Tag: risk management
309 articles

UK Firms Bolster Cyber Defenses as AI Risks Mount
As uncertainty becomes the new normal, UK businesses are bolstering their cyber defenses, with 68% of leaders planning to boost cybersecurity investment over the next year. Despite this, many remain vulnerable, with fewer than three in 10 confident in their ability to respond to a major cyber incident.

SecurityScorecard Bolsters Internet Visibility with Driftnet Acquisition
SecurityScorecard has acquired Driftnet, an internet scanning startup, to supercharge its third-party risk management capabilities with deeper, real-time visibility into internet infrastructure and hidden exposures. This strategic move allows SecurityScorecard to directly control data quality and drive future innovation in AI security.

Securing Autonomous AI Requires New Risk Strategies
Autonomous AI agents are revolutionizing enterprise environments with lightning-fast speed, unprecedented autonomy, and access to sensitive systems and data - but many security teams lack the visibility and control to manage the resulting risks. This game-changing technology is rapidly expanding the enterprise attack surface, demanding new risk strategies to stay ahead.

Cyber Insurance Grapples with AI Liability Risks
As AI-driven tools take on a bigger role in patient care, hospitals and insurers are scrambling to reevaluate cyber insurance policies and figure out who's liable when things go wrong. To navigate this uncertainty, experts recommend carefully scrutinizing policy exclusions to ensure you're protected against your biggest risks.

Allianz Transfers Commercial Cyber Unit to Coalition
This game-changing partnership brings a fresh approach to commercial cyber insurance, elevating protection and benefits for customers. By joining forces, Allianz and Coalition are revolutionizing cyber coverage with a unique and robust offering.

Breach Readiness Lags as Identities Become Prime Attack Surface
To stay ahead of threats, organizations must move beyond generic risk assessments and instead focus on tailored risk management, taking into account the unique business context and technical severity of potential breaches. By doing so, they can harden identity controls, improve governance, and build a stronger defense against cyber attacks.

Securing AI Adoption Requires New Risk Oversight Approach
As AI adoption accelerates, organizations are essentially onboarding fast-moving digital colleagues that require a new risk oversight approach - one that acknowledges their unique behavior and risk profile, which differs significantly from human workers. Traditional human-centric controls may not be enough to secure this new digital perimeter.

US Agencies Warn of AI Deployment Risks, Issue Security Guidance
As AI systems become more autonomous, US agencies warn that they may behave unexpectedly, and organisations should prepare for this by prioritising resilience and risk containment. To stay safe, businesses should assume the unpredictable and plan deployments with caution.

Security Leaders Face New Risk Calculus with AI-Driven Workforces
The modern workforce has a new equation: humans and AI agents working together, facing the same dynamic threats and risks. This emerging reality demands a fresh approach to security, one that recalibrates risk and rethinks trust in a blended workforce.

Attackers Target New Assets Within Minutes of Exposure
The moment a new asset goes live with a public IP address, the clock starts ticking - and within minutes, attackers are circling, waiting to pounce on unsuspecting targets. In just 24 hours, a newly exposed asset can go from discovery to compromise, with threat actors exploiting vulnerabilities at an alarming rate.

Cyber Risks Expose Organizations to Increased Threats
Organizations are facing a harsh reality: understanding cyber risk is only half the battle, as the real challenge lies in responding effectively when a threat strikes. Marsh's 2026 People Risks report reveals that cyber-related challenges, including cyber-threat literacy, top the list of people risks, ahead of technological change and skills shortages.

Threat Response Times Hinge on Smart SOC Design
When a breach occurs, the clock is ticking - and the cost of delayed response can be crippling, with every hour of inaction threatening data exfiltration, service disruption, regulatory exposure, and brand damage. A smart SOC design can be the difference between a swift response and a devastating fallout.

Insurance Premiums Signal Global Supply Chain Strains Ahead
A sharp spike in maritime war-risk insurance premiums served as an early warning sign of impending supply chain disruptions in the Strait of Hormuz, offering a potential low-cost signal for officials to anticipate and prepare for global supply shocks. By tracking these premium changes, Australia and other nations may be able to mitigate the impact of future disruptions.

Cyber Insurance Claims Data Reveals Top Incident Types
A new report reveals that a whopping majority of cyber insurance claims are driven by just three types of incidents, forcing insurers, organizations, and regulators to rethink where risk lies and how it should be priced. This surprising concentration of claims in a few categories has significant implications for managing financial risk.

NIST Scales Back Vulnerability Ratings Amid Surge in Submissions
The National Institute of Standards and Technology is overhauling its vulnerability rating system, scaling back severity scores for lower-priority flaws as submissions surge. This change means some software flaws will no longer get a severity score, shifting focus to the most critical vulnerabilities.

Mythos Threat Looms Over Cyber Defenses
A new force in cyberspace, known as Claude Mythos, threatens to revolutionize the speed at which cyber defenses are compromised, dramatically shortening the window between vulnerability discovery and exploitation. Experts warn that this emerging threat could upend traditional cybersecurity strategies, making it essential for organizations to reassess their approach to managing vulnerabilities and security operations.
CISOs Face Emerging AI Risk Management Challenges
As AI evolves from a useful tool to an omnipresent force, chief information security officers must urgently reassess their risk management playbook to stay ahead of emerging threats. A recent GovInfoSecurity webinar, "What CISOs Need to Know About AI Risk," tackles this critical question and explores the implications of AI risk for CISOs.

AI Adoption Exposes Hidden Security Gaps in Enterprise Operations
As AI rapidly moves from experimentation to executive mandate, organizations face a daunting challenge: how to harness its power while securing and governing its adoption. With boards, investors, and executives pushing for integration, the pressure is on to balance AI adoption with robust security and oversight.

Goldman Sachs Bolsters Defenses with Anthropic's Mythos Model
Goldman Sachs is taking a proactive approach to harnessing AI's potential while safeguarding against risks, partnering with Anthropic and security vendors to deploy controls around powerful models like Mythos. CEO David Solomon emphasizes the bank's hyper-aware stance, balancing innovation with robust risk management to mitigate threats like accelerated cyberattacks.

Vulnerabilities Surge as Velocity Gap Widens in AI-Driven Development
The alarming truth: while alert volume grew by 52% year-over-year, prioritized critical risks exploded by nearly 400% in just 90 days, leaving defenders scrambling to keep up with a tsunami of high-impact problems. A new dataset from OX Security reveals this velocity gap in AI-driven development, where the noise is rising - but it's the critical risks that should give defenders pause.

Cybersecurity Risk Outpaces Corporate Defenses
As companies pour more resources into AI and technology, a pressing question remains: can they defend what matters most? Despite escalating investments, many firms admit they're ill-equipped to tackle growing cybersecurity risks, which now rank among the top business threats.

Experts Weigh In on Claude Mythos and Project Glasswing Implications
Security experts recently gathered to share their insights on Claude Mythos and Project Glasswing, shining a spotlight on the risks, oversight, and urgency surrounding these emerging initiatives. By bringing their perspectives to the public record, the discussion sets the stage for scrutiny and debate.

AI Adoption Enters Agentic Era with Heightened Security Risks
As AI pilot projects evolve into autonomous systems operating across entire corporations, the stakes are rising - and so are the security risks. The era of experimentation is over; now it's time to face the bills and take control of enterprise AI risks, responsibilities, and responses.

Scenario Planning Evolves as Uncertainty Compounds Global Risk
When the future suddenly stops making sense, organizations are faced with a daunting decision: stick with outdated planning methods or evolve to anticipate the unexpected. As uncertainty compounds and trends become less reliable, a new approach to strategic planning and risk management is urgently needed.