Welcome to Purpleboar

An eclectic collection of posts and articles from my personal and professional life. Whether you landed here for the professional content or because you found a post about something more niche, you are equally welcome. Pull up a chair.

Featured Posts

About

By day, I work in information security and data protection, which mostly means persuading people that yes, this does matter, and no, you can’t just use “password123”.

If you’ve arrived here via something security-related or a post about 3D printing, this might seem like an unexpected detour. Bear with me.

I will likely cover this in a post eventually, but a quick whistle stop of how I came to be here. Like many in my field, my route to Information Security and Data Protection was roundabout to say the least. Academically, I studied History, medieval history in particular. I went on to complete a post graduate qualification, worked for a while in several fields landing in IT. Then went back to Uni and completed my teacher training to be an Lecturer, before another left turn took me back to IT. After some time in IT support and training made successive moves to Information Management > Information Security > Data Protection to where I am now, wearing all three hats!

Recent Posts

Every project starts somewhere. This one starts with good intentions last Christmas when I bought the, then new, Kill Team Hivestorm box with the best of intentions. The idea was to get two Warhammer 40K forces, terrain and rules all in one go, with the added bonus of the solo play rules included in Hivestorm.

Reflecting this week and speaking with colleagues across the sector I am reminded of some truths that I learned early in my InfoSec/InfoGov journey. Two that have stood out are that having well written policies and robust processes does not mean that people will follow them. And inexorably linked to the first is that training staff, and importantly senior officers and key staff is only half a job if they aren’t able to demonstrate their understanding and put it into practice.

I read an interesting blog post from NCSC this week talking about recent research with frontier AI models in simulated enterprise attacks. The progress is impressive, eighteen months ago, the best available models barely made a dent. But now, the most recent models responding impressively and finding attack approaches the scenario designers hadn’t thought of. And the cost of running a full attempt was roughly £65! A sophisticated, AI-assisted attack delivered with low cost and without specialist expertise.