cybersecurity

State CISO Confidence Drops From 48% to 22%, NASCIO-Deloitte 2026 Study Finds

The 2026 NASCIO-Deloitte Cybersecurity Study reveals a significant drop in state CISO confidence, falling from 48% in 2022 to 22%, due to increased cyber threats, reduced federal support, aging infrastructure, and AI-enabled attacks. The study highlights the need for whole-of-state cybersecurity governance, AI risk frameworks, reassessment of federal program dependencies, and implementation of effectiveness metrics to help rebuild confidence in public-sector cybersecurity programs.

https://www.cybersecurity-insiders.com/state-ciso-confidence-nascio-deloitte-2026-study/

Cybersecurity Professionals Say High-Profile Incidents Boost Execs’ Credibility

A May ISC2 survey of nearly 800 cybersecurity professionals found that 76% believe leaders gain credibility by having managed real, high-profile security incidents, indicating a shift in attitude toward executives who have experienced breaches. Key traits fostering trust include strong communication of risk to senior leadership, a long-term cybersecurity vision, and the ability to work effectively with boards to secure budgets, emphasizing the importance of experienced and transparent leadership in cybersecurity.

https://www.itbrew.com/stories/cybersecurity-professionals-say-high-profile-incidents-boost-execs-credibility

How CISOs Can Manage Sovereign-Cloud Security Risks

As geopolitical tensions increase, CISOs managing sovereign-cloud security risks must carefully assess both the security of cloud providers and the security controls implemented within the cloud. Alternative regional cloud providers often lack the robust governance, resilience, and security features of major hyperscale providers, requiring CISOs to enforce clear workload placement strategies, rigorous control assessments, and legal compliance to balance sovereignty requirements without compromising long-term security and resilience.

https://www.cybersecuritydive.com/news/how-cisos-can-manage-sovereign-cloud-security-risks/821323/

Cybersecurity Without Clarity: Why Most Organizations Stay Reactive

Despite increased investments in cybersecurity tools, many organizations remain reactive due to a lack of clarity in ownership, governance, and operational discipline. Cybersecurity requires clear accountability, business alignment, and leadership involvement to move from constant problem response to proactive risk management and long-term security maturity.

https://nationalcioreview.com/articles-insights/cybersecurity-without-clarity-why-most-organizations-stay-reactive/

NSA Launches Zero Trust Implementation Guidelines Resource Webpage

The National Security Agency (NSA) has launched a new resource webpage providing guidelines for implementing Zero Trust architecture. This initiative aims to assist organizations in enhancing their cybersecurity posture by adopting Zero Trust principles more effectively.

https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4496862/nsa-launches-zero-trust-implementation-guidelines-resource-webpage/

Bitwarden Scrubs ‘Always Free’ and ‘Inclusion’ Values From Its Website as Longtime Execs Step Down

Bitwarden, a popular open-source password manager, has undergone leadership changes with longtime CEO Michael Crandell moving to an advisory role and CFO Stephen Morrison departing, replaced by executives with private equity and software backgrounds. Concurrently, the company quietly removed the phrase “Always free” from its website’s pricing page, although the free plan remains available; Bitwarden’s chief customer officer stated the company remains committed to offering a robust free plan.

https://www.fastcompany.com/91542655/bitwarden-scrubs-always-free-and-inclusion-values-from-its-website-as-longtime-execs-step-down

How Deepfakes Are Rewriting the Rules of the Modern Workplace

Deepfake technology is increasingly impacting the modern workplace by enabling sophisticated impersonation attacks that exploit trust in familiar voices and faces, leading to significant security risks such as fraudulent payment approvals and misinformation. Organizations must adapt by implementing stricter verification processes, expanding incident response plans to address synthetic media threats, and applying zero-trust principles to communication channels to safeguard against these evolving digital manipulations.

https://www.cio.com/article/4170894/how-deepfakes-are-rewriting-the-rules-of-the-modern-workplace.html

More Money Is Going to Physical Security, but It’s Often CISOs That Oversee It: EY

A recent EY survey reveals that organizations are increasing budgets for physical security, with nearly 80% allocating more funds, sometimes up to 50%, amid rising board oversight. However, many place responsibility for physical security with Chief Information Security Officers (CISOs), blending physical and cybersecurity, which can lead to under-resourcing physical protection; EY recommends centralizing security functions, clarifying accountability, and expanding security preparedness through integrated threat intelligence and realistic crisis simulations.

https://www.facilitiesdive.com/news/more-money-is-going-to-physical-security-but-its-often-cisos-that-overse/820077/

Stop Blaming Your People: the Case for Human-Centred Cyber Security

The article argues against blaming employees as the weakest link in cyber security and advocates for a human-centred approach that focuses on educating people as a key defense. Cyber security expert Caitriona Forde emphasizes shifting training from corporate obligation to teaching essential life skills that protect individuals and their families, thereby fostering a culture of empowerment rather than shame. With evolving AI threats, businesses must adopt practical measures like explaining risks, encouraging cautious behavior, sharing experiences openly, verifying requests, and governing AI use to build resilience and reduce incidents.

https://www.businessnews.com.au/article/Stop-blaming-your-people-the-case-for-human-centred-cyber-security

Software Bill of Materials for AI – Minimum Elements

The Cybersecurity and Infrastructure Security Agency (CISA) outlines the minimum elements for a Software Bill of Materials (SBOM) specific to AI systems to enhance transparency and security. These elements include detailed information about the components, versions, and relationships within AI software to help identify vulnerabilities and manage risks effectively. This approach aims to improve trust and security in AI technologies by providing comprehensive visibility into their software components.

https://www.cisa.gov/resources-tools/resources/software-bill-materials-ai-minimum-elements

Scroll to Top