CISO Trends

The chief information security officer (CISO) role is growing in importance and remit. Discover the latest trends and analysis for CISOs and information security leaders.

Insights

Blog

Microsoft’s Project Perception Announcement And How To Implement It Right

Allie Mellen 1 day ago
Today, Microsoft announced Project Perception: a series of red, blue, and green team agents designed to be coordinated together in an agentic architecture to evaluate infrastructure and close gaps as close to autonomously as possible. The red team agents find potential paths to compromise, the blue team agents prioritize and evaluate them, and the green […]
Blog

Never Too Small, Part 2: The Rise Of The Cyber Ambulance Chasers

Jess Burn 6 days ago
Two years ago, several of us wrote that Arlington, Massachusetts wasn’t “too small for cybercriminals” after a business email compromise diverted nearly half a million dollars from a town construction project. The criminals didn’t target a major enterprise or a household brand. They found a small municipality with finite staff and resources and even less […]
Blog

An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident

Jeff Pollard 7 days ago
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
Blog

Human Risk Management MythBusters: What’s True, What’s False, And What’s Evolving

Jinan Budge July 9, 2026
In less than 12 months, wars escalated and reescalated, markets swung wildly, trade tensions intensified, and even rice prices elevated, causing chaos. The pace of change has been relentless, and that’s before considering the volatility facing security leaders from AI or cybersecurity threats. Also, less than a year ago, I published a blog on human […]
Blog

Databricks Unleashes The Genie: The Power Of The Four C’s

Kevin Ogunsua July 7, 2026
The Databricks Data + AI Summit 2026 signals a shift from experimentation to enterprise-scale, agentic AI. With over 30,000 attendees (representing a 36% annual increase) and global participation across more than 150 countries, Databricks is positioning itself as a foundational platform for data-intelligent applications. Last year, we wrote that Databricks went “beyond the lakehouse” by […]
Blog

The EU’s Digital Markets Act Meets The Mobile OS, Round Two

Paddy Harrington June 24, 2026
Tensions between regulators and mobile platform leaders are raising a critical question: How far should openness go when it could expose users to new risks? This blog explores the trade-offs between device freedom, platform safeguards, and the growing security implications of AI-powered assistants.
Blog

Total Recall: A Cautionary Fable Of Anthropic And The US Government

Jeff Pollard June 15, 2026
On Friday, June 12, the same model class covered by our previous blog post went dark. Anthropic suspended Fable 5 and Mythos 5 worldwide after the US Department of Commerce issued an export control directive, which led to requests from prominent cybersecurity pros to undo the action. The bypass that triggered the export controls, per […]
Blog

How Fable 5 And Mythos 5 Change AI Security, Data Retention, And Vendor Risk

Jeff Pollard June 10, 2026
Anthropic’s Fable 5 and Mythos 5 is the most 2026 product launch you’ll read this year. The same model can find nation-state zero days, design novel drug candidates, and play FireRed on a Gameboy Advance with nothing but screenshots. And for the gaming fans out there, yes, we got Fable 5 before Fable 4. These […]
Blog

Announcing Forrester’s Top Cybersecurity Threats For 2026

Jitin Shabadu June 10, 2026
AI innovation is moving at an unprecedented rate, and geopolitical tensions show no signs of easing. Forrester identifies these factors as two primary forces reshaping the threat landscape, placing additional strain on CISOs who are already stretched thin managing increasingly complex security programs. Anthropic’s Claude Mythos Preview and Project Glasswing are early signals of how […]
Blog

Announcing The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026

Geoff Cairns May 21, 2026
Our latest evaluation of workforce identity security providers, The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026 is now available! Workforce identity security is now a strategic pillar of modern cybersecurity, driven by the expansion of nonhuman identities, increasingly sophisticated identity‑based attacks, and the operational demands of Zero Trust. Organizations already grappling with identity sprawl across […]
Blog

OpenAI’s Daybreak Promises To Improve AppSec But Introduces A New Pricing Model: Five Buyer-Side Implications For CISOs

Jeff Pollard May 13, 2026
OpenAI recently announced Daybreak, its vision for making agentic application security faster and more capable. While promising, Daybreak will also make security more expensive per unit of work. In this model, customers will pay for tokens and multiagent workflows burn tokens. CISOs and CIOs should budget for application security (AppSec) line-item inflation, not deflation, with […]
Blog

How CISOs Can Thrive Amid Geopolitical And Economic Uncertainty

Merritt Maxim April 20, 2026
Amid escalating geopolitical conflicts, economic turmoil, and ongoing tariff chaos, chief information security officers (CISOs) are operating in a prolonged state of uncertainty in which cyberattacks have become a new component of armed conflict, expanding the attack surface just as organizations are struggling to secure AI and critical infrastructure. Security leaders are also facing budget […]
Blog

Project Glasswing: The 10 Consequences Nobody’s Writing About Yet

Jeff Pollard April 10, 2026
Anthropic’s Project Glasswing and Claude Mythos Preview prove that autonomous zero-day discovery now operates at scale. We evaluate the immediate, medium-term, and structural consequences for security teams, vendors, insurers, regulators, and future careers.
Blog

Project Glasswing Shows That AI Will Break The Vulnerability Management Playbook

Erik Nost April 8, 2026
Anthropic, along with 11 other companies, recently announced Project Glasswing — an initiative that aims to secure software in the wake of advances in AI capabilities, most notably Anthropic’s Claude Mythos Preview frontier model. Project Glasswing is made up of a who’s who of tech companies, cybersecurity vendors, and others: Amazon Web Services, Anthropic, Apple, […]
Blog

RSAC 2026: An AI Coming-Of-Age Story Without The Romance

James Plouffe March 31, 2026
RSAC Conference 2026 has come and gone. Gone, too, are the petting zoos of yesteryear, replaced this year by — of all things — pop-up tattoo parlors. Or as one attendee observed, “We’ve traded livestock for live needles.” This year’s attendance of over 43,500 was flat compared to 2025, but the sessions and exhibit floor […]
Blog

Geopolitical Volatility Has Become A Technology Leadership Test

Stephanie Balaouras March 24, 2026
Geopolitical volatility is testing and redefining technology leadership, demanding sharper trade-offs, stronger resilience, and faster decisions from CIOs and CISOs. Read guidance from our new research to help navigate these challenges.
Blog

From Sedimentary To Strategic: Rethinking Security Organizational Design

Madelein van der Hout March 19, 2026
Security organizational design sits at the intersection of strategy and circumstance. External pressures force change, while internal constraints limit redesign.
Blog

The Security Priorities APAC And EMEA Leaders Doubled Down On — And Deprioritized — In H2 2025

Jinan Budge March 17, 2026
In the second half of 2025, security and risk (S&R) leaders in APAC and EMEA continued to grapple with familiar pressures, but they reprioritized how they address them. While AI; governance, risk, and compliance (GRC); and third-party risk management (TPRM) stayed stubbornly on top of the charts, application security and security organization structure resurfaced with […]
Blog

Prevent MDR-To-IR Handoff Chaos Before A Breach

Jess Burn March 16, 2026
Security leaders often assume that once they’ve invested in managed detection and response (MDR) services, the hardest parts of breach detection and response are behind them. Alerts are monitored. Playbooks exist. Someone is watching the environment 24/7. Then, they have a security incident. It escalates quickly. And the response feels less coordinated than expected. We […]
Blog

The Stryker Attack: Enterprise Resiliency Plans Can’t Ignore UEM

Paddy Harrington March 13, 2026
The alleged Stryker cyberattack underscores a critical blind spot in enterprise resilience strategies: the outsized risk and impact of compromised device and endpoint management platforms.
More posts