From malware to crime as a service
Ransomware as a service (RaaS), phishing as a service, deepfake as a service: cybercrime has been industrialised, and the barrier to entry has dropped sharply.
Two books written from the same conviction: artificial intelligence is no longer a tool you pick up, it is a layer of the environment. One looks at the defensive side; the other at everyday use. Neither asks for a technical background.
For two decades information security meant putting barriers in front of a human attacker. Today the attacker reasons, plans and executes with the same tools as the defender. That symmetry changes the whole problem, and understanding it matters as much to a security professional as to someone who just wants to use an assistant without giving away their data.
Ransomware as a service (RaaS), phishing as a service, deepfake as a service: cybercrime has been industrialised, and the barrier to entry has dropped sharply.
Prompt injection, model poisoning, abuse of agents with tools and persistent memory: attack surfaces that did not exist three years ago.
Zero Trust, phishing-resistant MFA with FIDO2 and passkeys, abuse of OAuth tokens and sessions. The perimeter stopped being the network a long time ago.
SBOM, open-source dependencies, SLSA and signing with Sigstore: protecting what you build also means protecting what you pull in without looking at it.
Post-quantum cryptography stops being an academic debate: what is encrypted today can be decrypted tomorrow if it was stored waiting for that moment.
Bias, hallucinations, limits and privacy. Getting value out of AI without becoming dependent on it is a skill, not a legal disclaimer in the footer.
A summary of the shift that Ciberseguridad y la Revolución de la IA follows chapter by chapter.
| Area | Before | Now |
|---|---|---|
| Phishing | Give-away language mistakes | Native-quality copy generated by an LLM in any language |
| Impersonation | Spoofed email | Real-time voice and video cloning |
| Detection | Signatures and rules | Agents that correlate XDR/SIEM telemetry and cut the noise |
| Response | Fixed playbooks | SOAR with agents that adapt the playbook and learn from the incident |
| Vulnerabilities | CVSS-based prioritisation | Real exploitability with EPSS and continuous threat exposure management (CTEM) |
| Threat model | Protect the network | Protect the models, the agents and their tools as well |
Two reading levels for two audiences that overlap more every year.
Protecting information in the age of autonomous agents
A full tour of the current state of AI-assisted cybersecurity: updated threat fundamentals, modern AI and its branches, what AI already does for the defence, the concrete techniques that improve information security, and the emerging risks the technology itself introduces.
It closes with a forward-looking roadmap towards a resilient, ethical ecosystem compatible with post-quantum cryptography.
Using Microsoft Copilot in your daily life
A book for a general audience, with no technical prerequisites, about getting value from Copilot in the three places where it shows most: home, work and school. It pairs clear explanations of the concepts with real use cases and ethical reflection.
It includes a practical prompting guide and an honest treatment of bias, limitations and privacy: empowering people without creating dependence.
The two books share a conceptual frame, but they do not assume the same starting point.
From technical analysis to business: which activities survive automation and which ones have their years numbered.