Skip to main content

Sync NI Magazine Summer 2026

Page 1


Stephen McKeown, Global Vice President and Managing Director

Welcome to the summer 2026 edition of the Sync NI magazine

Northern Ireland has always had a reputation for innovation, ingenuity and a quiet confidence. Today, that confidence is firmly justified. In the most recent European Regional Innovation Scoreboard, the region was ranked a Strong Innovator, highlighted as a pocket of excellence beyond traditional capitals, and recognised in the top group for employment in innovative enterprises.

As you read this edition of Sync NI, it’s clear our local tech community is not just keeping pace with global change but helping to shape it. Across artificial intelligence, cyber security and digital careers, we continue to punch well above our weight on the world stage.

What stands out most in this issue is not simply the pace of technological progress, but the calibre of the people behind it. From engineers to product designers, the depth and quality of skills coming out of Northern Ireland are exceptional. As my article in this edition highlights, our region plays a vital role in global technology ecosystems, shaping products and business systems used by millions of people every day. That influence is built on deep technical expertise, strong judgement, and a culture rooted in trust and accountability. It prioritises meaningful outcomes, focusing on building products and services that customers love.

Technology itself has changed dramatically. We’ve moved beyond viewing innovation as something that happens on the edge of organisations. Today, operating “at the frontier” of an industry means embedding it into day-to-day work, continuously learning, and rethinking how value is created for customers and communities

alike. AI, automation and cyber capabilities are evolving at extraordinary speed. Continuously investing in skills is no longer optional; it’s essential. The most successful technologists are those who stay curious, who learn constantly, and who are prepared to challenge assumptions.

Just as important as technical skill is culture. The strongest teams are built on connection and collaboration, people learning together and pushing boundaries safely and responsibly. Practices that prioritise quality, ethics and trust ensure technology creates space for better judgement, creativity and empathy.

Bringing clearer, more thoughtful measurement into day to day decisions helps turn intent into impact. It ensures teams focus on what really matters, using metrics that connect directly to real outcomes and business results. This emphasis on how we work, not just what we build, is one of Northern Ireland’s greatest strengths, and a key reason our talent is so highly regarded and sought after around the world.

For students and young people thinking about their future, there has never been a more exciting time to choose a career in technology. While the tools and platforms we use continue to evolve at remarkable speed, the work of solving real problems, shaping how society benefits, and improving people’s lives. This issue of Sync NI captures a region in motion, confident, ambitious and connected. I hope it inspires professionals to keep learning and encourages the next generation to see technology as a pathway to impact, purpose and possibility.

About Sync NI

Sync NI is proud to be the voice of Northern Ireland’s vibrant technology and business sector.

The Sync NI website and magazine brings readers the latest tech and business news, views, jobs and events in Belfast and beyond.

Sync NI Contacts

Editorial Phone: 028 9082 0947 Email: team@syncni.com

Advertising & Partnerships

Louis Kingston Phone: 028 9082 0947

Email: louis@syncni.com

Digital Content

Patricia Westlake

Email: patricia@syncni.com

General Enquiries

Sync NI

Rochester Building 28 Adelaide street

Belfast BT2 8GD Phone: 028 9082 0947

Email: team@syncni.com

Online: www.syncni.com

Copyright No part of this publication may be reproduced without the written permission of the copyholder and publisher. Sync NI accepts no responsibility for the accuracy of contributed articles or statements appearing in this magazine and any views or opinions expressed are not necessarily those of Sync NI, unless otherwise indicated. No responsibility for loss or distress associated to any person acting or refraining from acting as a result of the material in this magazine can be accepted by the authors, contributors, editors or publishers. Sync NI does not endorse any goods or services advertised, nor any claims or representations made in any advertisement in this magazine.

Inside this edition

Operating at the frontier: How Allstate is redefining technology, trust and talent

Building AI that works in the real world: Inside Northern Ireland’s Artificial Intelligence Collaboration Centre

AI’s impact on recruitment: What’s changing (and what isn’t)

Why digital twins are becoming a strategic capability for the UK economy

Q&A with Eddie Coghlan, Head of Development at TP ICAP & Belfast Technology Hub

Lewis Silkin's research reveals NI employers know AI matters, but are struggling to deploy it

Northern Ireland's Cyber Frontline: Assessing the risks, threats and opportunities

Q&A with Thom Langford, EMEA CTO at Rapid7

Identity at risk: Why Cyber Security in Northern Ireland must rethink what it protects

Yesterday’s defences, today’s attacker

Navigating Cybersecurity crossroads: Key lessons for 2026

Reach beyond: Engineering careers at Liberty IT

Q&A with Tommy McClean, Principal Product Designer at DailyPay

Elevate 9D brings a new approach to workplace wellbeing to Belfast

Q&A with Chris Lester, European and UK Patent Attorney at CME Group

Resilience in Tech Leadership: Stephen McCabe and Ciaran May in conversation

Our health data opportunity

Operating at the frontier: How Allstate is redefining technology, trust and talent

q In a recent article, you wrote about what it really takes to operate “at the frontier.” What does that mean in practice?

Operating at the frontier of an industry isn’t about chasing the next new tool or headline technology. It’s about knowing your customers and fundamentally rethinking how work gets done, how decisions are made, and how value is created, with a clear line of sight from every action to outcomes for customers, employees and shareholders.

To do that successfully, you can’t treat innovation as something that happens on the edges of the business. It’s not an experiment, or a side project, it’s embedded into day-today work. Teams are trusted to think in terms of outcomes and solve complex problems end-to-end, testing and scaling solutions, with continuous learning built directly into how the organisation operates.

Frontier organisations also understand the full potential of technology, but pair that with strong judgement and clear accountability. Digital capability on its own isn’t enough. What matters is how people collaborate across disciplines, how leaders create the conditions for experimentation, and how organisations stay relentlessly focused on the business outcomes that matter.

That mindset, our culture, how we work, how we lead and how we grow talent, is the foundation for everything that follows.

q How is that ambition reflected in Allstate’s wider strategy?

Allstate’s Transformative Growth strategy is focused on increasing key market share, by offering affordable prices and great customer experience across protection products. The results show that approach is working and technology plays a critical role.

Particularly, where it helps remove friction, improve decisionmaking and allow people to focus on higher value work. Across Allstate today, intelligent automation already supports a sizable proportion of activity, from software development to customer communications, reducing friction, lowering escalation rates and improving speed and consistency at scale.

This progress is translating into real market impact, creating an employee culture we are proud of and validating the longterm strategy the enterprise is executing.

We’re also building a holistic AI ecosystem instead of deploying isolated tools. It’s the heart of an integrated, enterprise-wide approach that combines advanced, context aware and agentic capabilities, with affordable, simple and connected customer experiences.

This combination of scale, discipline and intentional innovation is what differentiates organisations operating at the frontier

Stephen McKeown, Global Vice President and Managing Director at Allstate NI

from those simply reacting to change.

q What does this look like in practice for Allstate engineers and technologists?

One very tangible example is our digital product model and emphasis on paired programming, particularly in cloud and product engineering. This isn’t just an agile technique; it’s an investment in long-term engineering capability.

By structuring our teams so engineers learn and solve problems together, we’ve seen measurable benefits. Paired programming has increased employee development and satisfaction while improving quality by more than 180% over the last two years. It allows teams to share context, challenge assumptions and build more resilient solutions, which is important when working on complex, high-impact systems.

As technology reshapes how software is built, strong engineering fundamentals become even more important. Practices like paired programming and test-driven development help ensure delivery with speed and quality.

q Trust comes up repeatedly in conversations around technology. Why is it so critical?

Trust ultimately determines whether any business or new technology succeeds. Allstate’s promise to customers is that they are in good hands when it matters most. That could be your digital identity being stolen or home being damaged in a hurricane.

It means being deliberate about how systems are designed and governed, being transparent with customers and employees, and ensuring people stay accountable. Trust should always be at the center of the relationship you develop with customers and every other stakeholder.

The focus on trust goes beyond how technology is used. It’s embedded in how the organisation operates. Allstate was

named one of the world’s Most Ethical Companies for the 12th consecutive year by the Ethisphere Institute, a recognition that reflects integrity, accountability and consistently doing the right thing for our customers, employees and society.

q There’s often concern that AI will reduce jobs rather than create them. How does Allstate see its responsibility here?

We see a clear responsibility to use technology in a way that expands opportunity. Recent research shows that employees are far more positive, engaged, and better able to lead change when organisations have a clear approach to AI. That means being explicit about how AI is used, why it is used, and where human oversight applies. I believe that is absolutely true.

As work evolves, demand is growing for new skills and new roles, from engineers and data specialists to digital product managers and business architects who can apply technology responsibly to complex problems. We decided to invest £16 Million in skills development to ensure that our employees are ready to not only leverage AI, but to be able to lead on how we reimagine our business in the future.

Operating at the frontier is about highervalue skills, continuous development and a strong culture of problem solving. This is why continued investment in talent, learning and early career pathways remain central, ensuring people arrive into an organisation that has already transformed, and continues to evolve.

q How does this global strategy connect to Allstate in Northern Ireland specifically?

Allstate in Northern Ireland plays a vital role in Allstate’s global technology ecosystem as a European Digital Centre of Excellence with real influence on enterprise outcomes.

Teams here are deeply involved in platform engineering, digital product

development and intelligent systems. Local teams play a critical role in building the business capabilities, technology platforms and execution muscle that underpin Allstate’s progress, helping redefine what ‘good’ looks like across the enterprise.

What makes Northern Ireland particularly special is the quality of the talent and the culture that has developed here. The teams consistently operate at a level recognised across the wider organisation, combining deep technical expertise with leadership and curiosity. That gives people here real influence over how new capabilities are shaped and deployed across the business.

q Finally, what should people watching Allstate take away from this moment?

Periods of rapid change demand clarity of intent to stay focused and succeed.

Allstate has always been a strong company, but it is fast emerging as a leader in the adoption in this new world. It was the first large company to ever win the Tony Hsieh Award at the TED Conference for our groundbreaking approach to workplace culture and innovation. That award recognised how we’re reinventing the way we work to help our team members maximize their potential. The award committee in particular highlighted Allstate’s technology operating model and the tremendous work of our employees for keeping our customers at the center of it all.

Organisations operating at the frontier don’t just adopt new technologies. They shape how those technologies are used, guided by purpose, ethics and a focus on long-term value and that is exactly the journey Allstate is on today. It means continuing to serve customers better, generating sustainable shareholder value, expanding opportunity for employees and strengthening the communities we’re part of.

Building AI that works in the real world: Inside Northern Ireland’s Artificial Intelligence Collaboration Centre

Sync NI met with Christopher McCausland and Bronagh Lannigan, Principal AI Engineers at the Artificial Intelligence Collaboration Centre (AICC) to discuss how AI can be adopted in a way that is practical, responsible and genuinely valuable to small and medium sized enterprises in Northern Ireland.

A £16.3 million initiative led by Ulster University in partnership with Queen’s University Belfast, and supported by Invest NI and the Department for the Economy, the AICC has a clear mandate: to help Northern Ireland’s SMEs move beyond curiosity into confident, responsible, real-world AI adoption. At its core, it is less about selling technology and more about building capability.

“We’re here to advance awareness and adoption of AI technologies among small and medium enterprises in Northern Ireland,” explains Christopher McCausland, Principal AI Engineer at the AICC. “we do that through hands-on support working directly with companies and through training that strengthens the wider AI ecosystem locally.” That dual focus, on delivery and skills, sets the tone for everything the centre does.

What makes the AICC distinctive within Northern Ireland’s tech landscape is not simply its scale or funding, but its position

as a connector. For many SMEs, engaging with university research can feel intimidating or inaccessible. The AICC acts as a bridge, translating academic advances into applied solutions that fit real business constraints.

“A lot of the companies we work with wouldn’t naturally know where to start with the universities,” Christopher says. “But there’s huge value there in research and expertise, particularly when you can connect it properly. That’s where we come in.” Bronagh Lannigan, also a Principal AI Engineer at the centre, describes the work as inherently bespoke. Rather than pushing generic AI solutions, the team works with businesses to break down their specific problems and determine whether AI even makes sense in the first place.

“Sometimes the answer is actually ‘no, you don’t need AI for this,’” Bronagh says. “And that’s an important outcome too. When AI is appropriate, it tends to be very tailored towards niche problems in local contexts, with very practical deployments.”

Running through everything the centre does is a strong emphasis on responsible AI. Every project begins with a critical question: should this system even exist, and if so, how can it be deployed safely, ethically and transparently?

That mindset, once peripheral, is increasingly central to

Northern Ireland’s AI identity.

Ask which sectors are best positioned to benefit from AI today, and the answer is less about novelty and more about data and pressure.

“The biggest opportunities tend to be in industries that are datarich or under resource pressure,” Bronagh explains. “Financial services, advanced manufacturing, retail, legal tech, industries where there are bottlenecks, repetitive processes, or compliance burdens.” Rather than replacing expertise, AI is being used to augment it. Predictive maintenance in manufacturing, for example, can reduce downtime. Retailers are using AI to optimise supply chains and forecasting. Professional services firms are adopting AI tools to reduce manual review and improve accuracy. Crucially, the AICC does not approach these sectors with a one-size-fits-all solution.

“Our first question isn’t ‘how do we sell AI?’” Christopher says. “It’s ‘do you actually need it?’ And if the answer is yes, we focus on using AI to handle the mundane but necessary tasks, freeing people to apply their domain expertise where it really matters.”

Much of this work happens through the AICC’s Transformer Programme, which provides hands-on support to local SMEs across a broad range of sectors. Projects range from legal technology and renewable energy to flood-risk analysis and medical imaging. This is designed to help transition from proof of concept to real-world impact.

One of the most impactful examples currently underway involves medical imaging to support cancer triage. Working with a company that already has a strong track record in this area, the AICC is helping integrate AI to improve both speed and accuracy. “That’s where it becomes real,” Christopher says. “When you can see tangible outcomes that benefit society such as decision support systems for faster triage it really brings home the value.”

Elsewhere, the team has delivered fraud detection systems for financial services firms, precision tools for legal workflows, and forecasting models to help manufacturers manage global supply chains. In one recent case, a local manufacturer worked with the centre to develop an AI-driven forecasting pipeline to anticipate component demand months in advance.

“They ended up hiring someone specifically to manage that system,” Christopher notes. “That’s a concrete example of AI creating roles, not removing them.” Success, however, looks different for every business. For some, it is time saved. For others, fewer errors, higher confidence with clients, or the ability to launch entirely new services. “There isn’t one metric,” Bronagh says. “The point is whether it delivers meaningful value for that company.”

As AI tools become more accessible, there is a growing misconception that deep technical skills are becoming optional. Both Christopher and Bronagh push back strongly on that idea.

“You still need the fundamentals,” Bronagh says. “If you can’t code, it’s very hard to critically evaluate the output of code and you’re still accountable for it.” Beyond programming, understanding the data has become increasingly vital. Where the data comes from, how clean it is and what biases it may carry are considerations that sit at the heart of AI workflows. “More and more,” Bronagh adds, “there’s also a translation role. Engineers have to work closely with domain experts, becoming partners

Christopher McCausland, Principal AI Engineer at AICC
Bronagh Lannigan Principal AI Engineer at AICC

rather than just implementers.”

Christopher sees AI as a broad spectrum of tools rather than a single skillset, ranging from traditional machine learning and image analysis to prompt engineering with large language models.

“Not everyone needs to know everything,” he says. “What matters is mapping a clear business use case first, and then deciding which tools and frameworks make sense.” Equally important is the ability to evaluate AI systems properly, not just in abstract metrics, but in the business context.

“Accuracy, sensitivity, specificity, these numbers only matter if you understand what they mean for the actual problem you’re solving,” he says. “And AI never exists in isolation. You also have to think about system cost, latency, failure modes.”

So how much AI competency is about mathematical depth versus practical application?

“It depends entirely on the role,” Christopher explains. “If you’re a full AI engineer or researcher, you should understand models from first principles. But for many users, especially senior leaders, what’s more important is understanding how AI works at a high level, its limitations, and its risks.” That high-level literacy, he argues, is essential for informed decision-making in boardrooms as much as in engineering teams. Bronagh agrees. “Different roles wear different hats. Depth and breadth are both valuable… just in different measures.”

Concerns about AI replacing jobs are rarely far from the conversation, but the AICC’s experience on the ground paints a more nuanced picture.

“We’re seeing entirely new roles emerge,” Bronagh says, pointing in particular to responsible AI, governance and assurance positions. “Companies want to use AI ethically and safely,

and that requires people who understand both the technology and its implications.” There has also been a surge in demand for AI engineers, applied data scientists, data engineers and technical product managers. These positions are often filled by professionals transitioning from more traditional software roles.

What stands out is how often AI adoption leads to hiring, not redundancy.

“When companies see real value,” Christopher says, “they invest further. They build capability around it.”

For software engineers, the next decade is likely to feel less like replacement and more like acceleration. This will be a period of augmentation rather than simple automation.

“Developers are already using AI to handle boilerplate code, search logs, identify bugs,” Bronagh explains. “What took hours can now take minutes.” That does not make the role less technical, but more strategic. “You still need to understand what’s happening,” she says. “But it gives you more time to focus on design, integration and higherlevel thinking.” Christopher describes AI fundamentally as an augmentation tool. “It speeds things up, but responsibility still sits with the engineer,” he says. “The challenge for organisations is making sure that speed doesn’t lead to burnout and that people still have time to think creatively.”

With students and graduates understandably anxious about the future, both engineers offer reassurance, practical guidance and advice for the next generation.

“Don’t be afraid of AI,” Christopher says. “It’s a tool, and it’s here to stay. Young people are already highly tech-literate, and they often see opportunities others don’t.” He encourages students to explore entrepreneurial ideas and to

become proficient with AI rather than avoiding it. Bronagh’s advice is simpler, but no less powerful: learn how to learn. “The tools will change,” she says. “What matters is staying curious, asking good questions, and being open to change.” Communication skills, she adds, are increasingly critical when it comes to translating between stakeholders, technology and real-world needs.

Looking ahead, Christopher is particularly excited about more efficient AI models such as smaller, task-specific systems optimised for energy usage.

“We have to be conscious of the environmental cost of AI,” he notes. “Using the right model for the right job matters.” For Bronagh, the excitement lies not just in the technology, but in human imagination. “Seeing how people want to use AI and coming up with ideas we’d never think of ourselves is really inspiring,” she says. “Turning those ideas into something real.”

If there is one thing both engineers would like to see more of, it is shared learning between organisations across Northern Ireland and beyond.

“People don’t need to share everything,” Bronagh explains, “but sharing lessons builds confidence and sparks ideas.” Christopher, meanwhile, is extremely encouraged by how far Northern Ireland has already come. “In just over a year, we’ve seen a real shift towards responsible AI,” he says. “It’s now part of the conversation and not just an afterthought.”

That culture around collaborative, ethical and grounded work practices may prove to be Northern Ireland’s greatest advantage as AI continues to reshape the global economy. As Christopher puts it: “It’s not just about what we can do with AI, but actually what we should do.”

Visit aicc.co to find out more and follow the AICC on LinkedIn to stay connected.

AI’s impact on recruitment: What’s changing (and what isn’t)

AI is no longer sitting on the sidelines of recruitment. It’s already shaping how businesses hire, from writing job adverts and screening CVs through to scheduling interviews and improving candidate communication.

The conversation has moved quickly from “Will AI affect recruitment?” to “How do we use it properly?”

At VANRATH, we’re seeing first-hand how technology is improving hiring processes. But while AI is changing recruitment, it isn’t replacing recruiters. It’s giving them better tools to work more efficiently and focus on highervalue work.

Recruitment teams are often dealing with high volumes of applications, tight turnaround times, and pressure from hiring managers to move quickly. AI helps streamline this by sorting CVs, identifying relevant skills, and reducing time spent on manual screening.

From an operational perspective, this is where the impact is most obvious. Tasks like CV filtering, initial shortlisting, interview scheduling, and candidate updates can now be partially automated. That reduces administrative pressure and allows recruiters to spend more time engaging directly with candidates and clients.

It also improves consistency in the early stages of hiring. AI tools can apply the same criteria across all applications, helping reduce the impact of fatigue or unconscious variation in decisionmaking. That said, the quality of output still depends heavily on the quality of input. A vague job brief or poorly defined requirements will still lead to poor outcomes.

Where things become more interesting is how AI is moving beyond simple keyword matching. Modern tools are starting to identify transferable skills and patterns across different career paths, helping surface candidates who might not fit traditional profiles but still have strong potential.

For example, someone moving from an office administration or PA background into a project coordinator role may not tick every keyword on the job description, but their experience managing diaries, coordinating stakeholders, and keeping multiple priorities on track can translate well. AI helps surface these kinds of profiles earlier in the process, widening the talent pool beyond obvious job-title matches.

Another developing area is predictive hiring. Some systems analyse historical hiring data to forecast which candidates are more likely to succeed in a role. While this can support operational decision-making, it should be used as guidance rather than a rulebook.

Recruitment isn’t purely data-driven. Culture, motivation, and team dynamics rarely show up in datasets. Predictive tools can inform decisions, but they can’t replace human judgement. AI can also improve candidate experience. For example; automated scheduling removes delays in arranging interviews, chatbots handle common queries instantly, and automated updates keep candidates informed without constant manual follow-up.

This creates a more efficient and responsive process, particularly in highvolume environments where delays can easily build up. But there’s a balance to strike. If automation is used without care, the process can feel impersonal, with candidates left interacting more with systems than people.

That’s why the operational benefits of AI need to sit alongside human oversight. The aim isn’t to remove touchpoints, but to remove friction.

For recruiters, this shift is changing how time is spent. Less energy goes into repetitive administrative tasks, and more focus is placed on consultancy, relationship building, and advising both clients and candidates. In many ways, AI is pushing the profession towards being more strategic. But despite all the change, the fundamentals of recruitment remain the same.

At its core, recruitment is still about understanding people, recognising potential, and making informed decisions that go beyond what’s written on a CV. AI can support that process, but it can’t replicate experience, instinct, or genuine human connection.

The operational side of recruitment is evolving quickly. The human side is still what makes it work.

Rebecca Jama, Operations Manager at VANRATH

From patient stories to patient safety

How AI is exploring turning patient stories into an early warning system for Northern Ireland's health system

Every day, patients across Northern Ireland share their experiences of healthcare. Some stories are positive. Others raise concerns. Most, until recently, they remained individual stories.

Indicaretor is changing that. Built through a collaboration between Queen's University Belfast, the Regulation and Quality Improvement Authority (RQIA), Care Opinion, and the Public Health Agency — and brought to life through Momentum One Zero's innovation infrastructure — it uses natural language processing to analyse patient feedback at a scale no human team could manage. Indicaretor delivers a dashboard that shows the potential of tracking how care quality changes across services, teams and organisations delivering care over time, surfacing signals of good practice for spread and scale, and risks to remediate.

We sat down with Dr. Chris Hawthorne, the researcher behind the build, to find out how it works, what it has shown, and where it goes next.

q RQIA — the healthcare regulator for Northern Ireland — was interested in exploring AI as an early warning system for patient narratives. What funnelled their interest in this space?

RQIA receives large amounts of textual and information concerning the registered organisations they regulate but less information about services provided outside of registered services, in statutory care. Patients and service users routinely provide feedback about their experiences through a public platform called Care Opinion, and when you consider this covers the whole of Northern Ireland, it quickly becomes a big data opportunity. Deriving key insights from that data has the potential to deliver real, positive change to the health and social care system.

When RQIA approached Queen's, the aim was to explore whether AI could catch those early signals from patient experiences — issues that have arisen before they snowball into something much bigger — while then also having the opportunity to spread, share and encourage good practice

Dr. Chris Hawthorne, Indicaretor

across the region.

q Care Opinion has been gathering patient stories from Northern Ireland's health trusts for five years. What were those stories actually showing that nobody had been able to act on yet?

A single story on Care Opinion has the ability to improve health and social care. What makes it such an extraordinary platform is its ability to facilitate a direct response between healthcare staff and the patient about their experience — whether that experience is good or bad. Care Opinion already works with researchers across UK universities to analyse those stories.

What we were interested in was the bigger picture. When stories are pulled together, what do they collectively show, and how does that change over time? I always think of the Ulster Folk Museum — watching weaving on the loom, where every thread is vital to the overall fabric. Each individual story matters. But together they tell something much larger.

q Applying NLP to unstructured health data sounds straightforward, but patient stories can be exceedingly complicated in narrative. What did you have to figure out before you could build something a regulator would trust? I drew on my experience as a researcher and applied those same principles to the build. When information is presented, it needs to be easy to understand, transparent in where it has come from, and reproducible. Holding to those standards consistently shaped every conversation we had around the functionality and analysis within Indicaretor — and ultimately gave the regulator confidence in what we were showing them. They are keen too that this would not just be a tool available to the regulator but would be available to those providing services so that they can take steps to improve issues that are drawn out through Indicaretor.

q During the build you were in regular discussion with RQIA and Care Opinion to test whether what you were building was actually useful to them. What did that collaboration look like in practice? The nature of our discussions has always been rooted in a shared set of values: improving health and social care, listening to the patient voice, and empowering health and social care staff. Having those values clearly in place from the start shaped everything. They weren't just a backdrop — they were the reason the collaboration held together through the complexity of the build and why Indicaretor is what it is today.

q The dashboard tracks positivity scores across cleanliness, food, level of care and staff communication at service, in services or at organisational delivery level over time. What does it look like in practice in identifying good quality care and areas of improvement? Within Indicaretor, patient narratives are categorised into different topics, things that people are talking about in their stories of their experience, and the dashboard gives end users a trending view across all of them. Depending on the pattern of the signal, such as when a particular category is consistently receiving high positivity scores – highlighting a strong quality of care or equally when the positivity score is lower, it signals that this is an area for improvement. It is the patterns that emerge across many stories over time.

q RQIA commissioned a second phase in March 2026, before the spin-out had even happened. What had Indicaretor shown them in phase one that gave them that confidence?

It was a testament to the ongoing relationship between Queen's, Momentum One Zero, Care Opinion and RQIA that we were able to continue the development of Indicaretor and move more deeply into its application

in patient safety and organisational culture. That kind of sustained trust between partners doesn't happen by accident — it is built through consistent, transparent and high-quality collaboration delivering actionable insight.

q Indicaretor Analytics Limited was spun out of Queen's in May 2026. What drove the decision to commercialise, and what does that make possible?

During the project it became clear that commercialisation could be the driver for longer-lasting impact, sustainability and broader delivery of what we set out to do — improving healthcare at scale. That realisation was supported by the strength of our relationships with RQIA and Care Opinion, and it paved the way for the spin-out. The commercial route is not a departure from the mission. It is how the mission reaches further.

q Momentum One Zero brought together academia, public bodies and a social enterprise platform under one project. That is not a group of organisations that would naturally work with each other. What did having that convener make possible?

Momentum One Zero bridges an innovation gap. It brings together interdisciplinary academic research and pairs it with real-world problems across multiple sectors — enabling innovation for social good while also building commercially sound products in a supportive environment. In numerous meetings across this project, someone would say: 'To excuse the pun, but we've got some real momentum.' And I think that sums up what Momentum One Zero actually does. Indicaretor is still in active development, with multiple end users and a growing body of evidence behind it. For Northern Ireland's health and social care system — and potentially for health systems far beyond it — the question is no longer whether AI can make sense of patient feedback at scale. Indicaretor has answered that. The question now is how far the answer can travel.

How digital, data and AI are reshaping health and care around people, not technology

q You’ve worked across government, health boards, and now with CGI spanning the UK and Australia. What’s the single biggest shift you’ve witnessed in how health and care systems think about digital transformation?

The biggest shift I’ve seen is that digital transformation has moved from being seen as an IT programme to being understood as a system transformation challenge.

When I first worked in this space, digital was often framed around systems: electronic records, portals, infrastructure, apps. All of that still matters, of course, but the conversation has matured. The real question for intelligent leadership now is not “what technology do we buy?” but “how do we redesign health and care around people, outcomes and sustainability?”

That is a fundamentally different starting point. It means digital is no longer something that sits in the CIO’s office. It touches workforce, finance, clinical practice, social care, community assets, prevention, data ethics, citizen experience and operating models. It requires boards and executives to think differently about risk, value, capacity and partnership.

For me, the most important shift is from digitising existing

processes to reimagining how care works. If we simply digitise broken pathways, we make bad processes faster. The opportunity now is to use digital, data and AI to help people access the right care, at the right time, in the right place, from the right people and increasingly, that place should be closer to home.

q Data is often described as the lifeblood of modern healthcare, but health systems have historically struggled to unlock its value. Where are you seeing genuine breakthroughs, and what’s still holding the sector back?

The genuine breakthroughs are happening where organisations stop treating data as a technical asset and start treating it as a strategic asset for care, safety, planning and prevention.

We are seeing real progress in three areas. The first is the creation of more integrated views of the person, not perfect, but improving. Shared care records, regional data platforms and interoperability layers are beginning to give clinicians and care teams a more complete picture of someone’s needs. In our work with one client, for example, the digital enablement

Justine Ewing Vice President Health, Care and Life Sciences for UK & Australia at CGI

roadmap identified the need for a regional data fabric, a single view of a person, better flow of data between systems, and data and analytics as core foundations for integrated health and care.

The second breakthrough is operational insight. Data is increasingly being used to understand demand, patient flow, asset utilisation, workforce pressures and community capacity. That matters because the sector cannot simply keep adding more capacity into acute settings. We need to think about the link to public health more generally and see the whole system in near real time and act earlier.

The third is population health and prevention. We are beginning to connect data across primary care, community care, social care, public health and wider determinants of health. In the past this has been the poor cousin in transformation. Addressing it and making it a priority creates the potential to identify risk earlier and design interventions around people and communities rather than institutions.

But there are still big barriers. Legacy systems are one. Data quality is another. Governance can be fragmented, and organisations are rightly cautious about privacy, consent and public trust. There is also a cultural challenge: people will not use data they do not trust, and they will not trust data if they cannot understand its provenance, quality or purpose.

The answer is not to build one giant database fishing from one data lake. It is to create the conditions for safe, ethical, interoperable and purposeful data sharing. That means standards, information governance, cyber security, data quality, clear benefits, and absolute clarity about what problem we are trying to solve. Data is only valuable when it helps someone make a better decision or enables a better outcome.

q AI is generating enormous excitement across every sector, but healthcare carries unique risks around patient safety, bias and ethics. How should health systems be approaching AI adoption responsibly, and where is CGI helping clients navigate that? Health systems should approach AI with ambition, but not hype. I am excited about AI, but in healthcare we have to be very clear: the standard is different because the consequences are different. We are dealing with people’s lives, their rights, their data and their trust.

Responsible adoption starts with the problem, not the technology. What decision are we trying to improve? What harm are we trying to reduce? What administrative burden are we trying to remove? What clinical or operational outcome are we trying to support? If we cannot answer those questions, we are not ready to deploy AI.

The second principle is governance. AI in health needs clear clinical accountability, ethical review, bias testing, explainability, safety monitoring and ongoing assurance. It is not enough to test something once and declare it safe. Models drift, populations change, and healthcare environments are complex.

The third is transparency with the public and workforce. People need to know when AI is being used, what it is being used for, what it is not being used for, and who remains accountable.

At CGI, our role is often to help clients move from curiosity to controlled adoption. That means AI readiness assessments, data maturity work, cyber and privacy assurance, use case prioritisation, architecture, governance and delivery. Our own Health & Care 2035 strategy for the sector positions AI as part of a secure-by-design transformation agenda, not as a standalone technology play.

q As you look into the future, what does a digitally transformed, community-centred health and care system in the UK actually look like for an ordinary patient? And what’s the realistic path to getting there? For an ordinary patient, a digitally transformed, community-centred system should feel simpler, more joined up and more human.

It should mean I do not have to keep repeating my story. The people involved in my care can see the right information, with the right permissions, at the right time. I can access advice, appointments, results and care plans through channels that work for me. If I am living with a long-term condition, I can be supported at home with remote monitoring, selfmanagement tools and clear escalation routes. If my health starts to deteriorate, the system can spot that earlier and intervene before I reach crisis. A digitally transformed system is not one where everyone has more apps. It is one where technology removes friction.

The realistic path is incremental, not magical. We need to build the foundations first: cyber resilience, interoperability, data quality, digital identity, cloud, legacy modernisation and workforce confidence. Then we need to prioritise high-value pathways where the case for change is strongest for example in frailty, long-term conditions, discharge, urgent care, maternity, mental health, and prevention.

We also need demonstrators that prove what works. CGI’s 2035 Challenge frames this well: we think of places like West Wales as whole-system test beds, prove the blueprint, measure the benefits, and then scale what works rather than endlessly reinventing locally.

The future I want to see is not technology replacing human care. It is technology creating the capacity for more human care. Less duplication, less waiting, less fragmentation, more prevention, more dignity, more trust.

Why digital twins are becoming a strategic capability for the UK economy

Considering ongoing geopolitical uncertainty, supply chain challenges and the growing need to innovate, digital twins represent a strategic capability for the UK with immense value for UK industry.

Traditional operating models have long been reliant on static data and reactive decision making, leaving business leaders with a lack of insight and not enough resources at their disposal.

Digital twins offer dynamic, data-driven visual representations of real-world systems that enable the simulation, optimisation and prediction of operations in real-time. As such, they provide the foresight and insight necessary for business leaders to identify new opportunities, mitigate risk and meet demand which are essential in the context of unprecedented economic and commercial unpredictability.

At Digital Catapult, we deliver the UK Digital Twin Centre to accelerate the practical application of this type of deep tech

innovation across industry and recognise first-hand the growing importance of digital twin solutions and their role as a critical capability for the UK economy.

Strengthening supply chain resilience

The nature of modern industrial supply chains is inherently interconnected across geographies and sectors, meaning that disruption in one region or industry can quickly cascade elsewhere. For example, recent developments in the Middle East have exposed the vulnerabilities and interdependence of global supply chains, with the Strait of Hormuz transporting 20 million barrels of crude oil and oil products every day last year, and its effective closure causing wide-ranging impacts to global markets and sectors.

Digital twins enable businesses and governments to simulate potential disruptions, testing scenarios, situations and responses before events occur, informing planning and preparedness. This includes modelling supply shortages, logistics delays, equipment failures, or shipping obstructions, enabling businesses and governments to identify

Katrina Thompson, Director of the UK Digital Twin Centre

vulnerabilities and reduce risk. Digital twins can also encourage operational optimisation, allowing business leaders to monitor systems in real time, predict maintenance needs and improve resource efficiency during periods of increased demand, strengthening UK industrial supply chain resilience.

With real-time data continuously informing decisions across supply chains, digital twins are proving to be of immense value in empowering business leaders to understand the options available to them and where to optimise operations to maintain commercial success.

The broader economic opportunity

As well as the operational benefits of digital twins for the UK, digital twins also serve as a vehicle to mobilise economic growth more broadly. Digital twin solutions have the potential to deliver significant productivity gains for businesses across a variety of different industries, enabling more efficient use of assets, infrastructure, and resources. By simulating resource-use, businesses can access rich data that can inform leaders on where cost-cutting measures can be implemented or how energy can be optimised to cut costs.

Similarly, organisations can use digital twins for predictive maintenance, performance optimisation, or to deliver data-driven services, converging with other areas of deep tech innovation including artificial intelligence (AI), advanced connectivity and more.

By combining digital twin solutions with other areas of deep tech innovation, digital twins represent an opportunity to open new markets, develop new solutions and strengthen expertise that can be commercialised. As such, digital twins also represent a shift towards more data-driven industries, mobilising economic growth across key sectors including aerospace, defence, cybersecurity, maritime and more. A recent report for example, reported that

the digital twin market is set to grow by nearly $32 billion from 2021 to 2026, demonstrating the economic value of the deep tech innovation, particularly in the context of its convergence with other technologies. The impact on operational efficiency as well as its role in mobilising economic growth across other sectors further highlights the value of digital twin capabilities for the UK economy.

Delivering the UK Digital Twin Centre to drive growth

Digital twin capabilities will be critical to long-term economic growth in the UK. The capacity to model and simulate a range of scenarios will be critical to weathering economic storms, supply chain disruptions and mounting uncertainty, improving the UK’s industrial supply chain resilience, and boosting its credibility in the eyes of international investors and global PLC.

This is why Digital Catapult is harnessing the digital twin opportunity in collaboration with Shorts Brothers, Thales UK, and Artemis Technologies at the UK Digital Twin Centre, a £37.6million initiative funded by the Belfast Region City Deal and Innovate UK, to de-mystify digital twins and accelerate their application and adoption across industry. By convening capabilities between industry, startups and SMEs, and technological experts, real-world applications of digital twin solutions can be trialled and validated, developing new solutions that can be integrated into existing operational workflows.

The Centre is also proving the value of digital twins in supporting businesses to reduce the time it takes to develop and validate complex products and solutions. The prototyping process for new products or assets can be lengthy, often requiring long pilots, iterations, and adaptations to meet changing regulatory requirements. Digital twins enable businesses to prototype at pace, modelling and simulating adjustments

to new products and creating scenarios to ascertain success or the need for continued exploration and development. This is why Digital Catapult has also partnered with the Centre for Modelling and Simulation (CFMS), to convene CFMS’ modelling capabilities with Digital Catapult’s digital twin expertise, strengthening the prototyping process and mitigating risk.

On the Digital Twin accelerator programme for example, Voxshell has worked on a HydroTwin Aerospace project that aims to create an AIenabled digital twin platform to enable engineers to visualise real-time system behaviour, reducing prototyping costs. With supply chains stretched and under pressure to deliver products or new assets at pace, particularly in the context of aerospace, defence and security, digital twins are already proving to be a critical capability for the UK, becoming ever more important to unlocking economic growth in the years to come.

As economic growth remains a priority for government and industry alike, new capabilities that underpin market growth in the UK will be essential to unlocking new opportunities, opening markets and mitigating supply chain failures that could derail the country’s growth trajectory. This is why digital twins represent a key capability for the UK economy and will grow in importance as new digital solutions are applied to industry and equip the UK to be future ready. At Digital Catapult, we’re committed to accelerating the practical application of digital twins across industries and is why we continue to convene capabilities to make sure the UK capitalises on the digital twin opportunity and leverages the deep tech innovation as a vehicle for long-term economic growth.

Any reader interested in learning more about our digital twin activity can visit: digicatapult.org.uk/programmes/ programme/uk-digital-twin-centre

Q&A with Eddie Coghlan, Head of Development at TP ICAP & Belfast Technology Hub

q Can you give us an overview of TP ICAP's technology footprint in Belfast, and what makes it a strategically important location for the firm's engineering capability? Belfast is an important hub location for TP ICAP with technology as a cornerstone. Our technology footprint spans end-to-end delivery: from core application development and platform engineering through to cloud, data, regulatory reporting, and the supporting operational processes and tooling necessary to build and run systems within our production environment.

Teams in Belfast work on critical systems that support front office trading globally, alongside post-trade processing and fulfilling regulatory obligations across multiple business units, asset classes, and technology platforms. Belfast forms a key part of the company’s transformation goals to modernise critical trading platforms towards cloud-native architectures working in collaboration with AWS and aligned with the firm’s

broader cloud and AI goals.

What makes Belfast strategically important is the combination of scale, capability, and maturity. 2026 is TP ICAP’s 10-year anniversary in Belfast and across this period we’ve built a deep pool of experienced technologists who don’t just execute requirements but actively design, modernise, and evolve our technology platforms. Belfast is a place where we build products, not just support them.

The location also gives us access to a strong and growing local talent market, supported by close links with both local universities and the wider tech ecosystem. We are actively investing in long-term capability, developing future leaders, and maintaining continuity in critical engineering areas. TP ICAP Belfast is a highly resilient, cost-effective, and innovative engineering base playing a central role in how we scale technology, manage risk, and deliver change globally.

q What does "bespoke" software development mean in practice at TP ICAP and what are the key benefits of building technical infrastructure in house as opposed to adopting an existing vendor solution?

At TP ICAP, bespoke software development means, rather than adapting our business to fit the constraints of an off-the-shelf product, we build platforms and infrastructure that are deliberately designed around our needs and the specific markets, workflows, and regulatory obligations we operate within.

Our engineers work closely with the business to design systems that reflect the real complexity of interdealer broking and electronic markets: the trade lifecycles, the asset-class nuances, the non-functional and latency characteristics, alongside the complex regulatory reporting demands. Our requirements are unique and evolve constantly as markets, regulations, and client expectations change. When this happens, we need to respond quickly; owning our platforms allows us to move at our own pace rather than waiting for vendor roadmaps or release cycles.

Being bespoke doesn’t mean reinventing everything from scratch. We deliberately build on commoditised components where it makes sense: cloud infrastructure, managed services, standard protocols etc however the control logic, data models, integrations, and proprietary workflows and domain expertise that differentiate TP ICAP are developed and owned in-house. That gives us end-to-end ownership, from design through build, operate, and run, allowing us to constantly evolve when necessary.

q What are the core engineering principles that guide how your development teams build and maintain proprietary platforms?

At TP ICAP, our engineering principles are designed to balance innovation with the realities of operating at scale in a

highly regulated, always-on market environment. Stability, resiliency and scalability are key tenets that underpin our technology estate and form the basis of everything we build.

Our teams own their platforms end-to-end and are accountable for designing, building, operating and evolving the platform over time. This ownership mindset drives higher-quality engineering, more resilient operations, and faster issue resolution. Observability, telemetry, security, and the ability to effectively support platforms in production are critical to delivering change frequently and safely, with the ability to recover quickly when things go wrong. These capabilities are fundamental to resilience and operational control.

We value strong fundamentals: clean code, test automation, clear architectural standards etc but we also emphasise collaboration and continuous learning. Our goal is to build scalable and resilient systems that work reliably for the business every day.

q How does AI fit into the Software Development Lifecycle (SDLC) at TP ICAP?

When we talk about AI at TP ICAP, we’re very deliberate about positioning it as an enabler of the SDLC, not something that sits outside it or bypasses existing controls. AI fits into the SDLC in the same structured, governed way as any other technology, with additional guardrails where justified.

From a requirements and design perspective, AI helps teams explore options more quickly by refining requirements, identifying edge cases, and validating architectural patterns, for example. However, engineers and architects remain accountable for design decisions, and our development standards require that designs explicitly address security, resilience,

and compliance before delivery can begin, regardless of whether AI tooling was involved.

During development, AI assists productivity with code generation, refactoring, documentation, or test creation all benefitting from the tools. This generation accelerates delivery and improves consistency with the output treated the same as humanwritten code. It goes through peer review, automated testing, and security scanning as part of our CI/CD pipelines like code by any other author. Our SDLC explicitly mandates checks including security controls, static code analysis and risk-based testing, which apply equally to all code including AI-assisted code.

AI doesn’t redefine our SDLC, it strengthens it when used correctly. AI simply helps teams move faster and make better-informed decisions within that framework, rather than cutting across it. This approach allows us to adopt AI safely and pragmatically while remaining fully aligned with the regulatory, security, and resilience expectations of a financial services environment.

q As Cyber criminals become more resourceful in the age of AI, How do you characterise the current threat landscape facing FinTech organisations and has the nature of attacks changed significantly in recent years?

The threat landscape facing FinTech organisations has become both more sophisticated and more industrialised over the last few years with AI accelerating that trend rather than fundamentally changing the game overnight.

At a high level, we still see the same core objectives from attackers: data theft, disruption, financial gain but the tools and techniques have evolved significantly. AI is enabling cyber criminals to automate reconnaissance,

scale attacks more efficiently, and make social engineering far more convincing than it was even a few years ago. Focusing on Phishing and social engineering, AI can generate realistic, well-targeted messages at scale, which increases the likelihood of initial compromise. This means the human layer of defence (awareness, controls, and culture) is just as important as technical safeguards, if not more so.

Attackers increasingly look for the weakest link rather than attacking core systems head-on. In a complex, interconnected technology estate, that makes visibility, monitoring, and strong vendor governance critical. Has the nature of attacks changed? Yes, as has the speed, scale, and adaptability of attackers. However, the fundamentals of good cyber defence haven’t changed. Strong identity controls, least-privilege access, patching, segregation, monitoring, and incident response remain essential and must be implemented far more rigorously and consistently than in the past.

At TP ICAP, our approach is therefore defence-in-depth and risk-based. We assume breach, we build layered controls, and we treat cyber security as a continuous discipline rather than a compliance exercise. The organisations that succeed will be those that combine strong technology controls with clear governance, skilled people, and a culture that takes cyber risk seriously.

q What was the strategic rationale for adopting AWS as your primary cloud provider and can you summarise the benefits of cloud versus on-prem?

Our move to AWS was a deliberate strategic decision rather than a purely technical one. It was underpinned by our need to support scale, resilience, and speed in a business where technology is fundamental to how we operate and compete. AWS were also keen to collaborate to help us progress our technology platforms in our

modernisation journey.

We operate globally, across multiple asset classes and time zones, with very high availability requirements. Cloud infrastructure allows us to scale capacity up and down dynamically and to design for resilience across regions. That level of elasticity and built-in redundancy is extremely difficult and costly to achieve consistently in a traditional on-prem environment. Speed to market is also a critical tenet of Cloud. Infrastructure provisioning that used to take weeks or months can now be done in minutes through automation shortening feedback loops, enabling more experimentation, and encouraging small, incremental changes rather than large, high-risk releases.

This is critical when responding to regulatory change, market evolution, or client needs. All this with the backdrop of security, tooling, monitoring, and controls that would be hard for most firms to replicate internally at the same depth.

To be clear, cloud doesn’t remove the need for good engineering discipline. It raises the bar. You still need strong architecture, security standards, automation, and operational ownership. But when combined with those principles, cloud becomes a genuine force multiplier, enabling TP ICAP to modernise faster, scale safely, and focus more of our engineering effort on building differentiated capabilities rather than running infrastructure.

q How do you attract and retain top engineering talent in Belfast in an increasingly competitive market? Belfast has a very competitive technology landscape so attracting and retaining great engineers requires much more than just offering interesting roles. To be successful you have to provide meaningful work, long-term career growth, and an environment people genuinely want to be part of.

First, the work itself matters. Engineers at TP ICAP work on real, complex problems that sit at the heart of global financial markets, building and modernising missioncritical platforms, operating at scale, and working in a highly regulated environment where quality and resilience genuinely count. That sense of purpose and impact is a big draw for experienced engineers who want their work to matter.

Second, we invest heavily in people and career development. We’re very deliberate about building depth of capability in Belfast, not just headcount. That means structured learning, exposure to modern technologies like cloud and AI, opportunities to work across different domains, and clear progression paths into senior technical or leadership roles. Our message to engineers is simple: your growth is our future.

Third, culture is key. We operate with a high degree of trust and autonomy, supported by modern engineering practices and flexible working models. Teams are empowered to make decisions, take ownership of their platforms, and balance delivery with sustainability. That flexibility is increasingly important, particularly as expectations around work-life balance have evolved.

We also benefit from Belfast’s wider ecosystem: strong universities, a growing tech community, and close collaboration with industry partners. That allows us to bring in early-career talent, support them as they develop, and retain institutional knowledge over time. Taken together, our approach is about building a sustainable engineering community in Belfast, not just hiring for today’s needs. By investing in people, trusting teams, and giving engineers meaningful problems to solve, we’ve been able to attract and retain strong talent in a market where competition continues to intensify.

Lewis Silkin's research reveals NI employers know AI matters, but are struggling to deploy it

AI is already directly impacting how organisations operate, hire, and manage people. Northern Ireland has strengths in software development, FinTech, and advanced manufacturing, but Lewis Silkin’s research suggests employers here still do not properly understand how to use AI in their businesses.

Our Future @ Work 2026 report analysed insights from over 660 business leaders globally, whilst our joint survey with MCS Group gathered responses from 66 NI business leaders. Together, these datasets suggest there may be gaps in local understanding and readiness.

Both surveys rank efficiency as the key opportunity presented by AI. In the NI survey, 86.4% cited ‘increased efficiency and productivity’ as the key benefit - far ahead of any other. Globally, respondents had a broader appreciation, with 21% highlighting new revenue streams as a key win, compared to only 6% of NI respondents. This suggests NI employers may not yet fully understand AI’s wider capacities.

The top challenge NI employers said they were facing related to identifying use cases for AI within

their business. Amongst the global respondents, this issue ranked 7th on the list of key concerns. It is clear that NI employers know AI can help their business, but they seem to be struggling to work out exactly how it can help, and so are less able to make the business case for investment.

The focus on efficiencies from the NI cohort could well be linked to a perceived gap in AI literacy at a strategic level. A higher percentage of NI respondents were concerned about limited leadership knowledge than in the global survey. Whilst the evidence suggests leaders are excited about the opportunities presented by AI, it seems a lack of understanding at board level

about how the technology can be applied in practical ways may be holding them back. Both surveys were aligned in identifying a shortage of AI literacy across the board as their biggest readiness gap.

In terms of how AI is likely to impact workforces in the next twelve months, the survey results agree it is likely to transform roles rather than eliminate them. Neither set of respondents imagine a binary ‘AI replaces jobs’ scenario - rather, jobs are going to change and employers will need staff who are willing and able to reskill to embrace the changes.

Slightly more NI respondents expected AI to reduce or

transform entry-level pathways, than the global figure of 20%. Given the demographic profile of the region and its falling birthrate, fewer entry-level roles today could well pave the way for talent shortages at a more senior level in the future. The challenge will be to leverage the benefits of new technology whilst enabling staff to develop the other skills and experience AI cannot replace (such as leadership, empathy and commercial judgement).

Whilst employers know they need to invest in staff training and AI literacy, both surveys suggest that investment is likely to lean towards technology rather than people in the next twelve months. A comparison of the two surveys suggests that this investment focus may be slightly less unbalanced in NI, with 43.2% saying they were leaning toward a technology spend, compared to roughly 74% of global respondents.

Overall, the NI survey results suggest that NI employers share the same hopes and concerns as their global counterparts. However, they still appear to be working out exactly how to use AI in their businesses, whereas globally, the focus has moved beyond identifying use cases to more strategic integration and implementation.

Emma Grossmith, Managing Associate at Lewis Silkin

Sync NI hosted a roundtable of leading cybersecurity professionals from across Northern Ireland to discuss the evolving threat landscape, the enduring challenges of skills and investment, and what the region needs to do to protect and grow its cyber sector.

The pace of change in cybersecurity has always been relentless. But according to a group of senior professionals who gathered for a frank roundtable discussion hosted in Rapid7’s Belfast offices, something has shifted.

The threats are faster, smarter, and more deceptive than ever before. The tools available to attackers have democratised in ways that would have seemed implausible even five years ago. And while Northern Ireland's cyber community is widely regarded as one of the most collaborative and capable in the UK, significant structural challenges remain from boardroom blind spots to a skills pipeline that needs to adapt to ensure it remains fit for purpose in a rapid-evolving threat landscape.

The panel brought together voices from across the ecosystem: Chaired by Rapid7’s Thom Langford, CTO EMEA and joined by Ned Faulkner, AI Security Engineer at Version One; Jason Donnan, Security Manager at Apex Fintech Solutions Joanne English, Cluster Manager for NI Cyber; Ben Harrison, founder Loquerion Security and Colin Metcalfe, Cyber Defence Operations Manager at TP ICAP. The conversation ranged across AI-driven threats, nation-state activity, the limitations of threat intelligence, and the urgent need

Northern Ireland's Assessing the risks,

to rethink how the industry attracts and retains talent.

We are often told that we currently exist in a new threat landscape however while this might appear to be true, fundamentally it’s the same playbook, just it is now playing out at a terrifying new speed fuelled by advancements in technology. As a statement, this is a good place to start a conversation with industry experts who work at the coalface of Cyber Security and get a sense of the issues addressing the sector.

There was broad consensus that the fundamentals of cyber-attack and defence haven't changed however their velocity and sophistication absolutely have. "History doesn't repeat itself,

it rhymes," observed Version 1’s Ned Faulkner. "We're seeing that exactly with how AI is being used for things like deepfakes and supply chain attacks. These aren't unfamiliar attacks. What has changed is the speed and complexity."

The days of spotting a phishing email by its broken English and obvious spelling mistakes are over. Modern AIgenerated communications are fluent, contextually accurate, and increasingly indistinguishable from the genuine article. Voice cloning, the panel noted, now requires as little as three to five seconds of audio that can be easily harvested from a LinkedIn video or corporate marketing content to produce a convincing imitation of a senior executive. The implications for social

Ireland's Cyber Frontline: risks, threats and opportunities

engineering attacks are significant.

Loquerion’s Ben Harrison drew on an analogy that resonated throughout the discussion: "Humans invented scissors. It was a good day all around. Shortly thereafter, someone started running with them." The dual-use nature of almost every powerful cyber tool means that defensive and offensive capabilities advance in lockstep. Blocking one attack vector simply redirects adversaries to the next.

What has genuinely changed, the group agreed, is the speed of exploitation. Where previously a zero-day vulnerability might sit dormant for weeks or months between discovery and active exploitation, that window has now collapsed to days, sometimes

hours. Attackers, increasingly operating with automated pipelines and near-zero marginal cost per attack, can afford to throw everything at every target. "99-plus percent of attacks don't get through the initial phase," observed Ben Harrison, "but they're all automated, so the cost is so low that you may as well throw everything at the wall."

If there was a sweepstake for how long it would take for Mythos to enter the conversation… it was hardly surprising it was mentioned shortly after the introductions were barely complete. When raising the question of AI being utilised as an offensive weapon, the conversation inevitably turned to Anthropic's recently disclosed 'Mythos', an AI model that, in controlled testing, was reportedly capable of identifying

and chaining exploits autonomously, including the detection of a 27-year-old unpatched vulnerability in an opensource system. Anthropic has chosen to keep the model closed-source, citing the risks of public release.

"The key thing this has spotlighted," said Ned Faulkner, "is how AI can be used both offensively and defensively." The panel was careful not to overstate the threat as for the moment there remains genuine debate about how much of the Mythos narrative is security research and how much is marketing but the directional implications are serious. If AI systems can reliably chain exploits and identify vulnerabilities at a scale and speed no human team can match, the already-stretched patching cycles faced by most organisations become

(L-R) Ben Harrison, founder Loquerion Security; Ned Faulkner, AI Security Engineer at Version One; Colin Metcalfe, Cyber Defence Operations Manager at TP ICAP; Jason Donnan, Security Manager at Apex Fintech Solutions; Thom Langford, CTO EMEA Rapid7 and Joanne English, Cluster Manager for NI Cyber

effectively untenable.

Apex Fintech Solutions, Jason Donnan, drawing on his background in health service cybersecurity before moving to FinTech, put the challenge bluntly: "Nobody can keep up with patching cycles as things currently are. If they start throwing out critical vulnerabilities at a really high rate, we're in serious difficulty."

Debate moved somewhat predictably to the subject of ‘Boards, Budgets, and the Language Problem’

Perhaps the most animated part of the discussion centred on a problem that has dogged the cybersecurity industry for years: the chronic failure to translate technical risk into language that resonates in the boardroom. Several panellists noted that despite years of effort to elevate cyber to board-level status, the result has often been slower procurement cycles rather than faster responses.

"By the time a request for new tooling gets to board level and gets agreement, the world has changed so rapidly that everything being discussed is already obsolete," noted NI Cyber’s Jo English, reflecting feedback from member companies in her organisation. This was further mirrored by TP ICAP’s Colin Metcalfe who added the observation that the organisations most likely to act are often those responding to a recent incident, or a change of CISO,

rather than proactively planning ahead.

Ben Harrison argued that the fundamental problem is one of category: cybersecurity is being treated like a project, when it’s actually an ongoing adversarial relationship with no fixed endpoint. "You can't win cybersecurity by defining a three-year strategy, setting the budget, executing, and declaring it finished. The adversary reacts to everything you do. It is war, not in terms of explosions and shooting, but it is a war."

The panel's recommended approach was to reframe the conversation entirely, away from fear, uncertainty, and doubt, and towards risk-adjusted return on investment. "Rank your risks by return on investment to address them," suggested Ben Harrison. "Start with impact and likelihood, then consider the cost to reduce that risk to a point where you can sleep at night, and then just start spending down that list until you're comfortable. That language lands in boardrooms, because risk and price are things boards understand."

Equally important, the group argued, is improving the industry's ability to demonstrate the value of what it does, something cybersecurity has historically been poor at. "How do you prove a negative?" acknowledged Rapid 7’s Thom Langford. "How

do you prove something didn't happen because you did something?" It remains one of the sector's most persistent unsolved problems.

The conservation moved on to address the impact of nation States, blurred lines, and the limits of threat intelligence

The discussion also addressed the growing convergence of nationstate actors, criminal groups, and hacktivists, a trend that is fundamentally complicating defensive planning. The model is increasingly one of statesponsored outsourcing: sovereign cyber operations providing cover, resources, or simply looking the other way while affiliated criminal groups conduct attacks against designated targets.

"China hacks for data, North Korea hacks for money, and Russia hacks for mischief," as one widely cited formulation has it. The problem, as Colin Metcalfe noted, is that when you combine that three-way motivation with increasingly sophisticated tooling and a broad community of independently motivated bad actors, the attack surface becomes almost impossible to map reliably.

This matters particularly for how organisations consume threat intelligence. Jason Donnan highlighted the risk of treating intelligence feeds, even from high-fidelity

sources such as FS-ISAC (FS-ISAC is a not-for-profit organization that advances cybersecurity and resilience for the global financial system representing over 5000 organisations globally) as definitive or complete. "Threat intelligence must be tailored to your industry, business and assets to provide true benefit," he said. "If not, it can lead to false positives and waste analysts time investigating due to the quantity of intelligence feeds available." The group cautioned against singlesource dependency and urged organisations to apply contextual judgement rather than treating any intelligence report as a final word.

On the supply chain front, Jason Donnan pointed to a rapidly escalating problem: vendor proliferation. “This expands the attack surface and introduces risks that you do not fully control”. It has been highlighted by the number of recent third-party breaches and is concerning due to the impact. “A compromised vendor can become an indirect route into your environment, even if you have strong defences in place”.

One question that was offered to the floor was whether are we currently suffering from a skills gap or rather, or was the attitude gap being overlooked?

If boardroom engagement was the session's most animated topic, the skills conversation was arguably its most hopeful. The panel pushed back sharply against

the conventional narrative of a widening skills gap driven by supply failing to meet demand. The real problem, several argued, is that the industry continues to hire badly.

"We have an attitude gap, not a skills gap," challenged Thom Langford, playing devils advocate in his role as chair. "We just seem to expect that we can only ever hire round pegs to fit round holes." The panel offered vivid counterexamples. Colin Metcalfe described hiring a 17-year-old with no A-levels who became one of the best cyber analysts he had ever worked with.

Jason Donnan noted that one of the most effective members of his security operations team came from a background in design and architecture, bringing entirely fresh perspectives to threat analysis. "If people have the same background, they all come up with the same conclusion," he observed. "Having people from different backgrounds is genuinely fascinating as well as operationally beneficial."

Ben Harrison was characteristically direct about what the industry should be looking for: "You can't teach passion. If you put a puzzle in the middle of the interview room, the person you want is the one whose eyes light up the moment they see it." He was equally critical of some educational pathways that have prioritised tool familiarity over genuine

problem-solving instinct. "They didn't teach them to be cybersecurity professionals. They taught them to use the tools from ten years ago."

The group also stressed that cyber careers extend well beyond the technical. Governance, policy, risk management, audit, and business continuity roles are all vital and yet these careers are chronically under-promoted in schools and universities. One example stood out: a head of cyber audit hired for their degree in human psychology, who turned out to be an exceptional interviewer of technical staff precisely because they asked questions no one else had thought to ask.

Retention, too, came under scrutiny. Colin Metcalfe highlighted the unsustainable pressure placed on analysts where burnout within 18 to 24 months is common hence the need to build genuine flexibility and training investment into working models. "The time for certification should be within your working week, not tagged on to the other 38 hours," he said. Pay-back clauses tied to certification costs were singled out as a particular barrier, especially for talented staff in lowerwage markets.

So what comes next, as the threat landscape evolves how does insider threats, autonomous systems and the human question factor into all of this?

Looking ahead, the panel identified several emerging threats that warrant serious attention. The rise of the human insider threat, not in the traditional sense of a disgruntled employee, but in the form of statesponsored actors infiltrating companies through remote hiring processes. This was flagged as a growing and underappreciated risk. The widespread shift to remote and hybrid working has made this significantly easier to execute, and deepfake technology means that even sustained video-call contact may not reliably verify identity.

AI-driven propaganda and influence operations were also raised as a significant near-term concern and the systematic use of social media to manipulate public opinion across borders, at a scale and sophistication that will only grow. "We need some kind of global governance and crossborder agreement on standards for verifying whether content is humangenerated," said Ned Faulkner. "That is going to be a major topic."

Further out, Ben Harrison drew attention to the concept of fully autonomous companies, organisations with no human employees, operating entirely through AI and robotics as a genuinely novel attack surface. "Human out of the loop will be getting bigger," he said. On quantum technologies, the panel was measured: significant, yes, but the killer application remains unclear

and the timeline uncertain.

Perhaps most strikingly, Ben Harrison referenced some companies, including a local council department that had begun reverting to pen and paper after concluding it could no longer trust its digital security posture. Thom Langford was not alone in his assertion "In the long term, that means they'll just get wiped out by larger organisations using technology effectively. There is a real risk of that if we don't keep up."

Throughout the conversation, a thread of genuine pride in Northern Ireland's cyber community was evident. The region's ecosystem, anchored by NI Cyber, a cluster that brings together academia, industry, and government was consistently cited as a rare strength: a community in which professionals from competing companies share intelligence, collaborate informally, and actively support one another across institutional boundaries.

That community capital is real, and it is valuable, but it will not be enough on its own. The panel's message, taken as a whole, was one of urgency tempered by optimism: the threats are serious and accelerating, the structural challenges in investment, hiring, and board-level engagement are persistent, but the talent, the culture, and the collaborative infrastructure to address them are already here.

Q&A with Thom Langford, EMEA CTO at Rapid7

q AI systems are being deployed rapidly across security operations. What does the attack surface of an agentic AI system actually look like, and how fundamentally different is it from securing a conventional software application?

Agentic AI expands the attack surface beyond anything we see in conventional software. Traditional software integrations are deterministic, with data flows that can be easily mapped and controlled with the right approach. Agentic AI is a totally different beast that creates its own connections and routes, making it difficult to predict or audit how information moves.

That unpredictability grows when agents start talking to one another and forming new connections between different systems. Multiple autonomous systems acting together can create very real unintended outcomes.

As we discussed in the recent SyncNI roundtable I chaired, attackers can automate, speed up, and scale up their operations. In that environment, an AI agent becomes less like a traditional application and more like a semi-autonomous operator inside the environment.

q Prompt injection attacks against AI agents are increasingly documented in research but rarely discussed in operational security circles. How seriously should defenders be taking this as a real-world threat right now, rather than a theoretical one? Prompt injection should absolutely be taken as a real-world

threat. We tend to discuss prompt injection in a research context, pointing to the extreme cases where some very clever university researchers got an AI agent or LLM to do something wild.

However, as Ned Faulkner highlighted in the roundtable, prompt injection should be treated as an operational reality. AI-generated content is now fluent and context-aware, removing traditional cues that defenders once relied on.

Combined with the collapse in exploitation timelines, this creates a serious situation where malicious instructions embedded in data sources can directly influence system behaviour. Automation also makes exploitation cheap, and prompt injection becomes just another scalable controlchannel attack.

Basically, if an AI agent can take action based on retrieved or contextual input, then prompt injection is already a live attack vector.

q If an AI agent is given access to sensitive systems and the ability to take autonomous actions, the consequences of it being manipulated or misbehaving are potentially catastrophic. What does "least privilege" mean in the context of an agentic AI, and are organisations thinking about this carefully enough? Least privilege in an agentic AI context means quite simply limiting what systems an AI can interact with, restricting what

Thom Langford, EMEA CTO at Rapid7

actions it can execute autonomously, and ensuring separation between decision-making and execution.

However, as raised by Joanne English from NI Cyber, the slow pace of board level decision making compared to the pace of change means many organisations are not yet structurally ready to even consider this

This is where strong observability tools come into play. Organisations need to have visibility to make sure they know how and where AI is being used, from sanctioned enterprise tools to ad-hoc experiments.

Monitoring data flows helps identify unapproved applications and contain agents before they spread. You need visibility into what’s actually happening, so you can start restricting unnecessary access and enforcing least privilege from the get go.

q There is a version of this future where AI security tools are so opaque that defenders can't audit what decisions were made or why. How do you think about explainability and auditability as security requirements in their own right, rather than just compliance concerns?

Explainability and auditability should be treated as core security requirements.

When an AI system takes an action, organisations need to be able to reconstruct what and why it happened. Without that visibility, it becomes extremely difficult to investigate incidents or detect manipulation.

In the roundtable, Colin Metcalfe at TP ICAP emphasised the importance of visibility across increasingly complex environments, and that concern extends directly into AI systems that operate autonomously. This is particularly important as systems become more autonomous and decision making becomes less transparent. It

is also just one way to ensure there is always a Human In The loop of any critical AI decision making.

When it comes to securing agentic AI, there are three key pillars of governance, observability, and oversight. I’ve already mentioned the importance of observability, but together, they’re the safeguards for operational trust in AI systems.

Governance sets the rules and access, observability shows what’s actually happening, and oversight is the human control keeping AI in check.

q Looking at the next 18 to 24 months specifically, what is the one development in the agentic AI space that you think the security industry is most dangerously underprepared for?

The most underprepared risk is the emergence of interconnected agentic systems operating across enterprise environments without continuous human oversight.

AI agents are extremely capable of delegating tasks, making decisions, and executing actions across multiple platforms. The concern is the potential for compromised decisions at scale across interconnected agents.

This creates a new class of attack surface where exploitation is spread across multiple autonomous components, amplifying impact and reducing response time.

A human should always be in the loop to ensure guardrails are actually in place and being followed, and that technology is running with both context and accountability.

Training is a key factor here too. It should focus on how employees interact with AI tools, challenge them, and apply their output responsibly. Employees should understand when to trust a model’s output, when to

question it, and when to step in.

q There is a documented shortage of Cyber professionals, how does Rapid7 address the skills gap and through continual learning ensure it remains at the cutting edge of Cyber defence?

The challenge is less about a simple shortage of talent and more about how organisations identify and develop the right skills.

At Rapid7, this is strongly anchored in Belfast, where the company has built an AI Centre of Excellence focused on applying data science and machine learning to real-world security problems. This acts as a hub for ongoing innovation and practical skills development.

There is also increasing understanding that effective security teams are not built solely from traditional career paths. Instead, diverse backgrounds, cultures and ways of thinking will always produce stronger operational outcomes than narrow technical specialisation alone.

The focus therefore shifts toward hiring for attitude, curiosity, adaptability, and problem-solving ability, rather than just predefined skillsets. Continuous learning is also critical, as the threat landscape evolves faster than static training or certification based models can keep up with.

Rapid7’s internship programmes in Belfast bring emerging talent directly into engineering and security teams, providing hands-on experience in live environments rather than isolated training.

Overall, the approach combines academia, applied research, and earlycareer development alongside a totally open mind to build adaptable security professionals who can evolve alongside an increasingly AI-driven threat landscape.

Identity at risk: Why Cyber Security in Northern Ireland must rethink what it protects

Cyber security has long been built on assumptions about trust, verification and who or what is allowed to act inside a system. According to Jason Donnan, Security Manager at Apex Fintech Solutions, many of those assumptions are no longer safe.

Drawing on experience across both the health service and FinTech sectors where cyber failure can have consequences far beyond financial loss Jason believes some of today’s most serious risks remain absent from mainstream risk registers. Not because they are obscure, but because they challenge long-standing mental models of security itself.

At the centre of that shift sits a deceptively simple concept: identity.

Most organisations still frame identity risk narrowly, focusing on credential theft, weak multi-factor authentication or privileged access abuse. While these remain real and prevalent threats, Jason argues they represent only the visible surface of a far deeper problem. “The more fundamental issue is that identity itself, our ability to reliably establish who or what is acting in a system, is becoming unreliable,” he says. This breakdown is happening on multiple fronts simultaneously. At the human layer, deepfake audio and video have moved rapidly from theoretical concern to practical fraud vector. Voice calls and visual confirmation, once treated as inherently trustworthy, can now be convincingly replicated at scale and low cost.

“Our training and verification instincts were built in a world

where hearing someone’s voice carried evidential weight,” Jason notes. “That assumption is now exploitable, and most organisational controls haven’t adapted.” Beyond human users, the non-human layer presents an even larger and more poorly governed attack surface. Modern systems rely on service accounts, API keys, OAuth tokens and automation credentials often numbering many times more than human identities, yet subject to far less scrutiny. “It’s a vast, poorly mapped exposure,” he says. “And it’s only growing.”

Agentic AI threatens to amplify the problem further. As organisations deploy AI systems capable of taking autonomous actions, they create an entirely new class of identity, one that most governance frameworks do not recognise at all. Few organisations, Jason argues, have asked basic questions: what can an AI agent not do? Who is accountable if it behaves unexpectedly? How would compromise even be detected? The deeper concern lies in how these issues are framed. Identity and access management, fraud, AI governance and third-party risk are typically treated as separate disciplines. In practice, they are converging on the same structural vulnerability.

“Identity has always been the load-bearing wall of access control,” Jason says. “Right now, it’s becoming unreliable across every layer of the stack at the same time.” Until this is treated as a unified, systemic risk, it will remain underappreciated.

FinTech operates under some of the most demanding regulatory and operational resilience frameworks of any sector. Jason is clear that this has real value. Regulation has

Jason Donnan, Security Manager at Apex Fintech Solutions

raised the minimum standard across the industry, forcing organisations to take resilience, incident response and third-party risk seriously.

However, regulatory maturity can also create false confidence. “Regulation is necessarily retrospective,” he says. “It codifies risks we’ve already understood well enough to legislate.” Many of the most dangerous AIrelated failure modes do not fit neatly into current frameworks. Model drift under adversarial pressure, emergent behaviour in multi-agent systems, and the illusion of control created by documented-but-ineffective safeguards all sit largely outside regulatory scope. The risk, Jason warns, is that compliance activity replaces genuine threat modelling. AI risk assessments become documentation exercises because regulators have not yet asked hard questions, precisely the gap adversaries are most likely to exploit.

Several blind spots are particularly concerning. There is no adequate regulatory model for non-human identity or autonomous agent behaviour within regulated processes. AI supply-chain risk is significantly under-addressed, with third-party models and services operating inside regulated perimeters but outside meaningful organisational control. And the pace of AI development means the gap between regulation and reality is widening, not closing. “Treat regulation as the floor, not the ceiling,” Jason advises. Boards should be briefed not only on compliance status, but on frontier risks that regulation has yet to reach. “Mistaking compliance for security has always been dangerous,” he says. “In the context of AI, it could be catastrophic.”

Another long-standing assumption under pressure is patching as a primary defensive strategy. As AIenabled systems begin discovering and chaining vulnerabilities faster than

human teams can respond, “keeping up with patching” alone is no longer viable. “We need to re-orient toward reducing exploitability, not just reducing exposure,” Jason explains. That shift begins with aggressive attack-surface reduction. Systems that do not need to be externally reachable should not be exposed. Remediation SLAs for internet-facing assets must tighten, while patching should be automated where technologies are stable and risk is low.

Equally important is prioritisation. Moving away from generic severity scores toward exploit-based assessment allows teams to focus effort where it matters. Organisations also need more flexible change windows that reflect the reality of accelerating vulnerability cycles. The end goal is a move from reactive vulnerability management to proactive exposure management, a mindset change that many organisations have yet to make. AI-driven financial fraud is already scaling in ways that challenge traditional detection models. Attackers benefit from asymmetric economics: they can afford repeated failures so long as a single attempt succeeds.

While both attackers and defenders increasingly use similar AI tools, Jason highlights one important defensive advantage, contextual depth. “External systems have to infer behaviour,” he says. “Internal systems know what ‘normal’ actually looks like.” By training AI models on genuine customer behaviour, transaction patterns and historical anomalies, organisations can detect when interactions appear constructed rather than organic. This requires a shift from pattern detection toward reasoning detection. Technical measures alone will not be enough. Adversarial testing, sound verification architecture and effective collaboration across institutions are essential.

“Threat actors share intelligence exceptionally well,” Jason notes.

“Defenders need to do the same.” Industry forums and informationsharing bodies such as FS-ISAC provide mechanisms for collective defence but remain underutilised. For Northern Ireland’s tightly connected financial and technology sectors, better collaboration could become a genuine strategic advantage. For midsized FinTech firms without the scale or resources of larger institutions, Jason’s advice is uncompromisingly practical: map your assets and data first. “You can’t protect what you don’t know.”

While most organisations have a reasonable grasp of human identity management, very few have equivalent visibility over non-human identities, service accounts, APIs, automated workflows and AI agents. That mapping exercise quickly exposes the most significant control gaps. From there, measures such as attacksurface reduction, data classification and third- and fourth-party risk monitoring become far more effective.

Despite the escalating threat landscape, Jason remains optimistic about the cyber security sector in Northern Ireland.

At Apex Fintech Solutions, significant investment is made in upskilling across engineering teams, including graduate security roles. While technical foundations are expected, they are rarely the deciding factor. Curiosity, structured problem-solving, calm judgement under pressure and a genuine commitment to continuous learning consistently outweigh specific tools or certifications. Candidates who ask questions, challenge assumptions and share knowledge thrive in a field where change is constant.

The future of cyber security, Jason makes clear, will not be defined by technology alone. It will be shaped by how people and organisations think about risk, trust and responsibility.

Yesterday’s defences, today’s attacker

The cybersecurity stack most organisations operate today was sized for a slower opponent. That opponent has been replaced. The question for technology leaders is whether their cadence has changed with it.

Most of the security stack operating in enterprises today was designed around yesterday’s problem. Strategies signed off last year, tooling acquired the year before, playbooks honed over a decade: all of it assumes a human attacker working human hours, opposed by a human analyst clicking through a human queue. That picture held up for a long time. Most investment, most org charts and most governance cycles still rest on it. Somewhere between the spring of 2025 and the disclosure of the Mythos model the following year, however, the picture became one of several worth defending against, and arguably the least urgent of them.

The shift is best understood through three properties that the frontier AI labs have now put their names to in writing. Artificial intelligence has become faster than the controls built to constrain it, more competent than most of the attackers organisations have priced into their threat models, and more

widely available than any offensive capability in the history of the profession. Faster, more competent, more widely available. Each word carries an obligation. Together they describe a different threat environment.

Take speed first. In February 2026, Sysdig’s Threat Research Team published a forensic account of an AI-assisted cloud intrusion in which an attacker moved from initial access to AWS administrative privileges in under ten minutes, traversing nineteen distinct identity principals on the way. Sergej Epp’s “Zero Day Clock”, once measured in weeks, now reads in hours. Patch processes that run on a daily review cycle, and security operations centres changing configurations weekly, sit outside the relevant window. By the time the ticket reaches triage, the attacker has finished and left.

Take competence next. Rob Joyce, former director of the United States National Security Agency’s Cybersecurity Directorate, used the keynote stage at last year’s RSA Conference to advise defenders against worrying about AI exploit developers. Twelve months on, he returned to the same stage to say he had changed his mind. The April 2025 Hack The Box capture-the-flag contest tells the same story:

Matt Holland, Director of Cyber & AI Security at Kainos

the leading AI team captured nineteen of twenty flags and finished twentieth out of 403 entries, ahead of 383 human teams. Forget the comfortable narrative about a script kiddie armed with a chatbot. What the frontier models now deliver is elite-tier exploit development, commoditised, and available by the hour.

Take availability last, because availability changes the math entirely. The defending profession has always faced a small number of brilliant attackers and a long tail of opportunists. AI flattens that distribution. The same capability now sits in every browser tab. Writing in March 2026, the veteran vulnerability researcher Thomas Ptáček observed that the craft of finding security flaws had been “cooked”: pointing an agent at a source tree and typing find me zero days simply works, and the new price of elite attention has fallen to epsilon. The Cloud Security Alliance’s AI Vulnerability Storm report, co-authored by Jen Easterly, Bruce Schneier, Chris Inglis, Phil Venables and others, formalises the same view. Five of its thirteen named risks carry a critical rating, and the cybersecurity risk model on which most boards still rely is itself classified as outdated.

What stays, what shifts

The existing defensive playbook still matters, in some ways more than ever before. Strong authentication, segmentation, fast patching, identity and privilege management remain the foundations of every credible security programme, and Phil Venables is right that under AI-driven attack these foundations move from sound to existential. What changes is the cadence at which they have to run, and the arrival of a new asset class on the corporate estate: the autonomous agent, an asset class the legacy controls predate. Five concrete priorities follow, and they should be addressed in order.

The first priority is non-human identity. Recent industry data places

the ratio of machine identities to human identities in the average enterprise at between 82-to-1 and 144-to-1, growing roughly forty-four per cent year on year. Around five per cent of cloud machine identities carry full administrative privilege, and some sixty-two per cent sit dormant, inactive for ninety days or more while still retaining their access. Drop an autonomous agent into that environment and the attack surface stops resembling a perimeter and starts resembling a cloud. The first move for any organisation is to inventory every non-human identity, name the human owner of each one, and retire what fails the justification test. Enumeration precedes defence.

The second priority is to retire the language of human-in-the-loop in favour of bounded autonomy. A tired analyst clicking approve on the seventeenth alert of a shift functions as a rubber stamp with a person attached, and threat actors know it. Bounded autonomy works the other way around. For each agent, a small set of pre-authorised action classes runs at machine speed; everything else stops by default. The principle, formalised in the new OWASP Top 10 for Agentic Applications under the heading “least agency”, is that autonomy is a feature an agent earns, one action class at a time.

The third priority is revocability. A useful diagnostic is the sixty-second test: pick any agent in production and ask whether, on discovery of its compromise, access can be revoked inside a minute across every system it touches. Most organisations fail at the first attempt. Long-lived API keys, cached OAuth grants, credentials scattered through downstream systems, and a central kill switch still on next quarter’s roadmap: these are the recurring patterns. The CSA report is direct on this point. The agent harness, meaning its prompts, tool definitions and retrieval pipelines, is

where the most consequential failures occur, ahead of the model itself.

The fourth priority is detection tuned for agentic behaviour. Conventional SIEMs were built to recognise a human pretending to be a process. The new problem runs the other way: a process behaving like a malicious human. Agentic attacks have a fingerprint, including constant authentication, tool-call sequences inconsistent with declared purpose, and cross-agent communication outside the expected graph. That fingerprint stands out clearly to a defender configured to look for it, and slips past one configured for last decade’s attacks.

The fifth priority is to treat artificial intelligence as a procurement category in its own right. Every model provider, every agent framework, every plugin and Model Context Protocol server has joined the corporate attack surface, and the OWASP Agentic Top 10 identifies supply chain compromise as a top-five risk precisely because agents fetch and execute components at runtime. An annual SOC 2 review falls short of the bar this category requires. Procurement needs a baseline questionnaire on training and red-teaming, contractual rights to audit and revoke, exit clauses that work in days rather than quarters, and an internal review body with the authority to refuse.

The cadence question

Every priority on this list can be purchased today. All five are achievable inside ninety days. Delivery at scale remains rare. Cadence, more than sophistication, defines the current threat landscape. Closing the gap between that cadence and the one our organisations were designed for is the work for the year ahead. Boards, regulators and insurers are already reading the new authority. The question they will ask next has moved on from the adequacy of the controls. They will ask whether the controls were ever sized for the right opponent.

Navigating Cybersecurity crossroads: Key lessons for 2026

Cybersecurity is entering a defining period. The lessons of 2025, the realities organisations face today, and the technologies emerging over the next few years point to a landscape that is more complex, faster-moving and more consequential than ever before.

As we look ahead to 2026, it has become far too apparent that tried and tested approaches may no longer be sufficient.

2025: A year of warnings and wake-up calls 2025 delivered brutal lessons about the fragility of our digital infrastructure. In January, PowerSchool, a cloud-based education platform tracking over 55 million students in more than 90 countries, fell victim to a breach. A 19-yearold Massachusetts student allegedly attempted to extort $2.85 million from the company, after compromising data on reportedly 1.2 million students and staff. The breach serves as a stark reminder that fundamental security hygiene remains non-negotiable, regardless of an organisation's scale or sophistication.

In February, SimonMed reported a ransomware-related breach affecting more than 1.2 million people, with the compromise linked to a vendor incident and a confirmed period of attacker access. In healthcare, this type of intrusion is not only a privacy event. It creates material risk of operational disruption where imaging, scheduling, and clinical workflows depend on digital availability.

2025 also marked a turning point for AI security. Promptextraction attacks against large language models were publicly observed, demonstrating how adversaries could manipulate models into revealing sensitive system prompts. In one welldocumented research case involving DeepSeek, engineered role-playing scenarios were used to bypass guardrails and

expose internal model logic.

In September, Jaguar Land Rover’s cyber incident halted production for close to six weeks. Analysis from the Cyber Monitoring Centre, cited by Reuters, estimated the cost to the UK economy at about £1.9bn and suggested disruption affected more than 5,000 organisations across the supply chain.

October brought a breach at WestJet, widely attributed by security researchers to the ShinyHunters group, which exposed data from 1.2 million passengers. In November, a breach at Miljödata affected 25 companies and 200 Swedish municipalities, disrupting operations across multiple organisations, including Volvo. In December, 120,000 internetconnected cameras in South Korea were compromised, with stolen footage used to produce large volumes of illicit content — a stark example of how irreversible the damage from poor IoT security can be.

The key takeaway from 2025 is that third-party risk is as critical as internal security, resilience matters when outages last weeks rather than hours, and organisations must assume incidents ‘will’ happen to them and to prepare for it. The real differentiator is whether systems, people and processes can function when core technology fails. It’s better to do this under a simulated attack rather than in the midst of the real thing.

AI's double-edged sword

As we move into 2026, AI is redefining the threat landscape at speed.

Shadow AI has emerged as the new partner to shadow IT. While unauthorised Dropbox installations and Google drives have provided exfiltration opportunities for years, we now face employees inputting sensitive data into public AI models.

Davey McGlade, Head of Cybersecurity at Version 1

This was famously exemplified by the Director of Cyber Security Infrastructure Agency (CISA) putting sensitive data into ChatGPT. This data may be retained or used to train future models, creating a perpetual security leak.

At the same time, “citizen developers” are vibe-coding AI-generated applications across enterprises with little oversight. These tools often accumulate technical debt that no one is equipped to service, while previously approved enterprise platforms and applications ship with new embedded AI features indistinguishable from core functionality. Where does this data go? How is it secured?

AI browsers such as Arc, Dia, Brave Leo and Comet introduce further risk. In December, researchers demonstrated a proof-of-concept on how Comet could be manipulated via a malicious email to carry out destructive actions, including deleting a user’s Google Drive content. We are increasingly granting AI agents autonomous access to digital estates without fully understanding the implications. Analysts, including Gartner, have warned that unmanaged AI agents represent a growing enterprise risk unless strong governance is implemented.

Deepfakes represent an evolution of a 40-year-old threat. Phishing, which emerged in 1985, trained us to spot typos and grammatical errors. Today's AI-generated attacks feature perfect spelling, flawless grammar, seamless translation and increasingly sophisticated audio and video that's virtually impossible to detect. According to Sumsub’s 2025–2026 Identity Fraud reporting, deepfake-related fraud attempts in the UK rose by 94% in 2025. With only seconds of audio required to clone a voice, any business process relying on voice verification is now vulnerable.

In November, Anthropic’s Claude was reportedly used by a Chinese

state-sponsored group to target 30 organisations, with 80–90% of intrusion tasks performed autonomously. While imperfect, this marked the first reported case of AI-orchestrated state-backed attacks and demonstrated how similar techniques could be adapted to compromise other large language models.

Organisations must test critical business processes against deepfake scenarios, while multi-channel verification should become standard and AI must be secured and governed rather than simply banned. Attacks are accelerating in both speed and scale, so defences must keep pace.

When digital and physical worlds converge

The next phase of cybersecurity will be shaped by a convergence of technologies that blur traditional boundaries. Autonomous agents are set to replace the one-to-one “human plus copilot” model with swarms of AI assistants. In a 3,000-person organisation, even three to five agents per employee could mean up to 15,000 autonomous entities operating simultaneously. Monitoring activity alone won’t be enough; organisations will need to understand intent, logic and inter-agent coordination. Managing your workforce may soon include managing and auditing a team of agents.

IoT proliferation accelerates with around 39 billion devices projected by 2030, with continued strong growth beyond that at roughly 14% yearover-year. We face a coming crisis of unpatchable legacy hardware, smart meters, medical monitors and industrial sensors that remain functional but legally and technically abandoned when manufacturers go bankrupt or discontinue product lines. Ransomware is moving from virtual to physical, with attackers disabling air conditioning in manufacturing plants or agricultural sensors, spoiling crops. Digital-only security teams must now consider

physical safety implications.

Humanoid robotics will disrupt physical workplaces as profoundly as agents disrupt virtual ones. China operates over 2 million factory robots, far exceeding any other single country. Companies like Figure AI, Tesla Optimus, Unitree B2, and Boston Dynamics are pushing boundaries despite well-documented failures. The cybersecurity implications are staggering, blurring lines between physical and digital security, creating unprecedented ethical and identity challenges and the potential for hacked robots to cause physical harm by freezing brake pads on automated vehicles or causing havoc in warehouses.

Underpinning everything is quantum computing which is potentially more disruptive than Y2K. When quantum chips combine with Shor's algorithm, existing encryption mechanisms protecting banking, finance and secure communications will collapse. The UK's National Cyber Security Centre already provides guidance urging organisations to inventory their cryptographic assets and embrace crypto-agility by implementing both classical and postquantum cryptographic solutions.

Acting now for a secure future

These challenges won’t be solved overnight, but organisations can act now. Critical decisions should be verified through multiple channels to counter deepfakes. Implement zero-trust architectures for non-human identities. Segregate IoT devices with multiple defence layers and develop strategies for when legacy patching becomes impossible. Start the transition to postquantum cryptography.

The future of cybersecurity is bright but not because threats are diminishing, but because there's never been a more critical time for our profession. Technology and threats will evolve, but one thing remains constant in that we will not be short of challenges anytime soon.

Reach beyond: Engineering careers at Liberty IT

At Liberty IT, career journeys into engineering don’t follow a single path. Amanda O’Prey, now a Senior Software Engineer, and Michael Anderson, an Engineering Manager, each took different routes into tech, from university discovery to apprenticeship learning.

Their stories highlight how curiosity, culture and continuous development can shape long-term, rewarding careers in a fast-moving and innovative industry.

q Can you walk us through your journey into techwhat inspired you to forge a career in technology and how did you end up at Liberty IT specifically?

Amanda: I enjoyed ICT at secondary school and was always curious about the possibilities in technology, but I didn’t actually write my first line of code until university. I came across Liberty IT while job hunting after graduation and decided to apply. After a long wait I received three offers in the same week. My decision came down to the interview experience: Liberty IT stood out because the interview day felt welcoming and community-focused, which made the choice easy.

Michael: I joined an IT apprenticeship through Belfast Met in 2015 after working in a call centre and realising my interest lay in technology. The apprenticeship route appealed because it let me earn while I learned. Liberty IT stood out during interviews for a number of reasons - the conversation felt genuine, interviewers were clearly passionate about technology, and the office had a relaxed, welcoming vibe. That

combination convinced me to join and stay.

q Amanda, how did Liberty IT compare to what you expected from a graduate role in tech?

It’s hard to remember all my original expectations, but the six week graduate programme really helped me settle in. From day one, I had a dedicated leader who was there to support my individual development, not just oversee project delivery. That ongoing career guidance with people actively supporting your broader growth, not just the current task has exceeded my expectations and made a big difference to my career development.

q Amanda, seven years is a strong tenure, what's kept you motivated and growing within the same company?

The people and the company culture. I’ve been lucky to work with very knowledgeable teams and colleagues who are willing to mentor and support you during the learning phase. That collaborative environment set a standard for how I work with others and kept me motivated to stay and grow. And yes, the technical challenges are interesting too.

q Michael, what drew you to an apprenticeship over a more traditional university route, and how has that path shaped your career?

I studied event management at university and found the practical, hands-on nature of work more suited to me. The apprenticeship blended structured learning with real responsibility from day one. Being embedded in teams accelerated practical skills, collaboration, stakeholder communication and pragmatic problem solving, which later

Amanda O’Prey, Senior Software Engineer at Liberty IT
Michael Anderson, Engineering Manager at Liberty IT

helped me progress into engineering and leadership roles.

q Describe a typical working week for you. What kinds of problems are you solving and what technologies are you working with?

Amanda: I work in Machine Learning Solutions, where I develop, deploy and maintain ML models and work closely with data scientists who design and train the algorithms. A lot of my time goes into productionising models and automating previously manual data processes.

Work varies day-to-day. Some days are smooth whilst others involve debugging and incident response. Technologies I use regularly include Apache Airflow, Snowflake, Databricks, GitHub Actions and Datadog.

Michael: I’m aligned to our Cybersecurity Operations Centre, supporting security analysts and engineers who build tools and automation to improve our security posture and incident response.

My week is varied and busy! It can include management meetings (resourcing, planning, team events), coaching engineers, removing blockers and tracking delivery of technical projects. I also focus on capability building - finding training, guiding career development and improving processes around CI/CD and observability. Technology varies by squad, but the themes are cloud-native services, automation, logging/monitoring, and secure development practices.

q What does career progression look like at Liberty IT? Is it purely technical, or are there other paths available?

Amanda: There are multiple paths. My progression has been technical. I joined as a graduate Associate Software Engineer, then moved to Software Engineer and now Senior Software

Engineer, but you can continue advancing technically or move into leadership if that’s your interest.

There are also other roles across the business such as Product Designer, Product Owner and Data Scientist, which allow you to stay in the technical space while focusing on different aspects of delivery and product.

Michael: Progression is flexible. We invest heavily in technical development, but we also prioritise soft skills such as presenting, stakeholder management and collaboration. Engineers can follow technical specialist tracks, move into management, or take hybrid roles such as tech lead or product-facing positions. We support these paths with mentoring, training budgets and clear competency frameworks.

q For other talented software engineers who'd never considered Liberty IT before, what would be the one thing you'd want them to know about working here?

Amanda: The Liberty IT culture. It’s unique. It prioritises people while driving high performance engineering. That, combined with flexibility to move internally, makes it easy for engineers to develop new skills and grow their careers in different directions.

Michael: For me, it’s the work-life balance is a genuine priority. It’s visible from the top down: people are encouraged to take breaks, pursue development and build connections with colleagues. That focus makes Liberty IT a place where you can grow technically while maintaining a sustainable life outside work.

q From your perspective, what are some of the strengths and mindsets that help people develop and grow at Liberty IT?

Amanda: Growth mindset: being curious, asking questions and treating mistakes as learning opportunities rather than failures.

Collaboration mindset: being willing to pair-program, share knowledge and accept feedback. Learning is faster when people help each other.

Michael: Ownership and curiosity. Liberty IT provides resources and opportunities, but the fastest progress comes from people who proactively shape their own development by bringing ideas, preparing 1:1s and seeking feedback. A collaborative mindset also matters: people who help others succeed tend to accelerate their own growth.

q Outside of the technical skills, what's the most valuable thing working in tech has taught you?

Amanda: Working in tech taught me that clear communication, honest feedback and teamwork are essential. It also taught me resilience. Staying calm, investigating methodically and recovering from failures matters more than any single technical trick.

Michael: Success is collective. The best outcomes come when teams pull together - technical ability matters less if you can’t bring others along.

q What advice would you give to someone who’s considering a career in tech?

Amanda: Stay curious and be open to continuous learning because tech is always evolving. AI is a great example of that and I’d encourage anyone considering a career in tech to embrace AI as a force multiplier. Learn how to use tools to accelerate development, automate repetitive tasks and prototype ideas faster. Practice prompt engineering, it has become a practical, everyday skill, so building confidence with it early can make a real difference.

Michael: Be ready to learn continuously. Tech moves fast and staying relevant requires effort, but if you enjoy problem-solving and learning, it’s a career with long-term opportunity.

q Give us an overview of your journey into Product Design. Why did you choose this pathway?

I originally started out as a graphic designer working in print, with my first role being at a local newspaper. As everything started shifting digitally, I naturally moved into web design and taught myself along the way. Back then, the lines between disciplines were a bit blurrier, so you ended up wearing a lot of hats and figuring things out as you went.

The moment that really pulled me into product design was working on a website for a company that sold custom tarps online. It sounds simple now, but at the time it was a genuinely interesting problem to solve because their whole process had previously been very human and very manual. I found myself sitting with the people taking orders, understanding how customers thought, how measurements were explained, where confusion happened, and how we could make that all feel intuitive digitally. That was probably the first time I realised design wasn’t just about visuals, it was about helping people understand something and making their lives a little easier.

q What led you to join DailyPay? What does your day to day look like as the Principal Product Designer? What drew me to DailyPay was the opportunity to work on a product that genuinely matters to people. DailyPay supports hard working employees – many of which are leveraging the tool to navigate important financial moments and gain a bit more understanding and flexibility over their pay.

Designing for those moments comes with a real sense of responsibility, and that immediately resonated with me. I’ve always had a passion for mobile design. There’s something really powerful about creating products that live in people's pockets and become part of their everyday routines, benefiting

their overall wellbeing.

Day-to-day, my role is a mix of handson design leadership and connecting dots across the organisation. I work closely with product designers across different squads, helping shape experiences so they feel joined up and consistent rather than fragmented. A big part of my role is also evolving our design system and improving how our teams collaborate. Helping them turn ideas into something practical, scalable, and useful for real people.

q How would you describe your core design philosophy? How does that shape your approach in your role at DailyPay?

I think the best products are the ones that quietly fit into people’s lives and help without demanding too much from them. My philosophy has always been that design should be genuinely useful first and foremost. Not loud. Not overly complicated. Just thoughtful, clear, and there when people need it.

That mindset shapes a lot of how we approach design at DailyPay. People don’t usually open financial apps because they’re having a brilliant day. Often, they are trying to solve a problem, reduce stress, or feel more in control of their situation. We think a lot about the emotional weight of those moments and how design can either ease that pressure or accidentally add to it. That means focusing heavily on clarity, reducing complexity, building trust through reliability, and creating experiences that feel calm rather than overwhelming.

q How does product design improve user experience? How do you help that come to life at DailyPay?

Good product design improves user experience by removing friction and helping people achieve what they need to do with as little stress as possible. Sometimes that means simplifying a journey, sometimes it means using

Tommy Principal

Q&A with Tommy McClean, Principal Product Designer at DailyPay

clearer language, and sometimes it’s about recognising that a user might already be anxious before they even open the app.

At DailyPay, we try to design with empathy. We want experiences to feel human, respectful, and relevant to real life. A lot of my role is helping ensure that philosophy stays consistent across the product, whether that is through the design system, collaboration with squads, or shaping the bigger picture of how the app evolves over time. I enjoy zooming out and looking at how all the pieces connect together because users don’t experience products feature-by-feature, they experience one overall journey.

q What do you see in the future for product design?

I’m genuinely excited about where product design is heading, especially with the rise of AI. I don’t see AI replacing designers, but I do think it’s going to massively change how we work. What interests me most is the idea that AI could allow designers to spend more time thinking deeply about people, behaviour, and experiences rather than getting stuck in production work. It’s already helping teams prototype faster, explore ideas quicker, and remove a lot of repetitive tasks that can slow creativity down.

The technology will evolve quickly, but I still think the human side of design, the empathy, judgement, understanding emotion and context, will become even more valuable. The future of product design feels less like humans versus AI, and more like humans focusing on what it really means to be human.

Breaking ceilings and building pipelines: Senior women in tech on transforming the industry in Northern Ireland

Women In Business recently organised a roundtable of senior female leaders from across Northern Ireland's technology sector to discuss some of the industry's most persistent challenges: attracting, retaining, and elevating women in tech.

The meeting took place in the iconic Custom House Belfast hosted by Barbara McKiernan, Managing Director VANRATH, the headline sponsor at the upcoming Women in Tech Awards and Caroline Coyle, Women in Business Director.

Sync NI was there to cover the event, a candid, experiencedriven conversation that moved well beyond statistics and into the practical realities of culture, mentorship, leadership, and a rapidly evolving AI landscape. Here are the key themes

and recommendations that emerged from the day.

The retention problem Is a culture problem

Getting women through the door is only half the battle. Several leaders around the table were frank about the fact that their organisations struggle not with recruitment, but with keeping women long enough for them to grow into senior roles.

One recurring theme was the tendency for women to gravitate organically toward teams led by female managers, often teams that consistently ranked among the highest performers within the organisation. The reason, participants agreed, was not simply gender solidarity, but empathy. Women in those teams reported feeling understood by leaders who could relate to the realities of caring responsibilities, maternity

leave, and the constant juggling act that disproportionately falls to women regardless of how supportive their organisations claim to be.

The recommendation from the group was clear: organisations cannot rely on good intentions. Senior female leaders must be intentional about creating structured internal networks where junior women are visible to and supported by those further along in their careers.

One participant described a tiered mentoring model being piloted in her organisation, where mid-level staff support those just entering the business, while senior leaders mentor those ready to step into leadership roles. The goal is to ensure that women see a credible path upward before they decide there isn't one and look

elsewhere.

The mirror problem: Women not supporting women

One of the more honest moments in the discussion came when a senior leader acknowledged that earlier in her career, she had been so focused on earning her place at the table, on being "one of the lads" that she had not done enough to bring other women along with her. Several heads around the table nodded in recognition.

This is what might be called the mirror problem: women who have succeeded in male-dominated environments can sometimes, unconsciously, replicate the very behaviours that made it difficult for them to progress. The antidote, the group agreed, is not to exclude men from the conversation, but to build a culture of active inclusion where elevating women is not seen as coming at the expense of their male colleagues, but as making the whole team stronger.

The most effective teams, multiple participants observed, often tend to be those led by male leaders who are genuine advocates for gender balance often, though not exclusively, men who have daughters or sisters and have developed a natural empathy for the challenges women face in professional environments. Leaders like this don't just tolerate different communication styles; they design their team cultures around them.

Finding your voice and helping others find theirs

One theme that surfaced repeatedly was the difficulty many women experience in having their voices heard in technical environments, particularly early in their careers. One participant recalled being told by a senior male leader and mentor that she was routinely letting others speak over her in meetings, and that what she had to contribute was more valuable than what was being heard. That intervention, she said, changed the

trajectory of her career.

The message to organisations was unambiguous: don't wait for women to raise their hands. Deliberately create environments where different communication styles are respected, where speaking over colleagues is not rewarded, and where leaders model inclusive behaviour visibly and consistently. As one leader put it, the presence of a "Women in Tech" banner on a company website means far less than whether women in that company actually feel their contributions are valued day to day.

The education gap starts earlier than you think

The conversation turned to a challenge that begins well before the workplace: the educational pipeline. Participants flagged the A-level system in Northern Ireland as a structural barrier, noting that students are required to narrow their subject choices at a stage when many young women are yet to discover an interest in technology. Broader curricula, as seen in other markets, tend to keep boys and girls studying STEM subjects together for longer which in turn produces a more balanced pool of candidates entering higher education and the workforce.

Several leaders also pointed to the role of parents as under-acknowledged gatekeepers. Families who are not themselves in the technology industry often default to steering academically capable children toward medicine or law, simply because they are not aware of the breadth and earning potential of careers in tech. Changing parental perceptions could be just as impactful as any school outreach programme.

There was broad support for deeper engagement between technology companies and secondary schools not just career talks, but hands-on curriculum contribution. The group noted that proposed legislation requiring software companies

in Northern Ireland to nominate representatives to teach parts of the tech curriculum in schools is a step in the right direction.

AI as both challenge and opportunity for gender balance

The latter part of the discussion moved into the evolving role of artificial intelligence — and its implications, both for women in tech and for the industry as a whole.

One organisation described a sophisticated hub-and-spoke governance model for AI deployment, and noted with interest that the hub, responsible for oversight, guardrails, and ethical decision-making, was disproportionately staffed by women. Several participants suggested this was not a coincidence. Data analytics and AI governance roles are relatively new disciplines, unburdened by the decades of male-dominated hiring patterns that still shape software engineering teams. For organisations looking to diversify, these emerging areas represent a genuine opportunity.

The group was candid about the risks, however. There was concern about

the halting of graduate recruitment programmes as companies lean into AI-driven productivity gains. The worry is that today's cost savings create tomorrow's skills vacuum. This could lead to a generation of engineers who never developed foundational capabilities because they skipped the early career years where those skills are formed.

There was also discussion of what one participant called "AI brain fry" describing the cognitive overload that comes when AI tools dramatically accelerate output but human capacity to review, validate, and direct that output hasn't kept pace. The consensus was that AI is not replacing human judgement; it is, at its best, amplifying it. But that distinction requires strong leadership and a clear-eyed governance framework to sustain.

Practical recommendations

Across the discussion, a number of solid and practical recommendations emerged for organisations serious about improving gender balance in their teams:

Firstly, build structured mentoring programmes with visible role models at every level. Don't rely on informal networks. Create deliberate touchpoints between junior women and experienced senior leaders within the organisation.

Secondly, nominate your people for industry awards. The Women in Tech Awards were highlighted as a meaningful, tangible way to boost the confidence and visibility of women who are doing exceptional work but are not being recognised outside their immediate teams.

Thirdly, invite men into the conversation. The group agreed to explore a dedicated male advocates session as a future forum event recognising that cultural change in organisations will not happen without engaging the men who currently hold

the majority of senior positions.

Next, engage with industry bodies and working groups. Organisations were encouraged to consider membership with Software Northern Ireland and to actively nominate women — particularly those earlier in their careers to participate in working groups covering education, talent, and future technology.

Finally, show up, and bring someone with you. Whether it is a roundtable, a conference, or a speaking engagement, bringing a junior colleague along, especially one who would never attend on their own is an act of mentorship in itself.

The conversation around the table reflected both the genuine progress that has been made and the considerable distance still to travel. What was striking was the absence of resignation. These are leaders who have navigated significant barriers, and they are not waiting for structural change to happen from the top down. They are building the culture they wish they had been part of to benefit the next generation of Women in Tech.

Elevate 9D brings a new approach to workplace wellbeing to Belfast

In a corporate culture where long hours, constant connectivity and packed schedules are often worn as badges of commitment, the ability to truly switch off has become increasingly rare.

Yet amid growing concerns about stress, burnout and disengagement, a Belfast-based startup believes the answer to better performance may lie not in working harder, but in learning how to reset.

Elevate 9D, a new entrant in Northern Ireland’s wellbeing space, is introducing what it describes as a neurosciencebacked breathwork experience designed specifically for modern workplaces. Its launch reflects a broader shift in how organisations are thinking about employee wellbeing, not as a perk, but as a foundational part of sustainable performance.

At the centre of Elevate 9D’s offering is “9D Breathwork”, a guided experience that blends intentional breathing techniques with carefully designed auditory and sensory elements. The aim is to help participants access distinct brainwave states typically associated with deep relaxation, clarity and emotional processing.

Unlike traditional workplace wellbeing initiatives that can feel like yet another item on an already full to-do list, the experience is intended to move participants out of constant “doing mode” and into a state of recovery. Advocates argue this allows the nervous system to reset, helping the body step out of prolonged stress responses and into a more restorative state.

The scientific basis behind breathwork continues to attract growing interest.

Research has shown that controlled breathing can influence the nervous system, shifting it from a chronic fightor-flight mode into what is often called a parasympathetic or “rest and digest” state. This transition is associated with improved emotional regulation, increased focus and reduced physical tension, outcomes that are increasingly relevant in high-pressure workplaces.

While Elevate 9D marks the first corporate-focused 9D offering in Belfast, similar approaches have already shown promise in other settings. In schools across the city, versions of the method have been used to support children experiencing anxiety and emotional regulation challenges. Early feedback from those environments has suggested improvements in focus, wellbeing and resilience, contributing to interest in applying the model to adult working populations.

Globally, organisations are experimenting with alternative approaches to mental health support as traditional interventions struggle to keep pace with rising workplace stress. Against that backdrop, Elevate 9D arrives at a moment when employers are under increasing pressure to provide

meaningful, evidence-informed support for their teams.

The company’s founder Kelly Nixon is a fully certified 9D breathwork facilitator who has spent time in highpressure corporate environments. That personal experience, juggling demanding workloads with personal responsibilities, was a driving factor behind launching the business.

“There is a growing recognition that humans aren’t designed to operate at full output all the time,” Kelly explains “Yet modern work culture often expects exactly that.”

Rather than positioning wellbeing as a reactive response to burnout, Elevate 9D frames it as a proactive investment. Reported benefits for employees include reduced stress and anxiety, improved mental clarity, stronger emotional resilience and increased energy. For businesses, that can translate into healthier teams, greater engagement and a more sustainable approach to productivity.

As conversations around mental health continue to evolve, token gestures are increasingly falling short. Employees are looking for approaches that reflect the realities of modern working life and offer genuine impact.

By combining science, breath and lived human experience, Elevate 9D is tapping into that shift by offering something simple, but potentially powerful: the space to pause, reset and return to work not just feeling better, but functioning better.

In a world that rarely slows down, learning how to stop, even briefly, may be becoming one of the most valuable skills of all.

Kelly Nixon, Founder, Elevate9D

Q&A with Chris Lester, European and UK Patent Attorney at CME Group

I’m a UK and European Patent Attorney working at CME Group in Belfast. My job sits at the intersection of law, technology and finance. My academic background is in physics, and I’ve always enjoyed trying to understand how things work.

After starting my career in private practice, finding an inhouse patent attorney role in Northern Ireland with a worldleading fintech company such as CME Group felt like hitting the jackpot. It’s a privilege to work closely with our software engineers at the forefront of financial technology, helping to protect the company's valuable inventions in the heart of Belfast’s growing tech community.

q Protecting intellectual property is an essential business function across all industries. In terms of confidential information, patents, trade marks and copyright, how do software engineers typically engage with these rights? When it comes to the creation of protectable IP rights,

software engineers are often the “prime movers” who generate the core ideas on which IP rights are based. For example, software code is protected by copyright, and through writing code, engineers automatically create enforceable IP rights (e.g. the right to stop others from copying and using that code). Confidential information and trade marks are other examples of IP rights that software engineers will be very familiar with and encounter every day.

For patents and inventions, software engineers will often be the ones who generate the inventive ideas and also bring ideas to life in the real world. I love engaging with software engineers at CME Group, a place where patentable inventions flow quite naturally from the day-to-day problem-solving tasks that our engineers are engaged in. Also, for many of our inventors, having their name on a granted patent provides a great sense of achievement. CME Group engineers are generally curious about all aspects of IP, and how it can help to secure and support CME Group’s leading position in the derivatives industry.

q Can you walk us through what actually makes a piece of software patentable and what's the single biggest misconception developers and businesses have about protecting their software with patents?

In a nutshell, software is patentable if it provides a new and non-obvious technical solution to a technical problem. It’s not about the code itself, but how the code works and what it actually does. For example, if a piece of software can be used to make a computer processor faster, smaller or more efficient, then that software is more likely to be considered technical/ patentable. On the other hand, if a piece of software can only be used to make a business or administrative process faster or more efficient (without changing the way the underlying computer itself works or operates), then that software is less likely to be considered technical/patentable.

I spend a lot of time trying to determine

whether or not an idea would be considered technical. The meaning of the word “technical” can be hard to pin down and has to be judged on a case-by-case/territory-by-territory basis. I think this uncertainty results in a common misconception that you can’t patent software at all - you definitely can. However, the laws of many countries mean that, in practice, not all software can be patented.

q AI tools are increasingly being embedded in most developers' workflows. What are some of the interesting new challenges and IP-related questions that you see emerging in this space?

The rise of AI-assisted coding presents some fascinating challenges, for example around ownership and inventorship. Over the past few years, courts in several countries have found that only humans can be considered inventors and authors for the purpose of obtaining patents and copyrights, leaving a potential protection gap for innovations that are purely AIgenerated. It's a rapidly evolving area, and at CME Group, we are constantly learning and adapting our strategy.

q Are software patents treated differently in the US, UK, and EU and how do organisations navigate this while operating across global markets?

There are some crucial differences in how software patents are treated across the globe. At the European Patent Office, there’s a strong emphasis on the invention having a "technical character", and it’s often challenging to obtain European patents for software-implemented business methods. At the US Patent and Trademark Office, the focus is often around whether the invention is considered an "abstract idea” and the legal landscape has been shaped by a series of landmark court decisions. The UK Intellectual Property Office generally follows the European approach, but the UK has

its own caselaw and nuances which at the time of writing are in something of a state of flux. Navigating the differences between jurisdictions requires a global patent strategy. I work closely with my US colleagues and our outside counsel to ensure that CME Group patent applications are prepared in a way that gives them the best chance of success in all key jurisdictions.

q As new technologies continue to evolve, what areas of software development are expected to attract the most significant patent activity in the future?

Perhaps unsurprisingly, I think that the most significant and exciting area for future patent activity will be around AI. AI has the potential to transform every industry on the planet, so naturally there is a global race at the moment for patents which protect these innovations.

Of course, securing meaningful patent protection for AI-based inventions is complicated by the strict rules around patenting software, and I think this is exactly why the area will be such a focus in the years to come. Because it can be so tricky to secure patent patent protection for AI innovations, the companies that do manage to obtain such granted patents will have hugely valuable assets.

q What advice would you give to a developer who has never thought about IP before but is about to launch a product?

For anyone about to launch a product that hasn’t considered IP, I would suggest carrying out an IP Audit before the launch. An IP Audit could answer questions such as what protectable assets does the product include? Who owns those assets? Does the product rely on the use of any third-party IP? The answers could help to unlock further commercial value and avoid costly legal surprises down the road.

Resilience in Tech Leadership: Stephen McCabe and Ciaran May in conversation

What happens when a deep tech innovation centre starts asking questions that have nothing to do with technology?

Momentum One Zero's Stephen McCabe and Natural Resilience's Ciaran May don't come from the same world — one builds innovation ecosystems, the other works with leaders who risk being consumed by them. But what they found themselves talking about touches something most people in tech recognise and few say out loud.

Stephen: I’m really interested in the relationship between high performing teams and psychological safety – what has your experience taught you about how those concepts fit together?

Ciaran: High performance without psychological safety will get you results, but not for long. Psychological safety is the cornerstone of a high performing team — it allows people to feel seen, heard, valued and understood, and provides a pathway to contribute to something bigger than themselves.

What I see in tech teams especially is that you can drive output through pressure, urgency and fear and in the short term it can look impressive. But underneath that, there’s usually friction building. People stop speaking up. They hide mistakes. They optimise for looking competent rather than critical thinking.

Psychological safety is what allows a team to stay in performance over time. It creates an environment where people can challenge, admit uncertainty, and solve problems properly rather than defensively.

The key distinction I always make is that psychological safety is not about being comfortable. It’s about being able to contribute fully without fear of being diminished.

The highest performing teams I've worked with hold both high standards and high safety. One without the other leads to burnout or mediocrity.

Stephen: Reflecting on my own career journey, I think I spent a lot of early years being driven by fear (often ‘imposter syndrome’, anxiety that I would somehow be ‘found out’ by my much smarter colleagues) - in other words, a real deficit in psychological safety. Ironically, that produced good results in the short to medium term – I ran very hard to produce good outcomes. But it wasn’t sustainable, and I’ve experienced long periods of anxiety and clinical depression in the past as a result. That’s why I’m so passionate about this kind of conversation.

In industries where identity is tightly coupled to performance, how do you separate self-worth from output?

Ciaran: This is one of the biggest challenges in highperformance environments, particularly in tech where output is so visible and measurable. The risk is that people start to equate “what I produce” with “who I am.”

When that happens, every success inflates you, and every setback destabilises you. If your entire identity sits inside your role, your nervous system is constantly under threat.

Understanding that your work role is only part of you — not

Stephen McCabe, Executive Director at Momentum One Zero
Ciaran May, Leadership & Resilience Speaker at Natural Resilience

Momentum One Zero Momentum One Zero is a deep tech innovation centre at Queen's University Belfast, business-led and built under the Belfast Region City Deal to create commercial value at the convergence of AI, cyber security, and wireless technologies.

Natural Resilience

Natural Resilience works with founders, senior leaders and executive teams to build sustainable high performance — focusing on the systems, behaviours and environments that allow people to perform under pressure without burning out, drawing on experience across elite sport, policing and leadership development.

all of you — creates stability. It allows you to review your work objectively, take feedback without it becoming personal, and maintain consistency under pressure.

Stephen: I’m interested too in the idea that we often intertwine our identities with our careers – that's a natural thing to do when we derive self-worth from output. Do you think there are any pitfalls in that? How important is extending our identity ‘beyond the workplace’?

Ciaran: There's a real danger in becoming one-dimensional. When identity is overly tied to career, two things happen. First, people become fragile — a failed project, a bad quarter, a difference of opinion hits harder than it should. Second, decision-making narrows. People protect status instead of pursuing progress.

The leaders who sustain performance tend to have multiple anchors — family, health, interests, community — not as a distraction from work, but as a foundation for it. It allows better decisions, because your entire sense of self isn't tied to the outcome of a single meeting or product release.

Stephen: Are there frameworks or mental models that help people maintain clarity under sustained pressure?

Ciaran: Under pressure, people don’t rise to the occasion they fall to their systems. So the question becomes: what are your systems?

A simple model I use with leaders is: Awareness > Regulation > Response

First, awareness. Can you recognise what’s happening internally? Stress, frustration, defensiveness etc

Second, regulation. Can you create enough space to avoid reacting impulsively? That might be as simple as a pause, a breath, or stepping out of a situation.

Third, response. Can you choose a behaviour that aligns with the outcome you actually want, not just what you feel in the moment?

Most breakdowns in leadership happen in that middle step, lack of regulation. So we build simple, repeatable practices that allow leaders to stay composed when it matters most.

Stephen: If you had to prioritise 2–3 interventions for someone overwhelmed in a tech role, what would they be?

Ciaran: The mistake most people make when they’re overwhelmed is trying to do more, better. What’s usually needed is less, but clearer.

First, I’d look at load. What actually matters this week? Not everything is equal, but we often treat it that way.

Second, physiology. Sleep, movement, nutrition and social connection, these aren’t lifestyle extras, they are performance drivers. If your physiology is off, everything feels harder than it should.

Third, conversation. Most pressure builds in silence. Whether that’s a colleague, a mentor or a professional, speaking things out loud often reduces complexity immediately.

None of these are revolutionary, but consistently applied, they are transformative.

Stephen: I’ve had multiple cycles of therapy, as many people have. For me, talking things through with an objective and professional person can be a bit of a game changer – it's something that should be seen as normal, as part of a weekly routine! A good therapist will also help with strategies for resilience – what do I actually need to do when i find myself in a difficult conversation, in a situation where there is conflict? Fight, flight, dissociate? Or is there another way?

You’ve work with lots of tech leaders, and seen how they operate. What does a “sustainable career” in a highpressure industry look like to you? How do you develop resilience for a career – rather than a quick fix?

Ciaran: A sustainable career isn’t built on intensity alone. It’s built on rhythm. What I see in a lot of high-performing tech professionals is cycles of overdrive followed by depletion. That might work for a product sprint, but it’s not a career strategy.

Sustainability comes from designing how you work. That includes clear boundaries around recovery and deliberate reflection, not just constant execution. An understanding of your own operating system such as when you perform best, how you make decisions, what drains you.

Resilience, in that sense, isn’t about pushing through. It’s about building a way of operating that allows you to keep showing up, at a high level, for years.

Our health data opportunity

Northern Ireland has a oncein-a-generation opportunity in health data. At the heart of it is Encompass — a unified digital health record for every person in Northern Ireland, and one of the most advanced health data systems in the world. Dr Michael Quinn — consultant nephrologist, clinical informatician, and Professor of Practice at Momentum One Zero — explains what it means, and what's at stake if we don't act on it.

q What does Encompass make possible that wasn't possible before?

Encompass means a person's clinical record finally follows them — GP referral, outpatient clinic, hospital admission, discharge — as a single coherent story. Most health systems don't have this. They have fragments — faxes, scanned letters, clinical memory.

What it makes possible: populationlevel visibility, real-time service planning, longitudinal research at scale, and the elimination of safety risks from clinicians making decisions without the full picture. It gives us a single source of truth for AI and decision support. Before Encompass, every digital health initiative in NI hit the same wall — fragmented data. That wall is gone.

q How does that translate into a more efficient health system in practice?

The infrastructure does three things. It removes friction — chasing results, repeating tests, hunting for letters. It enables proactive identification of patients before they deteriorate, shifting effort from acute to planned care. And it gives us operational data to plan capacity and understand demand at a system level, rather than trust by trust.

But infrastructure alone doesn't deliver efficiency. It has to be paired with workflow redesign, capability development, and governance that lets clinicians and managers act on what the data shows. The technology is necessary — it isn't sufficient.

q How real is the opportunity to turn NI's health data into an economic asset?

The opportunity is real and distinctive. 1.9 million people on a single EHR is rare anywhere in the world — a genuinely valuable asset for clinical trials, real-world evidence studies, and AI tool development.

What's needed is the trusted research environment, governance framework, and commercial model to work with the data safely and at speed. Genomics England, Finland's Findata, and Denmark's national infrastructure are useful comparators — none started with our advantage.

The risk is straightforward: if we

don't move now, the window closes. Our advantage is real but it isn't permanent.

q What's the most underexplored opportunity you see right now?

Two things. The nearest-term value is using Encompass data to run services better: demand forecasting, theatre utilisation, workforce planning, identifying patients drifting toward crisis. That's where data has the fastest impact on outcomes and financial sustainability.

The second is clinical AI evaluation. Tools are being deployed globally with limited real-world validation. NI's combination of a single record, an integrated commissioner-provider, and strong research base could make us where clinical AI is properly tested before it scales.

q If we get this right, what does healthcare in NI look like in ten years?

A health system that learns from itself. Where every patient encounter improves the care of the next. Where clinicians spend more time with people. Where a researcher in Belfast answers questions in weeks that currently take years — and where life sciences companies build here because the data, the governance, and the clinical partnerships make it the obvious choice.

Above all, a healthier population. The point isn't digital sophistication — it's people living longer, better lives, with a system sustainable for the next generation. The infrastructure is the means; healthcare worthy of the name is the end.

Dr Michael Quinn, Momentum One Zero
Northern Ireland's health data infrastructure is already ahead of most of the world. Momentum One Zero is here to make sure that advantage doesn't sit idle.

Upskill or reskill with university-accredited Microcredentials from Queen’s.

Turn static files into dynamic content formats.

Create a flipbook
Sync NI Magazine Summer 2026 by Sync NI - Issuu