Opinion

The CISO Role Is Broken. A New Title Won't Fix It.
Security leaders are being asked to run the whole company while also running its defences. One analyst says the org chart itself is the problem, not the people in it.

The Hidden Blindspot in Industrial Cyberattacks, and How Fake Devices Help Fill It
When hackers cross from a company's office network into the systems that run physical equipment, the trail goes cold. A maturing technique called cyber deception is starting to change that.

Five engineering habits that actually earn customer trust (and one that is quietly expanding the problem)
A privacy expert argues that compliance checkboxes are the easy part. The hard part is making sure a customer's choice is respected by every system that touches their data, even the ones nobody thinks about.

From Navy Sailor to Cybersecurity Chief: What Chris Wheeler Learned About Trust
Resilience CISO Chris Wheeler spent years in the Navy before moving into corporate security. His core lesson: the job is about earning trust, not just blocking attacks.

The Cybersecurity Bill Is Getting Too Big to Pay
A record $4.99 million average cost per breach, bloated tool stacks, and AI spending that outpaces its own savings are squeezing smaller businesses toward a breaking point.

Microsoft's PowerToys gets a Window Hopper: Alt+Tab, but only for the app you're using
The free Windows add-on now lets you flick between, say, five browser windows without wading through every other program open on your desktop.

Vulnerability management is drowning, and AI is being sold as the lifeboat
Security teams face more software flaws than they can patch, and vendors are pitching frontier AI as the fix. Lucy Green looks at what that actually means for the people running these programmes.

Hired to Build, Judged on the Breach That Never Happened
The skills that land someone a CISO job are rarely the ones the board scores them on a year later. That gap is quietly ending careers.

A Local Housing Authority Lost $1 Million to Email Fraud. Here Is What It Did Next.
A cybersecurity consultant's account of how a small government agency rebuilt its defences after criminals silently rerouted a wire transfer offers a practical road map for the thousands of local bodies running on skeleton IT crews.

CodeSecCon Brings Developers and Security Teams Together to Fix a Growing Blind Spot
A virtual conference focused on building safer software is drawing both coders and cybersecurity professionals to the same table, a pairing that rarely happens and badly needs to.

The Security Chiefs Who Finally Get to Tell Their Stories
A new documentary series lets cybersecurity leaders speak openly about hacks, burnout, and the human cost of keeping organisations safe. One episode alone involves $2 million stolen in a single phone call.

Your Team's Slack Messages During a Breach Could Cost More Than the Breach Itself
The panicked notes, the finger-pointing threads, the 'we knew about this' one-liners: what your staff types in the first 24 hours of a cyber incident can become courtroom evidence. Here is why that matters, and what to do before the subpoena arrives.

From Coder to Chief: How Standard Chartered's Security Boss Runs Defence at a Global Bank
The bank's top security executive explains how the job has changed, why security leaders must speak business not just tech, and what artificial intelligence means for both attackers and defenders.

The Tech Risks Hiding in Plain Sight on Every Company's Balance Sheet
Boards spend hours debating growth investments and almost no time on the quiet failures building underneath their feet. A closer look at why that imbalance is getting more dangerous.

From Gatekeeper to Growth Partner: What the Modern CSO Role Actually Looks Like
Security chiefs who keep talking about firewalls while their peers talk about revenue will keep getting ignored. Here is what the shift to business-first security leadership looks like in practice.