<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[CISO HQ ]]></title><description><![CDATA[CISO HQ is an independent publication for Chief Information Security Officers and cybersecurity leaders. We cover the latest cyber threats, industry trends, funding, M&A, executive moves, and the technologies shaping enterprise security. ]]></description><link>https://www.cisohq.io</link><image><url>https://substackcdn.com/image/fetch/$s_!T2is!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F802272e2-c335-4db1-835a-9f659f19ffba_1280x1280.png</url><title>CISO HQ </title><link>https://www.cisohq.io</link></image><generator>Substack</generator><lastBuildDate>Fri, 02 Oct 2026 21:59:31 GMT</lastBuildDate><atom:link href="https://www.cisohq.io/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Media Network]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[cisohq@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[cisohq@substack.com]]></itunes:email><itunes:name><![CDATA[Media Network]]></itunes:name></itunes:owner><itunes:author><![CDATA[Media Network]]></itunes:author><googleplay:owner><![CDATA[cisohq@substack.com]]></googleplay:owner><googleplay:email><![CDATA[cisohq@substack.com]]></googleplay:email><googleplay:author><![CDATA[Media Network]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[CISO Tips: Merlin Namuth on Earning Trust and Measuring Everything Against Risk]]></title><description><![CDATA[Denver CISO Merlin Namuth shares his approach to budgeting, vendor pitches, incident response, and team culture, all measured against business risk.]]></description><link>https://www.cisohq.io/p/ciso-tips-merlin-namuth-on-risk-based-security-leadership</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-merlin-namuth-on-risk-based-security-leadership</guid><dc:creator><![CDATA[John Kevin Hao]]></dc:creator><pubDate>Mon, 28 Sep 2026 06:52:50 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/bb40781b-c6f8-4af6-9da3-4354c7bd1d7c_263x309.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k_yE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k_yE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg 424w, https://substackcdn.com/image/fetch/$s_!k_yE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg 848w, https://substackcdn.com/image/fetch/$s_!k_yE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!k_yE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k_yE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg" width="263" height="309" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:false,&quot;imageSize&quot;:&quot;normal&quot;,&quot;height&quot;:309,&quot;width&quot;:263,&quot;resizeWidth&quot;:263,&quot;bytes&quot;:43606,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cisohq.io/i/217645141?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:&quot;center&quot;,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k_yE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg 424w, https://substackcdn.com/image/fetch/$s_!k_yE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg 848w, https://substackcdn.com/image/fetch/$s_!k_yE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!k_yE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e5e157e-3d1b-4f83-abf7-fb1c7013b156_263x309.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><a href="https://www.linkedin.com/in/merlin-namuth">Merlin Namuth</a> is the Chief Information Security Officer at the City and County of Denver, where he leads security for over 50 agencies and departments. His experience spans multiple industries and includes building security programs from the ground up, advancing mature programs, leading incident response, and handling compliance, architecture, and mergers and acquisitions. A regular conference speaker and security startup advisor, he is also an active writer and podcast guest in the security community.</p><p>For Namuth, security leadership comes down to risk and trust. His approach includes weighing every tool purchase and budget request against the risk it reduces, cutting work that doesn&#8217;t move the program forward, and building relationships across the organization before a crisis hits. In this edition of <a href="https://www.cisohq.io/">CISO Tips</a>, Namuth shares practical lessons on budgeting, vendor evaluation, incident response, team culture, and translating technical risk for executives.</p><h4>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</h4><p>Before you buy any new security tool, first understand what risk it will address, how much it will reduce that risk, and if the cost justifies the impact it will have on risk.</p><h4>What&#8217;s one rule you enforce on your team that other teams would find strict?</h4><p>We are in a position of high trust in the organization, and it is very important for us to have high integrity, adhere to the policies and rules, and help everyone who comes to our team, whether or not their issue falls within something we support and can fix. Trust takes a lot of work to earn and can go away in an instant with a bad decision.</p><h4>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</h4><p>It is based on the severity of the risk and how reducing this risk will positively or negatively impact the business.</p><h4>What&#8217;s one line that works when asking the board or CFO for a budget?</h4><p>I explain the risk and how an increased budget will reduce that risk. Conversely, I share how no change in budget will keep the risk the same, and the potential costs to the business if it is exploited.</p><h4>What should a CISO cut from their program tomorrow with zero regret?</h4><p>Work the team is doing that doesn&#8217;t reduce risk or mature the security program.</p><h4>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</h4><p>If the solution solves a current challenge I have and fits in my current roadmap. When the vendor says they can have their solution running and providing value within 15 minutes, I tend to eliminate them from consideration.</p><h4>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</h4><p>I canceled weekly status meetings with my team because we had enough informal conversations for me to be informed. Too many meetings is malware.</p><h4>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</h4><p>Getting the right people involved, which should be outlined in the incident response plan.</p><h4>What&#8217;s one question every CISO should ask their team this week?</h4><p>I usually lead with &#8220;How are you?&#8221; I want my team to feel valued and appreciated, and to know that everything we do is part of the team. If one person on the team is struggling with something, it is the responsibility of the rest of the team to help out.</p><h4>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</h4><p>In my current role as CISO for the City and County of Denver, I discuss how something can impact our public safety agencies and our residents.</p><h4>What&#8217;s your best tip for surviving the CISO role in exactly five words?</h4><p>Build relationships before crisis hits.</p><p>More tips from the series:</p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-samuel-keter-on-turning">CISO Tips: Samuel Keter on Turning Security Controls Into Business Decisions</a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-bryce-austin-on-building">CISO Tips: Bryce Austin on Building a Security Program That&#8217;s &#8220;Secure Enough&#8221;</a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-stefano-pasotti-on-turning">CISO Tips: Stefano Pasotti on Turning Cybersecurity Into Business Resilience</a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-maurizio-imperadore-on">CISO Tips: Maurizio Imperadore on Resilience, Identity and Cutting Security Noise</a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer">CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust</a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p>]]></content:encoded></item><item><title><![CDATA[Upwind Acquires Aegis as New AI Security Labs Targets AI-Powered Cyberattacks]]></title><description><![CDATA[As artificial intelligence becomes more deeply integrated into enterprise workflows, security teams are facing a growing set of challenges around the systems that support those deployments.]]></description><link>https://www.cisohq.io/p/upwind-acquires-aegis-as-new-ai-security</link><guid isPermaLink="false">https://www.cisohq.io/p/upwind-acquires-aegis-as-new-ai-security</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 23 Sep 2026 12:48:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RJd5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RJd5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RJd5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RJd5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RJd5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RJd5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RJd5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg" width="1456" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RJd5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RJd5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RJd5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RJd5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b8ae240-0586-4a4e-8887-8ee3ee5d7d67_2048x1365.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>As artificial intelligence becomes more deeply integrated into enterprise workflows, security teams are facing a growing set of challenges around the systems that support those deployments. </span><a href="https://www.upwind.io/"><span>Upwind</span></a><span> is addressing that shift by acquiring AI security startup Aegis and creating a new AI Security Labs operation, as first reported by </span><a href="https://www.axios.com/pro/enterprise-software-deals/2026/09/23/upwind-cybersecurity-aegis"><span>Axios</span></a><span>.</span></p><p><span>The acquisition brings Aegis founders Omri Limor and Saar Ankonina into Upwind and establishes a dedicated research and engineering initiative within the company. Upwind says the labs will investigate emerging AI security risks while working to turn that research into enterprise-grade security capabilities.</span></p><p><span>The new operation will build on both Aegis&#8217;s technology and Upwind&#8217;s existing runtime platform, with work spanning scanning, attack detection and other AI security capabilities.</span></p><h2><span>A Focus on the New AI Attack Surface</span></h2><p><span>AI agents are increasingly capable of interacting with applications, accessing information and executing tasks, while skills and plugins can give those systems additional functionality. Those capabilities also introduce new components and potential security considerations for organizations deploying AI-powered workflows.</span></p><p><span>Upwind AI Security Labs will focus on researching those risks and developing capabilities designed to identify and address them. The labs will also prioritize secret scanning in transit and at rest, with Upwind pointing to industry findings involving API keys and session tokens that were compromised and harvested at scale for malicious campaigns.</span></p><p><span>The initiative builds on Aegis&#8217;s original focus on security challenges created by AI infrastructure. The startup was founded by Limor and Ankonina, who began their careers together as 8200 alumni working in offensive cybersecurity before later serving in different roles and eventually becoming peers.</span></p><p><span>After leaving the unit, the two founded Aegis to work on sophisticated AI-generated attacks, including autonomous exploitation pipelines and large-scale credential harvesting. The company later approached Upwind about strategic partnership and investment, and several months of collaboration ultimately resulted in the acquisition.</span></p><h2><span>Combining Two Security Capabilities</span></h2><p><span>For Upwind CEO and Co-Founder Amiram Shachar, bringing Aegis into the company is intended to increase the speed at which the organization can respond to developments in AI security.</span></p><p><span>&#8220;AI security is developing extremely quickly, and by acquiring Aegis and bringing Omri and Saar on board, we are building a team that can move just as quickly,&#8221; said Amiram Shachar, CEO and Co-Founder at Upwind. &#8220;The Aegis team brings a deep understanding of the challenges around securing agents, skills, and plugins, and by combining that expertise with Upwind&#8217;s existing platform, we can move from research to real-world security capabilities much faster.&#8221;</span></p><p><span>The Aegis founders similarly see the acquisition as a way to accelerate their existing work. &#8220;We initially built Aegis as a startup to tackle the missing security layer around AI agents, skills and plugins,&#8221; said Omri Limor, Co-Founder of Aegis. &#8220;After spending several months working together with Upwind, it became clear that joining forces through an acquisition and establishing AI Security Labs inside Upwind would allow us to move much faster and combine our technology with the capabilities Upwind has already built.&#8221;</span></p><p><span>Ankonina added that the integration offers a direct route to scaling the technology. &#8220;Integrating our technology directly into Upwind&#8217;s platform gives us an immediate path to scale,&#8221; added Saar Ankonina, Co-Founder of Aegis. &#8220;The establishment of AI Security Labs provides the ideal environment to accelerate research and protect enterprise AI workflows.&#8221;</span></p><h2><span>Expanding Beyond the Initial Team</span></h2><p><span>The labs are beginning with 12 developers and researchers from Aegis and Upwind, with plans to significantly increase that number. Upwind expects the group to reach approximately 25 people within three months and potentially grow to 35 as the initiative continues to develop.</span></p><p><span>The planned growth will expand the company&#8217;s research and engineering capacity as it works on emerging AI security challenges. Shachar said the team is intended to become a significant research and engineering capability within Upwind rather than remain a small group attached to the acquisition.</span></p><p><span>&#8220;We built AI Security Labs on the foundation of the Aegis acquisition with the ambition to create a significant research and engineering capability within Upwind,&#8221; said Shachar. &#8220;We expect the team to grow from 12 people today to 25 and potentially 35 in the coming months, allowing us to expand our research and accelerate the development of new AI security capabilities.&#8221;</span></p><h2><span>Speeding Up the Path From Research to Market</span></h2><p><span>A central part of the initiative will be connecting security research with practical product development. Upwind says that as AI capabilities evolve, identifying new attack techniques and translating those findings into usable defenses will become increasingly important.</span></p><p><span>By bringing Aegis&#8217;s technology and team into Upwind, the company says AI Security Labs can shorten the path between identifying emerging risks and developing new security capabilities. The effort is positioned as an extension of Upwind&#8217;s existing mission around cloud and AI security.</span></p><p><span>&#8220;As AI transforms both the threat landscape and the speed of modern cyber operations, this is the ideal moment to build, innovate, and lead in cloud and AI security,&#8221; added Shachar. &#8220;With AI Security Labs, Upwind is reinforcing its mission to protect modern enterprise infrastructure and ensure organizations can safely embrace the next era of AI innovation.&#8221;</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Samuel Keter on Turning Security Controls Into Business Decisions]]></title><description><![CDATA[With more than a decade of experience across cloud security, audits, risk management and security governance, Samuel Keter has worked at the intersection of cybersecurity and business operations across banking, fintech and consulting organizations.]]></description><link>https://www.cisohq.io/p/ciso-tips-samuel-keter-on-turning</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-samuel-keter-on-turning</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Thu, 17 Sep 2026 11:07:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FjHD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FjHD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FjHD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!FjHD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!FjHD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!FjHD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FjHD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FjHD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!FjHD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!FjHD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!FjHD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e1fff5b-2f2e-4250-bac6-70edf7d7e309_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>With more than a decade of experience across cloud security, audits, risk management and security governance, </span><a href="http://linkedin.com/in/samuel-kibet-keter-014b7398?originalSubdomain=ke"><span>Samuel Keter</span></a><span> has worked at the intersection of cybersecurity and business operations across banking, fintech and consulting organizations. He has led teams through ISO 27001, PCI DSS, SOC 2 and NIST programs, managed complex cloud and on-premises audits, and advised executive leadership on security risks and controls across multiple regions.</span></p><p><span>For Keter, effective security leadership is less about accumulating tools and metrics and more about building systems that reduce measurable risk. His approach includes testing what existing technology can already accomplish before buying new products, enforcing security gates in development pipelines, allocating resources according to risk, and translating technical exposure into numbers executives already understand. In this edition of </span><a href="https://www.cisohq.io/"><span>CISO Tips</span></a><span>, Keter shares practical lessons on budgeting, incident response, cloud identity, compliance evidence and making security decisions that hold up under scrutiny.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading CISO HQ ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>Before you buy any new security tool, first build the simple version with what you already own. We scripted a cloud misconfiguration audit across every project before looking at a posture product. The audit identified most of the issues that the demo had presented. The identified gaps formed the basis for the shortlist and our negotiating position.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>Nothing merges without a signed commit and a green security gate, and the gate is required verification, not advisory. It blocked a release in its first week, and the team fixed the finding rather than disabling the verification. That decision is the rule.  Most teams have the same policy but a pipeline that doesn&#8217;t enforce it.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>70, 20, 10. 70% of the budget and headcount is allocated to risk reduction, 20% to proof, and 10% to options. Workload identity to kill static keys retires a register item, so it comes from the 70. Compliance automation that collects control evidence on a schedule reduces no risk but makes SOC 2 and PCI DSS continuous,  so it comes from the 20. A month for an engineer to build an alert triage agent might fail, so it comes from the 10. A second dashboard is not being developed because  someone prefers the interface, so it remains on hold.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>This expense is not security spending. It is the cost of keeping our license to process payments. Then I put the control cost next to the share of revenue running over card rails, and the conversation becomes about their exposure rather than my budget.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Do not use any metric that counts items unless it influences a decision. We dropped total open vulnerabilities from the executive report and replaced them with exploitable findings on internet-facing assets and the median days to close. The total rose the next month because we found more. Nobody asked, because the numbers that mattered fell.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>I ask how the product authenticates to my cloud. A service account key with an owner role fails the test I hold my engineers to, and the meeting is over. Federated identity,  scoped permissions, and an expiring token earn the next twenty minutes.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>The weekly alert review involves five people reading raw findings displayed on a screen.  A monitoring agent now ingests events from source control, applies a rule-based severity floor before the model sees them, and logs every decision to an audit table. It ran in shadow mode for weeks, with the team grading its calls before anything was routed based on its output. The audit table is now our evidence for the monitoring control.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Stopping the pipeline. In a package registry compromise this year, freezing CI and pinning the package took under ten minutes. Working out how it was poisoned took days. Teams do those in the wrong order, and every build in between pulls the compromised version again.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>If an auditor asked for evidence of this control at nine tomorrow, what would we be able to provide? Ask about one control each week. The phrase &#8220;I would have to pull it  together&#8221; indicates that while the control is legitimate, the supporting evidence is lacking, which is the basis for the next audit finding.</span></p><p><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></p><p><span>Three numbers the board already tracks: customers exposed, money at risk, and hours until we would know. A permissive IAM binding means nothing to them. Every customer in the wallet database, the balance held there, and four days before detection fires gets a decision in the same meeting.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>Trust nothing. Log everything. Sleep.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-bryce-austin-on-building"><span>CISO Tips: Bryce Austin on Building a Security Program That&#8217;s &#8220;Secure Enough&#8221;</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-stefano-pasotti-on-turning"><span>CISO Tips: Stefano Pasotti on Turning Cybersecurity Into Business Resilience</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-maurizio-imperadore-on"><span>CISO Tips: Maurizio Imperadore on Resilience, Identity and Cutting Security Noise</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer"><span>CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning"><span>CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[A LinkedIn Post From Mate Security’s Asaf Wiener Is Putting AI And Cyber Defense Back In The Spotlight]]></title><description><![CDATA[A growing discussion among cybersecurity executives is taking place around a deceptively simple question: what happens if artificial intelligence moves faster on the offensive side than it does on the defensive side?]]></description><link>https://www.cisohq.io/p/a-linkedin-post-from-mate-securitys</link><guid isPermaLink="false">https://www.cisohq.io/p/a-linkedin-post-from-mate-securitys</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 16 Sep 2026 13:35:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bV4P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bV4P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bV4P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png 424w, https://substackcdn.com/image/fetch/$s_!bV4P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png 848w, https://substackcdn.com/image/fetch/$s_!bV4P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!bV4P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bV4P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png" width="1456" height="910" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:910,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bV4P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png 424w, https://substackcdn.com/image/fetch/$s_!bV4P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png 848w, https://substackcdn.com/image/fetch/$s_!bV4P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png 1272w, https://substackcdn.com/image/fetch/$s_!bV4P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5079cbcc-1b7a-4e1b-b783-0b199ad5daf3_2048x1280.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>A growing discussion among cybersecurity executives is taking place around a deceptively simple question: what happens if artificial intelligence moves faster on the offensive side than it does on the defensive side?</span></p><p><span>Asaf Wiener, CEO and co-founder of </span><a href="https://mate.security/"><span>Mate Security</span></a><span>, raised that question in a </span><a href="https://www.linkedin.com/feed/update/urn:li:activity:7505646768601137153/"><span>LinkedIn post</span></a><span> that has generated substantial discussion among cybersecurity professionals. His argument challenges the idea that slowing the development of advanced AI automatically reduces risk, pointing instead to the possibility that restrictions could affect defenders more directly than attackers.</span></p><p><span>The post was prompted by a </span><a href="https://darioamodei.com/post/we-must-pace-the-frontier"><span>letter</span></a><span> from Anthropic CEO Dario Amodei advocating for &#8220;pacing the frontier,&#8221; a proposal centered on coordination and responsible development among leading AI companies.</span></p><p><span>Wiener took a </span><a href="https://mate.security/blog/outpace-the-frontier"><span>different view</span></a><span>.</span></p><p><span>&#8220;Pace the frontier, and you pace exactly one side of this fight, the defense side,&#8221; he wrote. &#8220;The answer isn&#8217;t to slow defenders down. It&#8217;s getting trusted, verifiable AI into their hands faster, with the right guardrails in place.&#8221;</span></p><p><span>The response attracted comments from cybersecurity professionals unaffiliated with Mate Security, helping turn what could have been a company executive&#8217;s policy reaction into a wider industry discussion.</span></p><h2><span>The Problem With A One-Sided Race</span></h2><p><span>Wiener&#8217;s argument rests on an asymmetry in cybersecurity.</span></p><p><span>AI companies can voluntarily coordinate around safety standards. Attackers generally do not operate under the same constraints.</span></p><p><span>That creates a potential disconnect between the pace of AI development and the pace at which organizations prepare to defend themselves. If security teams wait for future AI capabilities to arrive before investing in AI-driven defense, they may be responding to a threat that is already evolving.</span></p><p><span>In the longer analysis accompanying his LinkedIn post, Wiener describes these as two separate frontiers: the frontier of AI capability and the frontier of offensive cyber activity.</span></p><p><span>The latter does not wait for the former.</span></p><p><span>&#8220;There&#8217;s a second frontier the letter never touches: how fast attackers are already moving with the AI that exists today,&#8221; Wiener wrote.</span></p><p><span>Several commenters picked up on that distinction. Omer Karny responded, &#8220;Exactly. Thinking that everyone will pace themselves because someone said it- just won&#8217;t work&#8230;&#8221; Noam Bar-Lev similarly wrote, &#8220;100%. Slowing things down gives attackers the edge.&#8221;</span></p><h2><span>From AI Experiment To Security Infrastructure</span></h2><p><span>The discussion is also part of a larger transition in enterprise cybersecurity.</span></p><p><span>For years, AI in security was largely associated with detecting anomalies, prioritizing alerts or helping analysts process large quantities of data. The emergence of AI agents introduces a different proposition: systems that can conduct investigations and potentially execute portions of a response process with substantially less human intervention.</span></p><p><span>That creates a new requirement alongside speed: control.</span></p><p><span>Wiener argues that security agents should be subject to the same principles increasingly being discussed for frontier AI. They should be verifiable, auditable and accountable for the systems they interact with.</span></p><p><span>This is where his argument moves beyond simply calling for faster AI adoption. The proposition is not that companies should deploy autonomous systems without restrictions. Instead, organizations should build guardrails that allow AI-driven security operations to move quickly while remaining within defined boundaries.</span></p><h2><span>Why The Post Resonated</span></h2><p><span>The reaction to Wiener&#8217;s post reflects the fact that the issue sits at the intersection of two of the industry&#8217;s biggest conversations: AI governance and cybersecurity preparedness.</span></p><p><span>Inbal Argov commented that organizations need to focus on &#8220;the mechanisms around the models that make them trusted and operationalized, and hunting down the frontier-powered attackers.&#8221; Sharon Rosenman wrote, &#8220;Slowing down innovation is not a good idea and will practically not happen. Great insight.&#8221;</span></p><p><span>Other commenters took a more concise approach. Chris Hoard called it &#8220;A good read. Thanks,&#8221; while Dineshwar Sahni wrote, &#8220;&#8230;and attackers won&#8217;t write 3000+ or 6000+ essays &#8230; You got it right mate!&#8221;</span></p><p><span>The variety of responses helps explain why the post has attracted attention beyond Mate Security&#8217;s immediate network. Rather than discussing a product launch or corporate milestone, Wiener entered an active debate about the future of AI and cybersecurity&#8212;and connected an abstract AI policy question to a concrete concern for security teams.</span></p><p><span>The takeaway from his argument is not that AI governance is unnecessary. It is that governance and defensive readiness need to advance together. As AI becomes increasingly capable on both sides of the cybersecurity equation, the organizations responsible for protecting networks, applications and data will have to consider how quickly their defenses can operate when the threat itself is moving at machine speed.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Mate Security, Palo Alto Networks, and ServiceNow Join OpenAI’s First-Day Push to Reinvent Cyber Defense]]></title><description><![CDATA[The cybersecurity industry is entering an unusual period in which the technology being used to attack organizations is advancing at the same time as the technology being used to protect them.]]></description><link>https://www.cisohq.io/p/mate-security-palo-alto-networks</link><guid isPermaLink="false">https://www.cisohq.io/p/mate-security-palo-alto-networks</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Mon, 07 Sep 2026 13:35:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!k3UY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k3UY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k3UY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png 424w, https://substackcdn.com/image/fetch/$s_!k3UY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png 848w, https://substackcdn.com/image/fetch/$s_!k3UY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png 1272w, https://substackcdn.com/image/fetch/$s_!k3UY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k3UY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png" width="1456" height="972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k3UY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png 424w, https://substackcdn.com/image/fetch/$s_!k3UY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png 848w, https://substackcdn.com/image/fetch/$s_!k3UY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png 1272w, https://substackcdn.com/image/fetch/$s_!k3UY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e19c912-9492-42d7-b0fc-320fab8e5e07_1470x981.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>The cybersecurity industry is entering an unusual period in which the technology being used to attack organizations is advancing at the same time as the technology being used to protect them. Artificial intelligence has the potential to widen or close that gap, depending on how quickly defenders can put increasingly capable systems to work.</span></p><p><span>OpenAI is attempting to accelerate the defensive side of that equation. In a new open letter titled</span><a href="https://openai.com/collective-cyberdefense/"><span> &#8220;A Call to Action on Cyber Defense</span></a><span>.&#8221; OpenAI President and Co-Founder Greg Brockman is calling on companies, governments and technology providers to coordinate their efforts around AI-powered cyber defense.</span></p><p><span>Among the first-day signatories are </span><a href="https://www.paloaltonetworks.com/"><span>Palo Alto Networks</span></a><span>,</span><a href="https://mate.security/"><span> Mate Security</span></a><span>, and</span><a href="https://www.servicenow.com/"><span> ServiceNow</span></a><span>, putting the three companies among a select group of market leaders backing the initiative from its launch. The participation is particularly notable for Mate Security, which is part of a relatively small group of companies developing an agentic approach to cyber defense.</span></p><h2><span>A Narrow Window</span></h2><p><span>The premise of OpenAI&#8217;s initiative is straightforward: the cybersecurity industry cannot afford to wait until AI-enabled attacks have fully matured before modernizing defensive capabilities.</span></p><p><span>&#8220;We have a limited window to strengthen cyber defenses,&#8221; the letter says.</span></p><p><span>OpenAI predicts that AI-enabled cyber attacks will become more widespread and sophisticated as models continue to improve. The company points to a broad range of potential targets, including hospitals, water treatment plants and the infrastructure that supports the internet.</span></p><p><span>But the letter is not simply a warning about AI.</span></p><p><span>OpenAI argues that today&#8217;s advances also give defenders an opportunity to address weaknesses that have remained embedded in enterprise and public-sector environments for years.</span></p><h2><span>The Security Debt Problem</span></h2><p><span>Many of the vulnerabilities highlighted in the letter are hardly new. Organizations continue to struggle with unpatched software, weak authentication, excessive permissions, misconfigurations and legacy systems that are difficult to upgrade.</span></p><p><span>The difference is that AI could change the economics of addressing those problems.</span></p><p><span>OpenAI argues that cyber-capable AI can bring specialized security capabilities to a larger number of defenders while making core security tasks &#8220;faster, cheaper and better.&#8221;</span></p><p><span>That proposition could be particularly important for organizations with small security teams. Instead of expecting a limited number of specialists to manually investigate every alert or vulnerability, AI agents could increasingly take responsibility for portions of the investigative and remediation process.</span></p><h2><span>Why Mate Security Is Significant</span></h2><p><span>This is where Mate Security&#8217;s participation becomes particularly relevant.</span></p><p><span>Mate is building an open foundation for agentic cyber defense, positioning AI agents as active participants in security investigations rather than simply assistants to human analysts.</span></p><p><span>The company&#8217;s Gamebooks technology is designed to provide agents with structured investigation procedures while allowing them to reason, pivot and act as an investigation develops.</span></p><p><span>That combination addresses a central issue surrounding autonomous security systems. Security teams want AI to operate with enough independence to reduce workload, but they also need predictable processes and organizational controls.</span></p><p><span>Agentic cyber defense attempts to bridge that gap.</span></p><h2><span>Palo Alto Networks And The Broader Market</span></h2><p><span>Palo Alto Networks represents a different but equally important part of the cybersecurity landscape.</span></p><p><span>Its participation demonstrates that the move toward AI-enabled defense is not limited to emerging vendors or companies built exclusively around autonomous agents. Established cybersecurity platforms are also becoming part of the transition toward AI-driven security operations.</span></p><h2><span>ServiceNow And The Remediation Gap</span></h2><p><span>ServiceNow&#8217;s inclusion extends that picture into the enterprise systems where security work is carried out.</span></p><p><span>The letter does not stop at detection and investigation. It asks organizations to fix their most dangerous weaknesses, verify that those fixes work and measure progress by tangible outcomes, including how quickly attacks are contained.</span></p><p><span>Those steps depend on coordination across teams that often sit outside the security function. A confirmed vulnerability still has to be assigned, scheduled, applied and closed out, and that process is frequently where remediation stalls.</span></p><p><span>The presence of Palo Alto Networks, Mate Security and ServiceNow together therefore offers a snapshot of where the market is heading: established security infrastructure and enterprise workflow platforms are evolving alongside a new generation of AI-native and agentic security technologies.</span></p><h2><span>A Shared Responsibility</span></h2><p><span>OpenAI&#8217;s letter also makes clear that the company does not believe the future of cyber defense should be controlled by a single vendor.</span></p><p><span>&#8220;No single company should control the future,&#8221; it says, arguing for a collective response involving governments, cybersecurity companies, technology partners and frontier AI companies.</span></p><p><span>The letter calls for more threat-intelligence sharing, tested playbooks, authorized testing and practical assistance for critical infrastructure organizations.</span></p><p><span>For the companies, becoming first-day signatories puts them behind that broader industry effort at a pivotal moment.</span></p><p><span>The cybersecurity market has spent years discussing the potential of artificial intelligence. The latest initiative suggests that the conversation is moving into a more consequential phase: determining how quickly AI can become a practical, scalable and accountable tool for the people defending the world&#8217;s most important digital systems.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Blackstone Leads Huskeys’ $27M Series A as Network Edge Complexity Creates a New Security Challenge]]></title><description><![CDATA[Enterprise cybersecurity teams are increasingly dealing with a problem that is less about whether they have security tools and more about whether those tools can work together.]]></description><link>https://www.cisohq.io/p/blackstone-leads-huskeys-27m-series</link><guid isPermaLink="false">https://www.cisohq.io/p/blackstone-leads-huskeys-27m-series</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 02 Sep 2026 12:35:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!D9zH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D9zH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D9zH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png 424w, https://substackcdn.com/image/fetch/$s_!D9zH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png 848w, https://substackcdn.com/image/fetch/$s_!D9zH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png 1272w, https://substackcdn.com/image/fetch/$s_!D9zH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D9zH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png" width="1456" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!D9zH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png 424w, https://substackcdn.com/image/fetch/$s_!D9zH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png 848w, https://substackcdn.com/image/fetch/$s_!D9zH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png 1272w, https://substackcdn.com/image/fetch/$s_!D9zH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3973d27a-65aa-48a8-9424-835a5482a619_1565x1043.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Enterprise cybersecurity teams are increasingly dealing with a problem that is less about whether they have security tools and more about whether those tools can work together.</span></p><p><span>Internet-facing applications now operate across a growing combination of cloud providers, content delivery networks, web application firewalls and other network services. That expansion has given organizations more ways to build and secure applications, but it has also created fragmented environments that can be difficult to understand and manage consistently.</span></p><p><a href="https://huskeys.io/"><span>Huskeys</span></a><span> is betting that this growing complexity requires a new layer of security management. The cybersecurity company has raised a $27 million Series A led by Blackstone Innovations Investments, bringing its total funding to $35 million following an $8 million seed round. The funding was first reported by the </span><a href="https://www.wsj.com/pro/private-equity/blackstone-backs-cybersecurity-startup-huskeys-to-fight-unwanted-ai-traffic-410c5c6a?reflink=desktopwebshare_permalink"><span>Wall Street Journal</span></a><span>.</span></p><p><span>The round also included Merlin Ventures, Skinos Ventures, Zscaler Ventures, Okta Ventures, Bright Pixel Capital and SV Angel, as well as individual investors including WAF and CAPTCHA inventor Eran Reshef and executives from organizations including Palo Alto Networks, Cloudflare, Check Point, AWS, Google, Microsoft and Intel.</span></p><h2><span>Security Teams Are Managing an Expanding Edge</span></h2><p><span>The network edge has become a convergence point for applications, customers, revenue and cyber threats. Yet the technologies used to manage that environment are often distributed across multiple vendors and platforms.</span></p><p><span>Security teams may need to understand configurations and policies across CDNs, WAFs, cloud-native security tools and networking components such as load balancers, VPCs and security groups. Making changes in those environments can introduce a separate risk: disrupting legitimate traffic while attempting to block malicious activity.</span></p><p><span>That balancing act is becoming more difficult as applications become increasingly dynamic and AI-driven. Security teams must respond to emerging threats while maintaining business continuity and avoiding false positives that could affect customers.</span></p><p><span>Huskeys is building what it calls a Network Edge Security Management platform, or NESM, to address that challenge.</span></p><h2><span>A Layer Above Existing Security Tools</span></h2><p><span>The company&#8217;s approach does not involve replacing the infrastructure organizations already use. Instead, Huskeys&#8217; platform is designed to connect and orchestrate existing technologies across the network edge.</span></p><p><span>Through its patented Unified Data Model, the company creates a common layer of understanding across different environments, providers and technologies. The goal is to allow security insights, policies and actions to move across platforms while supporting multi-cloud and multi-vendor environments.</span></p><p><span>The platform includes continuous posture assessment, dynamic policy generation and orchestration. It also provides Virtual Patching, which allows security teams to mitigate vulnerabilities directly at the network edge while a permanent fix is developed, tested and deployed within application code.</span></p><p><span>Huskeys is also addressing the growing role of autonomous AI agents, which are creating new forms of legitimate traffic that security teams must distinguish from potentially malicious automation.</span></p><p><span>&#8220;We founded Huskeys because security teams are being asked to protect increasingly complex edge environments with legacy tools that were never designed to work together or to address the challenges of the new AI era,&#8221; said Itai Gafni, CEO and Co-Founder of Huskeys. &#8220;Every business today runs through its network edge - that&#8217;s where your customers, your revenue, and your threats all meet, yet for most organizations, that edge works against them instead of for them. As AI transforms both legitimate traffic and cyberattacks, organizations need an intelligence layer that continuously understands what&#8217;s happening across the edge and adapts security in real time. Our goal is to make the network finally work for the business, not against it. That&#8217;s the category we&#8217;re building.&#8221;</span></p><h2><span>An Investor Bet on Network Edge Security</span></h2><p><span>Huskeys says its customer base includes TikTok, LEGOLAND, Ro, Blackstone and Hugging Face. The company is already analyzing more than a trillion web requests and thousands of network configurations every day across organizations worldwide.</span></p><p><span>Blackstone&#8217;s investment comes as organizations face increasing pressure to secure infrastructure without creating friction for the applications and services that generate business value.</span></p><p><span>&#8220;The way organizations secure internet-facing applications is fundamentally changing. AI-driven traffic and increasingly fragmented edge environments require a new approach to security management,&#8221; said Adam Fletcher, Chief Information Security Officer at Blackstone. &#8220;Huskeys has built a platform designed to operate at enterprise scale while advancing a new category for the modern network edge. We believe the company is well positioned to redefine how organizations manage edge security, and we&#8217;re excited to support Huskeys as they continue to develop their product in this important category.&#8221;</span></p><p><span>The central question Huskeys is trying to answer is becoming increasingly relevant: as organizations add more security and infrastructure technologies to the network edge, who or what will manage the entire environment as one connected system?</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Mate Brings Controlled Autonomy to Security Operations With Gamebooks]]></title><description><![CDATA[Governance has been the quiet gating factor on AI adoption in the security operations center.]]></description><link>https://www.cisohq.io/p/mate-brings-controlled-autonomy-to</link><guid isPermaLink="false">https://www.cisohq.io/p/mate-brings-controlled-autonomy-to</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 26 Aug 2026 14:23:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!sgZk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sgZk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sgZk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sgZk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg" width="1456" height="750" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:750,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sgZk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Governance has been the quiet gating factor on AI adoption in the security operations center. Security leaders can articulate the upside of agents that reason and act at machine speed. They also carry accountability for what those agents do to production systems.</span><a href="https://mate.security/"><span> Mate Security</span></a><span>&#8216;s launch of Gamebooks, first reported by </span><a href="https://siliconangle.com/2026/08/26/exclusive-mate-security-launches-gamebooks-to-govern-how-ai-agents-run-investigations/"><span>SiliconANGLE</span></a><span>, is aimed squarely at that accountability question.</span></p><h2><strong><span>The Governance Problem, Stated Plainly</span></strong></h2><p><span>Organizations need AI agents to get it right. Mate&#8217;s framing of the standard is specific: 90 percent accuracy is not sufficient when the remaining margin can disable a legitimate account, revoke an executive&#8217;s access, or shut down a critical production system.</span></p><p><span>The industry&#8217;s response has been to limit AI autonomy, generally by placing a human at every decision point. That preserves control. It also caps the speed of the defense, because an agent waiting for human approval cannot operate at machine speed. Mate cites the recent Hugging Face incident as a demonstration that AI-driven attacks run continuously, in parallel, and adapt as defenders respond.</span></p><p><span>Mate&#8217;s position is that the choice is not autonomy versus control. It is controlled autonomy, which means letting agents reason, pivot, and act while keeping them inside the organization&#8217;s methodology, policies, and guardrails.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K0jz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K0jz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!K0jz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!K0jz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!K0jz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K0jz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg" width="1456" height="910" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:910,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K0jz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!K0jz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!K0jz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!K0jz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3363a92d-d827-46bb-8e6f-73855c3f3227_1600x1000.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong><span>Encoding Methodology Into Software</span></strong></h2><p><span>A Gamebook is where an organization&#8217;s investigative approach becomes something an agent can follow.</span></p><p><a href="https://mate.security/platform/gamebooks"><span>Mate Security&#8217;s Gamebooks</span></a><span> each define what must be investigated, what evidence must be established, which conditions should change the investigation, which actions are permitted, and when an agent must escalate, stop, or request approval. That last element is the governance hook. Escalation points, stop conditions, and approval requirements are properties of the Gamebook rather than judgment calls the agent makes on its own.</span></p><p><span>Gamebooks define investigative intent rather than a fixed execution path. The agent is told what to accomplish and which boundaries apply. It determines the route from the evidence and the organization&#8217;s most current context.</span></p><h2><strong><span>Separation of Powers</span></strong></h2><p><span>The architecture reinforces the governance model through layering.</span></p><p><span>An orchestrator reads the investigation and composes the appropriate Gamebooks. Gamebooks carry investigative intent, required evidence, and boundaries. Capabilities give agents reusable, vendor-neutral security skills. Agents apply those capabilities dynamically as evidence emerges. The</span><a href="https://mate.security/blog/introducing-the-security-context-graph"><span> Security Context Graph</span></a><span> keeps everything grounded in shared state and current organizational context. Flows form the controlled execution layer that governs how agents interact with specific tools and systems.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sgZk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sgZk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sgZk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg" width="1456" height="750" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:750,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sgZk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 424w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 848w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!sgZk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcbf6cbc-b347-4a86-aba1-6fe4fcf3b423_1600x824.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>Mate makes a point of what this separation achieves for risk owners. Investigative intent stays consistent while execution adapts, and agents never receive unrestricted access to real systems.</span></p><h2><strong><span>Continuity as a Control</span></strong></h2><p><span>Change is a governance risk in its own right. Organizations replace security tools. They acquire companies with different security stacks. Vendors introduce new alert types. Experienced analysts leave.</span></p><p><span>Under a traditional playbook model, each of those events means rebuilding workflows, and every rebuild is an opportunity for drift away from approved procedure. With Gamebooks, investigative intent remains intact while execution adapts. The same Gamebook continues to operate through a tool change or an acquisition. When an analyst leaves, the Security Context Graph preserves previous decisions along with the reasoning and context behind them. The world changes. The investigation methodology does not have to be rebuilt.</span></p><h2><strong><span>Ownership of the Method</span></strong></h2><p><span>Gamebooks are extensible and customizable, which matters for organizations that treat their investigative methodology as proprietary. Teams can adapt agentic investigations to their own processes, tools, and institutional knowledge without taking on the complexity of building, testing, and operating agentic systems.</span></p><p><span>Existing playbooks can be translated into investigative intent. Mate&#8217;s expert-designed Gamebooks can be extended with organization-specific requirements. Proprietary tools and data can be connected. New investigation procedures can be written in natural language.</span></p><p><span>Mate owns the underlying agent engineering, evaluations, testing, and execution. As models, tools, and environments change, Mate continuously validates and evolves the system while customers retain their investigation logic and customizations. The division is clear. Organizations define how they investigate. Mate ensures the agents execute it reliably. Customers build with Mate rather than around it.</span></p><h2><strong><span>An Audit Trail That Improves the System</span></strong></h2><p><span>Gamebooks operate inside Mate&#8217;s</span><a href="https://mate.security/blog/continuous-detection-continuous-response"><span> Continuous Detection / Continuous Response</span></a><span> loop, where detection, investigation, and response function as one continuous process.</span></p><p><span>Every investigation adds evidence, relationships, outcomes, and reasoning to the Security Context Graph. That record does double duty. It preserves the basis for decisions, and it feeds improvement, since useful investigation patterns can strengthen capabilities, update Gamebooks, or become new detections. Noisy detections can be tuned based on actual investigation results.</span></p><h2><strong><span>The Direction of Travel</span></strong></h2><p><span>&#8220;AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,&#8221; said Oren Saban, Co-Founder and Chief Product Officer at Mate. &#8220;The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.&#8221;</span></p><p><span>Gamebooks join the Security Context Graph and CD/CR as Mate&#8217;s architecture for agentic security operations, moving investigations from scripted automation toward trusted agentic work. Gamebooks are generally available as part of the Mate platform, and the company will showcase them at CrowdStrike Fal.Con 2026.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Bryce Austin on Building a Security Program That’s “Secure Enough”]]></title><description><![CDATA[Cybersecurity leaders are constantly asked to do more: deploy new tools, close more vulnerabilities, produce more dashboards, and justify larger budgets.]]></description><link>https://www.cisohq.io/p/ciso-tips-bryce-austin-on-building</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-bryce-austin-on-building</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Mon, 24 Aug 2026 10:01:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!UVNi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UVNi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UVNi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!UVNi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!UVNi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!UVNi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UVNi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UVNi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!UVNi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!UVNi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!UVNi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b464395-58d2-47a4-afb2-a1b6f8b52ef2_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Cybersecurity leaders are constantly asked to do more: deploy new tools, close more vulnerabilities, produce more dashboards, and justify larger budgets. But for </span><a href="https://www.linkedin.com/in/bryceaustin/"><span>Bryce Austin</span></a><span>, CEO of TCE Strategy and a practicing fractional CISO, effective security starts with a simpler question: What problem are we actually trying to solve? Austin argues that security teams should be deliberate about what they buy, how they allocate resources, and whether a technology investment genuinely improves the organization&#8217;s security posture.</span></p><p><span>Austin brings experience advising companies ranging from 50 employees to members of the S&amp;P 500, along with his perspective as the author of Secure Enough? 20 Questions on Cybersecurity for Business Owners and Executives. His approach puts people and decision-making ahead of technology, from assigning a human owner to every security tool to eliminating dashboards that don&#8217;t lead to action. In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Austin shares practical advice on cutting shelfware, communicating risk to executives, preserving evidence during incidents, and making sure security teams focus on the risks that actually matter.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>&#8230;define the specific problem you are trying to solve. You buy a sports car to have an exciting driving experience, not haul a large trailer. Make sure everyone agrees on the problem before anyone starts shopping for solutions.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>Do not move the goalposts on a security project. I require my teams to manage project deadlines and to proactively reach out if something is going to get in the way of a deadline. For example, when decommissioning an insecure system, standing up the new system to replace it makes the cybersecurity issue WORSE while both systems are running. It is not until the old system is completely gone that you have done any good to the cybersecurity posture of the organization.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>My ratio is 1:1: every cybersecurity tool needs a human owner. If I can&#8217;t identify someone with the time and expertise to properly manage a product before we buy it, I don&#8217;t want it. I also look hard at whether a process or procedure change can solve the same problem. New tools need additional resources to manage and maintain, and sometimes introduce new vulnerability risk (read: SolarWinds Orion in 2020) or operational risk (read: CrowdStrike in July 2024).</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>Cybersecurity isn&#8217;t perfect. We need to be Secure Enough for us. Cybersecurity issue XYZ is not one that I can make a credible argument that we are Secure Enough. Either we consciously accept this risk as a leadership team, or we find the funding to fix it.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Shelfware. Kill it. If you bought a software package or service and it isn&#8217;t working out because your team doesn&#8217;t have the time or expertise to effectively utilize it, cut it ASAP.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>I ask, &#8220;What business problem do you solve that no one else solves, or that you solve better for a given price?&#8221; If they can&#8217;t give me a 60-second answer that makes sense, I&#8217;m out.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>Security dashboards that don&#8217;t help me make good decisions are just wall art. I eliminate them entirely, or make revisions so that reasonable action can be taken because of the information they contain. 2000 &#8220;critical&#8221; vulnerabilities on the monthly patching report are not actionable. Thirty &#8220;actively exploited by ransomware gangs&#8221; vulnerabilities on the same report are very actionable.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>They forget to preserve evidence. Take screenshots. Record what you are seeing. Disconnect computers from the network but don&#8217;t reflexively reboot or power them off, as you may destroy valuable evidence in active memory. If you can&#8217;t otherwise contain an actively spreading attack, then containment takes priority. Preserving the active memory of an infected computer often leads to meaningful clues as to what is going on.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>What is getting in your way that I can help you with?</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I&#8217;ve used this one a lot: Most car tires want around 35 psi of air in them. Having a car tire that is 3 psi low on air is not best practice, but it is not an emergency. A car tire with only 3 psi of air is a life safety issue when traveling 70 mph on the highway. A big part of my job is helping executives understand whether the cybersecurity issue in front of us is the former or the latter.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>People come first. Not technology.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-stefano-pasotti-on-turning"><span>CISO Tips: Stefano Pasotti on Turning Cybersecurity Into Business Resilience</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-maurizio-imperadore-on"><span>CISO Tips: Maurizio Imperadore on Resilience, Identity and Cutting Security Noise</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer"><span>CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning"><span>CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on"><span>CISO Tips: Carlos Garc&#237;a Batista on Turning Cybersecurity Into Operational Resilience</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Stefano Pasotti on Turning Cybersecurity Into Business Resilience]]></title><description><![CDATA[Stefano Pasotti, CISO and ICT Manager at DN Automotive Italy, brings a pragmatic perspective to cybersecurity shaped by years of experience across software development, IT leadership, manufacturing, and logistics.]]></description><link>https://www.cisohq.io/p/ciso-tips-stefano-pasotti-on-turning</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-stefano-pasotti-on-turning</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Mon, 17 Aug 2026 09:32:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!J3NL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!J3NL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!J3NL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!J3NL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!J3NL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!J3NL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8742b202-fef9-4dbb-a401-5181b5b18363_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><a href="https://www.linkedin.com/in/stefano-pasotti-1b507326/"><span>Stefano Pasotti</span></a><span>, CISO and ICT Manager at DN Automotive Italy, brings a pragmatic perspective to cybersecurity shaped by years of experience across software development, IT leadership, manufacturing, and logistics. In his role, he oversees cybersecurity, infrastructure, and digitalization initiatives across European operations, where technologies ranging from WMS and production planning to EDI and IoT must work securely and reliably.</span></p><p><span>For Pasotti, effective security is ultimately about making better business decisions. His approach emphasizes measurable risk reduction over flashy tools, practical incident readiness over compliance theater, and clear communication that translates technical risk into business consequences such as production downtime. In this edition of CISO Tips, he shares his principles for evaluating security investments, preparing teams for incidents, working with vendors, and leading security programs with discipline and reflection.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>...I ask myself how much it actually reduces our risk percentage, how much it really makes us safer. Is it a necessary move, or just a &#8216;cool tool&#8217;?</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>Document everything. An experience that isn&#8217;t written down is an experience lost.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>Training before tools, always. It only takes one wrong click to waste a thousand technology solutions.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>I put risk on the table, not the tool. How much risk is the company willing to take? How much downtime can we afford, and how likely is it to actually happen?</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Some certifications that only exist for the plaque on the wall. If they change nothing in practice, they&#8217;re just time spent &#8212; not security.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>&#8220;If they throw around technical jargon at random, or bombard me with overly detailed questions that make no sense at this stage, I know right away they haven&#8217;t listened. Same if they show no interest in understanding who we are and what we do before pitching us something: they&#8217;re not selling a solution, they&#8217;re selling a script.&#8221;</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I rarely eliminate; I prefer to rebuild. The latest case: incident response policies and runbooks that only existed on paper &#8212; I rewrote them to be truly operational, not just a compliance exercise.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Stopping to think. Speed is critical, so the temptation is to act immediately &#8212; but acting without a moment&#8217;s reflection can cause more damage than the incident itself.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>If it happened right now, would we actually know what to do, or would we be improvising?&#8221;</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I translate everything into production downtime. Once the risk is clear to everyone, then we talk solutions.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>Stop, reflect, then take action.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[What Bloom Security's Extension Resurrection Research Means for Extension Pack Governance]]></title><description><![CDATA[Ask a security team to name the least governed system in the enterprise and few will say &#8220;the developer laptop.&#8221; They should.]]></description><link>https://www.cisohq.io/p/what-bloom-securitys-extension-resurrection</link><guid isPermaLink="false">https://www.cisohq.io/p/what-bloom-securitys-extension-resurrection</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Thu, 13 Aug 2026 14:03:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lBH5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lBH5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lBH5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 424w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 848w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 1272w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lBH5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png" width="1456" height="1089" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1089,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lBH5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 424w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 848w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 1272w, https://substackcdn.com/image/fetch/$s_!lBH5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80bc8c40-5f34-46ae-8c05-1542a018277d_1552x1161.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Ask a security team to name the least governed system in the enterprise and few will say &#8220;the developer laptop.&#8221; They should. It changes daily. Extensions, packages, plugins, and AI tooling get assembled on the fly, rarely pass through review, and remain largely invisible to endpoint detection.</span><a href="https://bloom.security/"><span> Bloom Security</span></a><span>&#8216;s latest research turns that abstraction into a measurable exposure across roughly half a million downloads and more than 750 extension packs.</span></p><p><span>The vulnerability is called Extension Resurrection, and it affected both Open VSX and the Visual Studio Code Marketplace. What makes it worth a board-level conversation is not the exploit chain. It is the trust model the exploit chain borrows.</span></p><h2><span>One Install Decision, Ten Unreviewed Consequences</span></h2><p><span>When a developer installs an extension pack, they are not installing one tool. They are accepting a curated list of dependencies, every one of them granted deep access to the filesystem, running processes, and the network.</span></p><p><span>The pack was reviewed. Its contents were not. Bloom Security identifies that gap between what a user trusts and what actually gets installed as precisely where the attack lives.</span></p><p><span>Extension packs therefore behave as a risk multiplier. A single approval quietly expands the attack surface by five, ten, or more components that nobody explicitly evaluated. The research is unambiguous about the required posture change: treat extension packs within the same threat model as direct extension installs, and review the bundle manifest rather than the pack name.</span></p><h2><span>Volume Is Working Against Defenders</span></h2><p><span>Scale deserves attention here. In the first six months of 2026, the VS Code Marketplace nearly doubled in size. Between the two marketplaces, roughly 1,400 new extensions ship every single day. AI tooling has let teams move faster than before, and the output is an explosion of new software landing continuously.</span></p><p><span>Every developer runs at least one extension outside the defaults of their chosen IDE. That baseline was never the interesting part. The interesting part is that the catalog defenders would need to vet is growing faster than any manual review process can absorb.</span></p><h2><span>What the Attack Actually Required</span></h2><p><span>The technical prerequisites were modest, which is the point.</span></p><p><span>Both marketplaces permitted packs to reference extensions that did not exist. Bloom Security calls those dangling references Shadow Dependencies, and they arise either when a pack is mirrored to Open VSX without one of its bundled components, or when an extension referenced by a live pack is deleted.</span></p><p><span>Extensions are identified by publisher or namespace paired with an extension ID, so hijacking one means claiming the original publisher or namespace rather than just an available name. Both platforms allowed open registration of those names, including names that published software actively referenced.</span></p><p><span>Bloom Security&#8217;s scan quantified the field. Open VSX: 94 of 321 packs carried a shadow dependency with an unregistered namespace. VS Code Marketplace: 677 of 4,179 packs carried a shadow dependency, 60 of them under an unregistered publisher. Two of those were used for a live proof: prettify-json under mohsen1 on Open VSX, and control-snippets under svipas on the VS Code Marketplace.</span></p><p><span>Open VSX initially rejected an exact version match because it already held a ghost record from a mirrored manifest. Incrementing the version resolved that instantly, since packs reference bundled extensions by ID without pinning versions.</span></p><h2><span>The Part That Should Worry Risk Owners</span></h2><p><span>Installation was never the only vector. Auto-update configuration for bundled extensions is inherited from the pack, and the default is enabled. Anyone who installed an affected pack in the past, under default settings, could receive attacker-controlled code on a routine update.</span></p><p><span>Extensions run with Node.js host access. They read and write files, spawn child processes, and reach the network. Bloom Security&#8217;s assessment is that an extension is not sandboxed in any meaningful sense with respect to code execution, so a malicious install is functionally remote code execution on the machine.</span></p><p><span>That machine belongs to a software developer. Source repositories, cloud credentials, deployment pipelines, internal tooling. Applying a deliberately conservative estimate that half of the affected downloads had auto-update on, the research arrives at roughly a quarter of a million compromised developer endpoints within a day.</span></p><h2><span>The Control Set Being Recommended</span></h2><p><span>Bloom Security lists three capabilities security teams need, and none of them are novel. The difficulty is that most organizations lack all three for this surface.</span></p><p><span>The first is inventory of installed extensions and packs across the organization. The second is visibility into IDE configuration, specifically whether auto-update is enabled and for which extensions, plus whether policy limits installs to a pre-approved list. The third is extension scanning that audits capabilities, security posture, and risk for each installed extension, treated as a continuous process covering every new version rather than a one-time exercise.</span></p><p><span>For developers, the guidance is narrower. Auto-updated extension packs behave like auto-updates for every extension they bundle. Install once does not mean static forever. Periodically review what the IDE has actually installed, not just what was chosen.</span></p><h2><span>Vendor Response as a Governance Signal</span></h2><p><span>Bloom Security reported to the Eclipse Foundation on February 5, 2026, and to Microsoft via MSRC on February 17, 2026.</span></p><p><span>Eclipse assigned all at-risk namespaces to the open-vsx account within hours, then implemented a pre-publication check now blocking packs with non-existent bundled extensions and extensions with non-existent dependencies. Triage also surfaced that extension dependencies were vulnerable to the same technique. Bloom Security describes the experience as very positive and points to Open VSX as a model for marketplace response.</span></p><p><span>Microsoft&#8217;s path was longer. MSRC&#8217;s first assessment was Moderate severity on the basis that the Visual Studio Marketplace already had publisher resurrection prevention in place. Bloom Security disputed that with video evidence and additional examples of re-registering removed publishers, and the case was reopened. Engineering subsequently confirmed a partial fix from October and stated that prevention had covered admin actions since October and user actions only as of that month. The two stages landed in October 2025 and June 2026 respectively, documented at github.com/microsoft/vsmarketplace/discussions/1708. Microsoft acknowledged the completion arrived after the report. The eight-month interval between stages left real exposure for user-action resurrection, which Bloom Security demonstrated.</span></p><p><span>The broader lesson does not stop at extensions. The endpoint attack surface expands constantly through installs, updates, configuration drift, and AI tools pulling in fresh dependencies. Bloom Security&#8217;s argument is that everything running there needs to be continuously known, vetted, and governed as an ongoing process rather than a periodic audit. Organizations without that visibility, the research concludes, sit a few clicks away from an incident.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Jörg Scheiblhofer on Analytical Security Leadership]]></title><description><![CDATA[Cybersecurity leadership is rarely about having the most tools or the most elaborate security program.]]></description><link>https://www.cisohq.io/p/ciso-tips-jorg-scheiblhofer-on-analytical</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-jorg-scheiblhofer-on-analytical</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 12 Aug 2026 09:40:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!f1_n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f1_n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f1_n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f1_n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f1_n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!f1_n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07c4cedf-6049-4d6d-b4b6-ab4fc20d87ae_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Cybersecurity leadership is rarely about having the most tools or the most elaborate security program. For </span><a href="https://www.linkedin.com/in/joerg-scheiblhofer/"><span>J&#246;rg Scheiblhofer</span></a><span>, Chief Information Security Officer at ORF, effective security starts with understanding the organization&#8217;s requirements, processes, and actual risk before deciding which technologies or controls are needed. His approach emphasizes analytical thinking, consistency, and a clear understanding of the potential impact of security decisions.</span></p><p><span>In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Scheiblhofer shares his perspective on making better decisions under pressure, communicating cyber risk to executives through relatable analogies, and avoiding assumptions during critical incidents. From assessing the real situation in the first minutes of an attack to tailoring risk discussions for the board, his advice reflects a practical philosophy: strong cybersecurity requires sound analysis, clear communication, and a human approach.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first&#8230;&#8221;</span></h3><p><span>&#8230;you have to think about process and your requirements &#8220;</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>There are no exceptions on suspicion without an analytical basis and certainly no general exceptions.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>It is not a single sentence; rather, it is a presentation, tailored to the target audience, of the risks that exist or may arise if measures are not implemented.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>Has he dealt with his potential customer?</span></p><p><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it? -</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Accurately assessing the actual situation. In the heat of the moment, this is often overlooked. What&#8217;s one question every CISO should ask their team this week?</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I like to use the creation of analogies from everyday life. In a way, a language in pictures, so that management can imagine something better.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>1.) remain consistent 2.) adopt an analytical approach 3.) tailor communication to the target audience 4.) assess the risk and potential damage 5.) remain human</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-maurizio-imperadore-on"><span>CISO Tips: Maurizio Imperadore on Resilience, Identity and Cutting Security Noise</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer"><span>CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning"><span>CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on"><span>CISO Tips: Carlos Garc&#237;a Batista on Turning Cybersecurity Into Operational Resilience</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking"><span>CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Stephen Wadsworth Named VP of Sales at Reclaim Security as Company Scales Exposure Remediation Business]]></title><description><![CDATA[Cybersecurity companies often reach an inflection point when technology validation gives way to the harder task of building a repeatable commercial engine.]]></description><link>https://www.cisohq.io/p/stephen-wadsworth-named-vp-of-sales</link><guid isPermaLink="false">https://www.cisohq.io/p/stephen-wadsworth-named-vp-of-sales</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Tue, 11 Aug 2026 12:39:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!unE8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!unE8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!unE8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!unE8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!unE8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!unE8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!unE8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!unE8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!unE8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!unE8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!unE8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51b02e7b-4f78-4326-8bee-06195e65007b_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Cybersecurity companies often reach an inflection point when technology validation gives way to the harder task of building a repeatable commercial engine. For </span><a href="https://reclaim.security"><span>Reclaim Security</span></a><span>, that stage is arriving as the company seeks to expand adoption of its approach to automated exposure remediation.</span></p><p><span>The company has appointed Stephen Wadsworth as Vice President of Sales, giving the veteran cybersecurity sales executive responsibility for Reclaim&#8217;s U.S. go-to-market operation. Based in Boston, Wadsworth brings nearly two decades of experience building sales organizations at security companies, including several that were later acquired.</span></p><p><span>His career includes an early sales leadership role at Luminate Security, which was acquired by Symantec, and most recently leading sales at Entitle through its acquisition by BeyondTrust. He has also held leadership positions at Threat Stack, Banyan Security and Cyolo.</span></p><p><span>For Reclaim, the move comes at a time when the company is seeking to capitalize on enterprise demand for technologies that can do more than identify security problems.</span></p><h2><span>The Remediation Gap</span></h2><p><span>The security industry has become increasingly effective at finding exposures. The resulting challenge is that security teams can be left with large inventories of issues requiring attention, even as the tools generating those findings continue to improve.</span></p><p><span>Reclaim has built its platform around addressing that gap. Its AI Security Engineer continuously discovers exposures across endpoint, email, identity, browser and cloud environments, then plans business-aware fixes and executes them.</span></p><p><span>The company describes its approach as preemptive exposure remediation, with the technology designed to operate across an organization&#8217;s existing security stack. Instead of adding another dashboard, Reclaim aims to make the security tools enterprises already own more effective by helping turn findings into implemented fixes.</span></p><p><span>Wadsworth sees that distinction as increasingly important to security leaders.</span></p><p><span>&#8220;I&#8217;ve spent my career skating to where the puck is going,&#8221; said Wadsworth. &#8220;CISOs don&#8217;t need more security tools, they need more value from what they already pay for. Every CISO I&#8217;ve spoken to in the last 6&#8211;12 months is tired of being told they have more problems to fix. The market is hungry for outcomes. As adversaries increasingly abuse frontier models at scale, continuous, real-time prevention needs to be the focus &#8212; and Reclaim is built to turn findings into implemented fixes without disruption.&#8221;</span></p><h2><span>Why Wadsworth&#8217;s Background Matters</span></h2><p><span>The new sales chief arrives with a r&#233;sum&#233; closely tied to emerging cybersecurity companies moving toward larger strategic outcomes.</span></p><p><span>At Luminate Security, Wadsworth was an early sales leader before the company was acquired by Symantec. At Entitle, he most recently led sales before its acquisition by BeyondTrust. His experience also spans Threat Stack, Banyan Security and Cyolo.</span></p><p><span>That background is relevant to Reclaim as it builds its U.S. revenue operation. The company is not simply adding a sales executive to an established business; it is looking to scale commercial momentum around a category it believes is becoming increasingly important to enterprise security teams.</span></p><p><span>&#8220;Stephen has built the sales organizations behind some of the most consequential security companies of the last decade,&#8221; said Barak Klinghofer, co-founder and CEO of Reclaim Security. &#8220;The industry has spent ten years getting better at finding and prioritizing exposures and barely moved on fixing them. Visibility without remediation is noise. With Stephen leading sales, we&#8217;re scaling the team that fixes what everyone else only finds.&#8221;</span></p><h2><span>Reclaim&#8217;s Next Growth Phase</span></h2><p><span>The appointment follows a period of funding and customer momentum for Reclaim. In March 2026, the company announced a $20 million Series A led by Acrew Capital, with participation from QP Ventures and Ibex Investors, bringing its total funding to $26 million.</span></p><p><span>Reclaim has also published customer results involving Telit Cinterion, Pine Gate Renewables, Competitive Power Ventures and Aqua Security, among others. The company says its customers use the platform to turn lists of findings into implemented fixes, typically demonstrating value within a 10-day proof of value.</span></p><p><span>That customer proposition sits at the center of Reclaim&#8217;s growth strategy. Rather than asking enterprises to add another layer of security visibility, the company is positioning remediation as the outcome that matters.</span></p><p><span>Wadsworth&#8217;s appointment gives Reclaim an executive whose previous experience includes building sales organizations during pivotal moments for security companies. His immediate task will be to translate that experience into growth for a company betting that the next evolution of exposure management will be measured less by what security teams discover and more by what they successfully eliminate.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Maurizio Imperadore on Resilience, Identity and Cutting Security Noise]]></title><description><![CDATA[Maurizio Imperadore, Head of the Cybersecurity Team at Connect S.p.A., brings a network engineering background to the CISO role, with experience spanning telecommunications, network design, Cisco and HP systems, and Session Initiation Protocol (SIP).]]></description><link>https://www.cisohq.io/p/ciso-tips-maurizio-imperadore-on</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-maurizio-imperadore-on</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Sun, 09 Aug 2026 12:16:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!I4ci!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!I4ci!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!I4ci!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!I4ci!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!I4ci!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!I4ci!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2af0a22-8562-4c74-90ba-f4d20b310ecc_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><a href="https://www.linkedin.com/in/maurizio-imperadore-0561787/"><span>Maurizio Imperadore</span></a><span>, Head of the Cybersecurity Team at Connect S.p.A., brings a network engineering background to the CISO role, with experience spanning telecommunications, network design, Cisco and HP systems, and Session Initiation Protocol (SIP). His approach to cybersecurity is grounded in operational resilience: making the most of existing security investments, maintaining strong identity controls, and ensuring security decisions are tied to business continuity.</span></p><p><span>In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Imperadore shares practical lessons on where security teams should focus their time and resources. From enforcing zero exceptions on MFA to replacing lengthy risk reports with a single-page executive dashboard, his advice centers on reducing noise, communicating risk in financial terms, and building a security program that protects the operations the business depends on most.</span></p><h3><span>Before you buy any new security tool, first&#8230;</span></h3><p><span> Ensure you are fully utilizing the native security capabilities of your existing stack.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>Zero exceptions on MFA and identity verification, even for emergency admin actions.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>The 80/20 rule: 80% on core operational resilience and visibility, 20% on new security innovation.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>&#8220;This isn&#8217;t an operational expense; it&#8217;s the cost of keeping our core revenue streams online.&#8221;</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Outdated annual compliance training that tick boxes without changing user behavior.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>If they can&#8217;t clearly articulate the specific problem they solve without using buzzwords in the first minute.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>Eliminated lengthy monthly risk slide decks and replaced them with a dynamic single-page executive dashboard.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Pausing to establish clear incident roles and dedicated communication channels before touching systems.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>&#8220;Which alert or process is generating the most noise and wasting your time?&#8221;</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>Translating technical vulnerabilities directly into financial downtime: &#8220;If X fails, core operations stop for Y hours at a cost of $Z.&#8221;</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>Prioritize relentlessly, delegate, rest daily.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer"><span>CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning"><span>CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on"><span>CISO Tips: Carlos Garc&#237;a Batista on Turning Cybersecurity Into Operational Resilience</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking"><span>CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning"><span>CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Jigar Shah on Buying Fewer Tools, Building More Trust]]></title><description><![CDATA[For many security leaders, the biggest challenge isn&#8217;t keeping up with the latest threats; it&#8217;s ensuring cybersecurity remains aligned with business priorities.]]></description><link>https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-jigar-shah-on-buying-fewer</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 05 Aug 2026 09:04:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!zrMx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zrMx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zrMx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zrMx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zrMx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!zrMx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffee88939-84d2-4e42-a200-5a0b1d0a0238_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>For many security leaders, the biggest challenge isn&#8217;t keeping up with the latest threats; it&#8217;s ensuring cybersecurity remains aligned with business priorities. </span><a href="https://www.linkedin.com/in/jigar-cxo/"><span>Jigar Shah</span></a><span>, Chief Information Security Officer at Medusind, believes the most effective CISOs are those who focus less on accumulating security technologies and more on solving real business problems. Drawing on more than two decades of leadership across healthcare, financial services, banking, retail, and consulting, Shah has built his career around connecting cybersecurity, technology, business strategy, and governance.</span></p><p><span>In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Shah shares the principles that shape his leadership approach, from evaluating vendors based on business outcomes rather than product features to eliminating &#8220;security theater&#8221; that adds complexity without reducing risk. He also explains why trust, not technology, is the foundation of every successful security program, and why CISOs should spend far more time preventing tomorrow&#8217;s incidents than reacting to today&#8217;s.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>&#8220;...understand the business problem you&#8217;re trying to solve.&#8221;</span></p><p><span>Technology should never drive strategy. If you can&#8217;t explain the business outcome in one sentence, you probably don&#8217;t need another security tool.</span></p><p><span>&#8220;Buy fewer tools. Solve more problems.&#8221;</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>&#8220;Never bring me a security problem without at least one business-focused solution.&#8221;</span></p><p><span>I don&#8217;t want my team to be known for just identifying risks. I want them to be known for enabling the business safely.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>I follow a simple rule: 80% enabling the business, 20% fighting fires.</span></p><p><span>If I&#8217;m spending more time reacting than enabling, we&#8217;re investing in symptoms instead of resilience.  Spend 80% preventing tomorrow&#8217;s incidents or issues that can become an incident and 20% responding to today&#8217;s.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>I&#8217;m not asking you to fund cybersecurity; I&#8217;m asking you to protect the business strategy you&#8217;ve already approved. That changes the conversation from cost to business enablement.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Security theater. Anything that looks impressive but doesn&#8217;t measurably reduce risk or improve resilience. Examples include reports nobody reads, meetings without decisions, and controls that create more friction than value.</span></p><p><span>&#8220;If it only checks a box, cut it.&#8221;</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>I ask three questions:</span></p><ol><li><p><span>What business problem do you solve?</span></p></li><li><p><span>Can you prove measurable outcomes? Give an example of how you turned things around for your customers?</span></p></li><li><p><span>Why are you different from the ten vendors I met this month?</span></p></li></ol><p><span>If they answer with features instead of outcomes, the meeting is probably over.</span></p><p><span>&#8220;Features sell products. Outcomes earn meetings.&#8221;</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I eliminated long weekly status meetings. We replaced them with a live dashboard and a 15-minute decision meeting. The goal isn&#8217;t to exchange information. The goal is to make decisions and have an action plan with outcomes.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Defining who&#8217;s making decisions. Everyone starts investigating. Very few establish clear incident command. Without decision ownership, technical excellence becomes organizational chaos.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>&#8220;If you were attacking us tomorrow, where would you start?&#8221; It changes the conversation from compliance to adversarial thinking.</span></p><p><span>Alternative: &#8220;What are we doing today simply because we&#8217;ve always done it?&#8221;</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I rarely talk about vulnerabilities. I ask: &#8220;What happens to revenue, customers, operations, or reputation if this control fails?&#8221; Executives don&#8217;t invest in CVEs. They invest in protecting business outcomes. I frame it in business results, risks, and revenue.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>&#8220;Build trust before a crisis happens.&#8221; Because that&#8217;s really the essence of the CISO role. Technology changes. Threats evolve. But the ability to build trust with executives, employees, customers, regulators, and your team is what ultimately determines your success.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning"><span>CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on"><span>CISO Tips: Carlos Garc&#237;a Batista on Turning Cybersecurity Into Operational Resilience</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking"><span>CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning"><span>CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first"><span>CISO Tips: Paul Blahusch on Business Success Coming First</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Upwind First to Expose One of the Largest Open-Source Supply Chain Threats Targeting JavaScript ]]></title><description><![CDATA[The software supply chain has become one of cybersecurity&#8217;s most attractive targets, largely because attackers no longer need to compromise thousands of organizations individually.]]></description><link>https://www.cisohq.io/p/upwind-first-to-expose-one-of-the</link><guid isPermaLink="false">https://www.cisohq.io/p/upwind-first-to-expose-one-of-the</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Tue, 04 Aug 2026 14:55:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DE3b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DE3b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DE3b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DE3b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DE3b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!DE3b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0704bf5-7eed-4230-81a2-1e8f7943e0b7_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>The software supply chain has become one of cybersecurity&#8217;s most attractive targets, largely because attackers no longer need to compromise thousands of organizations individually. Instead, infiltrating a single trusted dependency can create a ripple effect across countless development environments. That scenario played out this week when </span><a href="http://upwind.io"><span>Upwind</span></a><span> became the first to publicly report a malicious release of the widely used npm package Keyv, warning developers that the compromise had the potential to impact a massive portion of the JavaScript ecosystem.</span></p><p><span>The discovery centered on keyv@6.0.0, a malicious version of one of npm&#8217;s most heavily used packages. With approximately 154 million weekly downloads, Keyv serves as a core dependency for thousands of JavaScript applications, making any compromise particularly significant. Upwind&#8217;s findings prompted immediate guidance for organizations to remove the affected version and investigate whether sensitive credentials had been exposed.</span></p><h2><span>A Malicious Update Hidden Inside a Trusted Package</span></h2><p><span>According to Upwind, the compromised release introduced a previously unseen preinstall hook that executed automatically during installation. Rather than changing the package&#8217;s expected functionality, the attackers inserted an obfuscated loader designed to run before developers ever began using the library.</span></p><p><span>The loader downloaded the Bun runtime from GitHub Releases before launching a bundled payload capable of harvesting credentials from developer workstations and CI/CD environments. Among the targeted secrets were AWS credentials, GitHub tokens, npm authentication tokens, and HashiCorp Vault credentials, giving attackers a potential pathway into both development infrastructure and cloud environments.</span></p><p><span>&#8220;What makes this incident particularly significant is the package&#8217;s reach,&#8221; Upwind wrote in its public disclosure. &#8220;With approximately 154 million weekly downloads, keyv is a foundational dependency used across thousands of JavaScript projects, dramatically increasing the potential blast radius of the compromise.&#8221;</span></p><p><span>That reach transformed what could have been an isolated package compromise into an incident with ecosystem-wide implications.</span></p><h2><span>The Attack Expanded Beyond Keyv</span></h2><p><span>As researchers continued analyzing the incident, evidence emerged that the campaign had spread beyond the original Keyv release. Multiple malicious package versions were identified across the npm ecosystem, suggesting that stolen publishing credentials enabled attackers to distribute poisoned releases through additional packages.</span></p><p><span>Because package versions and &#8220;latest&#8221; tags changed rapidly as maintainers responded, security experts advised organizations to inspect their resolved dependency versions, lockfiles, and software bills of materials rather than relying solely on package registry listings.</span></p><p><span>The malware reportedly went well beyond credential theft. Analysis indicated it could collect authentication tokens, cloud credentials, private keys, and other sensitive information from developer machines and CI/CD runners. Some reports also described functionality capable of republishing compromised packages using stolen npm publishing access, increasing the possibility of automated propagation throughout the ecosystem.</span></p><p><span>Although the total number of affected packages continued evolving throughout the response, the campaign demonstrated how quickly attackers can leverage trusted software distribution channels once publisher credentials are compromised.</span></p><h2><span>Trust Alone Is No Longer a Security Strategy</span></h2><p><span>One of the more concerning aspects of the incident is that the compromised package reportedly passed through legitimate software release workflows.</span></p><p><span>Modern software supply chain protections, including provenance and build attestations, can verify how software is built, but they cannot always determine whether malicious code entered the development pipeline before those trusted processes began. As a result, organizations increasingly need visibility into dependency behavior&#8212;not just whether software was signed or built correctly.</span></p><p><span>The incident also reflects a broader shift in attacker strategy. Instead of focusing exclusively on exploiting deployed applications, threat actors are increasingly targeting developer tools, package managers, and build environments where a single successful compromise can reach thousands of downstream users.</span></p><h2><span>A Reminder That Popular Packages Are Valuable Targets</span></h2><p><span>For organizations using Keyv, Upwind urged immediate action: remove keyv@6.0.0, pin dependencies to a verified clean version, rotate credentials if the malicious release was installed, and review CI/CD pipelines, lockfiles, and SBOMs for exposure.</span></p><p><span>&#8220;This incident is another reminder that highly trusted, high-volume dependencies remain prime targets for supply-chain attackers-and that a single malicious release can have ecosystem-wide consequences,&#8221; Upwind said.</span></p><p><span>The discovery serves as another reminder that software supply chain security extends beyond vulnerability management. Even trusted, widely adopted open-source components can become attack vectors when release pipelines or publisher credentials are compromised. By identifying the malicious Keyv release early, Upwind&#8217;s disclosure highlighted both the speed at which these campaigns can unfold and the importance of continuously monitoring the behavior of software dependencies, not just the software itself.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Andy Curtis on Turning Cybersecurity Into Business Risk Decisions]]></title><description><![CDATA[Andy Curtis is an experienced cybersecurity leader and CISO with a background in information security implementation, architecture, and strategic security programs across government, finance, and enterprise environments.]]></description><link>https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-andy-curtis-on-turning</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Tue, 04 Aug 2026 10:01:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WWjw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WWjw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WWjw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WWjw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WWjw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!WWjw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf4a8b90-ca12-4581-a656-1d6d2579196d_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><a href="https://www.linkedin.com/in/c1andrew/"><span>Andy Curtis</span></a><span> is an experienced cybersecurity leader and CISO with a background in information security implementation, architecture, and strategic security programs across government, finance, and enterprise environments. As CISO at Gadget Access, he has worked across frameworks including ISO 27001, NIST, and Essential Eight, helping organizations strengthen their security posture while aligning cyber initiatives with broader business priorities. His approach combines hands-on technical expertise with a strong understanding of risk, governance, compliance, and the realities of operating security programs at scale.</span></p><p><span>In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Curtis shares a practical perspective on making cybersecurity more effective by connecting technical decisions to measurable business outcomes. From avoiding unnecessary security-tool sprawl and translating vulnerabilities into executive-level risk, to testing incident response plans and proving that backups can actually support recovery, his advice centers on one core principle: security teams should focus less on collecting tools and metrics and more on reducing material risk. For Curtis, that means learning to communicate in the language of business, making informed trade-offs, and ensuring that cybersecurity decisions ultimately support the organization&#8217;s ability to operate and recover.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>...prove it will reduce a material risk&#8212;and prove you can operate it.</span></p><p><span>The license fee is only the admission price. The real cost includes implementation, integration, data ingestion, training, tuning, support, additional infrastructure, operational headcount and the time required to investigate whatever the new dashboard turns red.</span></p><p><span>I am a supporter of best-of-breed technology when an organization can afford best-of-breed integration and operations. Otherwise, you can end up with several excellent products collaborating mainly through their invoices.</span></p><p><span>Sometimes a well-integrated platform delivers a better overall outcome than a collection of individually superior tools with gaps between them. Equally, consolidating everything onto one platform simply because the vendor has an attractive bundle can introduce lock-in and concentration risk. The right answer depends on coverage, interoperability, operational maturity and the risk being treated&#8212;not which logo appears highest on an analyst diagram.</span></p><p><span>A vendor-sponsored 2025 survey of 1,000 executives found that participating organizations were using an average of 83 security solutions from 29 vendors. That does not prove platforms are always better, but it does confirm that integration overhead is not something CISOs have collectively imagined after too much coffee.</span></p><p><span>The CISO&#8217;s job is not to assemble the most impressive security-tool collection. It is to achieve the greatest sustainable reduction in risk for the money available.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>Everyone in the security team must be able to explain their work in business, executive, and risk language.</span></p><p><span>I do not expect every analyst or engineer to become a miniature CFO. I do expect them to understand the business service they are protecting, the risk scenario they are changing, the consequence of doing nothing, and the decision required from management.</span></p><p><span>&#8220;We have 4,700 vulnerabilities&#8221; is information.</span></p><p><span>&#8220;Three internet-facing vulnerabilities create a credible path into the customer payments environment, and the remediation owner needs an approved outage before Friday&#8221; is decision support.</span></p><p><span>A technical finding without business context is unfinished work.</span></p><p><span>This is not about dumbing down the technical truth. It is about expressing that truth in the operating language of the audience. Executives generally think in terms of objectives, exposure, obligations, trade-offs, money, customers and accountability. Security professionals should be able to move between those concepts and the technical detail without losing accuracy in either direction.</span></p><p><span>Current ASD guidance explicitly treats business acumen, communication and relationship-building as core CISO capabilities, and expects cyber reporting to translate security issues into operational, financial and legal risk. I apply that expectation across the team rather than reserving it for whoever attends the board meeting.</span></p><p><span>CVSS 9.8 may be technically correct. It is rarely a complete executive sentence.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>My starting ratio is 50:50.</span></p><p><span>Roughly half of the program should be driven top-down by material business risks: critical services, crown-jewel data, regulatory obligations, credible threat scenarios and the consequences the organization genuinely cannot tolerate.</span></p><p><span>The other half should be driven bottom-up by operational reality: unsupported systems, excessive privileges, weak configurations, failing backups, poor asset visibility, incomplete logging and all the low-hanging fruit that has somehow remained on the tree for six budget cycles.</span></p><p><span>The top-down half prevents the security team from becoming extremely efficient at fixing the wrong things. The bottom-up half prevents the enterprise risk register from becoming a beautifully formatted description of controls that do not actually work.</span></p><p><span>NIST CSF 2.0 reinforces this linkage: practitioners implement and measure risk treatment activities, while executives integrate cyber risk information with the organization&#8217;s wider enterprise risk decisions. Both views are necessary because neither strategy nor telemetry is sufficient by itself.</span></p><p><span>I use industry spending benchmarks and breach-cost studies as reasonableness checks, not as allocation formulas. &#8220;Our peers spend 12 percent&#8221; does not tell me whether our identity architecture is sound, whether our backups restore or whether half the estate is running on something last patched during the Howard government.</span></p><p><span>The ratio is a compass, not a religion. It should move as risks, maturity and business priorities change. Incidents, in particular, have very little respect for resource-allocation models.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>&#8220;It is cheaper than one material breach every five years.&#8221;</span></p><p><span>That line gets attention. It does not, by itself, earn approval.</span></p><p><span>The next slide needs to contain the arithmetic: the credible scenario, the business services affected, the potential outage, the likely response and recovery cost, the customer and regulatory consequences, and how much the proposed investment will reduce either the likelihood or the impact.</span></p><p><span>The argument should not be, &#8220;Cyber incidents are expensive, therefore approve everything in my spreadsheet.&#8221; It should be, &#8220;Here is a plausible loss scenario, here are the available treatment options, here is what each option costs, and here is the residual exposure under each choice.&#8221;</span></p><p><span>IBM&#8217;s 2025 study reported a global average breach cost of US$4.4 million across the organizations studied. That is useful context, but a generic worldwide average is not a substitute for understanding your own economics. A CFO should see the potential interruption to your services, your revenue, your customers and your obligations&#8212;not an impressive-looking number borrowed from somebody else&#8217;s breach.</span></p><p><span>Fear may secure a meeting. Credible options, quantified assumptions and transparent trade-offs secure a budget.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Raw technical reporting to executives who cannot reasonably act on it.</span></p><p><span>I would immediately cut the 40-page reports filled with vulnerability counts, firewall events, malware detections, phishing statistics, and screenshots from security products. That information may be valuable to security operators, engineers and control owners. It is usually not useful in its raw form to a board or executive committee.</span></p><p><span>Executive reporting should answer a smaller set of harder questions:</span></p><p><span>What important business service is exposed? What is the credible scenario? Is the exposure increasing or decreasing? Are the relevant controls working? Who owns the treatment? What decision or intervention is required, and by when?</span></p><p><span>The underlying technical evidence should still exist. It should simply be presented at the level where someone can use it.</span></p><p><span>AICD guidance recommends that board reporting go beyond isolated technical measures and traffic lights to include risk outcomes, relevant threats and trend information. ASD guidance similarly expects reporting to be structured around business functions and to cover risk profiles, key systems, uplift activity, incidents and expected returns on security investment.</span></p><p><span>A board pack is not a SIEM export wearing a tie.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>I ask one question:</span></p><p><span>&#8220;In one minute, explain the problem you believe we have, the measurable outcome you will improve, and what we can stop doing if your product works.&#8221;</span></p><p><span>A good vendor will have asked enough questions to understand the environment, the existing controls, the operating model, the constraints and the outcome we are trying to achieve.</span></p><p><span>They will also be able to discuss implementation effort, dependencies, staffing requirements, data quality, integration limitations and where their product is not the answer.</span></p><p><span>A weak vendor will respond with the company origin story, three analyst quotations, the phrase &#8220;single pane of glass&#8221; and an urgent announcement that artificial intelligence has changed everything since Tuesday.</span></p><p><span>I am also interested in whether the proposed solution replaces or simplifies anything. Adding one more console, agent, data lake, workflow and set of alerts is not necessarily an improvement simply because the demonstration contains a colorful attack graph.</span></p><p><span>Current ASD procurement guidance emphasizes supplier transparency, security track record, lifecycle considerations and clear allocation of responsibilities between customer and supplier. Those are much better indicators of a sustainable relationship than the smoothness of the demonstration environment.</span></p><p><span>Any vendor can demonstrate a dashboard. The grown-up conversation is about the operating model.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I eliminated the vulnerability meeting that consisted of security reading scanner results aloud to people who were quietly reconsidering their career choices.</span></p><p><span>It was an activity meeting rather than a risk meeting. We could spend an hour discussing thousands of findings without answering the most important question: which weaknesses create a credible path to material business impact?</span></p><p><span>I replaced it with an application and business-service risk review.</span></p><p><span>Instead of beginning with vulnerability volume, we begin with business criticality, internet exposure, sensitive data, identity and privilege pathways, known exploitation, exploit probability, compensating controls, remediation ownership, and trend. The scanner results still provide evidence, but they no longer dictate the agenda.</span></p><p><span>This matters because no single technical score represents organizational risk. FIRST&#8217;s EPSS estimates the probability that a vulnerability will be exploited, but explicitly warns that it is not a complete risk score. Asset purpose, value, accessibility, controls and potential impact must still be considered.</span></p><p><span>We use RAG reporting because it gives executives a rapid view of hotspots and creates some healthy competition between teams. But RAG is navigation, not analysis. Green is not a control, and red is not a diagnosis. A red customer-payment platform and a red internal test server are not equivalent merely because PowerPoint has assigned them the same shade.</span></p><p><span>The new discussion is not, &#8220;Who has the most vulnerabilities?&#8221;</span></p><p><span>It is, &#8220;Which application is most likely to hurt us, who owns the response, and is the exposure moving in the right direction?&#8221;</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Activating the business response, rather than only the technical response.</span></p><p><span>Technical teams quite reasonably begin containing the threat, collecting evidence and working out what happened. But a significant incident also needs an incident commander, a decision log, a reliable communications channel and early engagement from the people responsible for legal, communications, business continuity, critical services and executive decisions.</span></p><p><span>Someone should also be given explicit responsibility for protecting and validating the recovery path. That does not mean immediately restoring systems or connecting backup infrastructure to a potentially compromised environment. It means establishing whether the backups are isolated, current and likely to be usable; whether the associated credentials may be compromised; and whether there is a clean recovery path available when it is needed.</span></p><p><span>Backups are frequently treated as a magic incantation: somebody says, &#8220;We have backups,&#8221; and everyone feels better. The useful question is whether we can restore the right services, from trustworthy data, within a timeframe the business can survive.</span></p><p><span>ASD guidance emphasizes enacting the incident response plan once an incident is identified, while its continuity guidance highlights the need to maintain communications and critical business functions when normal systems are unavailable.</span></p><p><span>The SOC can contain malware. It cannot, by itself, authorize customer communications, decide whether payroll outranks email for recovery, or explain the situation to the regulator.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>&#8220;When did we last prove, in practice, that our incident response and business continuity plans work together?&#8221;</span></p><p><span>Not when were they last reviewed.</span></p><p><span>Not when did somebody update the document footer.</span></p><p><span>When were they last road-tested under realistic conditions, involving the people, suppliers and decision-makers who would actually be required during an incident?</span></p><p><span>A meaningful exercise should test decision authority, escalation paths, out-of-band communications, executive availability, legal and regulatory thresholds, supplier contacts, manual business workarounds, backup restoration, service-recovery priorities and the assumptions behind recovery time and recovery point objectives.</span></p><p><span>It should also expose awkward practical details. Are the emergency contact details stored somewhere accessible when email is down? Can the crisis team collaborate without using the potentially compromised corporate environment? Does the person named as incident commander still work here? Can the backup be restored, or has the organization merely been paying to store it very carefully?</span></p><p><span>Current ASD guidance requires incident management policies and associated response plans to be exercised at least annually, and separately expects boards or executive committees to participate in planning and exercises for major cyber incidents. For a critical or rapidly changing environment, annual testing should be treated as a floor rather than an aspiration.</span></p><p><span>A tabletop exercise that ends with everyone congratulating themselves is often just a meeting with a plot.</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I use a structure like this:</span></p><p><span>&#8220;This creates a credible pathway to [critical service] being unavailable or compromised for [period], affecting [customers, operations or data], with a plausible financial impact of [$X&#8211;$Y]. We can reduce the likelihood or duration through [action] at a cost of [$Z]. The decision required is [choice].&#8221;</span></p><p><span>That framing translates the technical condition without hiding it. It connects the weakness to a business promise, explains the plausible scenario, acknowledges uncertainty, quantifies the potential consequence and makes the decision explicit.</span></p><p><span>I also try to make &#8220;reputational damage&#8221; less abstract. Reputation is not a mysterious cloud that descends after an incident. It can appear as customer attrition, reduced conversion, lost bids, delayed sales, increased support demand, regulatory scrutiny, partner concern or prolonged executive distraction. Where possible, I connect reputation to those observable commercial and operational effects.</span></p><p><span>The use of ranges is important. Cyber quantification should improve decision-making, not manufacture false precision. Saying the impact is plausibly between $3 million and $8 million, based on stated assumptions, is often more credible than claiming the answer is exactly $5,421,763 because a spreadsheet contains several decimal places.</span></p><p><span>Both ASD and NIST expect cyber risk information to support broader organizational risk and investment decisions rather than remain isolated in specialist terminology.</span></p><p><span>Executives do not need a guided tour of the CVE. They need to know which promise to customers it could break.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>Learn to talk executive risk.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on"><span>CISO Tips: Carlos Garc&#237;a Batista on Turning Cybersecurity Into Operational Resilience</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking"><span>CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning"><span>CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first"><span>CISO Tips: Paul Blahusch on Business Success Coming First</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-diyar-akhmedov-on-prioritizing-risk-over-hype"><span>CISO Tips: Diyar Akhmedov on Prioritizing Risk Over Hype</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Carlos García Batista on Turning Cybersecurity Into Operational Resilience]]></title><description><![CDATA[For Carlos Garc&#237;a Batista, cybersecurity is ultimately about protecting the continuity of essential services.]]></description><link>https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-carlos-garcia-batista-on</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Sun, 02 Aug 2026 12:32:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CmSJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CmSJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CmSJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CmSJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CmSJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!CmSJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3412a0e-a333-4bbe-8d83-45923000d777_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>For </span><a href="https://www.linkedin.com/in/cgarbat/"><span>Carlos Garc&#237;a Batista</span></a><span>, cybersecurity is ultimately about protecting the continuity of essential services. As CISO and Information Security Officer for the Directorate General of Emergencies within the Gobierno de Canarias, he operates at the intersection of critical infrastructure protection, emergency response, operational resilience, and regulatory compliance. His responsibilities include coordinating cybersecurity across technical and operational environments, working with authorities on incident management, and helping ensure that essential services remain secure and available when they are needed most.</span></p><p><span>That perspective shapes a pragmatic approach to security leadership, one grounded in ownership, accountability, and resilience rather than simply accumulating more tools and controls. From questioning whether a security investment actually reduces operational risk to establishing clear command structures during incidents, Garc&#237;a Batista emphasizes the importance of turning cybersecurity into actionable decisions. In this edition of </span><em><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a></em><span>, he shares practical guidance on everything from evaluating vendors and securing privileged access to communicating risk with executives and knowing which security activities are no longer worth the effort.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>Before you buy any new security tool, first define the operational risk you are trying to reduce, who will own the tool, who will operate it, and what decision it will help you make.</span></p><p><span>A tool without ownership becomes another unmanaged asset.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>No privileged access without a clear purpose, a named owner, traceability, and a review date.</span></p><p><span>Access should never be granted just because &#8220;it may be useful someday.&#8221; In security, convenience without control becomes risk very quickly.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>I try to keep a practical balance between prevention, detection, response, and resilience.</span></p><p><span>If most of the effort goes only into buying preventive controls, the organization may look protected but still be unable to detect, respond, or recover properly. For critical services, resilience deserves budget, time, and executive attention.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>&#8220;This is not only a cybersecurity investment; it is an operational continuity investment.&#8221;</span></p><p><span>That framing usually works because it connects security to service availability, institutional responsibility, and business or public-service impact.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>Security activities that generate reports but do not generate decisions.</span></p><p><span>If a report, meeting, metric, or control does not help reduce risk, improve visibility, assign responsibility, or support a decision, it should be simplified, automated, merged, or removed.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>I ask three questions:</span></p><p><span>What specific risk does this reduce?</span></p><p><span>How will it integrate with what we already have?</span></p><p><span>Who in my team will operate it on a bad day?</span></p><p><span>If the answer is vague, the pitch is not mature enough.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I try to eliminate meetings that only exist to exchange information that could have been documented beforehand.</span></p><p><span>They should be replaced by short, evidence-based operational reviews: what changed, what risk increased, what decision is needed, who owns the next action, and by when.</span></p><p><span>Security governance should create clarity, not ceremony.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>They often skip defining the incident commander and the decision-making channel.</span></p><p><span>Many teams start investigating immediately, but without clear coordination, roles, and communication discipline. In an incident, technical work matters, but command structure matters just as much.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>&#8220;What are we currently accepting as normal that is actually a risk?&#8221;</span></p><p><span>That question usually reveals technical debt, informal exceptions, undocumented dependencies, weak ownership, or processes that only work because one person knows how to keep them alive.</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>I translate technical risk into operational consequence.</span></p><p><span>Instead of saying, &#8220;We have a vulnerability in this system,&#8221; I prefer to say, &#8220;If this fails or is compromised, this service may be unavailable, this decision may be delayed, or this operational capability may be affected.&#8221;</span></p><p><span>Executives need to understand impact, not just threat language.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>Govern calmly, document, prioritize, breathe.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking"><span>CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning"><span>CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first"><span>CISO Tips: Paul Blahusch on Business Success Coming First</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-diyar-akhmedov-on-prioritizing-risk-over-hype"><span>CISO Tips: Diyar Akhmedov on Prioritizing Risk Over Hype</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-peter-egyed-on-why-consistency"><span>CISO Tips: Peter Egyed on Why Consistency and Prioritization Strengthen Cybersecurity</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[Bloom Security Emerges With $20M Seed to Protect the Expanding AI-Native Endpoint]]></title><description><![CDATA[The traditional corporate endpoint was built around a simple premise: organizations knew which devices employees used and could largely control the software installed on them.]]></description><link>https://www.cisohq.io/p/bloom-security-emerges-with-20m-seed</link><guid isPermaLink="false">https://www.cisohq.io/p/bloom-security-emerges-with-20m-seed</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Thu, 30 Jul 2026 13:05:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Hn71!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hn71!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hn71!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hn71!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg" width="1456" height="970" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:970,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hn71!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Hn71!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47b9817a-4dea-4c8f-95a6-997c1f93d270_2048x1365.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>The traditional corporate endpoint was built around a simple premise: organizations knew which devices employees used and could largely control the software installed on them. That model is becoming harder to maintain as AI agents, browser extensions, MCP servers and code packages become embedded in daily work.</span></p><p><a href="https://bloom.security/"><span>Bloom Security</span></a><span> is launching with the goal of addressing that growing complexity. The Tel Aviv-based company has emerged from stealth with a $20 million seed round led by Glilot Capital Partners, with participation from </span>Ten Eleven Ventures (1011vc), <span>Okta Ventures, and Runtime Ventures. </span><a href="https://www.axios.com/pro/enterprise-software-deals/2026/07/30/bloom-security-endpoint-crowdstrike"><span>Axios</span></a><span> first reported about the company&#8217;s launch and funding.</span></p><p><span>The funding also includes prominent angel investors, including the founders of Dig Security, Demisto, Snyk and Talon. Bloom said its platform is already deployed at dozens of large enterprises across the United States and Europe, giving the startup an early foothold as companies look for ways to manage the security implications of rapid AI adoption.</span></p><h2><span>The New Software Perimeter</span></h2><p><span>The challenge Bloom is targeting goes beyond the traditional definition of endpoint security. Employees are increasingly assembling their own software environments through AI tools, extensions and other applications, while browsers, IDEs and AI agents introduce marketplaces that can expand the number of tools operating on a corporate device.</span></p><p><span>For security teams, the issue is not necessarily that these tools are malicious. Instead, legitimate software can become a source of risk because of how it is configured, what permissions it receives or how it interacts with other systems and data.</span></p><p><span>&#8220;In the AI era, the employee device is no longer just a managed endpoint,&#8221; said </span><a href="https://www.linkedin.com/in/itay-keren-%F0%9F%8C%B8-544760148/"><span>Itay Keren</span></a><span>, Co-Founder and CEO of Bloom Security. &#8220;Every endpoint is now running software no one reviewed, connecting to services no one provisioned.&#8221;</span></p><p><span>Bloom points to a range of potential risks, including AI agents with incorrect configurations, plugins that have excessive data permissions, screen recorders operating on executive devices and code libraries that pull from untrusted sources. These scenarios can create attack paths that traditional endpoint detection and response products may not have been designed to identify or manage.</span></p><p><span>&#8220;As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality,&#8221; Keren added. &#8220;Security teams need a way to understand, govern, and control modern tools without disrupting how employees work.&#8221;</span></p><h2><span>Understanding Risk in Context</span></h2><p><span>Bloom Security&#8217;s platform is designed to give organizations a broad inventory of what is running across their endpoints, including software, tools, extensions and code. It also examines how those components interact with data and systems and analyzes supply-chain risk, configurations and permissions.</span></p><p><span>The company is taking a contextual approach to determining exposure. Its premise is that the risk associated with a particular application can vary significantly depending on the employee using it and the environment in which it operates.</span></p><p><span>&#8220;The same tool can be completely acceptable on one endpoint and high-risk on another,&#8221; said </span><a href="https://www.linkedin.com/in/ofir-balassiano/"><span>Ofir Balassiano</span></a><span>, Co-Founder and Chief Product Officer at Bloom Security. &#8220;Risk depends on context: the user&#8217;s role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time.&#8221;</span></p><p><span>The platform is also designed to let security teams take action based on those assessments. Bloom says organizations can block risky installations before they reach employee devices, enforce secure configurations and remediate risks without manual approval workflows.</span></p><p><span>That combination of visibility and enforcement is central to the company&#8217;s positioning as it targets large enterprises navigating AI adoption at scale.</span></p><h2><span>Building From Enterprise Security Experience</span></h2><p><span>Bloom&#8217;s leadership team has backgrounds at several established cybersecurity companies. CEO Itay Keren previously held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security and Demisto. Chief Product Officer Ofir Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks and previously worked at Dig Security and XM Cyber.</span></p><p><span>Chief Technology Officer </span><a href="https://www.linkedin.com/in/itay-frishman/"><span>Itay Frishman</span></a><span> built AISPM and DSPM solutions at Palo Alto Networks and Dig Security, alongside earlier cybersecurity research and development experience. Bloom currently has 30 employees, many of whom previously worked together at Dig Security.</span></p><p><span>&#8220;While this is technically our first company as founders, our team has built and integrated category-defining products before,&#8221; said Itay Frishman, Co-Founder and CTO. &#8220;We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today.&#8221;</span></p><p><span>Bloom&#8217;s investors see the changing endpoint as an emerging category in enterprise security. Kobi Samboursky, Founder and Managing Partner at Glilot Capital, said the company&#8217;s early traction reflects the urgency of the problem.</span></p><p><span>&#8220;AI has changed the enterprise endpoint in ways the security industry is still catching up to. Agents, MCP servers, browser extensions, and code packages now run on every employee&#8217;s machine, entirely outside the reach of traditional controls,&#8221; said Kobi Samboursky, Founder and Managing Partner at Glilot Capital. &#8220;Bloom identified this gap before the market did, and the business traction we&#8217;ve seen in their first months is unprecedented for a company at this stage. A team this experienced with a problem this urgent and momentum this strong is what category-defining companies look like from day one.</span></p><p><span>With $20 million in seed funding and deployments at dozens of large enterprises, Bloom is now focused on a security perimeter that is changing alongside the workplace itself. Its bet is that protecting the AI-native endpoint will require organizations to understand not only what is running on employee devices, but also the context in which that software operates and the access it has to corporate resources.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Whisperer Publishes Its Company-by-Company Guide to Black Hat USA 2026]]></title><description><![CDATA[Black Hat USA 2026 takes place August 1 through 6 at the Mandalay Bay Convention Center in Las Vegas, with expert trainings, summits, and main conference briefings covering the technologies and challenges shaping modern cybersecurity.]]></description><link>https://www.cisohq.io/p/ciso-whisperer-publishes-its-company</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-whisperer-publishes-its-company</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 29 Jul 2026 13:15:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!3Th7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3Th7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3Th7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 424w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 848w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 1272w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3Th7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3Th7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 424w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 848w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 1272w, https://substackcdn.com/image/fetch/$s_!3Th7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92afe690-8ebc-4aad-9244-e466649b0963_1740x1160.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>Black Hat USA 2026 takes place August 1 through 6 at the Mandalay Bay Convention Center in Las Vegas, with expert trainings, summits, and main conference briefings covering the technologies and challenges shaping modern cybersecurity. Organizations are contending with AI-driven threats, expanding attack surfaces, cloud complexity, and growing volumes of security data. Vendors are answering with new approaches to detection, response, exposure management, and resilience. What follows is a company-by-company reference to 12 firms worth attention, drawn from the </span><a href="https://cisowhisperer.com/12-cybersecurity-companies-to-watch-at-black-hat-usa-2026/"><span>CISO Whisperer watch list</span></a><span>.</span></p><h2><strong><span>Upwind</span></strong></h2><p><span>Cloud and AI security handled from the runtime layer.</span><a href="https://www.upwind.io/"><span> Upwind</span></a><span> connects cloud inventory, posture, network topology, applications, and identities, then blends real-time and agentless signals to produce a live view of infrastructure, networks, APIs, and data flows. Faster threat response is the outcome it sells. Placed in the Super Tier.</span></p><h2><strong><span>Cloudflare</span></strong></h2><p><span>A global network for building, securing, and scaling applications, AI agents, and workforces without managing the infrastructure underneath.</span><a href="https://www.cloudflare.com/"><span> Cloudflare</span></a><span> pushes security, connectivity, and code execution toward users and data. The network spans more than 335 cities and reaches 95% of the world&#8217;s population within 50 milliseconds. The company says its network powers 42% of the Fortune 500, which reflects its broad role in the modern internet ecosystem. Super Tier.</span></p><h2><strong><span>Illumio</span></strong></h2><p><span>Breach containment across hybrid and multi-cloud environments.</span><a href="https://www.illumio.com/"><span> Illumio</span></a><span> combines Zero Trust principles, AI-powered insights, and segmentation to detect threats, restrict lateral movement, and contain attacks before they spread. Super Tier.</span></p><h2><strong><span>Arctic Wolf</span></strong></h2><p><span>The Aurora Superintelligence Platform, positioned as a foundation for more automated security operations.</span><a href="https://arcticwolf.com/"><span> Arctic Wolf</span></a><span> uses AI agents to help organizations operate at machine speed. Built-in trust controls and human oversight provide validation, governance, and the expertise needed to manage complex security decisions. Super Tier.</span></p><h2><strong><span>Cohesity</span></strong></h2><p><span>Data protection and cyber resilience on one platform. The</span><a href="https://www.cohesity.com/"><span> Cohesity</span></a><span> Data Cloud brings data protection, security, recovery, and AI readiness together for hybrid cloud and SaaS workloads, strengthening threat detection, automating cyber recovery, reducing compliance risk, and making enterprise data more useful for AI initiatives. Super Tier.</span></p><h2><strong><span>Veracode</span></strong></h2><p><span>Application risk management across the software development lifecycle.</span><a href="https://www.veracode.com/"><span> Veracode</span></a><span> pairs visibility across code, dependencies, containers, and runtime signals with remediation guidance and AI-driven fixes. The aim is reduced security debt at maintained development speed. Featured Tier.</span></p><h2><strong><span>ThreatLocker</span></strong></h2><p><span>Zero Trust enforcement built on a deny-by-default model.</span><a href="https://www.threatlocker.com/"><span> ThreatLocker</span></a><span> permits only authorized applications, scripts, and processes to run across endpoints, cloud, and networks. Granular control is applied to prevent ransomware, reduce privilege abuse, limit lateral movement, and make data exfiltration more difficult. Featured Tier.</span></p><h2><strong><span>SafeBreach</span></strong></h2><p><span>Adversarial exposure validation for teams that want proof rather than assumption.</span><a href="https://www.safebreach.com/"><span> SafeBreach</span></a><span> tests whether defenses can withstand real-world attack techniques. The SafeBreach Helm platform combines exposure validation, AI orchestration, and existing security technologies to support continuous threat exposure management and measurable risk reduction. Featured Tier.</span></p><h2><strong><span>Mate Security</span></strong></h2><p><span>An agentic SOC designed for the speed and scale of modern threats.</span><a href="https://mate.security/"><span> Mate Security</span></a><span> uses a security context graph to give AI agents a tailored understanding of an organization&#8217;s environment, enabling support for detection building, triage, investigations, response, and threat hunting in a continuous cycle. Emerging Tier.</span></p><h2><strong><span>Daylight Security</span></strong></h2><p><span>Managed Agentic Security Services, or MASS, combining AI agents with experienced security professionals.</span><a href="https://daylight.ai/"><span> Daylight Security</span></a><span> covers managed detection and response, threat hunting, and phishing investigation and response. Its experts help customize detections, build integrations, and improve the context powering its AI systems. Emerging Tier.</span></p><h2><strong><span>Reclaim Security</span></strong></h2><p><span>An AI Security Engineer built to close the distance between identifying exposures and fixing them.</span><a href="https://reclaim.security/"><span> Reclaim Security</span></a><span> analyzes findings across security tools, understands business context, creates remediation strategies, and can deploy fixes through automated or approval-based workflows. Emerging Tier.</span></p><h2><strong><span>Zero Networks</span></strong></h2><p><span>Automated, identity-driven microsegmentation aimed at containing attacks and limiting lateral movement.</span><a href="https://zeronetworks.com/"><span> Zero Networks</span></a><span> applies segmentation to networks, identities, AI agents, and non-human accounts while helping organizations govern AI identities and restrict unauthorized activity. Emerging Tier.</span></p><h2><strong><span>Reading the Roster</span></strong></h2><p><span>Twelve entries, five in the Super Tier, three Featured, four Emerging. Read as a set, the list shows how far the industry has moved toward automation in the space of a single conference cycle. Four of the twelve describe AI agents as part of the product rather than as a roadmap item. Three extend their coverage to non-human identities. Black Hat USA 2026 arrives as AI reshapes both cybersecurity defense and the threat landscape, and the gathering of security leaders, researchers, practitioners, and vendors in Las Vegas will offer a view of how the industry is preparing for machine-speed attacks, autonomous systems, and increasingly complex digital environments.</span></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[CISO Tips: Sergey Tairyan on Thinking Like an Attacker and Leading Through Cyber Risk]]></title><description><![CDATA[In cybersecurity, effective leadership requires more than deploying the right tools or responding quickly to incidents.]]></description><link>https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking</link><guid isPermaLink="false">https://www.cisohq.io/p/ciso-tips-sergey-tairyan-on-thinking</guid><dc:creator><![CDATA[John Joseph Javier]]></dc:creator><pubDate>Wed, 29 Jul 2026 10:27:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1EH1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1EH1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1EH1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1EH1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png" width="1200" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1EH1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 424w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 848w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 1272w, https://substackcdn.com/image/fetch/$s_!1EH1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa609d1f8-0078-4d8a-b73a-c1c59755423d_1200x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p><span>In cybersecurity, effective leadership requires more than deploying the right tools or responding quickly to incidents. It requires a mindset built around continuous learning, attacker thinking, and the ability to translate technical risk into business impact. </span><a href="https://www.linkedin.com/in/sergey-tairyan-0081b072/"><span>Sergey Tairyan</span></a><span>, Chief Information Security Officer at the Technology Management Center of Yerevan City and founder of OmniSec and Oky.ai, brings more than 15 years of experience building and transforming security programs across industries. His expertise spans security operations, SOC leadership, SIEM and DLP, IAM and PAM, endpoint protection, incident response, and emerging areas such as steganography and post-quantum cryptography.</span></p><p><span>Known for combining hands-on ethical hacking with long-term security strategy, Sergey approaches cybersecurity with a focus on reducing real-world risk while keeping organizations resilient and operational. His advice reflects that philosophy, from researching a vendor before buying its tools and measuring security decisions in business numbers to prioritizing daily learning and clear leadership during a crisis. In this edition of </span><a href="https://www.cisohq.io/s/ciso-tips"><span>CISO Tips</span></a><span>, Sergey shares the principles, habits, and practical approaches that shape how he thinks about security leadership in an increasingly complex threat landscape.</span></p><h3><span>Complete this sentence: &#8220;Before you buy any new security tool, first...&#8221;</span></h3><p><span>Before you buy any new security tool, first do OSINT on the company behind it.</span></p><h3><span>What&#8217;s one rule you enforce on your team that other teams would find strict?</span></h3><p><span>Two non-negotiable rules:</span></p><ul><li><p><span>All team members must maintain 24/7/365 availability, including weekends, holidays, vacations, and days off.</span></p></li><li><p><span>Every team member spends one hour daily on learning and research.</span></p></li></ul><p><span>In cybersecurity, threats don&#8217;t rest and neither does learning.</span></p><h3><span>What&#8217;s a number or ratio that guides how you allocate budget, headcount, or your own time?</span></h3><p><span>65% prevention, 15% detection and response, 20% innovation and research.</span></p><p><span>AI has shifted the balance toward innovation, but the ratio should continuously adapt to business risk, technology, and the evolving threat landscape.</span></p><h3><span>What&#8217;s one line that works when asking the board or CFO for a budget?</span></h3><p><span>The board and CFO understand numbers, not technical details. So, I don&#8217;t ask for a security budget; I present a business risk calculation, showing the potential financial impact of an incident, its likelihood, and the cost of reducing that risk.</span></p><h3><span>What should a CISO cut from their program tomorrow with zero regret?</span></h3><p><span>With AI and mature open-source solutions, many enterprise security tools (such as SIEM, security scanners, and password managers) can now be deployed faster, customized, and operated at a fraction of the cost.</span></p><h3><span>What&#8217;s your 60-second test for whether a vendor pitch is worth your time?</span></h3><p><span>I present the vendor with 2-3 real security challenges and watch how they respond.</span></p><p><span>I&#8217;m looking for honesty, technical depth, and a problem-solving mindset - not marketing. If they ask the right questions and acknowledge limitations, they&#8217;ve earned more of my time.</span></p><h3><span>What&#8217;s one meeting, report, or process you eliminated, and what replaced it?</span></h3><p><span>I eliminated meetings focused on what we did and replaced them with discussions on what we learned.</span></p><p><span>Instead of status updates, we focus on new threats, lessons learned, and opportunities to improve our security posture.</span></p><h3><span>In the first 10 minutes of an incident, what&#8217;s the one action teams most often skip?</span></h3><p><span>Teams often skip establishing clear leadership.</span></p><p><span>In a major cyber incident, the CISO becomes the incident commander, directing the CIO, CTO, and other teams to coordinate the response.</span></p><h3><span>What&#8217;s one question every CISO should ask their team this week?</span></h3><p><span>What else can we automate to improve our resilience?</span></p><h3><span>What&#8217;s a phrase or framing you use to translate a technical risk for executives?</span></h3><p><span>Let&#8217;s talk in numbers.</span></p><h3><span>What&#8217;s your best tip for surviving the CISO role in exactly five words?</span></h3><p><span>- Learn. Test. Hack. Repeat.</span></p><p><span>More tips from the series:</span></p><ul><li><p><a href="https://www.cisohq.io/p/ciso-tips-kristin-lowery-on-turning"><span>CISO Tips: Kristin Lowery on Turning Security Activity Into Measurable Risk Reduction</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-paul-blahusch-on-business-success-coming-first"><span>CISO Tips: Paul Blahusch on Business Success Coming First</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-diyar-akhmedov-on-prioritizing-risk-over-hype"><span>CISO Tips: Diyar Akhmedov on Prioritizing Risk Over Hype</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-peter-egyed-on-why-consistency"><span>CISO Tips: Peter Egyed on Why Consistency and Prioritization Strengthen Cybersecurity</span></a></p></li><li><p><a href="https://www.cisohq.io/p/ciso-tips-nikolas-oelkrug-alders"><span>CISO Tips: Nikolas Oelkrug-Alders on Why Strong Security Starts With the Fundamentals</span></a></p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.cisohq.io/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.cisohq.io/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item></channel></rss>