price point that can be attractive to an SME.  So, this is one feature where AI can be of great benefit and is proving itself way more efficient than the correlation engines of old.  Of course, this isn’t the only difference, but it is the one we’re talking about today.

One type of AI that we didn’t qualify above was what is known as Agentic AI.  This is not a separate category but rather a description of how an AI behaves, rather than how capable it is.  For example, whereas many systems that fit within Narrow AI, do so because they are designed for specific tasks.  Agentic AI can plan and achieve a goal, providing it has the right information and instructions to act upon.  This enables it to undertake research for example, so when it finds what it thinks is an issue, it can research that to produce a more definitive answer to an analyst to review.  It might learn enough so that you will trust it with low level alerts and decisions, on its own.  Whether you think that that is intelligence or not, I will leave to you.

Agentic AI allows us to use a layered model embedded in an application which we can use to support SMEs at a reasonable price point.  That layered model includes:

  • Behavioural AI/ML → detects attacks.
  • Correlation engine → connects events across identities, endpoints, email, and cloud.
  • LLMs → explain incidents and assist administrators.
  • Human MDR analysts → validate and respond to serious threats.

Briefly:

Identity-based threat detection

Rather than looking at devices in isolation, we use a system which correlates activity around people (identities).

It continuously analyses signals from:

  • Microsoft 365 or Google Workspace accounts
  • Endpoints (Windows/macOS)
  • Email
  • Cloud storage
  • Dark web monitoring
  • External attack surface

The AI combines these signals to identify suspicious patterns, such as:

  • Impossible travel logins
  • Unusual login times
  • MFA changes
  • Credential leaks
  • Suspicious file access

Instead of generating dozens of alerts, it attempts to determine whether these events are part of the same attack.

Machine learning for detection

Machine learning is used to:

  • Learn normal user behaviour
  • Detect anomalies
  • Reduce false positives
  • Prioritise high-risk incidents

Generative AI (LLMs)

The system also uses large language models for tasks such as:

  • Summarising complex security incidents
  • Explaining alerts in plain English
  • Helping administrators understand why something was flagged
  • Generating phishing simulation emails for employee training

This is different from the AI used to detect threats, it’s focused on making security information easier to understand and act on.

Automated response

When the AI determines an attack is likely, it can recommend or automate actions such as:

  • Disabling compromised accounts
  • Isolating infected endpoints
  • Blocking phishing emails
  • Forcing password resets
  • Escalating incidents to a human analyst

The platform combines AI-driven automation with human security analysts for higher-confidence incidents.

So back to where I started before I got carried away.  Is AI truly intelligent?  I have my opinion which I hope came through here, but I leave you to make up your own mind.  One thing though is for sure, AI is here to stay, and it will continue to get developed and will get better, or worse, depending upon your point of view.

CYBER SECURITY IS COMMON SENSE, ISN’T IT?

Well, yes and no.  Whilst cybersecurity is often described as “common sense,” that statement is only partly true. Common sense does help avoid some online threats, but modern cybersecurity also requires awareness of evolving risks, organisational safeguards and some technical knowledge. Cybersecurity is best understood as a combination of common sense, education, and technology.  Or as we in cybersecurity, like to say, ‘People, Process and Technology.

On one hand, many cybersecurity practices are based on common-sense principles. People are advised not to share passwords, not to click on suspicious links, and to be cautious when receiving unexpected emails or messages. These actions are like everyday safety habits, such as locking doors or being careful when speaking to strangers. As is shows in the graphic above, you don’t go out in the morning, locking your doors, but leaving your windows open.  In cyber the use of strong passwords, enabling multi-factor authentication, and keeping software up to date are practical measures that reduce the likelihood of cyberattacks.

However, cybersecurity extends far beyond everyday judgment. Cybercriminals use sophisticated techniques such as phishing, ransomware, malware, and social engineering that can deceive even experienced users. Attackers often create convincing fake websites, emails, or phone calls that appear legitimate. As technology evolves, new vulnerabilities emerge that are not obvious to the average person. Without proper training, users may not recognise these threats, regardless of how cautious they are.

In addition, organisations cannot rely solely on employees’ common sense to protect their systems. Small to medium businesses need to implement security policies, use firewalls, anti-malware as a minimum, whilst considering encryption, intrusion detection systems, and regular security audits to defend against attacks. Employees should also be receiving regular cybersecurity awareness training to help them identify threats and respond appropriately. These technical and organisational measures complement individual responsibility.

Another reason cybersecurity is not simply common sense is that many attacks exploit software vulnerabilities rather than human mistakes. Even careful users can become victims if systems are not patched or if security controls are inadequate. This highlights the importance of skilled cybersecurity professionals who continuously monitor networks, manage risks, and respond to incidents.  The issue here is that many SMEs simply don’t have the knowledge to fully understand what is, and what is not, happening on their systems.

I going to show some examples now, not to showcase my managed service so much, but to demonstrate what most people simply don’t think about.  I could have chosen any of a dozen or so, but I’ve alighted on these.  In the example below, we are showing client services that are exposed to the internet.  This is something that an SME simply wouldn’t know about or perhaps understand the significance.

Figure 1 – Issue Types

What this shows is the varied types of issues that can arise and that need constant monitoring to stay on top of. These types of issues tend to fly under the radar of most SMEs, and for that matter many bigger companies, and can be exploited by hackers and scammers, with the aim of stealing your hard earned cash.

This next example shows an account compromise as it occurs. Most organisations will not know this is happening until it’s too late. If you can get an early heads up then you stand a chance of stopping it from occurring. All the common sense in the world won’t help you detect a breach as it’s happening, that takes monitoring or an absolute ton of luck.

Figure 1 – Potential account compromise

What we’ve seen here are just two examples of where common sense will only take you so far.  It’s a horrible expression, but you really don’t know what you don’t know.

In conclusion, cybersecurity involves an element of common sense, particularly in practicing safe online behaviour.  However, common sense alone is insufficient in today’s complex digital environment. Effective cybersecurity depends on a combination of informed users, ongoing education, robust technology, and well-designed security policies. Only by integrating these elements can individuals and organisations effectively protect themselves against increasingly sophisticated cyber threats.

We’d be happy to provide more information via a demonstration of our managed capability, including the offer of a fully functional and totally free 14-day trial.

HOW CAN SMEs MONITOR COMPLIANCE TO CYBER ESSENTIALS EASILY

I put up a post earlier this week about cyber essentials, how effective it is and how it should be viewed.  There have been some interesting posts recently on this subject and the main argument was that it should be viewed as a base line standard, not a total panacea. Adherence to it provides a good platform on which to stand your protections and provides a basic understanding of the issues involved, which many SMEs don’t fully grasp.

Cyber threats don’t just target enterprises anymore and SMEs are increasingly in the crosshairs, often without the resources to defend themselves effectively.  But it remains important to keep in mind that for many UK SMEs, cybersecurity is no longer just about protection, it’s about winning business. It’s important to think in terms of simplicity rather than complexity.  Cyber security doesn’t have to be complicated or expensive.

My post talked about what happens after a company has achieved compliance to CE? The requirement now is to certify that they will maintain that compliance throughout the 12-month period of the certification. That is why H2 has researched a service that can be provided to SMEs at a reasonable cost, that helps simplify that journey by providing an all-in-one cybersecurity platform with continuous monitoring aligned to Cyber Essentials requirements. It helps identify security gaps, strengthen your cyber posture, and keep your business on track for compliance, while protecting your users, devices, email, and cloud environment.

We did think however that perhaps a more detailed view might be worth publishing, and here it is.

NCSC has published v3.3 (Danzell) requirements effective from April 2026, which further tighten areas such as MFA and cloud-service requirements. Organisations that have only just adapted to last years changes (Willow) should already be reviewing the next revision to avoid another compliance scramble when renewal comes around. 

What changed in the Danzell question set?

The five Cyber Essentials control areas remain the same:

  • Firewalls
  • Secure Configuration
  • User Access Control
  • Malware Protection
  • Security Update Management

However, Danzell asks more detailed and specific questions about how these controls are implemented and evidenced. 

Key themes covered by the Danzell questions

Multi-Factor Authentication (MFA)

The questionnaire now requires organisations to identify all cloud services in use and confirm MFA is enabled where available. Missing MFA on supported cloud services can result in an automatic failure. 

Typical questions include:

  • What cloud services are used?
  • Is MFA enabled for all users?
  • Are administrator accounts protected by MFA?
  • What authentication methods are used?

Cloud Service Scope

Danzell explicitly brings cloud services into scope, including:

  • Microsoft 365
  • Google Workspace
  • Salesforce
  • Slack
  • Zoom
  • Cloud storage platforms

Organisations must declare these services and demonstrate appropriate security controls. 

Typical questions include:

  • Which cloud services store or process business data?
  • How are accounts managed?
  • How is access removed when users leave?

User Access Control

The questionnaire places greater emphasis on:

  • Administrative accounts
  • Privileged access management
  • Account lifecycle management

Typically, questions include:

  • Are administrator accounts separate from standard user accounts?
  • How are privileged accounts controlled?
  • How are unused accounts identified and removed?

Industry discussions indicate auditors are applying the separate-admin-account requirement strictly. 

Security Update Management

Danzell asks for clearer evidence regarding:

  • Operating system patching
  • Application patching
  • Firmware updates
  • Patch deployment timescales

Applicants need to be able to identify:

  • How are vulnerabilities identified?
  • Are high-risk vulnerabilities patched within 14 days?
  • How is firmware kept up to date?

The 14-day patching requirement is now a critical assessment point. 

Password and Authentication Controls

Questions now focus on:

  • Minimum password length
  • Password managers
  • Common-password blocking
  • Password less technologies and passkeys when used

Cyber Essentials v3.3 introduced a minimum 12-character password requirement in many scenarios. 

The effects of these changes will differ from company to company of course, many will already have much of this covered and some won’t.  Many will require guidance and assistance in making sure that they are prepared to what is now required, and that guidance will need to focus on how they need to change to meet the requirement.

But arguably the biggest operational issue is that CE now requires Owners/CEOs/Boards to certify that they will maintain the standard through its 12-month lifecycle, and not just at the point of certification.  That means monitoring their estate to maintain compliance, constantly, which in turn means having the means and resource to do it.  Not easy for many SMEs and they will be worried about cost.

The obvious answer though is a managed service.  SMEs often outsource their IT environment and see benefits in terms of cost and operational efficiency.  The same can be said for Cyber Security and monitoring, but the mindset tends to be different.  There is still the thought that their IT outsourcing company has this covered, or that cyber is a bit of black art and it will be expensive.

How does the H2 Service Help?

So, what does this service do that is so special?  Well, it will audit the 5 Cyber Essentials control areas, in some detail but it goes further.  Managing cyber security internally is a challenge.   With one out of two SMEs experiencing attacks, it’s clear that modern security requires continuous attention, as does cyber essentials compliance.  Threats can change daily and software needs continual updates.  Users need protection without friction and policies need to be enforced consistently.  Alerts need to be monitored, recognised and acted upon in real time.

Trying to manage all this internally means adding complexity, workload and risk.  Security should not compete with running a business and that is where a managed services makes a difference; by taking full operational ownership of cybersecurity, not just offering advice or tools.

Example of Multi Factor Authentication Detection

The service manages:

  1. Protecting user accounts and access, identifying who has admin privilege so that it can be revoked where it isn’t needed.
  2. Secure end points and devices, identifies operating system versions, anti-malware configurations, updates and alerts.
  3. Enforces security policies.
  4. Identifies cloud configurations and connections.
  5. Reduces risk from 3rd parties and shadow IT apps, identifying where 2FA is missing.
  6. Monitors threats and suspicious activity.
  7. It can monitor email boxes looking for phishing and ransomware, although that element is not strictly necessary for CE compliance.
Example of a client dashboard
Example of Cloud Share Data Detection

An added bonus is that it comes with phishing simulations to help train staff, and a comprehensive, automated, cyber awareness training package.

The system is powered by Agentic AI, although it has a human element, with the AI taking away the number crunching and hard work, leaving the human to identify what is, and what is not, real.  Using AI in this way enables us to keep the costs low, something very important to SMEs.

Scroll to top