Tag: ciso
-
National Life Group CISO expects more vulnerabilities in six months than in thirty years
In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/becky-palmer-national-life-group-ai-driven-cyber-threats/
-
Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud
Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/anthropic-enterprise-frontier-safeguards/
-
CISO role evolves with cyber resilience, AI integration
First seen on scworld.com Jump to article: www.scworld.com/news/ciso-role-evolves-with-cyber-resilience-ai-integration
-
What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/31/joye-purser-cohesity-kev-epss-cvss-conflicts/
-
How Security Buyers Actually Buy: The Committee, The Triggers, and The Quiet Veto
Most cybersecurity vendors sell to the CISO and lose the deal to a security engineer they never spoke to. Security purchases are committee decisions with an asymmetric structure: many people can kill a deal, few can approve one. Here is how it actually works. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-security-buyers-actually-buy-the-committee-the-triggers-and-the-quiet-veto/
-
What 90 days and a small budget can buy in AI agent security
In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/28/prasad-tharippala-versa-securing-ai-agents/
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
Kryptoagilität macht aus der Umstellung auf Post-Quanten-Kryptografie einen planbaren Dreijahresprozess
Die Umstellung auf Post-Quanten-Kryptografie ist kein spätes Technikprojekt für Spezialisten, sondern eine Managementaufgabe mit festen Fristen. Wer jetzt Krypto-Inventar, Priorisierung und Lieferantensteuerung aufsetzt, macht aus einer schwer kalkulierbaren Bedrohung einen planbaren Transformationsprozess. Der Beitrag zeigt, warum Kryptoagilität für Unternehmen wichtiger wird als die einmalige Wahl eines neuen Algorithmus und wie CIO, CISO und Einkauf die……
-
Production data in testing is still common, and Tricentis’ CISO wants it gone
In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/erika-dean-tricentis-production-data-in-testing/
-
How ‘Subtractive’ Security Erases Attack Paths
Chris Frenz, Rectangle Health CISO, on Reducing Risk From Attackers in Healthcare. Healthcare security teams can reduce cyber risk by removing attacker options before an incident occurs rather than relying primarily on detection and response, said Chris Frenz, CISO at Rectangle Health, describing a new subtractive-hardening architecture standard he developed for OWSAP. First seen on…
-
After Mythos: When the Attacker Doesn’t Need to Log In
AI Agents Are Rewriting Attack Economics, CISO Risk and Enterprise Defense For years, the attacker’s problem was access. Steal a credential, find an open port and wait. Today, increasingly, the attacker’s problem is simply asking an AI model the right question. That change was the real topic at a recent roundtable of CISOs and Microsoft…
-
After Mythos: When the Attacker Doesn’t Need to Log In
AI Agents Are Rewriting Attack Economics, CISO Risk and Enterprise Defense For years, the attacker’s problem was access. Steal a credential, find an open port and wait. Today, increasingly, the attacker’s problem is simply asking an AI model the right question. That change was the real topic at a recent roundtable of CISOs and Microsoft…
-
Top 5 Cross-Mapping Standards for Risk Management at Continuum GRC
Cross-mapping standards has emerged as a critical strategy for organizations navigating overlapping regulatory requirements in 2026. By aligning controls across frameworks such as NIST SP 800-171 Rev 3 and CMMC 2.0, compliance officers can reduce redundant efforts while strengthening risk management programs. Continuum GRC specializes in these integrated approaches to help CISOs achieve efficiency without”¦…
-
CMMC Compliance Assessments: 6 Key Steps by Continuum GRC
CMMC compliance assessments represent a critical evolution in protecting controlled unclassified information (CUI) across the defense industrial base. As organizations navigate CMMC 2.0 requirements in 2026, understanding the nuanced differences between self-attestation and third-party assessments becomes essential for CISOs and compliance officers managing NIST SP 800-171 Rev 3 controls. Recent regulatory emphasis on rigorous cybersecurity”¦…
-
Data Privacy Regulations: Unified Compliance by Continuum GRC
Data privacy regulations continue to evolve rapidly, demanding that organizations adopt unified compliance approaches to manage overlapping requirements efficiently. Continuum GRC delivers integrated risk management solutions that align multiple frameworks while addressing the technical and organizational realities faced by CISOs and compliance teams. Why Unified Compliance Matters for Data Privacy Regulations Fragmented compliance efforts often”¦…
-
Quantum Masterclass: Cryptography’s Enterprise Blind Spot
IBM’s Jai Singh Arun on Mapping Cryptography Risk Before Quantum Threats. Cryptography has been invisible across most enterprises for many years. But CISOs can gain visibility into their cryptographic risk and prioritize a migration to quantum-safe standards ahead of 2030 regulatory deadlines, said Jai Singh Arun of IBM Quantum Safe. First seen on govinfosecurity.com Jump…
-
Masterclass Quantum: Cryptography’s Blind Spot in the Enterprise
IBM’s Jai Singh Arun on Mapping Cryptography Risk Before Quantum Threats. Cryptography has been invisible across most enterprises for many years. But CISOs can gain visibility into their cryptographic risk and prioritize a migration to quantum-safe standards ahead of 2030 regulatory deadlines, said Jai Singh Arun of IBM Quantum Safe. First seen on govinfosecurity.com Jump…
-
The CISO Doesn’t Own the Outcome: A Shared-Accountability Model for Security Decisions
Tags: cisoFirst seen on scworld.com Jump to article: www.scworld.com/practitioner-decision-guide/the-ciso-doesnt-own-the-outcome-a-shared-accountability-model-for-security-decisions
-
Identity Is the New Perimeter, AI Is Blowing It Wide Open
CyberEdBoard Webinar Panel to Explore Non-Human Identity Risks, AI Governance. Enterprises have never been able to fully secure human identities, but now CISOs are responsible for securing millions of non-human identities including AI agents, APIs, service accounts. Join this CyberEdBoard panel for perspectives on shadow AI, zero trust, legal issues and governance. First seen on…
-
CISOs Break Their Silence in ‘Declassified’ Docuseries
Million-dollar heists, divorce, and career-ending burnout are all stories told in the latest docuseries revealing a behind-the-scenes look at the cybersecurity community. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisos-break-their-silence-in-declassified-docuseries
-
10 Integrated Risk Management Strategies with Continuum GRC in 2026
Tags: business, ciso, compliance, control, cybersecurity, governance, grc, risk, risk-management, strategy, threatIn 2026, organizations face an increasingly complex threat landscape where siloed risk management approaches fail to address the interoperability demands of modern regulatory frameworks. Integrated Risk Management has emerged as the essential discipline for CISOs and compliance officers seeking to unify cybersecurity controls, audit processes, and business objectives under a single governance model. Continuum GRC”¦…
-
Tricentis macht KI-Sicherheit zur Chefsache: Erika Dean übernimmt CISO-Posten
Tricentis ernennt Erika Dean zur CISO. Sie verantwortet Cybersecurity, Produktsicherheit, Software Supply Chain und Governance rund um Agentic AI. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/tricentis-macht-ki-sicherheit-zur-chefsache-erika-dean-uebernimmt-ciso-posten/a46196/

