Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Laboratory thwarts insider threat with Darktrace AI

Security

Laboratory thwarts insider threat with Darktrace AI

A leading laboratory specialising in vitro diagnostics has successfully stopped an insider threat with the help of Darktrace's self-learning AI.

Image courtesy Darktrace

The company, which has laboratories, offices and distribution centres in over 100 countries worldwide and more than 3,000 employees, specialises in the research, development and manufacturing of innovative in vitro diagnostic tests for disease, conditions and infections. The organisation uses Darktrace's detect, respond and investigate capabilities to defend against in-progress attacks at the early-stages.

Advertisement
ODU RT

Powered by Self-Learning AI, Darktrace technology develops an understanding of normal operations for the company. From this understanding it can then autonomously interrupt in-progress attacks at every stage from the initial entry with sophisticated spearphishing emails to brute-forced remote desktop protocol (RDP), command-and-control, and lateral movement, all without business disruption.

In one instance, Darktrace's Self-Learning AI detected an internal device communicating with the Tor network via an intermediary web service. Tor is an open-source privacy network that enables anonymous web browsing by guiding data traffic through different servers, located all over the world. Whilst it is not wholly malicious, it can be associated with the browsing of non-business or even illegal content.

The device was connecting with a darknet forum relating to the pharmaceutical market. Given that no other device within the organisation had visited the Tor network in the past, Darktrace AI flagged this to the security team as out-of-the-ordinary. With the AI taking care of early detection and making micro-level decisions the security team were uplifted and able to make important decisions that required business context.

The internal security team later found that this was likely an insider looking to sell proprietary intellectual property or even medical supplies on the darknet.

"Malicious or compromised insiders can be difficult to identify because their privileged access and knowledge of company workings allows them to evade detection by traditional security tools," commented Toby Lewis, Global Head of Threat Analysis, Darktrace. "In order to protect intellectual property from insider threat, organizations need to augment security teams with AI-powered technology to stop malicious activity in real time at the moment of detection."

Advertisement
PTC rectangle

 

 

Advertisement
ECS leaderboard banner
Viasat and Galaxy 1 to enhance Velaris

Aerospace Security Space

Viasat and Galaxy 1 to enhance Velaris

3 March 2026

Galaxy 1 Communications is working with Viasat to enhance delivery of Velaris, Viasat’s dedicated satellite communications service for Uncrewed Aerial Vehicles (UAVs) and Advanced Air Mobility (AAM) aircraft.

Cyacomb introduces Similarity Matching

Security

Cyacomb introduces Similarity Matching

3 March 2026

Edinburgh based digital triage experts, Cyacomb, today announced the availability of a new Similarity Matching capability within its Examiner Plus platform, enabling law enforcement to identify Child Sexual Abuse Material (CSAM) on mobile devices in minutes, even when images have been shared via messaging applications and altered from their ...

Atos UK&I launches Sovereign MXDR

Security

Atos UK&I launches Sovereign MXDR

2 March 2026

Atos, a specialist in AI-powered digital transformation, today launched a Sovereign Managed eXtended Detection and Response (MXDR) service specifically designed for UK government, critical infrastructure, financial services and other UK organisations requiring stringent data sovereignty and regulatory compliance.

Finland in UK to showcase space capabilities

Defence Security Space Events

Finland in UK to showcase space capabilities

26 February 2026

This week Finland brought together senior UK defence and aerospace stakeholders at the Finnish Ambassador’s Residence in London for a high-level strategic dialogue focused on Earth Observation (EO), Positioning, Navigation and Timing (PNT) and resilient space-enabled situational awareness.

Advertisement
Security & Policing Rectangle
UK Government launches new VMS and Cyber Profession

Security

UK Government launches new VMS and Cyber Profession

26 February 2026

The UK Government has launched a new vulnerability monitoring service (VMS) to reduce cyber risks and speed up fixes and a new Cyber Profession to build long-term resilience across public services.

Southend Airport unveils C3 screening equipment

Aerospace Security

Southend Airport unveils C3 screening equipment

24 February 2026

Passengers at London Southend Airport can now leave liquids up to two litres in their cabin baggage, as the award-winning airport unveils new security equipment.

Advertisement
ODU RT
Advertisement
ECS leaderboard banner