Risk Management

“We Think the Security Control Is Working” Is No Longer Good Enough

“We Think the Security Control Is Working” Is No Longer Good Enough 2026-09-15 at 22:30 By Sravish Sridhar Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek. […]

“We Think the Security Control Is Working” Is No Longer Good Enough Read More »

HelmGuard Raises $7.3 Million for Agentic GRC and Security

HelmGuard Raises $7.3 Million for Agentic GRC and Security 2026-09-09 at 20:23 By Ionut Arghire The company will increase its US market presence and will expand its engineering and go-to-market teams. The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

HelmGuard Raises $7.3 Million for Agentic GRC and Security Read More »

When AI quietly breaks things, who pays?

When AI quietly breaks things, who pays? 2026-09-03 at 08:00 By Mirko Zorz David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance […]

When AI quietly breaks things, who pays? Read More »

A battery storage cyberattack would look exactly like a badly tuned controller

A battery storage cyberattack would look exactly like a badly tuned controller 2026-09-02 at 12:00 By Mirko Zorz Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should […]

A battery storage cyberattack would look exactly like a badly tuned controller Read More »

AI vulnerability discovery scores the highest impact of 20 emerging risks

AI vulnerability discovery scores the highest impact of 20 emerging risks 2026-08-26 at 08:00 By Anamarija Pogorelec Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly […]

AI vulnerability discovery scores the highest impact of 20 emerging risks Read More »

Digital executive protection is a strategic imperative for CEOs

Digital executive protection is a strategic imperative for CEOs 2026-08-04 at 09:00 By Mirko Zorz In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email […]

Digital executive protection is a strategic imperative for CEOs Read More »

Aviation cyber risk sits on the ground, the blindness sits in the air

Aviation cyber risk sits on the ground, the blindness sits in the air 2026-07-31 at 08:30 By Mirko Zorz In this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in […]

Aviation cyber risk sits on the ground, the blindness sits in the air Read More »

US, Australia Release OT Isolation Guidance for Critical Infrastructure 

US, Australia Release OT Isolation Guidance for Critical Infrastructure  2026-07-29 at 13:58 By Ionut Arghire The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. The post US, Australia Release OT Isolation Guidance for Critical Infrastructure  appeared first on SecurityWeek. This article is […]

US, Australia Release OT Isolation Guidance for Critical Infrastructure  Read More »

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced 2026-07-29 at 08:30 By Mirko Zorz A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets […]

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced Read More »

The air gap is a myth and other OT security truths

The air gap is a myth and other OT security truths 2026-07-21 at 09:00 By Mirko Zorz Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. […]

The air gap is a myth and other OT security truths Read More »

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities 2026-07-15 at 17:07 By Ionut Arghire Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities Read More »

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure 2026-07-08 at 09:00 By Mirko Zorz In this interview with Help Net Security, Miranda Ritchie, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and […]

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure Read More »

The Shift Toward Business-Aligned Risk Management

The Shift Toward Business-Aligned Risk Management 2026-07-06 at 18:20 By Steve Durbin Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. The post The Shift Toward Business-Aligned Risk Management appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

The Shift Toward Business-Aligned Risk Management Read More »

Organizations struggle to prioritize known cyber risks

Organizations struggle to prioritize known cyber risks 2026-07-03 at 07:30 By Anamarija Pogorelec Organizations collect more cyber risk data than ever, with many still struggling to build a unified view of their exposure. The latest State of Threat Management report from Filigran found that security teams continue to work across disconnected tools, leaving important context […]

Organizations struggle to prioritize known cyber risks Read More »

Who pays when you gate cyber-capable AI models?

Who pays when you gate cyber-capable AI models? 2026-06-22 at 09:00 By Mirko Zorz In this interview with Help Net Security, Jaya Baloo, COO & CISO at Aisle, examines the debate over restricting access to cyber-capable AI models. She lays out the strongest argument for gating these tools, then explains where it breaks down for […]

Who pays when you gate cyber-capable AI models? Read More »

Magnitude Emerges From Stealth Mode With $10 Million in Funding

Magnitude Emerges From Stealth Mode With $10 Million in Funding 2026-06-16 at 16:34 By Ionut Arghire The company is enhancing third-party risk management (TPRM) through autonomous AI agents. The post Magnitude Emerges From Stealth Mode With $10 Million in Funding appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Magnitude Emerges From Stealth Mode With $10 Million in Funding Read More »

Onspring CISO on where automated GRC systems fall short

Onspring CISO on where automated GRC systems fall short 2026-06-15 at 09:00 By Mirko Zorz In this interview with Help Net Security, Nichole Windholz, CISO at Onspring, talks about the limits of automated GRC systems and continuous control monitoring. She explains why color-coded dashboards can hide nuance, how teams can check the data feeding their […]

Onspring CISO on where automated GRC systems fall short Read More »

Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond

Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond 2026-06-04 at 17:45 By SecurityWeek News Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. The post Webinar Today: Third-Party Risk in Practice – […]

Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond Read More »

OAuth marketplace apps keep access after publishers vanish

OAuth marketplace apps keep access after publishers vanish 2026-06-04 at 16:06 By Mirko Zorz Installing an app from the Google Workspace Marketplace or GitHub Marketplace can grant a third party access to company email, files, calendars, code repositories, CI workflows, organization settings, and secrets. Marketplace presence gives these apps the appearance of approval. The OAuth […]

OAuth marketplace apps keep access after publishers vanish Read More »

The modern-day business can learn a lot about risk from this year’s mega events

The modern-day business can learn a lot about risk from this year’s mega events 2026-06-04 at 13:17 By Help Net Security Every year brings its share of global events, but 2026 is proving to be a banner year for mega-scale entertainment. The year got off to a roaring start with the Winter Olympics, and now […]

The modern-day business can learn a lot about risk from this year’s mega events Read More »

Scroll to Top