CISO

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree 2026-08-31 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity, […]

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree Read More »

What 90 days and a small budget can buy in AI agent security

What 90 days and a small budget can buy in AI agent security 2026-08-28 at 08:30 By Mirko Zorz In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing,

What 90 days and a small budget can buy in AI agent security Read More »

CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite

CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite 2026-08-27 at 14:15 By Kevin Townsend SecurityWeek talks to Chris Wheeler, CISO at Resilience, about his journey from the Navy to becoming a cybersecurity leader. The post CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to

CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite Read More »

Production data in testing is still common, and Tricentis’ CISO wants it gone

Production data in testing is still common, and Tricentis’ CISO wants it gone 2026-08-26 at 08:30 By Mirko Zorz In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught

Production data in testing is still common, and Tricentis’ CISO wants it gone Read More »

CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW

CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW 2026-08-18 at 17:30 By Kevin Townsend With no formal training and no career plan, Waisman built a path from Argentina’s early hacking scene to leading security at an AI-powered offensive security firm. The post CISO Conversations: Nico Waisman – From Self-Taught

CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW Read More »

Four corporate investigation mistakes organizations make under pressure

Four corporate investigation mistakes organizations make under pressure 2026-08-13 at 08:00 By Help Net Security In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and

Four corporate investigation mistakes organizations make under pressure Read More »

Post-quantum migration gets harder when every user holds a key

Post-quantum migration gets harder when every user holds a key 2026-08-12 at 09:00 By Mirko Zorz In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break

Post-quantum migration gets harder when every user holds a key Read More »

Who will be the Stanislav Petrov in your organization?

Who will be the Stanislav Petrov in your organization? 2026-08-11 at 09:00 By Help Net Security The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported

Who will be the Stanislav Petrov in your organization? Read More »

CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout

CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout 2026-08-04 at 17:30 By Kevin Townsend Russ Kirby, CISO at Ping Identity, shares how passion, courage, and “good enough” thinking shaped his path from HP to the C-suite—and what keeps him up at night. The post CISO Conversations: Russ Kirby – Passion Is the

CISO Conversations: Russ Kirby – Passion Is the Antidote to Burnout Read More »

Digital executive protection is a strategic imperative for CEOs

Digital executive protection is a strategic imperative for CEOs 2026-08-04 at 09:00 By Mirko Zorz In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email

Digital executive protection is a strategic imperative for CEOs Read More »

OWASP’s subtractive security project measures the attack paths you erased

OWASP’s subtractive security project measures the attack paths you erased 2026-08-04 at 08:30 By Mirko Zorz An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to anywhere, a scripting engine sitting there for the taking. Christopher Frenz

OWASP’s subtractive security project measures the attack paths you erased Read More »

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher 2026-07-30 at 09:15 By Mirko Zorz More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran without AI. Defenders bought similar technology and

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher Read More »

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced 2026-07-29 at 08:30 By Mirko Zorz A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced Read More »

Hugging Face breach reignites open-weights debate, raises liability questions

Hugging Face breach reignites open-weights debate, raises liability questions 2026-07-28 at 18:55 By Zeljka Zorz The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of

Hugging Face breach reignites open-weights debate, raises liability questions Read More »

Shadow AI incident response begins with logs that may already be gone

Shadow AI incident response begins with logs that may already be gone 2026-07-28 at 09:00 By Mirko Zorz In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound

Shadow AI incident response begins with logs that may already be gone Read More »

Building a defense in depth strategy for sensitive data

Building a defense in depth strategy for sensitive data 2026-07-23 at 07:00 By Help Net Security In this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting sensitive data. He argues that a single control, like encrypting a disk or

Building a defense in depth strategy for sensitive data Read More »

The air gap is a myth and other OT security truths

The air gap is a myth and other OT security truths 2026-07-21 at 09:00 By Mirko Zorz Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth.

The air gap is a myth and other OT security truths Read More »

The five step plan that cuts security budget waste

The five step plan that cuts security budget waste 2026-07-17 at 08:00 By Help Net Security In this Help Net Security video, Viktor Bulanek, CTO of Penetrify, explains where security budget waste comes from. Budgets get built around vendor categories, compliance checkboxes, and last year’s headlines. Attackers work along attack paths, and that mismatch is

The five step plan that cuts security budget waste Read More »

Scroll to Top