< ciso
brief />
Tag Banner

All news with #human risk management tag

65 articles

Give Yourself Room to Be Human at Work

📝 This week’s Threat Source reflects on balancing personal hardship with professional responsibility and highlights Talos’ stance that family comes first. The author shares a personal experience of supporting an ill relative while feeling pressure to appear indispensable after a prior layoff. The newsletter also outlines defensive cyber strategies for Cybersecurity Awareness Month, recommending behavior-based detections, deception techniques, and strict controls for AI and RMM tools.
read more →

Why Cybersecurity Skills Matter for Tech Students

🔍 Students in technical fields often worry their education lacks practical skills and fear being unprepared for the job market. Experts say this anxiety is normal and can be eased by building identity capital — practical experience, skills, and connections — through internships, courses, and adjacent learning. With digital threats rising and human error driving incidents, basic cybersecurity knowledge is increasingly essential for employers and graduates alike.
read more →

Aviation’s lesson for security in the AI era

✈️ Aviation recognized the human vigilance limit and built machines that act decisively on clear, observable danger rather than asking fatigued humans to be perfect. AI shifts many knowledge workers into that high-load role, erasing obvious phishing cues and increasing opportunities for adversaries to exploit attention decay. Security must focus controls on high-consequence actions — payments, bank-detail changes, credential resets — using mechanisms that trigger on the act itself. The hard part remains earning trust in machines that must judge intent in adversarial contexts without generating prohibitive false alarms.
read more →

How AI Is Reshaping Cybersecurity Roles and Hiring

🛡️ Security teams are restructuring as AI automates routine tasks and shifts responsibilities toward evaluation, governance, and strategic risk work. Leaders report consolidation of functions and changing role definitions, with analysts moving from signal-finding to judging outputs and engineers focusing on system design. Hiring now filters for AI fluency and judgment, while entry-level pathways are shrinking, creating a long-term skills and pipeline risk for organizations.
read more →

Why 'Burnout' Misses the Full Mental Health Picture

🧭 The author challenges the default use of the term burnout in cybersecurity, arguing it often mislabels distinct harms such as secondary traumatic stress, vicarious trauma, and moral injury. Drawing on research from high-trauma professions and personal experience, the piece outlines how each condition differs in cause and remedy. The author previews a forthcoming, peer-deployable framework to help security teams recognize and respond to these harms, urging colleagues to check in on one another.
read more →

North Korean job fraud expands beyond IT roles

🛡️ Researchers report DPRK-linked operators have broadened their employment fraud beyond IT into sales, marketing, and healthcare, using stolen and forged identities, VPNs, and proxy services to secure remote jobs at global firms. Investigations found evidence of PiKVM and USB capture hardware, synthetic personas aided by AI, and coordination via multi-account tools and facilitators who provision laptop farms. Agencies and firms are urged to strengthen identity verification and background checks to detect these sophisticated schemes.
read more →

AI Skills Now Required in Many Cybersecurity Roles

🔍 New research shows AI skills are now required in 28.5% of cybersecurity job adverts across G7 countries for Oct 2025–Mar 2026, up from 14.2% a year earlier. The report from the AI Workforce Consortium highlights an emerging “agentic skill stack,” shifts in role responsibilities, and rising demand for strategic, ethical, and human-centric skills alongside technical expertise.
read more →

Behavior-First Security Training for AI-Driven Risks

🔒 AI has increased employee awareness of cyber risks, but understanding threats is not the same as being ready to respond. The 2025 Security Awareness and Training report shows high awareness but a clear readiness gap: only 40% of organizations say employees are highly prepared for AI-based threats. Fortinet advocates behavior-first, role-based training with short scenario-driven modules to help employees apply judgment, verify requests, protect data, and use AI tools safely.
read more →

Professional athletes, wearables, and privacy risks

🔒 Wearables raise acute privacy concerns for professional athletes because biometric data can directly affect livelihoods. While such data can aid training and injury prevention, access by coaches, teams, or leagues risks misuse in discipline, contract negotiations, and betting markets. Experts warn commercialization could enable gamblers and teams to exploit sensitive signals like sleep or heart rate, and aging or injured players may be most vulnerable. Legal and ethical safeguards remain unresolved.
read more →

Breaking the Cycle of CISO Burnout and Resilience

🔒 When a major cyber incident occurs the CISO becomes the invisible CEO of crisis, making high‑pressure decisions while managing stakeholders and operational recovery. This intense role, combined with limited strategic influence and short tenures, drives burnout and turnover across EMEA. Preparation through exercises, clear measures of risk and a permanent strategic seat at the table are essential to build sustainable resilience.
read more →

Cybersecurity Professionals Reporting Increased Job Strain

🔐 A new report from ISSA and Omdia, surveying 380 practitioners, finds 68% of cybersecurity professionals say their jobs have become harder in the past two years. The study highlights that >70% are excluded from key technology decisions, with rising involvement from IT operations and platform engineering (79%) and tech choices made without cyber input (72%). Work-related stress is significant: 69% report work-life balance challenges and 47% have considered leaving due to stress. Respondents point to leadership commitment, compensation, and career support as key factors for job satisfaction.
read more →

Cybersecurity teams strained by lack of training time

🔒 A global ISC2 study of nearly 1,000 enterprise security leaders finds training budgets have risen but staff lack time to complete upskilling. AI is the top emerging skill organizations are addressing, yet practical barriers—competing workloads, outdated content, and trainer shortages—limit participation. Leaders urge protected, scheduled learning time and managerial support to make training effective.
read more →

Bayer overhauls security awareness for AI era

🧭 At Infosecurity Europe 2026, Bayer CISO Kevin Jones outlined a shift from checklist-based guidance to psychology-first security awareness to counter AI-enabled social engineering. The firm mandates behavior-focused training, ties AI access to role-based modules, and gates agent development behind completion. Bayer is moving SOCs toward supervised automation and updating supplier contracts and governance to enforce AI transparency and controls.
read more →

Chilling Effects: How Fear Is Reshaping Speech

📰 Chilling effects—the self-censorship and restraint people adopt under threat—are spreading across U.S. campuses and institutions in response to the Trump administration’s punitive tactics. Students, professors, journalists, researchers and cultural organizations report altering speech, research and programming to avoid legal, immigration, and institutional reprisals. The authors argue these effects are intentional, part of a broader strategy that leverages surveillance, uncertainty, and abuse of power to produce conformity and weaken democratic checks.
read more →

Incident-hardened CISOs earn greater trust

🔍 ISC2 research of 796 cybersecurity professionals shows that leaders who've managed real, high-profile incidents gain greater credibility. Over three quarters agreed such experience boosts trust, with 35% strongly agreeing. The survey finds outcome or blame of the prior incident is less relevant than the experience itself. Respondents emphasised a blend of technical and strategic skills, plus clear communication and team development.
read more →

Reframing Burnout as a Cybersecurity Risk

🛡️ Cybermindz warns that burnout among cyber professionals should be treated as a measurable operational risk rather than only a wellness concern. Their survey of 101 practitioners found frequent burnout and high emotional exhaustion, while their iRest® training study across 275 participants showed improved sleep, reduced exhaustion and lower attrition risk. Founder Peter Coroneos argues a risk-based framing can secure resources and support resilience.
read more →

One in Eight UK Employees Admit Selling Corporate Logins

🔒 A Cifas survey of 2,000 UK employees at firms with 1,000+ staff found 13% admitted to selling corporate logins in the past year or knew someone who had. The report highlights even higher tolerance among senior managers and executives, with justification rates rising to 32-43% and 81% for business owners. Cifas urges organisations to build fraud-aware cultures and deliver counter-fraud training to curb insider risk.
read more →

CISOs Rethink Hiring as AI Widens Skills Shortage Now

🔒 A persistent cybersecurity skills shortage is forcing CISOs to change hiring, training, and architecture decisions as AI amplifies attack scale and complexity. ISC2’s 2025 workforce study found 95% of organizations report at least one skills gap and nearly 60% call those gaps critical or significant. Leaders are turning to internal upskilling, automation, and role transitions, while balancing trade-offs between best-of-breed tooling, integrated platforms, and multicloud complexity.
read more →

The Fake IT Worker Threat CISOs Must Address Urgently

🛡️ Hiring fraud has produced thousands of fake IT workers who gain trusted access and create serious insider risks. Companies such as Amazon report coordinated attempts tied to state actors, while researchers like SentinelOne and vendors observe AI-enabled deepfakes, synthetic identities and stolen US credentials used to pass recruitment checks. Organizations must treat remote hiring as an access-control problem: strengthen identity screening, enforce staged trust, and deploy continuous post-hire telemetry and behavioral detection.
read more →

Top Sales Challenges Costing MSPs Cybersecurity Revenue

🔍 The article identifies five go-to-market barriers that prevent managed service providers (MSPs) from converting growing cybersecurity demand into predictable revenue. It argues many MSPs emphasize technical findings and frameworks rather than translating risks into business outcomes, leaving security positioned as a cost rather than a strategic investment. Cynomi's GTM Academy Complete Sales Kit is presented as a practical, operator-led playbook to align sales and technical teams, quantify ROI, and expand existing accounts through targeted discovery, scoring, and playbooks.
read more →