10 Web Analytics Tools That Measure Behavior, Not Just Pageviews
From Glassbox's compliance-grade replay to Datadog's observability-first approach, these platforms offer different depths of insight into why users act—and each comes with trade-offs.
Former GCHQ analyst Julian Richards explains why executive complacency fuels breaches, and how upskilling at the top beats any firewall.
Source material: techradar.com
Because when a breach happens, the board takes the hit — legally and reputationally — yet most executives still treat cybersecurity as someone else's problem. Julian Richards, a former GCHQ senior analyst, says this attitude is increasingly untenable. AI has collapsed the skill gap between ordinary criminals and state-sponsored groups. Tactics like ETERNALBLUE, once stolen from the NSA and resold on the dark web, are now available to anyone. Executives who cannot distinguish a real threat from a false alarm will either overreact or freeze. The answer is not delegating, but hands-on training: crisis workshops, simulated ransomware exercises, and regular briefings on how AI tools like Claude Mythos and GPT-5.5 can both defend and attack. Without that layer of personal competence, the rest of the organization's security culture crumbles.
Complacency — the belief that a breach happens to other firms, not yours — remains the most intractable problem, says Richards. He identifies two persistent blind spots: that one, and a failure to grasp the human factor as the biggest threat vector. Even with advanced AI defenses, a single phishing click or a misconfigured internal protocol can undo everything. The 2025 IBM report quantified the stakes: a 44% increase in attacks exploiting public-facing applications, a 40% rise in vulnerability exploitation, and a 50% jump in active ransomware operators since 2025. These jumps stem from attackers adopting AI to automate reconnaissance, refine malware, and scale their operations, meaning even smaller firms are now in scope. Leaders who assume their industry or size protects them are precisely the targets AI-equipped attackers seek. Training, awareness, and crisis rehearsals feel tedious but remain the core defense, particularly because AI-enabled attacks often exploit human error rather than pure technical flaws.
AI has compressed the window between when a vulnerability is disclosed and when it's weaponized from months to days or even hours. Richards notes that threat actors now use AI to automate reconnaissance, modify malware, and chain exploits at industrial scale. But the reverse also holds: defenders can use AI to map and analyze attacks in real time, even as they mutate. This dynamic race means static security measures fail. Companies can no longer rely on patching within a quarterly cycle. The shrinking timeframe also pressures governments to rethink threat disclosure rules — compliance legislation, Richards says, moves far slower than technology. He advocates for allowing post-facto disclosure in fast-moving situations, so organizations aren't penalized for prioritizing containment over immediate public reporting.
No — and Richards points to cryptography as a parallel world where exploits remain valuable for years after exposure. He introduces a widened notion of 'harvest now, exploit later,' alongside the established HNDL (harvest now, decrypt later). Attackers collect vulnerabilities and data now, waiting for the right moment or for AI to make decryption feasible. This means defenders must adopt a dynamic, diversified strategy that goes beyond technical fixes into human-layer planning. Instead of hoarding defensive secrets, businesses can use AI to continually map their own attack surface, simulating how an exploit might evolve. The lesson: don't assume a patched vulnerability is gone for good; threat actors may have already harvested it and will use it when a new connection is exposed.
Legacy systems often lack the APIs and data formats needed for AI-driven active defense, forcing companies to choose between incompatible tools. Richards cautions that there are 'good and bad products on the market' and many bad investment decisions are made in desperation. The core challenge is tailoring the defense strategy to the business's scale and shape — a one-size-fits-all suite will fail on aging infrastructure. He advises dealing with 'honest and adept brokers' who understand your environment, not just the latest AI hype. Practical steps: audit which legacy components can be monitored, invest in network segmentation to isolate AI tools from critical old systems, and prioritize patching for systems that are internet-facing. Without these, active defense like automated threat hunting can break more than it protects.
Richards predicts that court cases will be brought to challenge overly stringent threat disclosure penalties, with subsequent precedents eventually balancing organizational protection against the need for rapid response. This will require leveraging advanced cyber expertise in law and legislation, so businesses should ensure their legal teams understand AI threat dynamics and can navigate evolving legal frameworks. Documenting incident response decisions remains a prudent safeguard. Because AI accelerates the window between vulnerability discovery and exploitation, a rigid disclosure deadline can force companies to reveal vulnerabilities before they have patched them, or to risk penalties for waiting. Compliance legislation moves much more slowly than technology, so these windows will become increasingly outdated. Drawing on intelligence practice of selective disclosure for national security, commercial bodies may need creative regulation that allows for post facto disclosure in fast-moving situations. Until precedents emerge, legal teams should track evolving case law and build flexible response protocols that prioritize stakeholder safety while preserving evidence.
C-suite leaders need to upskill themselves first, says Richards — but they should also build relationships with reputable threat intelligence suppliers who offer triangulated data. For real-time incident response, he recommends working with analysts who have experience in intelligence, such as those from GCHQ backgrounds, rather than generic consultants. Larger organizations can create a dedicated cyber threat intel role that reports directly to the CEO. Small businesses should seek vetted MSSPs (managed security service providers) that specialize in their sector. Crucially, executives must participate in crisis exercises alongside their technical teams — deciding when to shut down systems, when to pay ransom (rarely advised), and when to contact authorities. The goal is to make decisions under pressure, not to rely on third-party advice alone.
Where this came from. This breakdown is based on source material published at techradar.com. Images above are used with the credits shown beneath each one.