Tag: risk management
309 articles

Securing Enterprise AI Requires Lifecycle Approach
The AI revolution is here, with nearly a third of organizations already leveraging AI for threat detection and incident response, and 63% expecting full integration by 2027 - but a staggering 73% of IT security leaders admit their organization wouldn't be ready for a major cyberattack. As AI adoption accelerates, the gap between usage and security readiness is growing alarmingly.

AI Tools Operate Largely Unchecked, Heightening Security Risks
Most AI tools are flying under the radar, with a staggering 80% operating without IT oversight in enterprise ecosystems, leaving organizations vulnerable to security risks. This alarming lack of governance is even more pronounced in smaller organizations, according to Reco's latest findings.

Cyber Insurance Losses Spike as Claim Costs Soar
Cyber insurance losses are skyrocketing as claim costs surge, with non-refundable fees in large suits potentially exceeding $10m before a case is even heard, and average claim costs jumping significantly in 2025 despite a decrease in overall claims.

NIST Seeks Overhaul of Vulnerability Database for AI-Driven Era
The National Institute for Standards and Technology is calling for a major revamp of its National Vulnerability Database to better tackle software vulnerabilities in the AI-driven era. It's seeking public input on how to modernize the database and its processes to stay ahead of emerging threats.

Zero-Knowledge Proofs Offer Secure Path for Cyber Risk Disclosure
ZKPs offer a game-changing solution, allowing companies to securely share proof of vulnerabilities without exposing sensitive data that could be exploited by attackers. By using ZKPs, organizations can demonstrate the truth of a statement, such as confirming a specific vulnerability exists, without revealing confidential details.

Generative AI Disrupts Hacker Landscape
The technical barriers that once limited credible cyberattacks are rapidly eroding, making it essential to rethink security strategies and prioritize exploitable risk over theoretical exposure. With generative AI, the traditional ranking of attacker sophistication is collapsing, empowering less-skilled hackers to launch more potent threats.

InfraTrust Report Flags Urgent Infrastructure Vulnerabilities
In a wake-up call for infrastructure security, Eclypsium's inaugural InfraTrust Pulse report reveals a staggering 61 vulnerabilities, including six critical ones, threatening the very foundation of our digital world. The monthly report aims to help organizations focus on the most pressing threats, prioritizing vulnerabilities that pose a real-world risk.

Patch Management Struggles to Keep Pace with AI-Accelerated Threats
Nearly a third of breaches occur because hackers exploit known vulnerabilities that could have been easily fixed with a patch, highlighting the urgent need for more efficient patch management. By speeding up patching, organizations could prevent around one in three incidents, making it a crucial defense against cyber threats.

GRC AI Tools Fall Short on Enterprise Readiness
Most organizations are flying blind when it comes to GRC AI tools, with a staggering 87% of IT and security pros admitting they can't fully see the AI tools active within their organization. This visibility gap poses a foundational risk, making it harder to rely on other controls and assurances.

Pentera Injects Validation into AI-Driven Security Workflows
Pentera is revolutionizing AI-driven security by injecting validation into workflows, empowering teams to turn disconnected risk signals into decisive action against real attack paths. By safely emulating attacker techniques, Pentera provides the evidence needed to transform guesswork into effective security measures.

Lumen Technologies Rebuilds Exposure Management with Trusted Asset Data
Lumen Technologies' security team transformed their exposure management by consolidating 40 disconnected systems into one trusted view, growing their asset count from 17,000 to 1.1 million devices. This overhaul empowered them to respond to incidents with confidence, knowing who owned what and taking informed risk decisions.

AI Exacerbates Vulnerability Prioritization Crisis
The irony of AI-powered vulnerability discovery is that it's creating an overwhelming crisis: despite spotting weaknesses at unprecedented speed and scale, organizations are no safer - just more inundated. The harsh truth is that a vulnerability is just a clue, not risk, and the real challenge lies in prioritizing and assessing true threats.

Threat Management Fails to Keep Pace with Visibility Gains
Most organizations are drowning in threat intelligence, with an average of 14 distinct feeds, yet struggle to turn that visibility into action, with 61% unable to identify which vulnerabilities are most likely to be exploited. As a result, security teams waste 42% of their time on low-priority risks, highlighting a critical gap between threat awareness and effective management.

AI Agents Emerge as Unchecked Identities in Enterprise Security
The equation for enterprise security is no longer simple: with AI agents now connected to critical business services, controlling identities is no longer enough to control risk. These emerging insiders have quietly become privileged - and potentially invisible - attack paths that security and identity programs must urgently address.

AWS Unveils AI-Powered Platform to Streamline Vulnerability Management
Discover and remediate code vulnerabilities with ease using AWS Continuum, a game-changing platform that streamlines vulnerability management with AI-powered recommendations and automated remediation. With Continuum, you can gain confidence in your security posture and automate fixes based on your own risk profiles and priorities.

Vulnerability Patching Lag Exposes 91% of Organizations to Known Threats
The alarming truth is that 91% of organizations are leaving themselves exposed to known threats due to a vulnerability patching lag, with only 9% able to remediate high-severity flaws within a critical 24-hour window. This delay is not just a statistic - it's a recipe for disaster, with organizations that patch more slowly facing significantly higher breach rates.

Boards Urged to Prioritize Cyber Risk Quantification
To make cyber risk more tangible and actionable, boards are advised to prioritize quantifying it in terms of dollar value, allowing managers across the organization to understand and address potential threats more effectively. By translating cyber risk into a clear financial impact, companies like BP are better equipping themselves to manage and mitigate digital threats.

AI Tools Expose Vulnerabilities in Army's Unified Network
The Army's unified network is facing a new wave of vulnerabilities, thanks to AI tools that are making it easier for attackers to breach defenses. With AI, techniques that once required specialized skills can now be scaled with ease, expanding the attack surface and increasing risk.

Australia Grapples with Integration Lag in Overlapping Risk Era
We're facing a new reality of overlapping risks that are continuous, concurrent, and cascading - a far cry from the isolated shocks of the past. It's time for governments and institutions to rethink their response to risk, as the old approach of tackling single problems at a time no longer fits the problem.

Threat Intelligence Fails to Bridge Business Risk Gap
Threat intelligence falls short when it doesn't drive informed decision-making, often leaving a gap between analyst findings and senior leaders' priorities. Silobreaker and the SANS Institute are bridging this gap with a new study that explores how to turn threat intelligence into actionable business risk strategies.

Cybersecurity Shifts from Risk to Acceleration, Connection
The World Economic Forum's 2025 survey reveals a stark reality: 72% of organizations are facing increased cyber risks, with ransomware remaining a top threat - forcing us to rethink how we keep information safe in an AI-driven world. It's time to shift from traditional risk management to practical, accelerated solutions.

Enterprise AI Risk Concentrated Among Small Group of Power Users
Meet the AI power users: a small but mighty 5% of enterprise employees who are generating a whopping 144 conversations or more with AI tools, creating a concentrated risk that demands attention. These super-users are producing far more intense interactions, with 18 prompts per conversation compared to just 2.

US Navy Rethinks Risk in Software Development for Edge Operations
The Department of the Navy is shaking up its approach to software development, redefining risk to deliver mission-critical data at breakneck speeds. By recalibrating its tolerance for risk, the Navy aims to accelerate the flow of vital information to where it's needed most, when it's needed most.

Cybersecurity Burnout Spurs Call for Risk-Based Response
Half of all cyber professionals are burning out weekly or daily - it's time for organizations to shift their approach and view burnout as a critical operational risk, rather than just a wellness issue. By reframing burnout in this way, businesses can prioritize effective solutions and safeguard their cyber resilience.