{"id":5333,"date":"2026-06-14T18:11:51","date_gmt":"2026-06-14T23:11:51","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5333"},"modified":"2026-06-14T18:11:51","modified_gmt":"2026-06-14T23:11:51","slug":"the-ciso-brief-june-14-2026-2","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5333","title":{"rendered":"The CISO Brief \u2014 June 14, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\">\n<p class=\"date\">June 14, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">The CISO Brief<\/h1>\n<p class=\"tagline\">Strategic intelligence for security leaders \u2014 board reporting, regulatory shifts, AI governance, and the changing economics of the CISO seat.<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>At a glance<\/h2>\n<p>This week&#8217;s brief circles one structural gap: AI is being adopted far faster than it is being governed, and the visibility to close the distance largely does not exist yet. A Lookout report finds enterprises can&#8217;t see most of their mobile AI activity even as 97% of leaders call AI governance mission-critical \u2014 and 63% investigated an incident in the past year where generative AI contributed to data leakage. The financial sector makes the gap concrete: 62% of firms have deployed AI agents and 93% gave them autonomy, yet one-fifth suffered an AI-tool security incident and 21% don&#8217;t even know whether they were breached through a misconfigured AI. The week&#8217;s most useful reads move past alarm into method \u2014 mapping NIST and ISO frameworks onto autonomous agents, and arguing that durable governance must be built around real workflows rather than blanket restriction.<\/p>\n<p>A regulatory wave is the other dominant theme, and it is arriving on multiple fronts at once. CISA&#8217;s Binding Operational Directive 26-04 pushes federal agencies toward risk-based vulnerability management \u2014 prioritizing by exploitability and exposure rather than CVSS severity alone \u2014 a US policy shift that will become a benchmark boards ask about. In the EU, OpenSSF warns two-thirds of manufacturers and developers remain unfamiliar with the Cyber Resilience Act ahead of its December 2027 deadline, with only a third producing SBOMs, while a GRC leader describes how the parallel arrival of NIS2, DORA, and the EU AI Act is overwhelming organizations. Compliance evidence that looks spotless on paper, one interview warns, can still hide a control that fails a real CMMC or FedRAMP assessment.<\/p>\n<p>Inside the org chart, the seat itself keeps shifting. Gartner&#8217;s 2026 Summit reports 71% of board members now accept greater cyber-risk to hit business goals, and predicts business acumen will be the primary differentiator of high-performing CISOs by 2028 \u2014 a reframing of security as a deliberate business trade-off rather than a veto. The economics follow: cyber-insurance rates are softening even as exclusions widen and claims scrutiny tightens, with the average global ransomware claim nearly doubling to $713k in 2025, and 73% of organizations have increased security-training budgets, naming AI the most important employee skill. Several foundational reads round out the picture with concrete board-communication and risk-quantification playbooks.<\/p>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/06\/topic-map-ciso-2026-06-14-1.png\" alt=\"Topic map of this week's CISO Brief themes\"><\/p>\n<p class=\"caption\">This week&#8217;s topic map \u2014 AI governance and agent identity, the converging EU\/US regulatory wave (CISA BOD 26-04, CRA, NIS2\/DORA\/AI Act), and the economics of the CISO seat: board risk appetite, cyber-insurance, and skills investment.<\/p>\n<\/p><\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h3>Cluster 1 \u2014 AI governance &amp; agent identity<\/h3>\n<div class=\"cluster-intro\">Adoption is outrunning visibility and controls. Mobile AI activity is largely unseen, agents are getting autonomy without identity discipline, and the most useful reads move from alarm to method \u2014 frameworks, workflows, and a risk-based model.<\/div>\n<ul class=\"index-list\">\n<li>1. Organizations can&#8217;t see much of their mobile AI activity \u2014 Help Net Security<\/li>\n<li>2. Shadow AI is exposing the same governance failures we&#8217;ve ignored for years \u2014 Infosecurity Magazine<\/li>\n<li>3. How to use NIST and ISO frameworks to govern AI agents \u2014 Help Net Security<\/li>\n<li>7. Agentic AI surges in financial sector even as many firms fail to manage security risks \u2014 Cybersecurity Dive<\/li>\n<\/ul>\n<h3>Cluster 2 \u2014 Regulation &amp; compliance: the EU\/US wave<\/h3>\n<div class=\"cluster-intro\">CISA shifts US agencies to risk-based patching while EU obligations stack up \u2014 the CRA, NIS2, DORA, and the AI Act arriving in parallel. The throughline: paper compliance is no longer enough, and awareness of what&#8217;s coming is dangerously thin.<\/div>\n<ul class=\"index-list\">\n<li>4. Spotless compliance evidence can still hide a broken control \u2014 Help Net Security<\/li>\n<li>5. CISA orders federal agencies to &#8220;patch smarter&#8221; (BOD 26-04) \u2014 Help Net Security<\/li>\n<li>9. Two-thirds of open-source community unaware of the Cyber Resilience Act \u2014 Infosecurity Magazine<\/li>\n<\/ul>\n<h3>Cluster 3 \u2014 CISO role economics: risk appetite, insurance &amp; skills<\/h3>\n<div class=\"cluster-intro\">The seat is being repriced as a business function. Boards are accepting more cyber-risk to chase growth, insurers are tightening the terms of transfer, and training budgets are bending toward AI. Business acumen, not just technical depth, is becoming the differentiator.<\/div>\n<ul class=\"index-list\">\n<li>6. CISO role changes as cyber-risk appetites in the C-suite grow \u2014 TechTarget<\/li>\n<li>8. Cyber insurance policyholders facing heavier scrutiny in underwriting, claims \u2014 Cybersecurity Dive<\/li>\n<li>10. Enterprises report increasing budgets for security training in AI and other critical topics \u2014 Cybersecurity Dive<\/li>\n<\/ul>\n<h3>Cluster 4 \u2014 Foundational reading<\/h3>\n<div class=\"cluster-intro\">Slightly older context pieces worth keeping on hand: the EU regulatory pile-up from the inside, two concrete board-communication and risk-quantification frameworks, a deeper cyber-insurance briefing, a marquee CISO departure at Meta, the year&#8217;s sharpest public-sector confidence data, and two forward-looking 2026 priority maps from KPMG and SecurityWeek.<\/div>\n<ul class=\"index-list\">\n<li>11. EU organizations buckle under rising compliance pressure \u2014 Help Net Security<\/li>\n<li>12. Lost in translation: cybersecurity board reporting for CISOs \u2014 TechTarget<\/li>\n<li>13. How to get boards to prioritize cyber-risk quantification \u2014 Infosecurity Magazine<\/li>\n<li>14. Cyber insurance rates are dropping, but exclusions widen \u2014 Dark Reading<\/li>\n<li>15. Guy Rosen, Meta&#8217;s CISO and top Israeli executive, announces departure \u2014 CTech (Calcalist)<\/li>\n<li>16. State CISO confidence drops from 48% to 22% (NASCIO-Deloitte 2026) \u2014 Cybersecurity Insiders<\/li>\n<li>17. KPMG 2026 report names non-human identities as a critical CISO problem \u2014 Cybersecurity Insiders<\/li>\n<li>18. Cyber Insights 2026: What CISOs can expect in 2026 and beyond \u2014 SecurityWeek<\/li>\n<\/ul>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. Organizations can&#8217;t see much of their mobile AI activity<\/h4>\n<p class=\"meta\">Help Net Security &middot; June 11, 2026<\/p>\n<p>A Lookout report lands the uncomfortable mismatch at the center of this week&#8217;s brief: enterprises lack visibility into most of their mobile AI activity even as 97% of leaders call AI governance mission-critical. The gap is not theoretical \u2014 63% of organizations investigated an incident in the past year where generative AI contributed to data leakage. For a CISO, that pairing turns AI governance from a policy aspiration into an audit and compliance accountability problem with a hole in the middle: you cannot govern, or report to a board on, activity you can&#8217;t see. The practical first move is instrumentation \u2014 egress visibility and inventory for mobile AI use \u2014 before any control framework can mean anything.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/11\/lookout-mobile-ai-governance-risks-report\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>2. Shadow AI is exposing the same governance failures we&#8217;ve ignored for years<\/h4>\n<p class=\"meta\">Infosecurity Magazine &middot; June 10, 2026<\/p>\n<p>This opinion piece is the strategic counterweight to the week&#8217;s alarm-driven data. Its argument: restriction-heavy AI governance is repeating decades-old compliance mistakes, and programs built on blanket prohibition will be routed around exactly the way prior generations of policy were. Durable governance, it contends, has to be built around real employee workflows and a risk-based model \u2014 meeting people where the work actually happens rather than legislating against it. For leaders sketching a 2026 AI governance charter, this is a useful framing check: the goal is a defensible path to &#8220;yes,&#8221; not a longer list of &#8220;no.&#8221; Read it alongside the framework-mapping piece below for the how-to that complements the why.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.infosecurity-magazine.com\/opinions\/shadow-ai-is-exposing-governance\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>3. How to use NIST and ISO frameworks to govern AI agents<\/h4>\n<p class=\"meta\">Help Net Security &middot; June 12, 2026<\/p>\n<p>Token Security&#8217;s CTO offers the practical playbook this issue keeps gesturing toward: map the NIST AI RMF and ISO\/IEC 42001 onto the governance of autonomous agents by treating each agent as a machine identity \u2014 with an owner, a defined scope, and lifecycle controls. That reframing is what makes agent governance tractable, because it plugs into identity and access disciplines security teams already run rather than inventing a parallel regime from scratch. For CISOs whose orgs are deploying agents faster than they are governing them, this gives a recognized-framework spine to build against and to show an auditor. Pair it with the financial-sector data below, which quantifies exactly how wide the ownership gap has already become.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/12\/nist-iso-frameworks-govern-ai-agents\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>4. Spotless compliance evidence can still hide a broken control<\/h4>\n<p class=\"meta\">Help Net Security &middot; June 4, 2026<\/p>\n<p>Secureframe&#8217;s compliance head delivers a warning that belongs in every audit-readiness conversation: organizations that pass on paper still fail real CMMC and FedRAMP 20x assessments, because clean evidence can sit on top of a control that does not actually work. The interview&#8217;s larger point is that continuous monitoring is reshaping how compliance work gets done \u2014 moving it away from point-in-time evidence collection toward ongoing assurance that the control is operating. For boards and CISOs, the takeaway is to stop treating a passed audit as proof of resilience and start asking what the control does between assessments. A grounding read for anyone preparing for a real assessor rather than a checklist.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/04\/marc-rubbinaccio-secureframe-cmmc-compliance-readiness\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>5. CISA orders federal agencies to &#8220;patch smarter&#8221; (BOD 26-04)<\/h4>\n<p class=\"meta\">Help Net Security &middot; June 11, 2026<\/p>\n<p>CISA&#8217;s Binding Operational Directive 26-04 shifts federal agencies to risk-based vulnerability management \u2014 prioritizing by exploitability and exposure rather than CVSS severity alone. It is the marquee US policy move of the week, and its significance extends well beyond government: federal directives tend to become the benchmark boards and auditors ask private organizations to measure themselves against. The directive validates what mature security programs already practice, that severity scores are a poor proxy for real risk, and gives CISOs external air cover to retire CVSS-driven patch SLAs in favor of an exploitability-and-exposure model. Worth reading even if you have no federal footprint, because the question &#8220;are we aligned to BOD 26-04?&#8221; is coming.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/11\/cisa-risk-based-vulnerability-management-government\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>6. CISO role changes as cyber-risk appetites in the C-suite grow<\/h4>\n<p class=\"meta\">TechTarget &middot; June 8, 2026<\/p>\n<p>From Gartner&#8217;s 2026 Security &amp; Risk Management Summit comes a number that reframes the job: 71% of board members now accept greater cyber-risk to hit business goals. Gartner&#8217;s accompanying prediction sharpens the point \u2014 business acumen will be the primary differentiator of high-performing CISOs by 2028. Read together, the two signals describe a role moving from risk veto to risk advisor, where the CISO&#8217;s value is in framing security as a deliberate business trade-off the board can own. For leaders building their own development plan, this is a direct prompt: the technical floor is assumed; the differentiator now is the ability to translate, price, and negotiate risk in the language of the business.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/366644003\/CISO-role-changes-as-cyber-risk-appetites-in-the-C-suite-grow\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>7. Agentic AI surges in financial sector even as many firms fail to manage security risks<\/h4>\n<p class=\"meta\">Cybersecurity Dive &middot; June 12, 2026<\/p>\n<p>A Cloud Security Alliance report quantifies the governance gap better than any anecdote. In financial services, 62% of firms have deployed AI agents and 93% have granted them autonomy \u2014 yet one-fifth have already suffered an AI-tool security incident, and 21% don&#8217;t know whether they were breached through a misconfigured AI. That last figure is the one to put in front of a board: it is not a story about attacks, it is a story about not knowing. The data is exactly the kind of board-ready evidence that justifies the agent-as-machine-identity discipline outlined earlier in this issue, and it makes the case that autonomy without ownership, scope, and monitoring is a breach you may simply never detect.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.cybersecuritydive.com\/news\/ai-agents-financial-services-payments-security-risks\/822800\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>8. Cyber insurance policyholders facing heavier scrutiny in underwriting, claims<\/h4>\n<p class=\"meta\">Cybersecurity Dive &middot; June 8, 2026<\/p>\n<p>The cyber-insurance market is sending a mixed signal that leaders renewing policies need to read carefully: rates are softening, but exclusions are widening and claims scrutiny is tightening \u2014 particularly around MFA enforcement, war, and systemic-event carve-outs. A persistent protection gap leaves SMEs especially exposed, and the headline economic figure underscores why insurers are pulling back: the average global ransomware claim nearly doubled to $713k in 2025. The practical implication is that a cheaper premium can mask a thinner policy, and that the questions underwriters ask about MFA are increasingly the questions a denied claim will hinge on. Treat the renewal as a controls audit, not a price negotiation.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.cybersecuritydive.com\/news\/cyber-insurance-policyholders-facing-heavier-scrutiny-underwriting-claims\/822089\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>9. Two-thirds of open-source community unaware of the Cyber Resilience Act<\/h4>\n<p class=\"meta\">Infosecurity Magazine &middot; June 8, 2026<\/p>\n<p>OpenSSF warns that 66% of manufacturers and developers \u2014 and 72% in the US and Canada \u2014 are unfamiliar with the EU Cyber Resilience Act ahead of its December 2027 deadline, and only 32% produce SBOMs for all products. That is a regulatory blind spot with direct supply-chain and product-liability exposure, because the CRA reaches anyone shipping software-enabled products into the EU regardless of where they are built. For CISOs, the read is twofold: your own product portfolio may carry undisclosed obligations, and your open-source dependencies sit upstream of vendors who may not know the rules apply to them. With eighteen months of runway, the cheap move now is awareness and an SBOM baseline before the deadline compresses the options.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.infosecurity-magazine.com\/news\/open-source-unaware-cyber\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>10. Enterprises report increasing budgets for security training in AI and other critical topics<\/h4>\n<p class=\"meta\">Cybersecurity Dive &middot; June 11, 2026<\/p>\n<p>An ISC2 report puts a workforce-investment trend on the table that leaders can carry straight into a budget conversation: 73% of organizations increased their security-training budgets in the past year, and 47% named AI the most important employee skill. The pairing is telling \u2014 spend is rising and it is being steered toward AI fluency, which tracks the governance and agent-identity themes running through this whole issue. For a CISO, the data is useful in two directions: it benchmarks your own training spend against peers, and it reinforces the argument that closing the AI capability gap is a near-universal priority rather than a niche bet. The skills line item is becoming a governance line item.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.cybersecuritydive.com\/news\/cybersecurity-training-budget-increases-ai-skills\/822640\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>11. EU organizations buckle under rising compliance pressure<\/h4>\n<p class=\"meta\">Help Net Security &middot; June 1, 2026<\/p>\n<p>A GRC leader describes, from the inside, how the parallel arrival of NIS2, DORA, and the EU AI Act is overwhelming EU organizations \u2014 with uneven national implementation and unclear enforcement compounding the load. The piece is a board- and regulator-level read on the EU regulatory pile-up that the CRA awareness gap (article 9) is one symptom of. The honest framing is its value: this is not a single deadline to plan against but a stack of overlapping regimes whose interactions are still being worked out in practice. For CISOs and GCs running EU-facing programs, it argues for treating compliance as an operating-model problem rather than a series of discrete projects, and for budgeting accordingly.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.helpnetsecurity.com\/2026\/06\/01\/antonija-vojnovic-span-cybersecurity-governance-challenges\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>12. Lost in translation: cybersecurity board reporting for CISOs<\/h4>\n<p class=\"meta\">TechTarget &middot; June 3, 2026<\/p>\n<p>Gartner analysts offer a concrete board-communication framework worth adopting wholesale: structure cyber reports the way the board already reads financial statements \u2014 a balance sheet, an income statement, and a cash-flow view of risk. The data behind the advice gives it urgency, with 93% of directors seeing cyber-risk as a threat to shareholder value. The framework&#8217;s appeal is that it meets the board in its own native format rather than asking directors to learn a security vocabulary. For any CISO whose board packs still lean on heatmaps and CVE counts, this is a ready-made template to retrofit before the next reporting cycle, and it pairs naturally with the risk-quantification playbook in the next item.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/366643884\/Lost-in-translation-Cybersecurity-board-reporting-for-CISOs\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>13. How to get boards to prioritize cyber-risk quantification<\/h4>\n<p class=\"meta\">Infosecurity Magazine &middot; June 3, 2026<\/p>\n<p>Security leaders from BP and NatWest explain how cyber-risk quantification and dollar-value framing won them board buy-in \u2014 a peer playbook rather than a vendor pitch. The piece is the practical complement to the financial-statement reporting framework above: where one supplies the format, this supplies the method for filling it with numbers a board will trust and act on. The credibility comes from the names attached, two large regulated enterprises that had to make CRQ work under real scrutiny. For a CISO trying to move the board conversation off severity ratings and onto financial exposure, this is the read to study before pitching the approach internally, and to cite when asked whether anyone serious actually does it.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.infosecurity-magazine.com\/news\/infosecurity-europe-board-cyber\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>14. Cyber insurance rates are dropping, but exclusions widen<\/h4>\n<p class=\"meta\">Dark Reading &middot; June 3, 2026<\/p>\n<p>Coverage from the Gartner SRM Summit gives the deeper briefing behind this week&#8217;s cyber-insurance headline: prices are stabilizing or falling, but exclusions, sub-limits, and tail-coverage gaps are quietly growing. The specifics matter for anyone renewing \u2014 carve-outs for social engineering such as ClickFix, for war, and for mass cloud-outage events are the ones most likely to surface at claim time rather than at signing. Read alongside the underwriting-scrutiny piece (article 8), it reinforces a single message: the headline premium is the least important term in the policy. CISOs should read the exclusions and sub-limits first and model the scenarios they actually fear against what the policy would, and would not, pay out.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/cyber-insurance-rates-drop-exclusions-widen\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>15. Guy Rosen, Meta&#8217;s CISO and top Israeli executive, announces departure<\/h4>\n<p class=\"meta\">CTech (Calcalist) &middot; June 2, 2026<\/p>\n<p>After nearly 13 years at Meta, Chief Information Security Officer Guy Rosen has told employees he is stepping down, staying on for several months to support a smooth handover. Rosen has held the CISO seat since 2022, leading cybersecurity across Meta&#8217;s global infrastructure, and over the past year also initiated and led the company&#8217;s internal AI transformation. The departure is a marquee-CISO transition worth watching for two reasons leaders will recognize: succession continuity at a hyperscaler-scale security organization, and the signal in Rosen&#8217;s stated next chapter \u2014 advising executives and organizations on navigating the AI era, which is exactly where the role&#8217;s center of gravity is moving. A useful data point for any board thinking about its own CISO bench depth and what the next generation of the role looks like.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.calcalistech.com\/ctechnews\/article\/sje1ashgge\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>16. State CISO confidence drops from 48% to 22%, NASCIO-Deloitte 2026 study finds<\/h4>\n<p class=\"meta\">Cybersecurity Insiders &middot; May 31, 2026<\/p>\n<p>The 2026 NASCIO-Deloitte Cybersecurity Study \u2014 covering the CISOs of all 50 states, DC, and the US Virgin Islands \u2014 found high confidence in protecting public data has collapsed from 48% in 2022 to just 22%, a 26-point drop. The drivers will be familiar to any leader: 78% name third-party breaches as the top anticipated threat, 55% flag AI-enabled attacks, and 16% reported budget cuts in 2026 (versus none in 2024), all compounded by the shift of the MS-ISAC from federal funding to a fee-based membership model. The public-sector specifics differ, but the arithmetic \u2014 more sophisticated threats, less external backstop, flat-to-declining budgets \u2014 is the same squeeze private-sector CISOs are modeling. The study&#8217;s own remedy, making effectiveness metrics the top 2026 initiative, doubles as a board-reporting cue for everyone else.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.cybersecurity-insiders.com\/state-ciso-confidence-nascio-deloitte-2026-study\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>17. KPMG 2026 cybersecurity report names non-human identities as a critical CISO problem<\/h4>\n<p class=\"meta\">Cybersecurity Insiders &middot; May 31, 2026<\/p>\n<p>KPMG&#8217;s 2026 cybersecurity considerations report \u2014 drawn from 20+ KPMG cyber leaders plus senior executives at Google, Microsoft, Palo Alto Networks, and ServiceNow \u2014 names eight CISO priorities and puts non-human identity governance at the load-bearing center. The argument: AI agents, service accounts, and machine credentials now outnumber human users in most enterprises, and identity practices built around human onboarding and quarterly attestation do not survive that ratio. The other seven considerations (autonomous-security workforce, geopolitics and resilience, AI safety, IT\/OT hyperconnectivity, post-quantum cryptography migration, supply-chain detection and response, and a broadened CISO mandate) all rest on whether the identity layer can name what is acting and on whose behalf. For leaders, KPMG&#8217;s sequencing is the takeaway \u2014 inventory non-human identities first, because the AI-safety and autonomous-SOC initiatives depend on it.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.cybersecurity-insiders.com\/kpmg-2026-cybersecurity-report-ciso-priorities\/\">Read the article<\/a>\n            <\/div>\n<div class=\"article\">\n<h4>18. Cyber Insights 2026: What CISOs can expect in 2026 and beyond<\/h4>\n<p class=\"meta\">SecurityWeek &middot; Cyber Insights 2026 series<\/p>\n<p>SecurityWeek&#8217;s annual Cyber Insights outlook is the strategic long-view companion to the rest of this issue. Its CISO installment argues that 2026 is the year security leaders begin dismantling architectures designed around human limitations \u2014 with agentic AI enabling investigation and response directly at the data source, reducing reliance on traditional SIEM, SOAR, and MDR. It frames the modern CISO as someone who must move fluidly between technical expert and business leader, because AI failures increasingly blur the line between a technical failure mode and a business catastrophe. The piece also flags the rise of AI-enabled malware that adapts in real time and a rapid modernization of offensive security and red teaming. A good anchor read when setting 2026 strategy against where the discipline is heading.<\/p>\n<p>              <a class=\"button\" href=\"https:\/\/www.securityweek.com\/cyber-insights-2026-what-cisos-can-expect-in-2026-and-beyond\/\">Read the article<\/a>\n            <\/div>\n<p>            <!-- Watch list --><\/p>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>BOD 26-04 ripple effects.<\/strong> Watching how quickly risk-based vulnerability management migrates from a federal directive into private-sector benchmarks, auditor expectations, and the &#8220;are we aligned?&#8221; question boards start asking.<\/li>\n<li><strong>EU CRA awareness curve.<\/strong> With two-thirds of developers still unfamiliar and a December 2027 deadline, expect a scramble around SBOM coverage and product-cybersecurity obligations \u2014 and the first concrete guidance on who carries liability.<\/li>\n<li><strong>Agent governance frameworks maturing.<\/strong> The machine-identity framing of AI agents is gaining traction; watching whether NIST AI RMF and ISO\/IEC 42001 mappings consolidate into something auditors and boards will recognize as standard.<\/li>\n<li><strong>Cyber-insurance exclusion creep.<\/strong> Softening rates paired with widening carve-outs (social engineering, war, systemic cloud events) make the next renewal cycle the one to watch for where the real coverage gaps land.<\/li>\n<\/ul><\/div>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">The CISO Brief<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>June 14, 2026 &middot; Weekly Edition The CISO Brief Strategic intelligence for security leaders \u2014 board reporting, regulatory shifts, AI governance, and the changing economics of the CISO seat. At a glance This week&#8217;s brief circles one structural gap: AI is being adopted far faster than it is being governed,&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,12,42],"tags":[],"class_list":["post-5333","post","type-post","status-publish","format-standard","hentry","category-editorial","category-regulations","category-security-industry-news"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5333","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5333"}],"version-history":[{"count":0,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5333\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5333"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5333"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}