InformationWeek CIO Corner: Dun & Bradstreet CTO Mike Manos

Dun & Bradstreet CTO Mike Manos describes the company’s transition from a historical information-gathering business to a modern, cloud-first provider of data analytics. Manos, who joined in 2021, led a review of all business and IT operations, addressed technical debt, migrated infrastructure to the cloud, and invested in staff upskilling. He emphasized setting clear technology standards, focusing on essential needs, and assessing vendor ROI. The article offers more detail in the full interview and supplements with related industry content and resources.

https://www.informationweek.com/it-leadership/informationweek-cio-corner-dun-bradstreet-cto-mike-manos

The Essential Reading List for Today’s CIO

CIOs' Essential Reading List: IT leaders recommend seven crucial books for today's CIOs to enhance leadership, strategic thinking, and navigate advancements like AI. Key titles include Simon Sinek's Start with Why for understanding purpose, and Richard Rumelt's Good Strategy Bad Strategy for problem-solving frameworks. Other notable mentions are Radical Candor for communication, The Coming Wave and Life 3.0 for insights into technology's impact and risks. These readings aim to help CIOs lead transformative changes within their organizations.

https://www.techtarget.com/searchcio/feature/The-essential-reading-list-for-todays-CIO

10 AI Predictions For 2026: Top Experts Share New Trends

The EU Commission, aiming to ensure smooth and predictable implementation of the AI Act, is preparing a comprehensive set of guidelines for 2026. These will offer practical directions on high-risk classifications, transparency, reporting obligations, quality requirements, responsibilities, and more. Special focus will be on simplifying research exemptions and clarifying legal overlaps, particularly for product development in medicines and medical devices. The Commission will also provide templates and direct support channels for stakeholders.

https://www.forbes.com/sites/bryanrobinson/2025/12/04/10-ai-predictions-for-2026-top-experts-share-new-trends/

Phishing, Privileges and Passwords: Why Identity Is Critical to Improving Cybersecurity Posture

TLDR: Identity is crucial in cybersecurity; breaches at M&S and Co-op highlight vulnerabilities. Modern attacks exploit cloud and remote work. Protect identity through least privilege access, strong passwords, MFA, and active account management. Embrace Zero Trust and managed detection response for security.

https://www.welivesecurity.com/en/business-security/phishing-privileges-passwords-identity-cybersecurity-posture/

Death to One-time Text Codes: Passkeys Are the New Hotness

Passkeys revolutionize MFA, phasing out vulnerable one-time passwords. Passkeys replace passwords with cryptographic key pairs for stronger authentication, preventing phishing attacks. Major platforms like Apple and Google support them, demonstrating high adoption rates among organizations. Passkeys improve sign-in success rates and reduce helpdesk incidents, yet usability challenges persist, especially across different operating systems. Ultimately, they represent a significant advancement in secure online identity verification.

https://www.theregister.com/2025/12/06/multifactor_authentication_passkeys/

CISOs Should Be Asking These Quantum Questions Today

Quantum-inspired software is already being used in critical enterprise settings, often without security teams’ full awareness, because it integrates so smoothly with existing tools and workflows. Current cybersecurity frameworks and compliance processes fall short when dealing with quantum and post-quantum solutions, particularly as the risk of “harvest now, decrypt later” attacks grows—where encrypted data stolen today could be decrypted in the future using quantum computers. Organizations face three encryption approaches: maintaining current standards (with risk), adopting quantum-based encryption (still ultimately vulnerable), or implementing post-quantum cryptography (most robust). Industries such as defense and aerospace are early adopters, but mature quantum-specific security guidelines are lacking, leaving organizations with gaps until new playbooks are developed.

https://www.darkreading.com/cybersecurity-operations/cisos-should-be-asking-these-quantum-questions-today

CISA Publishes Security Guidance for Using AI in OT

Global cybersecurity agencies released new guidance on safely deploying AI in operational technology systems, citing the high risks involved. OT is essential for critical infrastructure, and integrating AI can introduce risks such as model drift, safety bypasses, and process instability. Agencies urge thorough education on AI risks, a careful assessment of when to use AI, strong data controls, and transparent governance. Recommendations also emphasize the importance of monitoring and fail-safe processes, including human oversight. Experts note that while AI may enhance efficiency, its use in OT should be limited and highly disciplined, especially with high-risk models like large language models.

https://www.darkreading.com/cybersecurity-operations/cisa-publishes-security-guidance-ai-ot

Threat Landscape Grows Increasingly Dangerous for Manufacturers

Manufacturers remain the top target for cybercriminals in 2025, primarily due to security gaps, lack of expertise, and slow adoption of protective measures. Over half paid ransoms and faced high recovery costs, with ransomware attacks causing notable shutdowns and billions in losses. This year, exploited software vulnerabilities became the leading cause of breaches. The rise of AI and automation is boosting manufacturing efficiency but also increasing cybersecurity risks and creating new attack surfaces. Experts warn that the threat landscape will continue to worsen, especially as IT and OT environments merge and geopolitical issues persist.

https://www.darkreading.com/cyberattacks-data-breaches/threat-landscape-increasingly-dangerous-manufacturers

Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks

Summary: Russian threat actors are targeting organizations via phishing attacks that impersonate legitimate European security events, using Microsoft 365 OAuth and Device Code workflows to steal credentials. Techniques include rapport-building conversations, fake professional websites, and communication through messaging apps. Notable campaigns include the Belgrade Security Conference and Brussels Indo-Pacific Dialogue, with attackers expanding their target lists through responses. Indicators and investigative assistance are offered for potential victims.

https://www.volexity.com/blog/2025/12/04/dangerous-invitations-russian-threat-actor-spoofs-european-security-events-in-targeted-phishing-attacks/

Scroll to Top