Security News

CISOs must shift from tactical defense to strategic leadership
2024-07-19 03:30

Fully 95% of IT and security professionals believe security threats will be more dangerous due to AI - yet, despite that elevated risk, nearly one in three security and IT professionals have no documented strategy in place to address generative AI risks. When leaders don't understand vulnerability management, they may not realize how changing leadership priorities can impact the security of their organization.

ChatGPTriage: How can CISOs see and control employees’ AI use?
2024-07-16 05:00

This rings true; I've spoken with nearly 100 enterprise CISOs in the first half of 2024, and their primary concerns are how to get visibility over employee AI use, how to enforce corporate policies on acceptable AI use, and how to prevent loss of customer data, intellectual property, and other confidential information. How is AI acceptable use policy expressed? Consider an AI data access policy: a law or consulting firm might require that LLM data from client A can't be used to generate answers for client B. A public company's general counsel might want an AI topic access policy: employees outside of finance and below the VP level can't ask about earnings info.

5 Key Questions CISOs Must Ask Themselves About Their Cybersecurity Strategy
2024-07-08 11:00

Every CISO knows that cybersecurity is an increasingly hot topic for executives and board members alike. Only 5% of CISOs report directly to the CEO, indicating a potential lack of high-level influence, and 2⁄3 's of CISOs are two levels down from the CEO in the reporting structure.

Inside the minds of CISOs
2024-07-02 03:30

In this Help Net Security video, Nick McKenzie, CISO of Bugcrowd, discusses the key findings from their recent report, which comes at a crucial time as security leaders' roles are being discussed more with the current risk landscape and the increasing need to prioritize security first over operational resilience in almost all verticals. Most CISOs believe AI makes the threat landscape impossible to secure.

CISOs becoming more comfortable with risk levels
2024-06-28 04:30

Contradicting legacy stereotypes of the CISO as inherently risk averse, only 16% of today's CISOs classified their current risk appetite as low. CISOs see their CEOs as much more risk averse than themselves, with twice as many respondents perceiving their CEO as having a low-risk appetite.

CISOs’ new ally: Qualys CyberSecurity Asset Management 3.0
2024-06-25 03:30

Qualys CyberSecurity Asset Management 3.0 consolidates asset discovery and risk assessment into a single solution. A key differentiator of Qualys CyberSecurity Asset Management 3.0 is in the way its External Attack Surface Management technology works.

Pressure mounts on CISOs as SEC bares teeth with legal action
2024-06-21 03:30

A Panaseer investigation into organizations’ annual 10-K filings reported to the SEC shows that from January-May 2024, at least 1,327 filings mentioned NIST – a key indicator that cybersecurity...

eBook: CISO guide to password security
2024-06-20 02:45

Please turn on your JavaScript for this page to function normally. Password security has seen dramatic shifts driven by the escalation of cyber threats and technological advancements.

Rising exploitation in enterprise software: Key trends for CISOs
2024-06-19 03:00

Action1 researchers found an alarming increase in the total number of vulnerabilities across all enterprise software categories. "With the NVD's delay in associating Common Vulnerabilities and Exposures identifiers with CPE data, our report comes at a critical moment, providing much-needed insights into the evolving vulnerability landscape for enterprise software," said Mike Walters, President of Action1.

The Annual SaaS Security Report: 2025 CISO Plans and Priorities
2024-06-18 11:23

Seventy percent of enterprises are prioritizing investment in SaaS security by establishing dedicated teams to secure SaaS applications, as part of a growing trend of maturity in this field of...