Sign in to view Rob’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Greater Oxford Area
Sign in to view Rob’s full profile
Rob can introduce you to 10+ people at e2e-assure
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
8K followers
500+ connections
Sign in to view Rob’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Rob
Rob can introduce you to 10+ people at e2e-assure
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Rob
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Rob’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Articles by Rob
-
What the UK power plant cyber attack tells us
What the UK power plant cyber attack tells us
By Rob Demain 23-Aug-2026 What happened? A small power-generating site in the UK was taken offline during a cyber…
119
27 Comments -
The Year Cyber AI Stopped Being Only About the ModelJul 5, 2026
The Year Cyber AI Stopped Being Only About the Model
For much of the last year, cyber AI was discussed like a model leaderboard. Which model writes the best detection rule?…
7
-
What goes wrong with AI agents in the SOC (and how we handle it)Jun 12, 2026
What goes wrong with AI agents in the SOC (and how we handle it)
If you’re putting agentic AI into your SOC, or your MDR provider says they have, this is the list of questions to ask…
15
-
What Sub-Minute Response Actually RequiresJun 9, 2026
What Sub-Minute Response Actually Requires
We started looking hard at this back in October, and what we found has shaped how we have had to rethink detection…
16
2 Comments -
When the Disclosure Model Meets the Discovery MachineMay 28, 2026
When the Disclosure Model Meets the Discovery Machine
Microsoft published a blog post this week rebuking a researcher for dropping a chain of uncoordinated Windows zero-days…
2
1 Comment -
AI in the SOC doesn't need to be dramatic. It needs to be dependable.May 27, 2026
AI in the SOC doesn't need to be dramatic. It needs to be dependable.
After 30 years in this industry, I've watched a lot of "revolutionary" technology arrive, get oversold, and quietly…
10
-
The SOC Cannot Be Retrofitted with AI. It Has to Be Redesigned - and so does the SIEM.May 22, 2026
The SOC Cannot Be Retrofitted with AI. It Has to Be Redesigned - and so does the SIEM.
Two developments across late 2025 and early 2026 should set the terms of this conversation. The first was Gambit…
21
-
Drawing the Threat Model Against What Is Actually HappeningMay 18, 2026
Drawing the Threat Model Against What Is Actually Happening
The threat model implicit in most security programmes is a useful abstraction that has held up well for a long time…
4
-
The Patch Race Was Already Losing. Mythos Is the Moment That Makes It Hard to Argue Otherwise.May 13, 2026
The Patch Race Was Already Losing. Mythos Is the Moment That Makes It Hard to Argue Otherwise.
The release of Claude Mythos Preview on 7 April 2026, alongside Anthropic’s Project Glasswing coordinated disclosure…
7
-
Mythos, Glasswing, Chrome Exploit Research, and the UK Government Warning: What They Really Mean for Cybersecurity - AI hype or reality?Apr 16, 2026
Mythos, Glasswing, Chrome Exploit Research, and the UK Government Warning: What They Really Mean for Cybersecurity - AI hype or reality?
How 25+ years of cybersecurity knowledge became AI's training data—and why that changes everything This week brought…
34
2 Comments
Activity
8K followers
-
Rob Demain posted thisThe Manchester Airports Group breach is being read mainly as a customer data story. I think the more interesting angle is aggregation — and how hard this kind of attack can be to see. MAG has confirmed affected information includes email addresses, phone numbers, postcodes and vehicle registrations from parking, lounges, Fast Track and Wi-Fi services. Samples shared with reporters reportedly contained more: booking references, airport and terminal details, parking dates and times, historical spend, IP addresses, approximate location, device and customer-engagement data. There are also claims of records relating to future travel, although that has not yet been independently established. Individually, none of those fields looks especially remarkable. Together: person + mobile + postcode + IP + vehicle + airport + date/time is a very different dataset. And nobody necessarily set out to create it. It can grow gradually as parking, Wi-Fi, lounges, Fast Track and personalised services are connected to make travel easier. Every individual integration can make perfect sense. The technical claims around the breach are also interesting. FulcrumSec says airport-specific credentials for a marketing platform were exposed in client-side JavaScript. That remains unconfirmed. But if accurate, the attack may have looked less like: compromise → malware → lateral movement → database and more like: public website → credential → authenticated SaaS API → bulk extraction That creates a difficult problem for a SOC: - There may be no malware, no IOCS, etc. - No obvious command-and-control. - No lateral movement. - Potentially very little useful telemetry inside the organisation at all. No EDR, etc. And if the application legitimately talks to the SaaS platform from customers' browsers, source location may not help much either — those requests can naturally come from almost anywhere so detecting this type of attack is hard. The anomaly may simply be that a credential which normally performs one pattern of activity suddenly starts behaving differently, but it could be more subtle if the app has evolved to access the data...i.e. it hasn't suddenly changed, its legit behaviour may have evolved over time for example. To the SaaS platform it may still look like: Valid credential. Valid endpoint. HTTPS. Successful requests. The challenge is no longer just spotting a compromised server. It is understanding whether an identity, token or API key is behaving like the application it belongs to — often in a platform operated by somebody else. Its a tough challenge. MAG says airport operations, passenger safety and aviation security were unaffected, which is an important distinction. But the breach is a useful example of how two things can grow quietly over time: the value of the combined dataset, and the difficulty of seeing when somebody starts using it in a way they shouldn't. #CyberSecurity #DataBreach #APISecurity #SaaSSecurity
-
Rob Demain shared thisThis is one of the more interesting attacks I’ve seen recently. Attackers hijacked internet routing for part of Softaculous’s infrastructure, diverting traffic intended for Virtualizor’s software-update service to their own server. Normally, correctly validated HTTPS should prevent redirected traffic from becoming convincing impersonation. But according to Virtualizor’s investigation, the attackers obtained a valid Let’s Encrypt certificate while the hijack was active. The certificate authority’s validation checks followed the diverted route, reached the attacker’s server and saw what appeared to be control of the legitimate domains. The attackers could then serve a malicious Virtualizor update over apparently valid HTTPS. Because the update package was not independently cryptographically verified, affected hypervisors accepted it. Virtualizor’s maintenance process apparently runs as root on the hypervisor itself. When it loaded the modified files, the attacker’s code inherited those root privileges—without needing a separate privilege-escalation exploit. The malicious code reportedly added an attacker SSH key, installed a remote-access tool and created persistent access. The full chain: manipulate internet routing, obtain a trusted certificate, impersonate a software-update service and have its legitimate root process execute your code. The individual techniques were already known. Seeing them combined successfully against live virtualisation infrastructure is what makes this incident stand out. https://lnkd.in/eCgevdQ4 #CyberSecurity #BGP #SupplyChainSecurity #InfrastructureSecurity
-
Rob Demain shared thisThe BBC and Telegraph have reported on a cyber attack that took a small UK power-generating site offline last month, with the Telegraph attributing it to Iran-linked hackers. We still do not know how the attackers got in or whether they directly caused the outage. It could have been an exposed system, remote access, stolen credentials, a supplier compromise or something deeper in OT. Part of the downtime may also have been deliberate containment. Either way, a cyber incident resulted in a UK generating asset being unavailable. As our energy system becomes more distributed and interconnected, the real question is whether the same weakness could exist across many sites. There is a lot of good work happening across government, NCSC, DESNZ and Ofgem. The challenge is pace: CNI has to change safely, but the threat does not work to the same timetable. My full article here: #CyberSecurity #CNI #EnergySecurity #OTSecurity #CyberResilience
-
Rob Demain shared thisReally enjoyed this interview and i think we managed to cover some interesting stuff...perfect summer holiday listening :)Rob Demain shared thisOur latest episode is slightly later than planned, due to attendance at the Farnborough International Airshow last week! However, there is a link. Aviation is increasingly seen as part of critical infrastructure, along with rail, road transport, power and water. And other key areas of the economy, including banking and telecoms, are coming under #CNI too. The problem is that malicious actors are ramping up their attacks on CNI, with the UK's NCSC reporting that two-thirds are linked to nation states. Attackers are both willing to cross more "red lines", and are using AI to find and exploit vulnerabilities. So how do we fight back? The answers include improved business continuity planning, and sovereign AI. Our guest is Rob Demain, of e2e-assure. Read more here https://lnkd.in/dMqyYe2a, or you can listen directly here: https://lnkd.in/du63m9zbAI vs CNI: Rob Demain, e2e-assure - Security InsightsAI vs CNI: Rob Demain, e2e-assure - Security Insights
-
Rob Demain shared thisThere are some interesting updates in the National Risk Register 2026, particularly for anyone responsible for critical infrastructure. My main takeaway is that the likelihood scores are not the most important part. The recovery assumptions are: Health: months. Water: months. Policing: potentially 18 months. Data infrastructure: years in the worst cases. Financial market infrastructure: possible permanent data loss or corruption. These are reasonable worst-case planning assumptions, not predictions. But they show how difficult recovery becomes once an attacker is established in operational technology, identity systems or the data layer. At that point, restoring from backup is only part of the job. You also need to understand what happened, remove persistence and establish that the environment can be trusted again. That makes detection, investigation and forensic readiness part of recovery planning, not just security operations. The register also repeatedly warns that AI will make attacks faster, more efficient and easier to launch. So the practical question for CNI operators is straightforward: How much time is there between intrusion and impact, and can you detect the attacker within that window? I have written up my full take here: https://lnkd.in/eMCzeyaZ #CriticalNationalInfrastructure #CyberResilience #OperationalTechnology #IncidentResponse #NationalRiskRegisterWhat the National Risk Register 2026 actually says to CNI operators - e2e-assureWhat the National Risk Register 2026 actually says to CNI operators - e2e-assure
-
Rob Demain shared thisWorth a read as it matches what we are seeing….highly capable, highly available and guardrails optional…and changing the economics of cyber security. https://lnkd.in/ezCZ_t6XCheap Chinese AI to unleash new wave of cyberhacksCheap Chinese AI to unleash new wave of cyberhacks
-
Rob Demain reposted thisRob Demain reposted this"We can't run a human-based SOC against an AI threat." AI isn't just changing cybersecurity, it's changing the economics of it. Rob Demain, CEO & Founder of e2e-assure, explains why attackers can now scale faster and cheaper than ever before, and why the only way to keep up is to fight AI with AI. If cyber criminals are using AI at scale, defenders can't rely on human capacity alone. 🎧 Watch on YouTube: https://lnkd.in/eMAgcHGJ 🎙️ Listen on Spotify and Apple Podcasts: https://lnkd.in/eSpNFQyW Proudly supported by SonicWall, Halo, Arrow Cloud UK & Ireland, AMD, Check Point Software, WeFi Technology Group and N-able.
-
Rob Demain shared thisReally enjoyed this, thanks for having me Marc Sumner and team!Rob Demain shared thisNEW EPISODE💥 Rob Demain, CEO & Founder of e2e-assure, joins me to unpack the shift every business needs to understand: cybersecurity is moving into an AI‑driven era, and the old playbook won’t protect you. We talk cyber resilience, AI‑powered defence, the changing threat landscape, leadership in high‑pressure environments, and why MSPs must evolve fast. If you’re building or running a tech business, this one matters. Dropping tomorrow. Supported by SonicWall, Halo, Arrow Cloud UK & Ireland, AMD, Check Point Software, WeFi Technology Group and N-able.
-
Rob Demain shared this👀 Perimeter devices can make easy targets... "Advice follows the opportunistic exploitation of inadequately configured routers and network devices by Centre 16 of Russia’s Federal Security Service (FSB)" " Whilst the actor primarily uses SNMP scans to locate and compromise vulnerable routers, they have also exploited well-known vulnerabilities relating to Cisco devices, Cisco’s Smart Install (SMI) feature and web-portal flaws to gain control of network devices." https://lnkd.in/eyUkRn7zUK and Allies urge critical sectors to improve defences against Russian intelligence targetingUK and Allies urge critical sectors to improve defences against Russian intelligence targeting
-
Rob Demain liked thisIt's almost like the people running these things do not have experience in doing these kind of things...... what's mad is: there's a whole indsustry of people who run crazy, dangerous stuff... FOR FUN (and PROFIT)! It's called Cyber Security! I know I know it will never catch on /S
-
Rob Demain liked thisRob Demain liked thisIsn't it just the most satisfying feeling in PR when a rapid response rapidly responds!? On Sunday, the ORIGIN COMMS LTD team sprang into action when we got the opportunity for e2e-assure to speak to Times Radio about the Iran-linked attackers taking out a UK power plant. Always the professional, Rob Demain jumped on the phone on Sunday evening, and even got up at 6AM to speak to LBC on Monday morning. Before lunchtime, we'd turned Rob's radio bon mots into a tight comment for media that hadn't yet picked up the story, securing coverage with New Civil Engineer, Intelligent CISO, Industrial Cyber, Cyber News, and more. I got into PR for media lunches (remember those??), but this is the rush I stayed for! https://lnkd.in/extFwGhfIranian hackers shut down ‘small’ UK power station for 4 days | New Civil EngineerIranian hackers shut down ‘small’ UK power station for 4 days | New Civil Engineer
-
Rob Demain liked thisRob Demain liked thisA cyberattack reportedly linked to Iran forced a small UK power generator offline for four days. Cybersecurity experts from Barrier Networks, Illumio, Advania UK, OPSWAT, Orange Cyberdefense and E2E-assure discuss what the incident reveals about the growing threat to critical national infrastructure and the challenges of securing increasingly connected Operational Technology environments. Euan Carswell Ric Derbyshire Rob Demain Trevor Dearing James Neilson Pravesh Kara Grace Watkins Sam Rayment Jamie Dunn More here: https://lnkd.in/exG3RjEr Follow us: https://lnkd.in/e6fbUQVC
Experience & Education
-
e2e-assure Ltd
*** * *******
View Rob’s full experience
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
View Rob’s full profile
-
See who you know in common
-
Get introduced
-
Contact Rob directly
Other similar profiles
-
David Fountaine
David Fountaine
CEO & Founder of Creation Technology, a 60+ person Salesforce Consultancy, headquartered in London & with offices in India, that specialises in Salesforce Education Cloud, Experience Cloud, Marketing Cloud, MuleSoft, Data Cloud & Agentforce. <br><br>We are Industry Cloud experts & focus on delivering solutions to enterprise customers in the Higher Education Vertical. We deal with countless leading Universities, Business Schools & Education Ecosystem Organisations across the United Kingdom, Republic of Ireland, Western Europe, Africa & Middle East regions. <br><br>We have experience right across the full Student Lifecycle from Prospect to Influencer, Applicant, Student, Alumni & beyond. We deliver high quality solutions that deliver tangible results in respect of Recruitment & Admissions, Academic Operations & SIS, Student Success, Enterprise Enquiry Management, Alumni & Advancement, Research & Innovation, Business Services & beyond.<br><br>Salesforce Education Cloud Focus:-<br><br> - Experts in Salesforce Education Cloud for Universities, Business Schools & Education Partners<br> - Solutions for Recruitment & Admissions, Student Recruitment Management, Academic Operations & Student Information Systems (SIS), Student Success, Enterprise Enquiry Management, Alumni & Advancement, Research & Innovation, Business Services etc<br><br>Salesforce Education Cloud, Marketing Cloud, MuleSoft, Data Cloud & Agentforce Services:-<br><br> - Education Cloud Strategy & Roadmap<br> - Rapid Prototype Development<br> - Integration Services using Salesforce & MuleSoft Integration Platform<br> - Custom Application Development using Salesforce Lightning Platform<br> - Payments Enablement & Integration (i.e. Card Payments, Direct Debits, Invoice Integration)<br> - Salesforce Managed Services, Support Services, User Training & Adoption etc<br><br>We work across; Education Cloud, OmniStudio + Industry Common Capabilities, Experience Cloud, Marketing Cloud Engagement, Marketing Cloud Advanced, MuleSoft, Data Cloud, Agentforce.<br><br>About Creation:-<br><br> - 60+ expert Salesforce Consultants at Technical Architect / Tech Lead, Data Architect, Senior Salesforce Developer level. All of our consultants hold the latest Salesforce certifications<br> - Founded in 2006 (in business for over 19 years)<br> - London Head Office + Offshore Development Centre in India<br> - Experts in Industries / Verticals including; Higher Education, Professional Services, Media & Communications, High Tech, Conferences & Events etc<br><br>To contact Creation Technology visit www.creation.technology or call 0044 (0) 208 735 4270.
3K followersGreater London -
Brian Azzopardi
Brian Azzopardi
Rawstream is an innovative cloud-based web filtering and monitoring solution. We are focused on helping small and medium businesses spend their time online more productively, profitably and safely.<br><br>Cool stuff we do:<br>- Cloud-based content filtering - without the slow browsing! We solve the latency / bandwidth problem that plagues the other cloud-based products.<br>- Cloud DNS - fast simple deployment for networks and Guest WiFi<br>- Real-time reporting and API<br>- Accurate, actionable time reporting usable by management / HR<br>- Simple, automated deployment for Windows, Chromebooks and SOHO. No need for AD syncing.<br>- BYOD / guest device support without the associated IT admin workload<br>- solve hard problems around network security and data storage
1K followersMalta -
Brian T.
Brian T.
Very experienced Hardware and software developer (since 1978) first in telecoms hardware and later in systems software development.<br><br>Specialising in Microsoft platforms, particularly Azure, SQL Server and the .Net framework<br><br>Various Microsoft certifications in software development, and "out-of-band" abilities for systems design, making use of my varied background in hardware and software. <br><br>Implementation of Web and Worker roles in Azure. The cloud is a tremendous resource, allowing almost infinite scalability and resilience, but obviously everyone has concerns that "their data" - normally data relating to customers... will be seen by everyone. The trick is to seamlessly and transparently allow authorised access, ideally in granular fashion, not binary "Yes / No", while denying unauthorised access. <br><br>The three tenets of identity: <br>Identification: we all have multiple online personae, do we need to create yet another "identity silo"?<br>Authentication: you claim to be Joe - prove it.<br>Authorisation: Ok Joe, this is what you can see and do.<br><br>Historically every new site / application has implemented its own user management system, often badly, as an industry we need to upgrade these legacy "homebrew" authentication methods into claims-based protocols and schemes like SAML & OAuth. <br><br>Not everyone is, or wants to be, an IT expert - and offering Fibre broadband to the average home user is like handing a child a loaded Glock. <br><br>All IT professionals need to think security, stability and ethics. <br><br>They trust us.<br><br><irony><br>Apparently what I've been doing the past 30+ years is now state of the art - its called DevOps. Who would have thought..<br></irony>
175 followersGreater Guildford Area, United Kingdom
Explore more posts
-
Pete Rucinski BEng CEng CITP CCP
Assure Technical • 3K followers
In preparation for my speaker slot at the inaugural West Midlands Defence Procurement Event tomorrow, I’ve been reflecting on my key observations about navigating the Defence Cyber Certification (DCC) scheme. As early adopters of the framework, operating as an IASME accredited Level 1 Certification Body, Assure Technical has gained certification, in addition to certifying numerous clients. This dual experience has provided us with the critical observations and practical insights needed to support defence supply chain partners in making an effective, seamless transition to DCC, no matter which level your contracts demand. The biggest takeaway from the frontline is simple: you need to start the process early. Giving your business the runway to prepare before an impending tender deadline completely changes the dynamic. Taking a proactive head start allows you to focus on three critical areas: 🕰️ Start Preparing Early: You are required to provide concrete evidence that you actively comply with each control. This involves a significant amount of preparation for Level 1 certification and above. 🔍 Engage a DCC Certification Body Upfront: Don’t wait for the formal evaluation. Bringing in an accredited CB for a preliminary gap analysis gives you an objective view of your data flows, systems and policies - allowing you to effectively define your scope and prioritise changes. ⚙️ Embed routines before the rush: True readiness isn’t achieved by a last-minute scramble to pass an audit. Getting ahead of the timeline gives your team the space to weave baseline checks into standard daily routines, meaning your compliance evidence gathers naturally in the background. I’ll be diving deeper into these field insights tomorrow, joining @RyanProtheroe to explore realistic, grounded approaches to business governance. Entrance to the event is free, so why not pop down to Millenium Point in Birmingham. 👉 Explore our Defence Cyber Certification services: https://hubs.la/Q04l0_R60 #CyberSecurity #DefenceProcurement #SupplyChainResilience #DCC #AssureTechnical #BusinessGovernance #DPC2026
9
-
Tim H.
Information Systems Security… • 12K followers
A few years back, we carried out an IT Health CHECK for a well-known UK council. They had a vulnerability management solution in place, so we took a full sample of the data. What we found was staggering: around 30,000 high-criticality vulnerabilities. We presented the findings. The response was hostile, to put it mildly. We were told their previous ITHC supplier had only assessed 10 percent of the estate, and the council chose the sample themselves. One quote stuck with me: “We can’t possibly patch all that in time for you to issue a clean report.” We explained that the report was a point-in-time assessment and couldn’t be changed. They refused to share it with the PSN team, saying it would be too damaging. Instead, we got pushback: “We won’t be using you next year.” “We’re one of the most secure councils in the UK.” I then issued a heavily caveated report (my team had already downed tools!), clearly stating: “We only assessed the scope provided by the client. Systems outside this scope were not assessed.”. For those in the know, this means "the client chose their own scope", and is sufficient coverage if things outside that scope were then breached at a later date. That version, along with a remediation action plan (RAP), presumably written by the client, was then submitted to the PSN team, and I was told "it passed". We weren’t invited back the following year. I’ve been doing this sort of work for 30 years. I’m thick-skinned. But I do get upset and stressed when my team's professionalism and integrity are questioned. I take it personally. Over time, I’ve developed strong consulting and customer-facing skills to manage these situations, but the industry needs to do better. Integrity should never be negotiable. Does anyone else have experience of being put into awkward situations by clients, whom want to save face rather than admit to systemic security flaws?
4
-
Harj Singh
Aristi Limited • 939 followers
The UK’s National Cyber Security Centre (NCSC) has published pragmatic guidance to help organisations, especially those responsible for Critical National Infrastructure (CNI), plan, prepare and respond effectively to severe cyber threats. It’s a timely reminder that cyber resilience goes beyond technology. It requires strategic planning, operational readiness and organisational alignment. Key takeaways include: - Plan early and proactively: Embed severe threat response into enterprise risk planning and leadership decision-making. - Enhance situational awareness: Build threat intelligence and monitoring capabilities to detect and understand emerging risks quickly. - Harden and rehearse defences: Identify tactical measures to reduce exposure, document response actions, and regularly test them through exercises. - Integrate recovery planning: Connect response plans with wider business continuity and organisational objectives to ensure swift restoration. - Build long-term resilience: Plan not just for immediate threats but for adaptability and recovery across the threat lifecycle. In an increasingly hostile cyber landscape, this guidance reinforces the importance of preparedness, coordination and resilience at every level of the organisation. https://lnkd.in/gNYRiSJj #CyberSecurity #CyberResilience #CriticalNationalInfrastructure #CNI #IncidentResponse #BusinessContinuity #RiskManagement #OperationalResilience #NCSC #Leadership #SecurityStrategy
5
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More