Home Blog Page 2

3 Tools Every CISO Needs for Cyber Crisis Readiness in 2026

As cyber threats escalate in both volume and complexity, organizations are realizing a critical truth: prevention alone is no longer enough. Modern cybersecurity leadership demands something more, the ability to respond decisively when incidents occur.

Recent industry initiatives focused on cyber resilience highlight a growing shift toward executive preparedness and operational readiness, particularly through hands-on simulations and structured frameworks. Among these efforts, three practical outputs have emerged as essential tools for today’s CISOs, tools that move beyond theory and into real-world execution.

Here’s what every CISO should have in their cyber crisis playbook.

1. The Security Flow Turning Risk Into Actionable Priorities

A common challenge in cybersecurity programs is not the lack of data, it is the inability to prioritize effectively. With constant alerts and evolving threats, organizations need a way to separate signal from noise.

The concept of a Security Flow addresses this by introducing a structured risk matrix that prioritizes threats based on impact and likelihood.

For CISOs, this provides a clear framework to align cybersecurity investments with business risk, improve communication with executive leadership and the board, and enable faster decision making during high pressure incidents.

Rather than reacting to every alert equally, the Security Flow enables organizations to focus on what matters most, protecting the assets that would cause the greatest damage if compromised.

If your organization cannot clearly articulate which risks matter most, response efforts will always lag behind the threat landscape.

2. Security Design Concept Building Resilience Into Architecture

While many organizations invest heavily in tools, fewer establish a cohesive security design strategy that defines how systems should be protected at a structural level.

The Security Design Concept provides a framework for securing data flows across systems, defining trust boundaries, and implementing strong authentication and access controls.

This shifts cybersecurity from reactive defense to proactive architecture design.

For CISOs, the real value lies in integrating security early, embedding controls into digital transformation initiatives, reducing attack surfaces before vulnerabilities emerge, and ensuring consistency across hybrid and multi cloud environments.

Resilience is not bolted on, it is designed. Without a defined security architecture, even advanced tools can fail under pressure.

3. Security Skills Assessment and Recognition Measuring Readiness

Organizations often assume they are prepared for cyber incidents until a real crisis proves otherwise.

The Security Skills Assessment and Recognition approach enables organizations to measure incident response capability, benchmark teams against real world scenarios, and identify gaps in both technical and executive decision making skills.

This is especially critical as incident response increasingly involves cross functional leadership, not just IT teams.

Cyber incidents today impact operations, customer trust, and brand reputation. That means executives, not just security teams, must be ready to act.

Readiness is not about having the right tools, it is about having the right people trained to make the right decisions under pressure.

From Tools to Transformation The Rise of Cyber Resilience Leadership

Cybersecurity is no longer just about stopping attacks, it is about ensuring the organization can withstand and recover from them.

This evolution is pushing CISOs to engage directly with executive leadership, lead enterprise wide resilience initiatives, and invest in simulation driven training and decision making frameworks.

Tabletop exercises and scenario based simulations are becoming a cornerstone of this shift, giving leadership teams the experience they need before a real crisis hits.

Final Thoughts The New Cybersecurity Mandate

For today’s CISO, success is no longer defined solely by how well threats are prevented, but by how effectively the organization responds when prevention fails.

The three tools outlined here, risk prioritization, security design, and skills assessment, represent the foundation of a modern cyber resilience strategy.

Organizations that adopt these approaches will not only strengthen their defenses, they will build the confidence, clarity, and capability needed to lead through crisis.

The Man Fortune 500s Call When the Ransom Note Arrives

When a ransomware note hits a large publicly-traded company on a Tuesday morning, the first calls go to outside counsel, the incident response firm, and the FBI. The fourth call the one that actually determines whether the company survives the next two weeks financially intact typically goes to someone like Kurtis Minder.

Minder spent more than a decade building something rare: a team of digital spies embedded inside criminal networks. What started as a cyber intelligence operation essentially running a corporate espionage capability to track threat actors evolved, almost by accident, into one of the most specialized ransomware negotiation practices in the world. His work has been profiled in The New Yorker. He has testified before Congressional committees on ransomware policy. And he has sat across dark web chat windows from some of the most sophisticated criminal organizations operating today.

What he’s learned challenges nearly everything the enterprise security community assumes about how these attacks work who is doing them, how they think, and what it actually takes to survive one.

Digital Spies, Not Negotiators

Minder’s entry into ransomware negotiation wasn’t planned. His firm was running what he describes as human intelligence operations the kind of thing you’d expect from a government agency rather than a private company. “In order to be competitive and do that well, you really had to have your finger on the pulse of what the bad guys were doing,” he explains. “You had to run basically an espionage operation. You had to become digital spies make friends with the bad guys so you get invited to the party.”

Building those relationships took over twelve years and a recruitment process that draws on lessons from the intelligence community. Staff don’t walk in and start interacting with threat actors. They begin as analysts, earn trust internally, and only gradually work their way toward direct contact. Background checks are run by a firm that primarily serves the CIA. “When some people do background checks, they pay background-check.com something. $40. Ours costs a lot more than that,” Minder says.

The proof of concept for all that investment came unexpectedly. A client called with a ransomware incident. Minder tried to refer them to a negotiator he’d met at dinner someone who claimed to specialize in this work. That person ghosted him the morning of the call. Minder found himself alone in a WebEx session with the CEO, CISO, deputy CISO, legal counsel, an incident response firm, and an FBI representative facing his first-ever ransomware negotiation with no preparation and no precedent.

“I ended up doing the entire negotiation myself, kind of on the fly. That was the first one I’d ever done. Lucky for me, I’m a quick learner.” Kurtis Minder, Author, Cyber Recon

He spent the following nights cramming negotiation literature. He used former undercover police officers on his team as sounding boards. Two and a half weeks later, he settled the case at approximately ten percent of the original demand. The insurance company and law firm called the next day asking to work together again. That near-accident became the foundation of a practice that later brought him into contact with Chris Voss the former FBI hostage negotiator and author of Never Split the Difference and eventually into the pages of The New Yorker.

They Are Not Gangs. They Are Companies.

One of the most consequential misunderstandings in how the security community talks about ransomware, Minder argues, is the word “gang.” It implies disorganization, loose affiliation, and improvisation. The reality is nearly the opposite.

“I think calling them gangs has really misled the public. Gangs are a loose affiliation, somewhat disorganized. These groups, most of them, are not that.” Kurtis Minder.

The organizations Minder negotiates with have rank, middle management, quotas, and bonuses. They have training manuals. They have HR processes. They recruit talent away from rival groups the same way Silicon Valley poaches engineers “the same couple hundred people moving around, switching jobs, going from one group to the other just like we do in tech.” When a negotiator first engages via a dark web chat window, the person on the other end may not even speak English. They are reading from a pre-translated script, running responses through a translation tool before sending them back.

“It’s important to understand that,” Minder says, “because what you say, and how that translates in tone and context in Ukrainian or whatever, might make a difference in the outcome.”

Understanding the specific group behind an attack their playbook, their pricing logic, their known behavioral patterns is therefore not background color. It is the primary intelligence input that shapes every tactical decision in the negotiation.

The Decisions No One Pre-Plans

The most dangerous gap Minder encounters isn’t in technical defense it’s in decision architecture. When a ransom note arrives, the questions that determine the outcome have almost nothing to do with the negotiation itself. They are questions that should have been answered weeks or months earlier, and almost never are.

Does engaging with this group conflict with the organization’s values? Is the payment potentially illegal certain sanctioned groups make any transaction a federal matter regardless of circumstances? Does available threat intelligence suggest this group will ever reach a number the victim can actually pay? Are backups genuinely intact and restorable removing the need to engage at all?

“Once you say ‘hey, I got your ransom note’ you’re on the radar. They’re not going away now.” Kurtis Minder

That last point the decision to simply not respond is more powerful than most organizations realize. If backups are viable and restoration is possible, silence is a legitimate strategy. The moment an organization announces itself to a threat actor, it becomes a priority in a portfolio of hundreds of simultaneous victims.

PRE-NEGOTIATION DECISIONS EVERY CISO MUST PRE-PLAN
  • Does engaging with this threat actor conflict with organizational values or legal obligations?
  • Is this group sanctioned making payment potentially illegal regardless of business pressure?
  • Based on threat intelligence, will they ever reach a number you can actually pay?
  • Are backups intact and restorable making engagement unnecessary?
  • Does your bank allow large crypto transfers? Do you have a crypto broker relationship?
  • Has your incident response firm confirmed all attacker access is closed?

Minder has worked cases where negotiations collapsed entirely because a second threat actor had simultaneous, independent access to the same network. In one case during a Black Hat conference, two separate groups encrypted the same organization’s files independently. Double-encrypted virtual machine files are effectively unrecoverable. That managed service company shut down operations.

Negotiation Is Psychology, Not Accounting

When Minder finally opens a chat window with a threat actor, the first objective is not to establish a number. It is to establish that a transaction is going to happen. Everything else follows from that foundation.

The most common mistake he sees in transcripts from less experienced responders is positional bargaining an immediate counter-offer at a fraction of the demand. “You almost always get there eventually,” he concedes, “but you don’t want to start there. You don’t want to put a stake in the ground that early in the negotiation.”

The more productive early move is to ask the attackers to justify their number. Where did it come from? How did they arrive at it? In many cases, the answer reveals the gap. Attackers often use commercial business intelligence tools ZoomInfo, revenue databases to anchor on a topline figure that has no relationship to the victim’s actual financial position.

“We sometimes have to give them an impromptu business class. ‘Yeah, our topline revenue is four million. Our margin is two percent.’ They’re not business people. I have to explain what’s left over.” Kurtis Minder

That dynamic is about to change. Minder flags the intersection of AI and double extortion as the most significant emerging shift in the negotiation landscape. Attackers who exfiltrate data before encrypting it have always had theoretical leverage from that data but manually parsing thousands of financial documents to identify useful leverage is slow and inconsistent. That friction is disappearing.

“Their ability to now digest documents at scale and find the really juicy ones to use as leverage that’s already happening,” Minder says. “AI is going to make life a lot more difficult for negotiators unless you really don’t have money.”

The implication for CISOs is direct: financial records, board presentations, M&A documentation, and insurance policy details are no longer just compliance concerns. They are negotiation leverage assets, and data classification strategies need to account for that threat model explicitly.

The RaaS Economy and the Skill Floor That Disappeared

The structural change that made ransomware a persistent enterprise problem not an occasional nuisance is the complete separation of the attack into component parts, each handled by specialists who never need to interact with the others.

Initial access brokers do one thing: break into a network and sell the foothold. They have no interest in running ransomware. They list access on dark web marketplaces often for a few thousand dollars and let affiliates take it from there. Those affiliates don’t need to be hackers. They need to know how to use Tor and make a cryptocurrency payment. The Ransomware-as-a-Service platform handles everything else: data exfiltration, file encryption, ransom note generation, and in mature operations, round-the-clock operator support.

“If you know how to use Tor and you know how to make a cryptocurrency payment,” Minder says, “you can carry out an enterprise ransomware attack.”

The RaaS platform owners don’t even need to execute attacks themselves. They take a percentage of every ransom paid by affiliates using their infrastructure. It is, as Minder describes it, a franchise model one that scales without requiring the platform operator to touch a single victim directly.

Nation-States in the Hiring Pipeline

The same logic that makes criminal organizations more effective separation of roles, specialization, scale is now being applied by nation-states through a different attack vector entirely: employment.

North Korea’s government-backed remote worker program places trained operatives into US companies through AI-assisted interviews and deepfake identity construction. They receive a legitimate paycheck. More importantly, they receive legitimate network access the kind that doesn’t trigger a single intrusion detection alert because it looks identical to normal employee behavior.

The program has been amplified by a new category of AI interview coaching tools, one of which reportedly reached $100 million in ARR within months of launch. These tools transcribe questions in real time and display scripted answers as an overlay on a video call effectively a teleprompter invisible to the interviewer. Combined with voice synthesis and visual deepfake technology, the result is a hiring pipeline that standard enterprise screening was not designed to detect.

For CISOs, this is an insider threat that originates entirely outside the security team’s traditional visibility in a process owned by HR, with no security checkpoint between the interview and the first day of network access.

After the Attack: Where Companies Actually Lose

Assume the negotiation ends successfully. The decryption key works. Operations resume. The incident is, technically, over. What happens next not during the attack, but after is where Minder says companies most consistently fail, and where the legal and reputational damage compounds long after the attackers have moved on.

“Be as transparent as you can be within your knowledge boundary. The quickest way to squander goodwill is to make people think you misled them intentionally. That’s how you end up in a class action lawsuit.” Kurtis Minder

The instinct to say nothing, or to say as little as possible for as long as possible, is understandable but it reliably backfires. The affected community fills silence with speculation. By the time the standard “we are investigating” statement appears, trust has already begun to erode. What comes next the updates, the timeline, the disclosure is evaluated through the lens of whether the organization was trying to hide something.

None of this communication strategy should be designed during an active incident. The plan, the spokespeople, the escalation framework, the pre-approved language all of it needs to exist before the note arrives. Tabletop exercises that don’t include a communication workstream are, in Minder’s view, missing the scenario most likely to determine the organization’s long-term outcome.

What Tabletops Get Wrong

Speaking of tabletops: Minder has sat in on exercises run by some of the largest brands in incident response, and he has called some of those firms directly to tell them to stop making a specific, pervasive mistake. They put the ransom amount in the ransom note.

“In six years, I have never had a ransom note that has the amount in it,” he says. “It says the files are locked. If you want something, contact us.” The amount only exists after initial contact. By scripting a tabletop that skips that decision whether to engage, based on incomplete information, under time pressure the exercise eliminates one of the most consequential decision points in the entire response.

Other common failures: no designated scribe documenting what the exercise reveals needs to be fixed, no communication workstream, and scenarios that assume the incident response team has already closed all attacker access an assumption that is frequently wrong in real events.

The Three Controls That Would Stop Most Attacks

After years of post-incident debriefs in which attackers describe exactly how they got in often in remarkable technical detail Minder’s conclusions about prevention are unglamorous. Password reuse remains one of the most consistent initial access vectors. Multi-factor authentication is still unenforced across large portions of enterprise environments. Social engineering, the third major pathway, is addressed by awareness training that most organizations treat as a compliance checkbox rather than a genuine control.

“How many times do we have to talk about MFA? Just turn it on on everything you possibly can. They just log in. It doesn’t set off your intrusion detection system because it looks like normal behavior.” Kurtis Minder

Eliminate password reuse organization-wide. Enforce password manager adoption across all roles, not just technical staff.
Enable multi-factor authentication on every system that supports it. Credential stuffing only succeeds where MFA is absent.

Invest in user awareness training that treats social engineering as a primary attack vector not an afterthought to technical controls.
For organizations without a ransomware response playbook, Minder points to CISA’s published template as a solid starting point reflecting conclusions drawn from the same volume of attack data his own work has produced. The fundamental question he poses to every organization is not whether they will be attacked. It is whether they will have practiced their response before the note arrives.

“Plan for an attack as inevitable,” he says. “And then make sure your plan actually works.”

Kurtis Minder

About the Author

Kurtis Minder is a cybersecurity executive, author, and speaker with more than 20 years of experience in cyber threat intelligence, ransomware response, and digital risk management. As the former CEO and co-founder of GroupSense, he led one of the industry’s premier cyber reconnaissance and ransomware negotiation teams. Today, Kurtis is the author of Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation. He is a frequent speaker on cybercrime, digital risk, ransomware, and the human impact of cybersecurity. Kurtis is also an of ‘Author, Cyber Recon’. Learn more at KurtisMinder.com. This article is based on his appearance on The Cybersecurity Podcast by EC-Council, hosted by Jay Bavisi.

The Human Factor: Why AI Automation in GRC Still Needs Leadership in the Loop

The pitch comes regularly now: “Our platform automates 85% of your control assessment workload.” “Generative AI selects controls in seconds, no human review needed.” “Remediation workflows are fully autonomous; your team just tracks closure.”

It’s seductive. In an era when security teams are stretched thin and stakeholder expectations grow daily, the promise of AI-driven GRC is powerful. Automation delivers speed, consistency, and scale. And on the surface, it works assessments completed faster, artifacts are generated uniformly, and remediation tasks populate automatically.

But there’s a catch. I’ve seen it play out in multiple organizations: when you automate the thinking out of GRC, you lose the judgment that reduces risk.

The Automation Paradox in GRC

Yes, GRC has plenty of process work that AI handles beautifully. Control selection based on framework mappings and regulatory requirements. AI does it. Generating policy documents from templates? Efficient. Scheduling assessments based on risk criticality and compliance timelines. Perfect. The operational backbone of GRC, the mechanical parts, benefits immensely from automation.

The trouble starts when organizations treat this operational efficiency as strategic risk management. They don’t. Risk acceptance decisions, stakeholder engagement during assessments, and reporting that informs business leaders are not process problems. They’re leadership problems. And they still require a human in the room.

Consider a common scenario: An AI-driven assessment flags a control gap in a critical system. The platform assigns it a severity score, categorizes it by framework, and routes a remediation ticket automatically. Looks efficient, right? But the context is missing. Is this gap truly material to your organization’s risk profile? Has a similar gap already been accepted elsewhere in the business? Do you have the resources to remediate it, or do you accept the risk this quarter? What’s the business impact if this control fails?

None of that can be answered by a system. It requires someone who understands the business, knows the regulatory environment, and has the authority to make a trade-off decision. That’s a human, ideally, you.

Where Automation Adds Real Value

Let me be clear: this isn’t an argument against AI in GRC. I’m a strong believer in using technology to elevate work. The question is where.

Automation shines in the roles where speed and consistency matter but judgment doesn’t:

Control inventory and mapping: AI can correlate controls across frameworks, flag overlaps, and suggest maturity improvements based on your current state

Assessment scheduling and workflow: Automating when assessments run based on risk and compliance windows removes bottlenecks

Artifact generation: Policies, procedures, and evidence documents can be templated and AI-assisted without sacrificing quality.

Trend analysis: AI excels at spotting patterns in historical assessment data—repeated gaps, systemic weaknesses, emerging risks

Escalation routing: Flagging high-risk findings and routing them to the right stakeholder is perfect for automation

In each of these cases, AI does grunt work so your team can focus on judgment calls. That’s the right balance.

The Non-Negotiable Human Moments

Where I’ve seen organizations, stumble is treating high-stakes decisions as automated. They’re not. Here are the moments that still require human leadership:

Risk Acceptance: This is the apex of GRC, the formal decision to live with a particular risk. An AI system can surface the gap, calculate the exposure, even model scenarios. But deciding whether your organization accepts that risk requires judgment about business strategy, board tolerance, and competitive positioning. A CISO or risk leader must make that decision. It can’t be delegated to an algorithm, and if it is, you’ve abdicated accountability.

Stakeholder Engagement in Assessments: When you’re assessing a critical business process, the conversation with process owners is as valuable as the assessment itself. You’re not just checking boxes; you’re learning how the business operates, building trust, and surfacing context that shapes remediation priorities. Automating this step, letting an AI interview a stakeholder or submit assessment questions without human interpretation, erodes that relationship and misses crucial nuance.

Remediation Strategy and Trade-offs: Once you’ve identified gaps, the path forward isn’t obvious. Do you remediate immediately, accept the risk, or implement a compensating control? How do you phase remediation across the organization? Where do you shift resources? These decisions involve business impact, budget constraints, and organizational capacity. They require someone who understands both the security landscape and how your organization operates.

Executive Reporting: The compliance report that goes to the board or audit committee is a leadership communication tool, not just a data dump. It should tell a coherent story about your risk posture, the actions you’re taking, and the decisions you’re making. An AI-generated report full of metrics and status indicators misses the narrative. A board member asks, “Are we safe?” You can’t answer that with a dashboard, you need to synthesize data, context, and judgment into a clear perspective.

The Real Risk: Check the box – Compliance

Organizations that go all-in on GRC automation often end up with what I call “check the box compliance “all the motions of a mature GRC program, but without the substance. The assessments run on schedule. The tickets are closed. The reports are flawless. And yet, the organization’s actual risk posture hasn’t meaningfully improved.

Why? Because the automating organization has outsourced thinking to a tool. No one is asking the hard questions: Is this control actually preventing the risks we care about? Are we remediating in the right order? Does our team understand why they’re doing this work, or are they just clicking buttons?

The most mature GRC programs I’ve worked in had one thing in common: they used automation to accelerate process but kept the thinking in the room. The CISO was reviewing risk acceptance decisions, not rubber-stamping them. The assessment manager was synthesizing findings into actionable insights, not just exporting data. The team understood that their job was risk reduction, not compliance completion.

That distinction matters enormously.

Building the Right Human-AI Partnership

So how do you structure GRC for the era of AI without losing the judgment that matters?

Start by mapping your GRC processes and explicitly deciding: What decisions require human judgment, and what’s mechanical? Where you decide that human judgment is essential, design the automation to support that judgment, not replace it. The AI should pull data, surface patterns, highlight anomalies, and prepare recommendations. Humans should evaluate, decide, and own the outcome.

Second, resist the vendor narrative that more automation is always better. Vendors have an incentive to tell you that their platform can make you autonomous, that sells the product. But mature CISOs know better. Ask your vendor: where does your platform expect human judgment? Where are the gates where a leader must make a call? If they say their system needs almost no human input, be skeptical.

Third, invest in your team’s analytical and contextual knowledge. If you’re automating the thinking, your GRC team becomes clerical. If you’re automating the mechanics, your team becomes more strategic. That’s a very different investment.

The Accountability Question

Here’s the uncomfortable truth: when something goes wrong in GRC, a material gap wasn’t identified, a risk acceptance decision proved catastrophic, an audit finding was missed, someone must explain it. That someone is a person, not a platform. You can’t tell your board, “The AI decided this risk was immaterial.” That’s not accountability; it’s abdication.

The cases where GRC has failed, where breaches happened despite compliant-looking programs, often involved over-reliance on automation. The human judgment that might have caught the gap, asked the harder question, or pushed back on a risky assumption was missing.

The flip side: when GRC works well, it’s because someone is in the loop. Someone understood the business and the risk. Someone pushed back when the numbers didn’t feel right. Someone made a hard call and owned it.

Moving Forward

AI will continue transforming GRC. In five years, the tools will be faster, smarter, and more integrated. Good. They should be. But the fundamentals won’t change risk is a business judgment, not a data problem. Compliance is a means of managing risk, not an end. And accountability flows to people, not algorithms.

The CISOs who thrive in this era won’t be those who automated the most. They’ll be those who were thoughtful about where humans add the most value, who insisted on keeping judgment in the loop, and who used AI to amplify human leadership rather than replace it.

That’s not anti-AI. It’s pro-effective. And it’s the only way GRC reduces risk.

Ernest Blankson

About the Author

Ernest Blankson is a cybersecurity architect and enterprise risk management leader with over a decade of hands-on experience designing and implementing security governance, risk, and compliance programs at scale. Throughout his career, he has served in critical technical and strategic roles, including Information System Security Officer (ISSO), Senior Security Architect, Cybersecurity Engineer, and Senior Risk Advisor, across federal agencies, defense contractors, the judiciary, and enterprise sectors.

As one of the first cohorts of professionals selected to develop the industry’s first AI-centric security management credential, the ISACA Advanced in AI Security Management, Ernest brings rare insider knowledge of how AI governance frameworks are designed and validated. He participated directly in AAISM curriculum development, served as a beta tester validating the certification framework, and contributed to parallel efforts including the AAIR (AI Audit, Investigation, and Reporting) framework. This insider perspective, combined with a decade of practical AI governance implementation, positions him uniquely to bridge the gap between theoretical frameworks and operational reality.

Ernest’s core expertise centers on a fundamental challenge in modern cybersecurity: translating abstract technical risk into clear, quantifiable business intelligence that supports executive decision-making. He has modernized document-driven GRC processes into centralized governance platforms, designed common control inheritance programs, built enterprise risk registers, established AI governance structures across distributed teams, and regularly briefed C-suite and board-level leadership on organizational cyber and AI risk posture.

He is an active contributor to the cybersecurity profession, participating in ISC2 and ISACA volunteer initiatives including exam development, curriculum design, and professional ethics advocacy. His published work includes articles on transforming cybersecurity metrics into strategic business insights and on the limitations of traditional risk acceptance approaches in modern threat environments. Ernest holds professional certifications in information security and maintains active engagement with emerging standards and best practices in AI governance, risk quantification, and compliance modernization.

GITEX AI Europe

GITEX AI EUROPE takes over Berlin this 30 June and 1 July 2026
GITEX AI EUROPE, the most global tech and digital investment cross-industry event in Europe, is back in Germany 30 June to 1 July 2026, at Messe Berlin.

As Europe’s definitive platform for sovereign digital transformation, GITEX AI EUROPE unites enterprises, SMEs and startups with investors, policymakers and researchers to accelerate new business, new capital and new partnerships.

  1. Meet the Strategic AI & Tech Leaders Exhibiting at GITEX AI EUROPE – Amazon Web Services, Boston Limited, Hewlett-Packard, AMD, TrendAI and more.
  2. Attend Conferences & Masterclass – featuring leaders from OpenAI, KfW, Bosch, European Innovation Council, France Digitale, Euronext and more.
  3. Billion-dollar-valued Unicorns You Actually Want to Meet – Perplexity, Miro, Checkout.com, Delivery Hero, Wayve and Deepl.
  4. Supernova All-stars Pitch Competition -The most innovative founders compete for a €50,000+ equity-free prize pool, massive visibility and direct access to top-tier investors.

Registration is Now Live. Discounted passes are available for a limited time:

Save up to 50% On Your Conference Pass (Use Code PTNRGE50 )
Get Your Complimentary Visitor Pass From Us. (Use Code TECHFOMO)

4th Edition MENA Cyber Security Conference – Dubai Edition

4th Edition MENA Cyber Security Conference 2026: Securing Tomorrow, Today is a premier one-day cybersecurity conference designed to address the most critical security challenges of the next decade. The event brings together industry leaders, cybersecurity experts, and decision-makers from Government, Oil & Energy, Aviation, Defence, BFSI, Healthcare, Manufacturing, Retail, Logistics, Transportation, and Telecom to explore the latest trends, solutions, and technologies shaping the future of digital security.

The conference will feature a combination of keynote sessions and panel discussions, diving deep into the evolving cyber threat landscape. With a focus on cross-industry solutions, each session will deliver actionable insights on how organizations are adapting to the rapidly changing cybersecurity environment. Participants will gain strategies for tackling complex security challenges, adopting emerging technologies, and preparing for future risks.

Whether you’re a senior executive, security professional, or industry expert, the 4th Edition MENA Cyber Security Conference 2026 offers a unique opportunity to understand the future of cybersecurity and connect with peers and partners in an evolving digital ecosystem.

Registration Link: Attend As Delegate – MENA Cyber Security
(Use code MENACS06 during registration to confirm your participation. Strictly NOT for service providers)

Barcelona Cybersecurity Congress

Name : Barcelona Cybersecurity Congress
Website: https://www.barcelonacybersecuritycongress.com/
Date: November 3-5, 2026
Location: Hall 2, Gran Via Venue, Barcelona, Spain

Barcelona Cybersecurity Congress Returns 3–5 November to Champion Europe’s Digital Protection Leaders.

BCC26 gathers the European cybersecurity ecosystem at Fira de Barcelona. The seventh edition of the Barcelona Cybersecurity Congress (BCC26), organised by Fira de Barcelona and the Cybersecurity Agency of Catalonia, will take place on 3–5 November 2026 at Fira de Barcelona’s Gran Via venue. The event arrives at a critical moment: in Spain alone, INCIBE recorded 122,223 cybersecurity incidents in 2025, a 26% increase year on year. BCC26 is expected to welcome 6,000 professionals and over 100 exhibiting companies, making it the foremost European platform for cybersecurity commerce and knowledge.
The programme includes a Congress addressing digital resilience, critical infrastructure, and AI-driven threats; a Hacking Village; a Startup Cyber Experience; and a Networking Hub with the main European cybersecurity bodies. This edition will be held alongside Smart City Expo World Congress, bridging urban digitalisation and cyber defence.

CISO Global Leadership Awards: Honouring Europe’s Cybersecurity Leaders

The flagship moment of BCC26 is the CISO Global Leadership Awards — a prestigious ceremony recognising the Chief Information Security Officers and security leaders driving real change across industries and public institutions. The Awards celebrate outstanding vision, innovation, and measurable impact, putting the spotlight on the professionals who defend organisations against an ever-growing wave of cyber threats. For security professionals, attending is not just an honour — it is a gateway to the conversations that define the industry’s future. If you’d like to apply, you can do it here: https://www.barcelonacybersecuritycongress.com/congress/cybersecurity-leadership-awards/
For our CISOMAG community members, the event is offering exclusive free and discounted tickets.

You can avail 55% discount on the Full Congress Ticket. Register through this link – https://registration.firabarcelona.com/?cod_prom=RFHY8PAD#/en_GB/J137026/WEB

We’re Repeating the Same Mistake With AI That We Made With Cybersecurity

Walking the floor at RSAC 2026 is a lesson in pattern recognition. Booth after booth, banner after banner, artificial intelligence is everywhere: new product names, new taglines, new promises.

For Jay Bavisi, the concern is not the volume of AI claims but the familiar pattern underneath them: speed first, safeguards later.

“We’re rushing with the use of AI, but we’re not thinking through the implications of AI and cybersecurity with artificial intelligence. So that’s very concerning,” he said at RSAC 2026.

But the problem isn’t the branding. It’s what’s happening, or not happening, underneath it.

THE SAME AFTERTHOUGHT, DIFFERENT ERA

When Bavisi talks about AI, he keeps returning to the same underlying concern: the industry is treating governance as something that can be bolted on later, just as it once did with cybersecurity itself.

“Cybersecurity has … been an afterthought for many, many years,” he said. “We as a tech community rushed into building applications, network systems — we wanted efficiency. And then we said, oops, we forgot cyber. We’re repeating the same mistake with AI. We’re rushing with the use of AI, but we’re not thinking through the implications.”

The scale of investment makes this especially alarming. To put it in perspective, Bavisi cited the staggering financial commitment behind today’s AI race.

“It cost humans about $250 billion in today’s dollars to send Neil Armstrong to the moon. This year alone, we’re going to spend between $2.5 and $4.5 trillion on artificial intelligence.”

But here’s the statistic that should keep every board member up at night: while 84% of Fortune 500 companies now reference AI in their 10-K filings, only 18% have a fully implemented AI governance model in place.

“One in five companies on the Fortune 500 actually have a full-fledged governance model,” Bavisi said. “There is a tremendous amount of danger with the way we are governing AI. Or not governing.”

CISOS: HANDED THE KEYS TO A CAR THEY DIDN’T ORDER

Asked what this looks like inside organizations, Bavisi pointed immediately to the position CISOs have been put in: accountable for a fast-moving category they often did not choose, scope, or resource.

“I kind of feel sorry for CISOs,” he said. “Chief information security officers have traditionally been dealing with infrastructure, cloud applications, the standard protocols and surfaces we’ve been used to. And now comes this new era called AI, and it’s almost thrown at them.”

The dynamic he describes is one many security leaders will recognize immediately. AI programs are being stood up by program managers, CIO offices, and enthusiastic business units, and then the CISO is handed responsibility for protecting something they had little hand in designing.

“You, the CISO, are responsible for protecting it,” he said. “But then comes the question: how many red teamers are actually prepared to test AI models? What kind of governance frameworks do we have within an organization for implementation and governing of AI? These are all questions thrown at CISOs, with the instruction to just go manage it.”

The gap, he argued, is not just technical. It is organizational: responsibility is being assigned faster than capability, training, and governance are being built around it.

THE GOVERNANCE RECKONING IS COMING

On regulation, Bavisi’s view was straightforward: organizations treating AI governance as optional are moving against the broader direction of policy and oversight.

The EU AI Act is already in motion. NIST has published its AI Risk Management Framework. ISO 42001 is gaining traction. And Bavisi points out that 72 countries across the globe already have some form of AI framework in place.

“By 2027, this will all get mandated,” he said. “All organizations that are utilizing AI today and thinking, ‘Hey, this is going to be great’ — the boards are going to be required to implement some form of a framework. The SEC is certainly going to implement a requirement for AI framework governance.”

“There’s prompt injection, there’s LLM model takeovers, there’s data poisoning, agentic AI. All of these things are happening. So I really think we’ve got to put some structure in place, and governance is coming.”

The window to get ahead of it is closing. And the attack surface is only growing more complex. Bavisi ticked through a list that captures just how much has changed: prompt injection, LLM model takeovers, data poisoning, agentic AI running autonomously in enterprise environments.

THE ADG FRAMEWORK: ADOPT, DEFEND, GOVERN

Bavisi said the framework grew out of a year of research and debate with EC-Council’s AI advisory committee, which includes leaders from large enterprises such as Prudential, JP Morgan, Microsoft, and Salesforce. The result is the ADG Framework, Adopt, Defend, and Govern, which he described as a free blueprint for organizations trying to bring more structure to AI security and governance.

Adopt starts at the end-user level, but it goes well beyond phishing awareness. “The security awareness program that we’ve been doing for the last 20 years — that’s not going to work anymore,” Bavisi said. “We’ve got to think about: how am I going to use AI securely? What is prompt injection? End users are going to have to know about this. They need to understand that LLMs can be poisoned.”

Defend focuses on what happens once AI is implemented and the governance questions become concrete. Who owns the program? What is the escalation path? How is third-party risk being managed? Bavisi said those are the questions organizations need to answer early, not after deployment.

Govern addresses the compliance reality now taking shape. For professionals used to thinking in terms of ISO 27001, the landscape is expanding quickly as AI-specific frameworks take hold across jurisdictions.

Rounding it out: a Certified Offensive AI Security Professional credential, designed to take today’s certified ethical hackers and pen testers and arm them with the skills to red team AI models specifically.

THE TALENT GAP JUST GOT LARGER

The cybersecurity industry was already operating with a known deficit, more than four million unfilled positions globally before AI entered the picture. The question now is whether AI makes that gap better or worse.

Bavisi’s answer is nuanced, and probably more optimistic than most people expect, with an important asterisk.

“AI will eat some jobs,” he said plainly. “In the security operations center, the L1 jobs, and now L2, are almost vanishing. AI agents are able to do that job much better, more efficiently, at lower cost.”

“I don’t think the job market is going to vanish. I think it’s actually going to explode,” he continued. “The number of cybersecurity professionals we’re going to require with AI is going to be much higher than without AI. The only difference is that the professionals we need to build will have higher capability and higher demonstrable ability.”

The roles most at risk are the high-volume, lower-complexity jobs. The roles being created, he said, require deeper specialization: digital forensics experts, AI red teamers, AI program managers, and professionals focused on responsible AI governance and ethics.

“This talent is rare. It’s a good time for cyber professionals to uplift themselves and help organizations deal with this new maze called artificial intelligence.”

“OVER-AI-FYING”: THE RISK NOBODY’S TALKING ABOUT ENOUGH

The conversation took a fascinating turn near the end when the question of AI accountability came up. Who is responsible when an AI system causes harm or makes a consequential error?

“You cannot outsource the security. The risk will always remain with you,” Bavisi said. “The same is true with governance. You can use any platform out there, and that’s great. But the risk belongs to the organization.”

He also offered a stark glimpse at where the threat landscape is heading.

“We live in a world where AI now has its own social networks,” he said. “They can social engineer us now. AI is now able to blackmail human beings.”

“When robot engineering matches AI, you’re going to have humanoids,” he added. “Star Wars is not as far away as we thought it was.”

His broader point was that organizations are moving faster than their structures for accountability, training, and governance can keep up, and that the risk does not disappear just because a vendor or platform sits in the middle.

AI Everything Kenya x GITEX Kenya

🔥 AI EVERYTHING KENYA x GITEX KENYA

📍 19–21 May 2026 | Nairobi | Kenya

Accelerated by GITEX GLOBAL, the world’s largest tech and startup show, in collaboration with the Republic of Kenya, the Office of The Tech Envoy, AI EVERYTHING KENYA x GITEX KENYA is Driving Inclusive Access to East Africa’s AI & Digital Economies. The event unites global pioneers, enterprises, startups, and policymakers to explore real-world AI innovations and next-generation solutions.

A 3-day event to support East Africa’s Global AI Ascension:

SUMMIT: Future Build Home – Empowering Everyone Through AI

📍 19 May 2026 | The Sarit Expo Centre

EXPO: The Ultimate Meeting Point for Global Innovators, Governments, Investors & Buyers, Driving Digital Transformation & Investment

📍 20-21 May 2026 | Kenyatta International Convention Centre (KICC):

10,000+ Tech Executives | 400+ Global Enterprise & Startups I 75 Participating Countries I 100+ Active Investors & VCs | 150+ Global Speakers

💡 Co-located powerhouse events

🔹 North Star Kenya – startups & scaleups

🔹 FDX Kenya – East Africa’s premium platform for institutional finance & digital assets business
💥 Next-gen solutions across

AI | Cloud | Cybersecurity | IoT | Big Data | Industry 4.0 | Connectivity I Fintech | Agritech | Greentech | Edutech I SaaS I Quantum I Cloud I Smart Mobility

Experience East Africa’s Largest Launch Event for AI, Startups & Capital

📌 Get Involved → https://linktr.ee/aieverythingkenya

🌐 More Info → https://aieverythingkenya.com

#AIEVERYTHINGKENYA #GITEXKENYA

Cyber Security Expo

Name :Cyber Security Expo
Website:
https://www.cybersecurityexpo.co.uk/manchester
Date:
July 9, 2026
Location:
Manchester Central, Manchester, United Kingdom

Join the UK’s Leading Recruitment Event for Cyber Security Professionals

The need for cyber security professionals in the North has been increasing over recent years with many companies and government agencies relocating due to the governments levelling up programmes.
Running since 2022, The Cyber Security EXPO Manchester is hosted at the famous Manchester Central, home to the largest exhibitions in the northwest, creating a professional arena for networking on the day. Along with other cities in the North, Manchester has a growing need for skilled candidates has been evident over the years creating a demand for the Security Cleared and Cyber Security EXPO.

Visitor passes are FREE and provide access to all co-located events.

6th Annual 100 CISO Summit & Awards 2026

Name : 6th Annual 100 CISO Summit & Awards 2026

The 6th Annual 100 CISO Summit & Awards 2026 unites Malaysia’s foremost cybersecurity leaders, regulators, and technology experts to address the next wave of challenges. Through real-world case studies, forward-looking strategies, and practical discussions, this summit equips security leaders with the insights to anticipate AI-driven threats, prepare for post-quantum disruption, and embed resilience across the enterprise. Join us to explore the future of cybersecurity leadership, gain actionable intelligence from regional experts, and connect with peers shaping the next frontier of Malaysia’s cyber defense.