CISO Trends
The chief information security officer (CISO) role is growing in importance and remit. Discover the latest trends and analysis for CISOs and information security leaders.
Insights
Blog
The AI Doomsday Circus: Don’t “Step Right Up!”
Don’t let AI doomsday headlines dictate your strategy. Stay grounded in what’s real, manage the risks you can control, and focus on the investments most likely to create new value.
Blog
Announcing The Forrester Wave™: Proactive Security Platforms, Q3 2026
Last week, we released The Forrester Wave™: Proactive Security Platforms, Q3 2026. This is the first evaluation of this market under this title, which has evolved from attack surface management and unified vulnerability management. Security teams have increasingly turned to vulnerability risk management, attack surface management, and exposure management to decide which weaknesses matter most. […]
Blog
Manage Insider Risk To Protect Your Potential
National Insider Threat Awareness Month is drawing to a close. This year’s theme, “Protect Our Potential,” speaks directly to the impact that insider incidents can have. According to Forrester data, insider incidents account for 25% of data breaches, and a third of those incidents are due to malicious intent. Yet many organizations still don’t have […]
Blog
Cars Have Joined The Android Malware Economy
The first malware designed specifically for Android-powered vehicle systems signals that attackers now view cars as another endpoint in the broader technology ecosystem. Security leaders should assess how connected vehicles, mobile devices, and enterprise systems intersect as automotive platforms become part of the expanding attack surface.
Blog
CISOs: Stop Arguing That AI Doesn’t Work — Start Arguing About What It Costs
Last year, we took the stage at Forrester’s Security & Risk Forum to challenge the stories leadership teams were beginning to tell themselves about AI. That keynote became our new report, Resetting Security’s AI Narrative With Boards And Executives. We wrote it because CISO clients keep coming to us with the same concern: The AI […]
Blog
OT Security’s Next Chapter Starts When Asset Discovery Stops Being The Goal
OT security has moved beyond simply identifying connected devices. Learn why leading organizations are shifting their focus toward reducing operational risk, strengthening resilience, and enabling safer IT and OT security collaboration.
Blog
Intent Is The New Epicenter Of Agentic Security
Cybersecurity spent decades trying to stop things from happening, identifying them, and then investigating what happened. Agentic AI challenges us with a much more difficult question: What was the system trying to do? Agents don’t just execute instructions. They interpret objectives, select tools, access data, cross systems, and change tactics. In most cases, a user […]
Blog
Turn AEGIS Controls Into An Agentic AI Security Stack
Agentic AI creates control, technology, and purchasing problems. Security leaders need to know the controls that they must satisfy, the technologies that can satisfy them, where existing tools already provide coverage, and where a new investment actually fills a gap. Far too often, we see clients conducting that process in reverse order … trying to […]
Blog
Chasing AI Won’t Save You From Ignoring Endpoint Security
The rush to adopt AI and agentic technologies is capturing security leaders’ attention, but it risks overshadowing the controls that stop attacks before they start. Learn why strong endpoint protections remain essential for reducing risk, limiting exploitation paths, and enabling secure AI adoption.
Blog
The Capital Connection: Exploring Washington, DC During Security & Risk Forum 2026
Security & Risk Forum 2026 brings security, risk, and resilience leaders to Washington, DC, a city where technology, governance, security, and public trust intersect every day. From iconic landmarks and Smithsonian museums to neighborhood cafes and networking-worthy restaurants, explore what to see and do while you’re in the nation’s capital.
Blog
The First Principles Of Cybersecurity Still Apply
As cyberthreats evolve and AI accelerates attacker capabilities, the most effective defenses remain the foundational practices many organizations overlook. Learn why recent attacks on critical infrastructure reinforce the need to focus on basic security principles before investing in new technologies.
Blog
Bringing Crypto Agility And PQC Visibility To The Network With NAV
The Q4 2025 Forrester Wave™ evaluation for network analysis and visibility (NAV) solutions was the first iteration of the research to evaluate vendors on their post-quantum cryptography (PQC) capabilities, a decision that has become more pronounced in 2026. The rationale was compelling then; it is unavoidable now. Most notably, the US federal government has moved […]
Blog
Anthropic’s Pricing Shift Puts AI Consumption Risk Back On Customers
Back in May of this year, Anthropic announced changes to its pricing model. Its original fixed-fee, per-seat subscription model was replaced with one that separates platform access from AI consumption. Customers still pay for access, but usage is now metered and billed separately based on token consumption. Under the previous model, customers were split into […]
Blog
Introducing AEGIS — The Guardrails That CISOs Need For The Agentic Enterprise
AI agents aren’t coming — they’re already here, and they’re not waiting for your security architecture to catch up. Learn how Forrester’s new AEGIS framework can help CISOs secure, govern, and manage AI agents and agentic infrastructure.
Blog
Harness Up For Our Black Hat 2026 Recap
Black Hat 2026 generated more questions than it answered. Are we headed for a vulnerability apocalypse (aka vulnpocalypse), or are we clearing a backlog of flaws that AI can now find with ease? Can organizations patch fast enough? What should buyers expect from vendors when software can reason? Will AI be our undoing or our […]
Blog
Four Things You Should Know About Security Champions Networks (But Probably Don’t)
Long before I joined Forrester, or even before I worked in cybersecurity, I volunteered with an informal group supporting my previous company’s security team. That experience stayed with me. It sparked my interest in cybersecurity and ultimately led me into the profession. Fast-forward to 2026, and I was thrilled to be asked to update our […]
Blog
Microsoft’s Project Perception Announcement And How To Implement It Right
Today, Microsoft announced Project Perception: a series of red, blue, and green team agents designed to be coordinated together in an agentic architecture to evaluate infrastructure and close gaps as close to autonomously as possible. The red team agents find potential paths to compromise, the blue team agents prioritize and evaluate them, and the green […]
Blog
Never Too Small, Part 2: The Rise Of The Cyber Ambulance Chasers
Two years ago, several of us wrote that Arlington, Massachusetts wasn’t “too small for cybercriminals” after a business email compromise diverted nearly half a million dollars from a town construction project. The criminals didn’t target a major enterprise or a household brand. They found a small municipality with finite staff and resources and even less […]
Blog
An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
Blog
Human Risk Management MythBusters: What’s True, What’s False, And What’s Evolving
In less than 12 months, wars escalated and reescalated, markets swung wildly, trade tensions intensified, and even rice prices elevated, causing chaos. The pace of change has been relentless, and that’s before considering the volatility facing security leaders from AI or cybersecurity threats. Also, less than a year ago, I published a blog on human […]
More posts