< ciso
brief />
Tag Banner

All news with #insider risk tag

57 articles

Pentagon HR system breach exposes millions' data

🔒 The Pentagon's Defense Manpower Data Center (DMDC) confirmed a breach of its human resources management systems that exposed sensitive personal data. The intrusion, active from October 2025 to July 2026, allowed unauthorized access to PII including Social Security numbers, names, dates of birth, contact details, sex, race, and military personnel information for millions. DMDC said it initiated incident response measures and is offering 12 months of free credit monitoring through IDX; affected individuals must enroll by August 19, 2027.
read more →

Most Organizations Face Microsoft 365 Governance Incidents

📊 ShareGate's State of Microsoft 365 report found 77% of global organizations experienced at least one Microsoft 365 governance incident in the past year. The survey of nearly 1,800 IT professionals across nine countries highlights failures such as lingering access for former users, audit and compliance gaps, and sensitive data reaching unintended recipients. Rapid AI adoption and overconfidence in AI controls, plus limited proactive monitoring, are cited as key drivers of increased risk.
read more →

Webinar: Prioritizing Google Workspace Security Controls

🛡️ BleepingComputer will host a live webinar on September 23, 2026, titled "Breach autopsy: How fast-growing companies are breached through Google Workspace" with Material Security. Speakers Rajan Kapoor (VP of Security, Material Security) and Rick Fitzgerald (President, Fireside Consulting LLC) will analyze real documented Google Workspace breaches to show which controls matter most. The session focuses on practical prioritization for lean security teams, covering social engineering, malicious OAuth attacks, response actions in the first hours after a breach, and quick improvements ranked by effort and impact.
read more →

Fraudulent Hires Gain Early Network Access Risks

🔍 A HYPR report finds fraudulent hires obtain corporate credentials and internal access before detection in 42% of cases, with an average of 5.73 days of unmonitored access. The study of 500 US HR executives notes 98% encountered candidate fraud and highlights gaps across screening, interviews and onboarding. HYPR warns that attackers can bypass network breaches by securing legitimate credentials through remote hiring.
read more →

AI Exposes Outdated Security Structures

🔒 Organizations are investing heavily in security but remain stuck in compartmentalized models built for yesterday’s threats. AI-driven impersonation, deepfakes and automated social engineering now traverse digital, physical and operational boundaries, demanding cross-functional verification and unified response pipelines. Without documented processes and integrated tooling across cybersecurity, physical security, HR and legal, response efforts rely on informal relationships and risk critical delays. The next evolution requires threat-driven, integrated programs that pair AI capabilities with human expertise to detect, deter and respond faster.
read more →

US Military Disables Ad Tracking on Government Phones

🔒 Branches of the US military have disabled advertising IDs on government-issued phones and computers after concerns that commercially available location data was being used to target American forces. Senator Ron Wyden and Representative Pat Harrigan pushed the Pentagon for action and sought an inspector general investigation into how location data risks were handled. The move follows warnings about adversary exploitation of commercial location data and broader guidance urging personnel to limit personal device sharing and clean up social media.
read more →

Researching employment scams and insider risks

🔎 Impressive and sobering work highlights the need for rigorous background checks and continuous verification for remote employees. The analysis emphasizes vigilance for signs of insider threats, noting that operatives can blend into organizations for months or years while exfiltrating data or preparing theft. The use of controlled sandbox environments demonstrated how deep visibility and proactive investigation can disrupt such campaigns before they inflict real harm.
read more →

Rising Costs and AI Risks in Data Breaches

🔍 IBM’s 2026 Cost of a Data Breach report, from March 2025 to February 2026, finds the average breach cost rose to $6 million, with AI-enabled attacks comprising one in four incidents. The study of 600 organizations highlights that AI both increases attack speed and, when used defensively, can reduce costs by nearly $2 million. Key issues include poor access controls for AI models, compromised APIs and cloud misconfigurations, and long detection-to-containment times that inflate costs.
read more →

Senior executives driving shadow AI risk in enterprises

🔒 Senior leaders increasingly use unapproved AI tools despite clear security and privacy concerns, creating major headaches for CISOs and IT teams. TrustedTech’s survey found nearly two-thirds of senior decision-makers use shadow AI, often because sanctioned tools are slower or inadequate. Experts say this is a culture and usability problem rather than simple ignorance, and that governance must be modeled from the top while offering secure, usable alternatives.
read more →

Seven Essential Traits of Elite Security Engineers

🔒 Elite security engineers combine technical depth with business awareness and continuous learning. They must be proficient with AI-powered defense tools while understanding how adversaries use AI for phishing, malware, and model attacks. Top engineers think in systems, bridge cross-domain stacks, manage third-party and machine identity risk, and communicate risk clearly to leaders. Adaptability and continuous learning remain critical.
read more →

NHS warns staff over unlawful access to records

🔒 The NHS has warned staff they may face criminal prosecution and career-ending sanctions for accessing patient records without a legitimate reason. Head of the NHS Jim Mackey called such behaviour a “disgraceful breach of patient trust,” and the organisation has launched an awareness campaign alongside guidance for monitoring and preventing unauthorized access. The guidance urges technical controls such as least-privilege, MFA and role-based access, and notes real-time flags in modern electronic patient record systems. High-profile incidents and ICO action have prompted the drive to strengthen detection and deterrence.
read more →

Lessons from underground: combating BEC threats

📣 Flare researchers examined underground forum discussions and tools used to orchestrate Business Email Compromise (BEC) campaigns, finding that attacks extend beyond email to include remote access, cash-out networks, and call centers. Actors target finance and leadership SaaS accounts, increasingly using AI to craft realistic messages and scale operations. Defenders should monitor exposed credentials, enforce MFA, train high-risk staff, and treat multi-channel contacts cautiously.
read more →

AI Adoption Is Accelerating Risks for SMEs

🔒 Small and mid-sized businesses are rapidly adopting AI, often ahead of large enterprises, and this pace is outstripping their ability to govern associated cyber risks. Shadow AI—employees using public tools without oversight—exposes customer data, financial records, and intellectual property, while attackers increasingly exploit these weaker links in supply chains. The author urges owners and CFOs to map AI use, restrict sensitive data, treat AI access like hires, and engage advisors who can secure AI adoption effectively.
read more →

Reframing Trust: A CISO’s Risk-Tiering Model

🔍 Security awareness training that taught employees to spot obvious phishing cues is no longer sufficient. AI-generated attacks and legitimate-looking infrastructure have erased the surface signals users were trained to rely on, making sustained human vigilance unrealistic. The article argues for applying Daniel Kahneman’s fast/slow thinking at the organizational level to map and re-tier processes, keeping fast lanes where justified and revoking them where risk has changed.
read more →

Xsolis data breach compromises 1.4M patient records

🔒 Xsolis, a U.S. healthcare technology provider, detected a targeted phishing attack that led to unauthorized access to parts of its network in January 2026. The company says files containing sensitive customer information—such as names, addresses, dates of birth, insurance details, Social Security numbers, and medical treatment data—were accessed, affecting 1,396,519 individuals. Xsolis contained the breach, engaged external cybersecurity experts, reset user passwords, enhanced monitoring, accelerated employee security training, and is notifying impacted individuals with offered identity monitoring services.
read more →

Tabletop simulates modern retail ransomware mayhem

🔍 The Semperis-run "Enter the War Room" tabletop at Infosecurity Europe simulated a ransomware and reputational attack on fictional supermarket BlueCart. Red-team operators exploited supplier trust, stolen credentials, weak MFA, and poor network segmentation to access AI supply-chain systems and exfiltrate loyalty data. Attackers combined misinformation, deepfakes, fake orders, and payroll disruption to magnify harm, while defenders focused on out-of-band communications, honeypots, and refusing ransom demands to limit impact.
read more →

Cybersecurity Professionals Reporting Increased Job Strain

🔐 A new report from ISSA and Omdia, surveying 380 practitioners, finds 68% of cybersecurity professionals say their jobs have become harder in the past two years. The study highlights that >70% are excluded from key technology decisions, with rising involvement from IT operations and platform engineering (79%) and tech choices made without cyber input (72%). Work-related stress is significant: 69% report work-life balance challenges and 47% have considered leaving due to stress. Respondents point to leadership commitment, compensation, and career support as key factors for job satisfaction.
read more →

Why schools remain favourite cybercriminal targets

🔒 Recent ransomware incidents have shown that schools are year-round targets for cybercriminals. Evanston Township High School closed after an attack disrupted critical systems, while Powys County Council in Wales confirmed student and staff data were accessed at multiple schools. Districts are engaging external experts and notifying authorities, highlighting schools' limited budgets and reliance on networked systems.
read more →

Reframing Burnout as a Cybersecurity Risk

🛡️ Cybermindz warns that burnout among cyber professionals should be treated as a measurable operational risk rather than only a wellness concern. Their survey of 101 practitioners found frequent burnout and high emotional exhaustion, while their iRest® training study across 275 participants showed improved sleep, reduced exhaustion and lower attrition risk. Founder Peter Coroneos argues a risk-based framing can secure resources and support resilience.
read more →

Detecting and Blocking Unsanctioned AI in the Enterprise

🔍 While many organizations intentionally deploy AI to improve productivity, unsanctioned AI is proliferating faster — employees install tools or vendors embed assistants into existing apps. The article defines four AI categories and maps specific detection techniques to each, covering DNS, web gateways/NGFW, EPP/EDR, application and browser controls, and SSPM/identity governance. It flags OAuth consent as a high-risk channel and summarizes admin steps for Microsoft Entra, Google Admin, Salesforce, and ServiceNow to block or restrict app access.
read more →