risk management

Security and Generative AI Are Learning to Get Along

IT professionals are navigating the challenge of integrating generative AI into cybersecurity without compromising safety, as the technology’s reliance on large volumes of raw data can expand threat surfaces. Experts emphasize the need for strong security architecture and domain expertise to ensure AI tools are both effective and secure, a priority underscored by the recent White House cyber strategy calling for AI-enabled cyber defense and innovation stewardship.

https://www.itbrew.com/stories/2026/03/12/security-and-generative-ai-are-learning-to-get-along

AI Is Everywhere, But CISOs Are Still Securing It With Yesterday’s Skills and Tools, Study Finds

A 2026 study by Pentera reveals that most Chief Information Security Officers (CISOs) are struggling to secure AI systems using outdated skills and legacy security tools, with 67% reporting limited visibility into AI usage within their organizations. The primary challenges are not budget-related but stem from a lack of specialized expertise and insufficient AI-tailored security controls, leading many to rely on traditional defenses unsuited for the complexities of AI infrastructure.

https://thehackernews.com/2026/03/ai-is-everywhere-but-cisos-are-still.html

Bank Built Its Own AI Threat Hunter Because Vendors Can’t

Australia’s Commonwealth Bank developed its own agentic AI threat hunting tools after finding that cybersecurity vendors could not keep pace with the rapidly increasing volume and sophistication of AI-powered threats, which saw their weekly threat signals surge from 80 million to 400 billion. The in-house AI system significantly reduced threat assessment time from two days to 30 minutes and helps frontline analysts focus on problem-solving rather than repetitive tasks, addressing both operational scale challenges and analyst mental health concerns.

https://www.theregister.com/2026/03/17/commonwealth_bank_ai_defense/

Beyond the Menu of Options: a Taxonomy for Information Security Strategies

The article proposes a taxonomy for information security strategies, categorizing them into reactive defensive, proactive defensive, and offensive measures. Reactive defensive measures counter ongoing information influence, while proactive defensive measures build long-term resilience. Offensive measures involve a targeted state using information operations to counter malign influence.

https://smallwarsjournal.com/2026/03/16/beyond-the-menu-of-options-a-taxonomy-for-information-security-strategies/

When Geopolitics Goes Digital: How Wars Are Now Won Before the First Missile Is Fired

The article discusses how modern warfare now integrates offensive cyber operations as a primary phase before kinetic strikes, exemplified by recent US-led operations in Iran and ongoing conflicts in Ukraine. It highlights the escalating cyber threat to telecommunications and critical infrastructure, particularly from Iranian state and proxy actors, underscoring the urgent need for organizations, especially those with Middle East exposure, to enhance real-time threat intelligence, resilience, and defensive measures against rapid, sophisticated cyberattacks like the destructive Stryker company incident.

https://sosintel.co.uk/when-geopolitics-goes-digital-how-wars-are-now-won-before-the-first-missile-is-fired/

Using AI to Pick Team Leaders Without Crossing Ethical Lines

The featured article discusses how AI can assist CIOs in identifying potential team leaders by analyzing performance data objectively, while cautioning that humans must maintain final hiring authority to avoid legal, ethical, and bias-related risks inherent in AI-based decision-making.

https://www.informationweek.com/it-leadership/using-ai-to-pick-team-leaders-without-crossing-legal-or-ethical-lines

Cyber Enforcement – When an Incident Is Just the Tip of the Iceberg

The article explains that recent UK enforcement trends show cyber incidents often expose broader compliance failures, making the reported breach only the starting point for regulatory scrutiny. Regulators increasingly focus on security weaknesses, governance gaps, and data-handling practices across the organization, especially after cyberattacks. Fines have risen, and enforcement actions target private-sector companies with inadequate safeguards. The article concludes that organizations must treat cyber resilience, contractual risk allocation, and data protection controls as ongoing obligations because investigations can extend beyond the original incident to encompass broader operational and legal failings. 

https://www.slaughterandmay.com/insights/new-insights/cyber-enforcement-when-an-incident-is-just-the-tip-of-the-iceberg/

Information Security Strategy

Build a resilient information security strategy that aligns cybersecurity, risk management, and business goals. This approach integrates policies, people, and processes for effective protection in a rapidly evolving digital landscape. Establish a clear vision, assess current capabilities, define risks, and ensure ongoing adaptation to support operational stability and compliance. Engage security teams early in digital transformations to mitigate emerging risks and ensure smooth integration. Focus on practical execution through structured decision-making, budget alignment, and continuous improvement.

https://www.processexcellencenetwork.com/data-security/articles/information-security-strategy-how-to-build-a-system-that-actually-works

Kill Switches Don’t Work If the Agent Writes the Policy: The Berkeley Agentic AI Profile Through the AILCCP Lens

Berkeley's AI Risk-Management Standards Profile extends NIST's framework for AI agents, identifying risks like oversight failures and misinformation but lacks effective controls. It assumes agentic AI can follow traditional model-centric oversight, which misrepresents complex multi-agent behaviors. Proposed solutions, like human oversight checkpoints and kill switches, fail to address how agents operate seamlessly without discrete steps or how emergency shutdown mechanisms can be undermined. The AILCCP framework offers a more structured approach, emphasizing proactive controls and containment strategies that adapt to the dynamic nature of agent interactions.

https://law.stanford.edu/2026/03/07/kill-switches-dont-work-if-the-agent-writes-the-policy-the-berkeley-agentic-ai-profile-through-the-ailccp-lens/

Production AI Playbook: Human Oversight

Implementing human oversight in AI workflows mitigates risks by ensuring critical decisions are reviewed without slowing automation. Key patterns include chat approval, tool call gates, and multi-channel review to facilitate effective human-in-the-loop processes. These strategies enhance reliability by inserting review points for high-stakes actions, irreversible tasks, or ambiguous inputs, balancing oversight with efficiency.

https://blog.n8n.io/production-ai-playbook-human-oversight/

Scroll to Top