Risk Management

Pricing your bad days and how to build an economic model for security decisions

Pricing your bad days and how to build an economic model for security decisions 2026-10-08 at 09:00 By Mirko Zorz Ivan Milenkovic, VP Risk Technology EMEA at Qualys, explains how security leaders can build an economic model that puts money behind their decisions. He suggests starting with a few loss scenarios, then working down to […]

Pricing your bad days and how to build an economic model for security decisions Read More »

U.S. Bank CISO says the security role keeps growing and no one can own all of it

U.S. Bank CISO says the security role keeps growing and no one can own all of it 2026-10-06 at 09:00 By Mirko Zorz In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance. She […]

U.S. Bank CISO says the security role keeps growing and no one can own all of it Read More »

Three questions a hospital CISO should ask a healthcare fintech vendor

Three questions a hospital CISO should ask a healthcare fintech vendor 2026-10-05 at 08:30 By Mirko Zorz In this Help Net Security video, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every sprint, and issues touching patient data or funds disbursement come first. He covers […]

Three questions a hospital CISO should ask a healthcare fintech vendor Read More »

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says 2026-10-01 at 17:30 By Kevin Townsend PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures. The post Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says appeared […]

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says Read More »

Four Cyber Threats Harboring Big Plans for the Future

Four Cyber Threats Harboring Big Plans for the Future 2026-09-29 at 14:30 By Steve Durbin – AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. The post Four Cyber Threats Harboring Big Plans for the Future appeared first on SecurityWeek. This article is […]

Four Cyber Threats Harboring Big Plans for the Future Read More »

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot 2026-09-17 at 17:28 By Eduard Kovacs The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot Read More »

Comp AI Raises $34 Million for AI-Native Compliance and Security

Comp AI Raises $34 Million for AI-Native Compliance and Security 2026-09-17 at 16:00 By Ionut Arghire The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Comp AI Raises $34 Million for AI-Native Compliance and Security Read More »

The AI security question leaders should be asking instead

The AI security question leaders should be asking instead 2026-09-17 at 08:30 By Mirko Zorz In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why […]

The AI security question leaders should be asking instead Read More »

“We Think the Security Control Is Working” Is No Longer Good Enough

“We Think the Security Control Is Working” Is No Longer Good Enough 2026-09-15 at 22:30 By Sravish Sridhar Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek. […]

“We Think the Security Control Is Working” Is No Longer Good Enough Read More »

HelmGuard Raises $7.3 Million for Agentic GRC and Security

HelmGuard Raises $7.3 Million for Agentic GRC and Security 2026-09-09 at 20:23 By Ionut Arghire The company will increase its US market presence and will expand its engineering and go-to-market teams. The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

HelmGuard Raises $7.3 Million for Agentic GRC and Security Read More »

When AI quietly breaks things, who pays?

When AI quietly breaks things, who pays? 2026-09-03 at 08:00 By Mirko Zorz David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance […]

When AI quietly breaks things, who pays? Read More »

A battery storage cyberattack would look exactly like a badly tuned controller

A battery storage cyberattack would look exactly like a badly tuned controller 2026-09-02 at 12:00 By Mirko Zorz Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should […]

A battery storage cyberattack would look exactly like a badly tuned controller Read More »

AI vulnerability discovery scores the highest impact of 20 emerging risks

AI vulnerability discovery scores the highest impact of 20 emerging risks 2026-08-26 at 08:00 By Anamarija Pogorelec Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly […]

AI vulnerability discovery scores the highest impact of 20 emerging risks Read More »

Digital executive protection is a strategic imperative for CEOs

Digital executive protection is a strategic imperative for CEOs 2026-08-04 at 09:00 By Mirko Zorz In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email […]

Digital executive protection is a strategic imperative for CEOs Read More »

Aviation cyber risk sits on the ground, the blindness sits in the air

Aviation cyber risk sits on the ground, the blindness sits in the air 2026-07-31 at 08:30 By Mirko Zorz In this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in […]

Aviation cyber risk sits on the ground, the blindness sits in the air Read More »

US, Australia Release OT Isolation Guidance for Critical Infrastructure 

US, Australia Release OT Isolation Guidance for Critical Infrastructure  2026-07-29 at 13:58 By Ionut Arghire The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. The post US, Australia Release OT Isolation Guidance for Critical Infrastructure  appeared first on SecurityWeek. This article is […]

US, Australia Release OT Isolation Guidance for Critical Infrastructure  Read More »

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced 2026-07-29 at 08:30 By Mirko Zorz A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets […]

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced Read More »

The air gap is a myth and other OT security truths

The air gap is a myth and other OT security truths 2026-07-21 at 09:00 By Mirko Zorz Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. […]

The air gap is a myth and other OT security truths Read More »

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities 2026-07-15 at 17:07 By Ionut Arghire Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities Read More »

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure 2026-07-08 at 09:00 By Mirko Zorz In this interview with Help Net Security, Miranda Ritchie, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and […]

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure Read More »

Scroll to Top