Risk Management

Aviation cyber risk sits on the ground, the blindness sits in the air

Aviation cyber risk sits on the ground, the blindness sits in the air 2026-07-31 at 08:30 By Mirko Zorz In this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in […]

Aviation cyber risk sits on the ground, the blindness sits in the air Read More »

US, Australia Release OT Isolation Guidance for Critical Infrastructure 

US, Australia Release OT Isolation Guidance for Critical Infrastructure  2026-07-29 at 13:58 By Ionut Arghire The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. The post US, Australia Release OT Isolation Guidance for Critical Infrastructure  appeared first on SecurityWeek. This article is

US, Australia Release OT Isolation Guidance for Critical Infrastructure  Read More »

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced 2026-07-29 at 08:30 By Mirko Zorz A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced Read More »

The air gap is a myth and other OT security truths

The air gap is a myth and other OT security truths 2026-07-21 at 09:00 By Mirko Zorz Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth.

The air gap is a myth and other OT security truths Read More »

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities 2026-07-15 at 17:07 By Ionut Arghire Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities Read More »

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure 2026-07-08 at 09:00 By Mirko Zorz In this interview with Help Net Security, Miranda Ritchie, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure Read More »

The Shift Toward Business-Aligned Risk Management

The Shift Toward Business-Aligned Risk Management 2026-07-06 at 18:20 By Steve Durbin Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. The post The Shift Toward Business-Aligned Risk Management appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

The Shift Toward Business-Aligned Risk Management Read More »

Organizations struggle to prioritize known cyber risks

Organizations struggle to prioritize known cyber risks 2026-07-03 at 07:30 By Anamarija Pogorelec Organizations collect more cyber risk data than ever, with many still struggling to build a unified view of their exposure. The latest State of Threat Management report from Filigran found that security teams continue to work across disconnected tools, leaving important context

Organizations struggle to prioritize known cyber risks Read More »

Who pays when you gate cyber-capable AI models?

Who pays when you gate cyber-capable AI models? 2026-06-22 at 09:00 By Mirko Zorz In this interview with Help Net Security, Jaya Baloo, COO & CISO at Aisle, examines the debate over restricting access to cyber-capable AI models. She lays out the strongest argument for gating these tools, then explains where it breaks down for

Who pays when you gate cyber-capable AI models? Read More »

Magnitude Emerges From Stealth Mode With $10 Million in Funding

Magnitude Emerges From Stealth Mode With $10 Million in Funding 2026-06-16 at 16:34 By Ionut Arghire The company is enhancing third-party risk management (TPRM) through autonomous AI agents. The post Magnitude Emerges From Stealth Mode With $10 Million in Funding appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Magnitude Emerges From Stealth Mode With $10 Million in Funding Read More »

Onspring CISO on where automated GRC systems fall short

Onspring CISO on where automated GRC systems fall short 2026-06-15 at 09:00 By Mirko Zorz In this interview with Help Net Security, Nichole Windholz, CISO at Onspring, talks about the limits of automated GRC systems and continuous control monitoring. She explains why color-coded dashboards can hide nuance, how teams can check the data feeding their

Onspring CISO on where automated GRC systems fall short Read More »

Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond

Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond 2026-06-04 at 17:45 By SecurityWeek News Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. The post Webinar Today: Third-Party Risk in Practice –

Webinar Today: Third-Party Risk in Practice – Where Programs Break Down and How to Respond Read More »

OAuth marketplace apps keep access after publishers vanish

OAuth marketplace apps keep access after publishers vanish 2026-06-04 at 16:06 By Mirko Zorz Installing an app from the Google Workspace Marketplace or GitHub Marketplace can grant a third party access to company email, files, calendars, code repositories, CI workflows, organization settings, and secrets. Marketplace presence gives these apps the appearance of approval. The OAuth

OAuth marketplace apps keep access after publishers vanish Read More »

The modern-day business can learn a lot about risk from this year’s mega events

The modern-day business can learn a lot about risk from this year’s mega events 2026-06-04 at 13:17 By Help Net Security Every year brings its share of global events, but 2026 is proving to be a banner year for mega-scale entertainment. The year got off to a roaring start with the Winter Olympics, and now

The modern-day business can learn a lot about risk from this year’s mega events Read More »

Spotless compliance evidence can still hide a broken control

Spotless compliance evidence can still hide a broken control 2026-06-04 at 09:26 By Mirko Zorz In this interview with Help Net Security, Marc Rubbinaccio, Head of Cybersecurity and Compliance at Secureframe, explains where security teams go wrong when preparing for CMMC and FedRAMP 20x. The conversation covers how organizations check the 110 requirements but miss

Spotless compliance evidence can still hide a broken control Read More »

Zero trust physical security needs trust decisions at the edge

Zero trust physical security needs trust decisions at the edge 2026-06-02 at 09:09 By Mirko Zorz In this interview with Help Net Security, Chuck Davis, VP, Global Information Security at Hikvision, explains how zero trust applies to physical security systems like cameras and door controllers. He breaks down how to make trust decisions at the

Zero trust physical security needs trust decisions at the edge Read More »

EU organizations buckle under rising compliance pressure

EU organizations buckle under rising compliance pressure 2026-06-01 at 08:19 By Sinisa Markovic Cybersecurity governance in the EU is shifting under expanding frameworks such as NIS2 and DORA, while AI raises new questions for security teams. What the future brings is hard to predict, and organizations must find a way to cope. Antonija Vojnović, Governance,

EU organizations buckle under rising compliance pressure Read More »

145 AI laws passed in 2025 and privacy teams aren’t catching a break

145 AI laws passed in 2025 and privacy teams aren’t catching a break 2026-06-01 at 08:19 By Anamarija Pogorelec 145 AI-related laws were enacted by state legislatures in 2025, and more than 1,000 additional bills were introduced or revised, according to DataGrail’s Privacy and AI Trends Report 2026. Average cost of manual data subject request

145 AI laws passed in 2025 and privacy teams aren’t catching a break Read More »

Building a risk-based vulnerability management program that scales

Building a risk-based vulnerability management program that scales 2026-05-29 at 08:01 By Help Net Security In this Help Net Security video, Shankar Somasundaram, CEO at Asimily, explains how to build a risk-based vulnerability program. He notes that vulnerabilities are exploding by an order of magnitude in the age of AI-driven attacks, with one customer finding

Building a risk-based vulnerability management program that scales Read More »

The CISO selling confidence in a market full of breach headlines

The CISO selling confidence in a market full of breach headlines 2026-05-28 at 10:16 By Mirko Zorz Engineering teams across enterprise IT are writing their own software with AI coding assistants, spinning up agents that act on their behalf, and assigning those agents the same access privileges their human creators hold. The shift has pulled

The CISO selling confidence in a market full of breach headlines Read More »

Scroll to Top