<p>In today’s enterprise, some degree of cyber-risk exposure is inevitable. CISOs must use limited resources to <a href=”https://www.techtarget.com/searchsecurity/tip/Enterprise-risk-management-should-inform-cyber-risk-strategies”>strategically address the most significant risks</a>, in alignment with their organizations’ <a href=”https://www.techtarget.com/searchsecurity/feature/How-to-define-cyber-risk-appetite-as-a-security-leader”>cyber-risk appetites</a>.</p> <p>The easiest and fastest — but also least reliably…
Tag: Search Security Resources and Information from TechTarget
Lost in translation: Cybersecurity board reporting for CISOs
<p>Hundreds of security leaders from across industries recently packed a ballroom in National Harbor, Md., to tackle a challenge some consider even more daunting than nation-state hackers or AI-fueled cyber threats: presenting to a company’s board members so they understand…
Gartner Security & Risk Management Summit 2026: Adapting for AI
<p>The Gartner Security & Risk Management Summit gathers CISOs, business leaders and decision-makers with Gartner analysts to explore the current and future state of cybersecurity.</p> <p>This year’s Summit is being held June 1-3, 2026, at the Gaylord National Resort and…
How to prepare security controls for future AI regulations
<p>The global AI regulatory landscape is fragmented and volatile. As a result, cybersecurity leaders must reconcile competing compliance requirements and safeguard organizational AI without creating roadblocks to the overall AI strategy’s success.</p> <p>While the EU AI Act imposes a comprehensive,…
EO 14390 raises stakes for enterprise cybersecurity
<p>For years, federal cybersecurity policy has primarily focused on protecting government systems and critical infrastructure. Executive Order 14390: “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens” signals a broader shift in emphasis. Signed on March 6, 2026, the order…
First month of Mythos Preview testing exposes 10K flaws
<p>Organizations using Claude Mythos have discovered thousands of vulnerabilities in the first month of security testing under Project Glasswing, per an announcement from Anthropic last week.</p> <p>The project, initially announced on April 7, granted preview access of Mythos to about…
How to secure data at rest, in use and in motion
<p>Data security is a non-negotiable strategic imperative cloaked with business implications for risk management and competitive advantage.</p> <p>Organizations today face ever-increasing cybersecurity risks — both internal and external. Safeguarding data against financial losses, regulatory penalties and reputational damage is not…
OT attacks shift from recon to physical control, raising stakes
<p>In the Netflix thriller <i>Leave the World Behind, </i>a massive cyberattack plunges the U.S. into a complete electrical and technological blackout. While the scope and scale of the fictional attack are improbable, research suggests real-world malicious hackers are increasingly interested…
For CISOs, dawn of OpenAI Daybreak brings good and bad news
<p>The recent debut of OpenAI’s Daybreak means security leaders are waking up to a new reality: Artificial intelligence is no longer merely supporting cyberdefense but driving it.</p> <p>Accessible now to verified organizations and security teams, <a href=”https://openai.com/daybreak/”>Daybreak</a> combines OpenAI’s GPT-5.5…
Gartner Security & Risk Management Summit 2026: Adapting for AI
<p>The Gartner Security & Risk Management Summit gathers CISOs, business leaders and decision-makers with Gartner analysts to explore the current and future state of cybersecurity.</p> <p>This year’s Summit is being held June 1-3, 2026, at the Gaylord National Resort and…
Inside business email compromise attack: Real-world examples
<p>Business email compromise attacks have become some of the most costly and damaging threats facing organizations today. BEC attacks differ from traditional phishing schemes in that they rely on highly targeted social engineering tactics that exploit human psychology rather than…
Verizon 2026 DBIR: 6 key takeaways for CISOs
<p>The threat landscape is undergoing rapid and unprecedented change, as reflected in the “Verizon 2026 Data Breach Investigations Report.” For the first time in the report’s 19-year history, vulnerability exploitation was the leading initial access vector, displacing credential abuse from…
Identity security for AI agents: The proliferation challenge
<p>AI agents are proliferating across the enterprise, with use cases ranging from IT and security operations to legal and compliance tasks.</p> <p>Omdia, a division of Informa TechTarget, <a target=”_blank” href=”https://research.esg-global.com/reportaction/515202205/Marketing” rel=”noopener”>published</a> the results of a survey of 400 security leaders…
How to build a business impact analysis checklist
<p> <!– CONTENT COMPONENT :74294–></p> <p>Business impact analysis is key to developing an effective and comprehensive business continuity and disaster recovery plan.</p> <p>The business impact analysis (<a href=”https://www.techtarget.com/searchstorage/definition/business-impact-analysis”>BIA</a>) process involves identifying all potential threats and vulnerabilities to the business in…
Taking care of business: The CISO’s role in a cyber crisis
<p>The role of the chief information security officer is pivotal — and constantly evolving. Today’s CISOs are responsible for all aspects of cybersecurity planning, prevention and management, and must also be attuned to the needs of the business.</p> <p>Increasingly, the…
What CISOs need to know about AI audit logs
<p>AI is reshaping the application landscape, seemingly overnight. A recent Google Cloud <a target=”_blank” href=”https://services.google.com/fh/files/misc/google_cloud_roi_of_ai_2025.pdf” rel=”noopener”>survey</a> of 3,466 senior business leaders found 77% of organizations are increasing spending on generative AI, with the vast majority already reporting ROI on at…
SOC vs. MDR: What CISOs need to consider
<p>Every modern organization must monitor its networks continuously and respond to suspicious or malicious activity quickly and effectively. Two basic options exist: an in-house security operations center or a managed detection and response service. Some organizations use both.</p> <p>Let’s examine…
Instructure cyberattack reignites ransom payment debate
<p>Following a massive cyberattack on its popular Canvas learning management system, education software provider Instructure said it had struck a deal with malicious hackers to recover its stolen data. Instructure did not disclose the terms of the deal, but experts…
Transform SIEM rules with behavior-based threat detection
<p>Modern organizations invest heavily in SIEM systems to centralize security data across disparate platforms. They are an important cybersecurity component, yet still miss critical threats, often leaving organizations unaware and exposed. That leads to breaches, prolonged attacker dwell times and…
CISO’s guide: How to test an incident response plan
<p>An incident response plan helps mitigate unexpected and potentially disruptive cybersecurity events. Testing that plan is very much like test-driving a new car. It’s how a potential buyer confirms the experience lives up to the hype. Do all the features…