cybersecurity

Is Microsoft 365 a Compliant EDRMS?

Microsoft 365 can be used as an EDRMS if it complies with the Managing Digital Records in Systems Standard and the Minimum Recordkeeping Metadata Requirements Standard. Agencies must ensure information assets are protected, metadata is created, and information is accessible for the required duration. If M365 cannot be configured to meet these standards, integration with an EDRMS or saving information assets in an EDRMS is recommended.

https://archives.sa.gov.au/managing-information/Information-management/storing-information-assets/-is-microsoft-365-a-compliant-edrmsbusiness-system

The CTEM Divide: Why 84% of Security Programs Are Falling Behind

2026 study shows 84% of security programs lag due to lack of Continuous Threat Exposure Management (CTEM). Only 16% adopted CTEM, which enhances visibility and threat awareness. Despite 87% awareness, implementation struggles arise from organizational inertia and budget issues. Security complexity increases risk, making CTEM essential for managing high-stakes challenges. Without it, traditional security approaches fail to scale, urging leaders to reconsider their strategies.

https://thehackernews.com/2026/02/the-ctem-divide-why-84-of-security.html

Protecting the ICT Supply Chain: a Step-By-Step Guide to the New EU Security Framework

The European Commission proposed a new cybersecurity package, including a revised Cybersecurity Act (CSA2) and amendments to NIS2, to strengthen the EU’s cybersecurity resilience. The CSA2 introduces a five-step mechanism to address non-technical risks in the ICT supply chain, potentially prohibiting NIS2 organizations from using ICT equipment from high-risk suppliers, particularly those from countries posing cybersecurity concerns. This framework aims to protect the EU’s ICT supply chain, with potential implications for connectivity and space operators.

https://accesspartnership.com/opinion/protecting-the-ict-supply-chain-a-step-by-step-guide-to-the-new-eu-security-framework/

AI Fueled Massive Surge in Fraud Losses Last Year, Study Finds

AI-driven fraud surged last year, surpassing traditional methods, with attacks against U.S. customers rising 1,210% and losses hitting $1 billion, according to Pindrop research. Generative AI and deepfakes enabled fraudsters to automate scams effectively. Key targets included contact centers and urgent payment requests, with tactics involving synthetic identities. Nearly 71% of U.S. companies reported increased AI fraud attempts, highlighting a significant shift in the fraud landscape. The retail sector was particularly affected, with fraudsters automating low-dollar refund scams.

https://www.ciodive.com/news/ai-fueled-massive-surge-fraud-losses-pindrop-retail/811904/

When We See White Smoke, We Know We Have a New CISO

CISO Series highlights cybersecurity leadership and relationships. David Spark and Andy Ellis host, featuring Russ Ayres discussing effective communication of security metrics to the board, emphasizing storytelling over mere numbers. The episode explores AI's potential impact on cybersecurity roles, advocating for a balance of specialists and generalists. The show discusses the cyclical nature of point solutions and platform integration in security tools, concluding with a segment comparing deepfake attacks and zero-day exploits, leaning towards zero-days being worse due to accountability.

https://cisoseries.com/when-we-see-white-smoke-we-know-we-have-a-new-ciso/

Never Settle: How CISOs Can Go Beyond Compliance Standards to Better Protect Their Organizations

CISOs should prioritize resilience over merely meeting compliance standards to combat emerging cybersecurity threats effectively. While compliance sets basic security protocols, it may not address new risks adequately. CISOs are encouraged to enhance their strategies by extending their risk assessment timeframes, adopting scenario-based methodologies, and quantifying potential losses. Engaging with organizational leadership on these matters year-round can shift perceptions of cybersecurity from a cost to an essential investment in business sustainability.

https://www.csoonline.com/article/4128920/never-settle-how-cisos-can-go-beyond-compliance-standards-to-better-protect-their-organizations.html

How Top CISOs Solve Burnout and Speed up MTTR Without Extra Hiring

Top CISOs address SOC burnout and improve MTTR by prioritizing sandbox-first investigations and automating triage processes. This strategy reduces decision fatigue, lowers manual workload, and increases efficiency without requiring additional hiring. As a result, SOCs experience faster alert resolution, reduced escalations, improved detection rates for threats, and enhanced team retention. Effective utilization of evidence-based responses through platforms like ANY.RUN streamlines operations and fosters a more sustainable work environment.

https://thehackernews.com/2026/02/how-top-cisos-solve-burnout-and-speed.html

NIS2: Supply Chains as a Risk Factor

NIS2 increases supply chain security requirements, emphasizing external IT risks. Companies must integrate these risks into their security strategies, transforming dependencies into management responsibilities. Effective control of supply chains involves identifying critical partners, setting security standards, and continuous risk monitoring. CISOs' roles expand to include risk communication and holistic management. Compliance under NIS2 goes beyond paperwork, demanding real security measures and transparent assessments, ultimately enhancing operational stability and turning supply chains into strategic assets.

https://www.csoonline.com/article/4128381/nis2-supply-chains-as-a-risk-factor.html

Simple Security Solutions That Deliver a Big Impact

CISO Series discusses simple yet impactful cybersecurity strategies, emphasizing that flashy solutions often overshadow basic security controls that can prevent breaches. Regular upkeep, like firewall rule management, asset tracking, and consistent patching, is crucial yet frequently neglected. The conversation highlights the necessity of prioritizing security focus and implementing straightforward procedures to enhance cybersecurity efficacy. Simple processes, like separation of duties and ensuring asset visibility, are fundamental in reducing risk and improving overall cybersecurity posture.

https://cisoseries.com/simple-security-solutions-that-deliver-a-big-impact/

Scroll to Top