cybersecurity

Bridging Cybersecurity and AI

AI and machine learning models introduce new vulnerabilities, such as poisoning and evasion attacks, that traditional cybersecurity frameworks like the CVE Program are not equipped to address. The White House AI Action Plan proposes creating an AI Information Sharing and Analysis Center (AI-ISAC) to bridge the gap between existing cybersecurity infrastructure and AI security needs. Integrating AI vulnerability standards into established frameworks, such as the CVE Program, is crucial to ensuring the security of AI systems.

https://www.paloaltonetworks.com/blog/2026/01/bridging-cybersecurity-and-ai/

How Are You Actually Tracking BYOD Without Losing Your Mind (or Privacy)? : CIO

Tracking BYOD is challenging; current methods (Excel) are insufficient. Need balance between user privacy and security (MAM, conditional access). Management seeks visibility, but manual processes overwhelm the team. Are MDM profiles or app restrictions the solution? How to maintain asset inventory?

https://www.reddit.com/r/CIO/comments/1qffopw/how_are_you_actually_tracking_byod_without_losing/

CISO Role Reaches “Inflexion Point” With Executive-Level Titles

CISO roles are evolving to executive-level positions, with 46% of surveyed CISOs holding such titles, indicating increased business importance. However, 52% find their responsibilities unmanageable, especially in smaller organizations. Many still report to IT rather than business leaders, highlighting a divide in security leadership structures.

https://www.infosecurity-magazine.com/news/ciso-role-inflexion-point/

Forget Predictions: True 2026 Cybersecurity Priorities From Leaders

2026 cybersecurity priorities emphasize supply chain resilience, AI efficiency, and security accountability. Experts advocate managing third-party risks amid regulatory demands, enhancing cybersecurity through AI while avoiding job replacement narratives, and simplifying complex security policies. Radical shifts toward AI governance and collaborative intelligence are anticipated, aiming to streamline operations, increase efficiency, and promote shared responsibility in cybersecurity among teams.

https://www.securityweek.com/forget-predictions-true-2026-cybersecurity-priorities-from-leaders/

CISO Assistant: Open-source Cybersecurity Management and GRC

Extreme TLDR: CISO Assistant is an open-source GRC platform for risk management, enabling documentation of risks/control mapping to standards like ISO 27001 and NIST. It features a self-hosted community edition with role-based access and a focus on traceability. The tool supports ongoing updates, assessment tracking, and integrates with various systems. Future enhancements aim to extend AI capabilities and support multi-tenancy. Available on GitHub.

https://www.helpnetsecurity.com/2026/01/14/ciso-assistant-open-source-cybersecurity-management-grc/

2026 Study From Panorays: 85% of CISOs Can’t See Third-Party Threats Amid Increasing Supply Chain Attacks

2026 survey reveals 85% of CISOs lack visibility on third-party threats amid rising supply chain attacks, highlighting gaps in preparedness, monitoring, and compliance tools. Increased adoption of AI-driven risk management solutions noted but coverage remains insufficient.

https://www.cio.com/article/4116858/2026-study-from-panorays-85-of-cisos-cant-see-third-party-threats-amid-increasing-supply-chain-attacks.html

The Cybersecurity Paradox: Training the Next-gen Workforce

AI in cybersecurity enhances operations but also creates vulnerabilities. Traditional strategies must evolve to secure human-AI interactions, emphasizing Workforce Trust Management. This approach includes reliability, accountability, transparency, and ethical alignment. Organizations must proactively build frameworks as AI is integrated into workflows, requiring employee AI literacy and rapid response protocols. Embracing these changes is essential for maintaining security alongside innovation, as ignoring them risks catastrophic breaches.

https://www.weforum.org/stories/2026/01/cybersecurity-paradox-training-the-next-generation-workforce/

8 CIO Recommendations for ERP Implementation in 2026

Agentic AI is transforming ERP systems, enabling new operating models and improving agility, efficiency, and customer responsiveness. By 2026, CIOs should develop a business plan for agentic AI adoption, engage with ERP vendors, and define a human-AI collaboration strategy. They must also address risks, readiness gaps, and talent needs while planning for change management and communication strategies.

https://www.informationweek.com/software-platforms/8-cio-recommendations-for-erp-implementation-in-2026-think-agentic

Designing Safer Links: Secure Connectivity for Operational Technology

New guidance outlines eight core principles for designing, reviewing, and securing connectivity to and within OT systems. These principles, developed from the NCSC’s experience and industry engagement, aim to help organizations reduce attack surfaces and improve incident response. The guidance encourages OT owners, operators, integrators, and vendors to implement these principles for stronger connectivity design.

https://www.ncsc.gov.uk/blog-post/designing-safer-links-secure-connectivity-for-ot

How Microsoft Builds Privacy and Security to Work Hand-in-hand

Microsoft Security focuses on integrating security and privacy. Emphasizing trust, compliance, and customer data ownership, Microsoft employs technologies like Microsoft Entra and Purview to protect data efficiently without accessing it directly. They aim for seamless security through continuous authentication and strong regulatory adherence, viewing compliance as a chance for innovative enhancement. Microsoft prioritizes privacy as a fundamental right while ensuring security measures deepen customer trust.

https://www.microsoft.com/en-us/security/blog/2026/01/13/how-microsoft-builds-privacy-and-security-to-work-hand-in-hand/

Scroll to Top