CISO Trends

The chief information security officer (CISO) role is growing in importance and remit. Discover the latest trends and analysis for CISOs and information security leaders.

Insights

Blog

Turn AEGIS Controls Into An Agentic AI Security Stack

Jeff Pollard 4 days ago
Agentic AI creates control, technology, and purchasing problems. Security leaders need to know the controls that they must satisfy, the technologies that can satisfy them, where existing tools already provide coverage, and where a new investment actually fills a gap. Far too often, we see clients conducting that process in reverse order … trying to […]
Blog

Chasing AI Won’t Save You From Ignoring Endpoint Security

Paddy Harrington 5 days ago
The rush to adopt AI and agentic technologies is capturing security leaders’ attention, but it risks overshadowing the controls that stop attacks before they start. Learn why strong endpoint protections remain essential for reducing risk, limiting exploitation paths, and enabling secure AI adoption.
Blog

The Capital Connection: Exploring Washington, DC During Security & Risk Forum 2026

Forrester 5 days ago
Security & Risk Forum 2026 brings security, risk, and resilience leaders to Washington, DC, a city where technology, governance, security, and public trust intersect every day. From iconic landmarks and Smithsonian museums to neighborhood cafes and networking-worthy restaurants, explore what to see and do while you’re in the nation’s capital.
Blog

The First Principles Of Cybersecurity Still Apply

Paddy Harrington August 18, 2026
As cyberthreats evolve and AI accelerates attacker capabilities, the most effective defenses remain the foundational practices many organizations overlook. Learn why recent attacks on critical infrastructure reinforce the need to focus on basic security principles before investing in new technologies.
Blog

Bringing Crypto Agility And PQC Visibility To The Network With NAV

Jitin Shabadu August 12, 2026
The Q4 2025 Forrester Wave™ evaluation for network analysis and visibility (NAV) solutions was the first iteration of the research to evaluate vendors on their post-quantum cryptography (PQC) capabilities, a decision that has become more pronounced in 2026. The rationale was compelling then; it is unavoidable now. Most notably, the US federal government has moved […]
Blog

Anthropic’s Pricing Shift Puts AI Consumption Risk Back On Customers

Tracy Woo August 12, 2026
Back in May of this year, Anthropic announced changes to its pricing model. Its original fixed-fee, per-seat subscription model was replaced with one that separates platform access from AI consumption. Customers still pay for access, but usage is now metered and billed separately based on token consumption. Under the previous model, customers were split into […]
Blog

Introducing AEGIS — The Guardrails That CISOs Need For The Agentic Enterprise

Jeff Pollard August 12, 2026
AI agents aren’t coming — they’re already here, and they’re not waiting for your security architecture to catch up. Learn how Forrester’s new AEGIS framework can help CISOs secure, govern, and manage AI agents and agentic infrastructure.
Blog

Harness Up For Our Black Hat 2026 Recap

Jess Burn August 10, 2026
Black Hat 2026 generated more questions than it answered. Are we headed for a vulnerability apocalypse (aka vulnpocalypse), or are we clearing a backlog of flaws that AI can now find with ease? Can organizations patch fast enough? What should buyers expect from vendors when software can reason? Will AI be our undoing or our […]
Blog

Four Things You Should Know About Security Champions Networks (But Probably Don’t)

Madelein van der Hout August 9, 2026
Long before I joined Forrester, or even before I worked in cybersecurity, I volunteered with an informal group supporting my previous company’s security team. That experience stayed with me. It sparked my interest in cybersecurity and ultimately led me into the profession. Fast-forward to 2026, and I was thrilled to be asked to update our […]
Blog

Microsoft’s Project Perception Announcement And How To Implement It Right

Allie Mellen July 27, 2026
Today, Microsoft announced Project Perception: a series of red, blue, and green team agents designed to be coordinated together in an agentic architecture to evaluate infrastructure and close gaps as close to autonomously as possible. The red team agents find potential paths to compromise, the blue team agents prioritize and evaluate them, and the green […]
Blog

Never Too Small, Part 2: The Rise Of The Cyber Ambulance Chasers

Jess Burn July 23, 2026
Two years ago, several of us wrote that Arlington, Massachusetts wasn’t “too small for cybercriminals” after a business email compromise diverted nearly half a million dollars from a town construction project. The criminals didn’t target a major enterprise or a household brand. They found a small municipality with finite staff and resources and even less […]
Blog

An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident

Jeff Pollard July 22, 2026
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
Blog

Human Risk Management MythBusters: What’s True, What’s False, And What’s Evolving

Jinan Budge July 9, 2026
In less than 12 months, wars escalated and reescalated, markets swung wildly, trade tensions intensified, and even rice prices elevated, causing chaos. The pace of change has been relentless, and that’s before considering the volatility facing security leaders from AI or cybersecurity threats. Also, less than a year ago, I published a blog on human […]
Blog

Databricks Unleashes The Genie: The Power Of The Four C’s

Kevin Ogunsua July 7, 2026
The Databricks Data + AI Summit 2026 signals a shift from experimentation to enterprise-scale, agentic AI. With over 30,000 attendees (representing a 36% annual increase) and global participation across more than 150 countries, Databricks is positioning itself as a foundational platform for data-intelligent applications. Last year, we wrote that Databricks went “beyond the lakehouse” by […]
Blog

The EU’s Digital Markets Act Meets The Mobile OS, Round Two

Paddy Harrington June 24, 2026
Tensions between regulators and mobile platform leaders are raising a critical question: How far should openness go when it could expose users to new risks? This blog explores the trade-offs between device freedom, platform safeguards, and the growing security implications of AI-powered assistants.
Blog

Total Recall: A Cautionary Fable Of Anthropic And The US Government

Jeff Pollard June 15, 2026
On Friday, June 12, the same model class covered by our previous blog post went dark. Anthropic suspended Fable 5 and Mythos 5 worldwide after the US Department of Commerce issued an export control directive, which led to requests from prominent cybersecurity pros to undo the action. The bypass that triggered the export controls, per […]
Blog

How Fable 5 And Mythos 5 Change AI Security, Data Retention, And Vendor Risk

Jeff Pollard June 10, 2026
Anthropic’s Fable 5 and Mythos 5 is the most 2026 product launch you’ll read this year. The same model can find nation-state zero days, design novel drug candidates, and play FireRed on a Gameboy Advance with nothing but screenshots. And for the gaming fans out there, yes, we got Fable 5 before Fable 4. These […]
Blog

Announcing Forrester’s Top Cybersecurity Threats For 2026

Jitin Shabadu June 10, 2026
AI innovation is moving at an unprecedented rate, and geopolitical tensions show no signs of easing. Forrester identifies these factors as two primary forces reshaping the threat landscape, placing additional strain on CISOs who are already stretched thin managing increasingly complex security programs. Anthropic’s Claude Mythos Preview and Project Glasswing are early signals of how […]
Blog

Announcing The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026

Geoff Cairns May 21, 2026
Our latest evaluation of workforce identity security providers, The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026 is now available! Workforce identity security is now a strategic pillar of modern cybersecurity, driven by the expansion of nonhuman identities, increasingly sophisticated identity‑based attacks, and the operational demands of Zero Trust. Organizations already grappling with identity sprawl across […]
Blog

OpenAI’s Daybreak Promises To Improve AppSec But Introduces A New Pricing Model: Five Buyer-Side Implications For CISOs

Jeff Pollard May 13, 2026
OpenAI recently announced Daybreak, its vision for making agentic application security faster and more capable. While promising, Daybreak will also make security more expensive per unit of work. In this model, customers will pay for tokens and multiagent workflows burn tokens. CISOs and CIOs should budget for application security (AppSec) line-item inflation, not deflation, with […]
More posts