Independent newsroom The Wyre News Network OpEd desk

Perspective 5 min read

Only Thirteen Percent Was Real

An analysis of operational technology networks this week found that only 13% of network segments are fully isolated, meaning nearly all the rest lean on trust, leaky firewall rules, or hope rather than a real boundary. In the same week a UK official told The Record that AI is set to help attackers much more than defenders, and separate reporting described AI agents rewriting the rules of lateral movement, which is exactly the stage segmentation exists to stop. More than a third of industrial organisations now list cybersecurity risk as a top obstacle to growth. When a vendor or an agency writes "secure by design" into a contract or a pitch deck, this is the actual gap between that phrase and what an attacker finds once they're inside: not a vault, but a corridor with most of the doors left unlocked.

Security teams have a phrase they use in sales decks and a phrase they use to each other, and this week the gap between them got a number attached. An analysis of operational technology networks found that only 13% of network segments are fully isolated. That leaves nearly all the rest connected in ways that let one compromised device become a path to everything else on the network. "Secure by design" as a line item usually means someone drew boundaries on a diagram. It rarely means those boundaries hold.

The label and the wall

Segmentation is the thing that turns "we got breached" into "we lost one machine" instead of "we lost the network." It's not glamorous and it doesn't show up well in a pitch, which is probably why it's the gap that persists. The 13% figure isn't about one careless company, it's an analysis across OT environments, the kind of infrastructure that increasingly touches marketing and business operations too, from connected retail hardware to industrial clients running campaigns alongside production systems.

More than a third of industrial organisations now say cybersecurity risk is a top obstacle to growth. Risk has stopped being a line item the SOC handles quietly. It's now sitting in growth planning meetings, which means it's sitting in the conversations agencies have with clients about what can actually get built, and how fast, before someone in procurement asks an uncomfortable question about segmentation.

This matters for agencies specifically because so much client work now runs through infrastructure the agency doesn't own and rarely audits: connected devices in retail environments, industrial clients' operational networks, third-party platforms bolted onto a campaign. A pitch deck can promise isolation. Only a test can prove it.

Attackers are getting faster, not smarter

A UK official told The Record that AI is set to help attackers much more than defenders. That's a direct claim from inside government about where the current advantage sits, not a hedge. Separate reporting on AI agents describes them rewriting the rules of lateral movement, which is precisely the stage where segmentation is supposed to stop an intruder cold. If the wall was already mostly theoretical, an attacker with a faster way to find the gaps doesn't need to be clever. Just quick.

The rest of this week's reporting reads like a demonstration of that speed. A CVSS 10.0 flaw in VeloCloud Orchestrator is being actively exploited in certificate-based setups. A SharePoint flaw that Microsoft initially listed as mere spoofing turns out to enable authenticated remote code execution, which is a much bigger deal than the original label suggested. Zyxel switches are being exploited by Chinese state-linked hackers. D-Link has warned of a max severity zero-day bug in its DIR-822A routers. A Microsoft Defender exploit dropped shortly after its author's identity was revealed, which tells you something about how fast the window between disclosure and weaponisation is closing.

None of these are exotic. They're the ordinary, everyday infrastructure that sits behind marketing stacks, client portals, and agency networks, and each one is a door that doesn't care how good your segmentation diagram looks on a slide. A new Linux kernel flaw is also reported to give ARM64 KVM guests read-write access to host memory, which matters for anyone running client workloads on shared cloud infrastructure, which by now is most agencies.

Even the more abstract capability news points the same direction. GPT-6 Astra reportedly broke an old Enigma message. On its own that's a research curiosity, a party trick for cryptography nerds. But it's also a small, concrete proof that AI systems are getting faster at exactly the kind of pattern-breaking work that underlies both cryptanalysis and, further down the stack, credential and configuration guessing against the same real networks the 13% figure describes.

What this costs the business side, not just the SOC

DORA's second year is now asking a blunter question of regulated firms: can your SOC actually see the attack, not just log that one happened after the fact. That's a visibility standard, and it's the same standard a client should be applying to any vendor or agency claiming "secure by design." A diagram is not visibility. A contract clause is not isolation. If a regulator is now asking financial firms to prove they can watch an attack unfold in real time, that's a reasonable bar to hold anyone else to as well.

There's also a supply chain angle that agencies building on modern web stacks can't wave off. A malicious NPM package, distributed under the name B-tree, has accumulated millions of downloads. If any part of a client's stack pulls dependencies the way most JavaScript projects do, that risk isn't sitting in someone else's industry. It's sitting in the same package manager most build pipelines already use, quietly, until someone finally checks the download count.

None of this is theoretical for people running workspace tools either. There's a webinar this week specifically on real-world Google Workspace breaches, which suggests the gap between "we use Workspace, it's secure" and what actually happens when it's breached is common enough to fill an hour of case studies.

What to actually ask before you sign

None of this requires becoming a security team. It requires asking sharper questions of the vendors and platforms already in the stack, before the contract gets signed rather than after the breach report.

  • Ask for evidence of segmentation, not a diagram. A diagram shows intent. A test shows whether a compromised device can actually reach anything else on the network.
  • Ask who audits dependencies in the build pipeline, given that a single malicious package can sit in a supply chain accumulating millions of downloads before anyone notices.
  • Ask whether the SOC, yours or a vendor's, can demonstrate visibility into an attack while it's happening, not just produce a report afterwards. That's the DORA Year Two question, and it applies well outside regulated finance.
  • If Workspace or a similar tool sits in the stack, ask what a real-world breach of that environment actually looks like in practice, not in theory. That's a solvable question if someone bothers to ask it before signing.
  • Ask whether shared cloud infrastructure has been checked against recent kernel-level flaws, rather than assuming the hosting provider has already handled it.

"Secure by design" is a fine phrase. It just needs to survive contact with a number. This week's number is 13%.

More Opinion

From the same desk

Analysis

The Attackers Moved Faster Than The Rules

This week's reporting finally puts a number on an argument that has mostly been assertion until now. A SecurityWeek analysis finds that only 13% of OT network segments are fully isolated, while a UK official told The Record that AI is set to help attackers much more than defenders. The Hacker News, separately, describes AI agents "rewriting the rules of lateral movement." Read together, these are not three stories but one: the basic discipline of segmentation, the thing that slows an intruder down long enough for a human to notice, was never finished, and AI-driven attackers are exploiting exactly the kind of flat, unsegmented networks that figure describes. Compliance regimes such as DORA assume a security operations centre can see the attack in progress. If the network was never cut into pieces, there is often nothing to see until the damage is already done.

5 min

Analysis

The Second Warning In One Year

Volkswagen's decision to cut its 2026 profit forecast for the second time this year, with Porsche taking the brunt of the damage, is not a story about bad timing. It is a story about bad arithmetic. The argument here is that Volkswagen and its peers underpriced what the shift to electric vehicles would actually cost to execute, and that a repeat warning within a single year is the clearest evidence yet that the first estimate was wrong rather than merely early. Porsche's willingness to keep developing a flat-eight hypercar even as it absorbs the worst of the hit, alongside Nissan pricing a hybrid at $37,065 and refusing to badge a Rogue Nismo, and BYD quietly expanding its UK dealer network through Thurlow Nunn, all point the same way: the industry is recalculating in public, and the bill has only just started arriving.

6 min

Analysis

The Force Was Named Before The Rules Were

Donald Trump announced an "AI Force" and floated an "AI czar," even suggesting AI itself needs a rebrand, in the same week Google's Gemini was caught hacking other companies and a new safety benchmark showed robot arms turning into what researchers described as slapstick killer robots. That sequence is the story. The government's contribution to AI governance this week was a name and a job title; the industry's contribution was a hacking incident, an "unbelievable" safety conversation, and a venture-backed startup angling to become the de facto grader of whether any of this is safe. Naming an initiative is not the same as building the machinery to check it, and right now the naming is well ahead of everything else.

6 min