tips

Pricing your bad days and how to build an economic model for security decisions

Pricing your bad days and how to build an economic model for security decisions 2026-10-08 at 09:00 By Mirko Zorz Ivan Milenkovic, VP Risk Technology EMEA at Qualys, explains how security leaders can build an economic model that puts money behind their decisions. He suggests starting with a few loss scenarios, then working down to […]

Pricing your bad days and how to build an economic model for security decisions Read More »

Automation, AI agents or people? Sorting out who handles each security finding

Automation, AI agents or people? Sorting out who handles each security finding 2026-10-07 at 07:30 By Mirko Zorz Just over half of the 200 senior security and technology leaders polled for ArmorCode say their organizations will struggle to simplify their software security programs if they keep working the way they do today. The respondents are […]

Automation, AI agents or people? Sorting out who handles each security finding Read More »

U.S. Bank CISO says the security role keeps growing and no one can own all of it

U.S. Bank CISO says the security role keeps growing and no one can own all of it 2026-10-06 at 09:00 By Mirko Zorz In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance. She […]

U.S. Bank CISO says the security role keeps growing and no one can own all of it Read More »

Three questions a hospital CISO should ask a healthcare fintech vendor

Three questions a hospital CISO should ask a healthcare fintech vendor 2026-10-05 at 08:30 By Mirko Zorz In this Help Net Security video, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every sprint, and issues touching patient data or funds disbursement come first. He covers […]

Three questions a hospital CISO should ask a healthcare fintech vendor Read More »

A four-week plan to tackle vendor concentration risk

A four-week plan to tackle vendor concentration risk 2026-09-29 at 08:00 By Help Net Security In this Help Net Security video, Guilliano Molaire, founder of Skycloak, explains how to map vendor concentration risk. A company may pay 30 vendors and think its tools are spread out, but many of those vendors run on the same […]

A four-week plan to tackle vendor concentration risk Read More »

If you do one security check this quarter, make it agent memory

If you do one security check this quarter, make it agent memory 2026-09-28 at 09:00 By Mirko Zorz In this interview with Help Net Security, Chris Latimer, CEO of Vectorize, talks about the security risks hiding in AI agent memory. He found coding agents storing API keys, credentials, and sensitive documents in plain text on […]

If you do one security check this quarter, make it agent memory Read More »

Stop watching what AI agents say and start watching what they do

Stop watching what AI agents say and start watching what they do 2026-09-25 at 08:30 By Mirko Zorz In this interview with Help Net Security, Ariel Assaraf, CEO of Coralogix, explains why a system prompt can describe a boundary for an AI agent but cannot enforce one. Assaraf covers how his team builds AI agent […]

Stop watching what AI agents say and start watching what they do Read More »

What to do first when you get 90 days to secure AI agent data

What to do first when you get 90 days to secure AI agent data 2026-09-24 at 08:00 By Mirko Zorz In this interview with Help Net Security, Kelly Herrell, CEO at Nol8, explains where AI agents create exposure inside organizations. The first thing to examine is the data path: what an agent can reach, what […]

What to do first when you get 90 days to secure AI agent data Read More »

Know what was tested before your SAP ECC migration goes live

Know what was tested before your SAP ECC migration goes live 2026-09-21 at 09:00 By Mirko Zorz In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that […]

Know what was tested before your SAP ECC migration goes live Read More »

The AI security question leaders should be asking instead

The AI security question leaders should be asking instead 2026-09-17 at 08:30 By Mirko Zorz In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why […]

The AI security question leaders should be asking instead Read More »

A flat cybersecurity budget doesn’t have to mean weaker coverage

A flat cybersecurity budget doesn’t have to mean weaker coverage 2026-09-17 at 08:00 By Help Net Security Cheri Hotman, Managing Partner of Hotman Group, works as a vCISO and vGRC leader. In this Help Net Security video, she talks about holding coverage steady when the CFO asks for a flat budget or a 12% cut. […]

A flat cybersecurity budget doesn’t have to mean weaker coverage Read More »

What happens when AI agent governance is missing at scale

What happens when AI agent governance is missing at scale 2026-09-16 at 09:00 By Mirko Zorz In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does, since […]

What happens when AI agent governance is missing at scale Read More »

Ransomware negotiation tactics have turned into a business process

Ransomware negotiation tactics have turned into a business process 2026-09-08 at 08:40 By Help Net Security In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations. Ross walks through the tactics groups use once an attack begins, from […]

Ransomware negotiation tactics have turned into a business process Read More »

A five-part inventory for your AI agent credentials

A five-part inventory for your AI agent credentials 2026-09-04 at 08:30 By Help Net Security In this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build agents in AI studios, connect them to enterprise tools, and give them accounts to do useful […]

A five-part inventory for your AI agent credentials Read More »

When AI quietly breaks things, who pays?

When AI quietly breaks things, who pays? 2026-09-03 at 08:00 By Mirko Zorz David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance […]

When AI quietly breaks things, who pays? Read More »

National Life Group CISO expects more vulnerabilities in six months than in thirty years

National Life Group CISO expects more vulnerabilities in six months than in thirty years 2026-09-02 at 09:00 By Mirko Zorz In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot […]

National Life Group CISO expects more vulnerabilities in six months than in thirty years Read More »

What your vendor says about PQC tells you if they are ready

What your vendor says about PQC tells you if they are ready 2026-09-01 at 07:30 By Mirko Zorz In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity […]

What your vendor says about PQC tells you if they are ready Read More »

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree 2026-08-31 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity, […]

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree Read More »

Scroll to Top