Visualização de leitura

Cyber Risk Assumptions Are Becoming Obsolete Due to AI, Warn Five Eyes

AI Cyber Risk

AI Cyber Risk is evolving faster than many organizations can adapt, prompting a joint warning from the Five Eyes cyber security agencies. The agencies have called on business leaders, executives, and boards to act now, warning that advances in artificial intelligence are rapidly transforming the cyber threat landscape and shortening the time available to respond to emerging risks. In a coordinated statement, the leaders of the Five Eyes cyber security partnership said that while AI has the potential to improve defensive capabilities, it is also accelerating the speed, scale, and sophistication of cyber attacks. They cautioned that developments in Frontier AI are expected to exceed current industry expectations and could fundamentally change both offensive and defensive cyber operations within months rather than years.

AI Cyber Risk Demands Immediate Attention

The agencies stressed that AI is no longer a future consideration. According to the statement, AI is already lowering barriers for malicious actors and increasing the complexity of attacks. At the same time, it is reducing the gap between the discovery of vulnerabilities and their exploitation. As a result, organizations are being urged to assess their readiness, understand accountability structures, and strengthen foundational Cyber Security practices. The agencies emphasized that cyber resilience should be viewed as a critical component of business continuity, market confidence, and long-term organizational value. Leaders were encouraged to remain actively engaged as threats continue to evolve and new guidance emerges.

Frontier AI Is Accelerating Cyber Risk

The Five Eyes agencies warned that Frontier AI models are advancing faster than many organizations anticipate and could fundamentally reshape both cyber attacks and cyber defence within months. As these systems evolve, long-standing assumptions about cyber risk, threat detection, and vulnerability management may quickly become outdated.

The agencies cautioned that organizations that fail to adapt could face growing operational and strategic disadvantages. They emphasized that leaders should not view AI-driven cyber risk as a future challenge but as an immediate business concern requiring proactive planning, continuous assessment, and investment in cyber resilience. As AI capabilities expand, the agencies said organizations must remain prepared for rapidly changing threats and emerging vulnerabilities that may challenge traditional security approaches.

Cyber Resilience Is a Leadership Responsibility

The Five Eyes agencies stated that Cyber Resilience can no longer be treated solely as a technical issue. Instead, it should be considered a core Business Risk and a leadership responsibility. According to the statement, boards and executives must ensure that cyber resilience measures are not only implemented but are capable of functioning effectively during real-world incidents. The agencies noted that having security controls in place is not enough. Organizations must be confident those controls will perform under pressure. They also called on leaders to reassess long-standing trade-offs and adopt AI deliberately to strengthen defensive capabilities rather than focusing exclusively on operational efficiency.

Key Cyber Security Principles Highlighted

The agencies identified several principles organizations should adopt to address evolving AI Threats. They stated that Secure-by-Design and secure-by-default approaches should become standard practice rather than long-term goals. They also warned against relying on a single security solution, emphasizing that layered security remains essential. The statement further noted that as AI systems continue to evolve, organizations should expect new and previously unknown vulnerabilities to emerge, including Zero-Day Vulnerabilities. The agencies acknowledged that breaches are likely to occur and emphasized that preparedness is essential for containing incidents quickly and preventing them from escalating into larger operational and financial crises.

Practical Actions for Organizations

To reduce technical, operational, financial, and reputational exposure, the Five Eyes agencies outlined several practical actions. Organizations were advised to reduce their attack surface by limiting unnecessary system access and external connectivity. They were also encouraged to accelerate patching processes, warning that AI is shortening the time available between vulnerability disclosure and exploitation. The agencies highlighted unsupported legacy systems as strategic liabilities that can become easy targets for attackers. They also urged organizations to review and strengthen Identity and Access Controls, limit access to critical systems, enforce strong authentication, and regularly assess permissions. In addition, they recommended testing Incident Response plans, training teams, and preparing for breaches before they occur, with a focus on rapid containment and recovery.

Using AI to Strengthen Defense

The agencies noted that threat actors are already using AI to improve their capabilities and increase operational speed. As a result, defenders must also embrace AI-driven security tools. According to the statement, organizations that integrate AI into security operations can improve vulnerability detection, enhance software quality, identify unusual activity, and accelerate response efforts. The agencies emphasized that success will not depend on having the largest number of security tools. Instead, it will come from strong fundamentals, rapid action, and integrating cyber security into core business strategy.

Five Eyes Call for Collective Action

The Five Eyes leaders concluded that assumptions about cyber threats can become outdated within months due to the rapid pace of AI development. They urged organizations, including technology vendors, to act now, strengthen resilience, and remain prepared to adapt to changing threats. The agencies said leaders who move quickly can reduce exposure, strengthen resilience, and build trust among customers, partners, and investors. Those who delay, they warned, face growing and avoidable risk.

CISA Sets 72-Hour Patch Window for Federal Systems Facing Highest Cyber Risks

CISA vulnerability management directive

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced a new risk-based approach to vulnerability remediation, requiring federal civilian agencies to patch the most dangerous cyber vulnerabilities within 72 hours. Announced through Binding Operational Directive (BOD) 26-04, the new CISA vulnerability management directive replaces older remediation requirements with a framework designed to prioritize vulnerabilities that pose the greatest risk to government systems. The move comes as cybersecurity officials warn that artificial intelligence is helping threat actors identify and exploit security flaws faster than ever before. The directive aims to improve federal cyber resilience while ensuring agencies focus resources on threats most likely to be exploited.

New Risk-Based Model for Vulnerability Remediation

Under the directive, federal civilian agencies must evaluate vulnerabilities against four key criteria: According to CISA officials, vulnerabilities meeting three of these four conditions will face accelerated remediation deadlines. The strictest requirement applies to vulnerabilities that are actively exploited, can be automated, and affect internet-facing systems. Agencies must patch such vulnerabilities within 72 hours. In cases where exploitation could allow attackers to gain complete control of a system, agencies are also required to investigate whether a compromise has already occurred before applying security updates. For vulnerabilities that meet similar risk criteria but cannot be exploited automatically, agencies will have up to 14 days to complete remediation, provided attackers have not already achieved full system control. Federal agencies have been given 180 days to update their internal policies and adopt the new timelines.

CISA Vulnerability Management Directive Responds to AI-Driven Cyber Threats

A key driver behind the CISA vulnerability management directive is the growing concern that artificial intelligence is reducing the time between the release of a security patch and active exploitation by threat actors. CISA noted that cybercriminals are increasingly leveraging AI-powered tools to discover, analyze, and exploit vulnerabilities more efficiently. As a result, defenders have less time to respond once a vulnerability becomes public. The agency said the new framework reflects today's threat environment by considering not only the vulnerability itself but also attacker capabilities, exploitability, asset exposure, and the potential consequences of a successful attack. By combining these factors, CISA aims to help agencies make informed remediation decisions without overwhelming IT teams with unnecessary patching activities.

Directive Consolidates Existing Federal Requirements

The new directive harmonizes and updates requirements from two previous federal cybersecurity mandates:
  • BOD 19-02, which focused on vulnerability remediation for internet-accessible systems
  • BOD 22-01, which addressed risks associated with Known Exploited Vulnerabilities (KEV)
Rather than treating all vulnerabilities equally, the updated approach prioritizes those most likely to be weaponized by attackers. Acting CISA Director Nick Andersen said the directive is intended to help agencies focus on areas of highest risk while improving transparency, predictability, and resource planning for remediation efforts. The agency also encouraged organizations outside the federal government to adopt similar risk-based vulnerability management practices.

Agencies Must Check for Compromise Before Patching

One of the most significant additions in the new directive is the requirement for agencies to determine whether a vulnerable system has already been compromised before applying patches. CISA emphasized that installing a security update does not automatically remove attackers who may already have gained access to a network. As a result, agencies must assess when and how a compromise occurred and conduct appropriate investigations before remediation. This requirement reflects growing concerns that attackers often maintain persistence inside networks even after vulnerabilities are patched. The agency described compromise assessment as a critical component of effective cybersecurity risk management, particularly for vulnerabilities already known to be exploited in the wild.

Strengthening Federal Cybersecurity Readiness

The CISA vulnerability management directive aligns with broader U.S. government efforts to strengthen cybersecurity and secure federal information systems against increasingly sophisticated threats. The directive supports objectives outlined in the Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security, which calls for enhanced protection of civilian federal networks. As agencies implement the new requirements, CISA will monitor compliance, track progress, and provide support where necessary. The agency said the initiative represents an important step toward reducing cybersecurity risk across the federal enterprise while ensuring faster responses to the vulnerabilities most likely to be targeted by attackers.

Why AI-Native Cybersecurity Matters in the Age of Machine-Speed Threats

AI-Native Cybersecurity

By Sharat Sinha, CEO, Airtel Business The world has entered an era where more than 20 billion connected devices generate continuous digital exhaust. In this hyperconnected environment, AI-native cybersecurity is emerging as a critical foundation for protecting digital ecosystems. Every transaction, sensor read, API call and remote login now feeds a vast digital nervous system supporting economies, governments and critical infrastructure. As adversaries weaponize automation and AI to scale reconnaissance and exploitation, the cyberattack surface has expanded faster than traditional defenses can adapt. To safeguard national and enterprise resilience, security must evolve from fragmented, reactive controls to an AI-powered, human-led, always-on model delivered through a unified security platform.

Why Traditional Security Models Are Failing

Traditional architectures were designed for static networks and stable perimeters. They were never built for cloud-native workloads, edge computing, distributed workforces or API-centric digital ecosystems. Threat actors, however, now operate at machine speed—using AI to craft hyper-targeted phishing, escalate privileges autonomously and exploit misconfigurations in minutes. Meanwhile, breach discovery in many organizations still spans months. This widening gap between attacker speed and defender response highlights the need for continuous, intelligence-driven protection across network, identity, cloud and data layers.

AI-Native Cybersecurity Is Transforming Threat Detection

Within this shift, AI is emerging as a force multiplier—not a replacement—for human expertise. AI-driven analytics reduce false positives by up to 60%, correlate billions of signals across hybrid environments and detect weak anomalies invisible to manual analysis. Predictive models identify the vulnerabilities most likely to be weaponized, shrinking patch backlogs and strengthening overall resilience. Behavioral algorithms reinforce identity security by spotting subtle deviations that precede credential compromise. Even configuration hygiene improves as AI continuously validates cloud and network settings, eliminating exposures before they become incidents.

Unified Security Platforms Are Becoming the New Standard

AI is also enabling entirely new security capabilities. AI assistants for security leaders can summarize incidents, explain posture drift and produce board-ready insights in seconds. Autonomous SOC workflows now triage, enrich and contain threats across identity, endpoint and cloud layers. DevOps and cloud engineering teams use AI copilots to enforce guardrails and detect compliance drift—addressing misconfiguration risks that consistently rank among the top causes of breaches worldwide. These advancements reflect a broader global shift toward unified, AI-first cybersecurity platforms, where intelligence becomes the connective fabric linking telemetry from identity, network, cloud and data. Rather than operating dozens of siloed tools, organizations gain a single operating layer where detection, decision-making and response flow seamlessly. This consolidation accelerates containment, eliminates blind spots and frees security teams to focus on high-impact decisions. AI also strengthens data protection and regulatory alignment, including emerging requirements under India’s DPDP Act. Automated data classification, policy violation monitoring, retention enforcement and real-time breach alerts shift privacy oversight from periodic checks to continuous assurance. As India’s digital economy scales—driven by cloud adoption, fintech innovation and public digital infrastructure—AI-driven governance ensures both compliance and protection without increasing operational burden.

The Future of Cyber Resilience Will Be AI-Driven

The global direction is clear: AI-first, human-centered unified platforms are becoming the foundation of modern cyber resilience. With cyber incidents costing organizations millions of dollars and often causing systemic ripple effects, intelligent consolidation is no longer an efficiency strategy—it is a national and enterprise resilience strategy. Looking ahead, cybersecurity will be defined by how effectively organizations integrate AI across the entire lifecycle—posture management, threat prediction, protection, governance and automated response—while empowering human judgment at every critical decision point. In a world where threats operate at machine speed, always-on, AI-powered end-to-end protection is becoming the new standard. Organizations that embrace unified, AI-driven architectures will be best positioned to safeguard their people, data and services with confidence in an increasingly unpredictable digital landscape.

Before You Give AI Access to Your Code, Read This NCSC Warning

AI vulnerability management

The growing use of AI vulnerability management tools is changing how organisations identify security flaws, but the UK’s National Cyber Security Centre (NCSC) has warned that companies must not rush into adopting artificial intelligence without understanding the risks and operational challenges involved. In a detailed advisory, Ruth C, Head of Vulnerability Management Group at the NCSC, outlined 10 critical questions organisations should ask before using AI models to identify vulnerabilities in systems, software, and infrastructure. The guidance comes as businesses increasingly face pressure to adopt AI-driven security tools amid rising cyber threats and growing board-level focus on cyber resilience. The NCSC said that while AI can help improve security capabilities, simply finding vulnerabilities does not automatically make an organisation safer. In some cases, poor implementation of AI systems could even introduce new risks.

AI Vulnerability Management Should Start With Security Basics

A key message from the guidance is that organisations should prioritise cyber hygiene before investing heavily in AI vulnerability management solutions. According to the NCSC, unpatched systems and weak access controls remain far more dangerous than many advanced zero-day threats. The agency stressed that businesses should first understand their IT estate, software dependencies, and patching processes before relying on AI tools to uncover vulnerabilities. The advisory noted that thousands of vulnerabilities are reported every year, but only a relatively small percentage are actively exploited by attackers. The NCSC referenced data showing that more than 40,000 vulnerabilities were assigned CVEs in 2025, while only a fraction appeared in exploitation tracking systems such as the Known Exploited Vulnerabilities (KEV) catalog. This highlights why prioritised patching and effective remediation remain central to strong cybersecurity practices.

Organisations Must Prepare to Handle AI-Discovered Vulnerabilities

The NCSC warned that companies adopting AI vulnerability management tools need a mature process for handling the large number of findings these systems can generate. Security teams must be able to receive, prioritise, assess, and fix vulnerabilities without overwhelming operational teams. The guidance also emphasised the importance of addressing the root cause of vulnerabilities instead of only fixing individual flaws. The agency encouraged organisations to develop structured vulnerability management processes and maintain clear workflows for remediation and patch deployment.

Data Exposure and Infrastructure Risks Remain Major Concerns

The guidance also highlighted several risks associated with using AI models for vulnerability discovery. One of the biggest concerns is data exposure. Organisations may unknowingly provide AI platforms with access to sensitive code repositories, internal documentation, historic bug reports, or even production systems. The NCSC advised organisations to carefully assess how AI systems are deployed, what permissions they receive, and whether infrastructure is properly sandboxed. Businesses were also urged to review data retention policies, legal obligations, and jurisdictional issues before using hosted AI models. The advisory specifically asked organisations to consider questions such as whether the AI system can access production environments, how infrastructure will be secured, and whether the organisation understands the terms and conditions attached to AI services.

Human Expertise Still Critical in AI Vulnerability Management

While AI tools are becoming more capable, the NCSC made clear that they are not a replacement for cybersecurity professionals. The guidance stated that AI models should be viewed as tools that enhance the capabilities of security teams rather than replace them. Organisations were encouraged to invest in skilled cybersecurity staff who can validate AI-generated findings and interpret results accurately. The NCSC also recommended combining AI analysis with human verification to reduce false positives and improve the reliability of vulnerability assessments.

Long-Term Planning Needed as AI Models Evolve

The advisory stressed that organisations must prepare for rapid advancements in AI cybersecurity capabilities over the coming years. The NCSC believes frontier AI developments will play a major role in cyber resilience throughout the next decade. As new models emerge with evolving capabilities, organisations will need long-term strategies for managing resources, updating security workflows, supporting customers, and responding to vulnerabilities discovered in third-party products and services. The agency also emphasised the importance of strong asset management and dependency management practices, noting that organisations should have a clear understanding of all systems, libraries, and services operating within their environments. As interest in AI vulnerability management continues to grow, the NCSC’s guidance serves as a reminder that AI adoption in cybersecurity requires careful planning, governance, and operational maturity rather than quick deployment driven by hype alone.

U.S. Treasury Rolls Out Cybersecurity Information Sharing Initiative as Crypto Attacks Rise

digital asset cybersecurity initiative

The U.S. Department of the Treasury has unveiled a new digital asset cybersecurity initiative, aimed at strengthening defenses across the rapidly growing digital asset ecosystem. The initiative, announced by the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP), seeks to provide timely and actionable cyber threat intelligence to eligible U.S.-based digital asset firms. The move comes amid escalating cyberattacks targeting cryptocurrency platforms and follows recommendations outlined in the federal report “Strengthening American Leadership in Digital Financial Technology.”

Understanding About Digital Asset Cybersecurity Initiative 

At its core, the digital asset cybersecurity initiative will extend high-quality threat intelligence, previously reserved for traditional financial institutions—to digital asset companies and industry organizations. This includes insights that help firms detect, prevent, and respond to cyber threats affecting their platforms, customers, and infrastructure. “Digital asset firms are an increasingly important part of the U.S. financial sector, and their resilience is critical to the health of the broader system,” said Luke Pettit, Assistant Secretary for Financial Institutions. “By extending access to the same high-quality cybersecurity information used by traditional financial institutions, Treasury is helping promote a more secure and responsible digital asset ecosystem,” he added further. Eligible firms that meet Treasury criteria will receive this information at no cost, signaling a broader push to align cybersecurity standards across financial sectors.

Rising Threats Drive Urgency for Digital Asset Cybersecurity

The digital asset cybersecurity initiative comes at a time when cyber threats against cryptocurrency platforms are intensifying in both scale and complexity. Treasury officials emphasized that the initiative directly responds to this evolving threat landscape. “Cyber threats targeting digital asset platforms are growing in frequency and sophistication,” said Cory Wilson, Deputy Assistant Secretary for Cybersecurity. “This initiative expands access to actionable threat information that helps firms strengthen defenses, reduce risk, and respond more effectively to incidents.” Recent incidents emphasize the urgency. Alleged North Korean hackers reportedly stole $280 million from crypto platform Drift using a complex attack. Industry-wide losses exceeded $3.4 billion last year, with billions more lost annually over the past five years. In another case, Bitcoin ATM operator Bitcoin Depot disclosed a cyberattack on March 23 that resulted in losses exceeding $3.6 million. Additional breaches this year have reported losses of $26 million and $40 million, highlighting persistent vulnerabilities across the sector.

Government Push Amid Ongoing Crypto Crime

Despite increased enforcement efforts, cybercriminals and nation-state actors continue to exploit weaknesses in the digital asset ecosystem. U.S. authorities, including the Justice Department, have ramped up prosecutions and issued repeated warnings about infiltration attempts, particularly by North Korean threat groups. However, these measures have had limited success in curbing attacks. Threat actors continue to exploit coding flaws, social engineering tactics, and employee vulnerabilities to gain access to crypto platforms. The digital asset cybersecurity initiative is designed to complement these efforts by shifting focus toward proactive defense and real-time intelligence sharing rather than reactive enforcement alone.

Strengthening the Future of Digital Finance

Treasury officials also framed the digital asset cybersecurity initiative as a foundational step for the future of digital finance. As digital assets become more integrated into mainstream financial systems, cybersecurity is emerging as a critical pillar for sustainable growth. “This initiative reflects the principles of the GENIUS Act by promoting responsible innovation grounded in strong cybersecurity and operational resilience,” said Tyler Williams, Counselor to the Secretary for Digital Assets. “As digital assets become more integrated into the financial system, access to timely and actionable cyber threat information is essential to protecting consumers and safeguarding the stability of U.S. financial markets,” Williams added. The broader federal strategy emphasizes balancing innovation with security. The Treasury’s report highlights the need for regulatory clarity, risk mitigation, and public-private collaboration to support the long-term growth of digital assets while addressing illicit finance and cyber risks.

A Step Toward Industry-Wide Cyber Resilience

With cyberattacks continuing to disrupt the crypto ecosystem, the digital asset cybersecurity initiative represents a significant step toward improving industry-wide resilience. By bridging the gap between traditional financial cybersecurity frameworks and emerging digital asset platforms, the initiative aims to create a more secure and stable environment for innovation. As digital assets evolve from niche technology to a core component of global finance, initiatives like this may play a key role in shaping how the industry manages risk, and whether it can keep pace with increasing cyber threats.

CTG Launches Cyber Resilience Scoring Dashboard to Give CISOs a Single Risk Number

CTG, now operating under the Cegeka Group, is rolling out a cyber resilience scoring dashboard at RSAC 2026 that boils an organization’s security posture down to one number. The dashboard consolidates results from multiple security assessments into a single view. It produces an overall resilience score, domain-level maturity indicators, and progress tracking mapped to NIST,..

The post CTG Launches Cyber Resilience Scoring Dashboard to Give CISOs a Single Risk Number appeared first on Security Boulevard.

How CTEM is providing better cybersecurity resilience for organizations

Organizations today continuously face a number of fast-moving cyber threats that regularly challenge the effectiveness of their cybersecurity defenses. However, to keep pace, businesses need a proactive and adaptive approach to their security planning and execution.

Cyber threat exposure management (CTEM) is an effective way to achieve this goal. It provides organizations with a reliable framework for identifying, assessing and mitigating new cyber risks as they materialize.

The importance of developing cybersecurity resilience

Regardless of the industry, all organizations are subject to certain security risks. While various tools and solutions can help to reduce this risk, the only real way of maintaining a strong security posture is by developing a certain amount of cybersecurity resilience.

Cybersecurity resilience is the ability of a business to maintain its core operational state regardless of an attempted or even successful cyberattack. The key components of cybersecurity resilience include:

  • Proactive risk management: It’s important to be able to identify and mitigate any potential threats before they have the opportunity to exploit known vulnerabilities. This requires regular risk assessments and strict security policies.

  • Continuous monitoring and improvement: Monitoring systems and networks is critical to help identify suspicious network activity while informing the necessary stakeholders for mediation. Regularly reviewing logs and threat reports also allows organizations to improve their security efforts going forward.

  • Incident response and recovery: In the event of a successful breach, organizations must be prepared to handle all necessary protocols for threat containment while executing critical recovery efforts to minimize operational disruption.

  • Maintaining a progressive cybersecurity culture: While security tools and solutions are important, organizations looking to establish more cybersecurity resilience need to also build awareness with their employees on relevant threats and how they can help protect themselves and the business.

What is CTEM?

While establishing cybersecurity resilience on its own is important, the prevalence and severity of modern-day security threats mean organizations need to look for a more comprehensive approach to threat management.

CTEM relies on the use of automated routines spread across an organization’s entire infrastructure, designed to identify and assess any security gaps present. Unlike traditional vulnerability assessments, which are typically scheduled throughout the year, CTEM solutions enable real-time threat intelligence at all times.

When integrated across all of an organization’s IT assets, including on-premise and cloud networks, systems, applications and databases, CTEM solutions provide a much more proactive approach to strengthening an organization’s security posture.

Explore cyber threat management services

Key components of CTEM

CTEM frameworks operate by incorporating several key components across an organization’s entire infrastructure. These components include:

Threat intelligence

Leveraging real-time threat intelligence, CTEM references an organization’s location, industry type and digital structure to benchmark against similar organizations while recognizing and prioritizing likely threats. This helps businesses place their mitigation efforts in the right places while always being one step ahead of malicious attackers.

Vulnerability management

CTEM makes use of active vulnerability scanning and assessment tools to look for common vulnerabilities and exposures (CVEs) as well as misconfigurations in systems and networks that could lead to exploitation. Using automated routines, CTEM solutions will run continuous scans for these vulnerabilities and then prioritize them based on the most critical risks.

Security testing

Applying CTEM frameworks across an organization can often include making use of penetration testing services and establishing red teams to help simulate real-world attack scenarios. This helps organizations validate the effectiveness of their current cybersecurity solutions and helps to “stress-test” response capabilities.

Risk assessment

CTEM solutions apply various risk assessment methodologies to help evaluate the potential impact of discovered vulnerabilities. This includes considering various factors that can impact remediation efforts, including the types of assets at risk, how financially sensitive each asset is and the potential impact a successful breach could have on the long-term viability of an organization.

Breaking down the five stages of CTEM

CTEM deployments are an iterative process that involves continuous improvement and refinement. The five stages of CTEM include:

  1. Scoping: The initial stage of CTEM involves establishing certain boundaries within which the solution will operate. This requires organizations to identify the relevant systems, applications or key data the solution will actively monitor. Another element of this stage is to outline any specific goals or objectives that need to be achieved to ensure the solution is properly calibrated.

  2. Discovery: The discovery stage is when all digital assets are cataloged within the defined scope. While many assets may already be defined during initial scoping stages, the CTEM discovery process may also identify unknown assets, including SaaS solutions or other shadow IT elements that may have been missed. This stage is completed using a series of automated tools that scan and catalog new assets as they’re discovered.

  3. Prioritization: After all assets are properly cataloged, the next step is to assess and prioritize all risks associated with each of them. To achieve this, CTEM solutions will apply risk assessment protocols and active threat intelligence to determine the most critical risks.

  4. Validation: The validation stage makes sure that any identified vulnerabilities are legitimate and require an actual remediation process. This is designed to minimize or eliminate any false positives.

  5. Mobilization: The final stage of CTEM is mobilization, which is any action necessary to remediate vulnerabilities and mitigate risks. This can include coordinated efforts between security teams, IT operations and business stakeholders to ensure that vulnerabilities are addressed effectively.

Start implementing CTEM in your organization

Implementing CTEM is a crucial step towards improving an organization’s cybersecurity resilience. Here are some steps your organization can follow to start benefiting from CTEM integrations:

  1. Begin with a cybersecurity risk assessment: Take the time to conduct a comprehensive cybersecurity risk assessment with the help of a security services partner to identify any potential vulnerabilities in your organization.

  2. Embrace automation: Leveraging automation tools to streamline various aspects of your CTEM program is critical to enable real-time threat mitigation. This can help to reduce manual security efforts, improve the accuracy of risk remediation efforts and accelerate incident response times.

  3. Prioritize and validate: Prioritize any discovered vulnerabilities based on their potential impact on your organization and validate any potential attack vectors using techniques like penetration testing and red team simulations.

  4. Establish clear communication channels: It’s important to ensure that security information is shared effectively between different teams and stakeholders. Regardless of the type of CTEM solution your organization chooses to implement, establishing clear communication channels and protocols is essential to ensure that security information is disseminated effectively and acted on in a timely manner.

Keep your business ready

Implementing a CTEM program for your organization is a critical step for organizations considering today’s increasing cyber threats. By taking a proactive and continuous approach to your risk management strategy, you can significantly minimize your digital attack surface while achieving a more resilient cybersecurity posture.

The post How CTEM is providing better cybersecurity resilience for organizations appeared first on Security Intelligence.

Insights from CISA’s red team findings and the evolution of EDR

A recent CISA red team assessment of a United States critical infrastructure organization revealed systemic vulnerabilities in modern cybersecurity. Among the most pressing issues was a heavy reliance on endpoint detection and response (EDR) solutions, paired with a lack of network-level protections.

These findings underscore a familiar challenge: Why do organizations place so much trust in EDR alone, and what must change to address its shortcomings?

EDR’s double-edged sword

A cornerstone of cyber resilience strategy, EDR solutions are prized for their ability to monitor endpoints for malicious activity. But as the CISA report demonstrated, this reliance can become a liability when paired with inadequate network defenses. Here’s why:

  1. Tunnel vision on endpoints: EDR excels at identifying threats on individual devices but struggles with network-wide attacks. This leaves gaps when hackers exploit lateral movement or unusual data transfers — activities that often require network-level visibility to detect.
  2. Playing catch-up with threats: Traditional EDR tools depend on recognizing known indicators of compromise (IOCs). Advanced attackers can easily sidestep these tools by using novel techniques or blending in with legitimate activity.
  3. Blind spots in legacy systems: Legacy environments often go unnoticed by EDR, giving attackers free rein. In the CISA case, these systems allowed the red team to persist for months undetected.
  4. Overwhelmed defenders: Even when EDR generates alerts, security teams can become desensitized by a flood of notifications. As seen in the CISA assessment, critical warnings can slip through the cracks simply because defenders are too stretched to respond.

Common EDR pain points

The challenges highlighted in the CISA report mirror broader issues organizations face with EDR:

  • Detection without context: EDR tools often spot anomalies on endpoints but fail to connect the dots across the broader network. This lack of context can leave organizations blind to coordinated attacks.
  • Weak network integration: Without network-layer defenses, EDR struggles to identify malicious activities like unusual traffic patterns or data exfiltration, key tactics in advanced breaches.
  • Fragmented systems: Many organizations operate a patchwork of security tools, leaving critical gaps in coverage and making it harder to correlate data across endpoints, networks and cloud environments.
Explore threat detection and response services

The next evolution of EDR

Recognizing these shortcomings, cybersecurity is rapidly evolving beyond traditional EDR. Here’s how:

  1. Extended detection and response (XDR): XDR takes EDR to the next level by integrating endpoint, network and cloud data into a single platform. This broader scope allows organizations to see the full attack picture and respond more effectively.
  2. AI-driven insights: Cutting-edge EDR solutions now harness machine learning to detect subtle behavioral anomalies. By identifying deviations from normal activity, these tools catch threats even when no IOCs exist.
  3. Zero trust security: Zero trust architectures take endpoint defense a step further by ensuring no device or user is trusted by default. This integration of endpoint, identity and network security reduces dependence on EDR alone.
  4. Network visibility: Modern EDR tools are incorporating network traffic analysis to close the gaps identified in the CISA report. Monitoring traffic for anomalies, such as unusual data flows or external connections, bolsters defenses.
  5. Cloud-native solutions: As businesses embrace hybrid and cloud environments, EDR is evolving to provide seamless coverage across on-premises and cloud systems, addressing vulnerabilities in these critical areas.

Why do gaps persist?

Even with these advancements, many organizations struggle to fully address EDR’s limitations:

  • Resource strains: Small security teams often lack the bandwidth or expertise to implement and manage advanced solutions like XDR.
  • Budget constraints: Upgrading to integrated platforms or modernizing legacy systems can be costly.
  • Legacy challenges: Outdated environments remain vulnerable, acting as weak points that attackers can exploit.
  • Leadership missteps: As the CISA report pointed out, organizations sometimes deprioritize known vulnerabilities, leaving critical gaps unaddressed.

Building a more resilient future

The CISA red team findings are a wake-up call: Endpoint protection alone is no longer enough. To outsmart today’s sophisticated adversaries, organizations must adopt a layered defense strategy that integrates endpoint, network and cloud security. Solutions like XDR, zero trust principles and advanced behavioral analysis offer a path forward — but they require strategic investments and cultural shifts.

The post Insights from CISA’s red team findings and the evolution of EDR appeared first on Security Intelligence.

❌