Risk Management

Stop building security goals around controls

Stop building security goals around controls 2026-03-18 at 09:27 By Mirko Zorz In this Help Net Security interview, Devin Rudnicki, CISO at Fitch Group, argues that security strategy fails when it loses its connection to business outcomes. Rudnicki walks through how to align security goals with corporate priorities, why CISOs must present risk in terms […]

Stop building security goals around controls Read More »

Airbus CSO on supply chain blind spots, space threats, and the limits of AI red-teaming

Airbus CSO on supply chain blind spots, space threats, and the limits of AI red-teaming 2026-03-10 at 08:30 By Mirko Zorz Pascal Andrei, CSO at Airbus, knows that the aerospace and defense sector is facing a threat environment that is evolving faster than most organizations can track. From sub-tier suppliers quietly becoming entry points for

Airbus CSO on supply chain blind spots, space threats, and the limits of AI red-teaming Read More »

ArmorCode Raises $16 Million for Exposure Management Platform

ArmorCode Raises $16 Million for Exposure Management Platform 2026-03-06 at 18:14 By Ionut Arghire The company will accelerate platform development, expand go-to-market efforts, and invest in product innovation. The post ArmorCode Raises $16 Million for Exposure Management Platform appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

ArmorCode Raises $16 Million for Exposure Management Platform Read More »

Security debt is becoming a governance issue for CISOs

Security debt is becoming a governance issue for CISOs 2026-03-02 at 08:30 By Mirko Zorz Application security backlogs keep expanding across large development portfolios. Veracode’s 2026 State of Software Security Report puts numbers behind a familiar operational pattern, fixes lag discovery, and older weaknesses stay open across release cycles. 2026 findings against the 2025 baseline

Security debt is becoming a governance issue for CISOs Read More »

Four Risks Boards Cannot Treat as Background Noise

Four Risks Boards Cannot Treat as Background Noise 2026-02-26 at 19:30 By Steve Durbin The goal isn’t about preventing every attack but about keeping the business running when attacks succeed. The post Four Risks Boards Cannot Treat as Background Noise appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Four Risks Boards Cannot Treat as Background Noise Read More »

The $19.5 million insider risk problem

The $19.5 million insider risk problem 2026-02-26 at 09:09 By Mirko Zorz Routine employee activity across corporate systems carries an average annual cost of $19.5 million per organization. That figure comes from the 2026 Cost of Insider Risks Global Report, conducted by the Ponemon Institute and based on data from 354 organizations that experienced one

The $19.5 million insider risk problem Read More »

Lema AI Emerges From Stealth With $24 Million to Tackle Third-Party Risk 

Lema AI Emerges From Stealth With $24 Million to Tackle Third-Party Risk  2026-02-09 at 19:42 By Eduard Kovacs The funding was raised over Series A and seed funding rounds for its supply chain security solution. The post Lema AI Emerges From Stealth With $24 Million to Tackle Third-Party Risk  appeared first on SecurityWeek. This article

Lema AI Emerges From Stealth With $24 Million to Tackle Third-Party Risk  Read More »

New Paper and Tool Help Security Teams Move Beyond Blind Reliance on CISA’s KEV Catalog

New Paper and Tool Help Security Teams Move Beyond Blind Reliance on CISA’s KEV Catalog 2026-02-09 at 11:10 By Kevin Townsend The KEV list is useful but largely misunderstood. KEVology explains what it is, and how best to use it. The post New Paper and Tool Help Security Teams Move Beyond Blind Reliance on CISA’s

New Paper and Tool Help Security Teams Move Beyond Blind Reliance on CISA’s KEV Catalog Read More »

United Airlines CISO on building resilience when disruption is inevitable

United Airlines CISO on building resilience when disruption is inevitable 2026-02-09 at 09:09 By Mirko Zorz Aviation runs on complex digital systems built for stability, safety, and long lifecycles. That reality creates a unique cybersecurity challenge for airlines, where disruption can quickly become an operational and public trust crisis. In this Help Net Security interview,

United Airlines CISO on building resilience when disruption is inevitable Read More »

Organizations Urged to Replace Discontinued Edge Devices

Organizations Urged to Replace Discontinued Edge Devices 2026-02-07 at 17:41 By Ionut Arghire Edge devices that are no longer supported have been targeted in attacks by state-sponsored hackers, the US says. The post Organizations Urged to Replace Discontinued Edge Devices appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Organizations Urged to Replace Discontinued Edge Devices Read More »

Cybersecurity planning keeps moving toward whole-of-society models

Cybersecurity planning keeps moving toward whole-of-society models 2026-02-05 at 09:11 By Sinisa Markovic National governments already run cybersecurity through a mix of ministries, regulators, law enforcement, and private operators that own most critical systems. In that environment, guidance circulating among policymakers outlines how national cybersecurity strategies increasingly tie together risk management, workforce planning, technology standards,

Cybersecurity planning keeps moving toward whole-of-society models Read More »

What boards need to hear about cyber risk, and what they don’t

What boards need to hear about cyber risk, and what they don’t 2026-02-02 at 09:10 By Help Net Security In this Help Net Security video, Rishi Kaushal, CIO at Entrust, explains how security leaders should talk to the board about cyber risk. He focuses on what matters to board members and what does not. He

What boards need to hear about cyber risk, and what they don’t Read More »

TikTok Finalizes a Deal to Form a New American Entity

TikTok Finalizes a Deal to Form a New American Entity 2026-01-26 at 14:37 By Associated Press TikTok has finalized a deal to create a new American entity, avoiding the looming threat of a ban in the United States. The post TikTok Finalizes a Deal to Form a New American Entity appeared first on SecurityWeek. This

TikTok Finalizes a Deal to Form a New American Entity Read More »

A new framework helps banks sort urgent post-quantum crypto work from the rest

A new framework helps banks sort urgent post-quantum crypto work from the rest 2026-01-22 at 04:57 By Sinisa Markovic Financial institutions now have a concrete method for deciding where post-quantum cryptography belongs on their security roadmaps. New research coordinated by Europol sets out a scoring framework that helps banks rank systems and business use cases

A new framework helps banks sort urgent post-quantum crypto work from the rest Read More »

Cyber risk keeps winning, even as AI takes over

Cyber risk keeps winning, even as AI takes over 2026-01-19 at 07:00 By Anamarija Pogorelec Cyber risk continues to dominate global business concerns, with AI rising quickly alongside it. According to a new risk survey from Allianz, both are influencing how organizations plan for disruption, resilience, and recovery across regions and industries. Cyber incidents stay

Cyber risk keeps winning, even as AI takes over Read More »

Monnai Raises $12 Million for Identity and Risk Data Infrastructure

Monnai Raises $12 Million for Identity and Risk Data Infrastructure 2026-01-16 at 17:05 By Ionut Arghire The company will use the investment to accelerate the adoption of its solution among financial institutions and digital businesses. The post Monnai Raises $12 Million for Identity and Risk Data Infrastructure appeared first on SecurityWeek. This article is an

Monnai Raises $12 Million for Identity and Risk Data Infrastructure Read More »

Cybersecurity Firms React to China’s Reported Software Ban

Cybersecurity Firms React to China’s Reported Software Ban 2026-01-16 at 13:57 By Eduard Kovacs China has more than 5,000 cybersecurity companies and all the top 20 firms are working with the government.  The post Cybersecurity Firms React to China’s Reported Software Ban appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Cybersecurity Firms React to China’s Reported Software Ban Read More »

CISO Assistant: Open-source cybersecurity management and GRC

CISO Assistant: Open-source cybersecurity management and GRC 2026-01-14 at 13:25 By Mirko Zorz CISO Assistant is an open-source governance, risk, and compliance (GRC) platform designed to help security teams document risks, controls, and framework alignment in a structured system. The community edition is maintained as a self-hosted tool for organizations that want direct access to

CISO Assistant: Open-source cybersecurity management and GRC Read More »

Cyber Risk Trends for 2026: Building Resilience, Not Just Defenses

Cyber Risk Trends for 2026: Building Resilience, Not Just Defenses 2026-01-06 at 16:49 By Steve Durbin We can’t outpace the adversary by trying to stop every attack, but we can outlast them by engineering systems and culture to take a punch and try to quickly rebound. The post Cyber Risk Trends for 2026: Building Resilience,

Cyber Risk Trends for 2026: Building Resilience, Not Just Defenses Read More »

Executives say cybersecurity has outgrown the IT department

Executives say cybersecurity has outgrown the IT department 2025-12-30 at 08:03 By Anamarija Pogorelec Cybersecurity has moved from a technical problem to a boardroom concern tied to survival. A global Rimini Street study of senior executives shows security risk shaping decisions on technology, talent, and long term planning across industries that keep economies running. Cyber

Executives say cybersecurity has outgrown the IT department Read More »

Scroll to Top