<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <copyright>Copyright TechTarget - All rights reserved</copyright>
        <description></description>
        <docs>https://cyber.law.harvard.edu/rss/rss.html</docs>
        <generator>Techtarget Feed Generator</generator>
        <language>en</language>
        <lastBuildDate>Mon, 20 Jul 2026 03:41:49 GMT</lastBuildDate>
        <link>https://www.techtarget.com/searchsecurity</link>
        <managingEditor>editor@techtarget.com</managingEditor>
        <item>
            <body>&lt;p&gt;The tech industry is cautiously optimistic about the U.S. government's announcement this week to create a centralized clearinghouse for AI-discovered vulnerabilities. The key, executives and analysts said, will be how well the new initiative executes on its mission to collect and sort information on security flaws.&lt;/p&gt; 
&lt;p&gt;If the new Gold Eagle project simply produces huge quantities of unvalidated vulnerability reports, then a big problem only becomes worse, observers worry.&lt;/p&gt; 
&lt;p&gt;Unveiled Tuesday by the Trump administration, Gold Eagle is an effort to confront the growing challenge of software vulnerabilities being exposed by advanced LLMs. The volume of AI-found flaws is overwhelming human developers and security professionals. This creates a new and unpleasant reality for maintainers of code and the IT admins handling &lt;a href="https://www.techtarget.com/searchenterprisedesktop/definition/patch-management"&gt;patch management&lt;/a&gt; and day-to-day security updates.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Too many flaws, too few fixes"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Too many flaws, too few fixes&lt;/h2&gt;
 &lt;p&gt;Testing done with Anthropic's Mythos LLM, for example, reportedly uncovered 10,000 significant vulnerabilities in just &lt;a href="https://www.techtarget.com/searchsecurity/news/366643606/First-month-of-Mythos-Preview-testing-exposes-10K-flaws"&gt;one month of screening work under Project Glasswing&lt;/a&gt;, a cross-industry coalition of companies granted early access to Mythos. Some of the vulnerabilities, Anthropic said, had gone unnoticed for decades.&lt;/p&gt;
 &lt;p&gt;Recent tests found gaps even in &lt;a href="https://apnews.com/article/anthropic-mythos-ai-classified-systems-vulnerabilities-testing-3e8762c0527c4d8ed657cbe48c84a718"&gt;highly guarded, classified U.S. government systems&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;On a parallel track, &lt;a href="https://www.techtarget.com/searchsecurity/news/366643546/For-CISOs-dawn-of-OpenAI-Daybreak-brings-good-and-bad-news"&gt;OpenAI's Daybreak initiative&lt;/a&gt; aims to make vulnerability verification and remediation more efficient by uniting GPT models and the Codex Security system.&lt;/p&gt;
 &lt;p&gt;The government's Gold Eagle initiative is important recognition that frontier LLMs are forcing organizations to rethink how they remediate software, said Aaron Mitchell, CEO at HeroDevs, a company that helps companies secure their source software.&lt;/p&gt;
 &lt;p&gt;"Gone are the days of fixing vulnerabilities as they come in," Mitchell said. "Security and engineering teams can't keep up with the volume of findings or the amount of change required to continuously upgrade software."&lt;/p&gt;
 &lt;p&gt;AI's astonishing ability to find security weaknesses in code presents a monumental challenge -- even to organizations that adhere to &lt;a href="https://www.techtarget.com/searchsecurity/definition/cyber-hygiene"&gt;cyber hygiene&lt;/a&gt; best practices and are diligent about &lt;a href="https://www.techtarget.com/searchsecurity/tip/Types-of-vulnerability-scanning-and-when-to-use-each"&gt;vulnerability scanning efforts&lt;/a&gt;. The scale of the problem and potential for widespread harm to IT systems has gotten Washington's attention, with the Trump administration &lt;a href="https://www.cybersecuritydive.com/news/cisa-ai-trump-executive-order-implementation/822001/"&gt;issuing an executive order&lt;/a&gt; in June calling for action on the AI front.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="The prioritization problem"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The prioritization problem&lt;/h2&gt;
 &lt;p&gt;Gold Eagle is a step in the right direction, said Tyler Fordham, director of offensive security at Dark Wolf, a DevSecOps services company, but he sees potential problems with a government-run, AI-driven clearinghouse. If it simply dumps raw, automated alerts on IT teams, it will lead to patch fatigue and confusion about which vulnerabilities to prioritize, he said. Plus, a vast centralized database presents an inviting target for state-sponsored threat actors.&lt;/p&gt;
 &lt;p&gt;"For Gold Eagle to succeed, it has to be built as a secure resource that supports and funds defenders, not just another federal compliance initiative telling people what to fix," Fordham said.&lt;/p&gt;
 &lt;p&gt;A centralized queue of endless technical information won't do much to solve problems, said Joshua Copeland, cybersecurity director at Crescendo, which makes AI-based customer-experience tools.&lt;/p&gt;
 &lt;p&gt;"Gold Eagle will achieve success only if it functions as a decision and remediation engine, rather than merely serving as an advanced vulnerability collection system," said Copeland, who is also an adjunct professor at Tulane University.&lt;/p&gt;
 &lt;p&gt;Gold Eagle will need duplicate detection, minimum evidence standards and independent technical validation, Copeland said. Also on his wish list is a prioritization model that weighs active exploitation.&lt;/p&gt;
 &lt;p&gt;The lack of cooperation between the public and private sectors on vulnerability management has been a persistent complaint in the industry, said Theresa Lanowitz, a cybersecurity analyst at Omdia, a division of Informa TechTarget. In her view, a well-organized system could make a difference.&lt;/p&gt;
 &lt;p&gt;"The key to any vulnerability management program is to prioritize remediation to minimize impact," Lanowitz said. "And, once a vulnerability is fixed, it is important to make sure that downstream integrations do not break anything else."&lt;/p&gt;
 &lt;p&gt;Lanowitz said she is encouraged by Gold Eagle's focus on open source software (OSS), some of which continues to be used even after it reaches end-of-life status. "The software will continue to work, but there are no bug fixes, new features or security updates," Lanowitz said. "Unmaintained OSS presents opportunities for adversaries."&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Phil Sweeney is an industry editor and writer focused on cybersecurity topics.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>As AI-discovered software vulnerabilities accumulate at an unprecedented pace, security pros say they hope Gold Eagle creates some order from the chaos.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a296619547.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/news/366645907/Industry-reacts-to-Gold-Eagle-vulnerability-management-plan</link>
            <pubDate>Fri, 17 Jul 2026 13:30:00 GMT</pubDate>
            <title>Industry reacts to Gold Eagle vulnerability management plan</title>
        </item>
        <item>
            <body>&lt;p&gt;Modern software runs on open source. Nearly all codebases -- 98% -- contain open source code, according to a 2026 &lt;a target="_blank" href="https://www.blackduck.com/content/dam/black-duck/en-us/reports/rep-ossra.pdf" rel="noopener"&gt;report&lt;/a&gt; from cybersecurity vendor Black Duck, which scanned 947 codebases and analyzed nearly 3,000 individual projects between November 2024 and October 2025. Those open source components change constantly as maintainers ship patches, fixes and new versions.&lt;/p&gt; 
&lt;p&gt;A &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-create-an-SBOM-with-example-and-template"&gt;software bill of materials (SBOM) captures a snapshot&lt;/a&gt; of that inventory, so organizations can find and patch vulnerabilities quickly. The moment a developer merges a dependency update or a build pulls a new version, the document drifts from reality. A stale SBOM gives false confidence and slows the enterprise response when a vulnerability lands.&lt;/p&gt; 
&lt;p&gt;Regulation raises the stakes. Under the EU Cyber Resilience Act, beginning Sept. 11, 2026, organizations must report actively exploited vulnerabilities. By Dec. 11, 2027, manufacturers of products with digital elements must include machine-readable SBOMs in their technical documentation. Penalties for non-compliance could reach 15 million euros or 2.5% of global annual turnover. In the U.S., CISA and its partner agencies &lt;a target="_blank" href="https://www.cisa.gov/topics/information-communications-technology-supply-chain-security/sbom" rel="noopener"&gt;published&lt;/a&gt; joint SBOM guidance in September 2025 that pushes wider adoption. Unlike manual upkeep, AI tools can meet these demands at scale.&lt;/p&gt; 
&lt;h1&gt;How AI-Driven SBOM management works&lt;/h1&gt; 
&lt;p&gt;AI-driven tools treat the SBOM as a living inventory rather than a one-time artifact. They combine automation with machine learning across the following four functions.&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;&lt;b&gt;Continuous generation. &lt;/b&gt;The tools plug into your CI/CD pipeline and regenerate the SBOM on every build, so the inventory automatically tracks each release.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Component identification. &lt;/b&gt;Machine learning models, including natural language processing and graph neural networks, identify and classify components and trace transitive dependencies. One multi-model system, for example, &lt;a target="_blank" href="https://www.researchgate.net/publication/399038727_AI-Driven_SBOM_Automated_Software_Bill_of_Materials_Generation_and_Management" rel="noopener"&gt;reported&lt;/a&gt; 94.7% component detection and 91.3% accuracy in vulnerability mapping.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Drift detection. &lt;/b&gt;AI-driven tools compare the build-time SBOM against what actually runs in production to catch unauthorized packages, supply chain tampering and configuration drift.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Vulnerability correlation. &lt;/b&gt;AI enriches each component with exploitability intelligence and ranks findings by reachability, rather than raw CVE counts, so the highest-risk issues surface first.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1&gt;Benefits of using AI to maintain SBOMs&lt;/h1&gt; 
&lt;p&gt;For a CISO, the value of AI for SBOM creation and maintenance lies in accuracy, speed and audit-readiness.&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;&lt;b&gt;Accuracy at scale. &lt;/b&gt;AI continuously updates inventory across hundreds of repositories, a task no human team can match by hand.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Faster incident response. &lt;/b&gt;When the next &lt;a target="_blank" href="https://www.darkreading.com/cyberattacks-data-breaches/log4j-vulnerabilities-are-here-to-stay-are-you-prepared-" rel="noopener"&gt;Log4Shell&lt;/a&gt;-class flaw appears, a current inventory answers the question "are we affected" in minutes instead of days.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Less noise. &lt;/b&gt;Reachability analysis filters out components that pose no real exposure risk, so analysts spend time on issues that matter.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Compliance readiness. &lt;/b&gt;An always-current, machine-readable SBOM satisfies auditors, customers and regulators on demand.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1&gt;Risks and challenges&lt;/h1&gt; 
&lt;p&gt;&lt;a href="https://www.techtarget.com/searchcio/feature/AI-failure-examples-What-real-world-breakdowns-teach-CIOs"&gt;AI does not remove the need for human judgment&lt;/a&gt;. Weigh the risks before you rely on it for SBOMs or anything else. CISOs should consider the following:&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;&lt;b&gt;False positives and negatives. &lt;/b&gt;Automated tools can flag components that are not in production or miss ones loaded dynamically at runtime. Human review still matters.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Model opacity. &lt;/b&gt;When a model classifies or discards a component, the reasoning can be hard to audit. Demand &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-CISOs-need-to-know-about-AI-audit-logs"&gt;explainable output you can log&lt;/a&gt; and defend.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Data quality limits. &lt;/b&gt;An AI inventory is only as good as the sources it reads. Poor package metadata and incomplete scans produce a confident but incorrect SBOM.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Automation bias. &lt;/b&gt;Teams can over-trust a polished dashboard and stop verifying it. Treat AI output as a strong draft, rather than the final truth.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;A new attack surface. &lt;/b&gt;The AI tooling and its models become part of your supply chain. Vet them as you would any other dependency, and &lt;a target="_blank" href="https://www.darkreading.com/cyber-risk/make-ai-bom-usable-modern-security-program" rel="noopener"&gt;track your own AI components&lt;/a&gt; too.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h1&gt;Best practices for CISOs&lt;/h1&gt; 
&lt;p&gt;CISOs who decide to automate SBOM management with AI should start with the following steps:&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;Embed SBOM generation in every CI/CD pipeline so it runs on each build.&lt;/li&gt; 
 &lt;li&gt;Compare build-time and runtime SBOMs to catch drift before attackers do.&lt;/li&gt; 
 &lt;li&gt;Require explainable output and use human-in-the-loop reviews to verify high-risk findings.&lt;/li&gt; 
 &lt;li&gt;Prioritize flaws by reachability and exploitability, not raw vulnerability counts.&lt;/li&gt; 
 &lt;li&gt;Vet your SBOM AI tools, models and training data as supply chain components.&lt;/li&gt; 
 &lt;li&gt;Map your process to regulatory timelines now, ahead of deadlines.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Additionally, beware of potential pitfalls.&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;Don't treat the SBOM as a one-time document, rather than a living inventory.&lt;/li&gt; 
 &lt;li&gt;Don't trust AI output without validation and a clear audit trail.&lt;/li&gt; 
 &lt;li&gt;Don't ignore runtime drift because the build-time SBOM looks complete.&lt;/li&gt; 
 &lt;li&gt;Don't wait for regulators to force the conversation. By then, your company could be on the hook for hefty fines.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;A current SBOM is the foundation for &lt;a href="https://www.techtarget.com/searchsecurity/tip/4-software-supply-chain-security-best-practices"&gt;software supply chain security&lt;/a&gt;. AI keeps that inventory continuous and accurate at a scale that manual updates cannot match. By pairing AI tools with human oversight, CISOs can turn a compliance chore into a real-time view of supply-chain risk.&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;Matthew Smith is a vCISO and management consultant specializing in cybersecurity risk management and AI.&lt;/em&gt;&lt;/p&gt;</body>
            <description>AI tools can drive continuous, accurate SBOM management that turns compliance documentation into real-time supply chain security. Here's what CISOs should know.</description>
            <image>https://cdn.ttgtmedia.com/visuals/German/article/malware-1-adobe.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/tip/Why-CISOs-should-automate-SBOM-management-with-AI</link>
            <pubDate>Thu, 16 Jul 2026 18:17:00 GMT</pubDate>
            <title>Why CISOs should automate SBOM management with AI</title>
        </item>
        <item>
            <body>&lt;p&gt;CISOs and their teams are expected to demonstrate compliance with a range of regulations, frameworks and standards. With an alphabet soup of frameworks -- NIST, ISO, PCI DSS, HIPAA, GDPR and many other country- or sector-specific mandates -- there is a growing risk of duplicating effort, control gaps and audit fatigue.&lt;/p&gt; 
&lt;p&gt;CISOs can simplify governance by mapping security controls to the various domestic and international &lt;a href="https://www.techtarget.com/searchsecurity/tip/IT-security-frameworks-and-standards-Choosing-the-right-one"&gt;standards and regulations addressing cybersecurity&lt;/a&gt; through a unified control architecture.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Why control mapping matters"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why control mapping matters&lt;/h2&gt;
 &lt;p&gt;Enterprises that are required to demonstrate regulatory compliance must prove how they comply. In addition to a variety of audit tests, a map of the controls being used and the corresponding standards is an important piece of audit evidence.&lt;/p&gt;
 &lt;p&gt;Without a control map, CISOs and their teams can face redundant efforts when connecting controls to specific requirements, a lack of consistent application of controls within the enterprise and additional work gathering evidence for an audit.&lt;/p&gt;
 &lt;p&gt;Security teams can save time and effort by building a structured map of controls and requirements, consolidating all mapping into a single assessment. This helps &lt;a href="https://www.techtarget.com/searchsecurity/tip/Build-a-strong-cyber-resilience-strategy-with-existing-tools"&gt;strengthen cyber resilience&lt;/a&gt; by establishing a holistic baseline.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="How to build a control-mapping strategy"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How to build a control-mapping strategy&lt;/h2&gt;
 &lt;p&gt;Prior to preparing a control/standard map, define the overall strategy. This helps CISOs, auditors and regulators assess and verify compliance, minimizes duplication and enhances governance. The key is to define scope, establish a baseline control language and create a flexible and reusable mapping model. Adding AI to the process helps accelerate map preparation and assists with ongoing maintenance.&lt;/p&gt;
 &lt;p&gt;Obtain the most relevant and authoritative sources. Among the most important are:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;NIST CSF (Cyber Security Framework)&lt;/b&gt;. This framework provides guidance across a broad range of cybersecurity issues; implementation is voluntary.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;NIST SP 800-53&lt;/b&gt;. Designed for government use, these cybersecurity controls can be used by the private sector. Implementation is voluntary but considered essential for demonstrating compliance.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;ISO/IEC 27001&lt;/b&gt;. &lt;a href="https://www.techtarget.com/whatis/definition/ISO-27001"&gt;This is the global cybersecurity standard&lt;/a&gt;; compliance must be officially demonstrated.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;CIS Controls&lt;/b&gt;. Developed by the U.S. Center for Internet Security, there are 18 specific controls to address; implementation is voluntary.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;SOC 2 Security Controls&lt;/b&gt;. Developed to comply with the AICPA's Trust Services Criteria, these are auditable controls.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;HIPAA&lt;/b&gt;. The &lt;a href="https://www.techtarget.com/searchhealthit/definition/HIPAA"&gt;HIPAA&lt;/a&gt; security controls, which are mandatory in healthcare, can be applied in many industries; compliance must be officially demonstrated.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;PCI DSS&lt;/b&gt;. The &lt;a href="https://www.techtarget.com/searchsecurity/definition/PCI-DSS-Payment-Card-Industry-Data-Security-Standard"&gt;Payment Card Industry Data Security Standard&lt;/a&gt; is a mandatory requirement for organizations in the payment industry; it has six control objectives that delineate 12 specific requirements.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;FedRAMP&lt;/b&gt;. Based on NIST SP 800-53, these mandatory controls were designed for cloud service providers that handle federal data.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;CMMC&lt;/b&gt;. The Cybersecurity Maturity Model Certification was developed by the U.S. Defense Department to protect critical government data used by contractors.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;GPPR&lt;/b&gt;. The EU &lt;a href="https://www.techtarget.com/whatis/definition/General-Data-Protection-Regulation-GDPR"&gt;General Data Protection Regulation&lt;/a&gt; specifies how data generated and used by EU member nations and other nations that work with EU member states is protected from unauthorized use; compliance must be officially demonstrated.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Once the relevant requirements have been identified, develop a standard control language and taxonomy. Next, create a crosswalk or other approach where relevant data can be identified and used to support audits, prepare regulatory reporting and facilitate internal governance. Be sure to include information in the map that details evidence sources, e.g., origin and rationale.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Step-by-step approach"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Step-by-step approach&lt;/h2&gt;
 &lt;p&gt;Follow these steps to establish your control mapping.&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Define scope.&lt;/b&gt; Begin by identifying the standards, regulations, frameworks and internal policies to be mapped.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Build a catalog of cybersecurity controls.&lt;/b&gt; While there might be dozens of individual controls, try to group them in specific categories, such as access control and incident response.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Pick your mapping approach&lt;/b&gt;. This can include 1:1 (one control to one standard), partial mapping (one standard to many controls) or thematic mapping (grouping controls into categories, such as access control).&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Define mapping criteria&lt;/b&gt;. Set rules for how to develop mapping. Include factors such as intent, outcomes, safeguards or requirements for evidence.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Complete and document the mapping&lt;/b&gt;. Given the time it takes to complete a map, consider using internal experts dedicated to the project, external consultants or AI automation tools.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Initiate stakeholder validation&lt;/b&gt;. Invite representatives from the legal, audit, compliance and engineering groups to review the map's accuracy.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Launch the map&lt;/b&gt;. Once approved, integrate the map into governance, risk and compliance (&lt;a href="https://www.techtarget.com/searchsecurity/definition/governance-risk-management-and-compliance-GRC"&gt;GRC&lt;/a&gt;) workflows; risk assessments; reporting; and audits.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Use change control to maintain maps&lt;/b&gt;. Noting that standards and regulations periodically change, use the change-control process to keep maps up to date.&lt;/li&gt; 
 &lt;/ol&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Overcoming control mapping challenges"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Overcoming control mapping challenges&lt;/h2&gt;
 &lt;p&gt;When planning and developing a control map, there will be difficulties to overcome. To mitigate them, try to standardize the language and map structure to minimize confusion.&lt;/p&gt;
 &lt;p&gt;Consistency counts for standards, as well. Depending on the standard, the content might be more general and broad-based, while others could be detailed, so ensure that the language is as consistent as possible. Some standards and regulations, such as HIPAA and GDPR, describe outcomes, whereas others, such as NIST, CIS and SOC 2, provide specific controls. Be ready to update maps with the latest versions as standards, regulations and frameworks change.&lt;/p&gt;
 &lt;p&gt;In the broader organization, be aware of the impact on other functions. Internal departments, such as security, risk management, compliance and engineering, might have differing views of controls and how controls are applied.&lt;/p&gt;
 &lt;p&gt;Also be sure to check evidence requirements. Once controls have been mapped, see if there are any variances in evidence requirements.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Tools and technologies"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Tools and technologies&lt;/h2&gt;
 &lt;p&gt;Automated tools can assist with control map development. To streamline the development and maintenance processes, consider tools with AI capabilities.&lt;/p&gt;
 &lt;p&gt;Some available products include:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Archer Evolv, a control and regulatory mapping engine.&lt;/li&gt; 
  &lt;li&gt;CIS Controls Mapping, an Excel-based control mapping crosswalk to NIST, PCI DSS, ISO, HIPAA and SOC 2.&lt;/li&gt; 
  &lt;li&gt;Drata, an AI-based control mapping and monitoring tool.&lt;/li&gt; 
  &lt;li&gt;Hyperproof, an AI-based control mapping tool.&lt;/li&gt; 
  &lt;li&gt;LogicGate Risk Cloud, a tool to develop maps using workflows and mapping templates.&lt;/li&gt; 
  &lt;li&gt;NIST OSCAL (Open Security Controls Assessment Language), a set of NIST-developed hierarchical, formatted, XML- JSON- and YAML-based formats used for development and assessment of security controls.&lt;/li&gt; 
  &lt;li&gt;OneTrust, a tool that supports security map development using GDPR, DORA, ISO, NIST, HIPAA and others.&lt;/li&gt; 
  &lt;li&gt;Secureframe, an automated control mapping tool for SOC 2, ISO, HIPAA and other standards.&lt;/li&gt; 
  &lt;li&gt;ServiceNow GRC, a tool that includes crosswalk templates and evidence-collection features.&lt;/li&gt; 
  &lt;li&gt;Tugboat Logic, which is part of OneTrust, offering crosswalks for standards such as SOC 2, ISO and HIPAA.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;i&gt;Editor's note: The author chose to highlight these tools based on independent research, prioritizing anecdotally prominent and well-established offerings with significant user bases. This list is organized alphabetically.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Pros and cons of mapping with automation and AI"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Pros and cons of mapping with automation and AI&lt;/h2&gt;
 &lt;p&gt;Control mapping benefits from automation, and, more specifically, AI-assisted automation. Tasks required for mapping can be streamlined and completed more quickly with AI than through manual approaches and existing mapping applications.&lt;/p&gt;
 &lt;p&gt;Among the advantages are faster control and standard matching. AI algorithms can analyze control intent across standards and frameworks. Automation also enables a team to use consistent language across different standards. AI can monitor attributes continuously and alerts when standards and regulations are updated.&lt;/p&gt;
 &lt;p&gt;Other benefits of automated mapping include streamlined map creation; rapid collection of relevant evidence from various sources and event-ticketing systems; streamlined workflows for the control-testing process; real-time version control for control maps and internal controls; and collection of relevant evidence for audit preparation and reporting.&lt;/p&gt;
 &lt;p&gt;If using automation, note that while AI can gather relevant regulatory and standards documents, it cannot interpret the standard's intent without human review. Also, AI-generated maps could contain errors that would affect compliance. It's up to people to confirm the work produced is accurate and understandable to auditors and regulators.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Paul Kirvan, FBCI, CISA, is an independent consultant and technical writer with more than 35 years of experience in business continuity, disaster recovery, resilience, cybersecurity, GRC, telecom and technical writing.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Being able to map cybersecurity controls to applicable standards and regulations can make compliance work less complicated – especially when automation and AI come into play.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/folder-files13.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/tip/How-mapping-security-controls-can-ease-the-compliance-burden</link>
            <pubDate>Thu, 16 Jul 2026 16:47:00 GMT</pubDate>
            <title>How mapping security controls can ease the compliance burden</title>
        </item>
        <item>
            <body>&lt;p&gt;IoT is meant to drive operational efficiency and improve decision-making, largely by automating processes and reducing overall costs. But with these benefits come escalating cybersecurity &lt;a href="https://www.techtarget.com/iotagenda/tip/5-IoT-security-threats-to-prioritize"&gt;threats that target IoT devices&lt;/a&gt;, which are notoriously vulnerable compared to traditional IT infrastructure.&lt;/p&gt; 
&lt;p&gt;Several security frameworks address IoT, including the &lt;a target="_blank" href="https://www.techtarget.com/searchsecurity/definition/NIST-Cybersecurity-Framework" rel="noopener"&gt;NIST Cybersecurity Framework&lt;/a&gt; and &lt;a target="_blank" href="https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards" rel="noopener"&gt;IEC 62443&lt;/a&gt; for industrial systems. That said, one approach -- &lt;a href="https://www.techtarget.com/searchsecurity/tip/Perimeter-to-posture-A-roadmap-to-zero-trust-maturity"&gt;zero trust&lt;/a&gt; -- has bubbled to the top as the most practical way to secure IoT. Zero trust's emphasis on continuous verification, continuous validation, microsegmentation and network-based behavioral analytics helps enterprises address visibility and enforcement gaps common when working with low-cost IoT devices.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Common IoT security challenges"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Common IoT security challenges&lt;/h2&gt;
 &lt;p&gt;The rapid expansion of IoT devices and other connected components has dramatically increased the attack surface for enterprise organizations. IoT systems often offer poor visibility, have limited built-in security capabilities and lack support for endpoint protection software, hobbling IT security teams. As a result, unpatched devices with weak credentials are common.&lt;/p&gt;
 &lt;p&gt;Their inherent security flaws make IoT devices ripe targets for malicious hackers, who exploit them to scan the network and compromise other systems, creating a serious risk to mission-critical components and data. &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-manage-third-party-risk-in-the-supply-chain"&gt;Supply-chain risks&lt;/a&gt; only compound the issue. Pre-compromised IoT devices can introduce massive threats at scale, leading to botnets and persistent backdoors that make threat remediation incredibly difficult.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    Their inherent security flaws make IoT devices ripe targets for malicious hackers, who exploit them to scan the network and compromise other systems. 
   &lt;/figure&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;Enterprises that don't properly address these vulnerabilities face the constant risk of ransomware attacks, operational disruptions, and compliance and regulatory issues. The financial and reputational consequences could be catastrophic.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="How zero trust addresses IoT security"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How zero trust addresses IoT security&lt;/h2&gt;
 &lt;p&gt;Zero trust principles use a "never trust, always verify" philosophy, eliminating the implicit trust often found in organizations that traditionally rely on perimeter-based security. Zero trust shifts enforcement to the network, focusing on device verification and continuous validation of every request&lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;. Least-privilege policies&lt;/a&gt; -- i.e., &lt;a href="https://www.techtarget.com/searchnetworking/definition/microsegmentation"&gt;microsegmentation&lt;/a&gt; -- also sharply restrict device communications. That means a compromised IoT device cannot scan and infect other devices on the network, reducing the risk that a threat actor will disrupt operations or steal data from mission-critical systems.&lt;/p&gt;
 &lt;p&gt;Zero trust also solves the scalability issue of IoT security. Policies are applied, enforced and continuously validated at the network level rather than on the devices themselves. This method lets organizations centralize management and automate enforcement across thousands of endpoints regardless of device type, OS or firmware limitations.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Challenges of applying zero trust to IoT"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Challenges of applying zero trust to IoT&lt;/h2&gt;
 &lt;p&gt;While zero trust offers clear advantages over other methodologies, implementing it in IoT environments poses certain challenges. IoT networks contain many legacy and resource-constrained devices, making it difficult or even impossible to apply modern, network-based identity methods such as &lt;a href="https://www.techtarget.com/searchsecurity/definition/mutual-authentication"&gt;mutual authentication&lt;/a&gt;, device attestation or public key infrastructure enrollment. Network-level enforcement might also introduce latency, hindering the real-time capabilities of some IoT devices and platforms.&lt;/p&gt;
 &lt;p&gt;While zero-trust policy management is centralized, creating highly granular policies across thousands of IoT devices can grow increasingly complex. Interoperability issues can also arise for IoT endpoints that use non-standard or &lt;a href="https://www.techtarget.com/iotagenda/tip/Top-12-most-commonly-used-IoT-protocols-and-standards"&gt;proprietary protocols&lt;/a&gt;. Without proper processes to onboard devices within a zero-trust model, security policies can quickly become muddled, potentially leading to inconsistent enforcement and security gaps.&lt;/p&gt;
 &lt;p&gt;Finally, &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-implement-zero-trust-security-from-people-who-did-it"&gt;shifting to a zero-trust methodology&lt;/a&gt; requires new skills and tools, as well as organizational cultural shifts that, without proper management, can slow adoption and affect day-to-day operations.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Best practices for implementing zero trust for IoT"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Best practices for implementing zero trust for IoT&lt;/h2&gt;
 &lt;p&gt;Ideally, a zero-trust implementation follows a phased approach that addresses the operational constraints outlined above. CISOs should consider the following best practices:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;IoT device discovery and inventory&lt;/b&gt;. Identify and classify all existing IoT devices and platforms, along with their risk levels, functions, protocols and communication patterns.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Define protection boundaries&lt;/b&gt;. Specify which external resources IoT groups need to communicate with. Use this information to formulate protection boundary policies.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Apply microsegmentation. &lt;/b&gt;Based on IoT discovery and protection boundaries, create policies that enforce strict least-privilege access.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Develop context-aware policies&lt;/b&gt;. For IoT devices that require agentless enforcement, combine identity-based methods with &lt;a href="https://www.techtarget.com/searchsecurity/definition/user-behavior-analytics-UBA"&gt;behavioral analytics&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Measure and adjust&lt;/b&gt;. Use tools to monitor and track metrics, including IoT device visibility, policy-enforcement rate and lateral-movement reduction. Make policy adjustments accordingly to further restrict communication flows without disrupting operations.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;With proper collaboration across IT, security and operational technology teams and the right planning in place, zero trust can serve as the security foundation that enables IoT expansion for years to come.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Andrew Froehlich is founder of InfraMomentum, an enterprise IT research and analyst firm, and president of West Gate Networks, an IT consulting company. He has been involved in enterprise IT for more than 20 years.&lt;/em&gt;&lt;/p&gt;
 &lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>IoT devices have significant business benefits but also open enterprises to escalating security risks. Discover why zero trust is the most practical way to secure IoT.</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/AI-IoT-hero.png</image>
            <link>https://www.techtarget.com/searchsecurity/tip/Why-CISOs-should-use-zero-trust-security-for-IoT</link>
            <pubDate>Wed, 15 Jul 2026 18:37:00 GMT</pubDate>
            <title>Why CISOs should use zero-trust security for IoT</title>
        </item>
        <item>
            <body>&lt;p&gt;Enterprise AI deployments are scaling faster than any software category in history, now commanding 6% of the $300 SaaS market, according to venture capital firm Menlo Ventures. Meanwhile, McKinsey &amp;amp; Company has reported that 88% of businesses have applied AI to at least one task.&lt;/p&gt; 
&lt;p&gt;In their rush to deploy transformational AI or risk falling behind competitors, many enterprises are overlooking critical security vulnerabilities. The race to production is outpacing the due diligence required to ensure secure and resilient environments -- and adversaries are already exploiting the gap.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="AI breaches are different"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;AI breaches are different&lt;/h2&gt;
 &lt;p&gt;The introduction of AI into enterprise production environments creates an entirely different and potentially more expansive &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-is-attack-surface-management-and-why-is-it-necessary"&gt;attack surface&lt;/a&gt;. This fact is not lost on adversaries, who have been quick to capitalize on exposed AI infrastructure.&lt;/p&gt;
 &lt;p&gt;AI-driven applications differ from traditional software in numerous ways, starting with how they handle user input. In conventional applications, user input security controls run on predictability -- identical input equals identical output. Large language model (LLM) outputs, however, can change based on factors ranging from temperature, settings and context length to model updates and tool availability. This makes it challenging to verify when vulnerabilities are patched.&lt;/p&gt;
 &lt;p&gt;Another significant difference with LLMs is that adversaries don't have to exploit &lt;a href="https://www.techtarget.com/searchsecurity/opinion/Top-vulnerability-management-challenges-for-organizations"&gt;software vulnerabilities&lt;/a&gt;. Instead, threat actors can work in a manner resembling social engineering, manipulating an ambiguity or shifting context to penetrate the model. Plus, attackers don't have to take over infrastructure to exfiltrate sensitive information. They can manipulate an AI model to trigger malicious actions. Threat actors can also &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-data-poisoning-attacks-work"&gt;poison outputs&lt;/a&gt; by manipulating the data pipeline.&lt;/p&gt;
 &lt;p&gt;By its nature, AI is susceptible to tactics such as prompt injections and instruction hacking that adversaries use to trick the engine into ignoring rules and following nefarious instructions. Data exfiltration using &lt;a href="https://www.techtarget.com/searchenterpriseai/tip/RAG-best-practices-for-enterprise-AI-teams"&gt;retrieval-augmented generation&lt;/a&gt; (RAG) and connectors is another common attack method in which threat actors bypass access controls during retrieval. Bad actors also use AI to launch machine-speed attacks that can identify and exploit &lt;a href="https://www.techtarget.com/searcherp/feature/5-supply-chain-cybersecurity-risks-and-best-practices"&gt;supply chain&lt;/a&gt; vulnerabilities.&lt;/p&gt;
 &lt;p&gt;Adversaries can use language to bypass policies and controls maintained by conventional security tools. LLMs are often connected to multiple environments, including code, HR, tickets and CRM systems. Infiltrating an LLM workflow can therefore compromise multiple domains simultaneously. Data can be leaked through generated texts, summaries, tool outputs, logs and other unauthorized actions.&lt;/p&gt;
 &lt;p&gt;AI breaches are difficult to detect, too, with leaks occurring over multiple seemingly harmless inquiries. This forces investigators to determine whether the leaked data was from training, memory or a connector.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="Building a cyber-resilient AI environment"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Building a cyber-resilient AI environment&lt;/h2&gt;
 &lt;p&gt;The impact of an AI breach can be significant, ranging from exposed sensitive data and regulatory fines to integrated AI systems working improperly. Enterprises need to approach AI with security as an integral part of its use. Security practitioners must set governance and threat modeling from the outset. Security teams should model LLM-specific threats such as &lt;a href="https://www.techtarget.com/searchsecurity/tip/Types-of-prompt-injection-attacks-and-how-they-work"&gt;prompt injection&lt;/a&gt;, indirect injection and data leakage via RAG.&lt;/p&gt;
 &lt;p&gt;Authorization requirements at retrieval time, not just in the UI, are critical. Security practitioners need to ensure identity permissions extend to the database and search layers. While certainly not unique to AI, it is important to use data classification and tagging to keep potentially confidential and high-value documents from being indexed.&lt;/p&gt;
 &lt;p&gt;It is critical to safeguard all connectors and credentials. This means applying &lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;least-privilege&lt;/a&gt; access controls for connectors. Build security into tool and agent execution through policies that incorporate controls such as allowlists and constraints. It is also important to mandate human intervention for permanent actions, including payments and customer-facing emails.&lt;/p&gt;
 &lt;p&gt;To deflect prompt injections, security practitioners should use strong system prompts. Additionally, &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-implement-zero-trust-security-from-people-who-did-it"&gt;implement zero-trust controls&lt;/a&gt; that assume external content is potentially malicious until proven otherwise. Data loss prevention protocols are critical to block users from pasting sensitive content into AI that could be leaked.&lt;/p&gt;
 &lt;p&gt;The supply chain also needs security, which requires vetting all checkpoints and consistent maintenance of the model registry. Harden all infrastructure with isolation applied to tenants and indexes. Put strong identity and access management in place through single sign-on and MFA, maintaining zero-trust principles.&lt;/p&gt;
 &lt;p&gt;SecOps teams must be vigilant about logging and monitoring, looking for indicators such as abnormal query patterns and escalations in retrievals of sensitive labels. All organizations need to have an AI incident response guide that outlines elements such as taking tools and connectors offline, rotating tokens, purging indexes and verifying data leakage sources.&lt;/p&gt;
 &lt;p&gt;As AI continues its rapid integration into enterprise operations, organizations must recognize that speed without security is a recipe for disaster. The transformative potential of AI can only be realized when built on a foundation of cybersecurity and proactive risk management. Organizations that prioritize cyber-resilience today will be the ones that thrive in the AI-driven future, while those that neglect it could face breaches that could have otherwise been prevented.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Amy Larsen DeCarlo has covered the IT industry for more than 30 years, as a journalist, editor and analyst. As a principal analyst at GlobalData, she covers managed security and cloud services.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>AI attacks and breaches hit differently than traditional attacks, and therefore require more than traditional controls. The best defense requires planning for cyber-resilience.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/code_g1196680867.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/tip/Building-cyber-resilient-AI-in-the-enterprise</link>
            <pubDate>Tue, 14 Jul 2026 08:00:00 GMT</pubDate>
            <title>Building cyber-resilient AI in the enterprise</title>
        </item>
        <item>
            <body>&lt;p&gt;As enterprises race to deploy AI across their operations, a perfect storm is brewing: New AI-generated attack vectors are colliding with employees' growing emotional trust in chatbots and AI assistants, creating security blind spots that traditional defenses weren't designed to handle.&lt;/p&gt; 
&lt;p&gt;Security teams are knee-deep in mitigating the threats that accompany AI adoption, from &lt;a href="https://www.techtarget.com/searchsecurity/tip/Types-of-prompt-injection-attacks-and-how-they-work"&gt;prompt injections&lt;/a&gt; and &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-data-poisoning-attacks-work"&gt;data poisoning&lt;/a&gt; to bias exploitation, deepfakes, and models acting in unexpected ways. Though a constant struggle, this more technical concern accompanies the psychological issue of employees oversharing sensitive information with conversational AI systems they've come to trust as helpful and even friendly digital assistants -- a challenge that is harder to address.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="The problem of oversharing"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The problem of oversharing&lt;/h2&gt;
 &lt;p&gt;The personal use of generative AI and chatbots has broad social implications that bleed into the workplace. Psychologists understand that human beings tend to connect with anything that talks to them, &lt;a href="https://www.psychologytoday.com/us/blog/virtue-in-the-media-world/202405/chatbots-could-start-shaping-how-we-trust-and-who-we-trust" target="_blank" rel="noopener"&gt;even if it's a machine&lt;/a&gt;. And although most users know that AI isn't sentient, it can still elicit emotions -- specifically, misplaced trust.&lt;br&gt;&lt;br&gt;The line between workplace and personal AI is blurry, and some employees are bringing their bad habits to work. Many organizations have yet to establish firm policies for the use of AI assistants, and many employees use AI without awareness of their organization's AI strategy, suggesting widespread use of personal tools outside official channels. According to a &lt;a href="https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part" target="_blank" rel="noopener"&gt;Microsoft study&lt;/a&gt;, 78% of users bring their own AI tools to work, with the practice being more common at small and midsize companies. Further, a National Cybersecurity Alliance and CybSafe &lt;a href="https://www.staysafeonline.org/articles/oh-behave-the-annual-cybersecurity-attitudes-and-behaviors-report-2025" target="_blank" rel="noopener"&gt;survey&lt;/a&gt; found that 43% of employees who use AI for work tasks send sensitive data to AI applications without their employer's knowledge.&lt;/p&gt;
 &lt;p&gt;This reality is creating a new problem for security teams. Employees, already conditioned to trust their personal AI assistants -- everything from ChatGPT to AI friend apps -- are more likely to let their guard down and share personally identifiable information or sensitive company data with systems that lack inherent privacy safeguards. In fact, many publicly available GenAI platforms clearly state in their T&amp;amp;Cs that they use inputs as training data.&lt;br&gt;&lt;br&gt;There are real-world implications. For example, Samsung suffered &lt;a href="https://www.ciodive.com/news/Samsung-Electronics-ChatGPT-leak-data-privacy/647137/" target="_blank" rel="noopener"&gt;several security incidents&lt;/a&gt; related to AI assistants. In 2023, an engineer pasted proprietary source code for semiconductor equipment into ChatGPT to help correct errors, exposing confidential code used in the company's chip manufacturing process. Another employee exposed sensitive business intelligence and internal discussions after feeding the content of a high-level meeting into ChatGPT.&lt;/p&gt;
 &lt;p&gt;According to Naynesh Patel, managing director of cybersecurity at Accenture, the ease of information sharing with AI assistants is problematic, and traditional enterprise security was not designed for it. "The concept of a text box -- where you are able to put information in with little to no friction -- and the fact that it's helpful creates risk," he said.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Governance for AI trust"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Governance for AI trust&lt;/h2&gt;
 &lt;p&gt;The convergence of technical vulnerabilities and human psychology requires CISOs and their teams to adopt controls to defend against data loss via AI.&lt;/p&gt;
 &lt;p&gt;According to Patel, the solution isn't fixing AI; it's rethinking how the organization itself governs AI use among its employees. He said that most data security failures aren't model failures, but identity and &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-CISOs-need-to-know-about-AI-governance-frameworks"&gt;governance&lt;/a&gt; failures running at machine speed.&lt;/p&gt;
 &lt;p&gt;He recommended that security teams deploy the following basic protections alongside enterprise GenAI and chatbot instances:&lt;/p&gt;
 &lt;ul type="disc" class="default-list"&gt; 
  &lt;li&gt;Restrict the ability to post information that's shared anywhere else, such as with the AI parent company and related technology providers.&lt;/li&gt; 
  &lt;li&gt;Keep all data inputs within the boundaries of the organization.&lt;/li&gt; 
  &lt;li&gt;Grant just-in-time, &lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;least-privileged access&lt;/a&gt; for all employees.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Set telemetry that enables SecOps teams to see prompts and &lt;a href="https://www.techtarget.com/searchsecurity/tip/Beyond-awareness-Human-risk-management-metrics-for-CISOs"&gt;intervene at the moment of risk&lt;/a&gt;.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Data: The new perimeter"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Data: The new perimeter&lt;/h2&gt;
 &lt;p&gt;Data is the new perimeter, and GenAI and conversational AI represent both productivity tools and data exfiltration points. Security teams must treat them as they would any other approved digital tool: secure them, put controls around them, audit their use and educate employees on how to use them safely.&lt;/p&gt;
 &lt;p&gt;As far as human threats are concerned, companies must enforce strict policies. In the wake of its AI security woes, Samsung pursued disciplinary action against the employees, developed its own internal AI system with data controls and eventually enhanced its security protocols.&lt;/p&gt;
 &lt;p&gt;At its best, conversational AI provides efficiency to many at work and comfort to some at home. At their worst, AI assistants can make an already daunting threat landscape worse. What's certain, however, is that human nature is difficult to change, and people will continue to share more information than they should, which requires a fundamental evolution in how security leaders think about risk.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Richard Livingston is an editor with Informa TechTarget's SearchSecurity site, covering cybersecurity news, trends and analysis.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>As employees become more accustomed to using AI, they might be getting a little too comfortable. Learn how strong AI governance helps manage this new human risk.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/ai_a279596285.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/feature/Why-conversational-AI-is-redefining-your-security-perimeter</link>
            <pubDate>Mon, 13 Jul 2026 08:00:00 GMT</pubDate>
            <title>Why conversational AI is redefining your security perimeter</title>
        </item>
        <item>
            <body>&lt;p&gt;When it comes to malware delivery methods, attackers are sticking with what works -- even as they rely on a rapidly revolving door of payloads.&lt;/p&gt; 
&lt;p&gt;That's according to a report from the ReliaQuest Threat Research Team, which tracks threat activity quarterly. From March 1 to May 31, ClickFix was attackers' preferred malware delivery technique, followed by removable media such as USB drives.&lt;/p&gt; 
&lt;p&gt;ReliaQuest also monitors the top three malware families involved in confirmed security incidents, a list that has experienced almost complete turnover across the past three tracking periods. For defenders, that trend brings new urgency to old advice: Monitor threat behavior, not malware names.&lt;/p&gt; 
&lt;p&gt;Here's how security teams can defend against ClickFix and removable-media-based attacks.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Trending attack: How to defend against ClickFix"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Trending attack: How to defend against ClickFix&lt;/h2&gt;
 &lt;p&gt;Defenders can no longer consider ClickFix, a &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-avoid-and-prevent-social-engineering-attacks"&gt;social engineering&lt;/a&gt; technique that first appeared in 2024, an emerging or OS-specific threat, ReliaQuest researchers warned. It was the dominant malware delivery channel between March 1 and May 31, and the second most common in the previous three-month reporting period.&lt;/p&gt;
 &lt;p&gt;In addition to leading initial access, ClickFix also drove nearly a third of defense-evasion activity. And while it has historically targeted Windows users, ReliaQuest researchers recently observed ClickFix delivery of Atomic Stealer malware on macOS systems.&lt;/p&gt;
 &lt;p&gt;"For enterprises, macOS must no longer be treated as lower risk and now needs the same monitoring and response coverage as Windows," &lt;a target="_blank" href="https://reliaquest.com/blog/threat-spotlight-whats-trending-top-cyber-attacker-techniques-march-may-2026" rel="noopener"&gt;wrote&lt;/a&gt; Raigridas Bartkus, the report's author and a cybersecurity specialist at ReliaQuest.&lt;/p&gt;
 &lt;p&gt;ClickFix tricks users into engaging with prompts -- commonly disguised as legitimate error messages, update notifications and &lt;a href="https://www.techtarget.com/searchsecurity/definition/CAPTCHA"&gt;CAPTCHA&lt;/a&gt; checks -- and pasting malicious commands into system dialogs. While ClickFix often spreads through compromised websites, ReliaQuest noted it has recently shifted to email-based lures.&lt;/p&gt;
 &lt;p&gt;"This period we also &lt;a target="_blank" href="https://reliaquest.com/blog/threat-spotlight-deepload-malware-pairs-clickfix-delivery-with-ai-generated-evasion/" rel="noopener"&gt;saw&lt;/a&gt; a ClickFix loader use likely AI-generated obfuscation to deliver 'Deepload' malware, burying its real logic under thousands of meaningless variable assignments to defeat static scanning," Bartkus wrote. With AI, he added, &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-AI-malware-works-and-how-to-defend-against-it"&gt;attackers can generate new variants more quickly&lt;/a&gt;, giving defenders less time to adapt signature-based detection tools.&lt;/p&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Malware leaderboard: March 1, 2026 - May 31, 2026&lt;/h3&gt; 
   &lt;p&gt;Here are the malware families that dominated ReliaQuest's latest reporting period, along with their delivery methods.&lt;/p&gt; 
   &lt;p&gt;&lt;b&gt;Malware family:&lt;/b&gt; Gamarue, also known as &lt;i&gt;Andromeda&lt;/i&gt;, a familiar modular worm.&lt;b&gt;&lt;br&gt;Malware delivery:&lt;/b&gt; Spread through removable media, such as USB flash drives.&lt;/p&gt; 
   &lt;p&gt;&lt;b&gt;Malware family:&lt;/b&gt; NetSupport RAT, a remote access trojan variant of the legitimate IT remote administration tool NetSupport Manager.&lt;b&gt;&lt;br&gt;Malware delivery:&lt;/b&gt; The payload that ClickFix most often delivered, according to ReliaQuest.&lt;/p&gt; 
   &lt;p&gt;&lt;b&gt;Malware family:&lt;/b&gt; Raspberry Robin, a worm often used to provide initial access to ransomware operators.&lt;br&gt;&lt;b&gt;Malware delivery:&lt;/b&gt; Spread through removable media, such as USB flash drives.&lt;/p&gt;
  &lt;/div&gt;
 &lt;/div&gt;
 &lt;p&gt;ClickFix attacks are now so pervasive and scaling so quickly that continuous training, detection and triage are necessary in both Windows and macOS environments, according to the report. CISOs should consider taking the following steps:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Train users.&lt;/b&gt; By convincing targets to unwittingly run malicious commands on their own devices, ClickFix can bypass many file- and email-based controls. That makes an &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecurity-employee-training-How-to-build-a-solid-plan"&gt;educated user base&lt;/a&gt; the best defense. Train both Windows and macOS users never to paste commands in Run, Terminal or Script Editor.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Include ClickFix lures in security awareness training.&lt;/b&gt; Don't just tell users what to avoid -- show them, using simulated pop-up and email-based lures that mimic ClickFix attacks. Bartkus suggested including CAPTCHA and verification prompts, browser-to-shell hand-offs and "paste-this-to-continue" directives.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Restrict access to system dialogs.&lt;/b&gt; Restrict Run, Terminal and Script Editor access as much as possible, especially for nontechnical users in high-risk roles.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Monitor for suspicious behavior.&lt;/b&gt; Where impractical to restrict access to system dialogs -- for technical users, for example -- security teams should log and alert on RunMRU activity.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;"Monitoring for activity such as a sequence of base64 decoding, curl retrieval and PowerShell or osascript execution, for example, would represent reliably anomalous behavior in developer environments," a ReliaQuest spokesperson told &lt;a target="_blank" href="https://www.darkreading.com/vulnerabilities-threats/winner-dominant-malware-delivery-clickfix" rel="noopener"&gt;Dark Reading&lt;/a&gt;, a TechTarget Cybersecurity sister publication.&lt;/p&gt;
 &lt;p&gt;Because ClickFix attacks often rely on command obfuscation and obfuscated files, defenders should also look for legitimate-seeming files in unusual places.&lt;/p&gt;
&lt;/section&gt;           
&lt;section class="section main-article-chapter" data-menu-title="Trending attack: How to defend against USB-based compromise"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Trending attack: How to defend against USB-based compromise&lt;/h2&gt;
 &lt;p&gt;Among top initial access paths in March, April and May, removable media came in hot on ClickFix's heels. According to ReliaQuest researchers, two of the top three malware families during the reporting period spread through infected external devices such as USB drives.&lt;/p&gt;
 &lt;p&gt;The report noted a persistent seasonal trend: USB-based attacks tend to escalate during predictable annual periods, such as tax season and Q1 financial reporting. Presumably, employees use removable drives to transfer files among in-office, at-home and third-party environments, increasing enterprise risk.&lt;/p&gt;
 &lt;p&gt;ReliaQuest warned that USB-based malware can lead to broader compromise. Raspberry Robin, for example -- one of the reporting period's leading malware families -- often enables &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-role-does-an-initial-access-broker-play-in-the-RaaS-model"&gt;initial access for ransomware operators&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;According to the researchers, defenders should take the following steps to defend against USB-based attacks.&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Disable USB autorun across the enterprise IT environment.&lt;/li&gt; 
  &lt;li&gt;Use allowlists to &lt;a href="https://www.techtarget.com/searchsecurity/tutorial/How-to-disable-removable-media-access-with-Group-Policy"&gt;block unapproved removable devices&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Alert on shortcut (.lnk) or script execution from external drives.&lt;/li&gt; 
  &lt;li&gt;Approach any confirmed USB-based infection as the possible precursor to a &lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-3-ransomware-attack-vectors-and-how-to-avoid-them"&gt;major ransomware attack&lt;/a&gt;.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;em&gt;Alissa Irei is senior site editor of Informa TechTarget Security.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Now more than ever, defenders must look for suspicious behavior, not specific malware. Learn how to defend against two trending initial access methods.</description>
            <image>https://cdn.ttgtmedia.com/visuals/ComputerWeekly/Hero%20Images/security-malware-adobe.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/news/366645832/ClickFix-and-removable-media-lead-malware-delivery-methods</link>
            <pubDate>Fri, 10 Jul 2026 17:55:00 GMT</pubDate>
            <title>ClickFix and removable media lead malware delivery methods</title>
        </item>
        <item>
            <body>&lt;p&gt;In the education sector, cybersecurity controls and third-party risk management get put to the test -- and frequently don't get a passing grade.&lt;/p&gt; 
&lt;p&gt;Academic organizations might not seem like prime targets for cyberattacks, but these data-rich -- and security-insufficient -- schools, colleges and universities are often just what nefarious actors have in their sights.&lt;/p&gt; 
&lt;p&gt;In fact, cybersecurity services provider Quorum Cyber documented a 63% year-over-year increase in cyberactivity at higher-ed institutions from 2024 to 2025, and Clever, a K-12 identity platform vendor, found that 52% of U.S. school districts experienced a cybersecurity event in 2025, up 36% from the previous year. Further, threat exposure management platform vendor NordStellar reported that 2.4% of all ransomware attacks in the first half of 2026 targeted the education sector.&lt;/p&gt; 
&lt;p&gt;A growing trend among attacks on educational organizations is third-party breaches. In late April and early May, edtech company Instructure &lt;a href="https://www.techtarget.com/searchsecurity/news/366642963/Instructure-cyberattack-reignites-ransom-payment-debate"&gt;confirmed a cyberattack&lt;/a&gt; on its Canvas learning management platform. Threat group ShinyHunters claimed responsibility, stating it had stolen 3.65 TB of data, including information about 275 million users across nearly 9,000 schools.&lt;/p&gt; 
&lt;p&gt;In June, ShinyHunters &lt;a target="_blank" href="https://www.highereddive.com/news/colleges-hit-in-cyberattack-by-group-behind-canvas-breach-google-says/822831/" rel="noopener"&gt;took credit for&lt;/a&gt; another higher-ed attack, reporting that it exploited the Oracle PeopleSoft suite, which offers campus applications aimed to help higher-ed manage student records, admissions and financial aid.&lt;/p&gt; 
&lt;p&gt;The risks and challenges for edtech and academic institutions don't stop there. In this Reporter's Notebook video, Dark Reading features writer Arielle Waldman, Cybersecurity Dive senior reporter Eric Geller and TechTarget SearchSecurity executive editor Sharon Shea dive into the reality of edtech cybersecurity, including recent attacks, reasons why the sector is such a prime target and more.&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;Sharon Shea is executive editor of TechTarget Security.&lt;/em&gt;&lt;/p&gt; 
&lt;transcript&gt; 
 &lt;p&gt;&lt;b&gt;Editor's note:&lt;/b&gt; &lt;i&gt;This transcript has been edited for clarity and length by Informa TechTarget's internal AI assistant.&lt;/i&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Dark Reading's Arielle Waldman:&lt;/b&gt; Hi, everyone, welcome to another edition of the Reporters' Notebook. Today we're going to be discussing the education sector and all the issues that they've been facing. My name is Arielle Waldman and I'm a features writer for Dark Reading. I have Sharon Shea and Eric Geller with me. Would you like to introduce yourselves?&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Cybersecurity Dive's Eric Geller:&lt;/b&gt; Yes, I'm Eric Geller, senior reporter at Cybersecurity Dive.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;TechTarget SearchSecurity's Sharon Shea:&lt;/b&gt; Hi, I'm Sharon Shea, executive editor on TechTarget SearchSecurity.&lt;/p&gt; 
 &lt;p&gt;Thank you all for joining us today. We're excited to chat about edtech and the educational sector and cybersecurity. So, we're coming off the heels of what folks are calling the biggest attack on education in history. In late April and early May, edtech company Instructure confirmed a cyberattack on its Canvas Learning Management System. Threat group ShinyHunters claimed responsibility for the attack and said that they stole 3.65TB of data, including information from 275 million users across almost 9,000 schools. As of May 11, Instructure said it had reached an agreement with the attackers and that the software is safe to use. I don't think we know if they paid a ransom or not, but whatever "reached an agreement" means.&lt;/p&gt; 
 &lt;p&gt;And then again, just last week, ShinyHunters also claimed responsibility for further attacks on higher ed, reportedly exploiting the Oracle PeopleSoft software suites, [the vendors] for ERP, CRM [and] HCM, and they have campus applications to help higher ed manage student records, admissions and financial aid. Google noted that while some organizations were able to block or remediate the vulnerabilities before this latest round of attacks, others were compromised and have had their data published on data leak sites. So, education is unique. It's up against a lot of threats and this just touches on the supply chain side, the software supply chain and organizations getting hit because of their software suppliers, as in through Canvas and the PeopleSoft software.&lt;/p&gt; 
 &lt;p&gt;And also a bit of the ransomware in there, too, right? Because they spoke with the attackers and reached an agreement. So, Arielle, I didn't know if you want to talk a little bit more about other attacks that you've seen and written about.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Waldman:&lt;/b&gt; Sure. This seems to just be the latest supply chain attack. I think one issue is the concentrated area of schools that only use certain platforms and software. And they've just experienced so many attacks in the last five years alone. In 2023, there was a big one with Progress Software's MOVEit. It's a file transfer that schools use, and that was also a ransomware attack, and that affected a lot of schools as well, another supply chain ransomware situation, which is so common against the sector. And then the PowerSchool data breach that happened a couple of years ago. PowerSchool is an edtech cloud-based platform. It's used in K-12 schools. And in that case, it was a data breach and attackers made off with names, addresses, birth dates, academic records and even medical information.&lt;/p&gt; 
 &lt;p&gt;And in that case, I think it was confirmed that they paid a ransom to have the files deleted, which does seem common, maybe in the education sector. I don't know if it's always confirmed, but like you said, it seems like they talked with the attackers, which maybe insinuates that they did pay a ransom since the data is so valuable and sensitive when it comes to students. And with the most recent with Canvas, it happened during finals week, which put another kind of hurdle, kind of disrupted school even more so. Though I don't think the students were that upset. I saw a lot of things on social media with students thanking ShinyHunters for disrupting their finals and things like that. I think kids are so immune to it nowadays that their schools are just being attacked and they receive data breaches, as [does] everyone, and these attacks just continue to show that.&lt;/p&gt; 
 &lt;p&gt;Eric, do you want to dig into why schools are such a big target?&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Geller:&lt;/b&gt; It's a toxic combination of a bunch of factors. First, they have a lot of data. Second, they have a lot of data about people who are at the very beginning of their lives. So Social Security numbers and personal information is going be usable for a lot longer because these people are so young. If you steal that information, you have in some cases 80 more years of usefulness from it if the person doesn't change some of that information and you can't, you know, change the Social Security number. So the lifespan of the data is so much longer, and when you combine that with the fact that these are not well-protected organizations, they're funded by local governments. They have dire needs outside of cybersecurity that receive a lot more of the funding, teacher pay, infrastructure. They're not only valuable targets because of the data that they hold, but they're easy targets because of the networks that they run.&lt;/p&gt; 
 &lt;p&gt;There's also another security issue for them because a lot of them will give out tablets, and it's not always easy to manage the security of the tablets. Same with laptops, but also students are bringing their own devices to school. If you think about a business environment where you're trying to enforce a managed device policy because of the security risks of BYOD, it's so much harder in a school environment. So, you have all these outside devices coming into the network, and you could sort of think of it as an insider threat where the student doesn't have malicious intent.&lt;/p&gt; 
 &lt;p&gt;But if the attacker is able to break into the student's device because they're not prioritizing cybersecurity, and who among them is, that's another vector for them to get in. And then they can move across the network because that computer is given access to the network infrastructure at the school. So, these are places that don't have the money to prioritize cybersecurity. They have a hard time often attracting top-tier cybersecurity experts to work for them. They're connected in some cases to other local government infrastructure and that infrastructure is also vulnerable. And so all of that helps explain why it's easy to get in. And then, of course, as I said, once you get in, there's a lot of good stuff to take. So, the combination of those things makes them a really easy and valuable target.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Waldman:&lt;/b&gt; I was going to add in one thing. The students are also posing insider threats as well. They're trying to hack into the system sometimes, either just to see if they can hack or to change grades, maybe&amp;nbsp; just get around the security measures so they can break out onto the internet. They'll try to hack in that way.&lt;/p&gt; 
 &lt;p&gt;So, it's just schools are experiencing these threats from so many angles, not just attackers. Obviously, like you said, students aren't trying to be malicious, but it really just adds to the noise. And like you said, they're so under-resourced and understaffed. Adding to any noise, it makes these teams, you know, they're already busy, and they don't have time to sort through the noise and find out it's a student, and they just take more resources. So, schools just have it from all ends.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Shea:&lt;/b&gt; Absolutely. I was also going to touch on what you mentioned, the Social Security numbers and everything of the students. You also have their parents, folks who are also signing for the financials and everything. You have the staff, you have other faculty and even the financial aid data, payment data and a lot of healthcare information [that] will roll through the school as well. So, another big vector. And also a lot of the higher ed organizations are, you know, research facilities. So, you have all of that intellectual property also at risk.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Geller:&lt;/b&gt; Right, you have on the one end the students in the K-12 sector who are at the beginning of their lives and their data is very valuable. And then at the other end, you have the top-tier research universities where the students are a little older, but the other data is so much more valuable because it's not the parents' financial info. It's in some cases this, you know, patentable intellectual property, this confidential data about applied research innovations and we're talking about this in the education sector, but there is also an overlap with the defense sector because some of the universities do have defense contracts. Or if it's not military-related, they're working on scientific research for the government in other contexts. So, it is an interesting duality that you have the youngest of the young kids where you don't really care about what they're learning in school. You're not trying to get their arithmetic homework, but they as identity theft victims are so valuable. And then at the other end, the students are actually, because of what they're doing, more interesting than the identity of the people who are in the school.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Shea:&lt;/b&gt; I think, too, we touched on the resources of schools as well. You know, a lot of schools are on legacy infrastructure like older companies and those are difficult to patch, difficult to manage with limited budgets and limited staff.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Waldman:&lt;/b&gt; Great point. Can't afford the downtime often to patch as well.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Shea:&lt;/b&gt; Absolutely. And beyond the BYOD issue and insider threats, what other sort of problems are we seeing with the infrastructure, and why are there issues among higher-ed education?&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Geller:&lt;/b&gt; Well, I think one big challenge is these school districts don't have a lot of leverage with their vendors to enforce procurement requirements. So, one of the things that I think you're going to start to see is local governments will really try to package together the software that they need across the county or across, maybe it's the state, so that they can get better terms with the vendors so that they're putting in a larger purchase order, they have a little bit more sway with the vendor as opposed to the very specific school software that only the schools are going to buy, the vendor is in a much more advantageous position than the school because they sell to a lot of schools. The school is only buying from a handful of vendors. The school, in many cases, can't turn to another vendor either because it doesn't have exactly the features they need or because they've been using the same vendor for years and switching would be very difficult. And so, the relationship there, the biggest changes I think we're going to see in cybersecurity when it comes to the security of software are the result of procurement terms, what the buyer can require from the vendor as a result of the leverage that they have.&lt;/p&gt; 
 &lt;p&gt;And that's just not something that exists in the K-12, at least education environment. I won't speak to the higher-ed environment because oftentimes those public university systems have a lot of sway with their vendors because they're huge institutions. But a local school district, to say nothing of just a local government in general, is going [to] have a much harder time. And so, I think what you're seeing now, I actually was at a conference recently where there was a conversation about edtech. And there's going to be a push I think to try to include those terms in the contracts where possible and then where it isn't possible to explicitly have stronger cybersecurity language to try to litigate after a breach on the basis of existing statutes to try to get the vendors to do better about cybersecurity so that they don't expose themselves to that kind of liability with other customers going forward.&lt;/p&gt; 
 &lt;p&gt;Liability and vendor expectations and procurement ecosystem, I think that's an interesting space to watch if you're interested in edtech cybersecurity over the next few years. How does that evolve? How do the districts get more out of the software they're buying, even though they don't have the power to tell the vendors exactly what to do?&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Waldman:&lt;/b&gt; I don't know how motivated the vendors are to include strong security if there's not that many choices for the schools or, like you said, they've been using one vendor for a while, they don't have a lot of resources to switch. So yeah, maybe they'll be more motivated to do so if that's kind of built in there.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Shea:&lt;/b&gt; And I think that's also why you'll see, as we saw with Instructure, one vendor gets hit and it had, you know, 9,000 schools. So, it'll be interesting to see.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Waldman:&lt;/b&gt; Another threat that I've been covering are ghost students. So, this is just another issue that schools are dealing with. Basically, these are fake students. They could be bots or anything like that. And these threat actors take up resources because they apply for financial aid and other things. And they take it away from the real students. So they're kind of fake applicants. They can use celebrity names sometimes or stolen identities.&lt;/p&gt; 
 &lt;p&gt;And then in that way they secure admissions or financial aid. And it's really straining resources in higher education institutions. Basically, the individual goes through the application process, but they're not actually going to attend. They could be scammers or bots. And why in one case, a fake student stole more than $10 million in federal finances from California community colleges in just one year. So, it's definitely racking up there and taking even more resources away. Since the attackers know that schools are &lt;a name="_Int_sbdntkGb"&gt;&lt;/a&gt;really under-resourced and understaffed and they're just continuing to take advantage of that.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Shea:&lt;/b&gt; That's an interesting point. Have you seen how schools are combating this with the limited resources?&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Waldman:&lt;/b&gt; It's really getting tough. I don't think they are managing to get through some of them. I think awareness is where it's starting right now and just looking out for these threats and knowing that it's happening. I think the growing awareness is the first step so that the understaffed teams can know what to look for in those situations. Because before I think it was lesser known and it was hard to pick that out amongst all the threats that they're facing. So, the awareness I think is helpful there.&lt;/p&gt; 
 &lt;p&gt;And obviously ransomware continues to be a huge issue. I feel like ever since COVID, it just picked up against the schools and it just has not slowed down. I don't know if that's ever going to slow down. It seems schools just really can't handle ransomware with the downtime, and all the sensitive data. So, they just keep continuing to make due. Those attacks and schools continue to fall victim and there's so many different avenues now with all using some of the tools at home, like the parents, you know, the kids bring these things home and the parents have different logins, the teachers, the students, there's just so many different kinds of attack vectors there now, which makes it so much more difficult. Even the parents have to look out for these phishing emails or, you know, keep on top of that as well. It's not just the educators and students.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Shea:&lt;/b&gt; I think phishing, identity security, MFA, phishing-resistant authentication across all industries is an issue, but definitely in edtech as well.&lt;/p&gt; 
 &lt;p&gt;Well, I think we've had some interesting insights here today. I want to thank everyone for joining us. With TechTarget SearchSecurity, I am Sharon Shea.&lt;/p&gt; 
 &lt;p&gt;&lt;b&gt;Geller:&lt;/b&gt; And from Cybersecurity Dive, I'm Eric Geller.&lt;/p&gt; 
 &lt;b&gt;Waldman:&lt;/b&gt; From Dark Reading, I'm Arielle Waldman. Thank you.
&lt;/transcript&gt;</body>
            <description>Why are educational institutions easy targets for cybercriminals? Uncover the reality of edtech security, recent breaches and what schools must do.</description>
            <link>https://www.techtarget.com/searchsecurity/video/Edtech-gets-schooled-by-third-party-cyberthreats</link>
            <pubDate>Fri, 10 Jul 2026 13:10:00 GMT</pubDate>
            <title>Edtech gets schooled by third-party cyberthreats</title>
        </item>
        <item>
            <body>&lt;p&gt;MFA has long been one of the most effective security controls an organization can deploy. It's inexpensive compared to many security technologies, relatively easy to implement and capable of stopping a large percentage of credential-based attacks.&lt;/p&gt; 
&lt;p&gt;It's not a coincidence that nearly every security framework and cyber insurance policy recommends or requires &lt;a href="https://www.techtarget.com/searchsecurity/definition/multifactor-authentication-MFA"&gt;MFA&lt;/a&gt;. Even so, simply checking the MFA-enabled box doesn't mean an organization is adequately protected from attack. In many breaches, the victimized organization had MFA in place, and the flaw usually wasn't in the technology itself.&lt;/p&gt; 
&lt;p&gt;The trouble often results from how MFA was deployed, configured or managed over time. Like any security control, MFA is only as effective as its implementation.&lt;/p&gt; 
&lt;p&gt;Let's look at some common ways MFA can go wrong.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Mistake #1: Assuming MFA provides complete coverage"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Mistake #1: Assuming MFA provides complete coverage&lt;/h2&gt;
 &lt;p&gt;&lt;b&gt;Problem: &lt;/b&gt;One of the biggest mistakes organizations make is believing MFA is universally enforced. In reality, it's common to find exceptions that have accumulated over time. Service accounts, legacy applications, VPN appliances, privileged administrator accounts, emergency access accounts and older authentication protocols are often excluded because they were difficult to migrate or were temporarily exempted during deployment. It's also not uncommon for some high-level executives or other key stakeholders to be granted exemptions because they find MFA a nuisance.&lt;/p&gt;
 &lt;p&gt;Attackers don't care whether 98% of a target's users have MFA -- they'll find that 2%.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Solution: &lt;/b&gt;Periodically review authentication policies and identify accounts, applications or protocols that bypass MFA requirements, and, at minimum, enable more rigorous monitoring on these accounts.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Mistake #2: Relying on weak authentication factors"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Mistake #2: Relying on weak authentication factors&lt;/h2&gt;
 &lt;p&gt;&lt;b&gt;Problem:&lt;/b&gt; Not all MFA methods provide the same level of protection. SMS-based one-time codes remain common, but they're increasingly vulnerable to &lt;a href="https://www.techtarget.com/whatis/definition/SIM-swap-attack-SIM-intercept-attack"&gt;SIM swapping&lt;/a&gt;, phishing and social engineering schemes. Email-based verification introduces many of the same weaknesses if the email account itself becomes compromised.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Solution:&lt;/b&gt; Prioritize phishing-resistant methods whenever possible, such as &lt;a target="_blank" href="https://fidoalliance.org/specifications/" rel="noopener"&gt;FIDO2 security keys&lt;/a&gt;, &lt;a href="https://www.techtarget.com/whatis/definition/passkey"&gt;passkeys&lt;/a&gt;, &lt;a href="https://www.techtarget.com/searchenterprisedesktop/tip/How-to-set-up-Windows-Hello-for-Business-step-by-step"&gt;Windows Hello for Business&lt;/a&gt; or platform authenticators built into endpoint devices. These are much more difficult for attackers to outmaneuver.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Mistake #3: Giving in to MFA fatigue"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Mistake #3: Giving in to MFA fatigue&lt;/h2&gt;
 &lt;p&gt;&lt;b&gt;Problem:&lt;/b&gt; Push notifications made MFA easier for users, but they also created an opportunity for attackers. In an &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-solve-MFA-challenges-SIM-swapping-and-MFA-fatigue"&gt;MFA fatigue attack&lt;/a&gt;, malicious hackers bombard users with repeated approval requests, assuming that someone will eventually tap "Approve" simply to make the notifications stop. Combined with convincing social engineering, this technique successfully bypassed MFA in several &lt;a target="_blank" href="https://www.cybersecuritydive.com/news/mfa-multi-factor-authentication-cisco-talos-cyber/719254/" rel="noopener"&gt;high-profile breaches in recent years&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Solution:&lt;/b&gt; Many modern authentication platforms have implemented number matching, location awareness and additional verification steps. These features can significantly reduce accidental approvals. Enable them wherever possible.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Mistake #4: Neglecting session security"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Mistake #4: Neglecting session security&lt;/h2&gt;
 &lt;p&gt;&lt;b&gt;Problem:&lt;/b&gt; Many organizations focus heavily on the login process but pay far less attention to what happens afterward. If an attacker steals an authenticated browser session or access token, they might not need to authenticate again at all. Instead of passwords, nefarious actors increasingly target session cookies, OAuth tokens and browser credentials.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Solution:&lt;/b&gt; Most security teams now recognize that identity protection needs to extend beyond initial MFA entry. Conditional-access policies, device trust, session expiration, continuous-access evaluation and token protection all help reduce the risk of &lt;a href="https://www.techtarget.com/searchsecurity/tip/Common-browser-attacks-and-how-to-prevent-them"&gt;session hijacking&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Mistake #5: Forgetting about privileged accounts"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Mistake #5: Forgetting about privileged accounts&lt;/h2&gt;
 &lt;p&gt;&lt;b&gt;Problem:&lt;/b&gt; It's understood that admin accounts deserve stronger protection than standard users, though security teams don't always put this into practice. If attackers compromise some types of privileged accounts, they might be able to disable MFA controls for selected targets or everyone in an organization.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Solution:&lt;/b&gt; Global administrators for SaaS platforms, cloud infrastructure administrators, domain administrators and privileged help desk accounts need the strongest available authentication methods. Hardware security keys, &lt;a href="https://www.techtarget.com/searchsecurity/tip/Traditional-MFA-isnt-enough-phishing-resistant-MFA-is-key"&gt;phishing-resistant MFA&lt;/a&gt;, dedicated administrative workstations and privileged access management (PAM) tools significantly reduce risk.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Mistake #6: Treating MFA as a one-time project"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Mistake #6: Treating MFA as a one-time project&lt;/h2&gt;
 &lt;p&gt;&lt;b&gt;Problem:&lt;/b&gt; Organizations often invest heavily in an MFA rollout and then move on to the next initiative. Unfortunately, environments don't stand still. New SaaS applications are introduced, business acquisitions occur, legacy systems remain in production, developers create service accounts and so on. It's not uncommon for exceptions to accumulate.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Solution:&lt;/b&gt; Conduct periodic reviews that ask:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Which users are still exempt from MFA?&lt;/li&gt; 
  &lt;li&gt;Which applications don't support modern authentication?&lt;/li&gt; 
  &lt;li&gt;Are stronger authentication methods available?&lt;/li&gt; 
  &lt;li&gt;Have risky authentication patterns changed?&lt;/li&gt; 
  &lt;li&gt;Are conditional access policies still aligned with business requirements?&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Treat MFA as an operational security program rather than a completed project.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Mistake #7: Preparing for AI-assisted social engineering"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Mistake #7: Preparing for AI-assisted social engineering&lt;/h2&gt;
 &lt;p&gt;&lt;b&gt;Problem: &lt;/b&gt;Attackers are getting better at persuading users to approve authentication requests, often aided by AI. &lt;a href="https://www.techtarget.com/searchsecurity/tip/Generative-AI-is-making-phishing-attacks-more-dangerous"&gt;AI-generated phishing emails&lt;/a&gt;, realistic voice cloning and other deepfakes, as well as highly personalized social engineering, make it easier to trick users into approving MFA prompts or sharing authentication codes.&lt;/p&gt;
 &lt;p&gt;&lt;b&gt;Solution:&lt;/b&gt; These problems make user education even more important. Employees should understand that security teams, help desks or vendors should never ask them to approve an unexpected MFA request or provide a verification code over the phone. To reinforce this, frequently update &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecurity-employee-training-How-to-build-a-solid-plan"&gt;awareness training&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="MFA is a foundation, not a finish line"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;MFA is a foundation, not a finish line&lt;/h2&gt;
 &lt;p&gt;Despite these challenges, MFA remains one of the most effective security controls available. Organizations should view MFA as one component of a broader identity security strategy that includes phishing-resistant authentication, conditional access, PAM, session protection, continuous monitoring and &lt;a href="https://www.techtarget.com/searchsecurity/answer/How-to-conduct-a-periodic-user-access-review-for-account-privileges"&gt;regular policy reviews&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;When implemented thoughtfully and maintained over time, MFA stops countless attacks every day. The organizations that get the most value from MFA are the ones that recognize it's not a "final state" for authentication. Instead, it's one of the core foundations of a stronger identity security program.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Dave Shackleford is founder and principal consultant at Voodoo Security, as well as a SANS analyst, instructor and course author, and GIAC technical director.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Attackers have adapted their techniques to circumvent an organization's MFA controls. When they succeed, it's usually because MFA wasn't properly set up or managed.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a296619547.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/tip/Common-MFA-mistakes-and-how-to-fix-them</link>
            <pubDate>Thu, 09 Jul 2026 16:08:00 GMT</pubDate>
            <title>Common MFA mistakes -- and how to fix them</title>
        </item>
        <item>
            <body>&lt;p&gt;Effective threat modeling -- where security architects review system design, enumerate threats and mitigations, validate controls and map the attack surface of a system -- is critical to secure software but can be complex and time-consuming.&lt;/p&gt; 
&lt;p&gt;This guidance explains how AI helps security architects streamline threat modeling, making it more actionable and impactful while keeping strong security analysis integral to the software development lifecycle.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Threat modeling methodologies"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Threat modeling methodologies&lt;/h2&gt;
 &lt;p&gt;Threat modeling is a core part of the &lt;a href="https://www.techtarget.com/whatis/definition/security-by-design"&gt;secure-by-design&lt;/a&gt; approach to system development. It is used on applications, networks, devices, &lt;a href="https://www.techtarget.com/searchsecurity/feature/What-are-cloud-containers-and-how-do-they-work"&gt;containers&lt;/a&gt;, AI-based applications, or any hardware or software systems. The primary goal of threat modeling is to address any exploitable exposures in a system.&lt;/p&gt;
 &lt;p&gt;Formal methodologies for threat modeling form the basis of an overall program. The first steps to adoption include obtaining &lt;a href="https://www.techtarget.com/searchsecurity/post/4-tips-to-help-CISOs-get-more-C-suite-cybersecurity-buy-in"&gt;organizational support&lt;/a&gt; and clearly defining the problems AI will address. Accomplish this with baseline metrics that identify challenges in the absence of a threat modeling program. With that data in hand, communicate issues to leadership that stall the application development lifecycle.&lt;/p&gt;
 &lt;p&gt;After achieving organizational buy-in, begin adopting &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-secure-AI-infrastructure-Best-practices"&gt;AI tools&lt;/a&gt; to accelerate the manual processes on which traditional threat modeling relies. Many AI tools address the repetitive tasks associated with threat modeling, including:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;System design review.&lt;/li&gt; 
  &lt;li&gt;Enumerating threats and mitigations.&lt;/li&gt; 
  &lt;li&gt;Control validation.&lt;/li&gt; 
  &lt;li&gt;Data flow identification.&lt;/li&gt; 
  &lt;li&gt;System component mapping.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;For instance, AI could access application code, link code to runtime components and create diagrams of application flows between components. From there, it could enumerate threats and provide mitigations using language from standard &lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-threat-modeling-tools-plus-features-to-look-for"&gt;threat modeling frameworks&lt;/a&gt; such as STRIDE and LINDDUN.&lt;/p&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="AI automation: The human factor"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;AI automation: The human factor&lt;/h2&gt;
 &lt;p&gt;Although AI can help security architects build a complete understanding of an application, the process is incomplete without human oversight. The AI tools built into existing development and security workflows should comply with the organization's risk profile and system architecture. It is vital to augment AI rollout with &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecurity-employee-training-How-to-build-a-solid-plan"&gt;training&lt;/a&gt;; security architects and threat modelers must have a nuanced understanding of all AI-enhanced applications.&lt;/p&gt;
 &lt;p&gt;Security architects should also assemble cross-functional threat modeling teams comprising technical and business profiles. This practice ensures the threat modeling process considers both technical aspects and business risk.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="Overcoming obstacles with AI"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Overcoming obstacles with AI&lt;/h2&gt;
 &lt;p&gt;While AI can address many challenges, gaps can arise. Incomplete application understanding, for example, is an issue that affects many organizations. In the absence of detailed documentation, threat modelers typically have lapses related to things such as data flows between the constituent components, external dependencies, trust boundaries and runtime behavior.&lt;/p&gt;
 &lt;p&gt;Organizations experiencing such obstacles can use AI to generate detailed documentation, workflows and application architecture. &lt;a href="https://www.techtarget.com/searchenterpriseai/definition/natural-language-processing-NLP"&gt;Natural language&lt;/a&gt; understanding, together with semantic analysis, can be used to interpret documentation. AI models use transformer-based architectures and techniques to identify missing parts of an application and understand components such as architecture diagrams and code comments.&lt;/p&gt;
 &lt;p&gt;Tools that are multimodal fusion -- meaning they integrate information from multiple data types to create more comprehensive AI models -- also help address gaps by building a complete picture of an application when information is missing. Additionally, graphical neural networks can reconstruct missing components of architectural documentation through analysis of source code structure dependencies and existing documentation.&lt;/p&gt;
 &lt;p&gt;AI enables security architects to overcome common threat modeling challenges, but there are limitations. With the right approach, security leaders can use AI tools to automate many manual processes, making threat modeling faster and more scalable on an organizational level.&lt;/p&gt;
 &lt;p&gt;&lt;a href="https://www.gartner.com/en/experts/william-dupre" target="_blank" rel="noopener"&gt;&lt;i&gt;William Dupre&lt;/i&gt;&lt;/a&gt;&lt;i&gt; is an analyst in the Gartner for Technical Professionals Security and Risk Management Strategies team. Dupre and other Gartner analysts will present the latest insights for security and risk management leaders at the Gartner Security &amp;amp; Risk Management Summits, taking place July 22-24 in&lt;/i&gt;&lt;a href="https://www.gartner.com/en/conferences/apac/security-risk-management-japan"&gt;&lt;i&gt; &lt;/i&gt;&lt;/a&gt;&lt;a href="https://www.gartner.com/en/conferences/apac/security-risk-management-japan" target="_blank" rel="noopener"&gt;&lt;i&gt;Tokyo&lt;/i&gt;&lt;/a&gt;&lt;i&gt;, August 4-5 in&lt;/i&gt;&lt;a href="https://www.gartner.com/en/conferences/la/security-risk-management-brazil"&gt;&lt;i&gt; &lt;/i&gt;&lt;/a&gt;&lt;a href="https://www.gartner.com/en/conferences/la/security-risk-management-brazil" target="_blank" rel="noopener"&gt;&lt;i&gt;Sao Paulo&lt;/i&gt;&lt;/a&gt;&lt;i&gt; and September 22-24 in&lt;/i&gt;&lt;a href="https://www.gartner.com/en/conferences/emea/security-risk-management-uk"&gt;&lt;i&gt; &lt;/i&gt;&lt;/a&gt;&lt;a href="https://www.gartner.com/en/conferences/emea/security-risk-management-uk" target="_blank" rel="noopener"&gt;&lt;i&gt;London&lt;/i&gt;&lt;/a&gt;&lt;i&gt;. Follow news and updates from the conferences on &lt;/i&gt;&lt;a href="https://x.com/Gartner_inc" target="_blank" rel="noopener"&gt;&lt;i&gt;X&lt;/i&gt;&lt;/a&gt;&lt;i&gt; and &lt;/i&gt;&lt;a href="https://www.linkedin.com/showcase/gartner-for-it-leaders" target="_blank" rel="noopener"&gt;&lt;i&gt;LinkedIn&lt;/i&gt;&lt;/a&gt;&lt;i&gt; using #GartnerSEC.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>AI tools streamline threat modeling by automating repetitive tasks and helping security teams prioritize risks more effectively. But human oversight is still critical.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/ai_g1182183209.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/tip/How-to-operationalize-threat-modeling-with-AI</link>
            <pubDate>Thu, 09 Jul 2026 08:30:00 GMT</pubDate>
            <title>How to operationalize threat modeling with AI</title>
        </item>
        <item>
            <body>&lt;p&gt;The cybersecurity talent crisis has moved from a simple numbers problem to a fundamental mismatch between what organizations need and what the workforce can deliver.&lt;/p&gt; 
&lt;p&gt;While 87% of organizations plan to expand their security teams this year, according to Fortinet Training Institute's "2026 Cybersecurity Skills Gap" &lt;a href="https://www.fortinet.com/content/dam/fortinet/assets/reports/2026-cybersecurity-skills-gap-report.pdf" target="_blank" rel="noopener"&gt;report&lt;/a&gt;, the CyberSeek &lt;a href="https://www.cyberseek.org/heatmap.html" target="_blank" rel="noopener"&gt;online data tool&lt;/a&gt; found that there are only enough available cybersecurity workers in the U.S. to meet 74% of employer demand.&lt;/p&gt; 
&lt;p&gt;As problematic as that data is, it doesn't encapsulate the full extent of the workforce challenge. Cybersecurity leaders are finding not only a shortfall in the number of cybersecurity professionals, but also a significant misalignment between the &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecurity-skills-gap-Why-it-exists-and-how-to-address-it"&gt;available skills in the market&lt;/a&gt; and those needed in enterprise cybersecurity departments.&lt;/p&gt; 
&lt;p&gt;Researchers from SANS Institute and GIAC called it "a widening skills gap that organizations struggle to close, even as they increasingly recognize that having the right abilities matters more than simply adding head count," in the "2026 Cybersecurity Workforce Research Report."&lt;/p&gt; 
&lt;p&gt;"The problem isn't a shortage in head count. We're never going to get the numbers we want to get. It's really more about getting the needed skills," said Brian Correia, director of global cyber workforce strategy and engagement at SANS.&lt;/p&gt; 
&lt;p&gt;CISOs must &lt;a href="https://www.techtarget.com/searchcio/feature/How-to-attract-tech-talent-The-essentials"&gt;modernize their approach&lt;/a&gt; to recruiting workers. This involves moving away from a conventional search strategy and adopting one that creates multiple talent pipelines and emphasizes workforce development to ensure hires continuously learn the latest skills.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="The impact of the security talent, skills gaps"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;The impact of the security talent, skills gaps&lt;/h2&gt;
 &lt;p&gt;Staffing challenges affect an organization's cybersecurity posture. Recent &lt;a href="https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study" target="_blank" rel="noopener"&gt;research&lt;/a&gt; from ISC2 found that 88% of organizations experienced at least one significant cybersecurity event due to cybersecurity skills shortages.&lt;/p&gt;
 &lt;p&gt;Such findings are particularly troublesome because the increasing use of AI -- both &lt;a href="https://www.techtarget.com/searchenterpriseai/tip/Evaluate-the-risks-and-benefits-of-AI-in-cybersecurity"&gt;in SOCs&lt;/a&gt; and &lt;a href="https://www.techtarget.com/searchsecurity/tip/Generative-AI-is-making-phishing-attacks-more-dangerous"&gt;by malicious hackers&lt;/a&gt; -- is rapidly changing the types of skills needed by security professionals, putting organizations at even greater risk for incidents as they fall further behind in hiring.&lt;/p&gt;
 &lt;p&gt;"There are different skill sets needed in security due to AI," said Vikram Desai, senior managing director of cyber strategy, risk and architecture at professional services firm Accenture. "But people don't naturally have them. And very few organizations have training programs in place to help bridge this gap, so there is a giant gap between what is needed and the skills that job seekers present, and we [mistakenly] expect it to resolve itself."&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Legacy practices hurt hiring"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Legacy practices hurt hiring&lt;/h2&gt;
 &lt;p&gt;Desai called the belief that cybersecurity professionals should come fully skilled for existing positions a "legacy mindset." And it's not the only one -- plenty of other legacy recruitment strategies make it challenging for today's CISOs to fill open roles.&lt;/p&gt;
 &lt;p&gt;For instance, the blanket requirement for candidates to hold a bachelor's or master's degree is, according to Shawn Murray, former president of the ISSA, "an old-fashioned approach that's just not reasonable anymore." Moreover, he said security skills are evolving so quickly that a degree is no guarantee that a candidate has the skills needed at the time of hiring.&lt;/p&gt;
 &lt;p&gt;Others criticized conventional recruitment strategies that put HR teams or recruiting firms in charge of defining candidate requirements and screening. These processes lead to an unrealistically long list of skills and a misalignment with what the CISO actually needs from a new hire.&lt;/p&gt;
 &lt;p&gt;Experts said requiring candidates to have prior experience specifically in cybersecurity or IT is also unduly limiting. Murray noted that outdated recruitment and hiring practices can cause a chain reaction in a security organization, where understaffing that results from these practices puts more pressure on existing workers, who then experience burnout and quit, further depleting the team.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="A new hiring paradigm"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;A new hiring paradigm&lt;/h2&gt;
 &lt;p&gt;Researchers and CISO advisers identified the following hiring strategies that help CISOs find employees with the cybersecurity skills they need.&lt;/p&gt;
 &lt;h3&gt;Looking outside security&lt;/h3&gt;
 &lt;p&gt;Desai explained that workers of all kinds now have training in risk and security that, when coupled with a business background, can make them invaluable additions to a security team. "We're seeing leading CISOs shift to hiring cyber-savvy people who also know the business," he said.&lt;/p&gt;
 &lt;h3&gt;CISO-led hiring&lt;/h3&gt;
 &lt;p&gt;Another modern hiring practice involves the CISO leading recruitment and retention strategies, Murray said. He found that CISOs who identify the &lt;a href="https://www.techtarget.com/searchsecurity/tip/10-must-have-cybersecurity-skills-for-career-success"&gt;specific skills they need&lt;/a&gt; to fulfill their strategic missions, and then work with HR and recruiters to find candidates, are most successful.&lt;/p&gt;
 &lt;h3&gt;Community partnership&lt;/h3&gt;
 &lt;p&gt;Murray shared that leading CISOs also recruit from and develop partnerships with community colleges and training centers, recognizing that those institutions usually offer hands-on experience to students, making them ready to perform on day one at the job.&lt;/p&gt;
 &lt;h3&gt;Retention&lt;/h3&gt;
 &lt;p&gt;Good recruiting practices should be part of an overall talent strategy that includes retention. By ensuring people with the right set of skills are on staff, CISOs can build a bench of future security talent, avoiding the costs and training involved with new hires.&lt;/p&gt;
 &lt;h3&gt;Hiring for technical skills&lt;/h3&gt;
 &lt;p&gt;It's unlikely any candidate will have all the needed skills. Correia said CISOs shouldn't hold out for the perfect fit but rather seek candidates who demonstrate what he calls "technical capability," defined as meeting about 80% of the job's technical requirements. That approach, along with screening applicants for cultural fit and an aptitude for learning, enables CISOs to build teams for today and tomorrow.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Mary K. Pratt is an award-winning freelance journalist with a focus on covering enterprise IT and cybersecurity management.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>The cybersecurity talent gap won't be solved by head count alone. CISOs need to fundamentally rethink how they recruit, how they retain talent and what skills they really need.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/collab_g1227412970.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/tip/CISOs-guide-to-hiring-for-the-right-cybersecurity-skills</link>
            <pubDate>Wed, 08 Jul 2026 13:17:00 GMT</pubDate>
            <title>CISO's guide to hiring for the right cybersecurity skills</title>
        </item>
        <item>
            <body>&lt;p&gt;The latest cyberattack headlines leave security leaders asking a critical question: Does an AI agent's successful execution of an end-to-end ransomware attack signal a fundamental shift in threat response strategies, or does it simply underscore the enduring importance of cybersecurity fundamentals?&lt;/p&gt; 
&lt;p&gt;The Sysdig Threat Research Team last week identified what it claims is the first case of a cyberattack carried out by AI from start to finish. Dubbed &lt;i&gt;JadePuffer&lt;/i&gt;, the agentic threat actor gained initial access by exploiting a vulnerability in Langflow, a low-code AI builder for agentic and &lt;a href="https://www.techtarget.com/searchenterpriseai/definition/retrieval-augmented-generation"&gt;RAG&lt;/a&gt; applications. Sysdig said the attack was adaptive and fully automated, harvested credentials and passwords, and ultimately encrypted a production database and demanded a ransom.&lt;/p&gt; 
&lt;p&gt;"None of the individual techniques were novel or sophisticated," Michael Clark, director of threat research at Sysdig, wrote in a &lt;a target="_blank" href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion" rel="noopener"&gt;blog&lt;/a&gt;. "What is notable, however, is that an AI model strung them together into a complete ransomware operation against neglected internet-facing infrastructure."&lt;/p&gt; 
&lt;p&gt;Also notable is how the LLM could change course when it ran into a roadblock. At one point, "it went from a failed login to a working fix in 31 seconds," Clark wrote.&lt;/p&gt; 
&lt;p&gt;Interestingly, the ransom note contained a payment address commonly used as an example in bitcoin developer documentation. According to Clark, that could either mean that the agent hallucinated the address based on the documentation, or that the operator configured the agent using a real cryptowallet address -- one that, coincidentally, also appears in documentation. The AES key was also never saved, meaning the victim wouldn't have been able to recover the encrypted files even if they &lt;a href="https://www.techtarget.com/searchsecurity/tip/Should-companies-pay-ransomware-and-is-it-illegal-to"&gt;paid the ransom&lt;/a&gt;.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="AI doesn't change the playbook -- it just speeds up the game"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;AI doesn't change the playbook -- it just speeds up the game&lt;/h2&gt;
 &lt;p&gt;Chester Wisniewski, director and global field CISO at Sophos, told TechTarget Cybersecurity that the significance of this &lt;a href="https://www.techtarget.com/searchsecurity/feature/AI-powered-attacks-What-CISOSs-need-to-know-now"&gt;AI-driven attack&lt;/a&gt; lies not in changing how attackers operate, but in how quickly security leaders must respond.&lt;/p&gt;
 &lt;p&gt;"AI doesn't fundamentally change attacker behavior, but it has a big impact on speed and scale," he said. "The AI tried some things, failed and then retried. This means these attacks are noisy, but fast. If you can listen for the noise, you need to immediately action defenses to prevent further harm."&lt;/p&gt;
 &lt;p&gt;That rapid response doesn't change the entire playbook for cybersecurity leaders, however. While the use of an AI agent accelerated this attack, the fundamentals of defense remain much the same as in human-led attacks: Identify exposed systems, quickly patch vulnerabilities, secure credentials, and ensure security teams can detect and respond before an intrusion reaches critical systems.&lt;/p&gt;
 &lt;p&gt;John Bambenek, president of Bambenek Consulting, agreed that the most important lesson from the JadePuffer attack isn't the use of AI itself, but that threat actors are using &lt;a href="https://www.techtarget.com/searchsecurity/feature/The-AI-vulnerability-storm-is-here-Is-your-security-program-ready"&gt;new capabilities to exploit well-known vulnerabilities&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;"The key detail is that the vulnerability was already known and likely had enough detail to weaponize an exploit," Bambenek said. "AI may make things faster, but all it's exposing is that fundamentally much of our tech stack has always been waiting to be owned."&amp;nbsp;&lt;/p&gt;
 &lt;p&gt;Sysdig anticipates more such attacks as agentic tooling matures. Expect the first targets to be familiar weak spots -- internet-exposed applications, poorly secured configurations and &lt;a href="https://www.computerweekly.com/feature/How-IAM-providers-are-preparing-for-agentic-AI"&gt;administrative access points&lt;/a&gt; -- the same ones that malicious hackers have long exploited.&lt;/p&gt;
 &lt;p&gt;"Old vulnerabilities are being automated," Clark wrote. "Agents make spraying the entire historical vulnerability catalog effectively free, so the long tail of unpatched systems becomes more exposed, not less."&lt;/p&gt;
 &lt;p&gt;The result is a familiar security challenge at speed. Organizations have long faced attacks that target unpatched systems and exposed services, but AI-assisted campaigns reduce the time security teams have to respond.&lt;/p&gt;
 &lt;p&gt;"Around-the-clock monitoring is essential, but not enough. You need around-the-clock ability to react quickly," Wisniewski said.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Craig Galbraith is the founder and owner of Galbraith Multimedia, an independent journalism company that provides writing, editing, video hosting, podcasting, onstage presentation and consulting services to the technology industry.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>An AI model's autonomous execution of a complete ransomware operation marks a new era. Learn why experts say rapid detection and response, not revolutionary defenses, are key.</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/Ransomware_hero.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/news/366645613/First-fully-agentic-ransomware-attack-sparks-readiness-concerns</link>
            <pubDate>Wed, 08 Jul 2026 10:00:00 GMT</pubDate>
            <title>First fully agentic ransomware attack sparks readiness concerns</title>
        </item>
        <item>
            <body>&lt;p&gt;Whether hosted in-house or in the cloud, the web browser serves as the gateway to most enterprise work, making it a crucial consideration in any enterprise security strategy.&lt;/p&gt; 
&lt;p&gt;The current AI frenzy puts an even brighter spotlight on browser security. Employees access most AI tools through a browser, making an already tempting target even more inviting. Additionally, AI expands the scope of what users accomplish via browser sessions -- making it even more useful for bad actors to compromise those sessions. And through &lt;a href="https://www.techtarget.com/searchenterpriseai/tip/How-the-Model-Context-Protocol-simplifies-AI-development"&gt;MCP integrations&lt;/a&gt; and the like, AI is also increasing the reach of browser-based tools into the environment, thereby expanding the scope of the potential damage from browser breaches.&lt;/p&gt; 
&lt;p&gt;Malicious actors have been exploiting browser vulnerabilities for years, a problem that is only becoming more challenging due to the rising use of AI to probe software for vulnerabilities more effectively than ever. It is clear that browser security has never been as threatened as it is now.&lt;/p&gt; 
&lt;p&gt;In this moment of renewed attention to browser security and the risks of it failing, CISOs face two options for improving browser security: deploying secure enterprise browsers and deploying browser security plugins.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Pros and cons of secure enterprise browsers"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Pros and cons of secure enterprise browsers&lt;/h2&gt;
 &lt;p&gt;A secure enterprise browser is a managed application that is fully under the control of enterprise IT staff. Admins can implement security policies directly and insert controls into the browsing session that would normally be provided by network appliances or cloud services, including URL filtering, application firewalling and data loss prevention tactics.&lt;/p&gt;
 &lt;p&gt;Security teams can enforce rules for content filtering, prevent the use of unsafe sites and discourage personal browsing through the managed platform. At the same time, a fully managed browser provides rich monitoring of web use.&lt;/p&gt;
 &lt;p&gt;Advantages of secure enterprise browsers include:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Consistent and universal enforcement of centrally defined policies.&lt;/li&gt; 
  &lt;li&gt;Strong isolation models, which deliver stricter separation of processes and sessions, and better protection of platforms from web sessions and of tabs from each other.&lt;/li&gt; 
  &lt;li&gt;Easier separation of personal browsing from corporate browsing.&lt;/li&gt; 
  &lt;li&gt;Access to rich data on end-user experience and normal usage patterns, which boosts &lt;a href="https://www.techtarget.com/searchsecurity/tip/Top-10-UEBA-enterprise-use-cases"&gt;behavioral threat analysis&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;Reduced need for virtual desktop infrastructure (VDI) because staff BYOD browsing is less of a risk, it is easier to control contractor and third-party access to enterprise systems, and it enables simpler onboarding of staff from acquired companies or after a merger.&lt;/li&gt; 
  &lt;li&gt;Traction on &lt;a href="https://www.techtarget.com/searchsecurity/definition/privileged-access-management-PAM"&gt;privileged access management&lt;/a&gt; and privilege use.&lt;/li&gt; 
  &lt;li&gt;A vantage point where teams can examine data for leak potential before end-to-end encryption in an end-to-end tunnel, reducing load on firewall-based, man-in-the-middle style decryption.&lt;/li&gt; 
  &lt;li&gt;Strict control of extensions, which keeps the browser threat surface as small as possible, although some conventional browsers inside managed desktops and VDI environments can control this.&lt;/li&gt; 
  &lt;li&gt;Central management of the web UI, which provides more consistency across users within and among departments, such as everyone having the same core bookmarks.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Enterprise-secured browsers have the following disadvantages:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Cost, which is notable because previously a browser would have been free.&lt;/li&gt; 
  &lt;li&gt;Requires careful deployment and maintenance, as well as some end-user training.&lt;/li&gt; 
  &lt;li&gt;Unfamiliarity, which means employees need to learn and adapt to a new UI.&lt;/li&gt; 
  &lt;li&gt;Some sites might not work with the new browser.&lt;/li&gt; 
  &lt;li&gt;Some existing workflows might break because the secure platform gets in the way, which could result in interruptions and remediation costs, although the outcome is a more secure process.&lt;/li&gt; 
  &lt;li&gt;Vendor lock-in is possible because of the high cost of switching.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="Pros and cons of browser security plugins"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Pros and cons of browser security plugins&lt;/h2&gt;
 &lt;p&gt;Browser plugins are the standard method of adding function to a browser. Adding a standardized plugin just for security is straightforward. In some cases, IT can enforce the use of an extension and control its configuration centrally. While IT can't exert full control using a plugin, teams can make user browsing significantly more secure through additional phishing protection and URL filtering tools.&lt;/p&gt;
 &lt;p&gt;Advantages of using security plugins include:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Users retain their browser and its familiar UI, as long as a version of the desired plugin is available for that browser.&lt;/li&gt; 
  &lt;li&gt;Quicker, lower-impact, lower-friction deployment.&lt;/li&gt; 
  &lt;li&gt;Reduced chance that a website won't work with the secured platform.&lt;/li&gt; 
  &lt;li&gt;Reduced risk of broken processes and workflows.&lt;/li&gt; 
  &lt;li&gt;Low or no added software cost.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Disadvantages of the plugin approach include:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Inability to impose the same level of security as with a secure browser.&lt;/li&gt; 
  &lt;li&gt;Less security visibility than with an enterprise browser.&lt;/li&gt; 
  &lt;li&gt;A dependence on -- and to an extent working against -- the security model of the underlying browser since consumer browsers are not built to prevent users from adding, disabling or uninstalling plugins.&lt;/li&gt; 
  &lt;li&gt;Requires monitoring the compatibility of the extension with every update to the browser and dealing with updates that result in incompatibility.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Organizations that can't justify the expense of a proper rollout of a secure browser should focus on adding security extensions to improve browser security as much as possible. Likewise, organizations with a strong emphasis on user control of the user experience can implement extensions to raise the bar on phishing and malware protection.&lt;/p&gt;
&lt;/section&gt;       
&lt;section class="section main-article-chapter" data-menu-title="How CISOs should decide which is right for their organizations"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How CISOs should decide which is right for their organizations&lt;/h2&gt;
 &lt;p&gt;A secure enterprise browser and browser plugins can both improve security, but the right path depends on how a particular organization balances risk and needs with costs and friction.&lt;/p&gt;
 &lt;p&gt;Deploying a secure browser delivers better protection than an extension. If an organization decides it needs to achieve that level of security, it should find the resources to pay for the transition.&lt;/p&gt;
 &lt;p&gt;Organizations that want higher levels of security must &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecurity-budget-justification-A-guide-for-CISOs"&gt;justify the costs&lt;/a&gt; -- in time and dollars -- reduce the risk. If browsers are a major source of vulnerabilities in the organization's threat surface, that is a straightforward justification. Companies pushing &lt;a href="https://www.techtarget.com/searchenterpriseai/tip/How-to-prepare-your-business-for-agentic-AI-adoption"&gt;agentic AI adoption&lt;/a&gt; also have a clear business case.&lt;/p&gt;
 &lt;p&gt;It is also worth looking at the resources currently devoted to shoring up web security for insecure browsers. For example, CISOs could redirect money spent on appliances and services to funding a browser security upgrade.&lt;/p&gt;
 &lt;p&gt;If an organization's user experience is already locked down through VDI or desktop as a service, for example, then a secure browser would reduce the need for that other setup without making a huge difference to user experience. But, if the user experience is meant to be highly individualized and user-controlled, an extension might be the only way to improve security without sacrificing that.&lt;/p&gt;
 &lt;p&gt;And, if the budget is too tight for a secure browser rollout, a push for universal installation of well-configured security extensions makes sense.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;John Burke is CTO and a research analyst at Nemertes Research. Burke joined Nemertes in 2005 with nearly two decades of technology experience. He has worked at all levels of IT, including as an end-user support specialist, programmer, system administrator, database specialist, network administrator, network architect and systems architect.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Malicious actors have long targeted and exploited browser vulnerabilities. The widespread adoption of AI increases the risk, forcing CISOs to reevaluate browser security options.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_g1192070289.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/tip/Evaluating-secure-enterprise-browsers-vs-security-plugins</link>
            <pubDate>Tue, 07 Jul 2026 15:49:00 GMT</pubDate>
            <title>Evaluating secure enterprise browsers vs. security plugins</title>
        </item>
        <item>
            <body>&lt;p&gt;Emerging frontier AI models, such as Anthropic's Claude Mythos, are dramatically accelerating vulnerability discovery and exploitation, shrinking the window between a software flaw's discovery and its weaponization to mere hours.&lt;/p&gt; 
&lt;p&gt;In just a few months, Mythos has discovered &lt;a href="https://www.techtarget.com/searchsecurity/news/366643606/First-month-of-Mythos-Preview-testing-exposes-10K-flaws"&gt;thousands of critical flaws&lt;/a&gt; across every major OS and browser, creating working exploits without human guidance and enabling autonomous attacks at speed and scale, according to the Cloud Security Alliance (CSA) &lt;a target="_blank" href="https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosreadyv95.pdf" rel="noopener"&gt;report&lt;/a&gt;, "The Vulnerability Storm: Building a 'Mythos-ready' Security Program."&lt;/p&gt; 
&lt;p&gt;The report, co-authored with SANS, OWASP and more than a dozen CISOs, argues that organizations clinging to pre-AI assumptions about patch cycles, exploit timelines and incident frequency are operating with an already outdated risk model.&lt;/p&gt; 
&lt;p&gt;For CISOs and security teams, the trend demands a fundamental rethink of how vulnerabilities are prioritized, triaged and remediated.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Fight AI with AI"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Fight AI with AI&lt;/h2&gt;
 &lt;p&gt;The CSA report authors recommended that organizations deploy their own AI to defend their operations and strengthen their security architecture to slow attackers and limit consequential damage.&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Automate vulnerability management.&lt;/b&gt; Use LLM-powered agents to find and fix vulnerabilities in code, pipelines and dependencies and to move toward a fully automated vulnerability review process embedded in CI/CD pipelines.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Automate incident response.&lt;/b&gt; Automate incident response processes by preauthorizing containment actions and building playbooks that execute without waiting for human sign-off at every step.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Strengthen security basics.&lt;/b&gt; Enforce basic security controls -- network segmentation, egress filtering, phishing-resistant MFA, zero-trust architectures -- that limit damage and buy critical response time when an attack succeeds.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Rebuild risk models.&lt;/b&gt; Update risk models and &lt;a href="https://www.techtarget.com/searchcio/feature/From-IT-to-ROI-Framing-cybersecurity-for-the-board"&gt;board-level reporting&lt;/a&gt; to reflect the new threat environment. Organizations that still base response times and patch windows on pre-AI assumptions risk distorting their actual exposures and underfunding controls that matter most.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="A to-do list for CISOs"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;A to-do list for CISOs&lt;/h2&gt;
 &lt;p&gt;Rich Mogull, chief analyst for CSA and one of the report's authors, said CISOs should build security programs around the expectation that AI-enabled attackers can discover new vulnerabilities, create near-instant exploits and &lt;a href="https://www.techtarget.com/searchsecurity/feature/AI-powered-attacks-What-CISOSs-need-to-know-now"&gt;automate complex, multistage attacks&lt;/a&gt; without requiring any specialized skills.&lt;/p&gt;
 &lt;p&gt;"Minimum viable resilience means an organization expects constant, advanced attacks, often using zero days, and uses a mixture of security boundaries, more effective incident detection and response and faster patching to defend," Mogull said. "It also means fully integrating these same technologies into software development so the flaws attackers rely on are more likely to be remediated before software is ever released."&lt;/p&gt;
 &lt;h3&gt;Short-term priorities&lt;/h3&gt;
 &lt;p&gt;CISOs should prepare for a flood of patches addressing AI-discovered vulnerabilities that attackers could exploit within hours. Given the sheer number of discoveries, organizations won't be able to patch their way out of the crisis. Instead, they must focus on containing fallout as much as possible.&lt;/p&gt;
 &lt;p&gt;"Inventory and identify your most critical applications," Mogull said. "Then start segregating them and adding security boundaries so an attacker doesn't get the entire stack with only one flaw."&lt;/p&gt;
 &lt;h3&gt;Integrate AI into development&lt;/h3&gt;
 &lt;p&gt;Use AI agents for code review and align that process with existing software development lifecycle tools, such as static application security testing, dynamic application security testing and software composition analysis.&lt;/p&gt;
 &lt;p&gt;"Most organizations can even start scans in parallel with their existing pipelines if they can't get it inserted into the pipeline," Mogull said. "Be smart and use multiple agents to validate findings and not flood your own developers."&lt;/p&gt;
 &lt;h3&gt;Empower the SOC with AI&lt;/h3&gt;
 &lt;p&gt;"This is one area AI is very well suited for, and we've seen as organizations integrate AI into the SOC, they are getting some great results," Mogull said.&lt;/p&gt;
&lt;/section&gt;           
&lt;section class="section main-article-chapter" data-menu-title="A mindset shift, not just a tech upgrade"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;A mindset shift, not just a tech upgrade&lt;/h2&gt;
 &lt;p&gt;Andrew Braunberg, principal analyst at Omdia, a division of Informa TechTarget, said the CSA report highlights how important it is for CISOs and other security leaders to reassess their strategies.&lt;/p&gt;
 &lt;p&gt;"We are moving to an era of exploits on demand, basically," he said, adding that agentic AI lowers the bar for less sophisticated threat actors, increasing the persistence and cadence of attacks.&lt;/p&gt;
 &lt;p&gt;"The entire C-suite is going to need to get way past their traditional comfort zone with the idea of autonomous remediation. We are moving to a machine versus machine environment, and folks are going to have to readjust their risk tolerances one way or another," Braunberg said.&lt;/p&gt;
 &lt;h3&gt;Proceed with caution&lt;/h3&gt;
 &lt;p&gt;While Braunberg recommends &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-agentic-AI-means-for-cybersecurity"&gt;deploying AI agents to bolster security&lt;/a&gt;, he warned about the potential long-term cost implications. Vendors up and down the AI stack are currently subsidizing the use of their tools. Enterprises will ultimately have to consider what the actual costs are based on the complexity of the tasks being automated.&lt;/p&gt;
 &lt;p&gt;"Alert triage, for example, is relatively straightforward and requires modest inference and resource lookups," he said. "Threat hunting is a different animal entirely. Organizations need to understand those real costs before baking agentic into the SOC."&lt;/p&gt;
 &lt;h3&gt;Rethink software lifecycle management&lt;/h3&gt;
 &lt;p&gt;Beyond technical controls, organizations should rethink software lifecycle management in an AI-driven environment. It means understanding how AI tools enable secure-by-design software and how to reorient the SOC to embrace attack surface reduction, threat detection and incident response.&lt;/p&gt;
 &lt;p&gt;"How do we balance business risk, resiliency and security as we move toward autonomous response? The big questions are still people- and process-oriented," Braunberg said.&lt;/p&gt;
&lt;/section&gt;          
&lt;section class="section main-article-chapter" data-menu-title="Getting the fundamentals right"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Getting the fundamentals right&lt;/h2&gt;
 &lt;p&gt;Mythos represents an inflection point for both cybersecurity and AI, but it doesn't change the fundamentals of security as much as it changes the speed at which those fundamentals must operate, said Justin Fier, senior vice president of offensive security at Darktrace.&lt;/p&gt;
 &lt;p&gt;Many organizations are already struggling with basic security challenges, including lack of visibility across their environments, over-permissioned accounts, weak identity controls, and poor identity and access management hygiene. Mythos did not create those issues, but it raises the stakes around them, Fier said.&lt;/p&gt;
 &lt;p&gt;To that end, an AI-ready security environment wouldn't necessarily need to look dramatically different from what a strong security program does today. But that security foundation needs to move a whole lot faster in an AI world.&lt;/p&gt;
 &lt;h3&gt;Automate safely&lt;/h3&gt;
 &lt;p&gt;"CISOs need to start thinking about automation done in a safe and structured way," Fier said. "If organizations are going to patch at the speed and scale that will be required, some form of safe automation is going to be necessary."&lt;/p&gt;
 &lt;p&gt;He recommends using AI agents for code review, red teaming, incident response and other security functions, but only if organizations fully understand the risks -- especially &lt;a href="https://www.techtarget.com/searchsecurity/opinion/Identity-security-for-AI-agents-The-proliferation-challenge"&gt;those associated with AI agents&lt;/a&gt; -- before diving in.&lt;/p&gt;
 &lt;p&gt;"If organizations do not get identity right, they are essentially letting agents run around the business without enough visibility or auditability into what they are doing," Fier said. "That is where we start to see stories about agents wiping out code bases, making costly mistakes or creating real losses because they did not have the right controls around what they could access or change."&lt;/p&gt;
&lt;/section&gt;        
&lt;section class="section main-article-chapter" data-menu-title="Transform vulnerability management"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Transform vulnerability management&lt;/h2&gt;
 &lt;p&gt;Diana Kelley, CISO at Noma Security, said organizations must stop treating vulnerability management as a queue -- scanning to find issues, assigning an owner for the issue and waiting for the next patch or change window -- and start treating it as an operating model.&lt;/p&gt;
 &lt;p&gt;In an AI world, the queue approach won't work, she said, explaining that in an operating model, vulnerability response becomes a continuous business process with clear ownership, decision rights, automation, escalation paths and preapproved authority to contain risk. "The team is constantly asking: Is this exploitable in our environment? Is it on a critical system? Can we patch it now? If not, can we isolate it, block egress, rotate credentials, add monitoring or reduce blast radius today?"&lt;/p&gt;
 &lt;p&gt;In practice, that involves security, engineering, IT and business owners working together.&lt;/p&gt;
 &lt;p&gt;"The metric can't just be 'how many critical and high vulnerabilities did we patch this month?'" she said. "It has to be, 'How much exploitable exposure remains on systems that matter and how quickly can we reduce or contain it?'"&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Jaikumar Vijayan is a freelance technology journalist with more than 20 years of award-winning experience in IT trade journalism, specializing in information security, data privacy and cybersecurity topics.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>AI platforms are poised to accelerate vulnerability discovery and exploitation faster than humans can manage. It's time for CISOs to rethink their security strategies.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/clock-time02.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/feature/The-AI-vulnerability-storm-is-here-Is-your-security-program-ready</link>
            <pubDate>Mon, 06 Jul 2026 13:09:00 GMT</pubDate>
            <title>The AI vulnerability storm is here: Is your security program ready?</title>
        </item>
        <item>
            <body>&lt;p&gt;As cybersecurity threats intensify and perimeter-based security models continue to fail, organizations must adopt zero trust as a strategic, long-term approach to reducing risk and improving resilience surrounding cloud adoption, hybrid work and supply-chain exposure.&lt;/p&gt; 
&lt;p&gt;CISOs and IT decision-makers need a clear, practical understanding of what it takes to adopt and mature a zero-trust architecture -- namely, a realistic, multiyear roadmap for phased implementation that addresses cultural shifts, operational changes and governance structures.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="What zero trust really means -- and what it doesn't"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What zero trust really means -- and what it doesn't&lt;/h2&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/searchsecurity/definition/zero-trust-model-zero-trust-network"&gt;Zero trust&lt;/a&gt; is a security strategy based on the principle of "never trust, always verify," treating every access request as potentially hostile, regardless of location. It requires continuous verification and enforces explicit, &lt;a href="https://www.techtarget.com/searchsecurity/definition/principle-of-least-privilege-POLP"&gt;least-privileged&lt;/a&gt;, dynamically managed access.&lt;/p&gt;
 &lt;p&gt;Zero trust is not a product, control or single technology deployment; it's a strategic architecture and operating model designed to reduce risk and improve the security posture of organizations that have traditional, perimeter-based security models. Perimeter-based models -- which assume clearly defined "inside" and "outside" boundaries -- fail to address modern threats because they were designed for a world that no longer exists.&lt;/p&gt;
 &lt;p&gt;Zero trust relies on three foundational principles:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Explicit verification.&lt;/b&gt; Every access request is authenticated and authorized using components such as user identity, device health, location and behavior.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Least-privilege access enforcement.&lt;/b&gt; Users and devices receive only the minimum access required, and only for as long as needed.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Assume breach.&lt;/b&gt; Security operates under the assumption that attackers are already present, with controls designed to limit access and damage.&lt;/li&gt; 
 &lt;/ol&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Zero trust and organizational transformation"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Zero trust and organizational transformation&lt;/h2&gt;
 &lt;p&gt;Because zero trust changes how organizations manage risk, access and trust, &amp;nbsp;it is more than an IT initiative or a &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-choose-a-cybersecurity-vendor-Key-criteria"&gt;vendor selection&lt;/a&gt; and therefore depends on organizational alignment and leadership commitment.&lt;/p&gt;
 &lt;p&gt;Zero trust requires visible executive sponsorship to cut across silos. CISOs must communicate why the organization is changing its security approach and how zero trust supports not only security, but also business resilience, regulatory compliance, customer trust and digital delivery.&lt;/p&gt;
 &lt;p&gt;Operationally, zero trust transforms how teams design, deploy and manage systems. These changes could require &lt;a href="https://www.techtarget.com/searchITOperations/feature/How-AI-in-training-and-development-can-bridge-IT-talent-gaps"&gt;upskilling staff&lt;/a&gt; and redefining roles within operations and security teams.&lt;/p&gt;
 &lt;p&gt;Zero trust also changes how organizations manage accountability. It requires clear ownership and governance. CISOs must avoid disconnected tools, inconsistent policies and stalled progress across identity, infrastructure, applications, data and &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-build-an-effective-third-party-risk-assessment-framework"&gt;third-party systems.&lt;/a&gt; Consider a cross-functional steering committee consisting of IT, security, compliance, HR, legal, procurement and other key business units to make risk-informed decisions at scale.&lt;/p&gt;
&lt;/section&gt;     
&lt;section class="section main-article-chapter" data-menu-title="Building the business case: Measuring ROI beyond security"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;&lt;a href="https://www.techtarget.com/searchsecurity/tip/7-key-cybersecurity-metrics-for-the-board-and-how-to-present-them?Offer=ab_MeteredFormCopyEoc_var3"&gt;&lt;/a&gt;Building the business case: Measuring ROI beyond security&lt;/h2&gt;
 &lt;p&gt;CISOs can justify security investments by framing zero trust as a risk-management and operational-efficiency initiative with measurable returns.&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Quantifiable risk reduction.&lt;/b&gt; Metrics translate into avoided costs associated with breaches, downtime, regulatory penalties and reputational damage. Zero trust limits the impact of attacks, reduces lateral movement and shortens attacker dwell time.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Operational efficiency gains.&lt;/b&gt; Replacing manual access approvals and configurations with policy-driven automation reduces administrative overhead. It also accelerates onboarding, role changes and offboarding. Centralized identity and access controls simplify application integration, lowering the total cost of ownership and improving UX.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Business agility.&lt;/b&gt; Secure-by-design access models &lt;a target="_blank" href="https://www.darkreading.com/endpoint-security/securing-remote-workers-through-zero-trust" rel="noopener"&gt;support remote work&lt;/a&gt;, cloud migration, third-party collaboration and M&amp;amp;As without complex network and system reconfiguration. This added flexibility reduces the time-to-value for strategic initiatives and minimizes security friction when scaling up.&lt;/li&gt; 
 &lt;/ul&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="A realistic multiyear zero-trust roadmap"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;A realistic multiyear zero-trust roadmap&lt;/h2&gt;
 &lt;p&gt;Successful zero-trust transformations often span years, requiring multiple budget cycles and careful deliberation. Use a phased approach to align business priorities, operational readiness and security improvements.&lt;/p&gt;
 &lt;p&gt;The following roadmap outlines annual milestones that avoid business disruption while demonstrating progress.&lt;/p&gt;
 &lt;h3&gt;Year 1: Establish the foundation&lt;/h3&gt;
 &lt;p&gt;The first year focuses on creating the conditions for zero trust by establishing visibility, identity and control. Start with the following tasks:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Identity management.&lt;/b&gt; Consistently identify and authenticate users, devices and service accounts. Understand who has access to what and eliminate shared and unmanaged accounts.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Inventory infrastructure, applications and data. &lt;/b&gt;Zero trust cannot protect what it can't see. An inventory clearly defines what resources the organization owns and must secure.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Initial access policies, governance structures and success measures.&lt;/b&gt; Focus early efforts on high-value and high-risk systems, gaining momentum by delivering quick wins that reduce risk and build organizational confidence.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Outcome: Reduced exposure from compromised identities, clear ownership of access decisions and a solid foundation for future phases.&lt;/p&gt;
 &lt;h3&gt;Years 2-3: Expand and integrate&lt;/h3&gt;
 &lt;p&gt;Focus on scaling zero trust across the organization. Consider the following tasks:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Resource control.&lt;/b&gt; Add applications, workloads and data to its sphere. These areas include on-premises, cloud and SaaS systems.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Replace legacy network security.&lt;/b&gt; Progressively replace network trust with &lt;a href="https://www.techtarget.com/searchsecurity/tip/Why-zero-trust-requires-microsegmentation"&gt;segmentation&lt;/a&gt; and continuous verification to &lt;a target="_blank" href="https://www.cybersecuritydive.com/news/government-zero-trust-migration-black-hat/756985/" rel="noopener"&gt;limit lateral movement and contain breaches&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Telemetry integration.&lt;/b&gt; Integrate security data from identity systems, endpoints, applications and networks to enable informed, automated policy enforcement.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Governance maturity.&lt;/b&gt; Refine policies, improve metrics and embed zero trust into processes such as application development, third-party access and employee lifecycle management.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Outcome: Faster incident detection and response, improved efficiency and consistent enforcement of least-privileged access.&lt;/p&gt;
 &lt;h3&gt;Years 4-5: Optimize and operationalize&lt;/h3&gt;
 &lt;p&gt;At this point, shift zero trust from a program to a fully operationalized capability.&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Advanced analytics and automation.&lt;/b&gt; Use data to continuously evaluate risk and adapt access decisions in real time.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Policy improvements.&lt;/b&gt; Policies should become more dynamic, responding to changes in behavior, context and threat conditions.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Strategic initiatives reflect zero trust.&lt;/b&gt; Embed &lt;a href="https://www.techtarget.com/searchsecurity/tip/The-5-principles-of-zero-trust-security"&gt;zero-trust principles&lt;/a&gt; in M&amp;amp;As, new digital products and partnerships.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Outcome: The focus shifts from implementation to optimization and resilience, with measurable results, including reduced incident impact, faster recovery, improved audit results and greater confidence in scaling securely.&lt;/p&gt;
&lt;/section&gt;               
&lt;section class="section main-article-chapter" data-menu-title="Moving toward zero trust maturity"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Moving toward zero trust maturity&lt;/h2&gt;
 &lt;p&gt;A phased approach -- tailored to each organization's size and needs -- enables leaders to balance ambition with realism. The key choice for CISOs is how deliberately and effectively to guide the zero-trust transformation.&lt;/p&gt;
 &lt;p&gt;Begin by recognizing zero trust as an evolving capability, not a destination. It requires sustained leadership and governance to enable resilience, efficiency and security.&lt;/p&gt;
 &lt;p&gt;&lt;em&gt;Damon Garn owns Cogspinner Coaction and provides freelance IT writing and editing services. He has written multiple CompTIA study guides, including the Linux+, Cloud Essentials+ and Server+ guides, and contributes extensively to TechTarget Editorial, The New Stack and CompTIA Blogs.&lt;/em&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Transforming an organization to take on a zero-trust posture is no small affair. A phased, thoughtful approach can bolster security while supporting business outcomes.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/map_globe_g180411743.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/tip/Perimeter-to-posture-A-roadmap-to-zero-trust-maturity</link>
            <pubDate>Thu, 02 Jul 2026 10:33:00 GMT</pubDate>
            <title>Perimeter to posture: A roadmap to zero trust maturity</title>
        </item>
        <item>
            <body>&lt;p&gt;Organizations that rely on manual TLS certificate lifecycle management are racing against the clock. The 200-day certificate timeline, which took effect in March 2026, means the first wave of certificate renewals will arrive within a matter of months.&lt;/p&gt; 
&lt;p&gt;"People will feel the realities when they start to renew those first sets of certificates," said Sarah Almond, an analyst at Gartner. Nick France, CTO at Sectigo, a certificate authority (&lt;a href="https://www.techtarget.com/searchsecurity/definition/certificate-authority"&gt;CA&lt;/a&gt;) and certificate lifecycle management (CLM) provider, agreed, calling September and October a "wake-up call" for organizations that aren't ready.&lt;/p&gt; 
&lt;p&gt;The March 2026 change is just the first in a series of updates to certificate lifetimes. The phased approach set by the CA/Browser Forum, a consortium of CAs and browser vendors that sets standards for digital certificates, will further reduce the period to 100 days in March 2027 and ultimately to 47 days in March 2029.&lt;/p&gt; 
&lt;p&gt;The changing lifetimes are being done in the name of security, and experts and CAs warn that the transition requires immediate action to prevent costly outages or breaches that erode customer trust and disrupt operations.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="About TLS certificates and expiration"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;About TLS certificates and expiration&lt;/h2&gt;
 &lt;p&gt;TLS certificates -- digital credentials that verify the identity of a website, server or application -- enable encrypted, authenticated connections that protect data from interception. These certificates carry expiration dates to limit the impact of compromised, stolen or improperly issued certificates, enforce cryptographic upgrades and ensure compliance with policies and regulations.&lt;/p&gt;
 &lt;p&gt;If a TLS certificate expires, it is no longer trusted to establish TLS connections. Websites using the expired certificate are flagged as insecure by browsers, resulting in businesses losing credibility, trust and revenue. According to CyberArk's 2025 "State of Machine Identity Security" &lt;a target="_blank" href="https://www.cyberark.com/state-of-machine-identity-security-report/" rel="noopener"&gt;report&lt;/a&gt;, 72% of organizations experienced at least one certificate-related outage in the previous year -- before the shortened TLS certificate timeline took effect.&lt;/p&gt;
 &lt;p&gt;"Every service owner knows that rotation of a certificate must happen before expiration. Otherwise, end users will see scary or confusing error messages and lose trust in the service," said Ken Beer, director of cryptography at AWS.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Why the change?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why the change?&lt;/h2&gt;
 &lt;p&gt;Improved security is the driver of quicker expiration timelines. The CA/Browser Forum &lt;a target="_blank" href="https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/" rel="noopener"&gt;listed&lt;/a&gt; six benefits of reducing TLS certificate validity periods:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Certificates represent a snapshot in time.&lt;/b&gt; A TLS certificate reflects accurate ownership and validation information when it is issued. In time, that information could become outdated, making shorter certificate lifetimes more reliable.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Outdated certificates create security risks.&lt;/b&gt; Changes such as domain expiration, ownership transfers or compromised keys can leave a certificate valid even though the information it contains is no longer accurate, enabling misuse.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Shorter lifetimes reduce the impact of improperly issued certificates.&lt;/b&gt; If a CA improperly validates information or issues a certificate incorrectly, shorter validity periods limit how long the bad certificate remains trusted.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Shorter lifetimes drive automation adoption.&lt;/b&gt; More frequent renewals push organizations to adopt automated certificate issuance and renewal processes, improving the resilience and reliability of CLM systems.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Certificate expiration provides protection when revocation mechanisms fall short. &lt;/b&gt;Revocation technologies, such as certificate revocation lists and &lt;a href="https://www.techtarget.com/searchsecurity/definition/OCSP"&gt;OCSP&lt;/a&gt;, are not always timely or effective at scale. Shorter certificate lifetimes reduce reliance on those technologies.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Shorter lifetimes improve cryptographic agility.&lt;/b&gt; If a cryptographic algorithm becomes vulnerable or obsolete, shorter-lived certificates enable organizations and the internet ecosystem to transition more quickly to stronger cryptography.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;Another benefit of shortening the certificate lifecycle is post-quantum cryptography (&lt;a href="https://www.techtarget.com/searchsecurity/definition/post-quantum-cryptography"&gt;PQC&lt;/a&gt;) readiness. The March 2029 date is close to many predictions of when the industry expects quantum computers to go live -- and when they could break current cryptography algorithms. Shorter certificate lifetimes will make it easier for organizations to transition to &lt;a href="https://www.techtarget.com/searchcio/tip/Quantum-resistant-algorithms-Why-they-matter"&gt;quantum-resistant algorithms&lt;/a&gt; when current cryptographic standards become vulnerable.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Three critical steps for CISOs"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Three critical steps for CISOs&lt;/h2&gt;
 &lt;p&gt;If they haven't already, CISOs and their teams must start focusing on three key areas to prepare for the TLS certificate changes: inventorying, automating CLM and achieving crypto-agility.&lt;/p&gt;
 &lt;h3&gt;Inventory certificates&lt;/h3&gt;
 &lt;p&gt;To secure anything, CISOs must know what they have and where they are -- yet in the case of cryptography, only 32% of organizations have inventoried their assets, according to a Ponemon Institute &lt;a target="_blank" href="https://www.entrust.com/company/newsroom/entrust-global-report-finds-cryptographic-visibility-stagnant-as-quantum-threat-nears" rel="noopener"&gt;study&lt;/a&gt;.&lt;/p&gt;
 &lt;p&gt;To begin, CISOs should document all their organization's cryptographic assets. Creating a TLS certificate inventory helps reduce certificate-related outages and identify security risks, such as expired certificates, weak encryption, unmanaged certificates and shadow IT.&lt;/p&gt;
 &lt;p&gt;To create an inventory, identify certificates across all environments -- servers, devices, the cloud, and Kubernetes and containers -- and correlate them with their business service and owner. Use CLM platforms or cloud-native tools to simplify the process. Establish automated monitoring of factors such as expiration alerts, certificate changes and unauthorized certificates. Review, update and audit the inventory regularly.&lt;/p&gt;
 &lt;h3&gt;Automate certificate lifecycle management&lt;/h3&gt;
 &lt;p&gt;With an inventory in place, CISOs need to plan how to issue, deploy, revoke and renew certificates. While certificate requests and renewals are often automated, legacy systems, change management requirements and operational controls can introduce manual steps that prevent the process from being fully automated.&lt;/p&gt;
 &lt;p&gt;Brian Trzupek, senior vice president of product at DigiCert, a CA and CLM vendor, said that while many CAs automate certificate installation, the process is still a multistep one. "You start to diminish that because of network deployment aspects," he said. "Then there's the configuration testing of that deployed asset. In some cases, you can readily configuration test that, and others it's more complex, and CAs don't do that. There are layers of automation."&lt;/p&gt;
 &lt;p&gt;In terms of renewal, organizations definitely need to automate, Almond advised. "Most organizations that I speak to won't be able to cope with a manual process when the renewal period is 47 days," she said. "Some say manual processes will be too disruptive even before we get to 47 days, so at the 100-day point or before."&lt;/p&gt;
 &lt;p&gt;Greg Wetmore, vice president of product development at Entrust, a CLM vendor, attributed this to the scale of certificates in use today.&lt;/p&gt;
 &lt;p&gt;"Ten years ago, organizations would have only had a few certificates, and now we're into the thousands, tens of thousands, hundreds of thousands of cryptographic objects," he said.&lt;/p&gt;
 &lt;h3&gt;Build crypto-agility&lt;/h3&gt;
 &lt;p&gt;Moving from manual to automated TLS certification aligns with the broader need for &lt;a href="https://www.techtarget.com/searchenterpriseai/definition/crypto-agility"&gt;crypto-agility&lt;/a&gt; -- the ability to efficiently and quickly switch among cryptographic algorithms, keys and protocols without disrupting operations or sacrificing security -- in the modern digital landscape.&lt;/p&gt;
 &lt;p&gt;"It's not just changing or shortening certificate lifetimes; there are a lot of other changes happening in our industry -- public certificates, PKI and public CAs -- and a lot of them are customer-impacting," France said. "Everybody needs to start preparing for post-quantum encryption, post-quantum certificates and variants of that."&lt;/p&gt;
 &lt;p&gt;Almond agreed. "This whole challenge is really one of crypto-agility," she said.&lt;/p&gt;
 &lt;p&gt;And yet, the Ponemon study found that, despite strong government guidance, only 38% of organizations are actively preparing for the post-quantum era.&lt;/p&gt;
 &lt;p&gt;Two key steps of achieving crypto-agility are inventorying cryptographic assets and automating processes. Organizations must also control their cryptographic assets with policy, Wetmore said. Other &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-achieve-crypto-agility-and-future-proof-security"&gt;key steps include&lt;/a&gt; deploying a key management system, using PKI, and regularly testing and validating systems to ensure they are ready for the challenges posed by quantum computing and other future cybersecurity threats.&lt;/p&gt;
&lt;/section&gt;                  
&lt;section class="section main-article-chapter" data-menu-title="What's next? Preparing for inevitable change"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;What's next? Preparing for inevitable change&lt;/h2&gt;
 &lt;p&gt;The September and October renewal wave will separate the prepared from the unprepared. Organizations that have inventoried cryptographic assets, automated CLM processes and begun preparing for crypto-agility should be able to navigate the change successfully, while the organizations that haven't will face resource-intensive manual reviews, increased risk of outages and other business implications.&lt;/p&gt;
 &lt;p&gt;As Beer warned, organizations that fail to invest in automation will "waste time and resources managing their PKI, increasing their exposure to certificate-related outages and reducing their ability to use those resources to innovate in other areas of their business."&lt;/p&gt;
 &lt;p&gt;And the fact of the matter is that more changes to TLS certification lifetimes are coming, and the PQC era will be here before many realize it. The time to prepare is now.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Samira Sarraf is an award-winning international business and technology journalist and editor with 15 years of experience. She has published news and features on CSO Online, CIO.com, Computerworld, ARNnet, TechPartner News and more.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>TLS certificates now expire after 200 days. That window will soon narrow to 100 days and eventually to 47. Is your organization ready?</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a296619547.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/feature/TLS-certificate-lifetime-changes-What-CISOs-must-do-now</link>
            <pubDate>Wed, 01 Jul 2026 16:15:00 GMT</pubDate>
            <title>TLS certificate lifetime changes: What CISOs must do now</title>
        </item>
        <item>
            <body>&lt;p&gt;By now, every CISO has probably heard the phrase &lt;i&gt;lethal trifecta&lt;/i&gt; tossed around in AI security discussions. The term refers to a combination of three agentic AI properties that, together, make agents vulnerable to attack and put the enterprises using them at massive risk.&lt;/p&gt; 
&lt;p&gt;Programmer Simon Willison is credited with coining the term &lt;i&gt;lethal trifecta&lt;/i&gt; as it relates to &lt;a href="https://www.techtarget.com/searchenterpriseai/definition/agentic-AI"&gt;agentic AI&lt;/a&gt;. Unfortunately, the cybersecurity field does not currently agree on a universal definition: different cybersecurity analysts and AI researchers often pick different trios of properties. And, of course, there's no need to stop at three, but we lack a cutesy term like &lt;i&gt;quadfecta&lt;/i&gt; or &lt;i&gt;quintfecta&lt;/i&gt; to describe a longer list.&lt;/p&gt; 
&lt;p&gt;That said, conversations about the &lt;a href="https://www.techtarget.com/searchsecurity/tip/What-agentic-AI-means-for-cybersecurity"&gt;agentic AI&lt;/a&gt; lethal trifecta often center on the following three properties, as initially &lt;a target="_blank" href="https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/" rel="noopener"&gt;described&lt;/a&gt; by Willison:&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;Agent access to private or sensitive information, whether personal information about staff or customers or confidential intellectual property.&lt;/li&gt; 
 &lt;li&gt;Agent ingestion of uncontrolled content. That is, having an agent that reads data from sources the enterprise does not control, such as public websites, and that can contain either intentionally incorrect information -- meant to affect enterprise or agent decisions -- or hidden prompts intended to redirect agent goals or actions.&lt;/li&gt; 
 &lt;li&gt;Agent ability to communicate externally, and so to exfiltrate data.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Alternatively, some cybersecurity experts include the following properties in the agentic AI lethal trifecta:&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;Agent empowerment to act in ways that affect other enterprise systems -- e.g., reconfiguring network devices or modifying databases.&lt;/li&gt; 
 &lt;li&gt;Agent ability to plan and adaptively pursue long-term objectives without reconfirmation of purpose by a human. Adaptability includes the ability to exploit chains of low-impact vulnerabilities -- e.g., CVEs with low CVSS scores -- to achieve high-impact outcomes such as root-level access to a key server.&lt;/li&gt; 
 &lt;li&gt;Agent ability to self-improve and gain capabilities -- e.g., modifying its own code; modifying its own goals; finding other tools to fill its functional shortcomings; or designing better models, then creating and use tools based on them.&lt;/li&gt; 
 &lt;li&gt;Agentic velocity, or the ability to swamp human-scaled governance mechanisms.&lt;/li&gt; 
 &lt;li&gt;Agentic prompt drift -- i.e., agent non-determinism. Agents and other AIs can produce dramatically different results in response to the same prompt -- and indeed, many jailbreak attacks rely on this to get an AI to break free of its alignment training.&lt;/li&gt; 
 &lt;li&gt;Agent cost indeterminacy. An AI's actual costs, in terms of tokens expended, can spiral unpredictably due to factors such as prompt drift and "context rot," which drives it into recursive loops of re-reading the same context data.&lt;/li&gt; 
 &lt;li&gt;Agents with superhuman persuasiveness can pursue slow and sophisticated social engineering attacks at scales previously impossible.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Pick any subset of these problems, and the core idea is the same: AI plus agency plus permission to act in the enterprise environment add up to a risky synergy with potentially catastrophic consequences.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Why CISOs should pay attention"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why CISOs should pay attention&lt;/h2&gt;
 &lt;p&gt;Agentic AI introduces a new category of cyberthreat -- one that can exploit every other existing threat category. An agent with data access, external connectivity and the ability to act autonomously could reconfigure systems, exfiltrate sensitive data and more, making it both a &lt;a href="https://www.techtarget.com/searchsecurity/feature/Agentic-AIs-role-in-amplifying-and-creating-insider-risks"&gt;significant insider threat&lt;/a&gt; and attack vector for external threat actors.&lt;/p&gt;
 &lt;p&gt;Traditional security tools can't address the potential problems agentic AI creates; for example, traditional web application firewalls can't prevent &lt;a href="https://www.techtarget.com/searchsecurity/tip/Types-of-prompt-injection-attacks-and-how-they-work"&gt;prompt injection attacks&lt;/a&gt;. Organizations must update core architectures to properly integrate new categories of agentic AI security tools, as well as policies that govern acceptable use of agentic AI and incident response. However an organization defines the lethal trifecta, the CISO must coordinate and drive the &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-build-AI-security-guardrails-without-blocking-innovation"&gt;security and governance response&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;   
&lt;section class="section main-article-chapter" data-menu-title="How to assess your risk exposure"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How to assess your risk exposure&lt;/h2&gt;
 &lt;p&gt;As a CISO assessing your organization's lethal trifecta risk, ask yourself the following key questions:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;How much access do AI agents have to core enterprise software such as a CRM?&lt;/li&gt; 
  &lt;li&gt;How much access do AI agents have to enterprise data?&lt;/li&gt; 
  &lt;li&gt;How much access do AI agents have to enterprise infrastructure -- such as network equipment -- and services -- such as an IaaS environment or the DNS service?&lt;/li&gt; 
  &lt;li&gt;How much access do agents have to the internet?&lt;/li&gt; 
  &lt;li&gt;How much access do external entities have to systems in the environment, including AI agents -- e.g. through &lt;a href="https://www.techtarget.com/searchsecurity/tip/Secure-MCP-servers-to-safeguard-AI-and-corporate-data"&gt;Model Context Protocol&lt;/a&gt; (MCP) services?&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;The answers reveal the reach of AI agents in the enterprise -- including those entering through MCP from outside the organization -- and establish the baseline scope of risk. An inability to answer the questions with confidence signals a significant risk, in itself.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Mitigation strategies"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Mitigation strategies&lt;/h2&gt;
 &lt;p&gt;The best strategy for mitigating agentic AI risk is, as is so often the case, &lt;a href="https://www.techtarget.com/searchsecurity/feature/How-to-implement-zero-trust-security-from-people-who-did-it"&gt;implementing a zero-trust architecture&lt;/a&gt;. Infuse the AI infrastructure with core zero-trust principles, strictly limiting access to systems and data based on identity and allow lists. At a minimum, this will mean the following:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Adding &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecuritys-agentic-AI-identity-crisis-and-how-to-fix-it"&gt;identity management for AI agents&lt;/a&gt;, either by deploying a new ID management system specifically for agents or by extending an existing system able to meet requisite scale and speed targets. Software that manages identity for Kubernetes containers might serve, for example.&lt;/li&gt; 
  &lt;li&gt;Channeling communications from and to AI agents through MCP gateways or the like, to provide control points for allowing or denying access and for monitoring behavior.&lt;/li&gt; 
  &lt;li&gt;Adopting a "deny all" default access level and then allowing specific entities to do specific things, as necessary.&lt;/li&gt; 
  &lt;li&gt;Extending the tool set to include the following: 
   &lt;ul style="list-style-type: circle;" class="default-list"&gt; 
    &lt;li&gt;Semantic firewalls that sniff out prompt injection, hypnosis attempts and so on.&lt;/li&gt; 
    &lt;li&gt;"Path-dependent" access management systems that assess inbound and outbound prompts based on the context of past prompts, and watch for slow, subtle attack patterns.&lt;/li&gt; 
    &lt;li&gt;&lt;a href="https://www.techtarget.com/searchenterpriseai/tip/How-to-identify-and-manage-AI-model-drift"&gt;Model drift&lt;/a&gt; monitoring.&lt;/li&gt; 
    &lt;li style="list-style: none;"&gt; 
     &lt;ul style="list-style-type: circle;" class="default-list"&gt;&lt;/ul&gt; &lt;/li&gt; 
   &lt;/ul&gt; &lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;&lt;a href="https://www.techtarget.com/whatis/definition/behavior-based-security"&gt;Behavioral threat monitoring&lt;/a&gt; to catch and interrupt risky agent behavior patterns -- e.g., revoke an agent's access to a key database if it repeatedly tries to perform operations on the database for which it doesn't have permission.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;John Burke is CTO and a research analyst at Nemertes Research. Burke joined Nemertes in 2005 with nearly two decades of technology experience. He has worked at all levels of IT, including as an end-user support specialist, programmer, system administrator, database specialist, network administrator, network architect and systems architect.&lt;/i&gt;&lt;/p&gt;
 &lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>The very capabilities that make an AI agent useful also make it dangerous. Here's what CISOs should know about the agentic AI lethal trifecta, and what they should do about it.</description>
            <image>https://cdn.ttgtmedia.com/visuals/LeMagIT/hero_article/Hero-Danger-by-InfiniteFlow-Adobe-10.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/tip/The-agentic-AI-lethal-trifecta-What-CISOs-should-know</link>
            <pubDate>Tue, 30 Jun 2026 22:15:00 GMT</pubDate>
            <title>The agentic AI 'lethal trifecta': What CISOs should know</title>
        </item>
        <item>
            <body>&lt;p&gt;To protect corporate data and prevent security incidents, IT must have a program in place to audit the mobile endpoints that access business systems and data.&lt;/p&gt; 
&lt;p&gt;What falls under the category of "mobile device" for auditing has evolved over the years. While smartphones and tablets might come to mind first, mobile device security audits should also account for laptops, &lt;a href="https://www.techtarget.com/searchmobilecomputing/definition/BYOD"&gt;BYOD &lt;/a&gt;endpoints and other portable or network-connected devices that can access corporate resources.&lt;/p&gt; 
&lt;p&gt;A comprehensive mobile device audit program helps IT understand which devices are in use, how they are managed, what data they can access and whether they comply with security policies. Strong security controls are crucial as employees use more devices across office, remote and hybrid work environments.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Why are mobile device security audits important?"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Why are mobile device security audits important?&lt;/h2&gt;
 &lt;p&gt;Mobile devices store and transmit sensitive data on both managed and unmanaged networks. To mitigate risk, IT departments should conduct a mobile device security audit to systematically evaluate their organization's mobile device security measures.&lt;/p&gt;
 &lt;p&gt;A mobile device security audit assesses details such as the types of devices, OS versions, policies, access control, software updates and encryption. By examining these features, organizations can figure out how secure corporate resources are against potential data breaches.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    A mobile device audit program should give IT a repeatable way to assess mobile risk, not just a one-time checklist.
   &lt;/figure&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;Mobile auditing in the enterprise is not just about cellphones. It should be narrower than a complete network audit, but broad enough to include the portable and network-connected endpoints that can access corporate resources. That can include smartphones, tablets, laptops, BYOD devices and some IoT devices, depending on how they connect and what data or systems they can reach.&lt;/p&gt;
 &lt;p&gt;Some devices might seem fixed to one place or only serve one purpose, but they can still pose issues if they connect to Wi-Fi, Bluetooth or corporate networks. The goal is not to treat every connected device the same way, but to decide which devices create mobile or endpoint risk and include them in the right audit scope.&lt;/p&gt;
 &lt;p&gt;For example, if an organization relies on shared network credentials or weak access controls, an employee or attacker might connect an unmanaged device to the corporate network. IT admins need to know what that device is, what network segment it can reach, whether it is sending data and whether it creates a path to more sensitive systems.&lt;/p&gt;
 &lt;p&gt;It's important to consider factors such as OS version, manufacturer support, ownership model, patch status, app inventory, network access and network segmentation in a mobile audit. Because network security is a key component of mobile security, IT admins should separate high-risk or unmanaged devices from critical corporate infrastructure through segmentation, access controls and monitoring.&lt;/p&gt;
 &lt;p&gt;An audit shouldn't be a one-and-done task; it should be a recurrent part of a broader program. Regular audits help IT strengthen cybersecurity measures and keep them up to date, while educating end users on &lt;a href="https://www.techtarget.com/searchmobilecomputing/feature/7-mobile-device-security-best-practices-for-businesses"&gt;best practices for mobile security&lt;/a&gt;.&lt;/p&gt;
 &lt;figure class="main-article-image full-col" data-img-fullsize="https://www.techtarget.com/rms/onlineimages/mobile_computing-mobile_security-f.png"&gt;
  &lt;img data-src="https://www.techtarget.com/rms/onlineimages/mobile_computing-mobile_security-f_mobile.png" class="lazy" data-srcset="https://www.techtarget.com/rms/onlineimages/mobile_computing-mobile_security-f_mobile.png 960w,https://www.techtarget.com/rms/onlineimages/mobile_computing-mobile_security-f.png 1280w" alt="Graphic showing the top mobile security threats: malware attacks, phishing, lost or stolen devices, cross-app data sharing and unpatched OSes." height="220" width="560"&gt;
  &lt;figcaption&gt;
   &lt;i class="icon pictures" data-icon="z"&gt;&lt;/i&gt;A mobile device audit program should include measures to prevent and address common security threats, including malware, phishing and lost or stolen devices.
  &lt;/figcaption&gt;
  &lt;div class="main-article-image-enlarge"&gt;
   &lt;i class="icon" data-icon="w"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/figure&gt;
&lt;/section&gt;          
&lt;section class="section main-article-chapter" data-menu-title="8 key aspects of a mobile device security audit program"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;8 key aspects of a mobile device security audit program&lt;/h2&gt;
 &lt;p&gt;When conducting an audit, IT should pay attention to unmanaged, underpatched and higher-risk devices that employees bring into the organization. Mobile device management (&lt;a href="https://www.techtarget.com/searchmobilecomputing/definition/mobile-device-management"&gt;MDM&lt;/a&gt;) and unified endpoint management (&lt;a href="https://www.techtarget.com/searchmobilecomputing/definition/unified-endpoint-management-UEM"&gt;UEM&lt;/a&gt;) tools are important for inventory, policy enforcement, configuration management and data loss prevention.&lt;a href="https://www.techtarget.com/searchmobilecomputing/definition/mobile-threat-defense"&gt; Mobile threat defense&lt;/a&gt; tools can add risk detection for mobile phishing, malicious apps, device compromise and unsafe network connections.&lt;/p&gt;
 &lt;p&gt;NIST SP 800-124 Rev. 2 provides current guidance for managing mobile device security in the enterprise, including centralized device management and endpoint protection technologies. IT teams can use that guidance, along with internal risk requirements, to decide which controls and tools belong in the audit program.&lt;/p&gt;
 &lt;p&gt;There are several moving parts involved in a mobile device security audit program. To ensure that it's comprehensive and effective, admins should focus on the following key aspects:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Policies and procedures.&lt;/b&gt; Organizations must provide clear, thorough &lt;a href="https://www.techtarget.com/searchmobilecomputing/feature/Why-a-mobile-security-policy-is-a-must-have-corporate-policy"&gt;mobile device policies&lt;/a&gt;. These policies should cover acceptable use, data handling, passwords and remote access. IT should also regularly review and update security policies.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Access control&lt;/strong&gt;. Strong authentication methods, such as multifactor authentication, should be in place, along with role-based access control, conditional access policies and least-privilege access for sensitive data. Additionally, monitor and log access attempts, especially from unmanaged, noncompliant or high-risk devices.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Software and updates.&lt;/b&gt; IT should follow a rigorous update schedule for OS versions and security patches, with updates for critical vulnerabilities taking priority. Use &lt;a href="https://www.techtarget.com/searchmobilecomputing/tip/Top-7-mobile-device-management-tools-to-consider"&gt;MDM tools&lt;/a&gt; to help automate updates and compliance as well.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;MDM and UEM.&lt;/strong&gt; IT should use mobile device management or unified endpoint management tools for central management, policy enforcement, inventory tracking, compliance checks, remote wiping and app deployment. Management logs should also undergo regular audits.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Encryption. &lt;/strong&gt;IT should require strong encryption for data at rest and in transit. There should also be clear encryption requirements for sensitive information on devices. Hardware-backed protections, such as Trusted Platform Module and &lt;a href="https://www.techtarget.com/searchmobilecomputing/tip/Intro-to-iPhone-encryption-features-for-Apple-admins"&gt;Apple's Secure Enclave&lt;/a&gt;, can provide additional protection for supported devices.&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Security awareness training.&lt;/b&gt; Users should receive &lt;a href="https://www.techtarget.com/searchsecurity/tip/Cybersecurity-employee-training-How-to-build-a-solid-plan"&gt;education on mobile security&lt;/a&gt; and their role in maintaining it. This can include training on password hygiene, phishing, malware and other common threats, as well as instructions for what to do in the event of device loss or theft.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Removable media.&lt;/b&gt; Organizations should define policies for using removable media with mobile devices. Enforce encryption for data transfer to and from removable media, and consider restricting access if it isn't essential.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Compliance with NIST and other security standards.&lt;/b&gt; NIST guidelines and other relevant &lt;a href="https://www.techtarget.com/searchsecurity/tip/IT-security-frameworks-and-standards-Choosing-the-right-one"&gt;data security standards&lt;/a&gt;, such as the &lt;a href="https://www.techtarget.com/searchsecurity/definition/PCI-DSS-Payment-Card-Industry-Data-Security-Standard"&gt;Payment Card Industry Data Security Standard&lt;/a&gt; and &lt;a href="https://www.techtarget.com/searchhealthit/definition/HIPAA"&gt;HIPAA&lt;/a&gt;, must factor into audit programs. Evaluate password policies, encryption methods, incident response procedures, MDM, MTD and other factors against these standards.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;Mobile device audit program checklist&lt;/h3&gt; 
   &lt;p&gt;A mobile device audit program should answer these questions:&lt;/p&gt; 
   &lt;p&gt;✓ Which smartphones, tablets, laptops, BYOD devices and relevant IoT devices can access corporate resources?&lt;/p&gt; 
   &lt;p&gt;✓ Are devices enrolled in MDM or UEM, and are management policies applied consistently?&lt;/p&gt; 
   &lt;p&gt;✓ Are OS versions, patches, app inventories and compliance status current?&lt;/p&gt; 
   &lt;p&gt;✓ Are encryption, remote wipe, password and multifactor authentication requirements enforced?&lt;/p&gt; 
   &lt;p&gt;✓ Are unmanaged, noncompliant or high-risk devices blocked or restricted?&lt;/p&gt; 
   &lt;p&gt;✓ Are mobile threat defense tools or other controls used where risk warrants them?&lt;/p&gt; 
   &lt;p&gt;✓ Are audit findings assigned to owners, remediated and reviewed in future audits?&lt;/p&gt;
  &lt;/div&gt;
 &lt;/div&gt;
&lt;/section&gt;      
&lt;section class="section main-article-chapter" data-menu-title="Best practices for building an audit program"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Best practices for building an audit program&lt;/h2&gt;
 &lt;p&gt;There isn't a one-size-fits-all audit program that all IT departments can adopt. The specific details to focus on for a mobile device security audit program depend on the following factors:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Organization size. &lt;/b&gt;A large organization with a diverse range of mobile devices might need a more comprehensive audit program than a smaller organization with limited devices.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Device types. &lt;/b&gt;The types of mobile devices in use within the organization can influence the audit approach. For example, IT might focus on encryption and &lt;a href="https://www.techtarget.com/searchsecurity/tip/Pave-a-path-to-cybersecurity-and-physical-security-convergence"&gt;physical security&lt;/a&gt; when auditing laptops, while auditing smartphones might require more focus on access control and app security.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;OSes. &lt;/b&gt;Different OSes have &lt;a href="https://www.techtarget.com/searchmobilecomputing/tip/Are-iPhones-more-secure-than-Android-devices"&gt;varying security features and vulnerabilities&lt;/a&gt;, requiring tailored audit approaches.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Industry regulations. &lt;/b&gt;Organizations in regulated sectors, such as healthcare or finance, often need to follow industry-specific security standards. Their audit programs should reflect this.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Device ownership.&lt;/b&gt; Organizations with BYOD deployments must include some &lt;a href="https://www.techtarget.com/searchmobilecomputing/tip/What-can-organizations-do-to-address-BYOD-privacy-concerns"&gt;extra security and privacy considerations&lt;/a&gt; in their audit procedures.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;Once admins determine the audit objectives and scope, they should create and follow an audit checklist, which should generally include the following steps:&lt;/p&gt;
 &lt;ol class="default-list"&gt; 
  &lt;li style="list-style-type: none;"&gt; 
   &lt;ol start="1" data-spread="true" class="default-list"&gt; 
    &lt;li&gt;Audit mobile endpoints, including smartphones, tablets, laptops, BYOD devices and relevant IoT devices.&lt;/li&gt; 
    &lt;li&gt;Confirm device ownership, enrollment status, OS version, patch level, app inventory and compliance status.&lt;/li&gt; 
    &lt;li&gt;Ensure appropriate network segmentation and access controls for mobile, BYOD and IoT devices.&lt;/li&gt; 
    &lt;li&gt;Update mobile and IoT devices to the latest supported versions.&lt;/li&gt; 
    &lt;li&gt;Implement MDM or UEM tools for inventory, configuration, policy enforcement and remote wipe.&lt;/li&gt; 
    &lt;li&gt;Implement advanced security tools, including MTD, especially for high-risk organizations.&lt;/li&gt; 
    &lt;li&gt;Review identity controls, including multifactor authentication, conditional access and access removal for lost devices or departing employees.&lt;/li&gt; 
    &lt;li&gt;Document audit findings, assign owners and track remediation through completion.&lt;/li&gt; 
   &lt;/ol&gt; &lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;A mobile device audit program should give IT a repeatable way to assess mobile risk, not just a one-time checklist. The program should help teams understand which devices can access corporate resources, whether those devices meet security requirements and which risks need remediation first.&lt;/p&gt;
 &lt;p&gt;As mobile, BYOD and IoT use expands, audit programs should evolve with the environment. Regular reviews of device inventory, access controls, security tools and user behavior can help organizations protect sensitive data and reduce the chance that a mobile endpoint becomes a path into critical systems.&lt;/p&gt;
 &lt;p&gt;&lt;strong&gt;Editor's note&lt;/strong&gt;: &lt;em&gt;This article was updated to improve clarity and include current mobile device audit program considerations around MDM, UEM, BYOD, MTD, access controls and compliance. &lt;/em&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Michael Goad is a freelance writer and solutions architect with experience handling mobility in an enterprise setting.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>A mobile device audit program helps IT assess endpoint inventory, access controls, encryption, MDM, UEM, BYOD risk, compliance and remediation across mobile endpoints.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/mobile_g1182604339.jpg</image>
            <link>https://www.techtarget.com/searchmobilecomputing/tip/Key-aspects-of-a-mobile-device-security-audit-program</link>
            <pubDate>Mon, 29 Jun 2026 14:43:00 GMT</pubDate>
            <title>8 key aspects of a mobile device security audit program</title>
        </item>
        <item>
            <body>&lt;p&gt;Mobile devices in the enterprise are an increasingly large target for cyberattacks. Mobile security audits help IT identify device, app, network and user risks before those risks lead to data loss or unauthorized access.&lt;/p&gt; 
&lt;p&gt;With the growing amount of both corporate and personal data on smartphones and tablets, these devices are &lt;a href="https://www.techtarget.com/whatis/34-Cybersecurity-Statistics-to-Lose-Sleep-Over-in-2020"&gt;vulnerable to a range of mobile-specific threats&lt;/a&gt;. Prominent cyberthreats include the following:&lt;/p&gt; 
&lt;ul class="default-list"&gt; 
 &lt;li&gt;&lt;b&gt;Phishing and smishing attacks.&lt;/b&gt; Attackers can spread malware or obtain sensitive information by sending &lt;a href="https://www.techtarget.com/searchmobilecomputing/tip/How-to-incorporate-smishing-into-security-awareness-training"&gt;malicious emails, text messages or links&lt;/a&gt;.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Lost, stolen or unmanaged devices&lt;/b&gt;. Devices that are missing, poorly managed or outside policy can expose confidential corporate data.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Unsecured Wi-Fi&lt;/b&gt;. Public networks are often vulnerable to interception of data transmissions.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Outdated software&lt;/b&gt;. Older OSes and applications might have unpatched vulnerabilities.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Risky or malicious apps.&lt;/b&gt; Unapproved apps, excessive permissions or apps from untrusted sources can expose data or introduce malware.&lt;/li&gt; 
 &lt;li&gt;&lt;b&gt;Weak identity and access controls&lt;/b&gt;. Weak passwords, missing &lt;a href="https://www.techtarget.com/searchsecurity/definition/multifactor-authentication-MFA"&gt;multifactor authentication&lt;/a&gt; or poorly enforced access policies can increase the risk of account compromise.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The potential outcomes of such threats can significantly affect organizations. Consequences include data loss, financial damage, reputational harm, regulatory exposure and legal liabilities. Mobile security audits help organizations verify that policies are working, data is protected and mobile endpoints do not become an easy path into enterprise systems.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Understanding mobile security audits"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Understanding mobile security audits&lt;/h2&gt;
 &lt;p&gt;A security audit thoroughly assesses an organization's devices, apps, data management policies and networks. Its purpose is to detect vulnerabilities and ensure security, privacy and functionality. Traditional &lt;a href="https://www.techtarget.com/searchdisasterrecovery/tip/Six-ITGC-audit-controls-to-improve-business-continuity"&gt;security audits encompass all aspects of IT infrastructure&lt;/a&gt;. Mobile security audits, by contrast, focus specifically on mobile endpoints and the ways employees use them to access corporate resources.&lt;/p&gt;
 &lt;p&gt;A mobile security audit should cover technical controls, such as encryption, authentication, device configuration, app permissions, network access and remote wipe capabilities. It should also evaluate user behaviors, such as password management, app usage, use of public Wi-Fi, and compliance with bring-your-own-device policies.&lt;/p&gt;
 &lt;p&gt;Mobile-specific security audits address the unique risks associated with mobile devices. They assess portability, device ownership models, iOS and Android versions, managed and unmanaged apps, reliance on public networks, mobile device management controls and the separation of personal and corporate data. This specialized approach enables a more accurate evaluation of mobile security risks.&lt;/p&gt;
 &lt;p&gt;Mobile audits help support the following security components:&lt;/p&gt;
 &lt;ol data-spread="true" start="1" class="default-list"&gt; 
  &lt;li&gt;&lt;strong&gt;Risk assessmen&lt;/strong&gt;t. Audits help identify weaknesses in a mobile environment so IT can prioritize mitigation efforts.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Asset and configuration visibility&lt;/strong&gt;. Audits help IT confirm which devices, OS versions, apps, settings and access rights are present in the mobile environment.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Policy enforcement&lt;/strong&gt;. Regular audits ensure that the organization's mobile security policies are established and effective.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Threat detection&lt;/strong&gt;. Audits can reveal malware infections, unauthorized access attempts, risky apps, misconfigured devices and other suspicious activities.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Incident response&lt;/strong&gt;. A recent audit can provide valuable information for investigation and remediation in the event of a breach.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Compliance&lt;/strong&gt;. Many industries have regulations that require &lt;a href="https://www.techtarget.com/searchsecurity/tip/IT-security-frameworks-and-standards-Choosing-the-right-one"&gt;regular security controls&lt;/a&gt;, documentation and audits to protect sensitive data. In these industries, current mobile security insights are essential for maintaining compliance and avoiding legal issues.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;p&gt;Audits can also enhance an organization's reputation. It's important for organizations to show that they take data protection seriously and address security risks proactively. Regular audits demonstrate a commitment to mobile security, which builds trust with customers and other stakeholders.&lt;/p&gt;
 &lt;blockquote class="main-article-pullquote"&gt;
  &lt;div class="main-article-pullquote-inner"&gt;
   &lt;figure&gt;
    Mobile security audits help IT verify that policies are working, data is protected and mobile endpoints do not become an easy path into enterprise systems.
   &lt;/figure&gt;
   &lt;i class="icon" data-icon="z"&gt;&lt;/i&gt;
  &lt;/div&gt;
 &lt;/blockquote&gt;
 &lt;p&gt;Additionally, mobile security audits provide valuable insights for continuous improvement. Identifying and addressing weaknesses enables organizations to adapt to evolving threats and maintain strong security over time.&lt;/p&gt;
&lt;/section&gt;         
&lt;section class="section main-article-chapter" data-menu-title="How to conduct a mobile security audit"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;How to conduct a mobile security audit&lt;/h2&gt;
 &lt;p&gt;Several factors can affect how IT approaches mobile audits. Is the organization managing both iOS and Android devices? What regulatory standards does the organization have to follow? Admins should consider these and other questions when developing their approach.&lt;/p&gt;
 &lt;p&gt;While the audit process can vary between organizations, it generally involves the following steps:&lt;/p&gt;
 &lt;ol type="1" start="1" class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Define scope.&lt;/b&gt; Identify which devices, apps and networks to include in the audit.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Gather information.&lt;/b&gt; Collect data on mobile devices, software versions, security settings, apps and user access. This should include both BYOD and corporate-owned endpoints.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Evaluate security controls.&lt;/b&gt; Assess the strength of passwords, encryption, authentication mechanisms and other security measures.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Test for vulnerabilities.&lt;/b&gt; Conduct &lt;a href="https://www.techtarget.com/searchsecurity/definition/penetration-testing"&gt;penetration testing&lt;/a&gt; to simulate attacks and find weaknesses.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Analyze findings.&lt;/b&gt; Create a detailed report outlining vulnerabilities, risks and recommendations for improvement.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Implement remediation.&lt;/b&gt; Prioritize and address identified vulnerabilities based on their severity.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Implement continuous monitoring.&lt;/b&gt; Establish ongoing monitoring and regular audits to maintain a secure mobile environment.&lt;/li&gt; 
 &lt;/ol&gt;
 &lt;div class="youtube-iframe-container"&gt;
  &lt;iframe id="ytplayer-0" src="https://www.youtube.com/embed/QwRnGJdXGaA?si=4HhknaXbJSjvxfWU?autoplay=0&amp;amp;modestbranding=1&amp;amp;rel=0&amp;amp;widget_referrer=null&amp;amp;enablejsapi=1&amp;amp;origin=https://www.techtarget.com" type="text/html" height="360" width="640" frameborder="0"&gt;&lt;/iframe&gt;
 &lt;/div&gt;
 &lt;p&gt;Beyond the basic process, an effective audit touches on specific threats and risk management details. Additional audit tools, such as compliance checklists, can help with this. IT should use audits to review the following mobile security issues:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Malware from malicious apps&lt;/b&gt;. Security audits look at the sources of mobile applications, the permissions they request and their behavior. Conduct regular audits to ensure that only trusted apps are on devices, reducing the risk of malware infections.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Network security&lt;/b&gt;. Audits emphasize network security, especially when devices connect to public Wi-Fi networks. When conducting a mobile audit, review network configurations and mandate the use of VPNs or other secure networking policies. This helps safeguard data transmissions and prevent unauthorized access.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Mobile device management (MDM) and unified endpoint management (UEM). &lt;/b&gt;Effective &lt;a href="https://www.techtarget.com/searchmobilecomputing/definition/mobile-device-management"&gt;MDM&lt;/a&gt; and &lt;a href="https://www.techtarget.com/searchenterprisedesktop/definition/unified-endpoint-management-UEM"&gt;UEM&lt;/a&gt; are critical to mobile security. Audits should assess device configuration, compliance status, app management, encryption, remote wipe capabilities, patch levels and policy enforcement.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Identity and access controls&lt;/b&gt;. Mobile audits should review authentication requirements, multifactor authentication coverage, account access, conditional access policies and how quickly access is removed when an employee leaves or a device is lost.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Data protection&lt;/b&gt;. Audits should confirm that corporate data is encrypted, access-controlled, separated from personal data where appropriate and removable through selective wipe or full wipe when necessary.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;User behavior and awareness&lt;/b&gt;. Mobile security depends on users as well as tools. Audits should identify risky behaviors, such as installing unapproved apps, ignoring updates, using weak passwords or connecting to unsafe networks.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;div class="extra-info"&gt;
  &lt;div class="extra-info-inner"&gt;
   &lt;h3 class="splash-heading"&gt;What mobile security audits should cover&lt;/h3&gt; 
   &lt;p&gt;A mobile security audit should review more than whether devices are enrolled in management software. IT should also check device ownership, OS versions, app inventory, security settings, user access, network use, data protection controls and policy compliance.&lt;/p&gt; 
   &lt;p&gt;&amp;nbsp;&lt;/p&gt; 
   &lt;p&gt;The audit should confirm whether corporate data is encrypted, whether risky apps are present, whether devices can be wiped if lost or stolen, and whether users follow mobile security&lt;/p&gt; 
   &lt;p&gt;policies. The goal is to identify practical risks before they lead to data loss, account compromise or compliance problems.&lt;/p&gt;
  &lt;/div&gt;
 &lt;/div&gt;
 &lt;ul class="default-list"&gt;&lt;/ul&gt;
 &lt;p&gt;Mobile security audits should not be a one-time compliance exercise. They should give IT a repeatable way to understand mobile risk, confirm that security controls are working and prioritize fixes across devices, apps, networks and users.&lt;/p&gt;
 &lt;p&gt;As mobile access expands, regular audits can help organizations protect corporate data, support compliance and reduce the chance that a lost device, risky app or compromised account becomes a broader security incident.&lt;/p&gt;
 &lt;p&gt;&lt;strong&gt;Editor's note&lt;/strong&gt;: &lt;em&gt;This article was updated to improve clarity and include current mobile security audit considerations around BYOD, identity controls, app risk and mobile device management. &lt;/em&gt;&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Michael Goad is a freelance writer and solutions architect with experience handling mobility in an enterprise setting.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Mobile devices bring their own set of challenges and risks to enterprise security. To handle mobile-specific threats, IT should conduct regular mobile security audits.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/security_a292905838.jpg</image>
            <link>https://www.techtarget.com/searchmobilecomputing/tip/Why-mobile-security-audits-are-important-in-the-enterprise</link>
            <pubDate>Mon, 29 Jun 2026 13:33:00 GMT</pubDate>
            <title>Why mobile security audits are important in the enterprise</title>
        </item>
        <item>
            <body>&lt;p&gt;The traditional network perimeter has effectively disappeared, creating a major data security problem for CISOs and their teams.&lt;/p&gt; 
&lt;p&gt;Organizations today operate across on-premises, multi-cloud, API and edge systems with no fixed boundaries. Data traverses SaaS platforms and cloud services, remote user systems, APIs and partner ecosystems, changing the data security game. SaaS sprawl, &lt;a href="https://www.techtarget.com/searchcio/tip/6-dangers-of-shadow-IT-and-how-to-avoid-them"&gt;shadow IT&lt;/a&gt; and API-driven integrations only make the data security challenge more difficult.&lt;/p&gt; 
&lt;p&gt;Simply put, data protection has moved from perimeter security to distributed, lifecycle-based controls. Organizations must unify governance, encryption, tokenization and policy-based access into a single operating model to protect the organization's data, maintain resilience, meet compliance obligations and retain the performance that employees and customers expect.&lt;/p&gt; 
&lt;p&gt;The focus must shift from infrastructure security to data-centric protection, where identity and context -- not location -- determine access decisions. This requires applying consistent controls where data is created, stored, shared or processed.&lt;/p&gt; 
&lt;section class="section main-article-chapter" data-menu-title="Governance, visibility and data lifecycle control"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Governance, visibility and data lifecycle control&lt;/h2&gt;
 &lt;p&gt;Effective data protection begins with &lt;a href="https://www.techtarget.com/searchdatamanagement/tip/6-key-steps-to-develop-a-data-governance-strategy"&gt;governance&lt;/a&gt;. Organizations need clear data ownership models. Define responsibility for classifying data, approving access and managing protection policies across business units, cloud platforms and SaaS applications. Without accountability, security controls become fragmented and inconsistent.&lt;/p&gt;
 &lt;p&gt;Visibility is equally crucial. Continuously discover and monitor sensitive data across cloud, SaaS, databases, endpoints and edge environments. &lt;a href="https://www.techtarget.com/searchsecurity/tip/How-to-write-a-data-classification-policy-with-template"&gt;Data classification&lt;/a&gt; enables appropriate protections based on business value, sensitivity and regulatory requirements.&lt;/p&gt;
 &lt;p&gt;Establish data lifecycle controls to protect data from creation and active use to sharing, retention, archival and &lt;a href="https://www.techtarget.com/searchDataBackup/tip/Increase-backup-efficiency-with-a-data-destruction-policy"&gt;deletion&lt;/a&gt;. Lifecycle-based policies keep controls consistent and comprehensive as data moves among systems, platforms and users. Data lineage and audit trails provide the transparency needed for compliance and incident investigations. Use automated monitoring to identify policy drift and emerging risks before they become security incidents.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Core protection model: Encryption, tokenization and policy enforcement"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Core protection model: Encryption, tokenization and policy enforcement&lt;/h2&gt;
 &lt;p&gt;The core data-centric protection model supports safe, scalable data use across diverse systems. It relies on encryption, tokenization and policy-based access controls.&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;&lt;b&gt;Encryption&lt;/b&gt; is applied to &lt;a href="https://www.techtarget.com/searchsecurity/feature/Best-practices-to-secure-data-at-rest-in-use-and-in-motion"&gt;data at rest, in transit and in use&lt;/a&gt;.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Tokenization&lt;/b&gt; replaces sensitive data with placeholder values, aka &lt;i&gt;tokens&lt;/i&gt;, in analytics, SaaS tools and operational systems.&lt;/li&gt; 
  &lt;li&gt;&lt;b&gt;Policy-based access control&lt;/b&gt; enables dynamic enforcement based on identity, device, location and data sensitivity.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;These capabilities extend beyond the traditional infrastructure into APIs, microservices and third-party integrations. Consistency is critical -- fragmented policies create bypass paths and compliance gaps. Controls must also minimize friction for engineering teams while maintaining strict enforcement.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Key management and cryptographic control"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Key management and cryptographic control&lt;/h2&gt;
 &lt;p&gt;Key management a critical component of data protection, providing security and resilience while ensuring regulatory compliance. Establish centralized governance over key policies while permitting distributed enforcement where operationally necessary, such as SaaS systems, edge environments and cloud platforms.&lt;/p&gt;
 &lt;p&gt;Effective key management spans &lt;a href="https://www.techtarget.com/searchsecurity/tutorial/Use-ssh-keygen-to-create-SSH-key-pairs-and-more"&gt;secure key generation&lt;/a&gt;, storage, rotation, revocation and auditing. Automate these processes to reduce operational complexity and minimize human error. Use &lt;a href="https://www.techtarget.com/searchsecurity/definition/hardware-security-module-HSM"&gt;hardware security modules&lt;/a&gt;, which safeguard keys in tamper-resistant hardware, for additional protection for highly sensitive workloads.&lt;/p&gt;
 &lt;p&gt;Multi-cloud environments create unique key management challenges, including key portability, policy consistency and potential vendor lock-in. Clear separation of duties, comprehensive audit trails and continuous monitoring help ensure that only authorized users and systems can access protected data.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Performance, automation and risk-based architecture"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Performance, automation and risk-based architecture&lt;/h2&gt;
 &lt;p&gt;Protecting data at scale requires balancing strong security with operational efficiency. Encryption and tokenization can introduce latency and computational overhead, particularly in high-volume cloud environments and resource-constrained edge deployments. Classification enables organizations to adopt a &lt;a href="https://www.techtarget.com/searchsecurity/tip/5-ways-to-achieve-a-risk-based-security-strategy"&gt;risk-based approach&lt;/a&gt; that applies the strongest protections to the most sensitive and business-critical data while enabling efficient automated management.&lt;/p&gt;
 &lt;p&gt;Automation keeps controls consistent across multi-cloud, SaaS and edge environments. Policy-as-code and continuous integration/continuous delivery pipeline integration enforce security requirements automatically throughout the data lifecycle. Automated monitoring and real-time policy enforcement also reduce the risk of configuration errors, avoid control gaps and enhance visibility.&lt;/p&gt;
 &lt;p&gt;From an architectural perspective, organizations should limit the impact of breaches through segmentation, isolation and zero-trust policies. The goal extends beyond preventing unauthorized access to include containing incidents, reducing exposure and maintaining business continuity when security events occur.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Resilience, incident response and business continuity"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Resilience, incident response and business continuity&lt;/h2&gt;
 &lt;p&gt;Modern data protection strategies assume breaches are inevitable. Establishing data-centric &lt;a href="https://www.techtarget.com/searchsecurity/definition/incident-response"&gt;incident response&lt;/a&gt; enables rapid containment through:&lt;/p&gt;
 &lt;ul class="default-list"&gt; 
  &lt;li&gt;Encryption key revocation and invalidation to address encryption-based incidents.&lt;/li&gt; 
  &lt;li&gt;Immutable backups and encrypted recovery systems to support operational continuity.&lt;/li&gt; 
  &lt;li&gt;Automated responses to reduce dwell time and limit exposure.&lt;/li&gt; 
  &lt;li&gt;Incident planning aligned with regulatory obligations and business uptime requirements to ensure availability.&lt;/li&gt; 
 &lt;/ul&gt;
 &lt;p&gt;With effective governance and planning in place, data resilience becomes a competitive advantage, not just a compliance requirement.&lt;/p&gt;
&lt;/section&gt;    
&lt;section class="section main-article-chapter" data-menu-title="Regulatory alignment and business value"&gt;
 &lt;h2 class="section-title"&gt;&lt;i class="icon" data-icon="1"&gt;&lt;/i&gt;Regulatory alignment and business value&lt;/h2&gt;
 &lt;p&gt;Strong data protection supports trust, continuity and enterprise scalability across diverse, distributed environments. Regulatory alignment ensures data protection controls map to frameworks, such as GDPR, HIPAA and industry-specific requirements, through consistent, auditable enforcement. Automated classification, encryption and access logging reduce compliance burden and operational overhead while improving accuracy and traceability.&lt;/p&gt;
 &lt;p&gt;From a &lt;a href="https://www.techtarget.com/searchcio/feature/Make-business-case-for-tech-spend-based-on-ITs-CIOs-role"&gt;business perspective&lt;/a&gt;, evaluate data protection in terms of risk reduction, operational continuity and breach-impact mitigation, not just cost. Strong controls support customer trust, market expansion and reduced financial exposure.&lt;/p&gt;
 &lt;p&gt;The perimeter is gone. The question is no longer whether data will be exposed, but how quickly security teams can detect, contain and recover when it is. Organizations that succeed will be those that treat data as a continuously governed asset, not an infrastructure byproduct.&lt;/p&gt;
 &lt;p&gt;&lt;i&gt;Damon Garn owns Cogspinner Coaction and provides freelance IT writing and editing services. He has written multiple CompTIA study guides, including the Linux+, Cloud Essentials+ and Server+ guides, and contributes extensively to Informa TechTarget, The New Stack and CompTIA Blogs.&lt;/i&gt;&lt;/p&gt;
&lt;/section&gt;</body>
            <description>Traditional network boundaries have all but disappeared. Enterprises must find new ways to protect their digital assets in a world where SaaS and multi-cloud deployments dominate.</description>
            <image>https://cdn.ttgtmedia.com/rms/onlineimages/location_g1251263484.jpg</image>
            <link>https://www.techtarget.com/searchsecurity/tip/Beyond-the-perimeter-The-shift-to-data-centric-protection</link>
            <pubDate>Mon, 29 Jun 2026 10:53:00 GMT</pubDate>
            <title>Beyond the perimeter: The shift to data-centric protection</title>
        </item>
        <title>Search Security Resources and Information from TechTarget</title>
        <ttl>60</ttl>
        <webMaster>webmaster@techtarget.com</webMaster>
    </channel>
</rss>
