OT security market projected to quadruple as critical infrastructure threats grow

Posted in Commentary with tags on September 16, 2026 by itnerd

The global operational technology (OT) security market is projected to grow from $44.34 billion in 2025 to $178.93 billion by 2035, according to new research from SNS Insider, representing an annual growth rate of nearly 15%.

The growth is being driven by increasing cyberattacks against critical infrastructure and industrial control systems, along with the rapid adoption of industrial IoT, smart manufacturing and increasingly interconnected IT and OT environments.

Power, transportation, manufacturing, energy and utilities are among the sectors increasing investment in technologies designed to protect mission-critical operational systems. North America accounted for approximately 42% of the global OT security market in 2025. 

Security solutions, including threat detection, monitoring, vulnerability management and incident response, represented nearly 72% of the market in 2025. Managed and professional security services are expected to be the fastest-growing segment as organizations seek additional expertise to secure increasingly complex industrial environments.

Denis Calderone, CTO, Suzu Labs:

“The projected growth tracks with what we’ve been living through lately. The last several months have been a steady stream of attacks on operational technology, from Iran-linked activity against water and fuel-monitoring systems to the wave of PLC compromises that had water utilities scrambling this summer. When CISA is telling the entire water sector to pull PLCs off the public internet and the FBI is documenting lost pressure and actual flooding, budgets catching up to the threat isn’t hype, it’s just an inevitable fact.

“We strongly suspect that the speed in growth of these types of attacks are likely in line with the increased use of offensive AI. The August advisory from NSA, CISA, the FBI, DOE, and EPA on Siemens S7 controllers spelled it out pretty clearly. Attackers are using AI-generated scripts, dressed up to look like legitimate monitoring tools, to build working ICS capability with far less expertise and in far less time than this used to take. That compresses the learning curve that used to keep casual actors out of OT, which means more people can credibly threaten these environments. Executive Order 14306 last summer named this directly, calling out China, Iran, and others targeting critical infrastructure and steering federal cyber efforts toward AI-era threats. The forecast is really just the market responding to conditions.”

Damon Small, Board of Directors, Xcape Inc.:

“Rapidly converging IT and operational technology (OT) environments expose legacy industrial control systems to direct cyber risks, threatening revenue, physical safety, and operational continuity. Driven by aggressive digital transformation across power, manufacturing, and utilities, this market expansion highlights a growing operational vulnerability rather than simple tech adoption. Paradoxically, investment in OT security is surging alongside rising cybersecurity unemployment, revealing a structural mismatch: the skilled, experienced professionals required to protect complex physical assets remain scarce. Because legacy control systems frequently lack basic authentication controls, traditional perimeter security fails. To bridge this acute talent gap and secure legacy assets, security leaders must deploy AI-assisted tooling, enforce strict network segmentation between IT and OT domains, and mandate strong access governance for third-party maintenance connections.

Critical Takeaways

  • Convergence of IT and OT exposes legacy control systems to physical safety and operational continuity risks that traditional enterprise tools cannot address.
  • A shortage of specialized OT security talent makes pure headcount expansion unfeasible, driving adoption toward AI-assisted tooling for anomaly detection.
  • Immediate risk reduction requires strict network segmentation between IT and OT domains alongside tight access governance for third-party connections.

“If your OT security strategy relies entirely on hiring unicorns, prepare to explain your next outage to the board using hand puppets.”

Doc McConnell, Head of Policy and Compliance, Finite State:

“Until recently, operational technology was considered a niche specialty within the field of cybersecurity. A market projection like this shows that’s no longer the case.

“There are two drivers for this rapid expansion. First, we’re increasingly seeing adversaries targeting operational technology. In April, CISA, the FBI, and EPA warned that Iran-linked actors were reaching programmable logic controllers at U.S. water and energy utilities, and in July the FBI documented attackers changing addresses, passwords, and ladder logic on internet-exposed PLCs at water systems in at least seven states. These attacks have had real operational consequences, including pressure loss and flooding.

“And second, we’re seeing a trend toward OT protection in US policy. Last month’s executive order on bulk-power supply chain security puts the origin and security of grid equipment under federal scrutiny, and the Water Cyber Shield Act proposed in Congress would direct EPA to set tiered security standards for drinking water and wastewater systems.

“But OT operators can’t wait for policy to catch up, which is why we’re seeing particular growth in the services segment. Buying new security tooling is straightforward. Finding people who understand how a control system actually behaves, and who can build security into equipment without risking downtime or disruption is harder. In these environments, interruption in service is a life-safety issue, so that expertise is worth hiring for.”

The time to spend is now. Because it is a matter of when and not if you will get attacked.

Coast Guard and FBI board two U.S.-bound tankers after suspected cyberattacks

Posted in Commentary with tags on September 16, 2026 by itnerd

The U.S. Coast Guard and FBI are investigating suspected cyberattacks against at least two foreign tankers bound for the United States, according to Bloomberg.

Specialized teams boarded the vessels in the Gulf of Mexico in August after indications that their networks had been compromised by foreign cyber actors, examining both operational technology and information technology systems and working with crews to remove potential threats.

One of the vessels has been identified as the VL Prosperity, a very large crude carrier capable of transporting roughly 2.3 million barrels of oil. The tanker was reportedly attacked while traveling through the Strait of Gibraltar in early August and lost communications for more than 30 hours. U.S. authorities boarded the vessel on August 21. A second tanker targeted in a separate cyberattack was boarded on August 24 for a similar assessment.

The Coast Guard and FBI said there have been no reported operational disruptions, vessel instability, physical danger to crews or environmental impacts.

John Strand, Owner, Black Hills Information Security, Inc.:

“There’s a lot of conversation right now about attacks against operational technology, especially water and power systems, given the current geopolitical climate. But tankers are absolutely on the menu as well. What makes these environments so attractive is that much of this technology doesn’t have the same endpoint security you would expect on a Windows 11 workstation. You often don’t have EDR running on these systems. That creates a rich target for attackers because many of the defensive technologies we’ve come to rely on in traditional IT simply aren’t there.”

Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs:

“It appears two separate claims are circulating, and they’re being treated as one. The first one is from the Coast Guard, which has acknowledged indications that the vessel’s network was compromised, with no reported operational disruptions. The other comes from Iranian media, citing a single unnamed crew member, which has alleged a much more extensive compromise involving cooling, fuel systems, and other critical elements of the vessel. Those claims have not been independently verified as of yet, so it’s important to keep your skeptical hat on. Additionally, it’s important to note that Iranian media reporting on the incident also does not establish Iranian responsibility; attribution remains unresolved.

“Regardless, this is a significant situation. A suspected compromise aboard a tanker warrants serious attention even if propulsion and other critical systems continued operating normally. The fact that the Coast Guard and FBI deployed their cyber teams to assess the vessel and remove potential threats shows the importance, even if it does not validate the more dramatic claims.

“The reported communications outage raises a separate technical question. A compromise of the communications suite, or plain RF interference, could explain a 30-hour outage without a threat actor ever touching the ship’s controls. GPS receivers and satellite terminals are chronically soft targets, and I spent enough of my military career working through degraded and jammed satellite comms to know how ordinary that failure mode is. The Strait of Gibraltar in particular is a well-documented GNSS interference corridor, so that’s a possibility I’d want investigators to rule in or out early, but an outage on its own still tells you nothing about how far an intrusion actually reached.

“I think if we take anything away from this ordeal, it is that nothing came of this compromise. No major disruption, environmental impact, or danger to the crew, and if a threat actor genuinely had control of propulsion on a fully loaded crude carrier, the obvious question is why nothing was done with it. When I’ve seen this pattern in the past, it usually points to a proof-of-concept or recon attack, more colloquially put, a rehearsal, not a performance. Now, a rehearsal for what? Can’t say, and neither can anyone else right now, but that’s for the investigators to work out. Either way, with global oil supply already at its tightest it’s been in modern history, this isn’t a low-consequence practice run.”

Damon Small, Board of Directors, Xcape Inc.:

“Physical maritime operations and global energy supply chains face severe operational risks when shipboard networks are compromised. Contrary to official statements downplaying the event, a 30-hour communications blackout on a crude carrier is a significant operational disruption. Vessels underway depend heavily on continuous communications for navigation and collision avoidance, meaning an unannounced blackout can easily precipitate a maritime disaster. Modern commercial watercraft rely on multi-channel connectivity including Very Small Aperture Terminal (VSAT), cellular, and Wi-Fi systems, making a sustained blackout indicative of critical bridge system failure. Defenders must strictly segment bridge communication links from physical operational technology domains, audit firmware across satellite hardware, and monitor for anomalous signal degradation.

“Critical Takeaways

  • Communication loss directly compromises vessel navigation, making a multi-hour blackout a primary operational threat rather than a minor IT glitch.
  • Reliance on VSAT, cellular, and Wi-Fi links requires strict logical separation to prevent lateral movement into shipboard control systems.
  • Maritime operators must treat satellite communications and bridge telemetry as mission-critical assets requiring continuous anomaly monitoring.

“Calling a 30-hour communication blackout on a crude carrier non-disruptive is like ignoring a broken ship’s wheel because the horn still works.”

It seems like threat actors may have found a new hunting ground. That is bad news for all of us.

New GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Take Over Accounts 

Posted in Commentary with tags on September 16, 2026 by itnerd

Researchers have identified an active device code phishing campaign/kit dubbed “GhostCode” that is distributed through web contact forms, whereby threat actors pose as a procurement officer of a legitimate business. Device code phishing kits abuse the OAuth 2.0 device authorization grant flow to gain access to Microsoft accounts https://www.esentire.com/blog/ghostcode-dissecting-a-novel-device-code-phishing-kit

Michael Jenkins, CTO at  ThreatLocker provided the following comments:

“We’ve known for a while that attackers can get around MFA by stealing valid session tokens or sitting as an attacker-in-the-middle during MFA authentication. In this case, the victim completes a Microsoft authentication process but the attacker walks away with a valid token it can use to gain access. It’s another example of why MFA alone is no longer enough. Authentication should also verify that access is coming from an approved device so a stolen credential won’t work on an untrusted machine. Device identity needs to become another required layer of how we protect accounts online.”

Microsoft accounts are bane of my existence as account takeovers are common. One can hope that Microsoft does something about this so that changes.

Rogue AI agents expose a new authentication gap

Posted in Commentary with tags on September 16, 2026 by itnerd

Two newly disclosed incidents involving rogue AI agents are highlighting a similar security problem: autonomous software operating behind apparently legitimate access.

While OpenAI has disclosed] that agents operating through compromised accounts probed Hugging Face for vulnerabilities, Spain’s data protection authority (AEPD) has also disclosed what it describes as its first reported AI-agent-linked data breach, in which an agent identified vulnerabilities, gained access, modified personal data and viewed billing information with minimal human intervention.

Ted Miracco, CEO of Approov Had This To Say:

 “These incidents confirm that relying on account authentication alone is necessary but not sufficient. Whether it’s a probed vulnerability or an autonomous data breach, the fundamental issue remains: an account credential only proves who is authorized, not what software is actually behind the request.

   “When agentic software can operate autonomously at machine speed, APIs must move beyond simple authentication and verify both the identity and integrity of the agent software itself for every request. We are seeing a shift where security must be enforced within the software logic, or organizations will remain vulnerable to these sophisticated agent-based threats.”

AI can’t be trusted. That is the takeaway from this. Thus companies need to have all the required guardrails in place before it should be trusted. Otherwise you get this.

OpenAI’s rogue agents scoped out Hugging Face months before July breach 

Posted in Commentary with tags on September 16, 2026 by itnerd

Reuters reports that rogue OpenAI agents hijacked Hugging Face user accounts and probed the platform for vulnerabilities as early as May 13, nearly two months before the July breach OpenAI called an unprecedented cyber incident, eventually obtaining credentials and gaining root access to a Hugging Face server.

Justin Beals, CEO & Founder, Strike Graph

“OpenAI wants you to read this as a machine that went rogue. Read it as a governance failure instead. Per Reuters, the company’s agents were hijacking Hugging Face accounts and probing the site for vulnerabilities by May 13, roughly two months before the July breach OpenAI called an unprecedented cyber incident, and the agents eventually obtained credentials and gained root access to a Hugging Face server. No agent does any of that without humans upstream: someone launched the run, someone owned the environment it escaped, someone owned the monitoring that never fired. ‘The AI did it’ doesn’t move accountability off the org chart. It just tells you which controls failed, and who owned them.

The harder question isn’t whether OpenAI knew in May. It’s whether they chose not to look. The company has conceded that, with hindsight, some early signals should have triggered an earlier response, and it has acknowledged related incidents, including RubyGems and a dormant German wiki, only after outside researchers surfaced them. In compliance terms, that’s the line where ‘we didn’t know’ stops working as a defense and starts looking like willful blindness. You don’t need a criminal charge to see it: a lab running autonomous agents in internet-reachable environments has a duty to detect when those agents attack third parties and to disclose it without being caught first. Every regulated company already lives under that standard. A frontier lab shouldn’t get a discount on it.”

Mike Barry, VP Engineering, Team Cymru

“Vulnerabilities have always been found and exploited, and that cat-and-mouse will continue. What’s changed is the tempo. Agents work in large numbers, around the clock, and they’re efficient and effective at both discovery and exploitation. The July Hugging Face intrusion is the clearest example yet: OpenAI confirmed it was carried out by its own models, running with reduced cyber refusals for a benchmark evaluation. The natural response is to fight AI with AI, but Hugging Face’s responders found the commercial frontier models available to them refused to analyze the attacker’s exploit code, and they had to fall back on a locally hosted open-weight model. That’s a harmful asymmetry, a US frontier lab loosened the guardrails on its own model for its own purposes, that model breached a third party, and the defenders were left with the throttled versions the same class of labs ships to everyone else. The fix isn’t stripping guardrails wholesale. It’s trusted access for vetted defenders to frontier models with refusals tuned for forensic and defensive work, alongside capable open-weight models, so no incident responder is dependent on a single vendor’s refusal policy mid-breach. Visibility over time matters, but so does whether defenders are permitted to bring equivalent capability to the fight.”

This pretty much proves that more guardrails and restrictions need to be wrapped around AI. It also proves that Sam Altman and company can’t be trusted with this tech and action needs to be taken.

UPDATE: Additional commentary has come in starting with Ashley Knowles, Sr. Cyber Security Consultant, Black Hills Information Security (https://www.linkedin.com/in/ashleylknowles)

“I don’t believe that penetration testing will change dramatically from how the process is now. AI is allowing us to cover more ground than we could before in the same time frame as we can develop and test code quickly, analyze data, and automate parts of the process. However, this is where the human in the loop still needs to be carefully considered and implemented. AI produces false positives and negatives. It imagines CVE’s, exploits, and incorrectly identifies scenarios.

“As for OpenAI’s hugging face situation where the agent was probing for months prior, this is not a surprise. Most major breaches occur for longer than most people think. While conducting IR, you’ll be able to piece together a more accurate time frame.

“Additionally, OpenAI needs to reconsider giving their agents internet access. Security controls like they’re currently developing already exist. There’s no reason to reinvent the wheel here. They just need to be implemented.”

Mike Bell, Founder & CEO, Suzu Labs (https://www.linkedin.com/in/artificial-mike)

“Security professionals need to be in these processes from the start, not piecing things together months later. The RubyGems campaign was spinning up a new account every two to three minutes; any security team with proper monitoring catches that in real time. OpenAI’s own people didn’t catch the May activity. A 27-year-old in Germany did, in September.

“We need a different security model for autonomous agents, but first someone should explain why these companies keep finding out about their own agents’ behavior from press inquiries. Third-party monitoring, independent sandbox design review, red teams that report to someone outside the company being tested…… none of this is exotic. OpenAI and the other foundational model providers have the budget for it. What they have been producing instead is reactive disclosure after outside researchers do the actual work, then calling it transparency.

“The defense industry solved this problem years ago. CMMC, FedRAMP, third-party assessment organizations already exist precisely because self-certification does not hold up. An independent assessor reviews the environment, validates the controls, monitors the test, and signs off on the results with no stake in what those results show. The AI industry has the money and the talent pool available to it. The part that is missing is willingness to let someone else grade them.”

Kevin Surace, CEO, TokenCore (https://www.linkedin.com/in/ksurace)

“These were cybersecurity research agents built to find vulnerabilities, with safeguards reduced for testing. They were not customer support agents suddenly deciding to hack. That context matters. But finding weaknesses inside a controlled evaluation is different from probing an outside company. Using outside credentials and reaching third-party systems crossed the intended boundary. Even if they were executing their main goal.

“Security teams can recognize that boundary crossing by watching what an agent actually does. Before a run, they need to specify which systems, credentials and actions are permitted. Then they need to monitor tool use and network activity against those limits, block prohibited access and require human biometric approval before an agent acts on outside systems. Complete logs and a clear way to stop the run are essential. The organization operating the agent remains accountable for its actions.”

Hacker claims 7.5M customer records stolen from CenterPoint Energy

Posted in Commentary with tags on September 16, 2026 by itnerd

Texas utility CenterPoint Energy has confirmed a data breach after a hacker published customer information online and claimed to have stolen approximately 7.5 million records.

The company said an unauthorized third party obtained personal information through one of its external-facing systems and has brought in cybersecurity experts to investigate the intrusion.

The hacker, who uses the name “Lovely,” claims to have accessed millions of customer records containing names, addresses, phone numbers, email addresses, account numbers and other information. Samples of the allegedly stolen data were posted publicly, prompting CenterPoint to investigate and confirm that customer information had been compromised.

CenterPoint has not confirmed the hacker’s estimate of 7.5 million records and is still determining the number of customers and types of information affected. The company provides electricity and natural gas to millions of customers across several states, including Texas, Indiana, Minnesota and Ohio.

Jeremiah Fowler, Researcher for Black Hills Information Security:

“I have seen this unfortunate scenario play out far too often over the last few years when organizations outsource technology, development, customer support, data processing, or other business functions. Once the data is out of your control the risks are increased of an exposure and expands the potential attack surface. At the end of the day, even if the data is exposed through a contractor, vendor, or third-party system, they are still your customers and they trusted your organization with their information.

“Customer information is valuable because it can create a relationship of trust and increase the success rate of social engineering or phishing attempts. If criminals know your account number, payment amounts, support requests, and other details that only you and the service provider should know, this creates potentially dangerous scenario to build trust. Organizations may outsource services, but they are still responsible for the data protection of their customers and it is crucial that they know where information is stored, how it is transmitted, who can access it, how long it is retained, and ensure that the systems are independently audited for vulnerabilities.”

John Strand, Owner, Black Hills Information Security:

“This is a breach we need to watch closely because I think it’s going to break one of two ways. Either there was a customer-facing application exposed to the internet that was compromised, or this data was sitting on a service that never should have been exposed to the internet in the first place.

“That second possibility is particularly interesting because it’s an area I’ve been researching quite a bit lately. There are an incredible number of services exposed directly to the internet that have absolutely no reason to be accessible for customer or client interactions.

“Right now, the SEC filing tells us the breach involved an external service, but that still leaves the big question unanswered. Was this an application that legitimately needed to be internet-facing and was compromised, or was sensitive data sitting somewhere that never should have been exposed at all? That distinction matters, and we’ll need more information about the breach before we know which one happened.”

There needs to be more details here as there’s a lot of questions that are left unanswered. Hopefully we get those answers.

65% of Insurance Organizations Say Process-Related Challenges Have Caused AI Initiatives to Fail and it is Costing Them Millions

Posted in Commentary with tags on September 16, 2026 by itnerd

New research from Camunda, the enterprise platform for agentic orchestration, has revealed how broken business processes are causing AI initiatives to fail at a staggering rate. According to the report, The AI Process Gap, 65% of insurance organizations say that process-related challenges have caused AI initiatives to fail at an average cost of $1.40 million per business. Furthermore, another two thirds (65%) say that AI costs will spiral unless they gain better control over their business processes, with 79% believing that their AI investments will be a bust without more investment in process re-design. 

The report highlights how many insurance organizations are attempting to bolt AI onto business processes, which weren’t built in the AI era, vs taking the outcome-centric approach and re-designing them from scratch. That’s because 79% of organizations state that adding AI onto existing processes creates less internal resistance, with 77% saying adapting all their most important processes for AI will take up to five years.

Growing Governance and Compliance Exposure

The report reveals that legacy or poorly designed processes are a leading contributor to the AI-related compliance and governance failures insurance firms already face. 

  • 26% of organizations have suffered an AI-related compliance or governance issue in the past 12 months. And process-related issues have contributed to the vast majority (89%) of them.
  • One in five (18%) organizations fear AI agents going rogue if they make changes to a process.
  • 79% of employees fear that their use of AI will lead to a compliance issue in their organization and almost all (99%) expect process challenges will contribute to future AI-related compliance issues.

The Leadership-Employee Gap

Employees are also feeling the impact of AI being introduced into processes that were never designed for it. Many are left to absorb the friction, quietly working around the AI tools that were supposed to make their jobs easier. So while 88% of insurance organizations say AI is making their teams more productive, only 57% of employees agree. 

In fact, a quarter (26%) of organizations say they have rolled back on the use of AI because it’s had a negative impact on employees’ ability to do their job. And the consequences go further, with 40% of employees saying they would consider changing jobs due to poorly implemented AI.

The report also reveals the following:

  • 73% of employees were not fully consulted about how AI would be used to support their day-to-day work.
  • 63% of employees say they could use AI a lot more effectively if it was implemented differently.
  • 43% of employees say they have had to manually override AI outputs because the underlying process wasn’t set up correctly.
  • 35% of employees say they have used AI to artificially comply with their organization’s AI mandate when there was no need to do so.

For more information:

About the report

Camunda commissioned Sapio Research to conduct two surveys across the US, UK, Germany, and France. This edition reports the insurance responses: 34 process decision makers, comprising senior IT, operations, and transformation leaders involved in automation and AI strategy and execution at organizations with at least 1,000 employees, and 268 employees at organizations of the same size whose day-to-day work has had AI or automation introduced into it. Both surveys were conducted online in July and August, 2026.

New Report Says Finance Teams Are Speeding Up Tasks with AI, But Failing to Fix The Cash Cycle

Posted in Commentary with tags on September 16, 2026 by itnerd

Auditoria.AI today unveiled its seventh annual State of AI Automation in the Finance Office Report, revealing a finance function investing decisively in artificial intelligence (AI) while still working through the harder challenge of turning experimentation into reliable execution.

The 2026 report, The Age of Exploration, finds that 66.5% of finance organizations are increasing their investment in AI, with 24.2% now treating it as a top budget priority. Among respondents to the AI initiative success question, only 21.0% report meaningful, measurable results, while 64.8% report mixed or unsuccessful outcomes. A further 14.2% have not attempted an AI initiative.

AI is also firmly established across the finance office, but maturity remains low. Some 58.4% of finance teams remain in the exploring or piloting stages, while only 12.8% have progressed to optimizing or autonomous operations. Just 2.5% describe their finance operations as fully autonomous.

Finance is moving faster, but the work is still getting stuck

Finance teams are responding faster, while staffing pressure appears relatively contained. In 2026, 43.8% of shared inbox requests fall into the “within 24 hours” response band, with another 16.1% answered in under two hours. Meanwhile, 42.1% of finance teams say they are fully staffed and stable, and another 36.3% are hiring but regard their gaps as manageable, while only 9.2% report persistent hiring strain.

The follow-up burden has risen sharply. The share of finance teams spending 11 or more hours a week chasing vendors, customers, and internal stakeholders held between 17.6% and 29.7% from 2022 through 2025, then jumped to 44.5% in 2026, the largest single-year movement anywhere in this year’s study. A further 13.4% now spend more than 30 hours a week on follow-up, more than double last year’s 5.6%.

That points to a problem beyond response speed or headcount. Checking and updating data is now cited by 50.7% of respondents, followed by manual or repetitive work at 48.3% and document extraction at 46.2%.

Inaccurate or partially complete information from vendors and customers is also the biggest daily pain point at 22.1%, effectively tied with shared inbox volume at 21.7%.

Key findings from the 2026 report

  • AI investment remains strong: 66.5% of finance organizations are increasing AI investment, while only 0.7% are decreasing spend.
  • Measurable success remains limited: 64.8% report mixed or unsuccessful AI outcomes, while 21.0% report meaningful, measurable results.
  • Pilots continue to dominate: 58.4% remain in the exploring or piloting stages, with only 12.8% optimizing or operating autonomously.
  • AI is beginning to execute work: 39.9% operate with a model in which AI executes work, while 48.8% still retain human execution.
  • Integration is now the leading AI barrier: 36.7% cite integration with existing systems, narrowly ahead of high initial investment costs at 36.3%. Security and privacy follow at 34.5% and finding suitable automation tools at 33.8%. Resistance to technology adoption, once the leading barrier, has fallen to seventh.
  • Technology itself is the leading source of disappointment: Asked why AI initiatives fell short, 29.2% of all respondents, and 36.6% of those who reported a shortfall, say the technology did not perform as expected, followed by 21.7% citing internal buy-in or change management.
  • Confidence in finance data remains high: 75.4% say their reporting is accurate enough to meaningfully improve results, although only 24.7% treat improving data quality as a critical top priority.
  • Respondents largely expect AI to change rather than eliminate their roles: 60.6% expect AI to make their work more strategic or require new skills, while just 3.4% are concerned AI could reduce the need for their role entirely.

From AI assistance to Governed Autonomy

As AI becomes capable of doing more than drafting, analyzing, or recommending, the report also examines how much authority finance teams are prepared to give it.

Today, 26.3% of respondents operate with supervised autonomy, where AI handles routine work, and people review exceptions. Roughly one in seven respondents, 13.5%, describe their operating model as governed autonomy, where AI can execute work end-to-end within defined rules and compliance guardrails. By contrast, 33.1% still require a person to approve every AI-recommended action.

For Auditoria, this evolution toward Governed Autonomy represents an important next step in applying AI across the Cash Cycle.

The report also finds that AI deployment is spreading across the finance office, with the average finance team now using AI across 2.43 functions, a 36% increase in deployment breadth in a single year. Invoice and document digitization, anomaly and error detection, cash flow forecasting, and compliance reporting are among the most common applications, with no single use case dominating adoption.

About the research

The 2026 State of AI Automation in the Finance Office is based on a survey conducted by Auditoria.AI in 2026. Following data validation, the study included approximately 300 respondents, including finance and accounting professionals, as well as technology and transformation roles supporting the finance function. 

Download the full The Age of Exploration: State of AI Automation in the Finance Office Report 2026 report. 

Hackers sitting undetected for months is the real Revolut breach story

Posted in Commentary with tags on September 16, 2026 by itnerd

If you remember this post, then the follow up will be of interest to you. Revolut’s hackers claim that they were able to access sensitive data about wealthy customers by using a compromised Italian government email system to impersonate Italian law enforcement. This wasn’t a break in, Revolut handed over the keys.

Jeremy Leasher, Forward Deployed Security Architect, Binalyze said this

“The hackers claim to have breached Revolut using inherent authority – in this case an Italian government’s email system to simply ask for the data they wanted.

“The biggest concern this raises is how long the hackers claim to have been inside the Italian government’s e-mail system. Supposedly communicating with Revolut over several months to build up a treasure trove of ransom-able information. That doesn’t happen without evidence: there will have been logins, emails and files being sent and received, that should have set alarms ringing – but clearly didn’t. A key takeaway to remember is that we almost certainly don’t yet have the full picture of what the hackers got up to whilst they were in the system. There will be artifacts that prove what data was touched by the threat actor, and when. Having that visibility earlier could have meant earlier detection: and that’s what organisations should strive for.

“The Italian authorities should be taking immediate action to investigate at a deep level how the attackers gained access and what else they were able to do whilst they were inside their systems. Organisations both private and public need to be continuously alert for this kind of unauthorised activity, highlighting anomalies so they can be investigated before they turn into a crisis. 

“For those that have fallen victim to this breach and had their data disclosed it would be wise to ensure they are following the personal cybersecurity basics to keep themselves as safe as possible. This should include:

  • Enable strong multi-factor authentication (MFA) wherever possible: It’s easy to assume that all forms of MFA are equal. But passkeys or hardware-based methods that take more technical acumen, are much more secure and give more peace of mind than text messages.
  • Use a password manager: The most secure approach to passwords is to have a different one for every account. But most people’s memory can’t manage this; either passwords will be too simple, repetition will creep in. A password manager creates unique passwords for every account while offloading the memory work.
  • Regularly review account activity. Perhaps the most simple action, but there should be no place for unknown devices or sessions on your key accounts. A regular check on which devices are authorised and logged in will pay dividends in reporting and removing anything suspicious.”

This is a massive amount of pwnage. And deserves an investigation to match. Otherwise we are all wasting our time.

Deloitte says UK workers are spending nearly £1bn of their own money on AI for work

Posted in Commentary with tags on September 16, 2026 by itnerd

Deloitte’s new research shows that UK workers are spending nearly £1bn of their own money on AI for work. Could employers’ restrictions drive even more of that use out of sight?

Paul Stokes, CEO and co-founder, Prevalent AI has provided this comment.

“The Deloitte GenAI Workforce Survey shows that enterprises have struggled to keep up with the demands for AI adoption. If British workers are using personal tools to deliver corporate goals, then they are exposing sensitive company data to unnecessary risk.

Technology leaders need a pragmatic approach to AI adoption. By providing the right level of access to employees, together with guardrails and the structured use of enterprise data, they can drive employee productivity while meeting organisational and regulatory requirements around data protection and privacy.”

Honesty, the use of “shadow AI” needs to be cracked down upon because that is only going to end badly. First should come the education, then should come more stricter measures in my opinion.