Cybersecurity News
Filters
Filtered by tag: risk management × Clear
No standing still: Zero Trust and cybersecurity
Cyberattacks are growing in speed and scale, costing businesses billions — recent incidents hit Jaguar Land Rover, WestJet, and Collins Aerospace. With public trust in data handling already low, companies need modernized security strategies. Zero Trust, built on "never trust, always verify," limits breach damage by confining access rather than relying on a single perimeter. Despite 96% of firms planning adoption, only 35% have implemented it, highlighting an urgent need for cross-industry action and consistent standards.
NIST Warns of Unique Security Risks in Multi-Cloud Environments
NIST has identified 23 unique security challenges posed by multi-cloud environments, where organizations use services from multiple cloud providers simultaneously. The risks include increased attack surfaces, complex identity management, inconsistent security policies, and difficulties in data governance. NIST is calling on the cybersecurity community to develop solutions to address these emerging threats as multi-cloud adoption continues to grow.
AI vendor dependency is becoming a resilience risk
Enterprises increasingly rely on a small number of AI vendors, creating significant resilience risks if those services fail, change pricing, or shut down. Experts warn that organizations must build governance frameworks and contingency strategies into AI planning from the start, rather than treating vendor dependency as an afterthought, to ensure long-term stability and operational continuity.
What Is a Website Attack Surface? A Beginner’s Guide to Reducing Risk
A website's attack surface includes all exposed components that could be exploited, such as login pages, contact forms, plugins, APIs, and forgotten staging sites or backups. Every added feature introduces new elements requiring management and potential vulnerability. Reducing risk involves identifying and minimizing these exposed components to limit opportunities for attackers to compromise the site.
AI needs rules and rails: Why governance must move beyond policy
As AI adoption accelerates, organizations need more than high-level policy — they need practical operational guardrails. Governance must translate abstract principles into enforceable standards covering data use, model accountability, and risk management. Without structured frameworks embedded into workflows, AI systems risk drifting from business objectives, creating compliance gaps and unintended consequences. Effective governance requires collaboration across technical, legal, and business teams.
SMEs aren’t too small to target for cybercriminals, they’re too exposed to ignore
Small and medium-sized businesses are increasingly targeted by cybercriminals due to weaker security defenses compared to larger organizations. Despite holding valuable data and often serving as supply chain entry points to bigger companies, many SMEs underestimate their risk exposure. Limited budgets and IT resources leave them vulnerable, making them attractive, easy targets rather than overlooked ones.
Cybersecurity needs a new KPI: it's time to measure our ability to adapt
Traditional cybersecurity metrics focus on response and recovery times, but these don't capture an organization's ability to learn and evolve after incidents. Experts argue that "adaptability" should become a core KPI — assessing how well teams update defenses, adjust processes, and apply lessons learned. Without measuring adaptation, organizations risk repeating vulnerabilities and falling behind increasingly sophisticated threats.
Securing adoption in the era of shadow AI
Organizations face growing risks from "shadow AI" — unauthorized AI tools employees use without IT oversight. To address this, companies should establish clear AI usage policies, create approved tool inventories, and implement monitoring. Balancing restriction with enablement is key; overly rigid controls drive workarounds. Security teams should engage employees, offer sanctioned alternatives, and build governance frameworks that allow responsible AI adoption at scale.
AI is making cyber threats faster, but trust will define which businesses survive
AI is accelerating cyber threats by surfacing forgotten digital vulnerabilities, giving attackers faster, more sophisticated tools. But beyond technical defenses, businesses face a deeper challenge: maintaining customer trust. Companies that respond transparently to breaches and demonstrate genuine commitment to data protection will be better positioned to survive than those relying on security measures alone.
Beware the token trap: Why saving on inference might put your ADLC at risk
Cutting inference costs by reducing tokens may seem efficient, but it can compromise AI-driven legal or compliance (ADLC) systems by stripping context needed for accurate outputs. Incomplete prompts increase error risk, potentially triggering regulatory violations or flawed decisions. Organizations must weigh token savings against the liability and operational costs of getting those outputs wrong.
Guide to Cybersecurity Budget Planning: How Much + How To | Huntress
Cybersecurity budget planning requires balancing protection needs against available resources. Businesses should assess risks, inventory assets, and prioritize spending on the most critical vulnerabilities. Common budget factors include tools, staff training, incident response, and compliance. Experts generally recommend allocating 10-15% of IT budgets to security, though this varies by industry, size, and risk exposure.
How to Create a Secure WordPress Staging Site: Beginner’s Guide
A WordPress staging site lets you test updates and changes before they go live, reducing the risk of breaking your site for visitors. However, staging sites copy sensitive data like admin accounts, customer records, and API keys, making security essential. The article guides beginners through creating a staging environment while ensuring it remains protected from exposure or exploitation.
Incident Response Plans: What to Include & Why They Matter
Organizations need incident response plans to minimize damage during cyberattacks. Key components include defined roles, communication protocols, detection and containment procedures, recovery steps, and post-incident analysis. Without a plan, response times slow and costs rise. Huntress helps by providing threat detection, guided remediation, and support that keeps businesses prepared before, during, and after security incidents.
