CISO Trends
The chief information security officer (CISO) role is growing in importance and remit. Discover the latest trends and analysis for CISOs and information security leaders.
Insights
Blog
Cars Have Joined The Android Malware Economy
The first malware designed specifically for Android-powered vehicle systems signals that attackers now view cars as another endpoint in the broader technology ecosystem. Security leaders should assess how connected vehicles, mobile devices, and enterprise systems intersect as automotive platforms become part of the expanding attack surface.
Blog
CISOs: Stop Arguing That AI Doesn’t Work — Start Arguing About What It Costs
Last year, we took the stage at Forrester’s Security & Risk Forum to challenge the stories leadership teams were beginning to tell themselves about AI. That keynote became our new report, Resetting Security’s AI Narrative With Boards And Executives. We wrote it because CISO clients keep coming to us with the same concern: The AI […]
Blog
OT Security’s Next Chapter Starts When Asset Discovery Stops Being The Goal
OT security has moved beyond simply identifying connected devices. Learn why leading organizations are shifting their focus toward reducing operational risk, strengthening resilience, and enabling safer IT and OT security collaboration.
Blog
Intent Is The New Epicenter Of Agentic Security
Cybersecurity spent decades trying to stop things from happening, identifying them, and then investigating what happened. Agentic AI challenges us with a much more difficult question: What was the system trying to do? Agents don’t just execute instructions. They interpret objectives, select tools, access data, cross systems, and change tactics. In most cases, a user […]
Blog
Turn AEGIS Controls Into An Agentic AI Security Stack
Agentic AI creates control, technology, and purchasing problems. Security leaders need to know the controls that they must satisfy, the technologies that can satisfy them, where existing tools already provide coverage, and where a new investment actually fills a gap. Far too often, we see clients conducting that process in reverse order … trying to […]
Blog
Chasing AI Won’t Save You From Ignoring Endpoint Security
The rush to adopt AI and agentic technologies is capturing security leaders’ attention, but it risks overshadowing the controls that stop attacks before they start. Learn why strong endpoint protections remain essential for reducing risk, limiting exploitation paths, and enabling secure AI adoption.
Blog
The Capital Connection: Exploring Washington, DC During Security & Risk Forum 2026
Security & Risk Forum 2026 brings security, risk, and resilience leaders to Washington, DC, a city where technology, governance, security, and public trust intersect every day. From iconic landmarks and Smithsonian museums to neighborhood cafes and networking-worthy restaurants, explore what to see and do while you’re in the nation’s capital.
Blog
The First Principles Of Cybersecurity Still Apply
As cyberthreats evolve and AI accelerates attacker capabilities, the most effective defenses remain the foundational practices many organizations overlook. Learn why recent attacks on critical infrastructure reinforce the need to focus on basic security principles before investing in new technologies.
Blog
Bringing Crypto Agility And PQC Visibility To The Network With NAV
The Q4 2025 Forrester Wave™ evaluation for network analysis and visibility (NAV) solutions was the first iteration of the research to evaluate vendors on their post-quantum cryptography (PQC) capabilities, a decision that has become more pronounced in 2026. The rationale was compelling then; it is unavoidable now. Most notably, the US federal government has moved […]
Blog
Anthropic’s Pricing Shift Puts AI Consumption Risk Back On Customers
Back in May of this year, Anthropic announced changes to its pricing model. Its original fixed-fee, per-seat subscription model was replaced with one that separates platform access from AI consumption. Customers still pay for access, but usage is now metered and billed separately based on token consumption. Under the previous model, customers were split into […]
Blog
Introducing AEGIS — The Guardrails That CISOs Need For The Agentic Enterprise
AI agents aren’t coming — they’re already here, and they’re not waiting for your security architecture to catch up. Learn how Forrester’s new AEGIS framework can help CISOs secure, govern, and manage AI agents and agentic infrastructure.
Blog
Harness Up For Our Black Hat 2026 Recap
Black Hat 2026 generated more questions than it answered. Are we headed for a vulnerability apocalypse (aka vulnpocalypse), or are we clearing a backlog of flaws that AI can now find with ease? Can organizations patch fast enough? What should buyers expect from vendors when software can reason? Will AI be our undoing or our […]
Blog
Four Things You Should Know About Security Champions Networks (But Probably Don’t)
Long before I joined Forrester, or even before I worked in cybersecurity, I volunteered with an informal group supporting my previous company’s security team. That experience stayed with me. It sparked my interest in cybersecurity and ultimately led me into the profession. Fast-forward to 2026, and I was thrilled to be asked to update our […]
Blog
Microsoft’s Project Perception Announcement And How To Implement It Right
Today, Microsoft announced Project Perception: a series of red, blue, and green team agents designed to be coordinated together in an agentic architecture to evaluate infrastructure and close gaps as close to autonomously as possible. The red team agents find potential paths to compromise, the blue team agents prioritize and evaluate them, and the green […]
Blog
Never Too Small, Part 2: The Rise Of The Cyber Ambulance Chasers
Two years ago, several of us wrote that Arlington, Massachusetts wasn’t “too small for cybercriminals” after a business email compromise diverted nearly half a million dollars from a town construction project. The criminals didn’t target a major enterprise or a household brand. They found a small municipality with finite staff and resources and even less […]
Blog
An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
Blog
Human Risk Management MythBusters: What’s True, What’s False, And What’s Evolving
In less than 12 months, wars escalated and reescalated, markets swung wildly, trade tensions intensified, and even rice prices elevated, causing chaos. The pace of change has been relentless, and that’s before considering the volatility facing security leaders from AI or cybersecurity threats. Also, less than a year ago, I published a blog on human […]
Blog
Databricks Unleashes The Genie: The Power Of The Four C’s
The Databricks Data + AI Summit 2026 signals a shift from experimentation to enterprise-scale, agentic AI. With over 30,000 attendees (representing a 36% annual increase) and global participation across more than 150 countries, Databricks is positioning itself as a foundational platform for data-intelligent applications. Last year, we wrote that Databricks went “beyond the lakehouse” by […]
Blog
The EU’s Digital Markets Act Meets The Mobile OS, Round Two
Tensions between regulators and mobile platform leaders are raising a critical question: How far should openness go when it could expose users to new risks? This blog explores the trade-offs between device freedom, platform safeguards, and the growing security implications of AI-powered assistants.
Blog
Total Recall: A Cautionary Fable Of Anthropic And The US Government
On Friday, June 12, the same model class covered by our previous blog post went dark. Anthropic suspended Fable 5 and Mythos 5 worldwide after the US Department of Commerce issued an export control directive, which led to requests from prominent cybersecurity pros to undo the action. The bypass that triggered the export controls, per […]
More posts