Blog

Security Obligations Under GDPR Still Apply, Even if Data Is Anonymous in the Hands of an Attacker

UK Court of Appeal ruled in DSG Retail v. Information Commissioner that GDPR security obligations remain for controllers even if data is anonymous to attackers. The decision emphasizes the broad nature of “personal data” and the need for controllers to protect against unauthorized access, regardless of how data may appear to a third party. This ruling challenges prior interpretations that could diminish data protection responsibilities. It suggests that GDPR accountability may extend beyond the direct data handling by the controller.

https://iapp.org/news/a/security-obligations-under-gdpr-still-apply-even-if-data-is-anonymous-in-the-hands-of-an-attacker

In the AI Era, CISOs Worry About Data Leaks and Doubt Tech Will Solve Skills Gaps

CISOs recognize the need for AI but express concerns about risks, particularly data leaks and skills gaps. Despite AI's adoption in security, only mixed results are reported, with many affirming the technology won't resolve workforce shortages. Key worries include AI model hallucinations and regulatory challenges. Splunk's report recommends CISOs focus on clear AI governance and collaboration to integrate security into business strategy.

https://www.cybersecuritydive.com/news/in-the-ai-era-cisos-worry-about-data-leaks-and-doubt-tech-will-solve-skill/812964/

How to Get AI Democratization Right

The article discusses AI democratization, emphasizing CIOs' roles in enabling business users to harness AI responsibly while balancing innovation with governance to prevent security risks and operational inefficiencies. Effective strategies involve fostering AI literacy, establishing governance frameworks, and adapting change management practices to maximize AI integration and impact across organizations.

https://www.cio.com/article/4136302/how-to-get-ai-democratization-right.html

AI Won’t Break Microsoft 365. Your Security Backlog Will

TLDR: AI attackers exploit existing configuration backlogs in Microsoft 365, targeting long-neglected security settings rather than zero-day vulnerabilities. With rapid deployment of AI technologies and common misconfigurations across tenants, risks escalate while defenders struggle to keep up, emphasizing the need for immediate action on known security gaps.

https://thehackernews.com/expert-insights/2026/02/ai-wont-break-microsoft-365-your.html

AI Isn’t Failing, People Are Failing With AI

The article emphasizes that AI failures stem from improper application rather than from the technology itself, highlighting the importance of domain expertise and understanding model operations. It distinguishes between the effectiveness of models like BERT and GPT, advocating for a risk-based framework in deploying AI to manage industry-specific challenges and data utilization. Successful AI transformation relies on organizational fluency with technology and strategic planning.

https://www.cio.com/article/4135361/ai-isnt-failing-people-are-failing-with-ai.html

6 Strategies for Accelerating IT Modernization

Modernization of IT systems is crucial for businesses, with CIOs prioritizing upgrades to legacy systems amid pressure to innovate. Key strategies for faster modernization include leveraging AI to enhance processes, adopting managed services and serverless architectures, fostering a culture focused on modernization, clarifying roles and responsibilities, and implementing modular IT architecture for flexibility. These strategies can accelerate the transition to modern IT infrastructures, enabling organizations to innovate efficiently.

https://www.cio.com/article/4135451/6-strategies-for-accelerating-it-modernization.html

Open-Weight AI Models Fail the Jailbreak Test

Cisco’s State of AI Security report found that open-weight AI models are highly vulnerable to multi-turn jailbreak attacks, with a 92.78% success rate. These attacks, which use iterative prompts to bypass content filters, highlight the need for improved AI security measures. The report also emphasizes the risks associated with excessive agency in AI systems, particularly when they are granted broad autonomous authority over tools and data.

https://www.databreachtoday.com/open-weight-ai-models-fail-jailbreak-test-a-30823

The Biggest AI Fails of 2025: Lessons From Billions in Losses

2025 saw significant AI failures despite high global spending. Major examples include Volkswagen’s Cariad, which incurred $7.5 billion in losses from a rushed transformation and poor integration, and Taco Bell's AI, which faced public ridicule and operational chaos due to edge case mishandling. Other notable failures include Google’s AI producing false information, a $25 million deepfake scam at Arup, and issues leading to class-action lawsuits against UnitedHealth. Common lessons highlight the importance of starting small, ensuring human oversight, and auditing AI vendors for security. Businesses need to learn from these mistakes to implement AI effectively without repeat failures.

https://www.ninetwothree.co/blog/ai-fails

Building Pro-worker AI

Brookings identifies AI's potential to enhance worker capabilities through pro-worker technologies, categorizing them into five types: labor-augmenting, capital-augmenting, automating, expertise-leveling, and new task-creating technologies. While new task-creating tech is clearly beneficial for workers, automating tech is not. Pro-worker AI is underdeveloped due to firms prioritizing automation for economic returns. To promote pro-worker AI, policies should focus on health care and education, foster competition, encourage worker input, and create a supportive legal environment for worker ownership of skills.

https://www.brookings.edu/articles/building-pro-worker-ai/

The CISO Diaries February 2026 Report: The Security Priorities That Actually Move The Needle

CISO Diaries February 2026 report emphasizes evolving security priorities: trust shifts from perimeters to identity, supply chain risks now central, AI enhances integrity checks, response speed is crucial, and fundamental controls yield high returns. Security culture and incentives matter, while security teams increasingly oversee automation. Future focus: reducing reliance on perimeter defenses and manual operations.

https://cisowhisperer.com/the-ciso-diaries-february-2026-report-the-security-priorities-that-actually-move-the-needle/

Scroll to Top