< ciso
brief />
Tag Banner

All news with #security awareness tag

247 articles · page 2 of 13

DefCon bans smart glasses with recording features

🕶️ DefCon has added smart glasses to its banned list, prohibiting audio- or video-recording eyewear because organizers say there is no reliable way to tell if they are recording, which undermines trust and privacy. Attendees are required to wear non-smart corrective lenses if needed. The ban supplements strict photography rules that limit group shots and encourage portrait settings to blur backgrounds. Growing market activity from Google, Samsung, and Apple has heightened concerns among conferences and CISOs about privacy and data security.
read more →

Why screenshots can no longer be trusted proof

🛡️ Screenshots are merely images of what appeared on a screen and can be easily fabricated or altered. They may provide context but do not reliably prove who created the content or whether an underlying transaction actually occurred. Consumers and businesses should treat screenshots as supporting material only and seek original records, transaction references, or verification from the issuing service. Organizations must update verification processes to avoid fraud, operational costs, and reputational or regulatory harm.
read more →

Security Awareness Shifts From External to Internal Risk

🔒 External threats still drive security training, but organizations increasingly focus on internal risks arising from everyday workflows, cloud apps, collaboration tools, and AI. The 2025 Fortinet Training Institute report shows rising attention to data security, privacy, and AI-related guidance, and finds practical, role-specific training is needed to reduce accidental exposures. Fortinet highlights integrating awareness, simulation, and assessment to build a resilient workforce.
read more →

Ten survival tips for CSOs reporting directly to CEOs

🔒 As CSOs gain prominence, many now report directly to the CEO, shifting expectations from technical stewardship to strategic partnership. Reporting to the CEO grants greater access and influence but demands business-focused skills, clear metrics, and the ability to translate risk into business impact. Experts recommend aligning expectations, documenting goals, prioritizing trust and candor, and treating governance as a strategic enabler to drive organizational resilience.
read more →

MIT expands AI video surveillance across campus

🔍 MIT is deploying over 500 AI-equipped surveillance cameras across academic buildings, residence halls, and outdoor areas, a program costing more than $3 million and installing from November 2025 through September 2026. The cameras, largely Hanwha Wisenet AI models monitored with Ai-RGUS software, can classify faces and objects in real time and detect behaviors such as loitering and crowds, with data retained for up to 30 days unless exceptions apply. Technical specs include 2MP–4K resolution, PTZ capabilities, and classification up to 11 meters.
read more →

Cybersecurity Needs More Prevention, Less Cure

🛡️ Cybersecurity has drifted toward detection-first solutions, yet prevention remains more cost-effective and impactful. The industry invests heavily in visibility, alerting and response—metrics like mean-time-to-detect dominate—while compromise is often treated as inevitable. The author urges renewed emphasis on blocking threats through measures like phish-resistant MFA, segmentation and proactive patching, arguing that prevention reduces noise, lowers long-term costs, and strengthens overall security posture.
read more →

Behavior-First Security Training for AI-Driven Risks

🔒 AI has increased employee awareness of cyber risks, but understanding threats is not the same as being ready to respond. The 2025 Security Awareness and Training report shows high awareness but a clear readiness gap: only 40% of organizations say employees are highly prepared for AI-based threats. Fortinet advocates behavior-first, role-based training with short scenario-driven modules to help employees apply judgment, verify requests, protect data, and use AI tools safely.
read more →

CISOs Warn Executives Lack Understanding of Cyber Risk

🔒 A MetaCompliance report (July 9) based on responses from over 200 European CISOs finds 78% believe C-level executives do not fully grasp cybersecurity risks tied to employee behaviour. The survey highlights fading leadership support for security awareness, with 79% saying backing wanes over time and 40% worried employees share sensitive data with generative AI tools. AI-driven social engineering is cited as a key factor eroding confidence in organisational cyber resilience.
read more →

Top IT Security Certifications Driving Higher Pay

🔍 Foote Partners' 2Q 2026 report ranks the most valuable IT security certifications by average pay premium and recent market value increase. The article lists the top 13 credentials employers value now, describing each certification’s focus, prerequisites, exam length, and typical training and exam costs. It highlights portfolio certifications like GIAC’s GSE and GSP, vendor offerings from Microsoft and Check Point, and vendor-neutral options such as CCSK, ISACA’s CRISC and CISA, and ISC2’s CISSP and CSSLP. Practical, hands-on credentials like GX-CS and OffSec’s PEN-200/OSCP+ are also covered.
read more →

Why CAPTCHAs are Disappearing from the Web

🔍 CAPTCHAs began as distorted text and audio tests but have evolved into image challenges and now experimental gesture videos as AI improves. Google’s new hand-gesture approach records brief camera footage to verify 21 hand key points, raising privacy concerns despite reassurances about data handling. Alternative defenses include behavioral analysis, Cloudflare Turnstile, and hCaptcha, while passkeys offer a passwordless path that can reduce the need for human checks.
read more →

AI Reveals a Validation Gap in Cybersecurity Skills

🔍 The article argues that cybersecurity faces a validation gap rather than a simple skills shortage, stressing that theoretical training and certifications can’t replicate real-world experience. It highlights risks from rapid AI deployment without governance, and notes many organizations lack visibility into AI breaches. The author advocates building continuous, hands-on cyber ranges with AI Proving Grounds, realistic environments, and post-exercise analysis to nurture and validate talent.
read more →

SMB Cyber Readiness: Prioritize the Fundamentals

🔒 AI is reshaping attacker toolkits, but familiar failures—phishing, unpatched vulnerabilities, poor monitoring and weak passwords—remain the primary causes of incidents for SMBs. ESET telemetry and research show AI mainly amplifies these risks rather than replacing them with pervasive, real-time AI malware. Practical mitigations like patch management, identity protection, MFA, password managers and MDR services remain the most effective ways to improve readiness and resilience.
read more →

2026 Cybersecurity Assessment Reveals Resilience Gap

🔍 The 2026 Bitdefender Cybersecurity Assessment surveyed 1,200 IT and security professionals across six countries and found striking contradictions between awareness and operational resilience. Leaders often overestimate visibility into AI use, while frontline staff report gaps. Organizations agree reducing the attack surface is critical but face policy, resource, and disruption concerns. Many report pressure to conceal breaches despite acknowledging the importance of transparency.
read more →

How to Recognize Social Engineering Attacks

🔍 Social engineering exploits human emotions and urgency to trick people into sharing data or taking harmful actions. This article explains common psychological tactics scammers use, such as panic, authority impersonation, guilt, and manufactured urgency, and highlights practical red flags to watch for. It also advises verifying contacts via official channels, pausing before reacting, and seeking a second opinion to avoid manipulation.
read more →

Reframing Trust: A CISO’s Risk-Tiering Model

🔍 Security awareness training that taught employees to spot obvious phishing cues is no longer sufficient. AI-generated attacks and legitimate-looking infrastructure have erased the surface signals users were trained to rely on, making sustained human vigilance unrealistic. The article argues for applying Daniel Kahneman’s fast/slow thinking at the organizational level to map and re-tier processes, keeping fast lanes where justified and revoking them where risk has changed.
read more →

Staffing and AI Shape Modern SOC Challenges

🛡️ The SANS 2026 SOC Survey of 513 security professionals highlights staffing as the top operational challenge for SOCs, with a marked perception gap between practitioners and cyber leaders about hiring and retention. The report shows widespread AI/ML adoption (79%) but limited operational integration (36%), with most teams using vendor tools without customization. It also flags maturity issues in CTI use, OT/IoT coverage, and SOC measurement practices.
read more →

Cybersecurity Professionals Reporting Increased Job Strain

🔐 A new report from ISSA and Omdia, surveying 380 practitioners, finds 68% of cybersecurity professionals say their jobs have become harder in the past two years. The study highlights that >70% are excluded from key technology decisions, with rising involvement from IT operations and platform engineering (79%) and tech choices made without cyber input (72%). Work-related stress is significant: 69% report work-life balance challenges and 47% have considered leaving due to stress. Respondents point to leadership commitment, compensation, and career support as key factors for job satisfaction.
read more →

Cybersecurity teams strained by lack of training time

🔒 A global ISC2 study of nearly 1,000 enterprise security leaders finds training budgets have risen but staff lack time to complete upskilling. AI is the top emerging skill organizations are addressing, yet practical barriers—competing workloads, outdated content, and trainer shortages—limit participation. Leaders urge protected, scheduled learning time and managerial support to make training effective.
read more →

Practical defenses for unauthorized workplace AI

🛡️ This article outlines how enterprises can detect and block unauthorized AI tools—ranging from public chatbots like ChatGPT and Claude to meeting recorders and local model runners. It recommends monitoring NGFW/web-filter logs, EDR/EPP and MDM tools, browser policies, DNS reroutes, and application allowlists. The guidance covers detection indicators (domains, executables, SNI, calendar invites) and concrete lockdown steps (category blocks, policy toggles, OAuth restrictions). Emphasis is placed on offering approved alternatives and using layered controls rather than outright bans.
read more →

Most Firms Admit Deploying Vulnerable Production Code

🔍 A new Checkmarx report found that 95% of CISOs have been pressured to deprioritize or delay reporting security issues, and 75% acknowledged their organizations knowingly deployed vulnerable code to production. Respondents cited compensating controls, deadlines, late detection, and difficulty of fixes as reasons. The survey of 2,350 security professionals also flagged limited remediation rates and rising risks from AI-generated code.
read more →