A key resource on artificial intelligence and cyber security, exploring how AI could transform the way digital assets can be better protected, as well as the emerging threats AI could bring and what they mean for our digital future
CISOs should treat secrets sprawl as a governance challenge. This means enforcing clear ownership, adopting short-lived credentials, and extending security controls across the entire software development lifecycle.
Enterprises deploying LLMs have spent the past two years building defenses around a reasonable assumption: malicious behavior leaves a trace in the input.
AI may be helpful for monitoring logs or indicators of compromise, such as file or IP hashes. However, skilled talent is still needed to combat the increased sophistication of AI-driven cyberattacks. Automation is not yet the singular answer, and neither is more theory-based coursework.
AI isn't taking over the SOC; it’s turning analysts into "managers of agents" who oversee automated investigations instead of getting buried in repetitive alert triage.
AI agents are great for speed, but they can go rogue; we need to treat them like high-risk employees by locking down their identities and securing their APIs.
AI-powered SOC tools promise automation, but most only speed up triage instead of reducing real workload. Tines shows how real gains come from end-to-end workflows that execute actions across systems, not just summarize alerts.
Enterprise AI adoption is creating new security risks as sensitive data moves into public models, unverified AI tools enter production, and autonomous agents gain access to enterprise systems.
Agentic-adopting CISOs are taking different paths to upskilling security operations staff to make the most of AI. Here are the tenets their training and transformation strategies hold in common.
Enterprise AI systems can be corrupted through data poisoned by accident, adversaries, or bad hygiene. Most organizations have no idea how large that attack surface is — or whether they’re already exposed.
Noma Security’s Spring 2026 research report, Lethal by Design, establishes the scope of this asymmetry with uncomfortable precision and proposes a governance framework built around what organizations can actually control.
Enterprises are not waiting for security teams to figure out agent governance before deploying agents. The deployments are happening now, running on IAM infrastructure that wasn’t designed for non-human identities, tokens that are too broad, permissions not scoped to individual tasks, and no visibility into what agents are doing across API chains.
Most of the conversation around AI in cybersecurity focuses on how attacks are getting faster and more sophisticated. That is true, but it misses a more immediate issue. Many security teams are still operating in ways that assume a much slower threat environment.
No one seems to know what AI agents are doing, even the companies that keep them. MIND research underscores that AI Agents have gotten away from security teams and getting a fix on their identities and activities requires operational and cultural shifts.
AI agents are reshaping enterprise security, demanding identity governance and privilege controls to mitigate risks from their dynamic, autonomous actions.
To get content containing either thought or leadership enter:
To get content containing both thought and leadership enter:
To get content containing the expression thought leadership enter:
You can enter several keywords and you can refine them whenever you want. Our suggestion engine uses more signals but entering a few keywords here will rapidly give you great content to curate.