cybersecurity

Watch Your Words: Tim Brown’s Advice for CISOs

Tim Brown, former CISO of SolarWinds, shared insights at RSAC 2026 about the 2020 SolarWinds supply chain attack and his personal experience as the first CISO indicted in a civil lawsuit by the SEC for alleged fraud related to cybersecurity disclosures. Brown highlighted how excessive communication and misunderstood internal language during the ensuing SEC investigation led to legal challenges, emphasizing the critical need for clear communication policies and cautious internal messaging to prevent misinterpretation and legal risks in cybersecurity incident management.

https://www.techtarget.com/searchsecurity/feature/Watch-your-words-Tim-Browns-advice-for-CISOs

Why Cybersecurity’s Uncertainty Problem Is Getting Worse

Cybersecurity faces increasing uncertainty, with leading cryptographers unable to agree on the greatest threats. Paul Kocher, a cryptography researcher, warns that AI will accelerate the discovery of vulnerabilities in protocols and implementations, posing a significant threat to cybersecurity.

https://www.govinfosecurity.com/cybersecuritys-uncertainty-problem-getting-worse-a-31232

From Cyber Risk to Business Risk: How CISOs Should Engage the Board in 2026

IDC's 2026 insights highlight that cyber risk has evolved into a critical business concern at the board level, requiring CISOs to translate technical cyber threats into measurable business impacts and align security strategies with regulatory and operational priorities. Amid rising regulatory pressures like NIS2 and the EU AI Act, CISOs are advised to adopt financial risk metrics, implement robust risk management frameworks, and engage regularly with boards through clear, business-focused communication to enhance organizational resilience and informed decision-making.

https://www.idc.com/resource-center/blog/from-cyber-risk-to-business-risk-how-cisos-should-engage-the-board-in-2026/

EUDR in Practice: How to Correctly Set Up Due Diligence in the Supply Chain

The EU Deforestation Regulation (EUDR) establishes new due diligence requirements for companies dealing with certain commodities, mandating proof that products comply with EUDR and are deforestation-free before entering or leaving the EU market. Companies must collect detailed supply chain information, assess risks, implement mitigation measures if necessary, submit a Due Diligence Statement, maintain an internal due diligence system, and retain documentation for inspections.

https://www.grantthornton.cz/en/news/eudr-in-practice-how-to-correctly-set-up-due-diligence-in-the-supply-chain/

Ransomware’s New Era: Moving at AI Speed

Ransomware attacks are accelerating in speed and sophistication, with threat actors increasingly using artificial intelligence to quickly exploit valid credentials and bypass traditional security tools like endpoint detection and response (EDR). Reports from Halcyon and Arctic Wolf highlight that ransomware tactics have evolved from encrypting data to multi-extortion schemes and direct victim targeting, while AI enables automated, high-fidelity social engineering, making defense more challenging and emphasizing the need for improved access management and transparency in cybersecurity efforts.

https://www.darkreading.com/endpoint-security/ransomware-new-era-moving-ai-speed

Google Unleashes Gemini AI Agents on the Dark Web

Google has launched its Gemini AI agents in public preview to monitor the dark web, analyzing up to 10 million posts daily with 98 percent accuracy to detect relevant security threats for organizations. The tool builds detailed profiles of customers and uses advanced AI models to identify and prioritize genuine risks such as data leaks or initial access brokers, aiming to reduce false positives common in traditional dark web monitoring. Additionally, Google has integrated AI agents into its Security Operations platform to automate threat responses and investigations.

https://www.theregister.com/2026/03/23/google_dark_web_ai/

Ten Things to Ask Your IT Team About NIS2 Compliance

The article discusses the key areas organizations must address to ensure compliance with the EU's NIS2 directive, which mandates robust cybersecurity governance and resilience. It highlights ten critical focus points including risk analysis, incident handling, business continuity, supply chain security, and the importance of continuous evidence gathering and proper IT tools. The article emphasizes that leadership must proactively oversee cybersecurity measures to meet strict regulatory requirements and maintain business continuity in the face of threats.

https://www.kaseya.com/blog/nis2-compliance/

CISO’s Perspectives – The 4 Recommendations to Sleep Without a Worry

Paul Bayle, Group CSO at Atos, discusses key recommendations for CISOs to manage cybersecurity effectively and maintain peace of mind despite evolving threats. Emphasizing the importance of thorough IT system mapping, investing in multiple security technologies, fostering strong governance involving cross-department collaboration, and engaging with expert ecosystems, he highlights the challenges posed by “unknown unknowns” and the need for continuous awareness, training, and management support to mitigate risks across the organization.

https://atos.net/en/lp/cybershield/cisos-perspectives-the-4-recommendations-to-sleep-without-a-worry

How CISOs Can Survive the Era of Geopolitical Cyberattacks

Geopolitical cyberattacks, particularly destructive Iranian wiper campaigns, are increasingly targeting critical infrastructure and organizations to cause operational chaos rather than financial gain. These attacks rely on stolen credentials and legitimate administrative tools to move laterally within networks, making containment and strict internal access controls essential for CISOs to limit damage and ensure organizational resilience.

https://www.bleepingcomputer.com/news/security/how-cisos-can-survive-the-era-of-geopolitical-cyberattacks/

Shadow AI ‘Double Agents’ Are Outpacing Security Visibility – and That’s a Serious Concern for UK Businesses

UK businesses are rapidly adopting AI agents to automate tasks and boost productivity, with 62% already using them and 68% planning enterprise-wide rollouts soon. However, Microsoft’s Cyber Pulse report warns that these AI agents, acting autonomously across networks and systems, are outpacing security visibility and creating significant risks, highlighting the urgent need for robust governance, visibility, and zero trust security measures to manage and control their access safely.

https://www.techradar.com/pro/security/shadow-ai-double-agents-are-outpacing-security-visibility-and-thats-a-serious-concern-for-uk-businesses

Scroll to Top