Security Culture
Insights
Blog
Four Things You Should Know About Security Champions Networks (But Probably Don’t)
Long before I joined Forrester, or even before I worked in cybersecurity, I volunteered with an informal group supporting my previous company’s security team. That experience stayed with me. It sparked my interest in cybersecurity and ultimately led me into the profession. Fast-forward to 2026, and I was thrilled to be asked to update our […]
Blog
The Future Of AppSec May Be Autonomous, But The Present Is Surprisingly Practical
AI is no longer a future feature in application security; it is rapidly becoming a core part of how application security (AppSec) tools identify, prioritize, and remediate risk. Yet despite aggressive vendor investment, adoption remains constrained by trust concerns, questions about value, and uncertainty about pricing models. In our new report, The State Of Artificial […]
Blog
An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
Blog
Human Risk Management MythBusters: What’s True, What’s False, And What’s Evolving
In less than 12 months, wars escalated and reescalated, markets swung wildly, trade tensions intensified, and even rice prices elevated, causing chaos. The pace of change has been relentless, and that’s before considering the volatility facing security leaders from AI or cybersecurity threats. Also, less than a year ago, I published a blog on human […]