The Health Care Cybersecurity and Resiliency Act would mandate MFA, encryption, and penetration testing — with a 36-month clock and no guaranteed funding for rural providers.
Featured
Full CruiseCon 2026 coverage from aboard Mariner of the Seas, including AI security, privacy, insider threats, cyber risk and leadership.
Agentic AI is exposing the limits of static security policies, excessive permissions and decades of technical debt. Enterprises need dynamic, runtime security controls that evaluate what AI agents are doing in real time. (Sponsored by Eve Security)
Community Corner
See allFrom the CYBR.SEC.Community
CruiseCon AI & Privacy 2026: Ship's Log
Bill Brenner posts regular updates from abourd the Mariner of the Seas cruise ship, where he is covering the proceedings during CruiseCon 2026
When the Platform Can Say No Without Saying Why
No externally governed inference or action provider should constitute an unmitigated single point of failure. Where provider behavior cannot be sufficiently characterized, treat the provider as an untrusted-availability dependency.
Nonprofit Cybersecurity Won’t Be Fixed With Another Checklist
Nonprofit cybersecurity doesn't improve with more checklists and portals. Real change starts with conversations that expose hidden risks, build trust and turn advice into action.
Stop Chasing Reach: Why Niche Influence Matters More in Cybersecurity
As a cybersecurity start-up or scale-up you don't need everybody to know your name. You need the right people to keep encountering it for the right reasons.
AI and Nonprofits: The Monster Under the Bed Uses the Same Old Doors
AI is changing the threat landscape. For nonprofits and other under-resourced organizations, panic is a bigger risk than the technology.
Latest Articles
See all
Agentic AIAI Governance
AI Agents Will Make Mistakes. Enterprise Security Must Be Ready When They Do
As enterprises deploy autonomous AI agents across critical systems, security teams must assume those agents will make mistakes. Agentic AI security requires continuous monitoring of behavior, intent and context — not blind trust in permissions. (Sponsored by Eve Security)
AI Data BreachesCruiseConAI Governance
AI-Powered Bank Attacks Exposed 67,000 People. Here Are 5 Things Security Teams Should Do Now
Suspected AI-assisted cyberattacks breached seven South Korean financial firms and exposed data on more than 67,000 people. The attacks reinforce warnings heard at CruiseCon AI and Privacy 2026 and point to five security actions organizations should take now.
CruiseConAI GovernanceAI and Compliancedata security
Data Has No Passport: Why Global Privacy Governance Must Catch Up With AI
Speaking during CruiseCon Privacy & AI 2026, global privacy leader Adriana Antunes Winkler warned that organizations need a common privacy governance core with deliberate local controls as data crosses borders, AI agents take action and computing begins moving into orbit.
CruiseConAI and Insider RiskAgentic AI
AI Could Become the Next Insider Threat as Adversaries Target What Models Trust
Speaking during CruiseCon AI and Privacy, former CIA case officer Erin Whitmore warned that attackers may not need to hack enterprise AI. Manipulating the data and sources AI trusts could turn models into unwitting insider threats that steer organizations toward attacker-controlled decisions.
CruiseConAI and PrivacyCounter terrorism
Dead in the Water: What 30 Years of Fighting Terrorism Taught Dexter Ingram About the Threats We Face
At CruiseCon, former U.S. counterterrorism agent Dexter Ingram explained how terrorism and cybercrime increasingly follow the same playbook: exploit human weaknesses, adapt after disruption, hide behind new identities and move faster than defenders.
AI security spendingAgentic AI
AI Is Moving Faster Than Enterprise Security. Organizations Are Spending to Catch Up
AI adoption is accelerating faster than enterprise security controls can keep pace, with 94% of organizations increasing AI risk management spending as agentic AI, shadow AI, policy violations and security blind spots expand the attack surface.
AI GovernanceAgentic AIIdentity Security
Agentic AI Is Outrunning Enterprise Identity Governance
AI agents can co-opt human credentials and operate at machine speed, but most enterprises lack the identity frameworks to detect, contain, or audit what they're actually doing.
Podcasts & Video
See all
Podcast
The Wild West of Deploying Agents with Nadav Cornberg
Podcast
'Energized Cybersecurity Culture' Book Review with Michael Farnum
Podcast
CYBR.SEC.Careers with Sheridan Skurupey-McDonald & James “JB” Bryant
Video
Vendor Breaches, Shared Responsibility, and the Contract Clauses Security Teams Should Care About - Haylie Treas
Video
The 5-step Purple Team Blueprint - Ross Burke
Video
Your AI Isn't the Risk. What It Does Next Is - Bashyam Anant
Video