cybersecurity

Master Data Management (MDM)

MDM: Centralized approach to managing business data across systems, ensuring accuracy, consistency, and governance. Key components: data integration, quality, stewardship, and lifecycle management. Benefits: improved decision-making, compliance, and operational efficiency.

NIS2: Why Are Firms Struggling to Comply?

Many organizations struggle with compliance to the EU's NIS2 Directive due to complex supply chains, outdated infrastructure, and insufficient cybersecurity investment. ENISA warns that several critical sectors, like ICT and healthcare, face significant challenges. In contrast, industries such as electricity and banking show more cybersecurity maturity. Additionally, inconsistent national regulation and capacity issues hinder compliance efforts across EU member states. Recommendations for improving compliance include conducting risk assessments, establishing clear asset visibility, appointing NIS2 leaders, and implementing strong incident response plans.

https://www.itpro.com/business/policy-and-legislation/nis2-why-are-firms-struggling-to-comply

The 24-Hour Vs. 5-Day Divide: Why CEOs and CISOs Can’t Agree on Recovery Times

CEOs and CISOs disagree on cyberattack recovery times, with 80% of businesses expecting recovery in five days, while 23% aim for 24 hours. CISOs perceive the complexity of IT environments, affecting recovery strategies. A study showed recovery time improved to 28 days in Australasia, but dwell time before attacks averaged 199 days. Despite many organizations having incident plans, only 30% rigorously tested them, impacting recovery efficiency. Well-prepared organizations, fostering CISO-management communication and utilizing AI, perform better in cyber resilience, prioritizing continuous business recovery.

https://www.cdotrends.com/story/4639/24-hour-vs-5-day-divide-why-ceos-and-cisos-cant-agree-recovery-times

Beyond the Dark Web: Where Threat Actors Operate

Cybercriminals are increasingly moving operations from the dark web to mainstream platforms like Telegram, Discord, and social media due to law enforcement pressure and the practicality of these accessible channels. This shift enables easier communication, recruitment, and data leakage, complicating threat detection for defenders. Consequently, threat intelligence strategies must adapt to monitor diverse platforms effectively, necessitating enhanced operational security, language skills, and automation tools for efficient surveillance. The evolution of cybercriminal behavior highlights that the dark web is no longer the primary hub of illegal activities.

https://sosintel.co.uk/beyond-the-dark-web-where-threat-actors-operate/

What The Last Century Of Cybersecurity Can Teach Us About What Comes Next In The Age Of AI

AI transforms cybersecurity; businesses must adapt rapidly to avoid falling behind. With only 30% ready for AI integration, understanding past security evolutions can guide future strategies. AI can process alerts and aid in threat detection. Analysts must oversee AI actions, ensuring effectiveness and connection to business objectives. Emphasizing AI as a team member, training analysts as supervisors, and tying AI tasks to business impacts will enhance security operations and competitiveness.

https://www.forbes.com/councils/forbestechcouncil/2025/07/18/what-the-last-century-of-cybersecurity-can-teach-us-about-what-comes-next-in-the-age-of-ai/

What Are the Cybersecurity Trends We Need To Follow?

Cybersecurity Trends Summary

Focus on key emerging cybersecurity trends amidst evolving technologies. Discussions emphasize AI's dual role in enhancing security and increasing risks, particularly in secure coding practices and supply chain transparency. The challenge of legacy systems and the need for standardization are highlighted, alongside the potential impact of cyber insurance on security practices. Data management emerges as central to addressing security breaches, with AI tools like Data Security Posture Management (DSPM) seen as critical for improvement. Overall, increased community awareness and regulatory pressures are necessary for enhanced data privacy and security standards.

https://cisoseries.com/what-are-the-cybersecurity-trends-we-need-to-follow/

Open Source Intelligence (OSINT)

OSINT: data gathering from publicly available sources for intelligence purposes. Tools: social media, websites, databases. Applications: cybersecurity, law enforcement, market research. Ethical concerns: privacy, legal implications.

From the FBI to F&A: Lessons Learnt in Safeguarding Systems and Data

CISO Jill Knesek shares insights from her FBI experience applied to safeguarding financial data. She emphasizes that finance teams are vulnerable to cyber threats due to their access to sensitive data and often insufficient awareness of cyber risks. Effective cybersecurity demands a comprehensive business approach, involving training, robust financial controls, and addressing third-party risks. Communication of cyber risks in business terms is crucial for stakeholder engagement, while AI tools offer both opportunities and new threats, necessitating careful implementation. Knesek advises aspiring cybersecurity professionals to leverage diverse experiences, focusing on the human element's importance in security strategies.

https://www.computerweekly.com/opinion/From-the-FBI-to-FA-lessons-learnt-in-safeguarding-systems-and-data

Cybersecurity and AI : Towards a New Human-centered Approach

AI adoption is reshaping business and increasing risks, requiring a shift in cybersecurity to focus on human factors. Traditional security methods are insufficient as threats exploit human cognitive weaknesses. New scenarios include deepfake impersonation and misinformation. Addressing these risks involves enhancing cognitive awareness, establishing verification protocols, regulating AI use, mapping cognitive risks, and preparing response teams. A cultural shift in organizations is essential for proactive AI risk management, integrating technology with human capabilities for comprehensive cybersecurity.

https://www.rsm.global/france/en/insights/yuksel-aydin-cybersecurity-ai-human-centered-approach

A CISO’s AI Playbook

CISO AI Playbook: In a tough security budget climate, improving analyst productivity is crucial. Adopt a strategic framework focusing on throughput over headcount, leveraging AI to handle alerts efficiently. Key steps include calculating alert investigation costs, addressing analyst attention constraints, improving throughput via AI tools, ensuring transparency for trust, valuing time savings, and aligning security outcomes with business goals. AI aids in reducing investigation times and refocuses analysts on high-value tasks while balancing costs and risk mitigation for sustainable operations.

https://www.darkreading.com/vulnerabilities-threats/ciso-ai-playbook

Scroll to Top