Also this week: HIPAA gets a cybersecurity shakeup, water utilities ditch email-and-phone-call defense, AI agents blow past identity controls, ransomware gets an AI upgrade, and Zero Trust is put to the test.
Featured
Employees aren’t necessarily ignoring AI governance when they use unapproved tools. Olivia Rose argues that conflicting messages, weak training and poor leadership are fueling shadow AI — and policies alone won’t fix it.
Former CIA, FBI, NSA and counterterrorism professionals at CruiseCon explain how intelligence tradecraft can make cyber defenders safer and more effective on and off the job.
Community Corner
See allFrom the CYBR.SEC.Community
CruiseCon AI & Privacy 2026: Ship's Log (A.K.A. Racing Isaias)
Bill Brenner posts regular updates from abourd the Mariner of the Seas cruise ship, where he is covering the proceedings during CruiseCon 2026
When the Platform Can Say No Without Saying Why
No externally governed inference or action provider should constitute an unmitigated single point of failure. Where provider behavior cannot be sufficiently characterized, treat the provider as an untrusted-availability dependency.
Nonprofit Cybersecurity Won’t Be Fixed With Another Checklist
Nonprofit cybersecurity doesn't improve with more checklists and portals. Real change starts with conversations that expose hidden risks, build trust and turn advice into action.
Stop Chasing Reach: Why Niche Influence Matters More in Cybersecurity
As a cybersecurity start-up or scale-up you don't need everybody to know your name. You need the right people to keep encountering it for the right reasons.
AI and Nonprofits: The Monster Under the Bed Uses the Same Old Doors
AI is changing the threat landscape. For nonprofits and other under-resourced organizations, panic is a bigger risk than the technology.
Latest Articles
See all
AI and ransomwareRansomware
AI Is Making Ransomware Easier to Scale — and Putting More Businesses at Risk
AI-powered ransomware attacks don't need sophisticated new techniques to create more risk. ThreatLocker CTO Michael Jenkins says automation lets cybercriminals target more businesses with less work, putting smaller organizations increasingly in the crosshairs.
zero trust
Zero Trust Doesn’t End at Login: Why Security Teams Must Control What Happens Next
Zero Trust security requires more than authentication and network access controls. ThreatLocker CTO Michael Jenkins explains why organizations must restrict what users, applications and processes can do after access is granted.
HIPAAcompliance
Senate Votes to End HIPAA’s Risk-Based Cybersecurity Era
The Health Care Cybersecurity and Resiliency Act would mandate MFA, encryption, and penetration testing — with a 36-month clock and no guaranteed funding for rural providers.
CruiseConAgentic AIAI and Privacy
CruiseCon AI/Privacy 2026: Full Coverage
Full CruiseCon 2026 coverage from aboard Mariner of the Seas, including AI security, privacy, insider threats, cyber risk and leadership.
AI GovernanceAgentic AI
Static Security Policies Can't Keep Up With Agentic AI
Agentic AI is exposing the limits of static security policies, excessive permissions and decades of technical debt. Enterprises need dynamic, runtime security controls that evaluate what AI agents are doing in real time. (Sponsored by Eve Security)
Agentic AIAI Governance
AI Agents Will Make Mistakes. Enterprise Security Must Be Ready When They Do
As enterprises deploy autonomous AI agents across critical systems, security teams must assume those agents will make mistakes. Agentic AI security requires continuous monitoring of behavior, intent and context — not blind trust in permissions. (Sponsored by Eve Security)
AI Data BreachesCruiseConAI Governance
AI-Powered Bank Attacks Exposed 67,000 People. Here Are 5 Things Security Teams Should Do Now
Suspected AI-assisted cyberattacks breached seven South Korean financial firms and exposed data on more than 67,000 people. The attacks reinforce warnings heard at CruiseCon AI and Privacy 2026 and point to five security actions organizations should take now.
Podcasts & Video
See all
Podcast
AI or Bust with Olivia Rose
Podcast
Something to do with Skyrim with Michael Jenkins
Podcast
The Wild West of Deploying Agents with Nadav Cornberg
Podcast
'Energized Cybersecurity Culture' Book Review with Michael Farnum
Podcast
CYBR.SEC.Careers with Sheridan Skurupey-McDonald & James “JB” Bryant
Video
Vendor Breaches, Shared Responsibility, and the Contract Clauses Security Teams Should Care About - Haylie Treas
Video