Visualização de leitura

AI Won’t Replace Cybersecurity Jobs, It’ll Replace the Toil – Harsha Reddy Explains What’s Next

AI, Cybersecurity, Harsha Reddy

As enterprises race to bolt AI onto every business process, security leaders are being forced to answer a harder question than "should we adopt it" — it's "who's accountable when it goes wrong." To unpack this, The Cyber Express sat down with Harsha Reddy, Head of Information Security at Veterinary Emergency Group (VEG).

With nearly two decades in security leadership — including senior roles at Lixil and American Standard before joining VEG — Harsha brings a practitioner's view of where AI is genuinely changing the CISO's job, and where it's mostly just hype and shadow adoption.

Watch the Full Interview:

Harsha Reddy Explains Why AI Will Replace Tasks, Not Defenders

Harsha pushes back on the narrative that AI will hollow out security teams, pointing to Gartner research showing that while most fields are projected to lose jobs to AI, cybersecurity is expected to gain them. In his view, the technology is mainly absorbing the "toil" — log review, alert triage, evidence gathering — that keeps analysts from actually defending.

Also listen to S1 Episode: Awareness and Education at Young Age is the Answer to Cybersecurity Skill Gap

“It's the analyst who refuses to use AI that will get replaced by an analyst who uses it,” he says.

On adoption, Reddy points to a 2024 Microsoft-LinkedIn survey in which most executives called AI critical to their business, yet a majority had no formal plan and most had employees already bringing in their own tools. That gap, he argues, is why so many organizations are now dealing with AI-related data leaks. "Many organizations started onboarding AI like software when they should be onboarding it like staff." His fix isn't more restrictions — blocking AI just pushes it into the shadows — but guardrails, an internal AI enablement committee, and measuring actual business value instead of token consumption.

The conversation also digs into deepfake-driven fraud, why training employees to spot deepfakes is “a losing bet” at machine speed, and how he decides when to greenlight a new AI tool versus telling a business unit “not yet.”

The conversation closes with our newly introduced rapid-fire round "Express Shots" — Claude vs. ChatGPT, passkeys vs. passwords, and Reddy's prediction for the biggest cybersecurity threat of 2030.

💾

Read the latest updates Firewall Daily news and insights on The Cyber Expres, your trusted source for cybersecurity and information technology updates."

India Tightens Social Media Rules to Protect Children Online

India online safety rules

India online safety rules are being strengthened as the government steps up measures to protect children and other users from harmful digital content, cyber risks and emerging threats linked to artificial intelligence. The government said its policies are aimed at ensuring an open, safe, trusted and accountable internet, with recent measures focusing on child safety, privacy protection, faster content removal and stronger platform responsibilities.

The Information Technology Act, 2000, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, form the core legal framework governing online safety and intermediary responsibilities in India. The government has also highlighted the Digital Personal Data Protection Act, 2023, and recent amendments to the IT Rules as part of its broader approach to digital safety.

India Online Safety Rules Tighten Platform Responsibilities

Under the IT Rules, intermediaries are required to observe due diligence and inform users that they must not host, display, upload, modify, publish, transmit, update or share content that is harmful to children or violates applicable laws.

Recent amendments require social media platforms and other intermediaries to remove unlawful content within three hours of receiving an order from a competent court or a reasoned intimation from the appropriate government or its agency.

The government has also outlined specific obligations related to content involving nudity, impersonation and other sensitive material. In cases involving certain complaints about content featuring full or partial nudity, exposed private areas or artificially morphed images, intermediaries must take reasonable and practicable measures to remove or disable access within two hours.

Government Targets Harmful Content and OTT Platforms

The government said it has taken action against online platforms and OTT services over unlawful and obscene content. In the last two years, 50 OTT platforms have been disabled for public access in India for displaying obscene content and violating provisions including Sections 67 and 67A of the IT Act, Section 294 of the Bharatiya Nyaya Sanhita and the Indecent Representation of Women (Prohibition) Act, 1986.

The government also said it has taken note of reports alleging the dissemination of advertisements linked to child sexual abuse material (CSAM) on social media platforms and sought a detailed report from the concerned intermediary. The National Commission for Protection of Child Rights has also issued notices to the concerned platforms.

India Strengthens AI-Generated Content Safeguards

The government has also expanded its regulatory focus to address risks associated with AI-generated content and synthetically generated information. Amendments to the IT Rules introduce requirements for clear labelling and traceable metadata for permissible AI-generated content, allowing users to identify synthetically generated material.

The framework also strengthens platform accountability and requires greater user awareness about the legal consequences of unlawful AI-generated content. The rules specifically cover harmful material including CSAM, non-consensual intimate imagery and impersonation.

Platforms are required to deploy reasonable and appropriate technical measures, including automated tools or other mechanisms, to prevent users from creating, modifying, publishing or sharing synthetically generated information that violates applicable laws.

Significant Social Media Intermediaries are also required to make reasonable efforts to deploy technical measures to proactively identify content depicting rape, child sexual abuse or conduct, as well as content identical to information previously removed.

Child Privacy and Digital Addiction Remain Key Concerns

The Digital Personal Data Protection Act, 2023, provides a framework for protecting children's privacy online. It mandates parental consent for processing children's personal data and prohibits practices considered detrimental to children's well-being, including tracking, behavioural monitoring and targeted advertising directed at children.

The government has also highlighted digital addiction as a serious challenge affecting children and young people. The Economic Survey 2025-26 noted potential impacts on cognitive development, academic performance, workplace productivity, social connectedness and mental health, alongside risks linked to cyberbullying, compulsive gaming, social media and online gambling.

Cyber Awareness Reaches 11.37 Lakh Participants

Alongside regulatory measures, the government is expanding cyber awareness initiatives through the Information Security Education and Awareness project. So far, 6,650 awareness workshops have been conducted nationwide, reaching more than 11.37 lakh participants, including students, teachers, law enforcement officials, government personnel and members of the public.

The government has also highlighted digital safety initiatives in education. The PRAGYATA Guidelines provide a framework for safe online learning and responsible use of social media and electronic devices. CBSE has introduced digital etiquette and cybersecurity training initiatives, while NCERT has incorporated cyber safety into its curriculum.

The measures were outlined by Union Minister for Electronics and Information Technology Ashwini Vaishnaw in the Lok Sabha on July 22, 2026, as the government continues to strengthen its approach to c child protection and accountability across India's digital ecosystem.

What Ukraine’s Entry Into the EU Cybersecurity Reserve Means

Ukraine Joins EU Cybersecurity Reserve

Ukraine Joins EU Cybersecurity Reserve after receiving approval from the Council of the European Union, enabling the country to access emergency cybersecurity assistance during large-scale cyber incidents that exceed national response capabilities. The decision allows Ukraine to activate support from the EU Cybersecurity Reserve, a mechanism managed by the European Union Agency for Cybersecurity (ENISA) that provides incident response services through trusted private-sector cybersecurity providers. The move reflects ongoing EU-Ukraine cooperation on digital security and resilience amid evolving cyber threats.

Ukraine Joins EU Cybersecurity Reserve Under EU Cyber Solidarity Framework

The EU Cybersecurity Reserve was established under the Cyber Solidarity Act to help participating countries respond to significant cybersecurity incidents. Through the reserve, nations can request specialized assistance when their own incident response resources are overwhelmed. According to the European Commission, Ukraine will now be able to officially seek emergency European support if a cyberattack surpasses the capacity of its domestic response teams. This would allow cybersecurity experts from across the European Union to assist in incident containment and recovery efforts. The Commission described the decision as part of broader efforts to strengthen preparedness, improve rapid response capabilities, and encourage cooperation against growing cyber threats.

EU Highlights Digital Security Cooperation

Commenting on the development, Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, said Ukraine's inclusion strengthens collective cyber defenses and reflects the principle of solidarity at the core of Europe's digital future. The Commission noted that cyberattacks continue to present a persistent challenge and emphasized the importance of coordinated responses and shared expertise among partner nations. Ukraine's inclusion also aligns with the EU's strategic digital partnership agenda, which focuses on strengthening cybersecurity cooperation with neighboring countries.

Moldova Previously Granted Access

Ukraine becomes the second non-EU country to gain access to the reserve. Moldova was granted access in 2024 following an increase in Moscow-linked Cyber Threats and influence operations targeting the country. The Council's authorization for Moldova to use the reserve was described as a major step forward in regional cybersecurity cooperation. The arrangement was implemented under the Cyber Solidarity Act and formed part of broader EU-Moldova efforts to improve digital resilience. The European Commission stated that enhancing cybersecurity cooperation remains a key component of its partnership with Moldova.

Broader EU-Moldova Digital Cooperation Expands

Alongside cybersecurity initiatives, the European Union has expanded digital cooperation with Moldova in several strategic areas. The Commission welcomed a political agreement that will allow Moldova to join the EU Roaming Area under the "Roam Like at Home" framework following formal adoption. Once implemented, Moldovan citizens and EU travelers will be able to call, text, and use mobile data without additional roaming charges. Moldova has also joined the EU Third Countries' Trusted List, enabling easier validation of electronic signatures and seals between EU and Moldovan organizations, businesses, and citizens. To strengthen resilience against Disinformation and foreign interference, a new hub of the European Digital Media Observatory (EDMO) known as FACT has also been established with support from the European Commission.

Cyber Cooperation Advances as EU Membership Talks Progress

The cybersecurity announcement comes shortly after EU member states agreed to launch formal accession negotiations with both Ukraine and Moldova. European Commission President Ursula von der Leyen described the decision as a major milestone, stating that all member states had agreed to open the first accession negotiations cluster with the two countries. She said the move recognizes the reforms undertaken by Ukraine and Moldova despite significant challenges and reinforces the EU's commitment to peace, security, and stability across the region. With access to the EU Cybersecurity Reserve, Ukraine now gains an additional layer of support to strengthen its cyber resilience and coordinate responses to major cybersecurity incidents alongside European partners.

UK Social Media Ban for Under-16s Could Take Effect by Spring 2027

UK social media ban

The UK government has announced plans to introduce a UK social media ban for under-16s, preventing children from accessing major platforms such as TikTok, Instagram, Snapchat, Facebook, YouTube and X under a sweeping package of online safety reforms. The measures, expected to be brought before Parliament later this year and enforced from Spring 2027, would make Britain one of the toughest countries in the world when it comes to regulating children's access to social media. The proposal is part of a wider government effort to strengthen online child safety and address growing concerns about the impact of social media algorithms, harmful content and excessive screen time on young users. Prime Minister Keir Starmer described the move as a "line in the sand," arguing that technology companies have failed to do enough to protect children online. "Parents want to keep their kids safe and happy, but the online world has made that harder than ever," Starmer said. "That's why we're going further than any country in the world by banning social media for under-16s and putting wider protections in place to give kids their childhood back." UK Social Media Ban for Under-16s

UK Social Media Ban for Under-16s to Cover Major Platforms

The proposed UK social media ban for under-16s will apply to user-to-user platforms that allow users to interact and share content through algorithm-driven feeds. Platforms expected to fall under the restrictions include TikTok, Instagram, Snapchat, Facebook, YouTube and X. Messaging services such as WhatsApp and Signal are not expected to be included. Alongside the ban, the government plans to introduce new restrictions on features considered particularly risky for young users. These include livestreaming functions and communication between children and strangers across a wider range of digital services, including some gaming platforms. The government is also considering additional safeguards, including overnight access limits and measures designed to interrupt infinite scrolling for users under 18.

AI Chatbots Also Under Scrutiny

The reforms extend beyond social media platforms. Under the proposed rules, AI-powered "romantic companion" chatbots that simulate intimate or sexual relationships will be required to enforce a minimum age of 18. Similar intimate AI functions will also face restrictions for users under the age of 18. Officials say the broader approach reflects how children increasingly encounter online risks across multiple digital services rather than solely through social media platforms.

Global Momentum Builds Behind Social Media Age Restrictions

Britain's announcement comes amid growing international support for tighter social media age restrictions. Earlier this year, Spain announced plans to prohibit social media access for children under 16. Prime Minister Pedro Sanchez described the internet as a "digital Wild West" and said stronger protections were needed to shield young people from online harm. France has also moved in a similar direction. In February, French lawmakers approved legislation banning children under 15 from accessing social media platforms. The measure is expected to take effect at the start of the next school year. French President Emmanuel Macron strongly backed the proposal, stating that children's development should not be dictated by algorithms designed to maximize engagement. The developments have fueled debate over whether age-based restrictions could become a standard approach to child online protection across Europe and beyond.

Australia's Experience Highlights Enforcement Challenges

While support for restrictions is growing, Australia's experience shows that enforcement remains a major challenge. The Australia social media ban, introduced under Prime Minister Anthony Albanese, requires platforms to block users under 16 or face fines of up to AU$32 million. However, recent research suggests many children continue to access restricted platforms despite the rules. A study conducted by the Molly Rose Foundation and YouthInsight found that more than 60% of children aged 12 to 15 who previously used social media still had access to at least one account. The survey of 1,050 young people showed that 53% of former TikTok users, 53% of YouTube users and 52% of Instagram users remained active after the restrictions were introduced. Researchers also found evidence that some children created new accounts after the ban came into effect, raising questions about the effectiveness of current age verification systems.

Age Assurance Measures Key to Enforcement

To improve compliance, the UK government plans to introduce stronger age assurance measures and has tasked Ofcom with conducting a rapid review of age-verification technologies. The regulator will also review its enforcement capabilities, while ministers have pledged additional funding to support implementation of both the proposed regulations and existing provisions under the Online Safety Act. The announcement follows a national consultation that attracted more than 116,000 responses from parents, children and experts. According to government figures, nine in ten parents support a ban on social media access for children under 16. If approved, the reforms will mark one of the most significant changes to Britain's digital safety framework and could further accelerate a global shift toward stricter regulation of children's online experiences.

AI Heads to UK Courts, Bringing New Cybersecurity and Governance Challenges

AI legal assistants

The UK government is moving ahead with plans to test AI legal assistants in the Crown Court as part of a broader effort to reduce case delays and improve court operations. The initiative, announced at London Tech Week, will see artificial intelligence used to support legal research, case analysis, trial scheduling, and administrative tasks across parts of the justice system.

The move comes as courts continue to face significant backlogs, prompting officials to explore how technology can help legal professionals spend less time on routine work and more time handling active cases.

AI Legal Assistants to Support Crown Court Work

Under the new initiative, AI legal assistants will be developed with input from legal experts and AI developers to help lawyers and court staff manage routine legal tasks.

According to the government, the tools are expected to assist with legal research, reviewing case materials, and analysing information that would otherwise require significant manual effort. The aim is to improve efficiency across the Crown Court and help cases progress through the system more quickly.

Before any deployment in live court environments, the AI legal assistants will be tested in controlled settings to assess performance, reliability, and compliance with legal standards.

AI Tool Planned for Trial Scheduling

The government also revealed plans for judges to use an AI-powered case management tool designed to identify trial-ready cases and group similar hearings together.

Officials believe the technology can help courts make better use of available judicial resources by improving scheduling and reducing delays caused by administrative bottlenecks.

By helping courts prioritize and organize cases more effectively, the system could contribute to faster case resolution and improved courtroom utilization.

Justice Transcribe Expands Across Probation Services

Alongside the Crown Court initiatives, the government confirmed that all probation officers in England and Wales have now been equipped with Justice Transcribe, an AI-powered transcription tool.

The platform automatically records and transcribes conversations with offenders, eliminating the need for probation officers to manually transfer handwritten notes into digital systems.

Government estimates suggest the technology could save the equivalent of 18,750 calendar days of administrative work annually, allowing probation staff to dedicate more time to offender supervision and case management.

Similar AI Technology Being Tested in Tribunals

A similar transcription tool is currently being trialled within Immigration and Asylum Tribunals.

The pilot allows judges to generate digital case notes through automated transcription, reducing paperwork and administrative workloads. If successful, the technology could be expanded to other courts and tribunals across the justice system.

AI Growth Labs to Support Legal Technology Development

The announcement follows the launch of the government's new AI Growth Labs, testing environments designed to help organizations develop and evaluate AI systems before deployment.

The facilities are expected to support the UK's legal technology sector by providing controlled environments where AI applications can be assessed for safety, performance, and operational effectiveness.

With AI legal assistants, AI-powered scheduling tools, and automated transcription platforms now being tested across multiple parts of the justice system, the UK government is increasingly exploring how artificial intelligence can support court operations and reduce administrative workloads without replacing legal decision-making.

AI-Powered Bots Are Blurring the Line Between Users and Cyber Threats

AI-Powered Bots

For years, security teams have relied on behavioral clues to identify malicious activity. However, the rise of AI-powered bots is making that task far more challenging. Unlike traditional automated tools, these bots can imitate legitimate user behavior with remarkable accuracy, allowing them to blend into normal traffic patterns. A new study examining enterprise security readiness suggests that artificial intelligence is fundamentally changing how bot attacks are carried out. Rather than behaving like traditional automated tools, modern AI-powered bots are now capable of mimicking legitimate users with a level of sophistication that many organizations struggle to detect. The report, based on a survey of 300 enterprise leaders across North America, highlights a growing concern among cybersecurity professionals: attackers are no longer trying to force their way into systems. Instead, they are increasingly blending into normal digital activity.

AI-Powered Bot Threats Are Becoming More Advanced

According to the findings, AI-driven bot threats are reshaping the threat landscape by enabling attackers to automate reconnaissance, optimize targeting, and operate within normal user behavior patterns. Credential-based attacks remain the most common form of bot-related activity, with 74% of respondents identifying them as a major concern. DDoS attacks followed at 51%, while 40% reported dealing with AI-driven scraping campaigns designed to harvest sensitive information from websites and online platforms. What makes these attacks particularly challenging is not just their scale, but their ability to imitate legitimate traffic. Modern bots can browse websites, submit forms, test stolen credentials, and interact with applications in ways that closely resemble human behavior. Security experts warn that this evolution is making traditional bot detection methods less effective.

Many Organizations Still Rely on Slow Defensive Processes

While attackers are increasingly operating at machine speed, many organizations continue to update their defenses at a much slower pace. The survey found that only 25% of enterprises continuously update bot detection rules. In contrast, nearly half of respondents update protections on a weekly basis, creating potential windows of opportunity for attackers. This gap between attack speed and response speed is becoming a growing concern as AI lowers the barriers to launching automated campaigns. Researchers noted that the cost of executing large-scale bot attacks has dropped significantly, allowing threat actors to conduct more reconnaissance, launch more credential attacks, and scale operations faster than ever before.

The Challenge of Distinguishing Good Bots From Bad Bots

One of the most notable findings from the study is the difficulty organizations face when trying to classify bot activity. Nearly one-quarter of respondents said they cannot reliably distinguish malicious bots from legitimate automated traffic. That challenge is becoming increasingly relevant as businesses themselves rely on automation. Organizations commonly use bots for search engine optimization, website monitoring, analytics, and performance testing. As a result, security teams are often managing environments where beneficial and malicious automation can appear remarkably similar. Industry experts warn that threat actors are taking advantage of this overlap. By designing attacks that resemble trusted automated activity, they can reduce the likelihood of detection and remain active for longer periods.

Confidence Does Not Always Reflect Readiness

Despite growing concerns around AI-driven bot threats, many organizations remain confident in their ability to detect malicious activity. The survey found that 79% of enterprise leaders believe they can identify bot traffic. However, only 23% reported having mature, governance-driven programs designed to manage automated threats proactively. Meanwhile, 44% continue to rely primarily on reactive approaches, while many depend on default protections provided by web application firewalls and content delivery networks. This disconnect suggests that confidence may be outpacing actual preparedness. The report also found that only one-third of respondents said their existing tools successfully blocked more than half of AI-generated bot traffic over the past year.

Business Impact Extends Beyond Security Teams

The consequences of AI-driven bot threats are no longer limited to cybersecurity departments. More than half of surveyed organizations expect AI-powered bots to negatively affect customer experience during the next 12 months. Others anticipate increased exposure of sensitive data and growing operational challenges. Bots can create subtle but costly disruptions. Slower website performance, disrupted transactions, account takeover attempts, and unauthorized data collection can all affect customer trust and business performance. For large organizations handling millions of monthly website visits, even small disruptions can translate into significant financial and operational consequences.

A Shift Toward Bot Governance

As AI continues to reshape cyber threats, security leaders are increasingly being encouraged to move beyond traditional bot detection strategies. The report argues that organizations should begin treating bots as identity-bearing actors rather than simply another source of internet traffic. This approach places greater emphasis on understanding intent, verifying identities, and continuously assessing behavior rather than relying solely on signature-based detection methods. The broader message from the research is clear: as automated threats become more intelligent, organizations will need to focus not only on identifying malicious activity but also on understanding and governing it. The challenge is no longer just stopping bots. It is determining which automated actors can be trusted and which are actively working against the organization.

UK’s Online Age Checks Are Failing—Kids are Beating Them with AI, Fake Beards

U.S. Government Sues TikTok, TikTok

When governments introduced stricter online age checks under the UK’s Online Safety Act, the goal was to keep children away from harmful content. But in practice, the system is already showing cracks—and the most telling insight comes from the very users it’s meant to protect.

Children aren’t just countering age checks, they’re actively bypassing them—and often with surprising ease.

According to a new report from Internet Matters foundation, nearly half of children (46%) believe age verification systems are easy to get around, while only 17% think they are difficult. That perception isn’t theoretical. It’s grounded in real behavior, shared knowledge, and increasingly creative workarounds.

From simply entering a fake birthdate to using someone else’s ID, children have developed a toolkit to bypass techniques. Some methods are almost trivial—changing a date of birth or borrowing a parent’s login—while others reflect a growing sophistication. Kids reported submitting altered images, using AI-generated faces, or even drawing facial hair on themselves to trick facial recognition systems.

In one striking example, a parent described catching their child using makeup to appear older—successfully fooling the system.

I did catch my son using an eyebrow pencil to draw a moustache on his face, and it verified him as 15 years old. – Mum of boy, 12

But the problem goes deeper than perception. It’s systemic.

Also read: UK Regulator Ofcom Launches Probe into Telegram, Teen Chat Platforms

Bypassing Is the Norm, Not the Exception

The report reveals that nearly one in three children (32%) admitted to bypassing age restrictions in just the past two months. Older children are even more likely to do so, which shows how digital literacy often translates into evasion capability.

The most common methods?

  • Entering a fake birthdate (13%)
  • Using someone else’s login credentials (9%)
  • Accessing platforms via another person’s device (8%)

Despite widespread concerns about VPNs, they play a relatively minor role. Only 7% of children reported using them to bypass restrictions, suggesting that simpler, low-effort tactics remain the preferred route.

In other words, the barrier to entry is not just low—it’s practically optional.

Europe Threat Landscape Q1 2026, Online Age Check Europe’s cyber threat landscape Q1 2026 shows a sharp acceleration in cyber threats across the region. Do you know what's contributing to it?

Check Cyble's full analysis report here!

Even When It Works, It Doesn’t Work

Ironically, even when children attempt to follow the rules, the technology doesn’t always cooperate.

Some reported being incorrectly identified as older—or younger—by facial recognition systems. In cases where they were flagged as underage, enforcement was often inconsistent or temporary. One child described being blocked from going live on a platform for just 10 minutes before being allowed to try again.

This inconsistency creates a loophole where persistence pays. If at first you’re denied, simply try again.

A Risky Side Effect

Perhaps the most concerning finding isn’t that children can bypass age checks—it’s that adults can too.

The report states fears that adults may exploit these same weaknesses to access spaces intended for younger users. In some cases, this involves using images or videos of children to trick verification systems. There are even reports of adults acquiring child-registered accounts to blend into youth platforms.

This flips the entire premise of age verification on its head. Instead of protecting children, flawed systems may inadvertently expose them to greater risk.

Parents, Part of the Problem—or the Solution?

Adding another layer of complexity, parents themselves are sometimes complicit.

About 26% of parents admitted to allowing their children to bypass age checks, with 17% actively helping them do so. The reasoning is often pragmatic. Parents feel they understand the risks and trust their child’s judgment.

I have helped my son get around them. It was to play a game, and I knew the game, and I was happy and confident that I was fine with him playing it. – Mum of non-binary child, 13

But this undermines the consistency of enforcement. If rules vary from household to household, platform-level protections lose their impact.

Interestingly, the data also suggests that communication matters. Children who regularly discuss their online activity with parents are less likely to bypass restrictions than those who don’t.

Why Kids Are Bypassing in the First Place

The motivations aren’t always malicious. In many cases, children are simply trying to access social media (34%), gaming communities (30%), or messaging apps (29%) that their peers are already using.

What this resonate is a fundamental tension where age verification systems are trying to enforce boundaries in environments where social participation is the norm.

Age verification is often positioned as a cornerstone of online safety. But in practice, it’s proving to be more of a speed bump than a safeguard.

Children understand the systems. They share methods. They adapt quickly. And until the technology—and its enforcement—becomes significantly more robust, age checks may offer more reassurance than real protection.

UAE Cyber Security Council Warns 1 in 4 Public Files Contain Sensitive Personal Data

UAE Cyber Security Council

The UAE Cyber Security Council has raised concerns over widespread data exposure, revealing that nearly 25 percent of publicly accessible files contain sensitive personal data. The warning comes as part of its ongoing awareness efforts, urging individuals and organisations to strengthen basic cybersecurity practices. In its latest advisory under the “Cyber Pulse” campaign, the Council highlighted that poor file-sharing habits continue to expose users to avoidable cyber risks. The findings point to a growing gap between the use of cloud platforms and the understanding of how to secure shared data.

Public Files and Sensitive Personal Data at Risk

The Council’s findings show that a significant portion of files shared openly online contain sensitive personal data such as identification details, financial records, or login information. This raises concerns about how easily such data can be accessed by unintended users. The issue is not limited to publicly shared files. According to the Council, between 68 percent and 77 percent of privately shared files may also be accessible to unintended recipients due to weak access controls or misconfigured sharing settings. This highlights a broader problem where users assume that private sharing automatically ensures security. In many cases, improper permissions or link-based access can lead to unintentional exposure of sensitive personal data.

Cyber Security Council Highlights Encryption as Critical Safeguard

The UAE Cyber Security Council emphasized that encryption remains one of the most effective ways to protect sensitive personal data. Files that are encrypted before being shared or stored online are significantly less vulnerable to unauthorized access. The advisory noted that cloud storage platforms do not guarantee automatic protection of data. Without encryption, sensitive files remain exposed if access controls are bypassed or misconfigured. Alongside encryption, secure account management plays a key role in reducing risk. Weak passwords, reused credentials, and lack of authentication measures continue to be major contributors to data exposure incidents.

Key Cybersecurity Practices Recommended

To address the risks associated with exposed sensitive personal data, the Cyber Security Council outlined several essential cybersecurity practices. Users are advised to use strong and regularly updated passwords and enable two-factor authentication across all accounts. Avoiding public links when sharing sensitive files is also critical, as these links can be easily forwarded or accessed without proper restrictions. The Council stressed the importance of reviewing privacy settings and managing access permissions carefully. Monitoring file usage and access logs can help identify unusual activity and prevent misuse. Additional measures include deleting unused files and inactive sharing links, securing Wi-Fi networks, and keeping devices and software up to date. Users are also encouraged to review application permissions and limit access to only necessary services. When accessing files over public networks, the use of virtual private networks can provide an added layer of security. Regular data backups and secure database management on cloud platforms are also recommended to prevent data loss and unauthorized access.

Awareness Remains Key to Reducing Exposure

The Cyber Security Council noted that many cases involving sensitive personal data exposure are the result of simple, preventable mistakes. Lack of awareness around basic cybersecurity practices continues to be a major factor. The “Cyber Pulse” campaign, now in its second year, aims to address this gap by promoting safer digital behaviour among individuals and organisations. The initiative forms part of broader national efforts to build a secure and resilient digital environment. By encouraging users to adopt stronger security measures and understand the risks of improper file sharing, the Council aims to reduce the exposure of sensitive personal data and improve overall cybersecurity hygiene. The latest findings serve as a reminder that while technology platforms continue to evolve, the responsibility to secure data often lies with users. Simple steps such as enabling encryption, managing access, and reviewing shared content can significantly reduce the risk of data exposure.

FCC Proposes Tougher KYC Rules to Crack Down on Illegal Robocalls

KYC Rules for Robocalls

The Federal Communications Commission (FCC) is proposing stricter Know-Your-Customer (KYC) rules for robocalls as part of a broader effort to curb illegal calls and protect consumers. In a newly released Further Notice of Proposed Rulemaking, the agency outlined plans to tighten requirements for originating voice service providers, which are considered the first line of defense against unlawful robocalls. The proposal reflects growing concern that existing KYC rules for robocalls are not being consistently enforced, allowing bad actors to exploit gaps in the system. The FCC emphasized that stopping illegal calls before they enter the network remains the most effective way to reduce fraud and abuse.

Why the FCC Is Expanding KYC Rules for Robocalls

Under current FCC robocall regulations, voice service providers are required to take “affirmative, effective” steps to know their customers. However, regulators say some providers are failing to carry out adequate checks, resulting in a surge of illegal robocalls that defraud consumers and expose telecom networks to misuse. “Combatting illegal calls is our top consumer protection priority, and we are taking a holistic approach by attacking them at every point in their lifecycle.” The FCC noted that weak KYC rules for robocalls not only enable scams but also make it harder for law enforcement to track criminal activities, including drug trafficking and human exploitation that rely on anonymous communication channels.

Proposed Changes to KYC Rules for Robocalls

The FCC is seeking public comment on several measures aimed at strengthening KYC rules for robocalls and improving telecom KYC compliance. One key proposal is to require providers to collect more detailed customer information before granting access to calling services. This includes name, physical address, government-issued identification number, and an alternate contact number for all new and renewing customers. For high-volume callers, such as businesses or bulk calling services, the FCC is considering additional requirements. These may include collecting information on how the service will be used—such as marketing or political campaigns—as well as technical data like IP addresses used to place calls. The Commission believes these enhanced Know-Your-Customer rules for robocalls could deter fraudsters from entering the network and make it easier to identify them if illegal activity occurs.

Verification, Monitoring, and Data Retention

Beyond data collection, the FCC is also proposing stricter verification and monitoring under its updated KYC rules for robocalls. Providers may be required to verify customer identities using supporting documents such as government-issued IDs or business registration records. The agency is also exploring whether companies should retain KYC records for up to four years after a customer relationship ends, allowing time for investigations into illegal robocalls. Another key focus is ongoing monitoring. The FCC is considering whether providers should re-verify customer information when unusual activity is detected, such as sudden spikes in call volume or changes in traffic patterns. These measures aim to ensure that telecom networks are not continuously exploited by bad actors using false or stolen identities.

Tougher Penalties to Enforce Compliance

To strengthen enforcement, the FCC has proposed financial penalties tied directly to violations of KYC rules for robocalls. The agency is considering a base fine of $2,500 per illegal call, aligning penalties with the scale of harm caused. This per-call penalty structure is designed to discourage large-scale robocall operations, where millions of fraudulent calls can generate significant profits. The FCC believes that stronger enforcement will push providers to take telecom KYC compliance more seriously and close existing loopholes.

Recent Enforcement Highlights Gaps

The push for stronger KYC rules for robocalls comes amid ongoing enforcement challenges. In a recent case, the FCC proposed a $4.5 million fine against Voxbeam Telecommunications for allegedly routing illegal robocalls into U.S. networks. The investigation found that Voxbeam accepted traffic from Axfone, a Czech-based provider not listed in the FCC’s Robocall Mitigation Database. Under existing rules, such traffic should have been blocked, raising concerns about gaps in compliance and oversight. If adopted, the new rules could significantly reshape how voice service providers onboard and monitor customers, bringing telecom practices closer to the stricter identity verification standards already seen in the financial sector.

U.S. Treasury Rolls Out Cybersecurity Information Sharing Initiative as Crypto Attacks Rise

digital asset cybersecurity initiative

The U.S. Department of the Treasury has unveiled a new digital asset cybersecurity initiative, aimed at strengthening defenses across the rapidly growing digital asset ecosystem. The initiative, announced by the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP), seeks to provide timely and actionable cyber threat intelligence to eligible U.S.-based digital asset firms. The move comes amid escalating cyberattacks targeting cryptocurrency platforms and follows recommendations outlined in the federal report “Strengthening American Leadership in Digital Financial Technology.”

Understanding About Digital Asset Cybersecurity Initiative 

At its core, the digital asset cybersecurity initiative will extend high-quality threat intelligence, previously reserved for traditional financial institutions—to digital asset companies and industry organizations. This includes insights that help firms detect, prevent, and respond to cyber threats affecting their platforms, customers, and infrastructure. “Digital asset firms are an increasingly important part of the U.S. financial sector, and their resilience is critical to the health of the broader system,” said Luke Pettit, Assistant Secretary for Financial Institutions. “By extending access to the same high-quality cybersecurity information used by traditional financial institutions, Treasury is helping promote a more secure and responsible digital asset ecosystem,” he added further. Eligible firms that meet Treasury criteria will receive this information at no cost, signaling a broader push to align cybersecurity standards across financial sectors.

Rising Threats Drive Urgency for Digital Asset Cybersecurity

The digital asset cybersecurity initiative comes at a time when cyber threats against cryptocurrency platforms are intensifying in both scale and complexity. Treasury officials emphasized that the initiative directly responds to this evolving threat landscape. “Cyber threats targeting digital asset platforms are growing in frequency and sophistication,” said Cory Wilson, Deputy Assistant Secretary for Cybersecurity. “This initiative expands access to actionable threat information that helps firms strengthen defenses, reduce risk, and respond more effectively to incidents.” Recent incidents emphasize the urgency. Alleged North Korean hackers reportedly stole $280 million from crypto platform Drift using a complex attack. Industry-wide losses exceeded $3.4 billion last year, with billions more lost annually over the past five years. In another case, Bitcoin ATM operator Bitcoin Depot disclosed a cyberattack on March 23 that resulted in losses exceeding $3.6 million. Additional breaches this year have reported losses of $26 million and $40 million, highlighting persistent vulnerabilities across the sector.

Government Push Amid Ongoing Crypto Crime

Despite increased enforcement efforts, cybercriminals and nation-state actors continue to exploit weaknesses in the digital asset ecosystem. U.S. authorities, including the Justice Department, have ramped up prosecutions and issued repeated warnings about infiltration attempts, particularly by North Korean threat groups. However, these measures have had limited success in curbing attacks. Threat actors continue to exploit coding flaws, social engineering tactics, and employee vulnerabilities to gain access to crypto platforms. The digital asset cybersecurity initiative is designed to complement these efforts by shifting focus toward proactive defense and real-time intelligence sharing rather than reactive enforcement alone.

Strengthening the Future of Digital Finance

Treasury officials also framed the digital asset cybersecurity initiative as a foundational step for the future of digital finance. As digital assets become more integrated into mainstream financial systems, cybersecurity is emerging as a critical pillar for sustainable growth. “This initiative reflects the principles of the GENIUS Act by promoting responsible innovation grounded in strong cybersecurity and operational resilience,” said Tyler Williams, Counselor to the Secretary for Digital Assets. “As digital assets become more integrated into the financial system, access to timely and actionable cyber threat information is essential to protecting consumers and safeguarding the stability of U.S. financial markets,” Williams added. The broader federal strategy emphasizes balancing innovation with security. The Treasury’s report highlights the need for regulatory clarity, risk mitigation, and public-private collaboration to support the long-term growth of digital assets while addressing illicit finance and cyber risks.

A Step Toward Industry-Wide Cyber Resilience

With cyberattacks continuing to disrupt the crypto ecosystem, the digital asset cybersecurity initiative represents a significant step toward improving industry-wide resilience. By bridging the gap between traditional financial cybersecurity frameworks and emerging digital asset platforms, the initiative aims to create a more secure and stable environment for innovation. As digital assets evolve from niche technology to a core component of global finance, initiatives like this may play a key role in shaping how the industry manages risk, and whether it can keep pace with increasing cyber threats.
❌