Security Culture

Insights

Blog

Four Things You Should Know About Security Champions Networks (But Probably Don’t)

Madelein van der Hout August 9, 2026
Long before I joined Forrester, or even before I worked in cybersecurity, I volunteered with an informal group supporting my previous company’s security team. That experience stayed with me. It sparked my interest in cybersecurity and ultimately led me into the profession. Fast-forward to 2026, and I was thrilled to be asked to update our […]
Blog

The Future Of AppSec May Be Autonomous, But The Present Is Surprisingly Practical

Janet Worthington July 29, 2026
AI is no longer a future feature in application security; it is rapidly becoming a core part of how application security (AppSec) tools identify, prioritize, and remediate risk. Yet despite aggressive vendor investment, adoption remains constrained by trust concerns, questions about value, and uncertainty about pricing models. In our new report, The State Of Artificial […]
Blog

An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident

Jeff Pollard July 22, 2026
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
Blog

Human Risk Management MythBusters: What’s True, What’s False, And What’s Evolving

Jinan Budge July 9, 2026
In less than 12 months, wars escalated and reescalated, markets swung wildly, trade tensions intensified, and even rice prices elevated, causing chaos. The pace of change has been relentless, and that’s before considering the volatility facing security leaders from AI or cybersecurity threats. Also, less than a year ago, I published a blog on human […]