security risk management

With the proliferation of data and the ubiquity of connected devices, organizations can move with unmatched efficiency, but simultaneously incur increased risks. Read our insights on how security & risk professionals can succeed in this environment.

Discover how Forrester supports IT and security and risk leaders.

Insights

Blog

Never Too Small, Part 2: The Rise Of The Cyber Ambulance Chasers

Jess Burn 3 days ago
Two years ago, several of us wrote that Arlington, Massachusetts wasn’t “too small for cybercriminals” after a business email compromise diverted nearly half a million dollars from a town construction project. The criminals didn’t target a major enterprise or a household brand. They found a small municipality with finite staff and resources and even less […]
Blog

An AI Security Facepalm: OpenAI’s Evaluation Became Hugging Face’s Incident

Jeff Pollard 4 days ago
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
Blog

Microsoft Makes Passkeys Default: What Identity And Security Leaders Need To Do

Geoff Cairns July 16, 2026
Microsoft’s decision to make passkeys the default authentication method in Entra ID signals a broader industry shift: phishing-resistant authentication is no longer optional. Identity and security leaders should use this moment to accelerate passkey adoption, reduce reliance on vulnerable MFA methods, and align authentication strategies with Zero Trust principles.
Blog

Thinking Of Vibe Coding Your CLM? Consider These Five Trade-Offs First

Alla Valente July 2, 2026
Interest in build vs. buy for contract lifecycle management (CLM) is resurging, eerily invoking early-2000s vibes (pun intended). AI makes it easy to spin up something that looks like a CLM system — if you squint, you can see it. I keep thinking of a recent article about a Wall Street techie that vibe coded […]
Blog

Quantum Negligence On The Clock: The US Just Set The Egg Timer On Quantum Migration As An Enterprise Risk

Alla Valente July 2, 2026
The question is no longer whether organizations should prepare for the quantum era, but how they will prove that they acted in time. New US guidance elevates post-quantum cryptography migration from a technology initiative to a board-level risk management responsibility.
Blog

Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And … AI

Allie Mellen June 25, 2026
Last week, Forrester released The Forrester Wave™: Extended Detection And Response Platforms, Q2 2026. This is the third iteration of the extended detection and response (XDR) Wave, with prior versions published in 2021 and 2024. This Wave differs significantly from the past, especially because of: The number of vendors. This year, only seven vendors were […]
Blog

AI Is Moving Fast, But Trust Is Struggling To Keep Up: Why Security And Risk Leaders Can’t Miss Forrester’s AI Forum

Jinan Budge June 24, 2026
AI adoption is accelerating, but confidence in its outcomes isn’t. At Forrester’s AI Forum 2026, security and risk leaders will learn how to shift from traditional protection to a trust-and-assurance mandate — with practical frameworks, real-world perspectives, and strategies to secure an increasingly agentic enterprise while enabling innovation.

Secure AI Agents Before You Scale

Scaling AI agents shouldn’t mean scaling exposure. Download Forrester’s AEGIS playbook to set guardrails on intent, authority, and access so that adoption stays accountable, auditable, and defensible.

Webinar

Inside Bank Of America’s Enterprise AI Playbook

Join us September 24 to see how Bank of America turned AI ambition into enterprise-wide impact by starting with customers and scaling with trust.
Webinar

How Tech Leaders Govern AI Outcomes At Scale – APAC

Join us July 21 to learn how CIOs and tech leaders turn AI into measurable business outcomes. Bring clarity, accountability, and value to your AI strategy.
Blog

Total Recall: A Cautionary Fable Of Anthropic And The US Government

Jeff Pollard June 15, 2026
On Friday, June 12, the same model class covered by our previous blog post went dark. Anthropic suspended Fable 5 and Mythos 5 worldwide after the US Department of Commerce issued an export control directive, which led to requests from prominent cybersecurity pros to undo the action. The bypass that triggered the export controls, per […]
Webinar

How Tech Leaders Govern AI Outcomes At Scale

Watch this webinar to learn how CIOs and tech leaders turn AI into measurable business outcomes. Bring clarity, accountability, and value to your AI strategy.
Blog

Unlock Your AI Opportunity At Forrester’s AI Forums

Sharyn Leaver June 4, 2026
Join us in Singapore or Sydney to learn how to turn AI momentum into measurable advantage. Our AI Forums are geared toward technology, security, marketing, and customer experience leaders and teams.

Save 10% On Our Technology & Innovation Forums This Summer

Register by July 31 to lock in summer advantage savings — 10% off your ticket to our Technology & Innovation Forums in Austin, New York City, or London. Turn ideas into action with frameworks and strategies you can use immediately.

Blog

Announcing The Forrester Wave™: Governance, Risk, And Compliance Platforms, Q2 2026

Paul McKay May 27, 2026
Check out the latest Forrester Wave™ evaluation of the governance, risk, and compliance platforms market and its findings.
Blog

Announcing Forrester’s 2026 Security & Risk Enterprise Leadership Award

Stephanie Balaouras May 18, 2026
Have a great story about leveraging security, privacy, and risk management to drive trust, resilience, and responsible innovation? We'd love to hear from you.
Blog

It’s Time To Challenge The Blockchain Industry On Quantum Security

Martha Bennett May 18, 2026
Mixed signals are emanating from the blockchain world: On the one hand, in March, we saw the publication of the paper, Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities: Resource Estimates and Mitigations, the authors of which include a member of the core Ethereum team; Solana also updated its quantum-safety roadmap in April. Forward to May, […]
Blog

OpenAI’s Daybreak Promises To Improve AppSec But Introduces A New Pricing Model: Five Buyer-Side Implications For CISOs

Jeff Pollard May 13, 2026
OpenAI recently announced Daybreak, its vision for making agentic application security faster and more capable. While promising, Daybreak will also make security more expensive per unit of work. In this model, customers will pay for tokens and multiagent workflows burn tokens. CISOs and CIOs should budget for application security (AppSec) line-item inflation, not deflation, with […]
Blog

Drowning In Rules: Navigating America’s AI Regulatory Patchwork

Alla Valente May 11, 2026
US companies are drowning in AI rules. With a labyrinth of conflicting state laws and no single federal requirement, even the most responsible innovators are struggling to stay afloat. California’s landmark Transparency in Frontier Artificial Intelligence Act proved that states can regulate AI without killing innovation, but it also underscores a hard truth: The current […]

Save 10% On B2B Forum EMEA This Summer

Register by July 31 to lock in Summer Advantage savings — 10% off your ticket to B2B Forum EMEA (28–29 Sept, London). Leave with a plan to win in the GTM singularity as AI‑driven buyers rewrite the rules.

Blog

Brussels Takes Seven Member States To Court Over CER, And The Consequences Land On You

Madelein van der Hout May 8, 2026
If you are a CISO at a critical-infrastructure organization in Bulgaria, France, Luxembourg, the Netherlands, Poland, Spain, or Sweden, your Critical Entities Resilience (CER) Directive enforcement clock just shortened. On May 7, 2026, the European Commission referred all seven member states to the Court of Justice of the European Union for failing to transpose the CER Directive more […]
Blog

Not A Vendor, Still A Breach: Vercel’s Third-Party Risk Failure

Alla Valente April 27, 2026
Some security incidents are complex. The Vercel incident is more troubling because it was predictable. The attackers did not exploit a procurement gap. They exploited a definition gap. Here’s what happened. A Vercel employee signed up for Context.ai’s AI Office Suite using a corporate Google account and clicked something effectively equivalent to “Allow All,” granting […]
Blog

Game Over For Trust: A Roblox Cheat Gives Attackers The Advantage

Janet Worthington April 27, 2026
A cascading supply chain attack did not start with a zero-day exploit, an unpatched vulnerability, or a brute-force attack. It started with a bored employee wanting to get ahead in an online game. A Context.ai employee downloaded a Roblox game cheat, an unofficial script for an online game that came bundled with Lumma Stealer malware […]
More posts