#policy
91 stories taggedpolicy · page 3 of 7.

The CISO of 2029: Risk Strategist, Boardroom Adviser, AI Overseer
Four senior security leaders explain how the job of protecting a company is shifting from a technical gatekeeper role to something closer to a business co-pilot, and what that means by the end of the decade.

When an AI Bot Causes Harm, Who Pays? Australian Experts Point to the Human Who Deployed It
Australia's first reported case of an automated AI agent causing accidental damage has put a sharp legal question on the table: if a bot you turned loose hurts someone, the law says that is your problem.

From Coder to Chief: How Standard Chartered's Security Boss Runs Defence at a Global Bank
The bank's top security executive explains how the job has changed, why security leaders must speak business rather than just tech, and what AI means for attackers and defenders alike.

The US Government's Software Flaw Database Is Drowning. Can AI Be the Lifeguard?
The agency that tracks every known software weakness in the world is asking the public whether artificial intelligence can help it cope with a 72% surge in reported flaws.

Your security team's growing backlog is not their fault
When every vulnerability alert lands on the security team's desk, the result is not accountability. It is a queue that never shrinks. A clearer split of duties is the only fix.

White House Enlists Security Firms to Combat International Cybercrime
The U.S. government plans to partner with security companies to target foreign cybercrime gangs, with contracts potentially requiring a $1 million bond forfeited for non-compliance.

America's Drinking Water Networks Are Getting a Long-Overdue Security Upgrade
A new Senate bill and a first-of-its-kind monitoring centre launched at DEF CON aim to plug gaping security holes in the water systems that supply millions of American homes.

New Zealand Sanctions 33 Russia-Linked Cyber Operators and Child Abduction Networks
Wellington's latest penalties name hackers and individuals tied to the forced removal of Ukrainian children, signalling that digital warfare now sits alongside human-rights abuses on the sanctions list.

Train companies target 'donutters' and last-minute digital ticket fraud
A double-tap on a smartphone is costing UK rail operators millions. Here's how the schemes work and what operators plan to do about it.

Cyber Operations Are Now a Core Part of Modern War, Says CrowdStrike Co-Founder
Dmitri Alperovitch argues that hacking campaigns no longer just support military conflicts, they signal them, shape them, and sometimes replace them.

Cybersecurity Groups Draft 'SAFE' Rules for Sharing AI Incident Data
A coalition of more than 120 companies, including Nvidia, Cisco and Amazon, is asking for public feedback on a proposed framework that would let organisations quietly report AI security failures and share what they learned with everyone else.

New York Hands $9 Million to 153 Water Utilities to Plug Cyber Gaps
The grants come as hackers step up attacks on water and wastewater systems across multiple US states. Here is what the money buys, and what it means for the people who drink the water.

Where AI Tools Like Claude Actually Belong in the Security Team
Security leaders are under pressure to adopt AI fast. Here is a plain-English look at what platforms like Claude, Codex and Cursor actually do inside a security operations centre, and the policy questions that follow.

Your Company's Vendor Problem Starts Before Anyone Calls Security
When businesses pick software first and ask security questions second, they hand criminals a head start. Here is why fixing that order matters, and what a grown-up process actually looks like.

When a Browser Stops Trusting a Certificate Authority, Nobody Owns the Aftermath
Google's 2024 decision to drop Entrust from Chrome was technically correct. What happened next exposed a gap that no government agency, standards body, or industry forum is built to fill.