risk management

Why "Shady AI" is Security's Next Big Governance Problem
A recent incident at Meta involving an approved AI agent exposing sensitive data highlights the growing challenge of "shady AI." Unlike "shadow AI" (unapproved tools), shady AI involves approved tools being used in unexpected or poorly governed ways within an organization's visibility. This presents a significant governance problem for security teams, as traditional methods struggle to keep pace with the rapid evolution of AI capabilities and usage patterns.

CISA Issues Fresh SBOM Guidance. Did They Get It Right?
CISA has released updated guidance for Software Bill of Materials (SBOMs), introducing approximately two dozen changes to enhance their comprehensiveness. While these updates aim to provide more detailed information, some critics argue that the framework still falls short in offering substantial improvements for actual risk management.

Post-quantum cryptography (PQC) migration workshop report
The UK's National Cyber Security Centre (NCSC) and Vodafone recently co-hosted a workshop on post-quantum cryptography (PQC) migration, bringing together government, industry, and academic leaders. The event highlighted the critical need for collaboration in transitioning to quantum-resistant algorithms, emphasizing that no single organization can manage this shift alone. Key themes included securing executive sponsorship by framing PQC as a business risk, ensuring supply chain readiness, and fostering transparency and cross-sector collaboration to build national resilience against future quantum computing threats.

Blind Trust in AI Creates Cybersecurity Risks
Allowing AI models to both interpret and execute commands without human oversight introduces significant cybersecurity vulnerabilities. This lack of critical review can lead to unintended consequences and security breaches.

Tennis Analogy Highlights Cybersecurity's Imperfect Nature
A cybersecurity professional uses a tennis analogy to challenge the common notion that defenders must be perfect while attackers only need one success. By referencing Roger Federer's career statistics, the author illustrates that winning a match, much like cybersecurity, doesn't always equate to winning every single point. The key lies in winning the crucial points and understanding the strategic nuances of the game.

Operationalizing Day Minus Seven: The Cloud-Native ROC
The article introduces the concept of a Risk Operations Center (ROC) as a necessary evolution for cybersecurity teams facing AI-driven threats. It argues that traditional risk management models are insufficient due to the speed at which AI can discover and exploit vulnerabilities, especially in cloud environments. A ROC, powered by platforms like Qualys Enterprise TruRisk Management (ETM), aims to unify disparate security findings, hyper-prioritize risks based on exploitability and business impact, and enable autonomous remediation to keep pace with attackers.

5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management
A new report from Frost & Sullivan highlights the evolving landscape of Cloud Security Posture Management (CSPM), which is shifting from a compliance-focused tool to an integrated governance layer within Cloud Native Application Protection Platforms (CNAPPs). The market is projected to grow significantly, driven by the need for continuous risk-based prioritization, code-to-cloud visibility, and platform consolidation to manage multicloud complexity. Artificial intelligence is also playing an increasing role in enhancing CSPM capabilities.

A Day With Your Vector Command Red Team Pod
Continuous red teaming involves a dedicated team of specialists who work daily against a client's environment to identify risks. This ongoing process simulates a real adversary's persistence and coordination, providing a dynamic view of an organization's security posture. By continuously monitoring changes and potential vulnerabilities, the team offers actionable insights that go beyond traditional periodic assessments.

Improving security posture across the Microsoft partner ecosystem
Microsoft is detailing its strategy for enhancing security within its partner ecosystem, particularly focusing on Cloud Solution Providers (CSPs). These partners are crucial for deploying and managing Microsoft cloud services like Azure and Microsoft 365. The company aims to ensure the partner network remains healthy, compliant, and effective to deliver optimal customer outcomes.