The AI Supply Chain Can Execute Before the Application Does
AI artifacts are no longer passive data. DEF CON 34 shows how models, Skills, repositories and loaders can become execution paths — forcing CISOs to rethink supply-chain security, provenance and runtime authority.
MCP Is Becoming Enterprise Infrastructure
MCP is becoming enterprise infrastructure. As AI agents gain access to tools, identities and business systems, CISOs must govern not just integration — but the authority flowing through it.
The Agent Is the New Attack Path
A safe model does not imply a safe agent. Agentic AI shifts the security problem from jailbreaks to authority: can an attacker make the system perform an authorized action for an unauthorized reason?
Buildings Under Attack: Why Every CISO Must Prepare for Cyber-Physical Threats
Buildings are no longer passive infrastructure. They are connected cyber-physical systems that combine IT, OT, IoT and AI. This article introduces the emerging attack landscape every CISO should understand before smart buildings become the next major enterprise risk.
AI Cost Governance Is Becoming a Security Control
AI cost governance is becoming a security control. As chatbots evolve into agents, costs are driven by autonomous decisions, retrieval and tools—not users alone. The question is no longer what a token costs, but whether the organization can still see, limit and justify its AI-driven work.
The AI Control Gap
AI governance is becoming too small for the risks it is meant to manage. The real challenge is no longer responsible AI use, but whether organizations can still see, control, explain and stop the systems shaping their data, decisions, costs and dependencies.