cybersecurity

A Shared Vision of Software Bill of Materials (SBOM) for Cybersecurity

CISA and NSA, alongside 19 global cybersecurity organizations, released guidance for a unified Software Bill of Materials (SBOM) to enhance software transparency, security, and risk management in the digital supply chain. This initiative promotes SBOM adoption, standardized implementations, and integration into security processes for better vulnerability management.

https://www.cisa.gov/resources-tools/resources/shared-vision-software-bill-materials-sbom-cybersecurity

GenAI Is Fueling Smarter Fraud, but Broken Teamwork Is the Real Problem

80% of U.S. companies faced socially engineered fraud, with many suffering financial losses exceeding $500,000. Misalignment between finance and security teams exacerbates risks, as attackers exploit communication gaps. Generative AI complicates fraud detection by enabling sophisticated attacks across systems. Recommendations for CISOs include fostering teamwork between finance and security, adopting GenAI-resilient defenses, and considering broader impacts of fraud beyond direct losses.

https://www.helpnetsecurity.com/2025/09/01/ciso-fraud-prevention-genai/

SIEM’s “Evil Secret”: Agents Are Not Always Needed

Modern SIEM solutions often rely on outdated endpoint agents that increase costs and operational complexities. While still necessary in some cases, there's a transition towards cloud-native, agentless solutions that can centralize data processing, simplify operations, and reduce burdens on endpoints. The shift acknowledges the end of on-prem resource constraints, urging organizations to develop a plan for gradual phasing out of agents while maintaining security and compliance. Embracing agentless architecture is increasingly seen as essential for future readiness and efficiency.

https://securitybrief.com.au/story/siem-s-evil-secret-agents-are-not-always-needed

CIISec: Most Security Professionals Want Stricter Regulations

69% of security professionals want stricter cybersecurity laws, per a CIISec survey. Major regulations like the Cyber Security and Resilience Bill make senior management liable for breaches. 91% believe boards should be accountable for incidents. The UK plans to ban ransomware payments for certain sectors and enforce mandatory incident reporting.

https://www.infosecurity-magazine.com/news/ciisec-security-professionals/

The CISO’s AI Cybersecurity Survival Guide

CISOs face AI's hype in cybersecurity, urging a 10-step checklist to assess AI solutions effectively—focused on real problems, data integrity, explainability, performance metrics, integration, security, scalability, vendor reliability, ethical compliance, and cost. This guide stresses that AI enhances security but should not replace human intuition, highlighting the need for critical evaluation over marketing hype.

https://builtin.com/articles/ciso-ai-cybersecurity-survival-guide

NIS2 Is Intended to Make Organizations More Secure, but Will It Succeed?

NIS2 aims to enhance cyber resilience among EU organizations, but many member states have yet to implement it into national law ahead of the October 2024 deadline. An expert roundtable highlighted the varied progress, with countries like the Netherlands facing challenges due to bureaucratic delays. Compliance is viewed as necessary for security, yet many organizations remain reactive rather than proactive. There’s concern about the capacity of CERTs to support compliance efforts. Overall, while NIS2 could foster better security practices, the path to complete implementation remains complex and costly.

https://www.techzine.eu/blogs/security/133821/nis2-is-intended-to-make-organizations-more-secure-but-will-it-succeed/

AI Vibe Coding Meets Its Match in Flow Defending

Enterprises face a cybersecurity crisis due to rapid software development outpacing vulnerability patching, exacerbated by AI technologies. Exploits can occur within hours of vulnerability disclosure, while patching timelines stretch from 38 to over 150 days, increasing breach costs. A new approach, “flow defending,” is essential, distributing automated vulnerability management throughout the software development life cycle (SDLC) to enhance speed and efficiency, minimize risks, and align security metrics across teams.

https://www.scworld.com/perspective/ai-vibe-coding-meets-its-match-in-flow-defending

CISOs/CSOs Now Responsible for OT in Most Firms

CISOs/CSOs are increasingly responsible for operational technology (OT) security, with 52% of organizations reporting this compared to 16% in 2022. C-suite oversight of OT has risen to 95%, improving security maturity and reducing intrusion impacts. Key findings include a growth in OT security practices and vendor consolidation among organizations.

https://www.frontier-enterprise.com/cisos-csos-now-responsible-for-ot-in-most-firms/

Scroll to Top