Hi! I’m Philip Hall, a Sydney-based cyber security practitioner working at the intersection of artificial intelligence, cyber security and automation.
I have worked in technology for more than 30 years and in cyber security since the early 2000’s. My career has taken me through web development, infrastructure, virtualisation, cloud architecture, enterprise security architecture, consulting, cyber operations, threat intel, assurance and security awareness.
Today, my focus is Cyber AI and Automation: how artificial intelligence can improve cyber defence, how attackers will exploit it, and how organisations can adopt increasingly autonomous technology without losing control of their security, accountability or judgement.
Experience before the AI hype
My interest in artificial intelligence did not begin with the sudden popularity of generative AI.
Throughout my career, I have been drawn to emerging technology and its practical application. I want to understand how technology works, experiment with it directly and determine whether it can solve a real problem.
Cyber security has taught me to look beyond promises and demonstrations. New technology needs to work under pressure, withstand misuse and produce outcomes that people can trust.
Since entering cyber security in 2008, I have worked across architecture, cloud security, cyber operations, intelligence, incident response, assurance and awareness. This breadth helps me examine AI from several perspectives: technical capability, attacker behaviour, operational value, organisational risk and human impact.
I have also spent years translating complex security issues into practical advice for executives, boards, technology teams and people outside the security profession. That ability is becoming even more important as AI moves from experimental tools into business processes and critical decisions.
Where cyber security and AI now meet
Artificial intelligence is changing cyber security from both directions.
Defenders can use AI to analyse information, automate repetitive work, improve prioritisation and respond more quickly. Attackers can use the same capabilities to increase the speed, scale and sophistication of their operations.
AI agents introduce an even greater shift. These systems can be given memory, tools, credentials and permission to take actions across enterprise environments. That creates enormous potential, but it also creates new forms of risk.
An AI assistant that generates text is one thing. An autonomous agent that can access email, modify files, call APIs, write code or interact with production systems is something very different.
My current work examines how organisations can use these capabilities effectively while maintaining appropriate security controls, human oversight, auditability and accountability.
A hands-on approach to AI
I do not want to be another commentator repeating AI announcements or predicting that every new model will change the world.
I experiment with AI directly. I build prototypes, test models, explore agents, create automations and examine how these systems behave when they are given access to real tools and information.
That hands-on work informs my writing. I am interested in what the technology can genuinely do, where it fails, what risks are being overlooked and what organisations should do next.
I am optimistic about AI, but optimism should not require blind trust. Responsible AI adoption is not about stopping innovation. It is about making innovation sustainable, secure and worthy of confidence.
What I write about
This website focuses on subjects including:
- Cyber AI and security automation
- AI agents and autonomous-system security
- AI-enabled cyber threats and attacker behaviour
- Responsible and practical AI adoption
- AI governance, assurance and accountability
- Major cyber incidents and the lessons behind them
- Emerging technology that could materially affect organisations
- Digital risk, security leadership and decision-making
My aim is to separate meaningful developments from noise and explain why they matter in direct, understandable language.
I will not pretend to have certainty where certainty does not exist. I will distinguish between confirmed facts, reasonable analysis and speculation. When an AI announcement is genuinely important, I will explain why. When it is mostly marketing, I will say that too.
Who this website is for
I write for cyber security professionals, technology leaders, executives, policymakers and people trying to understand how AI will affect their organisations and careers.
You do not need to be an AI researcher or security engineer to follow the analysis. My goal is to make technically complex developments understandable without removing the detail that makes them useful.
The most important questions are rarely limited to what a technology can do. We also need to ask:
- What problem does it solve?
- What new risks does it create?
- Who remains accountable for its decisions?
- What access and authority should it receive?
- How do we recognise when it fails?
- What should leaders be doing now?
Looking ahead
The next phase of cyber security will be shaped by systems that can reason, act and operate at machine speed.
Our challenge is not merely to adopt them. It is to ensure they remain useful, accountable and secure.
Technology will continue to move quickly. Sound judgement, practical experience and human responsibility will matter more than ever.
That is the perspective I bring to this website.
Read my latest articles for practical analysis of Cyber AI, automation, artificial intelligence and the emerging risks shaping our digital future. You can also connect with me on LinkedIn for new articles, commentary and professional discussion.


