cybersecurity

BT: Why Human Firewalls Are Critical in AI Cybersecurity

BT Security’s Tris Morgan emphasizes the importance of human firewalls in AI cybersecurity, arguing that employee training is crucial against sophisticated AI-driven attacks. He believes that investing in a cyber-aware culture transforms employees into an active defense against threats. Despite advanced technology, many breaches result from human error, with attackers exploiting trust and behavior. Effective training should be ongoing, engaging, and relevant, using simulations and real-world scenarios to foster awareness. For SMEs, cost-effective strategies include realistic training and clear security policies to cultivate vigilance. Continual adaptation to evolving threats is essential for strong cybersecurity defenses.

https://aimagazine.com/news/bt-security-the-importance-of-humans-in-ai-powered-attacks

The End of Cybersecurity

Cybersecurity failures in the U.S. stem from software quality issues, not just cyber threats. As attackers exploit system vulnerabilities, the focus should be on improving software security rather than relying on the cybersecurity industry. AI presents a solution, enabling the creation of safer code and fixing existing flaws. To leverage AI effectively, incentives must be realigned, and a standardized approach to software security must be established. Without systemic changes, security will remain an afterthought in software design, leaving critical infrastructure at risk.

https://www.foreignaffairs.com/united-states/end-cybersecurity

Introducing MAESTRO: a Framework for Securing Generative and Agentic AI

CSOonline introduces MAESTRO, a framework for securing generative and agentic AI in banking, addressing rapid AI advancements and systemic risks not covered by traditional security models. It distinguishes seven AI risk layers—Foundation Models, Data Operations, Agent Frameworks, Deployment & Infrastructure, Evaluation & Observability, Security & Compliance, and Agent Ecosystems—and recommends minimum controls for each to enhance security and resilience against emerging threats.

https://www.csoonline.com/article/4072341/introducing-maestro-a-framework-for-securing-generative-and-agentic-ai.html

CISOs Must Rethink the Tabletop, as 57% of Incidents Have Never Been Rehearsed

CSOonline introduces a hybrid search to enhance content exploration. Key features include security spotlights, newsletters, resources, and buyer's guides, along with extensive topics on cybersecurity and IT management. An article emphasizes that 57% of cyber incidents are unexpected, prompting CISOs to rethink tabletop exercises to focus on realistic, smaller attacks rather than rehearsing for known threats.

https://www.csoonline.com/article/4071102/cisos-must-rethink-the-tabletop-as-57-of-incidents-have-never-been-rehearsed.html

How to Mitigate Supply Chain Attacks

TLDR: Supply chain attacks exploit trusted vendors, causing major cybersecurity threats like breaches in companies such as SolarWinds and MOVEit. Traditional risk management with checklists is outdated, leaving organizations vulnerable to fast-evolving attacks. Intelligence-led monitoring provides real-time visibility, early warning signals, and proactive defense, enhancing security against emerging threats. Best practices include continuous monitoring, integrating external intelligence, and fostering cross-team collaboration to build resilience against supply chain risks. Recorded Future offers tools to shift from reactive to proactive vendor risk management.

https://www.recordedfuture.com/blog/supply-chain-attacks

Embedding Threat Intelligence and Practical Training in ICS Cybersecurity Awareness for Frontline Resilience

Rethinking ICS cybersecurity focuses on embedding threat intelligence and practical training into awareness programs for frontline resilience. Traditional IT-centric views are inadequate due to rising state-sponsored threats. Organizations are shifting from mere compliance to a culture of cybersecurity, emphasizing safety, operational continuity, and employee empowerment. Dynamic role-based training, powered by AI, helps counter misinformation and improve real-time threat detection. Engagement, tailored training, and continuous assessment enhance security posture. ICS environments face unique challenges, necessitating specialized knowledge on risks tied to safety and engineering. As cybersecurity threats evolve, fostering a psychologically resilient workforce becomes essential, prioritizing verification and critical thinking to combat AI-driven deception and elevate operational safety.

https://industrialcyber.co/features/embedding-threat-intelligence-and-practical-training-in-ics-cybersecurity-awareness-for-frontline-resilience/

Responding to Cloud Incidents: a Step-by-Step Guide From the 2025 Unit 42 Global Incident Response Report

Cloud incidents are increasing and require specific investigation methods focused on cloud assets, identities, and configurations rather than traditional endpoints. Unit 42’s recommended response process includes the following steps:

Scope and Mindset for Cloud Investigations

  • 29% of incidents in 2024 involved cloud or SaaS environments.
  • Cloud investigations prioritize identities, misconfigurations, and service interactions.

Step 1: Triage and Scoping

  • Establish event timeline and detect abnormal activity.
  • Identify affected assets (VMs, IAM, storage, containers).
  • Address logging gaps—enable and retain logs for at least 90 days.

Step 2: Evidence Collection

  • Collect audit/resource logs, VM/container snapshots.
  • Capture volatile artifacts quickly as cloud environments are ephemeral.

Step 3: Identity and Role Forensics

  • Investigate IAM settings, login patterns, escalation attempts.
  • Watch for identity hopping and privilege misuse.

Step 4: Lateral Movement and Persistence

  • Detect movement across regions/services using existing credentials.
  • Use behavioral baselining to spot anomalies, not just failed logins.

Step 5: Containment, Eradication, Recovery

  • Contain compromised assets quickly without alerting attackers.
  • Remove persistence, rotate credentials, and validate remediation.
  • Restore operations, patch vulnerabilities, and monitor for follow-up attacks.

Recommendations

  • Centralize logs, develop IR playbooks, and prepare forensic sandboxes.
  • Institutionalize lessons learned to improve future incident response.
  • Adopt zero trust principles and use specialized security assessments and retainers for support.

https://unit42.paloaltonetworks.com/responding-to-cloud-incidents/

Employees Regularly Paste Company Secrets Into ChatGPT

TLDR

Employees risk data security by sharing sensitive information with ChatGPT, with 45% using generative AI tools and 22% pasting PII/PCI data. This raises compliance and data leakage concerns, as 82% of data shared is from unmanaged accounts. ChatGPT leads AI adoption in enterprises at 43%, while Microsoft Copilot sees low usage (2%). Security measures like enforced Single Sign-On are essential to mitigate risks.

https://www.theregister.com/2025/10/07/gen_ai_shadow_it_secrets/

Cloud Compliance Requirements: What You Need to Know

Cloud compliance is becoming a strategic necessity for businesses operating in multiple regions and sectors. Major regulations, such as GDPR, HIPAA, and PCI DSS, dictate how data is handled, driving system design and vendor selection. Non-compliance can result in severe fines, delayed launches, reputational damage, or even loss of market access. Certifications such as ISO 27001, SOC 2, and FedRAMP are increasingly prerequisites for customer and partner trust, while frameworks like NIST and CIS help ensure daily operational discipline. To keep pace with evolving laws surrounding privacy, AI risk, digital sovereignty, and industry-specific requirements, organizations must integrate compliance into their core cloud strategy, adopt ongoing monitoring, and ensure leadership remains directly involved. This approach turns compliance from a defensive burden into a competitive advantage and a key proof of enterprise readiness.

https://appinventiv.com/blog/cloud-regulatory-compliances-guide/

Are We Paying Enough Attention to the AI Risks?

KPMG Legal Reimagined outlines the primary legal, regulatory, and ethical risks associated with organizations utilizing AI. Key themes and takeaways:

  • Regulatory Landscape: Laws vary; the EU has the AI Act with strict requirements, while the UK is using decentralized, principle-based oversight.
  • Ethical Considerations: Focus on transparency, explainability, bias, and fairness. Ethics boards are used to oversee these issues.
  • Third-Party Risk: AI risk extends to suppliers; due diligence and contracts are vital.
  • Data Protection: Personal data must always comply with laws like GDPR; clear privacy notices are mandated.
  • AI and Copyright: Tension exists between using AI and creative industries’ rights; guidelines limit how legal data and generative AI can be used.
  • Pace of Change: Rapid AI advancements challenge legal professionals to keep up with new technologies and laws.
  • Opportunities for Legal Teams: AI can improve legal workflows and create new skill needs; leaders should plan for evolving roles and tech adoption.

https://kpmg.com/se/en/insights/newsletters/legal-reimagined/2025/are-we-paying-enough-attention-to-the-ai-risks.html

Scroll to Top