<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[CISO HQ ]]></title><description><![CDATA[CISO HQ is an independent publication for Chief Information Security Officers and cybersecurity leaders. We cover the latest cyber threats, industry trends, funding, M&A, executive moves, and the technologies shaping enterprise security. ]]></description><link>https://www.cisohq.io</link><image><url>https://substackcdn.com/image/fetch/$s_!T2is!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F802272e2-c335-4db1-835a-9f659f19ffba_1280x1280.png</url><title>CISO HQ </title><link>https://www.cisohq.io</link></image><generator>Substack</generator><lastBuildDate>Mon, 17 Aug 2026 21:37:14 GMT</lastBuildDate><atom:link href="https://www.cisohq.io/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Media Network]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[cisohq@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[cisohq@substack.com]]></itunes:email><itunes:name><![CDATA[Media Network]]></itunes:name></itunes:owner><itunes:author><![CDATA[Media Network]]></itunes:author><googleplay:owner><![CDATA[cisohq@substack.com]]></googleplay:owner><googleplay:email><![CDATA[cisohq@substack.com]]></googleplay:email><googleplay:author><![CDATA[Media Network]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[CISO Tips: Stefano Pasotti on Turning Cybersecurity Into Business Resilience]]></title><description><![CDATA[Stefano Pasotti, CISO and ICT Manager at DN Automotive Italy, brings a pragmatic perspective to cybersecurity shaped by years of experience across software development, IT leadership, manufacturing, and logistics.]]></description><link>https://www.cisohq.io/p/ciso-tips-stefano-pasotti-on-turning</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-stefano-pasotti-on-turning</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Mon, 17 Aug 2026 09:32:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!J3NL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J3NL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J3NL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J3NL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J3NL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><a href="https://www.linkedin.com/in/stefano-pasotti-1b507326/"><span>Stefano Pasotti</span></a><span>, CISO and ICT Manager at DN Automotive Italy, brings a pragmatic perspective to cybersecurity shaped by years of experience across software development, IT leadership, manufacturing, and logistics. In his role, he oversees cybersecurity, infrastructure, and digitalization initiatives across European operations, where technologies ranging from WMS and production planning to EDI and IoT must work securely and reliably.</span></p><p><span>For Pasotti, effective security is ultimately about making better business decisions. His approach emphasizes measurable risk reduction over flashy tools, practical incident readiness over compliance theater, and clear communication that translates technical risk into business consequences such as production downtime. In this edition of CISO Tips, he shares his principles for evaluating security investments, preparing teams for incidents, working with vendors, and leading security programs with discipline and reflection.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>...I ask myself how much it actually reduces our risk percentage, how much it really makes us safer. Is it a necessary move, or just a &#8216;cool tool&#8217;?</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>Document everything. An experience that isn&#8217;t written down is an experience lost.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>Training before tools, always. It only takes one wrong click to waste a thousand technology solutions.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>I put risk on the table, not the tool. How much risk is the company willing to take? How much downtime can we afford, and how likely is it to actually happen?</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Some certifications that only exist for the plaque on the wall. If they change nothing in practice, they&#8217;re just time spent &#8212; not security.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>&#8220;If they throw around technical jargon at random, or bombard me with overly detailed questions that make no sense at this stage, I know right away they haven&#8217;t listened. Same if they show no interest in understanding who we are and what we do before pitching us something: they&#8217;re not selling a solution, they&#8217;re selling a script.&#8221;</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I rarely eliminate; I prefer to rebuild. The latest case: incident response policies and runbooks that only existed on paper &#8212; I rewrote them to be truly operational, not just a compliance exercise.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Stopping to think. Speed is critical, so the temptation is to act immediately &#8212; but acting without a moment&#8217;s reflection can cause more damage than the incident itself.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>If it happened right now, would we actually know what to do, or would we be improvising?&#8221;</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I translate everything into production downtime. Once the risk is clear to everyone, then we talk solutions.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>Stop, reflect, then take action.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[What Bloom Security's Extension Resurrection Research Means for Extension Pack Governance]]></title><description><![CDATA[Ask a security team to name the least governed system in the enterprise and few will say &#8220;the developer laptop.&#8221; They should.]]></description><link>https://www.cisohq.io/p/what-bloom-securitys-extension-resurrection</link><guid isPermaLink="false">https://www.cisohq.io/p/what-bloom-securitys-extension-resurrection</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Thu, 13 Aug 2026 14:03:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lBH5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lBH5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lBH5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 424w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 848w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 1272w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lBH5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png" width="1456" height="1089" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1089,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lBH5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 424w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 848w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 1272w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Ask a security team to name the least governed system in the enterprise and few will say &#8220;the developer laptop.&#8221; They should. It changes daily. Extensions, packages, plugins, and AI tooling get assembled on the fly, rarely pass through review, and remain largely invisible to endpoint detection.</span><a href="https://bloom.security/"><span> Bloom Security</span></a><span>&#8216;s latest research turns that abstraction into a measurable exposure across roughly half a million downloads and more than 750 extension packs.</span></p><p><span>The vulnerability is called Extension Resurrection, and it affected both Open VSX and the Visual Studio Code Marketplace. What makes it worth a board-level conversation is not the exploit chain. It is the trust model the exploit chain borrows.</span></p><h2><span>One Install Decision, Ten Unreviewed Consequences</span></h2><p><span>When a developer installs an extension pack, they are not installing one tool. They are accepting a curated list of dependencies, every one of them granted deep access to the filesystem, running processes, and the network.</span></p><p><span>The pack was reviewed. Its contents were not. Bloom Security identifies that gap between what a user trusts and what actually gets installed as precisely where the attack lives.</span></p><p><span>Extension packs therefore behave as a risk multiplier. A single approval quietly expands the attack surface by five, ten, or more components that nobody explicitly evaluated. The research is unambiguous about the required posture change: treat extension packs within the same threat model as direct extension installs, and review the bundle manifest rather than the pack name.</span></p><h2><span>Volume Is Working Against Defenders</span></h2><p><span>Scale deserves attention here. In the first six months of 2026, the VS Code Marketplace nearly doubled in size. Between the two marketplaces, roughly 1,400 new extensions ship every single day. AI tooling has let teams move faster than before, and the output is an explosion of new software landing continuously.</span></p><p><span>Every developer runs at least one extension outside the defaults of their chosen IDE. That baseline was never the interesting part. The interesting part is that the catalog defenders would need to vet is growing faster than any manual review process can absorb.</span></p><h2><span>What the Attack Actually Required</span></h2><p><span>The technical prerequisites were modest, which is the point.</span></p><p><span>Both marketplaces permitted packs to reference extensions that did not exist. Bloom Security calls those dangling references Shadow Dependencies, and they arise either when a pack is mirrored to Open VSX without one of its bundled components, or when an extension referenced by a live pack is deleted.</span></p><p><span>Extensions are identified by publisher or namespace paired with an extension ID, so hijacking one means claiming the original publisher or namespace rather than just an available name. Both platforms allowed open registration of those names, including names that published software actively referenced.</span></p><p><span>Bloom Security&#8217;s scan quantified the field. Open VSX: 94 of 321 packs carried a shadow dependency with an unregistered namespace. VS Code Marketplace: 677 of 4,179 packs carried a shadow dependency, 60 of them under an unregistered publisher. Two of those were used for a live proof: prettify-json under mohsen1 on Open VSX, and control-snippets under svipas on the VS Code Marketplace.</span></p><p><span>Open VSX initially rejected an exact version match because it already held a ghost record from a mirrored manifest. Incrementing the version resolved that instantly, since packs reference bundled extensions by ID without pinning versions.</span></p><h2><span>The Part That Should Worry Risk Owners</span></h2><p><span>Installation was never the only vector. Auto-update configuration for bundled extensions is inherited from the pack, and the default is enabled. Anyone who installed an affected pack in the past, under default settings, could receive attacker-controlled code on a routine update.</span></p><p><span>Extensions run with Node.js host access. They read and write files, spawn child processes, and reach the network. Bloom Security&#8217;s assessment is that an extension is not sandboxed in any meaningful sense with respect to code execution, so a malicious install is functionally remote code execution on the machine.</span></p><p><span>That machine belongs to a software developer. Source repositories, cloud credentials, deployment pipelines, internal tooling. Applying a deliberately conservative estimate that half of the affected downloads had auto-update on, the research arrives at roughly a quarter of a million compromised developer endpoints within a day.</span></p><h2><span>The Control Set Being Recommended</span></h2><p><span>Bloom Security lists three capabilities security teams need, and none of them are novel. The difficulty is that most organizations lack all three for this surface.</span></p><p><span>The first is inventory of installed extensions and packs across the organization. The second is visibility into IDE configuration, specifically whether auto-update is enabled and for which extensions, plus whether policy limits installs to a pre-approved list. The third is extension scanning that audits capabilities, security posture, and risk for each installed extension, treated as a continuous process covering every new version rather than a one-time exercise.</span></p><p><span>For developers, the guidance is narrower. Auto-updated extension packs behave like auto-updates for every extension they bundle. Install once does not mean static forever. Periodically review what the IDE has actually installed, not just what was chosen.</span></p><h2><span>Vendor Response as a Governance Signal</span></h2><p><span>Bloom Security reported to the Eclipse Foundation on February 5, 2026, and to Microsoft via MSRC on February 17, 2026.</span></p><p><span>Eclipse assigned all at-risk namespaces to the open-vsx account within hours, then implemented a pre-publication check now blocking packs with non-existent bundled extensions and extensions with non-existent dependencies. Triage also surfaced that extension dependencies were vulnerable to the same technique. Bloom Security describes the experience as very positive and points to Open VSX as a model for marketplace response.</span></p><p><span>Microsoft&#8217;s path was longer. MSRC&#8217;s first assessment was Moderate severity on the basis that the Visual Studio Marketplace already had publisher resurrection prevention in place. Bloom Security disputed that with video evidence and additional examples of re-registering removed publishers, and the case was reopened. Engineering subsequently confirmed a partial fix from October and stated that prevention had covered admin actions since October and user actions only as of that month. The two stages landed in October 2025 and June 2026 respectively, documented at github.com/microsoft/vsmarketplace/discussions/1708. Microsoft acknowledged the completion arrived after the report. The eight-month interval between stages left real exposure for user-action resurrection, which Bloom Security demonstrated.</span></p><p><span>The broader lesson does not stop at extensions. The endpoint attack surface expands constantly through installs, updates, configuration drift, and AI tools pulling in fresh dependencies. Bloom Security&#8217;s argument is that everything running there needs to be continuously known, vetted, and governed as an ongoing process rather than a periodic audit. Organizations without that visibility, the research concludes, sit a few clicks away from an incident.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Jörg Scheiblhofer on Analytical Security Leadership]]></title><description><![CDATA[Cybersecurity leadership is rarely about having the most tools or the most elaborate security program.]]></description><link>https://www.cisohq.io/p/ciso-tips-jorg-scheiblhofer-on-analytical</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-jorg-scheiblhofer-on-analytical</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 12 Aug 2026 09:40:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!f1_n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f1_n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f1_n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f1_n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f1_n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Cybersecurity leadership is rarely about having the most tools or the most elaborate security program. For </span><a href="https://www.linkedin.com/in/joerg-scheiblhofer/"><span>J&#246;rg Scheiblhofer</span></a><span>, Chief Information Security Officer at ORF, effective security starts with understanding the organization&#8217;s requirements, processes, and actual risk before deciding which technologies or controls are needed. His approach emphasizes analytical thinking, consistency, and a clear understanding of the potential impact of security decisions.</span></p><p><span>In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Scheiblhofer shares his perspective on making better decisions under pressure, communicating cyber risk to executives through relatable analogies, and avoiding assumptions during critical incidents. From assessing the real situation in the first minutes of an attack to tailoring risk discussions for the board, his advice reflects a practical philosophy: strong cybersecurity requires sound analysis, clear communication, and a human approach.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first&#8230;&#8221;</span></h3><p><span>&#8230;you have to think about process and your requirements &#8220;</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>There are no exceptions on suspicion without an analytical basis and certainly no general exceptions.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>It is not a single sentence; rather, it is a presentation, tailored to the target audience, of the risks that exist or may arise if measures are not implemented.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>Has he dealt with his potential customer?</span></p><p><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it? -</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Accurately assessing the actual situation. In the heat of the moment, this is often overlooked. What&#8217;s one question every CISO should ask their team this week?</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I like to use the creation of analogies from everyday life. In a way, a language in pictures, so that management can imagine something better.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>1.) remain consistent 2.) adopt an analytical approach 3.) tailor communication to the target audience 4.) assess the risk and potential damage 5.) remain human</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-maurizio-imperadore-on"><span>CISO Tips: Maurizio Imperadore on Resilience, Identity and Cutting Security Noise</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer"><span>CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning"><span>CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on"><span>CISO Tips: Carlos Garc&#237;a Batista on Turning Cybersecurity Into Operational Resilience</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking"><span>CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Stephen Wadsworth Named VP of Sales at Reclaim Security as Company Scales Exposure Remediation Business]]></title><description><![CDATA[Cybersecurity companies often reach an inflection point when technology validation gives way to the harder task of building a repeatable commercial engine.]]></description><link>https://www.cisohq.io/p/stephen-wadsworth-named-vp-of-sales</link><guid isPermaLink="false">https://www.cisohq.io/p/stephen-wadsworth-named-vp-of-sales</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Tue, 11 Aug 2026 12:39:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!unE8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!unE8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!unE8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!unE8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!unE8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!unE8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!unE8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!unE8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!unE8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!unE8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!unE8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Cybersecurity companies often reach an inflection point when technology validation gives way to the harder task of building a repeatable commercial engine. For </span><a href="https://reclaim.security"><span>Reclaim Security</span></a><span>, that stage is arriving as the company seeks to expand adoption of its approach to automated exposure remediation.</span></p><p><span>The company has appointed Stephen Wadsworth as Vice President of Sales, giving the veteran cybersecurity sales executive responsibility for Reclaim&#8217;s U.S. go-to-market operation. Based in Boston, Wadsworth brings nearly two decades of experience building sales organizations at security companies, including several that were later acquired.</span></p><p><span>His career includes an early sales leadership role at Luminate Security, which was acquired by Symantec, and most recently leading sales at Entitle through its acquisition by BeyondTrust. He has also held leadership positions at Threat Stack, Banyan Security and Cyolo.</span></p><p><span>For Reclaim, the move comes at a time when the company is seeking to capitalize on enterprise demand for technologies that can do more than identify security problems.</span></p><h2><span>The Remediation Gap</span></h2><p><span>The security industry has become increasingly effective at finding exposures. The resulting challenge is that security teams can be left with large inventories of issues requiring attention, even as the tools generating those findings continue to improve.</span></p><p><span>Reclaim has built its platform around addressing that gap. Its AI Security Engineer continuously discovers exposures across endpoint, email, identity, browser and cloud environments, then plans business-aware fixes and executes them.</span></p><p><span>The company describes its approach as preemptive exposure remediation, with the technology designed to operate across an organization&#8217;s existing security stack. Instead of adding another dashboard, Reclaim aims to make the security tools enterprises already own more effective by helping turn findings into implemented fixes.</span></p><p><span>Wadsworth sees that distinction as increasingly important to security leaders.</span></p><p><span>&#8220;I&#8217;ve spent my career skating to where the puck is going,&#8221; said Wadsworth. &#8220;CISOs don&#8217;t need more security tools, they need more value from what they already pay for. Every CISO I&#8217;ve spoken to in the last 6&#8211;12 months is tired of being told they have more problems to fix. The market is hungry for outcomes. As adversaries increasingly abuse frontier models at scale, continuous, real-time prevention needs to be the focus &#8212; and Reclaim is built to turn findings into implemented fixes without disruption.&#8221;</span></p><h2><span>Why Wadsworth&#8217;s Background Matters</span></h2><p><span>The new sales chief arrives with a r&#233;sum&#233; closely tied to emerging cybersecurity companies moving toward larger strategic outcomes.</span></p><p><span>At Luminate Security, Wadsworth was an early sales leader before the company was acquired by Symantec. At Entitle, he most recently led sales before its acquisition by BeyondTrust. His experience also spans Threat Stack, Banyan Security and Cyolo.</span></p><p><span>That background is relevant to Reclaim as it builds its U.S. revenue operation. The company is not simply adding a sales executive to an established business; it is looking to scale commercial momentum around a category it believes is becoming increasingly important to enterprise security teams.</span></p><p><span>&#8220;Stephen has built the sales organizations behind some of the most consequential security companies of the last decade,&#8221; said Barak Klinghofer, co-founder and CEO of Reclaim Security. &#8220;The industry has spent ten years getting better at finding and prioritizing exposures and barely moved on fixing them. Visibility without remediation is noise. With Stephen leading sales, we&#8217;re scaling the team that fixes what everyone else only finds.&#8221;</span></p><h2><span>Reclaim&#8217;s Next Growth Phase</span></h2><p><span>The appointment follows a period of funding and customer momentum for Reclaim. In March 2026, the company announced a $20 million Series A led by Acrew Capital, with participation from QP Ventures and Ibex Investors, bringing its total funding to $26 million.</span></p><p><span>Reclaim has also published customer results involving Telit Cinterion, Pine Gate Renewables, Competitive Power Ventures and Aqua Security, among others. The company says its customers use the platform to turn lists of findings into implemented fixes, typically demonstrating value within a 10-day proof of value.</span></p><p><span>That customer proposition sits at the center of Reclaim&#8217;s growth strategy. Rather than asking enterprises to add another layer of security visibility, the company is positioning remediation as the outcome that matters.</span></p><p><span>Wadsworth&#8217;s appointment gives Reclaim an executive whose previous experience includes building sales organizations during pivotal moments for security companies. His immediate task will be to translate that experience into growth for a company betting that the next evolution of exposure management will be measured less by what security teams discover and more by what they successfully eliminate.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Maurizio Imperadore on Resilience, Identity and Cutting Security Noise]]></title><description><![CDATA[Maurizio Imperadore, Head of the Cybersecurity Team at Connect S.p.A., brings a network engineering background to the CISO role, with experience spanning telecommunications, network design, Cisco and HP systems, and Session Initiation Protocol (SIP).]]></description><link>https://www.cisohq.io/p/ciso-tips-maurizio-imperadore-on</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-maurizio-imperadore-on</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Sun, 09 Aug 2026 12:16:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!I4ci!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!I4ci!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!I4ci!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!I4ci!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!I4ci!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><a href="https://www.linkedin.com/in/maurizio-imperadore-0561787/"><span>Maurizio Imperadore</span></a><span>, Head of the Cybersecurity Team at Connect S.p.A., brings a network engineering background to the CISO role, with experience spanning telecommunications, network design, Cisco and HP systems, and Session Initiation Protocol (SIP). His approach to cybersecurity is grounded in operational resilience: making the most of existing security investments, maintaining strong identity controls, and ensuring security decisions are tied to business continuity.</span></p><p><span>In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Imperadore shares practical lessons on where security teams should focus their time and resources. From enforcing zero exceptions on MFA to replacing lengthy risk reports with a single-page executive dashboard, his advice centers on reducing noise, communicating risk in financial terms, and building a security program that protects the operations the business depends on most.</span></p><h3><span>Before you buy any new security tool, first&#8230;</span></h3><p><span> Ensure you are fully utilizing the native security capabilities of your existing stack.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>Zero exceptions on MFA and identity verification, even for emergency admin actions.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>The 80/20 rule: 80% on core operational resilience and visibility, 20% on new security innovation.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>&#8220;This isn&#8217;t an operational expense; it&#8217;s the cost of keeping our core revenue streams online.&#8221;</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Outdated annual compliance training that tick boxes without changing user behavior.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>If they can&#8217;t clearly articulate the specific problem they solve without using buzzwords in the first minute.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>Eliminated lengthy monthly risk slide decks and replaced them with a dynamic single-page executive dashboard.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Pausing to establish clear incident roles and dedicated communication channels before touching systems.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>&#8220;Which alert or process is generating the most noise and wasting your time?&#8221;</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>Translating technical vulnerabilities directly into financial downtime: &#8220;If X fails, core operations stop for Y hours at a cost of $Z.&#8221;</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>Prioritize relentlessly, delegate, rest daily.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer"><span>CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning"><span>CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on"><span>CISO Tips: Carlos Garc&#237;a Batista on Turning Cybersecurity Into Operational Resilience</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking"><span>CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning"><span>CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust]]></title><description><![CDATA[For many security leaders, the biggest challenge isn&#8217;t keeping up with the latest threats; it&#8217;s ensuring cybersecurity remains aligned with business priorities.]]></description><link>https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 05 Aug 2026 09:04:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!zrMx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zrMx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zrMx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zrMx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zrMx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>For many security leaders, the biggest challenge isn&#8217;t keeping up with the latest threats; it&#8217;s ensuring cybersecurity remains aligned with business priorities. </span><a href="https://www.linkedin.com/in/jigar-cxo/"><span>Jigar Shah</span></a><span>, Chief Information Security Officer at Medusind, believes the most effective CISOs are those who focus less on accumulating security technologies and more on solving real business problems. Drawing on more than two decades of leadership across healthcare, financial services, banking, retail, and consulting, Shah has built his career around connecting cybersecurity, technology, business strategy, and governance.</span></p><p><span>In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Shah shares the principles that shape his leadership approach, from evaluating vendors based on business outcomes rather than product features to eliminating &#8220;security theater&#8221; that adds complexity without reducing risk. He also explains why trust, not technology, is the foundation of every successful security program, and why CISOs should spend far more time preventing tomorrow&#8217;s incidents than reacting to today&#8217;s.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>&#8220;...understand the business problem you&#8217;re trying to solve.&#8221;</span></p><p><span>Technology should never drive strategy. If you can&#8217;t explain the business outcome in one sentence, you probably don&#8217;t need another security tool.</span></p><p><span>&#8220;Buy fewer tools. Solve more problems.&#8221;</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>&#8220;Never bring me a security problem without at least one business-focused solution.&#8221;</span></p><p><span>I don&#8217;t want my team to be known for just identifying risks. I want them to be known for enabling the business safely.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>I follow a simple rule: 80% enabling the business, 20% fighting fires.</span></p><p><span>If I&#8217;m spending more time reacting than enabling, we&#8217;re investing in symptoms instead of resilience.  Spend 80% preventing tomorrow&#8217;s incidents or issues that can become an incident and 20% responding to today&#8217;s.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>I&#8217;m not asking you to fund cybersecurity; I&#8217;m asking you to protect the business strategy you&#8217;ve already approved. That changes the conversation from cost to business enablement.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Security theater. Anything that looks impressive but doesn&#8217;t measurably reduce risk or improve resilience. Examples include reports nobody reads, meetings without decisions, and controls that create more friction than value.</span></p><p><span>&#8220;If it only checks a box, cut it.&#8221;</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>I ask three questions:</span></p><ol><li><p><span>What business problem do you solve?</span></p></li><li><p><span>Can you prove measurable outcomes? Give an example of how you turned things around for your customers?</span></p></li><li><p><span>Why are you different from the ten vendors I met this month?</span></p></li></ol><p><span>If they answer with features instead of outcomes, the meeting is probably over.</span></p><p><span>&#8220;Features sell products. Outcomes earn meetings.&#8221;</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I eliminated long weekly status meetings. We replaced them with a live dashboard and a 15-minute decision meeting. The goal isn&#8217;t to exchange information. The goal is to make decisions and have an action plan with outcomes.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Defining who&#8217;s making decisions. Everyone starts investigating. Very few establish clear incident command. Without decision ownership, technical excellence becomes organizational chaos.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>&#8220;If you were attacking us tomorrow, where would you start?&#8221; It changes the conversation from compliance to adversarial thinking.</span></p><p><span>Alternative: &#8220;What are we doing today simply because we&#8217;ve always done it?&#8221;</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I rarely talk about vulnerabilities. I ask: &#8220;What happens to revenue, customers, operations, or reputation if this control fails?&#8221; Executives don&#8217;t invest in CVEs. They invest in protecting business outcomes. I frame it in business results, risks, and revenue.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>&#8220;Build trust before a crisis happens.&#8221; Because that&#8217;s really the essence of the CISO role. Technology changes. Threats evolve. But the ability to build trust with executives, employees, customers, regulators, and your team is what ultimately determines your success.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning"><span>CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on"><span>CISO Tips: Carlos Garc&#237;a Batista on Turning Cybersecurity Into Operational Resilience</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking"><span>CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning"><span>CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first"><span>CISO Tips: Paul Blahusch on Business Success Coming First</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Upwind First to Expose One of the Largest Open-Source Supply Chain Threats Targeting JavaScript ]]></title><description><![CDATA[The software supply chain has become one of cybersecurity&#8217;s most attractive targets, largely because attackers no longer need to compromise thousands of organizations individually.]]></description><link>https://www.cisohq.io/p/upwind-first-to-expose-one-of-the</link><guid isPermaLink="false">https://www.cisohq.io/p/upwind-first-to-expose-one-of-the</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Tue, 04 Aug 2026 14:55:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DE3b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DE3b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DE3b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DE3b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DE3b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>The software supply chain has become one of cybersecurity&#8217;s most attractive targets, largely because attackers no longer need to compromise thousands of organizations individually. Instead, infiltrating a single trusted dependency can create a ripple effect across countless development environments. That scenario played out this week when </span><a href="http://upwind.io"><span>Upwind</span></a><span> became the first to publicly report a malicious release of the widely used npm package Keyv, warning developers that the compromise had the potential to impact a massive portion of the JavaScript ecosystem.</span></p><p><span>The discovery centered on keyv@6.0.0, a malicious version of one of npm&#8217;s most heavily used packages. With approximately 154 million weekly downloads, Keyv serves as a core dependency for thousands of JavaScript applications, making any compromise particularly significant. Upwind&#8217;s findings prompted immediate guidance for organizations to remove the affected version and investigate whether sensitive credentials had been exposed.</span></p><h2><span>A Malicious Update Hidden Inside a Trusted Package</span></h2><p><span>According to Upwind, the compromised release introduced a previously unseen preinstall hook that executed automatically during installation. Rather than changing the package&#8217;s expected functionality, the attackers inserted an obfuscated loader designed to run before developers ever began using the library.</span></p><p><span>The loader downloaded the Bun runtime from GitHub Releases before launching a bundled payload capable of harvesting credentials from developer workstations and CI/CD environments. Among the targeted secrets were AWS credentials, GitHub tokens, npm authentication tokens, and HashiCorp Vault credentials, giving attackers a potential pathway into both development infrastructure and cloud environments.</span></p><p><span>&#8220;What makes this incident particularly significant is the package&#8217;s reach,&#8221; Upwind wrote in its public disclosure. &#8220;With approximately 154 million weekly downloads, keyv is a foundational dependency used across thousands of JavaScript projects, dramatically increasing the potential blast radius of the compromise.&#8221;</span></p><p><span>That reach transformed what could have been an isolated package compromise into an incident with ecosystem-wide implications.</span></p><h2><span>The Attack Expanded Beyond Keyv</span></h2><p><span>As researchers continued analyzing the incident, evidence emerged that the campaign had spread beyond the original Keyv release. Multiple malicious package versions were identified across the npm ecosystem, suggesting that stolen publishing credentials enabled attackers to distribute poisoned releases through additional packages.</span></p><p><span>Because package versions and &#8220;latest&#8221; tags changed rapidly as maintainers responded, security experts advised organizations to inspect their resolved dependency versions, lockfiles, and software bills of materials rather than relying solely on package registry listings.</span></p><p><span>The malware reportedly went well beyond credential theft. Analysis indicated it could collect authentication tokens, cloud credentials, private keys, and other sensitive information from developer machines and CI/CD runners. Some reports also described functionality capable of republishing compromised packages using stolen npm publishing access, increasing the possibility of automated propagation throughout the ecosystem.</span></p><p><span>Although the total number of affected packages continued evolving throughout the response, the campaign demonstrated how quickly attackers can leverage trusted software distribution channels once publisher credentials are compromised.</span></p><h2><span>Trust Alone Is No Longer a Security Strategy</span></h2><p><span>One of the more concerning aspects of the incident is that the compromised package reportedly passed through legitimate software release workflows.</span></p><p><span>Modern software supply chain protections, including provenance and build attestations, can verify how software is built, but they cannot always determine whether malicious code entered the development pipeline before those trusted processes began. As a result, organizations increasingly need visibility into dependency behavior&#8212;not just whether software was signed or built correctly.</span></p><p><span>The incident also reflects a broader shift in attacker strategy. Instead of focusing exclusively on exploiting deployed applications, threat actors are increasingly targeting developer tools, package managers, and build environments where a single successful compromise can reach thousands of downstream users.</span></p><h2><span>A Reminder That Popular Packages Are Valuable Targets</span></h2><p><span>For organizations using Keyv, Upwind urged immediate action: remove keyv@6.0.0, pin dependencies to a verified clean version, rotate credentials if the malicious release was installed, and review CI/CD pipelines, lockfiles, and SBOMs for exposure.</span></p><p><span>&#8220;This incident is another reminder that highly trusted, high-volume dependencies remain prime targets for supply-chain attackers-and that a single malicious release can have ecosystem-wide consequences,&#8221; Upwind said.</span></p><p><span>The discovery serves as another reminder that software supply chain security extends beyond vulnerability management. Even trusted, widely adopted open-source components can become attack vectors when release pipelines or publisher credentials are compromised. By identifying the malicious Keyv release early, Upwind&#8217;s disclosure highlighted both the speed at which these campaigns can unfold and the importance of continuously monitoring the behavior of software dependencies, not just the software itself.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions]]></title><description><![CDATA[Andy Curtis is an experienced cybersecurity leader and CISO with a background in information security implementation, architecture, and strategic security programs across government, finance, and enterprise environments.]]></description><link>https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Tue, 04 Aug 2026 10:01:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WWjw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WWjw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WWjw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WWjw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WWjw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><a href="https://www.linkedin.com/in/c1andrew/"><span>Andy Curtis</span></a><span> is an experienced cybersecurity leader and CISO with a background in information security implementation, architecture, and strategic security programs across government, finance, and enterprise environments. As CISO at Gadget Access, he has worked across frameworks including ISO 27001, NIST, and Essential Eight, helping organizations strengthen their security posture while aligning cyber initiatives with broader business priorities. His approach combines hands-on technical expertise with a strong understanding of risk, governance, compliance, and the realities of operating security programs at scale.</span></p><p><span>In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Curtis shares a practical perspective on making cybersecurity more effective by connecting technical decisions to measurable business outcomes. From avoiding unnecessary security-tool sprawl and translating vulnerabilities into executive-level risk, to testing incident response plans and proving that backups can actually support recovery, his advice centers on one core principle: security teams should focus less on collecting tools and metrics and more on reducing material risk. For Curtis, that means learning to communicate in the language of business, making informed trade-offs, and ensuring that cybersecurity decisions ultimately support the organization&#8217;s ability to operate and recover.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>...prove it will reduce a material risk&#8212;and prove you can operate it.</span></p><p><span>The license fee is only the admission price. The real cost includes implementation, integration, data ingestion, training, tuning, support, additional infrastructure, operational headcount and the time required to investigate whatever the new dashboard turns red.</span></p><p><span>I am a supporter of best-of-breed technology when an organization can afford best-of-breed integration and operations. Otherwise, you can end up with several excellent products collaborating mainly through their invoices.</span></p><p><span>Sometimes a well-integrated platform delivers a better overall outcome than a collection of individually superior tools with gaps between them. Equally, consolidating everything onto one platform simply because the vendor has an attractive bundle can introduce lock-in and concentration risk. The right answer depends on coverage, interoperability, operational maturity and the risk being treated&#8212;not which logo appears highest on an analyst diagram.</span></p><p><span>A vendor-sponsored 2025 survey of 1,000 executives found that participating organizations were using an average of 83 security solutions from 29 vendors. That does not prove platforms are always better, but it does confirm that integration overhead is not something CISOs have collectively imagined after too much coffee.</span></p><p><span>The CISO&#8217;s job is not to assemble the most impressive security-tool collection. It is to achieve the greatest sustainable reduction in risk for the money available.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>Everyone in the security team must be able to explain their work in business, executive, and risk language.</span></p><p><span>I do not expect every analyst or engineer to become a miniature CFO. I do expect them to understand the business service they are protecting, the risk scenario they are changing, the consequence of doing nothing, and the decision required from management.</span></p><p><span>&#8220;We have 4,700 vulnerabilities&#8221; is information.</span></p><p><span>&#8220;Three internet-facing vulnerabilities create a credible path into the customer payments environment, and the remediation owner needs an approved outage before Friday&#8221; is decision support.</span></p><p><span>A technical finding without business context is unfinished work.</span></p><p><span>This is not about dumbing down the technical truth. It is about expressing that truth in the operating language of the audience. Executives generally think in terms of objectives, exposure, obligations, trade-offs, money, customers and accountability. Security professionals should be able to move between those concepts and the technical detail without losing accuracy in either direction.</span></p><p><span>Current ASD guidance explicitly treats business acumen, communication and relationship-building as core CISO capabilities, and expects cyber reporting to translate security issues into operational, financial and legal risk. I apply that expectation across the team rather than reserving it for whoever attends the board meeting.</span></p><p><span>CVSS 9.8 may be technically correct. It is rarely a complete executive sentence.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>My starting ratio is 50:50.</span></p><p><span>Roughly half of the program should be driven top-down by material business risks: critical services, crown-jewel data, regulatory obligations, credible threat scenarios and the consequences the organization genuinely cannot tolerate.</span></p><p><span>The other half should be driven bottom-up by operational reality: unsupported systems, excessive privileges, weak configurations, failing backups, poor asset visibility, incomplete logging and all the low-hanging fruit that has somehow remained on the tree for six budget cycles.</span></p><p><span>The top-down half prevents the security team from becoming extremely efficient at fixing the wrong things. The bottom-up half prevents the enterprise risk register from becoming a beautifully formatted description of controls that do not actually work.</span></p><p><span>NIST CSF 2.0 reinforces this linkage: practitioners implement and measure risk treatment activities, while executives integrate cyber risk information with the organization&#8217;s wider enterprise risk decisions. Both views are necessary because neither strategy nor telemetry is sufficient by itself.</span></p><p><span>I use industry spending benchmarks and breach-cost studies as reasonableness checks, not as allocation formulas. &#8220;Our peers spend 12 percent&#8221; does not tell me whether our identity architecture is sound, whether our backups restore or whether half the estate is running on something last patched during the Howard government.</span></p><p><span>The ratio is a compass, not a religion. It should move as risks, maturity and business priorities change. Incidents, in particular, have very little respect for resource-allocation models.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>&#8220;It is cheaper than one material breach every five years.&#8221;</span></p><p><span>That line gets attention. It does not, by itself, earn approval.</span></p><p><span>The next slide needs to contain the arithmetic: the credible scenario, the business services affected, the potential outage, the likely response and recovery cost, the customer and regulatory consequences, and how much the proposed investment will reduce either the likelihood or the impact.</span></p><p><span>The argument should not be, &#8220;Cyber incidents are expensive, therefore approve everything in my spreadsheet.&#8221; It should be, &#8220;Here is a plausible loss scenario, here are the available treatment options, here is what each option costs, and here is the residual exposure under each choice.&#8221;</span></p><p><span>IBM&#8217;s 2025 study reported a global average breach cost of US$4.4 million across the organizations studied. That is useful context, but a generic worldwide average is not a substitute for understanding your own economics. A CFO should see the potential interruption to your services, your revenue, your customers and your obligations&#8212;not an impressive-looking number borrowed from somebody else&#8217;s breach.</span></p><p><span>Fear may secure a meeting. Credible options, quantified assumptions and transparent trade-offs secure a budget.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Raw technical reporting to executives who cannot reasonably act on it.</span></p><p><span>I would immediately cut the 40-page reports filled with vulnerability counts, firewall events, malware detections, phishing statistics, and screenshots from security products. That information may be valuable to security operators, engineers and control owners. It is usually not useful in its raw form to a board or executive committee.</span></p><p><span>Executive reporting should answer a smaller set of harder questions:</span></p><p><span>What important business service is exposed? What is the credible scenario? Is the exposure increasing or decreasing? Are the relevant controls working? Who owns the treatment? What decision or intervention is required, and by when?</span></p><p><span>The underlying technical evidence should still exist. It should simply be presented at the level where someone can use it.</span></p><p><span>AICD guidance recommends that board reporting go beyond isolated technical measures and traffic lights to include risk outcomes, relevant threats and trend information. ASD guidance similarly expects reporting to be structured around business functions and to cover risk profiles, key systems, uplift activity, incidents and expected returns on security investment.</span></p><p><span>A board pack is not a SIEM export wearing a tie.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>I ask one question:</span></p><p><span>&#8220;In one minute, explain the problem you believe we have, the measurable outcome you will improve, and what we can stop doing if your product works.&#8221;</span></p><p><span>A good vendor will have asked enough questions to understand the environment, the existing controls, the operating model, the constraints and the outcome we are trying to achieve.</span></p><p><span>They will also be able to discuss implementation effort, dependencies, staffing requirements, data quality, integration limitations and where their product is not the answer.</span></p><p><span>A weak vendor will respond with the company origin story, three analyst quotations, the phrase &#8220;single pane of glass&#8221; and an urgent announcement that artificial intelligence has changed everything since Tuesday.</span></p><p><span>I am also interested in whether the proposed solution replaces or simplifies anything. Adding one more console, agent, data lake, workflow and set of alerts is not necessarily an improvement simply because the demonstration contains a colorful attack graph.</span></p><p><span>Current ASD procurement guidance emphasizes supplier transparency, security track record, lifecycle considerations and clear allocation of responsibilities between customer and supplier. Those are much better indicators of a sustainable relationship than the smoothness of the demonstration environment.</span></p><p><span>Any vendor can demonstrate a dashboard. The grown-up conversation is about the operating model.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I eliminated the vulnerability meeting that consisted of security reading scanner results aloud to people who were quietly reconsidering their career choices.</span></p><p><span>It was an activity meeting rather than a risk meeting. We could spend an hour discussing thousands of findings without answering the most important question: which weaknesses create a credible path to material business impact?</span></p><p><span>I replaced it with an application and business-service risk review.</span></p><p><span>Instead of beginning with vulnerability volume, we begin with business criticality, internet exposure, sensitive data, identity and privilege pathways, known exploitation, exploit probability, compensating controls, remediation ownership, and trend. The scanner results still provide evidence, but they no longer dictate the agenda.</span></p><p><span>This matters because no single technical score represents organizational risk. FIRST&#8217;s EPSS estimates the probability that a vulnerability will be exploited, but explicitly warns that it is not a complete risk score. Asset purpose, value, accessibility, controls and potential impact must still be considered.</span></p><p><span>We use RAG reporting because it gives executives a rapid view of hotspots and creates some healthy competition between teams. But RAG is navigation, not analysis. Green is not a control, and red is not a diagnosis. A red customer-payment platform and a red internal test server are not equivalent merely because PowerPoint has assigned them the same shade.</span></p><p><span>The new discussion is not, &#8220;Who has the most vulnerabilities?&#8221;</span></p><p><span>It is, &#8220;Which application is most likely to hurt us, who owns the response, and is the exposure moving in the right direction?&#8221;</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Activating the business response, rather than only the technical response.</span></p><p><span>Technical teams quite reasonably begin containing the threat, collecting evidence and working out what happened. But a significant incident also needs an incident commander, a decision log, a reliable communications channel and early engagement from the people responsible for legal, communications, business continuity, critical services and executive decisions.</span></p><p><span>Someone should also be given explicit responsibility for protecting and validating the recovery path. That does not mean immediately restoring systems or connecting backup infrastructure to a potentially compromised environment. It means establishing whether the backups are isolated, current and likely to be usable; whether the associated credentials may be compromised; and whether there is a clean recovery path available when it is needed.</span></p><p><span>Backups are frequently treated as a magic incantation: somebody says, &#8220;We have backups,&#8221; and everyone feels better. The useful question is whether we can restore the right services, from trustworthy data, within a timeframe the business can survive.</span></p><p><span>ASD guidance emphasizes enacting the incident response plan once an incident is identified, while its continuity guidance highlights the need to maintain communications and critical business functions when normal systems are unavailable.</span></p><p><span>The SOC can contain malware. It cannot, by itself, authorize customer communications, decide whether payroll outranks email for recovery, or explain the situation to the regulator.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>&#8220;When did we last prove, in practice, that our incident response and business continuity plans work together?&#8221;</span></p><p><span>Not when were they last reviewed.</span></p><p><span>Not when did somebody update the document footer.</span></p><p><span>When were they last road-tested under realistic conditions, involving the people, suppliers and decision-makers who would actually be required during an incident?</span></p><p><span>A meaningful exercise should test decision authority, escalation paths, out-of-band communications, executive availability, legal and regulatory thresholds, supplier contacts, manual business workarounds, backup restoration, service-recovery priorities and the assumptions behind recovery time and recovery point objectives.</span></p><p><span>It should also expose awkward practical details. Are the emergency contact details stored somewhere accessible when email is down? Can the crisis team collaborate without using the potentially compromised corporate environment? Does the person named as incident commander still work here? Can the backup be restored, or has the organization merely been paying to store it very carefully?</span></p><p><span>Current ASD guidance requires incident management policies and associated response plans to be exercised at least annually, and separately expects boards or executive committees to participate in planning and exercises for major cyber incidents. For a critical or rapidly changing environment, annual testing should be treated as a floor rather than an aspiration.</span></p><p><span>A tabletop exercise that ends with everyone congratulating themselves is often just a meeting with a plot.</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I use a structure like this:</span></p><p><span>&#8220;This creates a credible pathway to [critical service] being unavailable or compromised for [period], affecting [customers, operations or data], with a plausible financial impact of [$X&#8211;$Y]. We can reduce the likelihood or duration through [action] at a cost of [$Z]. The decision required is [choice].&#8221;</span></p><p><span>That framing translates the technical condition without hiding it. It connects the weakness to a business promise, explains the plausible scenario, acknowledges uncertainty, quantifies the potential consequence and makes the decision explicit.</span></p><p><span>I also try to make &#8220;reputational damage&#8221; less abstract. Reputation is not a mysterious cloud that descends after an incident. It can appear as customer attrition, reduced conversion, lost bids, delayed sales, increased support demand, regulatory scrutiny, partner concern or prolonged executive distraction. Where possible, I connect reputation to those observable commercial and operational effects.</span></p><p><span>The use of ranges is important. Cyber quantification should improve decision-making, not manufacture false precision. Saying the impact is plausibly between $3 million and $8 million, based on stated assumptions, is often more credible than claiming the answer is exactly $5,421,763 because a spreadsheet contains several decimal places.</span></p><p><span>Both ASD and NIST expect cyber risk information to support broader organizational risk and investment decisions rather than remain isolated in specialist terminology.</span></p><p><span>Executives do not need a guided tour of the CVE. They need to know which promise to customers it could break.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>Learn to talk executive risk.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on"><span>CISO Tips: Carlos Garc&#237;a Batista on Turning Cybersecurity Into Operational Resilience</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking"><span>CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning"><span>CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first"><span>CISO Tips: Paul Blahusch on Business Success Coming First</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-diyar-akhmedov-on-prioritizing-risk-over-hype"><span>CISO Tips: Diyar Akhmedov on Prioritizing Risk Over Hype</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Carlos García Batista on Turning Cybersecurity Into Operational Resilience]]></title><description><![CDATA[For Carlos Garc&#237;a Batista, cybersecurity is ultimately about protecting the continuity of essential services.]]></description><link>https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Sun, 02 Aug 2026 12:32:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CmSJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CmSJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CmSJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CmSJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CmSJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>For </span><a href="https://www.linkedin.com/in/cgarbat/"><span>Carlos Garc&#237;a Batista</span></a><span>, cybersecurity is ultimately about protecting the continuity of essential services. As CISO and Information Security Officer for the Directorate General of Emergencies within the Gobierno de Canarias, he operates at the intersection of critical infrastructure protection, emergency response, operational resilience, and regulatory compliance. His responsibilities include coordinating cybersecurity across technical and operational environments, working with authorities on incident management, and helping ensure that essential services remain secure and available when they are needed most.</span></p><p><span>That perspective shapes a pragmatic approach to security leadership, one grounded in ownership, accountability, and resilience rather than simply accumulating more tools and controls. From questioning whether a security investment actually reduces operational risk to establishing clear command structures during incidents, Garc&#237;a Batista emphasizes the importance of turning cybersecurity into actionable decisions. In this edition of </span><em><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a></em><span>, he shares practical guidance on everything from evaluating vendors and securing privileged access to communicating risk with executives and knowing which security activities are no longer worth the effort.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>Before you buy any new security tool, first define the operational risk you are trying to reduce, who will own the tool, who will operate it, and what decision it will help you make.</span></p><p><span>A tool without ownership becomes another unmanaged asset.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>No privileged access without a clear purpose, a named owner, traceability, and a review date.</span></p><p><span>Access should never be granted just because &#8220;it may be useful someday.&#8221; In security, convenience without control becomes risk very quickly.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>I try to keep a practical balance between prevention, detection, response, and resilience.</span></p><p><span>If most of the effort goes only into buying preventive controls, the organization may look protected but still be unable to detect, respond, or recover properly. For critical services, resilience deserves budget, time, and executive attention.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>&#8220;This is not only a cybersecurity investment; it is an operational continuity investment.&#8221;</span></p><p><span>That framing usually works because it connects security to service availability, institutional responsibility, and business or public-service impact.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Security activities that generate reports but do not generate decisions.</span></p><p><span>If a report, meeting, metric, or control does not help reduce risk, improve visibility, assign responsibility, or support a decision, it should be simplified, automated, merged, or removed.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>I ask three questions:</span></p><p><span>What specific risk does this reduce?</span></p><p><span>How will it integrate with what we already have?</span></p><p><span>Who in my team will operate it on a bad day?</span></p><p><span>If the answer is vague, the pitch is not mature enough.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I try to eliminate meetings that only exist to exchange information that could have been documented beforehand.</span></p><p><span>They should be replaced by short, evidence-based operational reviews: what changed, what risk increased, what decision is needed, who owns the next action, and by when.</span></p><p><span>Security governance should create clarity, not ceremony.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>They often skip defining the incident commander and the decision-making channel.</span></p><p><span>Many teams start investigating immediately, but without clear coordination, roles, and communication discipline. In an incident, technical work matters, but command structure matters just as much.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>&#8220;What are we currently accepting as normal that is actually a risk?&#8221;</span></p><p><span>That question usually reveals technical debt, informal exceptions, undocumented dependencies, weak ownership, or processes that only work because one person knows how to keep them alive.</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I translate technical risk into operational consequence.</span></p><p><span>Instead of saying, &#8220;We have a vulnerability in this system,&#8221; I prefer to say, &#8220;If this fails or is compromised, this service may be unavailable, this decision may be delayed, or this operational capability may be affected.&#8221;</span></p><p><span>Executives need to understand impact, not just threat language.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>Govern calmly, document, prioritize, breathe.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking"><span>CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning"><span>CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first"><span>CISO Tips: Paul Blahusch on Business Success Coming First</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-diyar-akhmedov-on-prioritizing-risk-over-hype"><span>CISO Tips: Diyar Akhmedov on Prioritizing Risk Over Hype</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-peter-egyed-on-why-consistency"><span>CISO Tips: Peter Egyed on Why Consistency and Prioritization Strengthen Cybersecurity</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Bloom Security Emerges With $20M Seed to Protect the Expanding AI-Native Endpoint]]></title><description><![CDATA[The traditional corporate endpoint was built around a simple premise: organizations knew which devices employees used and could largely control the software installed on them.]]></description><link>https://www.cisohq.io/p/bloom-security-emerges-with-20m-seed</link><guid isPermaLink="false">https://www.cisohq.io/p/bloom-security-emerges-with-20m-seed</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Thu, 30 Jul 2026 13:05:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Hn71!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hn71!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hn71!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hn71!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg" width="1456" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hn71!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>The traditional corporate endpoint was built around a simple premise: organizations knew which devices employees used and could largely control the software installed on them. That model is becoming harder to maintain as AI agents, browser extensions, MCP servers and code packages become embedded in daily work.</span></p><p><a href="https://bloom.security/"><span>Bloom Security</span></a><span> is launching with the goal of addressing that growing complexity. The Tel Aviv-based company has emerged from stealth with a $20 million seed round led by Glilot Capital Partners, with participation from </span>Ten Eleven Ventures (1011vc), <span>Okta Ventures, and Runtime Ventures. </span><a href="https://www.axios.com/pro/enterprise-software-deals/2026/07/30/bloom-security-endpoint-crowdstrike"><span>Axios</span></a><span> first reported about the company&#8217;s launch and funding.</span></p><p><span>The funding also includes prominent angel investors, including the founders of Dig Security, Demisto, Snyk and Talon. Bloom said its platform is already deployed at dozens of large enterprises across the United States and Europe, giving the startup an early foothold as companies look for ways to manage the security implications of rapid AI adoption.</span></p><h2><span>The New Software Perimeter</span></h2><p><span>The challenge Bloom is targeting goes beyond the traditional definition of endpoint security. Employees are increasingly assembling their own software environments through AI tools, extensions and other applications, while browsers, IDEs and AI agents introduce marketplaces that can expand the number of tools operating on a corporate device.</span></p><p><span>For security teams, the issue is not necessarily that these tools are malicious. Instead, legitimate software can become a source of risk because of how it is configured, what permissions it receives or how it interacts with other systems and data.</span></p><p><span>&#8220;In the AI era, the employee device is no longer just a managed endpoint,&#8221; said </span><a href="https://www.linkedin.com/in/itay-keren-%F0%9F%8C%B8-544760148/"><span>Itay Keren</span></a><span>, Co-Founder and CEO of Bloom Security. &#8220;Every endpoint is now running software no one reviewed, connecting to services no one provisioned.&#8221;</span></p><p><span>Bloom points to a range of potential risks, including AI agents with incorrect configurations, plugins that have excessive data permissions, screen recorders operating on executive devices and code libraries that pull from untrusted sources. These scenarios can create attack paths that traditional endpoint detection and response products may not have been designed to identify or manage.</span></p><p><span>&#8220;As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,&#8221; Keren added. &#8220;Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.&#8221;</span></p><h2><span>Understanding Risk in Context</span></h2><p><span>Bloom Security&#8217;s platform is designed to give organizations a broad inventory of what is running across their endpoints, including software, tools, extensions and code. It also examines how those components interact with data and systems and analyzes supply-chain risk, configurations and permissions.</span></p><p><span>The company is taking a contextual approach to determining exposure. Its premise is that the risk associated with a particular application can vary significantly depending on the employee using it and the environment in which it operates.</span></p><p><span>&#8220;The same tool can be completely acceptable on one endpoint and high-risk on another,&#8221; said </span><a href="https://www.linkedin.com/in/ofir-balassiano/"><span>Ofir Balassiano</span></a><span>, Co-Founder and Chief Product Officer at Bloom Security. &#8220;Risk depends on context: the user&#8217;s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.&#8221;</span></p><p><span>The platform is also designed to let security teams take action based on those assessments. Bloom says organizations can block risky installations before they reach employee devices, enforce secure configurations and remediate risks without manual approval workflows.</span></p><p><span>That combination of visibility and enforcement is central to the company&#8217;s positioning as it targets large enterprises navigating AI adoption at scale.</span></p><h2><span>Building From Enterprise Security Experience</span></h2><p><span>Bloom&#8217;s leadership team has backgrounds at several established cybersecurity companies. CEO Itay Keren previously held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security and Demisto. Chief Product Officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks and previously worked at Dig Security and XM Cyber.</span></p><p><span>Chief Technology Officer </span><a href="https://www.linkedin.com/in/itay-frishman/"><span>Itay Frishman</span></a><span> built AISPM and DSPM solutions at Palo Alto Networks and Dig Security, alongside earlier cybersecurity research and development experience. Bloom currently has 30 employees, many of whom previously worked together at Dig Security.</span></p><p><span>&#8220;While this is technically our first company as founders, our team has built and integrated category-defining products before,&#8221; said Itay Frishman, Co-Founder and CTO. &#8220;We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.&#8221;</span></p><p><span>Bloom&#8217;s investors see the changing endpoint as an emerging category in enterprise security. Kobi Samboursky, Founder and Managing Partner at Glilot Capital, said the company&#8217;s early traction reflects the urgency of the problem.</span></p><p><span>&#8220;AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee&#8217;s machine, entirely outside the reach of traditional controls,&#8221; said Kobi Samboursky, Founder and Managing Partner at Glilot Capital. &#8220;Bloom identified this gap before the market did, and the business traction we&#8217;ve seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.</span></p><p><span>With $20 million in seed funding and deployments at dozens of large enterprises, Bloom is now focused on a security perimeter that is changing alongside the workplace itself. Its bet is that protecting the AI-native endpoint will require organizations to understand not only what is running on employee devices, but also the context in which that software operates and the access it has to corporate resources.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Whisperer Publishes Its Company-by-Company Guide to Black Hat USA 2026]]></title><description><![CDATA[Black Hat USA 2026 takes place August 1 through 6 at the Mandalay Bay Convention Center in Las Vegas, with expert trainings, summits, and main conference briefings covering the technologies and challenges shaping modern cybersecurity.]]></description><link>https://www.cisohq.io/p/ciso-whisperer-publishes-its-company</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-whisperer-publishes-its-company</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 29 Jul 2026 13:15:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3Th7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3Th7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3Th7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 424w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 848w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 1272w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3Th7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3Th7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 424w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 848w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 1272w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Black Hat USA 2026 takes place August 1 through 6 at the Mandalay Bay Convention Center in Las Vegas, with expert trainings, summits, and main conference briefings covering the technologies and challenges shaping modern cybersecurity. Organizations are contending with AI-driven threats, expanding attack surfaces, cloud complexity, and growing volumes of security data. Vendors are answering with new approaches to detection, response, exposure management, and resilience. What follows is a company-by-company reference to 12 firms worth attention, drawn from the </span><a href="https://cisowhisperer.com/12-cybersecurity-companies-to-watch-at-black-hat-usa-2026/"><span>CISO Whisperer watch list</span></a><span>.</span></p><h2><strong><span>Upwind</span></strong></h2><p><span>Cloud and AI security handled from the runtime layer.</span><a href="https://www.upwind.io/"><span> Upwind</span></a><span> connects cloud inventory, posture, network topology, applications, and identities, then blends real-time and agentless signals to produce a live view of infrastructure, networks, APIs, and data flows. Faster threat response is the outcome it sells. Placed in the Super Tier.</span></p><h2><strong><span>Cloudflare</span></strong></h2><p><span>A global network for building, securing, and scaling applications, AI agents, and workforces without managing the infrastructure underneath.</span><a href="https://www.cloudflare.com/"><span> Cloudflare</span></a><span> pushes security, connectivity, and code execution toward users and data. The network spans more than 335 cities and reaches 95% of the world&#8217;s population within 50 milliseconds. The company says its network powers 42% of the Fortune 500, which reflects its broad role in the modern internet ecosystem. Super Tier.</span></p><h2><strong><span>Illumio</span></strong></h2><p><span>Breach containment across hybrid and multi-cloud environments.</span><a href="https://www.illumio.com/"><span> Illumio</span></a><span> combines Zero Trust principles, AI-powered insights, and segmentation to detect threats, restrict lateral movement, and contain attacks before they spread. Super Tier.</span></p><h2><strong><span>Arctic Wolf</span></strong></h2><p><span>The Aurora Superintelligence Platform, positioned as a foundation for more automated security operations.</span><a href="https://arcticwolf.com/"><span> Arctic Wolf</span></a><span> uses AI agents to help organizations operate at machine speed. Built-in trust controls and human oversight provide validation, governance, and the expertise needed to manage complex security decisions. Super Tier.</span></p><h2><strong><span>Cohesity</span></strong></h2><p><span>Data protection and cyber resilience on one platform. The</span><a href="https://www.cohesity.com/"><span> Cohesity</span></a><span> Data Cloud brings data protection, security, recovery, and AI readiness together for hybrid cloud and SaaS workloads, strengthening threat detection, automating cyber recovery, reducing compliance risk, and making enterprise data more useful for AI initiatives. Super Tier.</span></p><h2><strong><span>Veracode</span></strong></h2><p><span>Application risk management across the software development lifecycle.</span><a href="https://www.veracode.com/"><span> Veracode</span></a><span> pairs visibility across code, dependencies, containers, and runtime signals with remediation guidance and AI-driven fixes. The aim is reduced security debt at maintained development speed. Featured Tier.</span></p><h2><strong><span>ThreatLocker</span></strong></h2><p><span>Zero Trust enforcement built on a deny-by-default model.</span><a href="https://www.threatlocker.com/"><span> ThreatLocker</span></a><span> permits only authorized applications, scripts, and processes to run across endpoints, cloud, and networks. Granular control is applied to prevent ransomware, reduce privilege abuse, limit lateral movement, and make data exfiltration more difficult. Featured Tier.</span></p><h2><strong><span>SafeBreach</span></strong></h2><p><span>Adversarial exposure validation for teams that want proof rather than assumption.</span><a href="https://www.safebreach.com/"><span> SafeBreach</span></a><span> tests whether defenses can withstand real-world attack techniques. The SafeBreach Helm platform combines exposure validation, AI orchestration, and existing security technologies to support continuous threat exposure management and measurable risk reduction. Featured Tier.</span></p><h2><strong><span>Mate Security</span></strong></h2><p><span>An agentic SOC designed for the speed and scale of modern threats.</span><a href="https://mate.security/"><span> Mate Security</span></a><span> uses a security context graph to give AI agents a tailored understanding of an organization&#8217;s environment, enabling support for detection building, triage, investigations, response, and threat hunting in a continuous cycle. Emerging Tier.</span></p><h2><strong><span>Daylight Security</span></strong></h2><p><span>Managed Agentic Security Services, or MASS, combining AI agents with experienced security professionals.</span><a href="https://daylight.ai/"><span> Daylight Security</span></a><span> covers managed detection and response, threat hunting, and phishing investigation and response. Its experts help customize detections, build integrations, and improve the context powering its AI systems. Emerging Tier.</span></p><h2><strong><span>Reclaim Security</span></strong></h2><p><span>An AI Security Engineer built to close the distance between identifying exposures and fixing them.</span><a href="https://reclaim.security/"><span> Reclaim Security</span></a><span> analyzes findings across security tools, understands business context, creates remediation strategies, and can deploy fixes through automated or approval-based workflows. Emerging Tier.</span></p><h2><strong><span>Zero Networks</span></strong></h2><p><span>Automated, identity-driven microsegmentation aimed at containing attacks and limiting lateral movement.</span><a href="https://zeronetworks.com/"><span> Zero Networks</span></a><span> applies segmentation to networks, identities, AI agents, and non-human accounts while helping organizations govern AI identities and restrict unauthorized activity. Emerging Tier.</span></p><h2><strong><span>Reading the Roster</span></strong></h2><p><span>Twelve entries, five in the Super Tier, three Featured, four Emerging. Read as a set, the list shows how far the industry has moved toward automation in the space of a single conference cycle. Four of the twelve describe AI agents as part of the product rather than as a roadmap item. Three extend their coverage to non-human identities. Black Hat USA 2026 arrives as AI reshapes both cybersecurity defense and the threat landscape, and the gathering of security leaders, researchers, practitioners, and vendors in Las Vegas will offer a view of how the industry is preparing for machine-speed attacks, autonomous systems, and increasingly complex digital environments.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk]]></title><description><![CDATA[In cybersecurity, effective leadership requires more than deploying the right tools or responding quickly to incidents.]]></description><link>https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 29 Jul 2026 10:27:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1EH1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1EH1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1EH1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1EH1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1EH1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>In cybersecurity, effective leadership requires more than deploying the right tools or responding quickly to incidents. It requires a mindset built around continuous learning, attacker thinking, and the ability to translate technical risk into business impact. </span><a href="https://www.linkedin.com/in/sergey-tairyan-0081b072/"><span>Sergey Tairyan</span></a><span>, Chief Information Security Officer at the Technology Management Center of Yerevan City and founder of OmniSec and Oky.ai, brings more than 15 years of experience building and transforming security programs across industries. His expertise spans security operations, SOC leadership, SIEM and DLP, IAM and PAM, endpoint protection, incident response, and emerging areas such as steganography and post-quantum cryptography.</span></p><p><span>Known for combining hands-on ethical hacking with long-term security strategy, Sergey approaches cybersecurity with a focus on reducing real-world risk while keeping organizations resilient and operational. His advice reflects that philosophy, from researching a vendor before buying its tools and measuring security decisions in business numbers to prioritizing daily learning and clear leadership during a crisis. In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Sergey shares the principles, habits, and practical approaches that shape how he thinks about security leadership in an increasingly complex threat landscape.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>Before you buy any new security tool, first do OSINT on the company behind it.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>Two non-negotiable rules:</span></p><ul><li><p><span>All team members must maintain 24/7/365 availability, including weekends, holidays, vacations, and days off.</span></p></li><li><p><span>Every team member spends one hour daily on learning and research.</span></p></li></ul><p><span>In cybersecurity, threats don&#8217;t rest and neither does learning.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>65% prevention, 15% detection and response, 20% innovation and research.</span></p><p><span>AI has shifted the balance toward innovation, but the ratio should continuously adapt to business risk, technology, and the evolving threat landscape.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>The board and CFO understand numbers, not technical details. So, I don&#8217;t ask for a security budget; I present a business risk calculation, showing the potential financial impact of an incident, its likelihood, and the cost of reducing that risk.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>With AI and mature open-source solutions, many enterprise security tools (such as SIEM, security scanners, and password managers) can now be deployed faster, customized, and operated at a fraction of the cost.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>I present the vendor with 2-3 real security challenges and watch how they respond.</span></p><p><span>I&#8217;m looking for honesty, technical depth, and a problem-solving mindset - not marketing. If they ask the right questions and acknowledge limitations, they&#8217;ve earned more of my time.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I eliminated meetings focused on what we did and replaced them with discussions on what we learned.</span></p><p><span>Instead of status updates, we focus on new threats, lessons learned, and opportunities to improve our security posture.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Teams often skip establishing clear leadership.</span></p><p><span>In a major cyber incident, the CISO becomes the incident commander, directing the CIO, CTO, and other teams to coordinate the response.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>What else can we automate to improve our resilience?</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>Let&#8217;s talk in numbers.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>- Learn. Test. Hack. Repeat.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning"><span>CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first"><span>CISO Tips: Paul Blahusch on Business Success Coming First</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-diyar-akhmedov-on-prioritizing-risk-over-hype"><span>CISO Tips: Diyar Akhmedov on Prioritizing Risk Over Hype</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-peter-egyed-on-why-consistency"><span>CISO Tips: Peter Egyed on Why Consistency and Prioritization Strengthen Cybersecurity</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-nikolas-oelkrug-alders"><span>CISO Tips: Nikolas Oelkrug-Alders on Why Strong Security Starts With the Fundamentals</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Mate Security Raises $35M Series A, Pushing Total Funding Past $50M as Enterprises Prepare for AI-Scale Threats]]></title><description><![CDATA[The rise of artificial intelligence is forcing enterprises to reconsider nearly every aspect of cybersecurity.]]></description><link>https://www.cisohq.io/p/mate-security-raises-35m-series-a</link><guid isPermaLink="false">https://www.cisohq.io/p/mate-security-raises-35m-series-a</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Tue, 28 Jul 2026 13:05:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wgQL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wgQL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wgQL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png 424w, https://substackcdn.com/image/fetch/$s_!wgQL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png 848w, https://substackcdn.com/image/fetch/$s_!wgQL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png 1272w, https://substackcdn.com/image/fetch/$s_!wgQL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wgQL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png" width="1024" height="683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:683,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wgQL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png 424w, https://substackcdn.com/image/fetch/$s_!wgQL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png 848w, https://substackcdn.com/image/fetch/$s_!wgQL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png 1272w, https://substackcdn.com/image/fetch/$s_!wgQL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39add156-9421-4dfe-8eaa-a83cae083ddd_1024x683.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>The rise of artificial intelligence is forcing enterprises to reconsider nearly every aspect of cybersecurity. Security teams are no longer dealing only with larger volumes of alerts; they are preparing for attacks that can evolve at machine speed while evaluating AI-generated recommendations that must be accurate enough to trust. For many organizations, that has created demand for security platforms designed specifically for the AI era rather than adapted from legacy architectures.</span></p><p><a href="https://mate.security"><span>Mate Security</span></a><span> is one of the companies betting on that shift. Reported first by </span><a href="https://www.axios.com/pro/enterprise-software-deals/2026/07/28/mate-security-agentic-insight"><span>Axios</span></a><span>, the startup has announced a $35 million Series A funding round, bringing its total funding to more than $50 million less than a year after leaving stealth mode. The round was led by Canaan Partners and included participation from Insight Partners, Team8, and M12, Microsoft&#8217;s Venture Fund.</span></p><p><span>The investment comes as the company reports increasing adoption among Fortune 500 organizations and says its business has grown by more than 500% since the third quarter of 2025.</span></p><h2><span>Moving Beyond Traditional Security Operations</span></h2><p><span>As organizations introduce AI into security workflows, one challenge has become increasingly apparent: speed alone is not enough. Security analysts still need confidence that AI-generated findings accurately reflect what is happening inside their environments before they can take action.</span></p><p><span>Mate&#8217;s platform is designed around that principle. Rather than focusing exclusively on automation, the company has built what it describes as an open, agentic security operations platform powered by a patent-pending context layer. The goal is to provide AI agents with an understanding of the customer&#8217;s business so they can make more precise security decisions.</span></p><p><span>That contextual awareness extends beyond technical signals. According to the company, its platform evaluates operational information alongside security events, allowing AI agents to determine whether activity is expected business behavior or an incident that requires investigation.</span></p><p><span>For instance, if multiple login attempts trigger an alert, the platform can recognize whether the activity coincides with planned security testing. Similarly, if an employee accesses sensitive files, the system considers organizational context, including personnel changes and document classifications, before determining whether the activity poses a legitimate threat.</span></p><h2><span>Building an AI Foundation Instead of Another Tool</span></h2><p><span>Mate says the platform serves as a centralized foundation where organizational knowledge is collected, maintained, and governed through a Security Context Graph. AI agents operate using that shared knowledge base, allowing both Mate-developed agents and customer-built agents to work from consistent information while maintaining controls around permissions, auditability, and response.</span></p><p><span>The company also says its AI architecture includes persistent memory that improves over time through investigations, structured communication between specialized agents, and least-agency principles that restrict each agent to only the context and permissions required for its specific task.</span></p><p><span>&#8220;When we started Mate, we knew we had to invest in the foundation: context and trust, and build them deeply into our product,&#8221; said Asaf Wiener, CEO and Co-Founder of Mate Security. &#8220;We brought in some of the best AI builders and security experts, and I&#8217;m excited to see how well this approach is being received by the market. We will continue moving fast and stay laser-focused on our customers, as we expand into new markets and categories to build the Open Security Operations foundation of the future.&#8221;</span></p><h2><span>Investors See Strong Enterprise Momentum</span></h2><p><span>The latest financing follows Mate&#8217;s $15.5 million Seed round announced eight months ago, with all previous investors returning for the Series A.</span></p><p><span>Backers say the company&#8217;s approach stands apart because it focuses on enabling AI systems to understand organizational context rather than simply accelerating existing workflows.</span></p><p><span>&#8220;AI is forcing a fundamental rethink of security operations. What stood out to us about Mate wasn&#8217;t simply its use of AI; it was the team&#8217;s conviction that trustworthy AI requires a deep understanding of how an organization operates,&#8221; said Joydeep Bhattacharyya, General Partner at Canaan. &#8220;By building a shared context layer that gives AI agents that understanding, Mate has taken a fundamentally different approach to security operations. The customer feedback and success we&#8217;ve seen in competitive evaluations reinforce our belief that the team is solving an important problem in a differentiated way.&#8221;</span></p><p><span>Insight Partners highlighted the company&#8217;s ability to combine advanced AI capabilities with practical security operations.</span></p><p><span>&#8220;Security operations was not built for the speed or scale of modern AI-driven attacks,&#8221; said Teddie Wardi, Managing Director at Insight Partners. &#8220;Mate is doing something few security companies have managed: combining genuine AI depth with operational trust to rebuild security operations for the AI era. We are proud to support a team that consistently outexecutes.&#8221;</span></p><p><span>Team8 and M12 likewise pointed to the company&#8217;s execution, hiring, and commercial growth as indicators of its momentum in the emerging market for AI-native security operations.</span></p><h2><span>Showcasing at Black Hat USA</span></h2><p><span>The funding announcement comes just before Black Hat USA 2026, where Mate Security will exhibit at Booth 4717 from August 3 to August 6.</span></p><p><span>As enterprises continue adapting their security strategies for AI-driven threats, the company is positioning its platform around a central belief: that successful AI security operations require more than powerful models; they require AI systems that understand the business they are protecting.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Daylight Security Bets on Transparency With Detection Program Visibility ]]></title><description><![CDATA[There is a quiet market shift underway in managed security, and Daylight&#8217;s latest release is a useful signal of where it is heading. Daylight Security, the managed agentic security services company, today announced Detection Program Visibility, a capability that gives customers a measurable view of their entire detection program, including the parts a managed provider would traditionally keep hidden.]]></description><link>https://www.cisohq.io/p/daylight-security-bets-on-transparency</link><guid isPermaLink="false">https://www.cisohq.io/p/daylight-security-bets-on-transparency</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Mon, 27 Jul 2026 12:44:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-PXp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-PXp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-PXp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-PXp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-PXp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-PXp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-PXp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg" width="1024" height="683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:683,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-PXp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-PXp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-PXp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-PXp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb50e72bb-6edd-4ba0-bbfc-1d35f306cd5a_1024x683.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>There is a quiet market shift underway in managed security, and Daylight&#8217;s latest release is a useful signal of where it is heading.</span><a href="https://daylight.ai/"><span> Daylight Security</span></a><span>, the managed agentic security services company, today announced Detection Program Visibility, a capability that gives customers a measurable view of their entire detection program, including the parts a managed provider would traditionally keep hidden.</span></p><p><span>The strategic logic is straightforward. MDR providers have historically competed on outcomes and response times while keeping their detection content proprietary. Daylight is competing on something different: the customer&#8217;s ability to see, measure, and improve the program itself.</span></p><h2><span>The Market Problem</span></h2><p><span>Every security organization of reasonable size now runs a stack of tools, a SIEM full of accumulated content, and often a managed detection service on top. Each layer generates its own detections. Security tools expose theirs. MDR providers typically operate theirs as a black box.</span></p><p><span>The result, as Daylight describes it, is fragmentation across multiple systems. Customers cannot easily determine what is actually being detected, where coverage overlaps, and where the blind spots are. In a market where organizations are under pressure to justify every line of security spend, that opacity is becoming harder to defend.</span></p><h2><span>What Daylight Is Shipping</span></h2><p><span>Detection Program Visibility consolidates every detection a customer has into one place. That covers three sources: detections from security tools, SIEM content, and the detections Daylight operates on the customer&#8217;s behalf. Daylight organizes all of it into a shared model mapped to MITRE ATT&amp;CK.</span></p><p><span>The differentiating layer is operational context. Each detection carries data on alert volume, case outcomes, verdict statistics, overlap, and coverage gaps. This is where the capability moves past inventory and into measurement.</span></p><h2><span>The Competitive Angle</span></h2><p><span>Standalone detection visibility tools exist. Daylight&#8217;s counter is that visibility without investigation is a dead end. Because Daylight investigates the activity these detections generate, every investigation produces feedback on detection quality: which detections find meaningful threats, which create noise, which overlap, and where coverage is missing.</span></p><p><span>That feedback loop is the product&#8217;s core claim. It converts detection engineering from a static collection of rules into a measurable, continuously improving program. A pure visibility vendor cannot close that loop. An opaque MDR will not.</span></p><p><span>Hagai Shapira, CEO and co-founder of Daylight Security, made the positioning explicit. &#8220;Security leaders know how many alerts they receive, but they rarely know whether their detection program is actually improving,&#8221; he said. &#8220;For years, MDRs have asked customers to trust what happens behind the curtain. We believe customers should be able to see the detection program protecting them, understand how it&#8217;s performing, and continuously improve it with us. Detection Program Visibility is another step toward making managed security transparent instead of opaque.&#8221;</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J76T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J76T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png 424w, https://substackcdn.com/image/fetch/$s_!J76T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png 848w, https://substackcdn.com/image/fetch/$s_!J76T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png 1272w, https://substackcdn.com/image/fetch/$s_!J76T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J76T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png" width="415" height="826" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:826,&quot;width&quot;:415,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J76T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png 424w, https://substackcdn.com/image/fetch/$s_!J76T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png 848w, https://substackcdn.com/image/fetch/$s_!J76T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png 1272w, https://substackcdn.com/image/fetch/$s_!J76T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F555261b1-9ca0-4942-8d39-0d94001e4cfb_415x826.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><span>What Buyers Should Take From This</span></h2><p><span>For security leaders evaluating managed detection, the release sharpens a question worth asking of any provider: can you show me the detection program you run on my behalf, with performance data attached? Providers built on the black box model will struggle to answer. Daylight has now built its answer into the product.</span></p><p><span>The release also reframes what improvement means in an MDR relationship. Alert counts and response metrics measure activity. Detection quality metrics measure whether the program is getting better at its actual job. Those are different things. Daylight is arguing that customers should be able to see both.</span></p><h2><span>Availability and Outlook</span></h2><p><span>Detection Program Visibility is available now for Daylight Managed Agentic MDR customers.</span></p><p><span>Transparency plays are only as good as the data behind them, and the market will judge this one on whether the measurement holds up in practice. But the direction is notable. If customers begin to expect visibility into managed detection programs as a baseline, providers that built their businesses behind the curtain will face an uncomfortable choice: open up or explain why they will not. Daylight has made its choice and turned it into a feature.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Insight Partners And Glilot Capital Co-Lead $20M Investment In Way Security To Tackle IAM’s Costly Execution Gap]]></title><description><![CDATA[Identity and access management has become a central pillar of enterprise cybersecurity, but deploying identity systems across large organizations remains a persistent challenge.]]></description><link>https://www.cisohq.io/p/insight-partners-and-glilot-capital</link><guid isPermaLink="false">https://www.cisohq.io/p/insight-partners-and-glilot-capital</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Mon, 27 Jul 2026 11:09:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0JOy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0JOy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0JOy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!0JOy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!0JOy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!0JOy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0JOy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0JOy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!0JOy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!0JOy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!0JOy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9cb8f8e7-ee34-4f2f-ba14-b36035bb58f3_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Identity and access management has become a central pillar of enterprise cybersecurity, but deploying identity systems across large organizations remains a persistent challenge. Companies can invest heavily in IAM platforms only to face years of implementation work, high consulting costs and complex operational requirements.</span></p><p><span>As reported by </span><a href="https://www.axios.com/pro/enterprise-software-deals/2026/07/27/identity-way-security-microsoft-software"><span>Axios</span></a><span>, Insight Partners and Glilot Capital are co-leading a $20 million investment in </span><a href="https://www.way.security/"><span>Way Security</span></a><span>, a company founded by former security leaders Yossi Barishev and Yonatan Rosenberg. The company is building an AI-powered, agentic execution platform designed to automate the operational work traditionally required to deploy and manage IAM systems.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CISO HQ ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><span>Rather than asking enterprises to replace their existing identity infrastructure, Way Security is focused on helping organizations get more value from the platforms they already own. Its approach targets the gap between purchasing IAM software and successfully operationalizing it across complex enterprise environments.</span></p><h2><span>The Services Problem Behind IAM</span></h2><p><span>According to Way Security, enterprise IAM programs can routinely run years past schedule and reach seven- or eight-digit cost figures while still delivering less than originally promised. Implementation, customization and ongoing operational services can cost organizations three to five times more than the software itself, creating a services ecosystem that has grown larger than the IAM software market it supports.</span></p><p><span>The company believes this represents a multi-billion-dollar opportunity to change how identity programs are delivered. Its platform uses AI-driven automation and agentic workflows to execute tasks that have historically depended on consultants, system integrators and internal engineering resources.</span></p><p><span>&#8220;IAM is the only space in cyber where overspending and under-delivering is an acceptable reality,&#8221; said Barishev, co-founder and CEO of Way Security. &#8220;The more time we spent doing IAM, the more we realized how the industry normalized mediocrity and has almost given up trying to solve some of its biggest challenges.&#8221;</span></p><h2><span>Automating The Operational Layer</span></h2><p><span>Way Security&#8217;s platform is designed to automate activities associated with identity lifecycle management, access governance, authentication and policy enforcement. The company says organizations can apply identity controls across different types of identities and systems without custom integrations, manual workflows or ongoing dependence on application owners.</span></p><p><span>The platform also addresses applications that can be difficult to incorporate into conventional identity programs, including legacy, homegrown and custom applications that do not support standard federation protocols. Way Security connects these applications to the IGA, IdP and authentication controls organizations already own.</span></p><p><span>&#8220;Most IAM teams aren&#8217;t looking to replace the platforms they&#8217;ve already invested in,&#8221; said Rosenberg, co-founder and CTO. &#8220;They&#8217;re looking to finally get the return on investment they were promised. We built Way Security to automate the work that has traditionally stood between buying an IAM platform and actually realizing its value.&#8221;</span></p><h2><span>Experience From Inside Enterprise Security</span></h2><p><span>Way Security&#8217;s founders bring firsthand experience with the challenges they are trying to address. Barishev and Rosenberg spent years helping large enterprises navigate identity, governance and security initiatives, advising Fortune 500 organizations and leading enterprise security teams from within.</span></p><p><span>The pair also spent years leading incident response efforts for organizations facing major cyber incidents, repeatedly seeing weak identity controls become a root cause or critical enabler of successful attacks. Rosenberg additionally served as an officer in Israel&#8217;s Unit 8200, bringing an offensive security perspective to the company&#8217;s identity and security expertise.</span></p><p><span>&#8220;The issue isn&#8217;t that enterprises lack the right tools,&#8221; said Barishev. &#8220;It&#8217;s that those tools are incredibly expensive and complex to operationalize. We built Way Security to remove that friction.&#8221;</span></p><h2><span>Investors Target A Larger IAM Opportunity</span></h2><p><span>The $20 million investment reflects the belief from Insight Partners and Glilot Capital that the operational challenges surrounding IAM represent an opportunity beyond the traditional identity software market.</span></p><p><span>&#8220;Identity is one of the most critical layers of enterprise security, yet organizations still struggle to operationalize their investments efficiently,&#8221; said Jeff Horing, Co-Founder and Managing Director at Insight Partners. &#8220;Way Security is addressing a large and persistent gap between IAM software and real-world execution.&#8221;</span></p><p><span>Nofar Amikam, Managing Partner at Glilot Capital, pointed to the combination of the founders, market opportunity and the company&#8217;s approach. &#8220;As investors, we&#8217;re constantly looking for the rare combination of an exceptional team, a massive market opportunity, and a differentiated approach, said Nofar Amikam, Managing Partner at Glilot Capital. &#8220;With Yossi and Yonatan, all three were evident from our very first meeting. They possess a deep understanding of the identity challenges facing large enterprises because they&#8217;ve lived them firsthand, and they&#8217;ve built a fundamentally better way to solve them. Identity has become the foundation of modern security, and we believe this team has the vision, talent, and determination to build the company that will define how the next generation of enterprises manages and secures it.&#8221;</span></p><h2><span>Expanding The Identity Operations Market</span></h2><p><span>Way Security says it is already working with Fortune 500 companies, global healthcare organizations and financial institutions to accelerate IAM deployments, reduce manual implementation work and expand identity coverage across complex environments.</span></p><p><span>The company plans to use the new investment to aggressively expand its U.S. presence while continuing to invest in its identity operations platform. Its broader goal is to establish identity operations as a distinct category focused on making existing IAM technology easier to deploy and operate.</span></p><p><span>&#8220;We&#8217;re at a pivotal moment in the market,&#8221; said Rosenberg. &#8220;Identity has become the foundation of enterprise security, yet organizations still struggle to operationalize it effectively. Our priority now is to move quickly, expand our platform, grow our presence in the U.S., and establish Way Security as the category leader in identity operations before the market catches up.&#8221;</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction]]></title><description><![CDATA[As cybersecurity leaders face growing pressure to reduce risk while proving business value, the role of the CISO is increasingly defined by the ability to connect security decisions to measurable outcomes.]]></description><link>https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Mon, 27 Jul 2026 10:23:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uwTD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uwTD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uwTD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!uwTD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!uwTD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!uwTD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uwTD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uwTD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!uwTD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!uwTD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!uwTD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbeb190d-bec2-41f7-855b-61e64610e97a_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>As cybersecurity leaders face growing pressure to reduce risk while proving business value, the role of the CISO is increasingly defined by the ability to connect security decisions to measurable outcomes. </span><a href="https://www.linkedin.com/in/kristin-lowery-b1a2a02/"><span>Kristin Lowery</span></a><span>, Field Chief Information Security Officer at Optiv, brings extensive experience leading information technology and cybersecurity initiatives across Fortune 500 enterprises. Her background spans cybersecurity controls, cloud computing, vulnerability management, data protection, governance, business continuity, and large-scale technology transformations, with a focus on helping organizations reduce threats while supporting resilience and sustainable growth.</span></p><p><span>Throughout her career, Lowery has worked closely with senior executives and cross-functional teams to develop security strategies, strengthen governance, improve operational efficiency, and align technology investments with business priorities. In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, she shares a practical perspective on making security programs more effective, from evaluating the real problem before buying another tool and cutting unnecessary complexity to translating technical vulnerabilities into business exposure and establishing clear decision ownership during an incident. Her advice centers on a simple principle: security teams should focus less on activity for its own sake and more on measurable risk reduction, business impact, and the resilience to keep moving forward.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>Before you buy any new security tool, first get clear on the problem you&#8217;re trying to solve. Too often, teams add technology before confirming whether they already own a tool that can do the job&#8212;or whether the real issue is process, ownership, or adoption. I also think it&#8217;s important to regularly review your existing technology footprint, because many organizations are not getting full value from the solutions they already have. One recent conversation that stuck with me was with a CISO who asked his team to review their top tools and validate actual usage, especially as new AI capabilities continue to emerge.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>If we can&#8217;t connect a recommendation to risk reduction or a business outcome, we need to rethink it. Security teams can generate a lot of activity, but activity is not the same as progress. To me, progress means measurable operational risk reduction or an increase in business capability.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>I pay close attention to the balance between effort and actual risk reduction. If something takes significant time, creates operational drag, and does not meaningfully reduce risk, that is usually a signal to simplify it. I also believe key performance indicators and risk appetite should be reviewed at least annually so they remain relevant and useful.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>&#8220;This is not about buying another security tool. It is about reducing the likelihood and impact of an event that could disrupt the business, affect customers, or slow recovery.&#8221; CFOs and other leaders do not want to hear about the latest shiny tool. They want to understand impact, value, and how the investment fits into the broader environment.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>I would cut anything that creates noise without improving decision-making. That might include duplicate tools, reports no one uses, or processes people follow simply because &#8220;we&#8217;ve always done it that way.&#8221;</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>I want to quickly understand what risk they reduce, where they fit in the environment, what problem they solve better than what I already have, and how I would know the solution is working. If they can&#8217;t explain that clearly, it&#8217;s probably not the right conversation.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I&#8217;m a big believer in replacing status-for-status-sake meetings with decision-focused conversations. Instead of walking through dashboards, I&#8217;d rather ask: What changed? What matters? What decision do we need? Who owns the next step? I&#8217;m also comfortable canceling meetings that are no longer needed or ending them early. Staying connected with leaders and teams matters, but the agenda should support that purpose.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Teams understandably jump into technical triage, but they often skip defining business impact and decision ownership. Early on, someone needs to clarify what is affected, who needs to know, and who is empowered to make decisions.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>&#8220;Where are we making security harder than it needs to be?&#8221; That question usually opens an honest conversation about complexity, ownership, and whether our controls are working the way we think they are.</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I try to shift the conversation from &#8220;technical vulnerability&#8221; to &#8220;business exposure.&#8221; For example: &#8220;This is not just a system issue; it could affect operations, customer trust, recovery time, or our ability to meet business commitments.&#8221;</span></p><p><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></p><p><span>Stay curious, practical, and resilient. Keep moving forward&#8212;don&#8217;t spend too much time looking backward, because that&#8217;s not where you&#8217;re going.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first"><span>CISO Tips: Paul Blahusch on Business Success Coming First</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-diyar-akhmedov-on-prioritizing-risk-over-hype"><span>CISO Tips: Diyar Akhmedov on Prioritizing Risk Over Hype</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-peter-egyed-on-why-consistency"><span>CISO Tips: Peter Egyed on Why Consistency and Prioritization Strengthen Cybersecurity</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-nikolas-oelkrug-alders"><span>CISO Tips: Nikolas Oelkrug-Alders on Why Strong Security Starts With the Fundamentals</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-rocco-barra-on-never-taking-things-for-granted"><span>CISO Tips: Rocco Barra on Never Taking Anything for Granted</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Daylight Security Puts CISOs First With A Black Hat Concierge And A Dose Of Humor]]></title><description><![CDATA[Cybersecurity conferences are built around meetings, product demonstrations and vendor pitches, but Daylight Security is using Black Hat to make a different statement.]]></description><link>https://www.cisohq.io/p/daylight-security-puts-cisos-first</link><guid isPermaLink="false">https://www.cisohq.io/p/daylight-security-puts-cisos-first</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Thu, 23 Jul 2026 16:38:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wUpk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wUpk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wUpk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png 424w, https://substackcdn.com/image/fetch/$s_!wUpk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png 848w, https://substackcdn.com/image/fetch/$s_!wUpk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png 1272w, https://substackcdn.com/image/fetch/$s_!wUpk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wUpk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png" width="1024" height="683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:683,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!wUpk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png 424w, https://substackcdn.com/image/fetch/$s_!wUpk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png 848w, https://substackcdn.com/image/fetch/$s_!wUpk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png 1272w, https://substackcdn.com/image/fetch/$s_!wUpk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fd02c5a-3059-48f8-907b-2be1cdb9b5c0_1024x683.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;47bfe10b-8651-4778-85b9-def6168c388e&quot;,&quot;duration&quot;:null}"></div><p><span>Cybersecurity conferences are built around meetings, product demonstrations and vendor pitches, but </span><a href="https://daylight.ai"><span>Daylight Security</span></a><span> is using Black Hat to make a different statement. Instead of setting up a traditional booth, the company introduced the &#8220;CISO Genie,&#8221; a private concierge service designed to help security leaders with the practical demands of attending the event.</span></p><p><span>The initiative has also become a social media campaign. Two videos shared on LinkedIn by Hagai Shapira, Co-Founder and CEO of Daylight, use humor to portray the CISO Genie as a behind-the-scenes problem solver for security executives. The videos have generated significant engagement on LinkedIn while presenting a less conventional take on the relationship between cybersecurity vendors and their customers.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y6r4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y6r4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png 424w, https://substackcdn.com/image/fetch/$s_!Y6r4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png 848w, https://substackcdn.com/image/fetch/$s_!Y6r4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png 1272w, https://substackcdn.com/image/fetch/$s_!Y6r4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y6r4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png" width="1456" height="820" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:820,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y6r4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png 424w, https://substackcdn.com/image/fetch/$s_!Y6r4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png 848w, https://substackcdn.com/image/fetch/$s_!Y6r4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png 1272w, https://substackcdn.com/image/fetch/$s_!Y6r4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5571604e-cb4c-4814-8ec1-4eea6b59fd29_2048x1153.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The campaign&#8217;s central message appears in Shapira&#8217;s post accompanying the </span><a href="https://www.linkedin.com/posts/hagai-shapira_blackhat-mdr-aisoc-activity-7482437026965778432-Mer2?utm_source=social_share_send&amp;utm_medium=member_desktop_web&amp;rcm=ACoAACBfb1YBqKPR7SMH8cNxQw7G9p7EjKFyUbQ"><span>first video</span></a><span>: &#8220;A Black Hat booth costs about the same as taking care of 150 CISOs for an entire week. We chose the CISOs.&#8221; The decision reflects Daylight&#8217;s broader positioning around providing security leaders with a different kind of experience, rather than simply competing for their attention on the conference floor.</span></p><h2><span>From Airport Pickups To Ransomware Negotiations</span></h2><p><span>The first video introduces the CISO Genie through a series of requests that blend everyday conference frustrations with cybersecurity humor. His responsibilities include investigating incidents, calming executives and keeping security teams together, while his list of services extends to quiet meeting rooms, fresh shirts, dinner reservations, private airport pickups and personal barbers.</span></p><p><span>&#8220;I grant wishes for CISOs. I investigate incidents, calm down executives, and convince security teams not to quit,&#8221; the character says. The joke continues when the genie explains that CISOs no longer have just three wishes: &#8220;Used to be three. Then someone hacked the lamp. Changed it to unlimited.&#8221;</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eQC0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eQC0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png 424w, https://substackcdn.com/image/fetch/$s_!eQC0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png 848w, https://substackcdn.com/image/fetch/$s_!eQC0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png 1272w, https://substackcdn.com/image/fetch/$s_!eQC0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eQC0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png" width="1456" height="816" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:816,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eQC0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png 424w, https://substackcdn.com/image/fetch/$s_!eQC0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png 848w, https://substackcdn.com/image/fetch/$s_!eQC0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png 1272w, https://substackcdn.com/image/fetch/$s_!eQC0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4e4fdb3-ec99-4ae5-82c6-1e803b572963_2048x1148.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>The </span><a href="https://www.linkedin.com/posts/hagai-shapira_we-recently-introduced-the-ciso-genie-daylights-activity-7486048074663100417-zkTD?utm_source=social_share_send&amp;utm_medium=member_desktop_web&amp;rcm=ACoAACBfb1YBqKPR7SMH8cNxQw7G9p7EjKFyUbQ"><span>second video</span></a><span> builds on the same concept with a new set of demands, including finding a faster route across Mandalay Bay and securing a table for eight at Carbone. The latter proves particularly difficult for the fictional concierge. &#8220;I&#8217;ve handled ransomware negotiations. This was harder,&#8221; he says.</span></p><h2><span>A Campaign Built Around The CISO Experience</span></h2><p><span>The videos also poke fun at the language and trends surrounding cybersecurity. In the second episode, the genie is asked how he keeps up with everything and responds with an exaggerated routine: &#8220;We&#8217;re agentic! We&#8217;re agentic! We&#8217;re AI-native agentic! Again! More disruptive! Agentic! Every morning.&#8221;</span></p><p><span>Another scene introduces what the video calls &#8220;the most important room at Black Hat&#8221;: a quiet room for CISOs. When asked why everyone is whispering, the answer is simple: &#8220;CISOs are recovering.&#8221; Shapira&#8217;s accompanying post reinforces the campaign&#8217;s deliberately lighthearted approach: &#8220;No thought leadership today. Just press play.&#8221;</span></p><p><span>Beneath the humor is a broader message about how Daylight views its role in the security industry. The company&#8217;s first LinkedIn post says, &#8220;We built Daylight because we think security services should feel different. Less noise. Less friction. Better outcomes. More accountability.&#8221; By putting the CISO Genie at the center of its Black Hat presence&#8212;and turning the concept into a widely shared social campaign&#8212;Daylight is using humor to communicate that philosophy while giving security leaders something other than another vendor pitch to think about.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Paul Blahusch on Business Success Coming First]]></title><description><![CDATA[Paul Blahusch shares CISO tips on affording tools, leading by example, cutting low-value work, and framing risk so the business stays successful.]]></description><link>https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first</guid><dc:creator><![CDATA[John Kevin Hao]]></dc:creator><pubDate>Wed, 22 Jul 2026 08:24:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bud1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bud1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bud1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bud1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bud1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bud1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bud1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg" width="1456" height="1640" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1640,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:954880,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cisohq.io/i/208028140?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bud1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bud1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bud1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bud1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37d33a8e-36e5-489c-b020-9702ac055ba6_2409x2714.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><a href="https://www.linkedin.com/in/paul-blahusch-4701369/">Paul Blahusch</a> is the founder and president of <a href="https://www.ba-cyberconsulting.com/">B&amp;A Cybersecurity Consulting</a>. He is a former federal cabinet agency Chief Information Security Officer (CISO) with over 25 years of experience in cybersecurity leadership, specializing in safeguarding information systems and data. He has a proven ability to enhance organizational efficiency while managing substantial budgets and ensuring compliance with regulatory standards. Paul has expertise in developing and implementing comprehensive cybersecurity strategies, including zero trust frameworks and risk management initiatives. He is committed to fostering a culture of security awareness and readiness and is passionate about leveraging technology and best practices to protect critical assets and support organizational missions.</p><p>In addition to his work with B&amp;A Cybersecurity Consulting, he is the Cybersecurity Advisor for the Consortium of Universities of the Washington Metropolitan Area, a Mission Critical Fellow, and a frequent speaker at cybersecurity conferences.</p><h2><strong>1. Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</strong></h2><p>Determine if it makes you better and, if so, how you can afford it.</p><h2><strong>2. What&#8217;s one rule you enforce on your team that other teams would find strict?</strong></h2><p>I stressed scrupulous adherence by the cyber team to all organizational policies: budget, procurement, HR, physical security, and more. If we expected organization personnel to follow our cybersecurity policies, the cyber team should lead by example across the board.</p><h2><strong>3. What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</strong></h2><p>I&#8217;ll go with my own time. There is an ongoing mental calculation. Whatever is urgent and important gets attention. Generally, that ends up being what is most important at the moment to help protect and ensure business success.</p><h2><strong>4. What&#8217;s one line that works when asking the board or CFO for a budget?</strong></h2><p>Here is how this will pay for itself, through efficiencies, reducing or eliminating duplicative solutions, lower insurance premiums, and other savings.</p><h2><strong>5. What should a CISO cut from their program tomorrow with zero regret?</strong></h2><p>Do this exercise. Ask your team to tell you what activities they do that don&#8217;t appear to have value, and to estimate how much time they spend on each. For example, this could be a long-standing report they prepare that no one up the org chart ever comments on. Evaluate the results. Eliminate based on least value and highest cost. No regret.</p><h2><strong>6. What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</strong></h2><p>Tell me what problem I have that this helps solve, or how this makes me better, more secure, more efficient. Why would I want this? And tell me how I can have this within my current budget, whether by replacing or reducing something else, lowering cost elsewhere, or another option. How can I afford this?</p><h2><strong>7. What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</strong></h2><p>I killed maintaining the five-year cybersecurity strategic plan document. It was a bloated, time-consuming, never-referenced, obsolete-as-soon-as-it-was-published, costly product. We replaced it with annual tangible and trackable goals, combined with shorter &#8220;sprint&#8221; objectives throughout the year.</p><h2><strong>8. In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</strong></h2><p>Using the playbook. They often get so quickly engrossed in the technical details of the incident, determining the where and how, that they forget to open the playbook. This can lead them to miss important steps defined in the playbook, like preserving evidence, documenting a record of the incident, and establishing secure communications.</p><h2><strong>9. What&#8217;s one question every CISO should ask their team this week?</strong></h2><p>How can I best help you be successful? Is that by being a sounding board, getting you needed resources, providing top cover for an initiative, or providing a decision or approval?</p><h2><strong>10. What&#8217;s a phrase or framing you use to translate a technical risk for executives?</strong></h2><p>Executives are familiar with evaluating risks of all types. Frame technical, or cyber, risk through a similar lens. Namely, how it will impact the business.</p><h2><strong>11. What&#8217;s your best tip for surviving the CISO role in exactly five words?</strong></h2><p>Remember, business success comes first. As a C-Suite executive, my role isn&#8217;t to provide cybersecurity. Rather, it is to make sure the business is successful. The primary way I, as CISO, contribute to that success is by directing a cybersecurity program that keeps cyber risk at an acceptable level to the business.</p><p><span>Get more tips from CISOs working in various industries:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-diyar-akhmedov-on-prioritizing-risk-over-hype">CISO Tips: Diyar Akhmedov on Prioritizing Risk Over Hype</a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-peter-egyed-on-why-consistency"><span>CISO Tips: Peter Egyed on Why Consistency and Prioritization Strengthen Cybersecurity</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-nikolas-oelkrug-alders"><span>CISO Tips: Nikolas Oelkrug-Alders on Why Strong Security Starts With the Fundamentals</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-rocco-barra-on-never-taking-things-for-granted"><span>CISO Tips: Rocco Barra on Never Taking Anything for Granted</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-barak-blima-on-building-trust-before-needing-it"><span>CISO Tips: Barak Blima on Building Trust Before Needing It</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Fig Reframes SecOps Around Continuous Engineering as Security Environments Grow More Complex]]></title><description><![CDATA[Security operations teams are expected to respond quickly as new threats emerge, but the infrastructure behind that response is changing just as rapidly.]]></description><link>https://www.cisohq.io/p/fig-reframes-secops-around-continuous</link><guid isPermaLink="false">https://www.cisohq.io/p/fig-reframes-secops-around-continuous</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Tue, 21 Jul 2026 14:06:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!V6up!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V6up!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V6up!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V6up!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V6up!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V6up!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V6up!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg" width="1456" height="736" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:736,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V6up!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V6up!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V6up!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V6up!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83028b10-1ab1-464a-8456-8bbce71d8b81_1842x931.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Security operations teams are expected to respond quickly as new threats emerge, but the infrastructure behind that response is changing just as rapidly. New data sources are introduced, cloud services evolve, detections are added, and automations become part of increasingly interconnected workflows.</span></p><p><span>The challenge is that security infrastructure does not operate in isolation. A change in one part of the environment can affect another, potentially disrupting detection pipelines without immediately alerting the teams responsible for protecting the organization.</span></p><p><a href="http://fig.security"><span>Fig</span></a><span> is addressing that challenge by expanding its platform across what it describes as the complete SecOps engineering lifecycle. The company says its approach brings a CI/CD model to Security Operations (SecOps), allowing engineers to build, ship, and observe changes while maintaining greater confidence in the systems responsible for detection and response.</span></p><p><span>The move reflects a broader shift in security operations: as the technology stack becomes more complex, managing change itself is becoming a critical part of security engineering.</span></p><h2><span>Treating Detection Changes Like Software</span></h2><p><span>At its core, Fig is giving SecOps something it has never had: a complete engineering lifecycle for detections and configurations.</span></p><p><span>The workflow begins with the change an engineer wants to make. Rather than manually connecting systems and configuring infrastructure, the engineer describes the desired detection or configuration, and Fig analyzes the live environment to propose an implementation.</span></p><p><span>Before deployment, the proposed change is simulated and tested to evaluate its expected impact. Approved changes can then be deployed with version control and rollback capabilities, while continuous observability monitors detection flows after deployment.</span></p><p><span>The approach brings concepts that have become standard in software engineering into security operations. Testing and validation happen before production, changes can be rolled back, and ongoing monitoring continues after deployment.</span></p><p><span>For SecOps teams, the result is intended to be a more structured way to manage the infrastructure supporting detection and response.</span></p><h2><span>The Role of Security Data Lineage</span></h2><p><span>Fig&#8217;s platform is built on a deterministic graph of security data lineage that maps detections, data sources, and their connections throughout the SecOps environment.</span></p><p><span>The company views this lineage as the foundation for understanding how changes move through the infrastructure. By mapping the relationships between different components, Fig can evaluate proposed changes with greater context and assess how they might affect the broader detection pipeline.</span></p><p><span>That context becomes particularly important when changes originate outside the immediate control of the security team. Upstream or downstream systems can evolve independently, potentially creating problems that are difficult to identify until detection coverage has already been affected.</span></p><p><span>Continuous verification is designed to provide ongoing visibility into those relationships and help ensure detection flows continue working as intended.</span></p><h2><span>Turning Security Work Into an Engineering Workflow</span></h2><p><span>The platform is also intended to shorten the time required for several common SecOps activities.</span></p><p><span>Fig says security teams can turn threat reports into detections and queries more quickly, allowing them to address emerging threats without waiting through lengthy engineering processes. SIEM migrations can also be completed in weeks rather than months, according to the company, while organizations remain fully operational throughout the transition.</span></p><p><span>The platform&#8217;s data plane capabilities give teams greater control over data ingestion and storage spending without affecting live detections.</span></p><p><span>These capabilities point to a common objective: reducing the amount of manual infrastructure work required to keep security operations running, while allowing engineers to concentrate on detection logic and improving coverage.</span></p><h2><span>Confidence Becomes Part of the Deployment Process</span></h2><p><span>For Fig, speed is only one measure of an effective security engineering workflow. The company is equally focused on whether teams can trust the changes they make.</span></p><p><span>Jayme Hancock, Head of Security Operations and Engineering at AppLovin, said, &#8220;With Fig we build and ship accurate detection changes in minutes instead of weeks, without the endless plumbing.&#8221; He added, &#8220;My team builds with a confidence we&#8217;ve never had, and yeah, we&#8217;ve even started &#8216;vibe parsing.&#8217;&#8221;</span></p><p><span>The customer perspective reinforces the company&#8217;s argument that reducing the engineering effort around changes can also improve confidence in the resulting environment.</span></p><h2><span>A Broader Bet on Security Operations Resilience</span></h2><p><span>Fig&#8217;s platform expansion builds on its focus on Security Operations Resilience. The company has raised $38 million from Team8, Ten Eleven Ventures, and Crosspoint Capital, was named a finalist in the RSAC Innovation Sandbox, and says its technology has been deployed across dozens of Fortune 500 companies.</span></p><p><span>Founded by veterans of Google SecOps and Siemplify, Fig says its platform is informed by experience with large and complex security operations environments where changes can create unexpected failures.</span></p><p><span>Gal Shafir, Co-Founder and CEO of Fig, said the company wants to remove the perceived choice between speed and reliability. &#8220;Security teams shouldn&#8217;t have to choose between moving quickly and maintaining confidence in their SecOps Infrastructure,&#8221; he said. &#8220;Fig gives SecOps Engineers the same modern engineering workflow that software developers have long relied on. They can design changes with complete context, prove those changes work before deployment, and continuously verify that their security operations remain resilient as their environments evolve.&#8221;</span></p><p><span>As SecOps infrastructure becomes more interconnected, Fig&#8217;s approach suggests that resilience may increasingly depend on how organizations engineer change&#8212;not simply on how many security tools they deploy.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Diyar Akhmedov on Prioritizing Risk Over Hype]]></title><description><![CDATA[Diyar Akhmedov shares CISO tips on running PoCs before buying, budgeting by risk impact, faster incident response, and framing risk for the board.]]></description><link>https://www.cisohq.io/p/ciso-tips-diyar-akhmedov-on-prioritizing-risk-over-hype</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-diyar-akhmedov-on-prioritizing-risk-over-hype</guid><dc:creator><![CDATA[John Kevin Hao]]></dc:creator><pubDate>Tue, 21 Jul 2026 11:08:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!kLa7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kLa7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kLa7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!kLa7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!kLa7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!kLa7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kLa7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg" width="946" height="1280" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1280,&quot;width&quot;:946,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:175080,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cisohq.io/i/207899828?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kLa7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!kLa7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!kLa7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!kLa7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f7c0b2a-8bf4-4c12-a875-0d7b29590947_946x1280.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>With more than 20 years of experience across banking, financial services, government, and critical infrastructure, </span><a href="https://www.linkedin.com/in/diyar-akhmedov-91458950/"><span>Diyar </span>Akhmedov</a><span> has built his career around helping organizations make practical, risk-based security decisions. His background spans cyber risk management, security strategy, governance, regulatory compliance, security architecture, and building security programs that align with business objectives rather than industry trends.</span></p><p><span>In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, </span>Akhmedov<span> shares why every security investment should begin with a clear understanding of the problem it solves, why proof-of-concept testing matters more than polished vendor presentations, and how CISOs can communicate technical risks in business terms. His advice emphasizes disciplined prioritization, operational effectiveness, and focusing security efforts on measurable outcomes instead of the latest buzzwords.</span></p><h3><span>1. Complete the sentence: &#8220;Before buying any new security tool, first&#8230;&#8221;</span></h3><p><span>&#8230;make sure you clearly understand the problem you are trying to solve.</span></p><p><span>In practice, this is not always as obvious as it sounds. Sometimes a solution looks attractive because the market is talking about it, other companies are using it, or the vendor gave a strong presentation. Before making a decision, I try to answer a few basic questions: Which risk are we reducing? What will actually change after implementation? And how will we know whether the product is working?</span></p><p><span>For critical solutions, I prefer to run a PoC first. Over the years, I have seen products look excellent during a demo and then struggle with basic integration once the PoC started.</span></p><h3><span>2. What is one rule you enforce on your team that other teams might consider too strict?</span></h3><p><span>We do not make major security decisions based only on a vendor presentation, an analyst rating, or a product&#8217;s reputation in the market.</span></p><p><span>I need to see how the solution performs in our own environment. A strong presentation does not guarantee a successful implementation. During a PoC, you may discover issues with integration, performance, support quality, or day-to-day operations.</span></p><p><span>I have seen well-known products with strong brands create more manual work for the security team than real value. I have also seen less prominent solutions perform very well simply because they were a better fit for the organization&#8217;s actual processes.</span></p><h3><span>3. What metric or ratio guides how you allocate budget, headcount, or your own time?</span></h3><p><span>I do not use one fixed formula for every situation.</span></p><p><span>I normally look at the level of risk, the expected risk reduction, the cost, and the complexity of implementation. A low-cost initiative is not always the highest priority, and an expensive one is not automatically excessive. It depends on the potential business impact of the risk.</span></p><p><span>I apply the same approach to my own time. I try not to become involved in every technical detail when the team can resolve the issue independently. My time should be focused on areas where prioritization, a management decision, or communication with the business is required.</span></p><h3><span>4. What is the best phrase to use when asking the board or the CFO for the budget?</span></h3><p><span>I try not to start a conversation with a product name.</span></p><p><span>Instead of saying, &#8220;We need to buy a new system,&#8221; I explain the current risk, how it may affect the business, and what will change if the investment is approved.</span></p><p><span>The board does not necessarily need to understand every technical difference between EDR and SIEM solutions. It does need to understand whether the current situation could lead to the disruption of a critical service, financial loss, regulatory consequences, or damage to customer trust.</span></p><p><span>Once the conversation starts with business risk, the budget discussion becomes much more practical.</span></p><h3><span>5. What should every CISO remove from their program tomorrow without regret?</span></h3><p><span>Projects that exist only because they are currently popular or because &#8220;everyone else is doing them.&#8221;</span></p><p><span>The information security industry is highly influenced by trends. Every year brings new technologies, approaches, and impressive terminology. But if an initiative is not connected to a specific risk or business need, it can quickly become an expensive project without a clear outcome.</span></p><p><span>I would rather have a shorter, realistic security program than a large roadmap that cannot be delivered properly. It is better to address five important risks than to launch fifteen fashionable projects and fail to make any of them operational.</span></p><h3><span>6. How do you decide within 60 seconds whether a vendor presentation is worth your time?</span></h3><p><span>I normally ask three questions:</span></p><p><span>What problem does your product solve? How difficult is the integration? How will we measure the result after implementation?</span></p><p><span>I do not expect a complete technical answer in one minute. I want to understand whether the vendor can speak about real-world operations rather than only product capabilities.</span></p><p><span>If the answer immediately turns into a discussion about artificial intelligence, unique algorithms, and attractive dashboards, but says nothing about integration, operational workload, or success criteria, I usually take that as a warning sign.</span></p><h3><span>7. What meeting, report, or process did you eliminate, and what replaced it?</span></h3><p><span>I try to reduce meetings where participants simply repeat information that is already available in reports.</span></p><p><span>If the status of a project can be shown on one page or in a short dashboard, there is no reason to bring ten people together for an hour. A meeting is useful when a decision needs to be made, a blocker needs to be removed, or ownership needs to be clarified.</span></p><p><span>The same applies to reports. If a report is produced every week but no one uses it to make a decision, I question why the team is still spending time on it.</span></p><p><span>We should not measure effectiveness by the number of meetings or documents. What matters is how quickly decisions are made, and real problems are resolved.</span></p><h3><span>8. What do incident response teams most often miss in the first ten minutes?</span></h3><p><span>The first instinct is understandable: stop the attack as quickly as possible.</span></p><p><span>But in doing so, teams sometimes start shutting down systems, terminating processes, or changing configurations before collecting the necessary data. As a result, logs, memory contents, and other important evidence may be lost.</span></p><p><span>I am not saying that evidence preservation is always more important than containment. If there is an immediate threat to the business, it must be stopped. But the team should act consciously and understand which actions may destroy evidence and which data must be preserved first.</span></p><p><span>Good incident response is a balance between speed, damage control, and the ability to reconstruct what actually happened afterward.</span></p><h3><span>9. What question should every CISO ask their team this week?</span></h3><p><span>&#8220;Which security control do we believe is working even though we have not tested it recently?&#8221;</span></p><p><span>It could be backup and recovery, MFA, EDR, PAM, security monitoring, or the incident response plan.</span></p><p><span>In information security, it is very easy to confuse the existence of a control with its effectiveness. A system may be installed, the licence may be active, and the dashboard may show a green status, yet the control may still fail when it is actually needed.</span></p><p><span>That is why I trust test results more than confident assumptions.</span></p><h3><span>10. What phrase do you use to explain technical risk to executives?</span></h3><p><span>I usually say: &#8220;This is a business risk caused by a technical issue.&#8221;</span></p><p><span>That wording helps move the discussion from a purely technical level to a management level.</span></p><p><span>Executives do not always need the details of a vulnerability, configuration issue, or attack scenario. They need to understand what may happen, how likely it is, what the potential impact is, and which options are available.</span></p><p><span>My role is not to overwhelm them with technical language. It is to provide enough information for an informed decision.</span></p><h3><span>11. What is your best survival advice for a CISO role in exactly five words?</span></h3><p><span>Prioritize risks. Build trust. Explain.</span></p><p><span>Get more tips from CISOs working in various industries:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-peter-egyed-on-why-consistency"><span>CISO Tips: Peter Egyed on Why Consistency and Prioritization Strengthen Cybersecurity</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-nikolas-oelkrug-alders"><span>CISO Tips: Nikolas Oelkrug-Alders on Why Strong Security Starts With the Fundamentals</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-rocco-barra-on-never-taking-things-for-granted"><span>CISO Tips: Rocco Barra on Never Taking Anything for Granted</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-barak-blima-on-building-trust-before-needing-it"><span>CISO Tips: Barak Blima on Building Trust Before Needing It</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-fred-streefland-on-managing-business-risk"><span>CISO Tips: Fred Streefland on Managing Risk So the Business Can Do Business</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item></channel></rss>