cybersecurity

The Uncomfortable Truth About “More Visibility”

In 2025, organizations faced escalating cyber threats, with a weekly average of 1,968 attacks, an 18% year-over-year surge. Attackers are employing advanced techniques like ClickFix, leading to human-triggered attacks instead of traditional malware delivery. Concurrently, insufficient patching and unmanaged exposures foster vulnerabilities, emphasizing the need for Exposure Management as a proactive operating model. Key trends reveal gaps in action, shifting social engineering, volatile ransomware strategies, and reduced time-to-exploitation. The focus should be on actionable remediation rather than detection alone, advocating for safe, continuous exposure reduction to effectively combat modern threats.

https://thehackernews.com/expert-insights/2026/02/the-uncomfortable-truth-about-more.html

The Shadow AI Workforce: When Employees Go Rogue With Tech

Employees are using AI tools without official sanction, creating a “shadow AI workforce” that poses risks in data security and compliance. This trend emerged alongside the rise of generative AI tools, reflecting employees' desire for efficiency. HR must address this issue proactively by establishing clear AI policies, promoting safe usage, and fostering open communication about AI use. Ignoring or punishing this behavior can stifle innovation; instead, organizations should leverage it for strategic advantage by providing proper guidelines and training.

https://www.hrkatha.com/features/hr-pops-features/the-shadow-ai-workforce-when-employees-go-rogue-with-technology/

Cybersecurity Spending May Pay Off: Study Links Readiness to Stronger Returns

A study by Binghamton University found that companies with strong cybersecurity readiness and transparency about cyberattacks perform better financially. The study analyzed conference call transcripts from top U.S. public companies to gauge how cybersecurity risks were discussed and their impact on market valuation. The findings emphasize the importance of acknowledging and addressing cybersecurity issues for improved firm performance.

https://techxplore.com/news/2026-02-cybersecurity-pay-links-readiness-stronger.html

Why Organizations Must Move From Cybersecurity to Cyber Resilience

Cybersecurity has shifted to cyber resilience, ensuring organizations can operate amid disruptions. Effective resilience involves decision-making under pressure, organizational coordination, and preparation for extreme scenarios via tabletop exercises. While prevention remains crucial, resilience allows organizations to manage uncertainty and external pressures. Coordination is needed across teams to navigate crises effectively. Cyber resilience requires ongoing practice and adaptation, emphasizing teamwork over just technical solutions. Testing decision-making capabilities and communication aligns organizations for better responses in crises. Resilience must be continuously measured and practiced beyond mere system recovery.

https://www.weforum.org/stories/2026/02/from-cyber-security-to-cyber-resilience/

Is Microsoft 365 a Compliant EDRMS?

Microsoft 365 can be used as an EDRMS if it complies with the Managing Digital Records in Systems Standard and the Minimum Recordkeeping Metadata Requirements Standard. Agencies must ensure information assets are protected, metadata is created, and information is accessible for the required duration. If M365 cannot be configured to meet these standards, integration with an EDRMS or saving information assets in an EDRMS is recommended.

https://archives.sa.gov.au/managing-information/Information-management/storing-information-assets/-is-microsoft-365-a-compliant-edrmsbusiness-system

The CTEM Divide: Why 84% of Security Programs Are Falling Behind

2026 study shows 84% of security programs lag due to lack of Continuous Threat Exposure Management (CTEM). Only 16% adopted CTEM, which enhances visibility and threat awareness. Despite 87% awareness, implementation struggles arise from organizational inertia and budget issues. Security complexity increases risk, making CTEM essential for managing high-stakes challenges. Without it, traditional security approaches fail to scale, urging leaders to reconsider their strategies.

https://thehackernews.com/2026/02/the-ctem-divide-why-84-of-security.html

Protecting the ICT Supply Chain: a Step-By-Step Guide to the New EU Security Framework

The European Commission proposed a new cybersecurity package, including a revised Cybersecurity Act (CSA2) and amendments to NIS2, to strengthen the EU’s cybersecurity resilience. The CSA2 introduces a five-step mechanism to address non-technical risks in the ICT supply chain, potentially prohibiting NIS2 organizations from using ICT equipment from high-risk suppliers, particularly those from countries posing cybersecurity concerns. This framework aims to protect the EU’s ICT supply chain, with potential implications for connectivity and space operators.

https://accesspartnership.com/opinion/protecting-the-ict-supply-chain-a-step-by-step-guide-to-the-new-eu-security-framework/

AI Fueled Massive Surge in Fraud Losses Last Year, Study Finds

AI-driven fraud surged last year, surpassing traditional methods, with attacks against U.S. customers rising 1,210% and losses hitting $1 billion, according to Pindrop research. Generative AI and deepfakes enabled fraudsters to automate scams effectively. Key targets included contact centers and urgent payment requests, with tactics involving synthetic identities. Nearly 71% of U.S. companies reported increased AI fraud attempts, highlighting a significant shift in the fraud landscape. The retail sector was particularly affected, with fraudsters automating low-dollar refund scams.

https://www.ciodive.com/news/ai-fueled-massive-surge-fraud-losses-pindrop-retail/811904/

Scroll to Top