Quorum Cyber - Experts & Thought Leaders

Latest Quorum Cyber news & announcements

Kevin Hanes Leads Quorum's Global Expansion

Quorum Cyber, an a-winning Microsoft-first cyber security services provider, announces the appointment of Kevin Hanes as its new CEO to drive the next stage of global expansion. As a seasoned cyber security executive, growth leader, and recognized innovator with a proven track record of scaling high-performance teams, Hanes has led both Reveal Security and Cybrary as CEO, served as COO of Secureworks for eight years – where he built the firm's EMEA presence and Romania operations from scratch – and as Executive Director at Dell Technologies. His extensive leadership qualities, experience, and vision are ideally suited to delivering long-term, sustainable, enterprise value-creation at Quorum Cyber. Achieving operational excellence Hanes is passionate about collaborating closely with customers and supporting them to solve their biggest cyber security problems, fighting bullies, and helping good people win. His focus will be on protecting as many organizations as possible, achieving operational excellence, and building momentum to scale and optimize the business. With over 25 years of executive experience in the cyber security industry, Hanes’ unsurpassed track record underscores Quorum Cyber’s ambitious international expansion plans, and its strategy to serve the Microsoft ecosystem worldwide. “With growing AI risks in cyber security, enterprises and organizations need access to Quorum Cyber’s solutions more than ever. Kevin Hanes has the experience, expertise, and vision required to lead the company to the next chapter in its growth journey and I’m confident that he’ll transform Quorum Cyber into a global Microsoft-first cyber security powerhouse,” says Darren Battistoni, Chairman of the Board of Quorum Cyber and Managing Director of Eterna Growth Partners. Fastest-growing businesses “I’m excited and honored to be joining Quorum Cyber at a time when cyber security is undergoing massive changes at a rapid pace,” says CEO Kevin Hanes. “This is an excellent time for us to capitalize on, and harness, AI-powered technology, and fuse it together with human experience and touch at the right points to keep our customers safe around the clock and defending at machine-speed.”   Last week, Quorum Cyber achieved a place on the inaugural 2026 edition of The Sunday Times Scotland Fast 50, a prestigious annual list of Scotland’s fastest-growing businesses. Among its many other accolades are the 2025 Microsoft Security MSSP of the Year, Best Cybersecurity Service Provider of the Year at the Globee Awards 2026, ScotlandIS Digital Technology Business of the Year for 2026, and Cybersecurity Company of the Year at the 2025 Scottish Cyber Awards.

Quorum Cyber Report: Rising Global Cyber Vulnerabilities

Quorum Cyber reveals the extensive, but alarming findings of its 2026 Global Cyber Risk Outlook report. AI automation and Ransomware-as-a-Service (RaaS) platforms have fundamentally altered the threat landscape, enabling nation-state actors to automate up to 90% of intrusions, and pushing vulnerability disclosures past 35,000 for the first time. Attackers abandon slow-encryption tactics, as evidenced by ransom demands in financial services exploding by 179%. Organizations face a stark reality: detection windows are shrinking, barriers to hacker entry are collapsing, and even modestly skilled criminals now wield capabilities once reserved for elite operators. Cyber risk considerations Insights from the 2026 Global Cyber Risk Outlook are derived from incidents and investigations observed across over 350 global organizations ranging in staff size from 10 to 10,000 throughout calendar year 2025. Highlighted report findings that need to reshape 2026 cyber risk considerations include: The number of newly formed ransomware groups increased by 30% in the year to October 2025 Global vulnerability disclosures rose 21%, surpassing 35,000 Early evidence of a nation-state group using AI agents to automate up to 90% of an intrusion Cybercriminals are increasingly shifting away from encryption toward faster, lower-cost data exfiltration attacks New white-label RaaS platforms enabling rapid launch of branded criminal operations Average ransom demands surged across multiple sectors, including 179% in financial services and 97% in manufacturing Nation-state threat actors associated with Russia, China, and Iran remain the top threats to the public sector, while North Korea-linked actors likely earned over $2 billion from cybercrime in 2025 Professionalised cybercriminal economy                “Over the past year, we have witnessed a marked acceleration in the capability and ambition of threat actors. The proliferation of AI-enabled tooling, combined with an increasingly professionalised cybercriminal economy, has lowered barriers to entry and expanded the reach of even modestly skilled actors,” says Federico Charosky, Quorum Cyber’s Chief Executive Officer. “This report distills the most significant developments observed across our intelligence, incident response, and counter extortion work, offering practical guidance to help organizations anticipate and mitigate emerging risks.” Strengthening cyber resilience In addition, the 2026 Global Cyber Risk Outlook includes companion reports focused on nine industry sectors, including energy, financial services and insurance, healthcare and pharmaceuticals, higher education, housing and construction, legal and professional services, manufacturing, public sector, and retail. Each companion report outlines sector-specific threat dynamics and practical considerations for strengthening cyber resilience. To help organizations interpret these findings and prioritise action, Quorum Cyber will host a live webinar on February 25 featuring Lesley Kipling, Chief Security Advisor at Microsoft, alongside Quorum Cyber’s Threat Intelligence leadership. The session will examine how evolving threat actor tactics intersect with modern cloud, identity, and AI-driven environments — and what security leaders should focus on to strengthen resilience heading into 2026. The 2026 Global Cyber Risk Outlook reflects Quorum Cyber’s Microsoft-first approach to security, informed by deep visibility into cloud, identity, and AI-driven environments. Founded as a Microsoft-first security services provider, Quorum Cyber is a long-standing member of the Microsoft Intelligent Security Association (MISA) and holds all four Microsoft Security specialisations: Cloud Security, Identity and Access Management, Information Protection and Governance, and Threat Protection.

Quorum Cyber: Mitigating NodeSnake Threat In Education

Quorum Cyber, a cybersecurity firm, announced that it has identified two new variants of a Remote Access Trojan (RAT) tracked as NodeSnake.  The Quorum Cyber Threat Intelligence team is tracking this malware, which is highly likely attributed to Interlock ransomware due to infrastructure attribution. Quorum Cyber’s NodeSnake report Quorum Cyber’s NodeSnake report contains a detailed technical analysis and recommendations The team assessed that Interlock has likely recently shifted tactics to target both local government organizations and the higher education sector, based on recent observed activity.  Quorum Cyber’s NodeSnake report contains a detailed technical analysis and recommendations to mitigate the effects of the malware. Quorum Cyber’s Threat Intelligence Threat actors can use RATs to gain remote control over infected systems, access files, monitor activities, manipulate system settings, edit, delete or exfiltrate data. They can maintain persistence within an organization as well as to introduce additional tooling or malware to the environment.  Quorum Cyber’s Threat Intelligence team discovered code commonality within malware deployed against two British higher education institutions within a two-month period. Interlock ransomware infrastructure Interlock ransomware infrastructure seen targeting British universities, has now been detected On analysis, it is probable that both NodeSnake RATs were placed within the universities by the same threat actor. It is also certain that both instances of this malware are from the same family, with the later iteration possessing considerable advancements over the earlier variant. In a recent development, Interlock ransomware infrastructure seen targeting British universities, has now been detected impacting regional councils in the country. Use of the NodeSnake variants “We have observed threat actors increasingly targeting universities this year to exfiltrate valuable intellectual property, including research data, and possibly to test and hone new tactics, techniques, and procedures before potentially applying them in other sectors,” said Paul Caiazzo, Chief Threat Officer at Quorum Cyber. “Theft of research data suggests an espionage motivation, and as such, our Threat Intelligence team continues to monitor Interlock and its use of the NodeSnake variants so that we can advise organizations across sectors on practical steps they can take to prevent the theft of their own intellectual property.” Double-extortion tactics Interlock has targeted large or high-value organizations in a range of industries First observed in September 2024, Interlock has targeted large or high-value organizations in a range of industries across North America and Europe. It’s known to employ double-extortion tactics by encrypting data and threatening to release it unless a ransom fee is paid. Unlike many other ransomware groups, Interlock does not operate as a Ransomware-as-a-Service (RaaS) and has no known affiliates. Relevant ransomware reports Interlock ransomware could target both Linux and Windows operating systems, providing it with broad targeting capabilities. Quorum Cyber’s Threat Intelligence Community Group publishes a large collection of relevant ransomware reports, threat actor profiles, and timely threat intelligence bulletins that can all be downloaded for free.