cybersecurity

Living Risk Registers Help Security Leaders Prioritize Real Risk Over Compliance Theater

Living risk registers prioritize real cyber resilience by integrating compliance into risk management. Ann Dunkin advocates for a quarterly review process quantifying non-compliance consequences, aligning security with daily decision-making. Compliance traps often arise from structural flaws in funding and mandate authority. Effective cybersecurity requires collaboration between CIOs and CISOs, focusing on a team's culture and flexible incident response. As AI advancements create more complex risks, organizations must adapt strategies to safeguard against evolving threats.

https://www.thesecuritydigest.com/news/living-risk-register-compliance-ann-dunkin-georgia-tech

AI in the Middle: Turning Web-Based AI Services Into C2 Proxies & The Future Of AI Driven Attacks

AI services like Grok and Microsoft Copilot can be exploited by attackers as covert command-and-control (C2) proxies, blending malicious traffic with legitimate communications. This technique allows AI-driven malware to dynamically adapt its behavior based on real-time context from infected systems, potentially making it harder to detect. Check Point Research (CPR) details methods for achieving this, including the use of web interfaces to relay commands and data without traditional authentication barriers. The research outlines the evolving landscape of AI-driven threats, predicting a shift towards adaptive, context-aware malware that could significantly enhance the precision and speed of cyberattacks. Defensive strategies need to evolve alongside these threats, emphasizing monitoring and securing AI service interactions against abuse.

https://research.checkpoint.com/2026/ai-in-the-middle-turning-web-based-ai-services-into-c2-proxies-the-future-of-ai-driven-attacks/

CISO Julie Chatman Offers Insights for You to Take Control of Your Security Leadership Role

Challenges for CISOs:

  • Awareness: Difficulty in making stakeholders recognize the importance of security.
  • Funding: Budget requests are often seen as unnecessary until breaches occur.
  • AI Threats: Adapting to AI-enabled adaptive attacks.
  • Liability: Personal accountability without matching authority can deter talent.

Advice for CISOs:

  • Negotiate liability protection and communicate risks clearly.
  • Build budgets to reflect varying levels of needed security investment.
  • Stay updated on AI developments and enhance training to address new threats.
  • Foster a culture of open communication for reporting security concerns.

Key Insights:

  • Emphasizes understanding and leveraging business language in cybersecurity.
  • Encourages CISOs to foster a collective risk-ownership mindset.

https://www.csoonline.com/article/4131130/ciso-julie-chatman-wants-to-help-you-take-control-of-your-security-leadership-role.html

Security at AI Speed: The New CISO Reality

CISO roles have evolved due to AI, shifting focus to accountability and managing hybrid teams of humans and AI. Security leaders must adapt to automation providing insights while remaining responsible for outcomes. Compromises in security are often necessary for business objectives, and quantifying cyber risks can mislead strategy. Evaluation of security products now prioritizes machine-speed operation and organizational impact over traditional features. Organizations must recognize the risks of vendor reliance, ensuring contingency plans for potential failures. Adaptation to AI-driven capabilities is crucial for maintaining security in a rapidly changing landscape.

https://www.helpnetsecurity.com/2026/02/16/john-white-torq-agentic-ai-security/

The Uncomfortable Truth About “More Visibility”

In 2025, organizations faced escalating cyber threats, with a weekly average of 1,968 attacks, an 18% year-over-year surge. Attackers are employing advanced techniques like ClickFix, leading to human-triggered attacks instead of traditional malware delivery. Concurrently, insufficient patching and unmanaged exposures foster vulnerabilities, emphasizing the need for Exposure Management as a proactive operating model. Key trends reveal gaps in action, shifting social engineering, volatile ransomware strategies, and reduced time-to-exploitation. The focus should be on actionable remediation rather than detection alone, advocating for safe, continuous exposure reduction to effectively combat modern threats.

https://thehackernews.com/expert-insights/2026/02/the-uncomfortable-truth-about-more.html

The Shadow AI Workforce: When Employees Go Rogue With Tech

Employees are using AI tools without official sanction, creating a “shadow AI workforce” that poses risks in data security and compliance. This trend emerged alongside the rise of generative AI tools, reflecting employees' desire for efficiency. HR must address this issue proactively by establishing clear AI policies, promoting safe usage, and fostering open communication about AI use. Ignoring or punishing this behavior can stifle innovation; instead, organizations should leverage it for strategic advantage by providing proper guidelines and training.

https://www.hrkatha.com/features/hr-pops-features/the-shadow-ai-workforce-when-employees-go-rogue-with-technology/

Cybersecurity Spending May Pay Off: Study Links Readiness to Stronger Returns

A study by Binghamton University found that companies with strong cybersecurity readiness and transparency about cyberattacks perform better financially. The study analyzed conference call transcripts from top U.S. public companies to gauge how cybersecurity risks were discussed and their impact on market valuation. The findings emphasize the importance of acknowledging and addressing cybersecurity issues for improved firm performance.

https://techxplore.com/news/2026-02-cybersecurity-pay-links-readiness-stronger.html

Why Organizations Must Move From Cybersecurity to Cyber Resilience

Cybersecurity has shifted to cyber resilience, ensuring organizations can operate amid disruptions. Effective resilience involves decision-making under pressure, organizational coordination, and preparation for extreme scenarios via tabletop exercises. While prevention remains crucial, resilience allows organizations to manage uncertainty and external pressures. Coordination is needed across teams to navigate crises effectively. Cyber resilience requires ongoing practice and adaptation, emphasizing teamwork over just technical solutions. Testing decision-making capabilities and communication aligns organizations for better responses in crises. Resilience must be continuously measured and practiced beyond mere system recovery.

https://www.weforum.org/stories/2026/02/from-cyber-security-to-cyber-resilience/

Is Microsoft 365 a Compliant EDRMS?

Microsoft 365 can be used as an EDRMS if it complies with the Managing Digital Records in Systems Standard and the Minimum Recordkeeping Metadata Requirements Standard. Agencies must ensure information assets are protected, metadata is created, and information is accessible for the required duration. If M365 cannot be configured to meet these standards, integration with an EDRMS or saving information assets in an EDRMS is recommended.

https://archives.sa.gov.au/managing-information/Information-management/storing-information-assets/-is-microsoft-365-a-compliant-edrmsbusiness-system

Scroll to Top