Shadow AI Solutions Need a Unified Security Approach

Shadow AI presents a significantly greater enterprise risk than the previous shadow IT challenges, as employees' unsanctioned use of generative AI tools leads to compliance, data leakage, and regulatory penalties risks. Fortinet's executive Russ Schafer highlights the need for unified security platforms incorporating agentic AI to reduce attack resolution times from hours to seconds, emphasizing governance, access management, and interconnected agent frameworks to maintain control and security in AI-driven environments.

https://siliconangle.com/2026/03/30/shadow-ai-needs-unified-security-approach-rsac26/

The AI Revolution: Getting Culture Right for AI Success

The article discusses the critical role of fostering a balanced AI culture in enterprises to unlock AI's transformative potential. It emphasizes empowering employees through training and hands-on experience while ensuring governance to manage AI risks, addressing fears and skepticism about AI adoption, and tailoring AI education to different career levels. Leaders highlight that widespread, guided AI experimentation combined with effective governance and measuring ROI will drive innovation and competitive advantage as AI rapidly evolves and becomes integral to business operations.

https://www.cio.com/article/4146677/the-ai-revolution-getting-culture-right-for-ai-success.html

Teleport Report Finds Over-Privileged AI Systems Linked to Fourfold Rise in Security Incidents

A report by Teleport found that enterprises granting excessive access permissions to AI systems experience 4.5 times more security incidents than those restricting AI access, highlighting identity management's lag behind AI adoption. Based on interviews with 205 security leaders, the study shows that broad AI access correlates with higher incident rates, often due to static credentials and lack of automated governance controls, emphasizing the need for unified, machine-speed identity management to mitigate risks.

https://www.infoq.com/news/2026/03/teleport-ai-report/

Watch Your Words: Tim Brown’s Advice for CISOs

Tim Brown, former CISO of SolarWinds, shared insights at RSAC 2026 about the 2020 SolarWinds supply chain attack and his personal experience as the first CISO indicted in a civil lawsuit by the SEC for alleged fraud related to cybersecurity disclosures. Brown highlighted how excessive communication and misunderstood internal language during the ensuing SEC investigation led to legal challenges, emphasizing the critical need for clear communication policies and cautious internal messaging to prevent misinterpretation and legal risks in cybersecurity incident management.

https://www.techtarget.com/searchsecurity/feature/Watch-your-words-Tim-Browns-advice-for-CISOs

Why Cybersecurity’s Uncertainty Problem Is Getting Worse

Cybersecurity faces increasing uncertainty, with leading cryptographers unable to agree on the greatest threats. Paul Kocher, a cryptography researcher, warns that AI will accelerate the discovery of vulnerabilities in protocols and implementations, posing a significant threat to cybersecurity.

https://www.govinfosecurity.com/cybersecuritys-uncertainty-problem-getting-worse-a-31232

Ransomware and Phishing Still Drive Data-Security Incidents, But AI’s Shadow Looms

The 12th annual Data Security Incident Response Report by law firm BakerHostetler reveals that ransomware demands averaged $4.24 million last year, rising 70%, while phishing caused 30% of data-security incidents. The report highlights AI's growing role in cyberattacks, evolving beyond phishing enhancement to sophisticated social engineering and automated hacking, signaling a significant shift in the cybersecurity landscape.

https://www.digitaltransactions.net/ransomware-and-phishing-still-drive-data-security-incidents-but-ais-shadow-looms/

Understanding Passkeys

The article explores the concept of passkeys as a modern authentication method based on cryptographic key pairs managed by authenticators, offering benefits like phishing resistance, improved security, and ease of use over traditional passwords. It clarifies common misconceptions, such as the risk of being locked out if a device is lost and how passkeys relate to two-factor authentication, and shares personal experiences using passkeys with various services, highlighting both usability and security considerations. Ultimately, the author advocates for adopting passkeys—especially via password managers—as a convenient and secure replacement for passwords and encourages better security hygiene.

https://marending.dev/notes/passkeys/

The CISO’s Guide to Responding to Shadow AI

The article provides a guide for Chief Information Security Officers (CISOs) on responding to shadow AI, emphasizing four key steps: assessing the associated risks, understanding the motivations behind unapproved AI use, deciding whether to shut down or integrate shadow AI tools, and reviewing AI governance policies. It highlights that shadow AI usage often arises from the rapid adoption of AI tools without proper oversight, posing risks such as data breaches and operational disruptions, and stresses the importance of balanced governance to manage these risks while fostering responsible AI use within organizations.

https://www.csoonline.com/article/4143302/the-cisos-guide-to-responding-to-shadow-ai.html

AI Sovereignty Risk: a Five-Step Agenda for CIOs

The article discusses the growing importance of AI sovereignty, where nations control AI ecosystems within their borders, posing challenges for global CIOs. It outlines a five-step agenda for CIOs to manage AI sovereignty risks, including educating executives, consulting legal experts, balancing AI providers, securing data, and anticipating architectural shifts toward hybrid AI models. This approach helps organizations navigate complex regulatory environments and align AI strategies with jurisdictional compliance and enterprise goals.

https://www.idc.com/resource-center/blog/ai-sovereignty-risk-a-five-step-agenda-for-cios/

Transforming Diverse Experiences Into a Storied CIO Career

Denise Russell Fleming, CIO and EVP of technology and global services at BD, shares insights from her diverse career spanning business, marketing, customer support, and IT that uniquely positioned her to lead large-scale transformations. Highlighting the importance of trust, collaboration, and a growth mindset, Fleming discusses her journey to the CIO role, experiences with complex initiatives, and advice for CIOs aspiring to board service, emphasizing that effective leadership in technology is deeply rooted in understanding both people and business.

https://www.cio.com/article/4148293/transforming-diverse-experiences-into-a-storied-cio-career.html

Scroll to Top