For years, cybersecurity has had a familiar villain: the external attacker. The hacker breaking through the firewall, stealing credentialsΒ or exploiting an unpatched vulnerability. It is the scenario we have trained for, built defenses aroundΒ and spent decades trying to prevent.
Reading view
Shadow AI: The New Frontier of Shadow IT
As a CISO advisor, I am observing a familiar pattern gaining a new, critical dimension. What we historically identified as "Shadow IT", the use of unapproved SaaS and tools, is rapidly evolving into "Shadow AI."
Employees are increasingly leveraging AI bots for drafting, analysis, code generation and strategic decision-making. While the intention is often to drive efficiency, the lack of governance creates a dangerous risk surface: sensitive data leakage, compliance violationsΒ and the potential for operational decisions based on unverified, AI-generated content.
Trust Nothing: Tips to Secure AI Tools and Agents
So, you have some AI tools or are thinking about deploying them and want to know a bit about securing them.
You are not alone, but there are significant challenges due to the rapidly growing capabilities of AI, and the issues around new types of vulnerabilities we may not be used to thinking of. This is a very challenging area to attempt to secure, but I hope to point you in the right direction and set you up with some resources.
Trust, Verify, Protect: Modernizing Email Security for the Cloud
Picture this: Your company just fell victim to a massive data breach. The culprit wasn't a sophisticated malware strain, a zero-day exploit, or a compromised firewall. It was a perfectly legitimate-looking login from a VPβs account, originating from an unrecognized IP address, requesting an urgent wire transfer via a spotless, text-only email.
ClickFix Social Engineering is Now the Leading Malware Delivery Method
The ClickFix social engineering technique is now the top malware delivery method, according to a new report from ReliaQuest. These attacks trick users into copying a malicious command, then pasting it into a terminal and running it on their computers.
Prompt Injection and the Rise of Agentic Risk
Boxers will often say, the punches that hurt the most arenβt the ones which are thrown with the most force, but the ones they didnβt see coming. I think the same is true in cybersecurity. Itβs not the most advanced technically efficient, 0-day utilizing attacks thatΒ have the biggest impact, but rather those quiet ones. With no malware or suspicious login at three in the morning from an IP address in a country your company has never done business with. No alert fires. No dashboard turns red.