Visualização normal

Antes de ontemStream principal
  • ✇Firewall Daily – The Cyber Express
  • Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration Samiksha Jain
    Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research. The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific. The two countries said the Aus
     

Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

Australia-India PACTS

Australia and India have unveiled the Australia-India PACTS, a new framework designed to deepen bilateral cooperation on cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence research.

The new partnership replaces the 2020 Framework Arrangement on Cyber and Cyber Enabled Critical Technology Cooperation and aims to strengthen national security, economic growth, and regional stability across the Indo-Pacific.

The two countries said the Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS) builds on two decades of research collaboration, operational coordination, and policy engagement. It also reflects their shared commitment to creating secure digital ecosystems while promoting trusted technology partnerships.

Australia-India PACTS Built on Five Pillars

The Australia-India PACTS is structured around five pillars that will drive collaboration between governments, research institutions, universities, and the private sector. The framework is intended to increase two-way investment in emerging technologies while supporting innovation and the commercialisation of research.

The first pillar focuses on supply chain resilience by strengthening trusted technology supply chains and promoting secure trade. Both countries will establish a bilateral mechanism for trusted vendor frameworks and work together to improve undersea cable security through the Quad Partnership for Cable Connectivity and Resilience. The partnership also includes collaboration on semiconductor research, critical minerals, and trade diversification.

Australia-India PACTS Expands Critical Technology Collaboration

The second pillar focuses on critical technologies, with Australia and India planning to strengthen cooperation in artificial intelligence, telecommunications, biotechnology, advanced materials, and space technologies.

The framework also supports the development of international standards for trustworthy AI and encourages collaboration between academic institutions and industry to promote responsible AI deployment. The two countries will also explore joint research, investment initiatives, and commercial partnerships in emerging technologies to strengthen long-term economic security across the Indo-Pacific.

Australia-India Prioritises Cybersecurity

A major component of the partnership is Australia India cybersecurity cooperation. Under the third pillar, both governments will work together to counter cybercrime, deter malicious cyber activity, strengthen cyber policy coordination, and protect critical infrastructure.

The framework proposes a consolidated bilateral mechanism for cyber and ICT cooperation, expanded engagement in United Nations cyber processes, increased trade opportunities for cybersecurity businesses, and practical workshops involving government agencies and industry stakeholders.

The partnership will also establish a cyber technology skills incubator to promote knowledge exchange and workforce development.

Australia-India PACTS Advances Digital Resilience

The fourth pillar focuses on digital resilience across the Indo-Pacific. Australia and India will collaborate on trusted Digital Public Infrastructure initiatives and promote scalable digital solutions that support connectivity, healthcare, education, renewable energy, critical infrastructure, and digital transformation.

The partnership also seeks to expand pilot projects that help countries across the region build adaptable digital ecosystems while strengthening regional capabilities.

Defence Research and Governance Framework

The fifth pillar strengthens defence science collaboration through joint research, innovation partnerships, and greater engagement between Australia's Defence Science and Technology Group and India's Defence Research and Development Organisation.

Areas of cooperation include maritime surveillance, advanced materials, defence innovation, and stronger links between defence start-up ecosystems.

The Australia-India PACTS will be jointly overseen by the Australian Deputy Secretary of the International and Security Group within the Department of the Prime Minister and Cabinet and the Indian Deputy National Security Advisor. Annual Senior Officials Meetings will review progress, assess emerging cyber and technology risks, and identify future collaborative projects under each pillar.

With the launch of Australia-India Partnership on Cyber, Critical Technologies and Supply Chains (PACTS), both countries have outlined a long-term roadmap that brings together cybersecurity, critical technologies, supply chain resilience, digital resilience, and defence cooperation under a single strategic framework aimed at strengthening security and technology collaboration across the Indo-Pacific.

  • ✇Firewall Daily – The Cyber Express
  • Cyber Risk Assumptions Are Becoming Obsolete Due to AI, Warn Five Eyes Editorial
    AI Cyber Risk is evolving faster than many organizations can adapt, prompting a joint warning from the Five Eyes cyber security agencies. The agencies have called on business leaders, executives, and boards to act now, warning that advances in artificial intelligence are rapidly transforming the cyber threat landscape and shortening the time available to respond to emerging risks. In a coordinated statement, the leaders of the Five Eyes cyber security partnership said that while AI has the po
     

Cyber Risk Assumptions Are Becoming Obsolete Due to AI, Warn Five Eyes

23 de Junho de 2026, 04:30

AI Cyber Risk

AI Cyber Risk is evolving faster than many organizations can adapt, prompting a joint warning from the Five Eyes cyber security agencies. The agencies have called on business leaders, executives, and boards to act now, warning that advances in artificial intelligence are rapidly transforming the cyber threat landscape and shortening the time available to respond to emerging risks. In a coordinated statement, the leaders of the Five Eyes cyber security partnership said that while AI has the potential to improve defensive capabilities, it is also accelerating the speed, scale, and sophistication of cyber attacks. They cautioned that developments in Frontier AI are expected to exceed current industry expectations and could fundamentally change both offensive and defensive cyber operations within months rather than years.

AI Cyber Risk Demands Immediate Attention

The agencies stressed that AI is no longer a future consideration. According to the statement, AI is already lowering barriers for malicious actors and increasing the complexity of attacks. At the same time, it is reducing the gap between the discovery of vulnerabilities and their exploitation. As a result, organizations are being urged to assess their readiness, understand accountability structures, and strengthen foundational Cyber Security practices. The agencies emphasized that cyber resilience should be viewed as a critical component of business continuity, market confidence, and long-term organizational value. Leaders were encouraged to remain actively engaged as threats continue to evolve and new guidance emerges.

Frontier AI Is Accelerating Cyber Risk

The Five Eyes agencies warned that Frontier AI models are advancing faster than many organizations anticipate and could fundamentally reshape both cyber attacks and cyber defence within months. As these systems evolve, long-standing assumptions about cyber risk, threat detection, and vulnerability management may quickly become outdated.

The agencies cautioned that organizations that fail to adapt could face growing operational and strategic disadvantages. They emphasized that leaders should not view AI-driven cyber risk as a future challenge but as an immediate business concern requiring proactive planning, continuous assessment, and investment in cyber resilience. As AI capabilities expand, the agencies said organizations must remain prepared for rapidly changing threats and emerging vulnerabilities that may challenge traditional security approaches.

Cyber Resilience Is a Leadership Responsibility

The Five Eyes agencies stated that Cyber Resilience can no longer be treated solely as a technical issue. Instead, it should be considered a core Business Risk and a leadership responsibility. According to the statement, boards and executives must ensure that cyber resilience measures are not only implemented but are capable of functioning effectively during real-world incidents. The agencies noted that having security controls in place is not enough. Organizations must be confident those controls will perform under pressure. They also called on leaders to reassess long-standing trade-offs and adopt AI deliberately to strengthen defensive capabilities rather than focusing exclusively on operational efficiency.

Key Cyber Security Principles Highlighted

The agencies identified several principles organizations should adopt to address evolving AI Threats. They stated that Secure-by-Design and secure-by-default approaches should become standard practice rather than long-term goals. They also warned against relying on a single security solution, emphasizing that layered security remains essential. The statement further noted that as AI systems continue to evolve, organizations should expect new and previously unknown vulnerabilities to emerge, including Zero-Day Vulnerabilities. The agencies acknowledged that breaches are likely to occur and emphasized that preparedness is essential for containing incidents quickly and preventing them from escalating into larger operational and financial crises.

Practical Actions for Organizations

To reduce technical, operational, financial, and reputational exposure, the Five Eyes agencies outlined several practical actions. Organizations were advised to reduce their attack surface by limiting unnecessary system access and external connectivity. They were also encouraged to accelerate patching processes, warning that AI is shortening the time available between vulnerability disclosure and exploitation. The agencies highlighted unsupported legacy systems as strategic liabilities that can become easy targets for attackers. They also urged organizations to review and strengthen Identity and Access Controls, limit access to critical systems, enforce strong authentication, and regularly assess permissions. In addition, they recommended testing Incident Response plans, training teams, and preparing for breaches before they occur, with a focus on rapid containment and recovery.

Using AI to Strengthen Defense

The agencies noted that threat actors are already using AI to improve their capabilities and increase operational speed. As a result, defenders must also embrace AI-driven security tools. According to the statement, organizations that integrate AI into security operations can improve vulnerability detection, enhance software quality, identify unusual activity, and accelerate response efforts. The agencies emphasized that success will not depend on having the largest number of security tools. Instead, it will come from strong fundamentals, rapid action, and integrating cyber security into core business strategy.

Five Eyes Call for Collective Action

The Five Eyes leaders concluded that assumptions about cyber threats can become outdated within months due to the rapid pace of AI development. They urged organizations, including technology vendors, to act now, strengthen resilience, and remain prepared to adapt to changing threats. The agencies said leaders who move quickly can reduce exposure, strengthen resilience, and build trust among customers, partners, and investors. Those who delay, they warned, face growing and avoidable risk.
  • ✇Firewall Daily – The Cyber Express
  • CISA Sets 72-Hour Patch Window for Federal Systems Facing Highest Cyber Risks Samiksha Jain
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced a new risk-based approach to vulnerability remediation, requiring federal civilian agencies to patch the most dangerous cyber vulnerabilities within 72 hours. Announced through Binding Operational Directive (BOD) 26-04, the new CISA vulnerability management directive replaces older remediation requirements with a framework designed to prioritize vulnerabilities that pose the greatest risk to government systems. Th
     

CISA Sets 72-Hour Patch Window for Federal Systems Facing Highest Cyber Risks

CISA vulnerability management directive

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced a new risk-based approach to vulnerability remediation, requiring federal civilian agencies to patch the most dangerous cyber vulnerabilities within 72 hours. Announced through Binding Operational Directive (BOD) 26-04, the new CISA vulnerability management directive replaces older remediation requirements with a framework designed to prioritize vulnerabilities that pose the greatest risk to government systems. The move comes as cybersecurity officials warn that artificial intelligence is helping threat actors identify and exploit security flaws faster than ever before. The directive aims to improve federal cyber resilience while ensuring agencies focus resources on threats most likely to be exploited.

New Risk-Based Model for Vulnerability Remediation

Under the directive, federal civilian agencies must evaluate vulnerabilities against four key criteria: According to CISA officials, vulnerabilities meeting three of these four conditions will face accelerated remediation deadlines. The strictest requirement applies to vulnerabilities that are actively exploited, can be automated, and affect internet-facing systems. Agencies must patch such vulnerabilities within 72 hours. In cases where exploitation could allow attackers to gain complete control of a system, agencies are also required to investigate whether a compromise has already occurred before applying security updates. For vulnerabilities that meet similar risk criteria but cannot be exploited automatically, agencies will have up to 14 days to complete remediation, provided attackers have not already achieved full system control. Federal agencies have been given 180 days to update their internal policies and adopt the new timelines.

CISA Vulnerability Management Directive Responds to AI-Driven Cyber Threats

A key driver behind the CISA vulnerability management directive is the growing concern that artificial intelligence is reducing the time between the release of a security patch and active exploitation by threat actors. CISA noted that cybercriminals are increasingly leveraging AI-powered tools to discover, analyze, and exploit vulnerabilities more efficiently. As a result, defenders have less time to respond once a vulnerability becomes public. The agency said the new framework reflects today's threat environment by considering not only the vulnerability itself but also attacker capabilities, exploitability, asset exposure, and the potential consequences of a successful attack. By combining these factors, CISA aims to help agencies make informed remediation decisions without overwhelming IT teams with unnecessary patching activities.

Directive Consolidates Existing Federal Requirements

The new directive harmonizes and updates requirements from two previous federal cybersecurity mandates:
  • BOD 19-02, which focused on vulnerability remediation for internet-accessible systems
  • BOD 22-01, which addressed risks associated with Known Exploited Vulnerabilities (KEV)
Rather than treating all vulnerabilities equally, the updated approach prioritizes those most likely to be weaponized by attackers. Acting CISA Director Nick Andersen said the directive is intended to help agencies focus on areas of highest risk while improving transparency, predictability, and resource planning for remediation efforts. The agency also encouraged organizations outside the federal government to adopt similar risk-based vulnerability management practices.

Agencies Must Check for Compromise Before Patching

One of the most significant additions in the new directive is the requirement for agencies to determine whether a vulnerable system has already been compromised before applying patches. CISA emphasized that installing a security update does not automatically remove attackers who may already have gained access to a network. As a result, agencies must assess when and how a compromise occurred and conduct appropriate investigations before remediation. This requirement reflects growing concerns that attackers often maintain persistence inside networks even after vulnerabilities are patched. The agency described compromise assessment as a critical component of effective cybersecurity risk management, particularly for vulnerabilities already known to be exploited in the wild.

Strengthening Federal Cybersecurity Readiness

The CISA vulnerability management directive aligns with broader U.S. government efforts to strengthen cybersecurity and secure federal information systems against increasingly sophisticated threats. The directive supports objectives outlined in the Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security, which calls for enhanced protection of civilian federal networks. As agencies implement the new requirements, CISA will monitor compliance, track progress, and provide support where necessary. The agency said the initiative represents an important step toward reducing cybersecurity risk across the federal enterprise while ensuring faster responses to the vulnerabilities most likely to be targeted by attackers.
  • ✇Firewall Daily – The Cyber Express
  • Why AI-Native Cybersecurity Matters in the Age of Machine-Speed Threats Editorial
    By Sharat Sinha, CEO, Airtel Business The world has entered an era where more than 20 billion connected devices generate continuous digital exhaust. In this hyperconnected environment, AI-native cybersecurity is emerging as a critical foundation for protecting digital ecosystems. Every transaction, sensor read, API call and remote login now feeds a vast digital nervous system supporting economies, governments and critical infrastructure. As adversaries weaponize automation and AI to scale
     

Why AI-Native Cybersecurity Matters in the Age of Machine-Speed Threats

26 de Maio de 2026, 07:11

AI-Native Cybersecurity

By Sharat Sinha, CEO, Airtel Business The world has entered an era where more than 20 billion connected devices generate continuous digital exhaust. In this hyperconnected environment, AI-native cybersecurity is emerging as a critical foundation for protecting digital ecosystems. Every transaction, sensor read, API call and remote login now feeds a vast digital nervous system supporting economies, governments and critical infrastructure. As adversaries weaponize automation and AI to scale reconnaissance and exploitation, the cyberattack surface has expanded faster than traditional defenses can adapt. To safeguard national and enterprise resilience, security must evolve from fragmented, reactive controls to an AI-powered, human-led, always-on model delivered through a unified security platform.

Why Traditional Security Models Are Failing

Traditional architectures were designed for static networks and stable perimeters. They were never built for cloud-native workloads, edge computing, distributed workforces or API-centric digital ecosystems. Threat actors, however, now operate at machine speed—using AI to craft hyper-targeted phishing, escalate privileges autonomously and exploit misconfigurations in minutes. Meanwhile, breach discovery in many organizations still spans months. This widening gap between attacker speed and defender response highlights the need for continuous, intelligence-driven protection across network, identity, cloud and data layers.

AI-Native Cybersecurity Is Transforming Threat Detection

Within this shift, AI is emerging as a force multiplier—not a replacement—for human expertise. AI-driven analytics reduce false positives by up to 60%, correlate billions of signals across hybrid environments and detect weak anomalies invisible to manual analysis. Predictive models identify the vulnerabilities most likely to be weaponized, shrinking patch backlogs and strengthening overall resilience. Behavioral algorithms reinforce identity security by spotting subtle deviations that precede credential compromise. Even configuration hygiene improves as AI continuously validates cloud and network settings, eliminating exposures before they become incidents.

Unified Security Platforms Are Becoming the New Standard

AI is also enabling entirely new security capabilities. AI assistants for security leaders can summarize incidents, explain posture drift and produce board-ready insights in seconds. Autonomous SOC workflows now triage, enrich and contain threats across identity, endpoint and cloud layers. DevOps and cloud engineering teams use AI copilots to enforce guardrails and detect compliance drift—addressing misconfiguration risks that consistently rank among the top causes of breaches worldwide. These advancements reflect a broader global shift toward unified, AI-first cybersecurity platforms, where intelligence becomes the connective fabric linking telemetry from identity, network, cloud and data. Rather than operating dozens of siloed tools, organizations gain a single operating layer where detection, decision-making and response flow seamlessly. This consolidation accelerates containment, eliminates blind spots and frees security teams to focus on high-impact decisions. AI also strengthens data protection and regulatory alignment, including emerging requirements under India’s DPDP Act. Automated data classification, policy violation monitoring, retention enforcement and real-time breach alerts shift privacy oversight from periodic checks to continuous assurance. As India’s digital economy scales—driven by cloud adoption, fintech innovation and public digital infrastructure—AI-driven governance ensures both compliance and protection without increasing operational burden.

The Future of Cyber Resilience Will Be AI-Driven

The global direction is clear: AI-first, human-centered unified platforms are becoming the foundation of modern cyber resilience. With cyber incidents costing organizations millions of dollars and often causing systemic ripple effects, intelligent consolidation is no longer an efficiency strategy—it is a national and enterprise resilience strategy. Looking ahead, cybersecurity will be defined by how effectively organizations integrate AI across the entire lifecycle—posture management, threat prediction, protection, governance and automated response—while empowering human judgment at every critical decision point. In a world where threats operate at machine speed, always-on, AI-powered end-to-end protection is becoming the new standard. Organizations that embrace unified, AI-driven architectures will be best positioned to safeguard their people, data and services with confidence in an increasingly unpredictable digital landscape.
  • ✇Firewall Daily – The Cyber Express
  • Before You Give AI Access to Your Code, Read This NCSC Warning Samiksha Jain
    The growing use of AI vulnerability management tools is changing how organisations identify security flaws, but the UK’s National Cyber Security Centre (NCSC) has warned that companies must not rush into adopting artificial intelligence without understanding the risks and operational challenges involved. In a detailed advisory, Ruth C, Head of Vulnerability Management Group at the NCSC, outlined 10 critical questions organisations should ask before using AI models to identify vulnerabilities
     

Before You Give AI Access to Your Code, Read This NCSC Warning

AI vulnerability management

The growing use of AI vulnerability management tools is changing how organisations identify security flaws, but the UK’s National Cyber Security Centre (NCSC) has warned that companies must not rush into adopting artificial intelligence without understanding the risks and operational challenges involved. In a detailed advisory, Ruth C, Head of Vulnerability Management Group at the NCSC, outlined 10 critical questions organisations should ask before using AI models to identify vulnerabilities in systems, software, and infrastructure. The guidance comes as businesses increasingly face pressure to adopt AI-driven security tools amid rising cyber threats and growing board-level focus on cyber resilience. The NCSC said that while AI can help improve security capabilities, simply finding vulnerabilities does not automatically make an organisation safer. In some cases, poor implementation of AI systems could even introduce new risks.

AI Vulnerability Management Should Start With Security Basics

A key message from the guidance is that organisations should prioritise cyber hygiene before investing heavily in AI vulnerability management solutions. According to the NCSC, unpatched systems and weak access controls remain far more dangerous than many advanced zero-day threats. The agency stressed that businesses should first understand their IT estate, software dependencies, and patching processes before relying on AI tools to uncover vulnerabilities. The advisory noted that thousands of vulnerabilities are reported every year, but only a relatively small percentage are actively exploited by attackers. The NCSC referenced data showing that more than 40,000 vulnerabilities were assigned CVEs in 2025, while only a fraction appeared in exploitation tracking systems such as the Known Exploited Vulnerabilities (KEV) catalog. This highlights why prioritised patching and effective remediation remain central to strong cybersecurity practices.

Organisations Must Prepare to Handle AI-Discovered Vulnerabilities

The NCSC warned that companies adopting AI vulnerability management tools need a mature process for handling the large number of findings these systems can generate. Security teams must be able to receive, prioritise, assess, and fix vulnerabilities without overwhelming operational teams. The guidance also emphasised the importance of addressing the root cause of vulnerabilities instead of only fixing individual flaws. The agency encouraged organisations to develop structured vulnerability management processes and maintain clear workflows for remediation and patch deployment.

Data Exposure and Infrastructure Risks Remain Major Concerns

The guidance also highlighted several risks associated with using AI models for vulnerability discovery. One of the biggest concerns is data exposure. Organisations may unknowingly provide AI platforms with access to sensitive code repositories, internal documentation, historic bug reports, or even production systems. The NCSC advised organisations to carefully assess how AI systems are deployed, what permissions they receive, and whether infrastructure is properly sandboxed. Businesses were also urged to review data retention policies, legal obligations, and jurisdictional issues before using hosted AI models. The advisory specifically asked organisations to consider questions such as whether the AI system can access production environments, how infrastructure will be secured, and whether the organisation understands the terms and conditions attached to AI services.

Human Expertise Still Critical in AI Vulnerability Management

While AI tools are becoming more capable, the NCSC made clear that they are not a replacement for cybersecurity professionals. The guidance stated that AI models should be viewed as tools that enhance the capabilities of security teams rather than replace them. Organisations were encouraged to invest in skilled cybersecurity staff who can validate AI-generated findings and interpret results accurately. The NCSC also recommended combining AI analysis with human verification to reduce false positives and improve the reliability of vulnerability assessments.

Long-Term Planning Needed as AI Models Evolve

The advisory stressed that organisations must prepare for rapid advancements in AI cybersecurity capabilities over the coming years. The NCSC believes frontier AI developments will play a major role in cyber resilience throughout the next decade. As new models emerge with evolving capabilities, organisations will need long-term strategies for managing resources, updating security workflows, supporting customers, and responding to vulnerabilities discovered in third-party products and services. The agency also emphasised the importance of strong asset management and dependency management practices, noting that organisations should have a clear understanding of all systems, libraries, and services operating within their environments. As interest in AI vulnerability management continues to grow, the NCSC’s guidance serves as a reminder that AI adoption in cybersecurity requires careful planning, governance, and operational maturity rather than quick deployment driven by hype alone.

CISA Launches CI Fortify to Defend Critical Infrastructure From Nation-State Cyber Threats

CI Fortify

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has launched a new initiative called “CI Fortify” aimed at helping critical infrastructure operators prepare for disruptive cyberattacks linked to geopolitical conflicts. The initiative comes amid growing concerns over nation-state cyber threats targeting operational technology (OT) systems that support essential services across the United States. The CI Fortify initiative focuses on improving critical infrastructure resilience through two key objectives: isolation and recovery. CISA said the effort is designed to help operators maintain essential operations even if adversaries compromise telecommunications networks, internet services, or industrial control systems. According to the agency, nation-state actors are no longer limiting their activities to espionage. Instead, threat groups have increasingly been pre-positioning themselves inside critical infrastructure environments to potentially disrupt or destroy systems during future geopolitical conflicts.

CI Fortify Initiative Focuses on Isolation and Recovery

Under the CI Fortify initiative, CISA is urging critical infrastructure organizations to assume that third-party communications and service providers may become unreliable during a crisis. Operators are also being asked to plan under the assumption that threat actors may already have some level of access to OT networks. Nick Andersen, Acting Director at CISA, emphasized the need for organizations to prepare for worst-case operational scenarios. “In a geopolitical crisis, the critical infrastructure organizations Americans rely on must be able to continue delivering, at a minimum, crucial services,” Andersen said. “They must be able to isolate vital systems from harm, continue operating in that isolated state, and quickly recover any systems that an adversary may successfully compromise.” The isolation strategy outlined under CI Fortify involves proactively disconnecting operational technology systems from external business networks and third-party connections. CISA said this approach is intended to prevent cyber impacts from spreading into OT environments while allowing organizations to continue delivering essential services in a degraded communications environment. The agency advised operators to identify critical customers, including military infrastructure and other lifeline services, and determine the minimum operational capabilities needed to support them during emergencies. CISA also recommended updating engineering processes and business continuity plans to support safe operations for extended periods while systems remain isolated.

Recovery Planning Central to Critical Infrastructure Resilience

Alongside isolation, the CI Fortify initiative places strong emphasis on recovery planning. CISA urged operators to maintain updated system documentation, create secure backups of critical files, and regularly practice system replacement or manual operational transitions. The agency noted that organizations should also identify communications dependencies that could complicate recovery efforts, such as licensing servers, remote vendor access, or upstream network connections. CISA encouraged operators to work closely with managed service providers, system integrators, and vendors to understand potential failure points and establish alternative recovery pathways. The initiative also highlights broader benefits of emergency planning beyond cybersecurity incidents. According to CISA, the same planning processes can help organizations maintain operations during weather-related disruptions, equipment failures, and safety emergencies. The agency said isolation planning can help cut off command-and-control access to compromised systems, while strong recovery preparation can reduce incident response costs and shorten recovery timelines.

Security Vendors and Service Providers Asked to Support CI Fortify

The CI Fortify initiative extends beyond infrastructure operators and calls on cybersecurity vendors, industrial automation suppliers, and managed service providers to support resilience planning efforts. Industrial control system vendors are being encouraged to identify barriers that could interfere with isolation and recovery procedures, including licensing restrictions and server dependency issues. Managed service providers and integrators are expected to assist organizations in engineering updates, local backup collection, and recovery documentation planning. Meanwhile, security vendors are being asked to support threat monitoring and provide intelligence if nation-state actors shift from espionage-focused activity to destructive cyber operations. CISA also requested vendors share information related to tactics that could undermine recovery or bypass isolation protections, including malicious firmware updates and vulnerabilities affecting software-based data diodes.

Volt Typhoon Cyberattacks Continue to Shape U.S. Cybersecurity Strategy

The launch of CI Fortify is closely tied to ongoing concerns surrounding the Volt Typhoon cyberattacks, which U.S. officials have linked to Chinese state-sponsored threat actors. CISA’s initiative specifically references the Volt Typhoon campaign as an example of how adversaries have attempted to establish long-term access inside U.S. critical infrastructure systems to potentially support disruptive actions during military conflicts. The Volt Typhoon operation first became public in 2023, when U.S. authorities revealed that Chinese hackers had infiltrated multiple sectors of American critical infrastructure. Former CISA Director Jen Easterly stated in 2024 that the agency had identified and removed Volt Typhoon intrusions across several sectors. She later reiterated in 2025 that efforts continued to focus on identifying and evicting Chinese cyber actors from critical infrastructure environments. Despite these operations, cybersecurity researchers and some government officials have warned that Chinese threat actors may still retain access to portions of critical infrastructure networks. Several experts have argued that nation-state groups remain deeply embedded in certain environments despite years of remediation efforts. With the CI Fortify initiative, CISA appears to be shifting focus toward operational resilience, recognizing that prevention alone may not be sufficient against sophisticated nation-state cyber threats targeting U.S. critical infrastructure.

U.S. Treasury Rolls Out Cybersecurity Information Sharing Initiative as Crypto Attacks Rise

digital asset cybersecurity initiative

The U.S. Department of the Treasury has unveiled a new digital asset cybersecurity initiative, aimed at strengthening defenses across the rapidly growing digital asset ecosystem. The initiative, announced by the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP), seeks to provide timely and actionable cyber threat intelligence to eligible U.S.-based digital asset firms. The move comes amid escalating cyberattacks targeting cryptocurrency platforms and follows recommendations outlined in the federal report “Strengthening American Leadership in Digital Financial Technology.”

Understanding About Digital Asset Cybersecurity Initiative 

At its core, the digital asset cybersecurity initiative will extend high-quality threat intelligence, previously reserved for traditional financial institutions—to digital asset companies and industry organizations. This includes insights that help firms detect, prevent, and respond to cyber threats affecting their platforms, customers, and infrastructure. “Digital asset firms are an increasingly important part of the U.S. financial sector, and their resilience is critical to the health of the broader system,” said Luke Pettit, Assistant Secretary for Financial Institutions. “By extending access to the same high-quality cybersecurity information used by traditional financial institutions, Treasury is helping promote a more secure and responsible digital asset ecosystem,” he added further. Eligible firms that meet Treasury criteria will receive this information at no cost, signaling a broader push to align cybersecurity standards across financial sectors.

Rising Threats Drive Urgency for Digital Asset Cybersecurity

The digital asset cybersecurity initiative comes at a time when cyber threats against cryptocurrency platforms are intensifying in both scale and complexity. Treasury officials emphasized that the initiative directly responds to this evolving threat landscape. “Cyber threats targeting digital asset platforms are growing in frequency and sophistication,” said Cory Wilson, Deputy Assistant Secretary for Cybersecurity. “This initiative expands access to actionable threat information that helps firms strengthen defenses, reduce risk, and respond more effectively to incidents.” Recent incidents emphasize the urgency. Alleged North Korean hackers reportedly stole $280 million from crypto platform Drift using a complex attack. Industry-wide losses exceeded $3.4 billion last year, with billions more lost annually over the past five years. In another case, Bitcoin ATM operator Bitcoin Depot disclosed a cyberattack on March 23 that resulted in losses exceeding $3.6 million. Additional breaches this year have reported losses of $26 million and $40 million, highlighting persistent vulnerabilities across the sector.

Government Push Amid Ongoing Crypto Crime

Despite increased enforcement efforts, cybercriminals and nation-state actors continue to exploit weaknesses in the digital asset ecosystem. U.S. authorities, including the Justice Department, have ramped up prosecutions and issued repeated warnings about infiltration attempts, particularly by North Korean threat groups. However, these measures have had limited success in curbing attacks. Threat actors continue to exploit coding flaws, social engineering tactics, and employee vulnerabilities to gain access to crypto platforms. The digital asset cybersecurity initiative is designed to complement these efforts by shifting focus toward proactive defense and real-time intelligence sharing rather than reactive enforcement alone.

Strengthening the Future of Digital Finance

Treasury officials also framed the digital asset cybersecurity initiative as a foundational step for the future of digital finance. As digital assets become more integrated into mainstream financial systems, cybersecurity is emerging as a critical pillar for sustainable growth. “This initiative reflects the principles of the GENIUS Act by promoting responsible innovation grounded in strong cybersecurity and operational resilience,” said Tyler Williams, Counselor to the Secretary for Digital Assets. “As digital assets become more integrated into the financial system, access to timely and actionable cyber threat information is essential to protecting consumers and safeguarding the stability of U.S. financial markets,” Williams added. The broader federal strategy emphasizes balancing innovation with security. The Treasury’s report highlights the need for regulatory clarity, risk mitigation, and public-private collaboration to support the long-term growth of digital assets while addressing illicit finance and cyber risks.

A Step Toward Industry-Wide Cyber Resilience

With cyberattacks continuing to disrupt the crypto ecosystem, the digital asset cybersecurity initiative represents a significant step toward improving industry-wide resilience. By bridging the gap between traditional financial cybersecurity frameworks and emerging digital asset platforms, the initiative aims to create a more secure and stable environment for innovation. As digital assets evolve from niche technology to a core component of global finance, initiatives like this may play a key role in shaping how the industry manages risk, and whether it can keep pace with increasing cyber threats.
  • ✇Security Boulevard
  • CTG Launches Cyber Resilience Scoring Dashboard to Give CISOs a Single Risk Number Techstrong Editorial
    CTG, now operating under the Cegeka Group, is rolling out a cyber resilience scoring dashboard at RSAC 2026 that boils an organization’s security posture down to one number. The dashboard consolidates results from multiple security assessments into a single view. It produces an overall resilience score, domain-level maturity indicators, and progress tracking mapped to NIST,.. The post CTG Launches Cyber Resilience Scoring Dashboard to Give CISOs a Single Risk Number appeared first on Security Bo
     

CTG Launches Cyber Resilience Scoring Dashboard to Give CISOs a Single Risk Number

22 de Março de 2026, 22:35

CTG, now operating under the Cegeka Group, is rolling out a cyber resilience scoring dashboard at RSAC 2026 that boils an organization’s security posture down to one number. The dashboard consolidates results from multiple security assessments into a single view. It produces an overall resilience score, domain-level maturity indicators, and progress tracking mapped to NIST,..

The post CTG Launches Cyber Resilience Scoring Dashboard to Give CISOs a Single Risk Number appeared first on Security Boulevard.

  • ✇Security Boulevard
  • Rethinking Cyber Awareness: From Blame to Belonging  Dirk Schrader
    Stop treating employees like the "weakest link." Discover why traditional cybersecurity awareness training fails and how to build a culture of belonging through human-centered design, security guardrails, and collaborative resilience. The post Rethinking Cyber Awareness: From Blame to Belonging  appeared first on Security Boulevard.
     
  • ✇Security Boulevard
  • Threat Modeling with AI: A Developer-Driven Boon for Enterprise Security  Matias Madou
    For companies running a modern, adaptive and defense-centered security program, threat modeling is not a new concept. In fact, it’s one of the core tenets of preventative cybersecurity best practices. Being able to find vulnerabilities within software or a network, map them out and remediate them – before an attacker can successfully orchestrate a breach.. The post Threat Modeling with AI: A Developer-Driven Boon for Enterprise Security  appeared first on Security Boulevard.
     
  • ✇Security Boulevard
  • The Attack Chain Your AI System is Already Missing  Mayank Kumar
    As AI adoption accelerates, organizations must evolve their security strategies from prompt filtering to comprehensive behavioral monitoring. This shift is critical to safeguarding against adaptive threats and ensuring safe AI deployment in production environments. The post The Attack Chain Your AI System is Already Missing  appeared first on Security Boulevard.
     
  • ✇Security Boulevard
  • Will Your Organization Take the Quantum Leap in 2026? Read This First David McNeely
    Explore how organizations can prepare for the quantum age by developing quantum security intelligence, establishing governance plans, and prioritizing system updates. Learn strategies for building resilience without exorbitant investments as quantum computing technology advances The post Will Your Organization Take the Quantum Leap in 2026? Read This First appeared first on Security Boulevard.
     
  • ✇Security Intelligence
  • How CTEM is providing better cybersecurity resilience for organizations Josh Nadeau
    Organizations today continuously face a number of fast-moving cyber threats that regularly challenge the effectiveness of their cybersecurity defenses. However, to keep pace, businesses need a proactive and adaptive approach to their security planning and execution. Cyber threat exposure management (CTEM) is an effective way to achieve this goal. It provides organizations with a reliable framework for identifying, assessing and mitigating new cyber risks as they materialize. The importance of d
     

How CTEM is providing better cybersecurity resilience for organizations

13 de Janeiro de 2025, 14:00

Organizations today continuously face a number of fast-moving cyber threats that regularly challenge the effectiveness of their cybersecurity defenses. However, to keep pace, businesses need a proactive and adaptive approach to their security planning and execution.

Cyber threat exposure management (CTEM) is an effective way to achieve this goal. It provides organizations with a reliable framework for identifying, assessing and mitigating new cyber risks as they materialize.

The importance of developing cybersecurity resilience

Regardless of the industry, all organizations are subject to certain security risks. While various tools and solutions can help to reduce this risk, the only real way of maintaining a strong security posture is by developing a certain amount of cybersecurity resilience.

Cybersecurity resilience is the ability of a business to maintain its core operational state regardless of an attempted or even successful cyberattack. The key components of cybersecurity resilience include:

  • Proactive risk management: It’s important to be able to identify and mitigate any potential threats before they have the opportunity to exploit known vulnerabilities. This requires regular risk assessments and strict security policies.

  • Continuous monitoring and improvement: Monitoring systems and networks is critical to help identify suspicious network activity while informing the necessary stakeholders for mediation. Regularly reviewing logs and threat reports also allows organizations to improve their security efforts going forward.

  • Incident response and recovery: In the event of a successful breach, organizations must be prepared to handle all necessary protocols for threat containment while executing critical recovery efforts to minimize operational disruption.

  • Maintaining a progressive cybersecurity culture: While security tools and solutions are important, organizations looking to establish more cybersecurity resilience need to also build awareness with their employees on relevant threats and how they can help protect themselves and the business.

What is CTEM?

While establishing cybersecurity resilience on its own is important, the prevalence and severity of modern-day security threats mean organizations need to look for a more comprehensive approach to threat management.

CTEM relies on the use of automated routines spread across an organization’s entire infrastructure, designed to identify and assess any security gaps present. Unlike traditional vulnerability assessments, which are typically scheduled throughout the year, CTEM solutions enable real-time threat intelligence at all times.

When integrated across all of an organization’s IT assets, including on-premise and cloud networks, systems, applications and databases, CTEM solutions provide a much more proactive approach to strengthening an organization’s security posture.

Explore cyber threat management services

Key components of CTEM

CTEM frameworks operate by incorporating several key components across an organization’s entire infrastructure. These components include:

Threat intelligence

Leveraging real-time threat intelligence, CTEM references an organization’s location, industry type and digital structure to benchmark against similar organizations while recognizing and prioritizing likely threats. This helps businesses place their mitigation efforts in the right places while always being one step ahead of malicious attackers.

Vulnerability management

CTEM makes use of active vulnerability scanning and assessment tools to look for common vulnerabilities and exposures (CVEs) as well as misconfigurations in systems and networks that could lead to exploitation. Using automated routines, CTEM solutions will run continuous scans for these vulnerabilities and then prioritize them based on the most critical risks.

Security testing

Applying CTEM frameworks across an organization can often include making use of penetration testing services and establishing red teams to help simulate real-world attack scenarios. This helps organizations validate the effectiveness of their current cybersecurity solutions and helps to “stress-test” response capabilities.

Risk assessment

CTEM solutions apply various risk assessment methodologies to help evaluate the potential impact of discovered vulnerabilities. This includes considering various factors that can impact remediation efforts, including the types of assets at risk, how financially sensitive each asset is and the potential impact a successful breach could have on the long-term viability of an organization.

Breaking down the five stages of CTEM

CTEM deployments are an iterative process that involves continuous improvement and refinement. The five stages of CTEM include:

  1. Scoping: The initial stage of CTEM involves establishing certain boundaries within which the solution will operate. This requires organizations to identify the relevant systems, applications or key data the solution will actively monitor. Another element of this stage is to outline any specific goals or objectives that need to be achieved to ensure the solution is properly calibrated.

  2. Discovery: The discovery stage is when all digital assets are cataloged within the defined scope. While many assets may already be defined during initial scoping stages, the CTEM discovery process may also identify unknown assets, including SaaS solutions or other shadow IT elements that may have been missed. This stage is completed using a series of automated tools that scan and catalog new assets as they’re discovered.

  3. Prioritization: After all assets are properly cataloged, the next step is to assess and prioritize all risks associated with each of them. To achieve this, CTEM solutions will apply risk assessment protocols and active threat intelligence to determine the most critical risks.

  4. Validation: The validation stage makes sure that any identified vulnerabilities are legitimate and require an actual remediation process. This is designed to minimize or eliminate any false positives.

  5. Mobilization: The final stage of CTEM is mobilization, which is any action necessary to remediate vulnerabilities and mitigate risks. This can include coordinated efforts between security teams, IT operations and business stakeholders to ensure that vulnerabilities are addressed effectively.

Start implementing CTEM in your organization

Implementing CTEM is a crucial step towards improving an organization’s cybersecurity resilience. Here are some steps your organization can follow to start benefiting from CTEM integrations:

  1. Begin with a cybersecurity risk assessment: Take the time to conduct a comprehensive cybersecurity risk assessment with the help of a security services partner to identify any potential vulnerabilities in your organization.

  2. Embrace automation: Leveraging automation tools to streamline various aspects of your CTEM program is critical to enable real-time threat mitigation. This can help to reduce manual security efforts, improve the accuracy of risk remediation efforts and accelerate incident response times.

  3. Prioritize and validate: Prioritize any discovered vulnerabilities based on their potential impact on your organization and validate any potential attack vectors using techniques like penetration testing and red team simulations.

  4. Establish clear communication channels: It’s important to ensure that security information is shared effectively between different teams and stakeholders. Regardless of the type of CTEM solution your organization chooses to implement, establishing clear communication channels and protocols is essential to ensure that security information is disseminated effectively and acted on in a timely manner.

Keep your business ready

Implementing a CTEM program for your organization is a critical step for organizations considering today’s increasing cyber threats. By taking a proactive and continuous approach to your risk management strategy, you can significantly minimize your digital attack surface while achieving a more resilient cybersecurity posture.

The post How CTEM is providing better cybersecurity resilience for organizations appeared first on Security Intelligence.

  • ✇News – Security Intelligence
  • Insights from CISA’s red team findings and the evolution of EDR Jonathan Reed
    A recent CISA red team assessment of a United States critical infrastructure organization revealed systemic vulnerabilities in modern cybersecurity. Among the most pressing issues was a heavy reliance on endpoint detection and response (EDR) solutions, paired with a lack of network-level protections. These findings underscore a familiar challenge: Why do organizations place so much trust in EDR alone, and what must change to address its shortcomings? EDR’s double-edged sword A cornerstone of cy
     

Insights from CISA’s red team findings and the evolution of EDR

13 de Janeiro de 2025, 12:30

A recent CISA red team assessment of a United States critical infrastructure organization revealed systemic vulnerabilities in modern cybersecurity. Among the most pressing issues was a heavy reliance on endpoint detection and response (EDR) solutions, paired with a lack of network-level protections.

These findings underscore a familiar challenge: Why do organizations place so much trust in EDR alone, and what must change to address its shortcomings?

EDR’s double-edged sword

A cornerstone of cyber resilience strategy, EDR solutions are prized for their ability to monitor endpoints for malicious activity. But as the CISA report demonstrated, this reliance can become a liability when paired with inadequate network defenses. Here’s why:

  1. Tunnel vision on endpoints: EDR excels at identifying threats on individual devices but struggles with network-wide attacks. This leaves gaps when hackers exploit lateral movement or unusual data transfers — activities that often require network-level visibility to detect.
  2. Playing catch-up with threats: Traditional EDR tools depend on recognizing known indicators of compromise (IOCs). Advanced attackers can easily sidestep these tools by using novel techniques or blending in with legitimate activity.
  3. Blind spots in legacy systems: Legacy environments often go unnoticed by EDR, giving attackers free rein. In the CISA case, these systems allowed the red team to persist for months undetected.
  4. Overwhelmed defenders: Even when EDR generates alerts, security teams can become desensitized by a flood of notifications. As seen in the CISA assessment, critical warnings can slip through the cracks simply because defenders are too stretched to respond.

Common EDR pain points

The challenges highlighted in the CISA report mirror broader issues organizations face with EDR:

  • Detection without context: EDR tools often spot anomalies on endpoints but fail to connect the dots across the broader network. This lack of context can leave organizations blind to coordinated attacks.
  • Weak network integration: Without network-layer defenses, EDR struggles to identify malicious activities like unusual traffic patterns or data exfiltration, key tactics in advanced breaches.
  • Fragmented systems: Many organizations operate a patchwork of security tools, leaving critical gaps in coverage and making it harder to correlate data across endpoints, networks and cloud environments.
Explore threat detection and response services

The next evolution of EDR

Recognizing these shortcomings, cybersecurity is rapidly evolving beyond traditional EDR. Here’s how:

  1. Extended detection and response (XDR): XDR takes EDR to the next level by integrating endpoint, network and cloud data into a single platform. This broader scope allows organizations to see the full attack picture and respond more effectively.
  2. AI-driven insights: Cutting-edge EDR solutions now harness machine learning to detect subtle behavioral anomalies. By identifying deviations from normal activity, these tools catch threats even when no IOCs exist.
  3. Zero trust security: Zero trust architectures take endpoint defense a step further by ensuring no device or user is trusted by default. This integration of endpoint, identity and network security reduces dependence on EDR alone.
  4. Network visibility: Modern EDR tools are incorporating network traffic analysis to close the gaps identified in the CISA report. Monitoring traffic for anomalies, such as unusual data flows or external connections, bolsters defenses.
  5. Cloud-native solutions: As businesses embrace hybrid and cloud environments, EDR is evolving to provide seamless coverage across on-premises and cloud systems, addressing vulnerabilities in these critical areas.

Why do gaps persist?

Even with these advancements, many organizations struggle to fully address EDR’s limitations:

  • Resource strains: Small security teams often lack the bandwidth or expertise to implement and manage advanced solutions like XDR.
  • Budget constraints: Upgrading to integrated platforms or modernizing legacy systems can be costly.
  • Legacy challenges: Outdated environments remain vulnerable, acting as weak points that attackers can exploit.
  • Leadership missteps: As the CISA report pointed out, organizations sometimes deprioritize known vulnerabilities, leaving critical gaps unaddressed.

Building a more resilient future

The CISA red team findings are a wake-up call: Endpoint protection alone is no longer enough. To outsmart today’s sophisticated adversaries, organizations must adopt a layered defense strategy that integrates endpoint, network and cloud security. Solutions like XDR, zero trust principles and advanced behavioral analysis offer a path forward — but they require strategic investments and cultural shifts.

The post Insights from CISA’s red team findings and the evolution of EDR appeared first on Security Intelligence.

❌
❌