Topic: ciso role

  • Agentic AI: A CISO's Identity Crisis and Accountability

    Agentic AI: A CISO's Identity Crisis and Accountability

    Agentic AI introduces a new, complex identity class that shatters traditional security assumptions, combining autonomous, decentralized operation with human-like intent and machine-scale persistence. These AI agents create severe security risks by multiplying existing identity vulnerabilities, su...

    Read More »
  • AI Adoption Fuels Surge in Critical Security Flaws

    AI Adoption Fuels Surge in Critical Security Flaws

    A significant surge in hardware, API, and network vulnerabilities is creating unprecedented risks, driven by IoT proliferation and resulting in an 88% increase in hardware flaws and a doubling of network vulnerabilities. The rapid integration of AI into software development is expanding the attac...

    Read More »
  • Why JLR’s CISO Mandated In-Person Password Resets After Cyber-Attack

    Why JLR’s CISO Mandated In-Person Password Resets After Cyber-Attack

    Jaguar Land Rover's former CISO Ashish Shrestha required over 30,000 employees to reset their passwords in person after a major cyber-attack, prioritizing security over convenience. The in-person resets allowed the security team to verify identities, educate staff on threats, and enforce stronger...

    Read More »
  • Downtime Drives Resilience Planning into Security Ops

    Downtime Drives Resilience Planning into Security Ops

    The core responsibility of CISOs is shifting from solely preventing attacks to ensuring business resilience, defined as the ability to maintain and rapidly restore operations during any disruption. Recovery from incidents like ransomware is consistently more costly and time-consuming than expecte...

    Read More »
  • 20% of Data Breaches Require Two Weeks to Recover

    20% of Data Breaches Require Two Weeks to Recover

    A major data breach can cripple business operations for up to two weeks and cost millions of dollars, highlighting the critical need for robust cyber-resilience strategies that prioritize rapid recovery. Despite increasing threats, organizational preparedness is declining, with fewer companies re...

    Read More »
  • Inside Google DeepMind Security: A CISO Chat with John 'Four' Flynn

    Inside Google DeepMind Security: A CISO Chat with John 'Four' Flynn

    Google DeepMind, under John Flynn's leadership since 2024, is a leading AI research organization focused on innovation and security, evolving from its 2010 founding and 2023 merger with Google Brain. Flynn's cybersecurity career was shaped by early tech fascination and exposure to unsafe environm...

    Read More »
  • What CISOs Must Tell the Board About Cyber Risk

    What CISOs Must Tell the Board About Cyber Risk

    CISOs must communicate cybersecurity risks in business terms, focusing on the board's risk oversight duty and how threats could impact the organization's risk appetite. Boards require a synthesized risk index from multiple data sources to understand event probabilities and their financial, operat...

    Read More »
  • Why CISOs Must Prioritize Intent in Identity-First AI Security

    Why CISOs Must Prioritize Intent in Identity-First AI Security

    AI agents are now active operators performing critical tasks like provisioning infrastructure and handling sensitive data, requiring a new security paradigm beyond traditional models that govern human access. A significant security gap exists because AI agents often inherit excessive privileges a...

    Read More »
  • How AI Is Fueling a New Era of Cyberattacks

    How AI Is Fueling a New Era of Cyberattacks

    The rapid integration of AI into business operations is creating new cybersecurity vulnerabilities, as attackers use the same tools to exploit expanded digital perimeters and overlook security measures in the rush for speed. Attackers are leveraging AI techniques like vibe coding and prompt-based...

    Read More »
  • Infosecurity Europe: Getting Boards to Prioritize Cyber Risk Quantification

    Infosecurity Europe: Getting Boards to Prioritize Cyber Risk Quantification

    Cyber executives are gaining board-level support for cyber risk quantification by translating technical threats into business language, using financial metrics like potential revenue loss, regulatory fines, and operational downtime rather than fear-based presentations. Building trust over time th...

    Read More »
  • Security Pros Demand Stricter Regulations, CIISec Reports

    Security Pros Demand Stricter Regulations, CIISec Reports

    69% of cybersecurity professionals advocate for stricter cybersecurity laws, citing that current regulations are inadequate against modern threats. Professionals identify NIS2, DORA, and the UK Cyber Security and Resilience Bill as having the most significant impact on the field, despite some not...

    Read More »
  • Half of UK manufacturers lack cyber incident response plans

    Half of UK manufacturers lack cyber incident response plans

    Nearly one in three UK manufacturers (30%) experienced a cyber incident in the past year, yet the sector's cyber resilience is immature, with only 51% having an incident response plan and just 23% employing a dedicated chief information security officer. Cyber incidents cause significant operatio...

    Read More »