{"id":5612,"date":"2026-08-02T16:22:02","date_gmt":"2026-08-02T21:22:02","guid":{"rendered":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5612"},"modified":"2026-08-02T16:22:02","modified_gmt":"2026-08-02T21:22:02","slug":"the-ciso-brief-august-2-2026","status":"publish","type":"post","link":"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5612","title":{"rendered":"The CISO Brief \u2014 August 2, 2026"},"content":{"rendered":"<style>\n.single .entry-title,\n.single .entry-header .entry-title,\n.single .post-title,\n.single header.entry-header h1,\n.single h1.entry-title,\n.single .page-title,\n.post-template-default h1.entry-title,\n.post-template-default .entry-header,\narticle .entry-header,\narticle .entry-title { display: none !important; }\n.single .entry-header { margin: 0 !important; padding: 0 !important; }\n.single .entry-content { margin-top: 0 !important; padding-top: 0 !important; }\n<\/style>\n<table role=\"presentation\" class=\"wrapper\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"100%\">\n<tr>\n<td align=\"center\">\n<table role=\"presentation\" class=\"container\" cellpadding=\"0\" cellspacing=\"0\" border=\"0\" width=\"680\">\n<p>        <!-- Banner --><\/p>\n<tr>\n<td class=\"banner\" style=\"background-color:#0f172a;background:linear-gradient(135deg,#0f172a 0%,#1e3a8a 55%,#2563eb 100%);padding:36px 32px;color:#ffffff;\">\n<p class=\"date\" style=\"color:#ffffff !important;\">August 2, 2026 &middot; Weekly Edition<\/p>\n<h1 style=\"color:#ffffff !important;\">The CISO Brief<\/h1>\n<p class=\"tagline\" style=\"color:#ffffff !important;\">AI governance stops being a slide and becomes the CISO&#8217;s operational problem &mdash; shadow agents reaching into finance systems, boards misaligned on risk, and a record breach bill to prove the cost; regulation arrives on real dates as the EU AI Act&#8217;s transparency rules take effect and Washington moves on post-quantum, open-source software, and a two-year purge of legacy federal VPNs; and the role itself keeps shifting, from the CISO-as-CFO argument to a marquee hire at Meta. A week about who owns the risk when the tools move faster than the org chart.<\/p>\n<\/td>\n<\/tr>\n<p>        <!-- At a glance --><\/p>\n<tr>\n<td class=\"content\">\n<h2>At a glance<\/h2>\n<p>The week&#8217;s center of gravity was AI governance moving from principle to practice &mdash; and landing squarely on the security chief. An Okta study reported that most CISOs no longer feel they can fully govern the AI agents already on their networks, with shadow AI and leadership misalignment named as the two biggest obstacles; Cybersecurity Dive separately found companies now fear AI risk more than conventional cyber threats. CIO&#8217;s dissection of why AI governance keeps failing lands on the same fault line: the gap isn&#8217;t missing policies, it&#8217;s the absence of controls that actually bind at runtime. And Pathlock put a number on the stakes &mdash; roughly four in five organizations have no dedicated AI-governance function even as agents begin creating records, approving transactions and reaching into finance, HR and procurement systems. The through-line is uncomfortable for CISOs: they are being handed accountability for autonomous systems they can neither fully see nor reliably constrain.<\/p>\n<p>The cost side of that ledger got sharper. IBM&#8217;s 2026 Cost of a Data Breach report put the global average at $4.99M, with AI-enabled attacks running higher and ungoverned AI emerging as its own risk category &mdash; the empirical backstop for every governance argument a CISO will take to the board this quarter. That framing matters because regulation is no longer hypothetical: the European Commission began enforcing the AI Act&#8217;s transparency obligations on August 2, a hard date that turns model-disclosure duties into compliance reality, while a coalition of US tech giants pressed Washington to keep AI development open and transparent rather than locked down. The regulatory agenda widened on the federal side too &mdash; the White House flagged supply-chain strain in the post-quantum race, CISA issued open-source software security guidance for agencies, and Senator Ron Wyden demanded a two-year purge of legacy, internet-facing VPNs across the federal government, backed by a binding CISA directive and zero-trust procurement rules that would reshape the vendor market.<\/p>\n<p>Board-level risk kept its longer horizon in view. Forbes argued AI and quantum are now joint inputs to enterprise cyber risk that boards and CISOs must prepare for together, and the Coast Guard&#8217;s new maritime cybersecurity rules offered transferable lessons for any leader building a critical-infrastructure security program. Underneath it, the foundational thread returned to the role itself: CSO Online&#8217;s case that the modern CISO is becoming the next CFO, an iTWire piece asking who actually owns AI risk between the CISO and CFO, and Cybersecurity Insiders&#8217; finding that CISO personal-liability fears have nearly doubled as AI-governance mandates expand &mdash; accountability rising faster than authority, again.<\/p>\n<p>The people carrying that accountability were in motion. Meta hired Assaf Keren, a veteran of Qualtrics and PayPal, as its new CISO, replacing Guy Rosen after 13 years; a Dark Reading interview with former Citigroup CISO Brian Blauner distilled what actually makes a security leader effective; and the Solana Foundation&#8217;s new CISO warned that AI is making crypto scams markedly more convincing. On defense compliance, the Pentagon&#8217;s suspension of CMMC Phase 2 and the 60-day review behind it left contractors in an awkward in-between &mdash; obligations paused but not lifted, and a new kind of planning risk in their place. Taken together, it was a week that asked the same question in five registers: when the tools outrun the org chart, who is on the hook?<\/p>\n<p>            <!-- Topic map --><\/p>\n<div class=\"topic-map\">\n              <img decoding=\"async\" src=\"https:\/\/www.cybersecurityinstitute.com\/blog\/wp-content\/uploads\/2026\/08\/topic-map-ciso-2026-08-02-1.png\" alt=\"Topic map of this week's CISO Brief themes\" loading=\"eager\"><\/p>\n<p class=\"caption\">This week&#8217;s topic map &mdash; AI governance and AI-risk ownership landing on the CISO (shadow AI, governance gaps, AI agents reaching into finance workflows), the record $4.99M breach cost as the empirical backstop, the EU AI Act&#8217;s August 2 transparency enforcement and the US push for AI openness, the federal policy cluster (post-quantum supply-chain race, CISA open-source guidance, Senator Wyden&#8217;s legacy-VPN purge and zero-trust procurement), board-level AI-plus-quantum risk and the Coast Guard&#8217;s sector rules, the evolving role (CISO-as-CFO, personal liability), the Meta CISO hire, and the CMMC Phase 2 suspension.<\/p>\n<p>              <!-- INTERACTIVE_MAP_LINK_START --><\/p>\n<p style=\"margin:10px 0 0;text-align:center;\"><a href=\"https:\/\/www.cybersecurityinstitute.com\/blog\/?p=5611\" target=\"_blank\" rel=\"noopener\" style=\"display:inline-block;padding:8px 18px;background-color:#0f172a;color:#ffffff !important;text-decoration:none;border-radius:6px;font-size:13px;font-weight:600;\">View interactive topic map &rarr;<\/a><\/p>\n<p><!-- INTERACTIVE_MAP_LINK_END -->\n            <\/div>\n<p>            <!-- Article index --><\/p>\n<h2>Article index<\/h2>\n<h3>Weekly News<\/h3>\n<h4>AI governance and risk land on the CISO<\/h4>\n<div class=\"cluster-intro\">Shadow agents, board misalignment, and governance that fails at runtime &mdash; security leaders are being made accountable for AI they can neither fully see nor constrain, right as agents reach into business-critical systems.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>1. <a href=\"https:\/\/www.cybersecuritydive.com\/news\/ai-governance-shadow-cisos-okta\/826587\/\">Shadow AI, leadership resistance make AI governance tough for worried CISOs<\/a><\/td>\n<td class=\"src\">Cybersecurity Dive<\/td>\n<td class=\"dt\">Jul 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>2. <a href=\"https:\/\/www.cybersecuritydive.com\/news\/ai-cybersecurity-threats-business-fears\/826352\/\">Companies fear AI risks more than common cybersecurity threats<\/a><\/td>\n<td class=\"src\">Cybersecurity Dive<\/td>\n<td class=\"dt\">Jul 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>3. <a href=\"https:\/\/www.cio.com\/article\/4201343\/why-ai-governance-is-failing-and-what-actually-works.html\">Why AI governance is failing &mdash; and what actually works<\/a><\/td>\n<td class=\"src\">CIO<\/td>\n<td class=\"dt\">Jul 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>4. <a href=\"https:\/\/www.csoonline.com\/article\/4203384\/ai-agents-gain-access-to-financial-workflows-amid-growing-governance-gaps.html\">AI agents gain access to financial workflows amid growing governance gaps<\/a><\/td>\n<td class=\"src\">CSO Online<\/td>\n<td class=\"dt\">Jul 30, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>The price of ungoverned AI<\/h4>\n<div class=\"cluster-intro\">The empirical backstop for every governance argument: breach costs at a record high, with AI both raising the bill and creating a new risk category of its own.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>5. <a href=\"https:\/\/www.cybersecuritydive.com\/news\/data-breach-costs-ai-governance-ibm\/826463\/\">As data breaches grow costlier, ungoverned AI creates new risks<\/a><\/td>\n<td class=\"src\">Cybersecurity Dive<\/td>\n<td class=\"dt\">Jul 29, 2026<\/td>\n<\/tr>\n<tr>\n<td>6. <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/30\/ibm-cost-of-a-data-breach-2026\/\">Cost of a data breach 2026 averaged $4.99M; AI attacks ran higher<\/a><\/td>\n<td class=\"src\">Help Net Security<\/td>\n<td class=\"dt\">Jul 30, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Regulation, transparency and federal policy<\/h4>\n<div class=\"cluster-intro\">Compliance stops being theoretical &mdash; the EU AI Act&#8217;s transparency rules take effect on a fixed date, while Washington moves on AI openness, post-quantum supply chains, open-source software, and a mandated purge of legacy federal VPNs.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>7. <a href=\"https:\/\/www.cybersecuritydive.com\/news\/ai-open-source-weights-tech-industry-promote\/826240\/\">Tech industry giants say US must embrace openness, transparency in AI<\/a><\/td>\n<td class=\"src\">Cybersecurity Dive<\/td>\n<td class=\"dt\">Jul 27, 2026<\/td>\n<\/tr>\n<tr>\n<td>8. <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/news\/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august\">Commission starts enforcing AI Act rules and new transparency requirements on 2 August<\/a><\/td>\n<td class=\"src\">European Commission<\/td>\n<td class=\"dt\">Aug 1, 2026<\/td>\n<\/tr>\n<tr>\n<td>9. <a href=\"https:\/\/cyberscoop.com\/white-house-quantum-supply-chain-challenges\/\">White House: supply-chain challenges loom large in the post-quantum race<\/a><\/td>\n<td class=\"src\">CyberScoop<\/td>\n<td class=\"dt\">Jul 29, 2026<\/td>\n<\/tr>\n<tr>\n<td>10. <a href=\"https:\/\/cyberscoop.com\/cisa-open-source-software-security-guidance\/\">CISA issues open-source software security recommendations for federal agencies<\/a><\/td>\n<td class=\"src\">CyberScoop<\/td>\n<td class=\"dt\">Jul 30, 2026<\/td>\n<\/tr>\n<tr>\n<td>11. <a href=\"https:\/\/cyberscoop.com\/wyden-calls-for-federal-legacy-vpn-purge-zero-trust\/\">Sen. Wyden urges feds to purge legacy public-facing VPNs<\/a><\/td>\n<td class=\"src\">CyberScoop<\/td>\n<td class=\"dt\">Jul 27, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Board-level risk: quantum and critical infrastructure<\/h4>\n<div class=\"cluster-intro\">The longer horizon boards must plan for now &mdash; AI and quantum as joint cyber-risk inputs, and maritime sector rules with lessons that travel to any critical-infrastructure program.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>12. <a href=\"https:\/\/www.forbes.com\/sites\/chuckbrooks\/2026\/07\/28\/ai-and-quantum-are-impacting-cyber-risk-boards--cisos-must-prepare\/\">AI And Quantum Are Impacting Cyber Risk. Boards And CISOs Must Prepare<\/a><\/td>\n<td class=\"src\">Forbes<\/td>\n<td class=\"dt\">Jul 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>13. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/coast-guards-cybersecurity-rules-lessons-cisos\">Coast Guard&#8217;s New Cybersecurity Rules Offer Lessons for CISOs<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Jul 29, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>The CISO chair<\/h4>\n<div class=\"cluster-intro\">What effective security leadership looks like, and the new-role realities &mdash; from a veteran&#8217;s playbook to an incoming foundation CISO&#8217;s warning about AI-supercharged scams.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>14. <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/former-citigroup-ciso-blauner-great-security-leader\">Former Citigroup CISO Blauner on What Makes A Great Security Leader<\/a><\/td>\n<td class=\"src\">Dark Reading<\/td>\n<td class=\"dt\">Jul 28, 2026<\/td>\n<\/tr>\n<tr>\n<td>15. <a href=\"https:\/\/www.coindesk.com\/tech\/2026\/07\/31\/solana-foundation-s-new-ciso-warns-ai-is-making-crypto-scams-more-convincing\">Solana Foundation&#8217;s new CISO warns AI is making crypto scams more convincing<\/a><\/td>\n<td class=\"src\">CoinDesk<\/td>\n<td class=\"dt\">Aug 1, 2026<\/td>\n<\/tr>\n<\/table>\n<h3>Foundational Reading<\/h3>\n<h4>The evolving role and its liability<\/h4>\n<div class=\"cluster-intro\">The strategic reframing of the job &mdash; the CISO as a CFO-style steward of enterprise risk, the unresolved question of who owns AI risk, and personal-liability fears rising alongside AI-governance mandates.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>16. <a href=\"https:\/\/www.csoonline.com\/article\/4193375\/the-modern-ciso-is-becoming-the-next-cfo.html\">The modern CISO is becoming the next CFO<\/a><\/td>\n<td class=\"src\">CSO Online<\/td>\n<td class=\"dt\">Jul 7, 2026<\/td>\n<\/tr>\n<tr>\n<td>17. <a href=\"https:\/\/www.cybersecurity-insiders.com\/ciso-personal-liability-ai-governance\/\">CISO Personal Liability Fears Nearly Double as AI Governance Mandates Expand<\/a><\/td>\n<td class=\"src\">Cybersecurity Insiders<\/td>\n<td class=\"dt\">Jul 17, 2026<\/td>\n<\/tr>\n<tr>\n<td>18. <a href=\"https:\/\/itwire.com\/guest-articles\/guest-opinion\/the-ciso-cfo-and-ai-who-owns-the-risk-now\">The CISO, CFO &amp; AI: Who Owns the Risk Now?<\/a><\/td>\n<td class=\"src\">iTWire<\/td>\n<td class=\"dt\">Jul 23, 2026<\/td>\n<\/tr>\n<\/table>\n<h4>Defense compliance and leadership moves<\/h4>\n<div class=\"cluster-intro\">Contractors caught in a compliance limbo as CMMC Phase 2 is paused mid-rollout, and a marquee CISO hire at Meta.<\/div>\n<table class=\"index-table\">\n<tr>\n<th>Article<\/th>\n<th>Source<\/th>\n<th>Published<\/th>\n<\/tr>\n<tr>\n<td>19. <a href=\"https:\/\/www.techrepublic.com\/article\/news-cmmc-pause-ai-governance-defense-contractors\/\">CMMC Assessment Pause Leaves Defense Contractors Facing a New Risk<\/a><\/td>\n<td class=\"src\">TechRepublic<\/td>\n<td class=\"dt\">Jul 15, 2026<\/td>\n<\/tr>\n<tr>\n<td>20. <a href=\"https:\/\/federalnewsnetwork.com\/cybersecurity\/2026\/07\/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program\/\">Pentagon suspends CMMC Phase 2 requirements, launches review of program<\/a><\/td>\n<td class=\"src\">Federal News Network<\/td>\n<td class=\"dt\">Jul 14, 2026<\/td>\n<\/tr>\n<tr>\n<td>21. <a href=\"https:\/\/thenextweb.com\/news\/meta-hires-assaf-keren-ciso-qualtrics-paypal\">Meta hires Assaf Keren as new CISO, replacing Guy Rosen<\/a><\/td>\n<td class=\"src\">The Next Web<\/td>\n<td class=\"dt\">Jul 22, 2026<\/td>\n<\/tr>\n<\/table>\n<p>            <!-- Detailed write-ups --><\/p>\n<h2>Detailed write-ups<\/h2>\n<div class=\"article\">\n<h4>1. AI governance moves from slideware to the CISO&#8217;s operational problem<\/h4>\n<p class=\"meta\">Cybersecurity Dive &middot; CIO &middot; CSO Online &middot; July 28&ndash;30, 2026<\/p>\n<p>Three reports this week converged on the same conclusion: the AI-governance conversation has left the strategy deck and become an operational exposure the CISO owns. An Okta study reported by Cybersecurity Dive found that a majority of security leaders no longer believe they can fully govern the AI agents already running on their networks &mdash; shadow AI (tools adopted without review) and leadership resistance to guardrails were the two obstacles named most often. A companion Cybersecurity Dive piece found the anxiety has overtaken conventional threats outright: organizations now report fearing AI risk more than the malware and intrusion categories they have spent decades building programs around. CIO&#8217;s analysis of why AI governance keeps failing lands the diagnosis precisely &mdash; the shortfall is not a lack of written policy but the absence of controls that actually enforce at runtime, where an autonomous agent makes decisions faster than any review board can convene.<\/p>\n<p>CSO Online&#8217;s reporting on a Pathlock study gave the abstraction teeth. Roughly four in five organizations have no dedicated AI-governance function, even as agents are increasingly wired into finance, HR, procurement and other business-critical systems &mdash; creating records, approving transactions, and in some cases acting with standing privileges that no human is actively supervising. For a CISO the practical takeaway is that traditional access governance, built to answer &ldquo;who can do what,&rdquo; is the wrong shape for agents that answer to a prompt and a policy rather than a login. The defensible posture is the same one that worked for cloud and SaaS a decade ago, adapted for autonomy: a live inventory of every agent and its scope, least-privilege and time-boxed credentials, runtime policy enforcement rather than one-time sign-off, and continuous monitoring that can reconstruct what an agent actually did after the fact.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.cybersecuritydive.com\/news\/ai-governance-shadow-cisos-okta\/826587\/\">Cybersecurity Dive (shadow AI \/ Okta)<\/a> &middot; <a href=\"https:\/\/www.cybersecuritydive.com\/news\/ai-cybersecurity-threats-business-fears\/826352\/\">Cybersecurity Dive (AI fears)<\/a> &middot; <a href=\"https:\/\/www.cio.com\/article\/4201343\/why-ai-governance-is-failing-and-what-actually-works.html\">CIO<\/a> &middot; <a href=\"https:\/\/www.csoonline.com\/article\/4203384\/ai-agents-gain-access-to-financial-workflows-amid-growing-governance-gaps.html\">CSO Online (Pathlock)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>2. The record breach bill &mdash; and AI as its own line item<\/h4>\n<p class=\"meta\">Cybersecurity Dive &middot; Help Net Security &middot; July 29&ndash;30, 2026<\/p>\n<p>IBM&#8217;s 2026 Cost of a Data Breach report gave CISOs the number they will cite in every budget conversation this year: a global average of $4.99M per breach, another record, with AI-enabled attacks running measurably higher than the mean. Just as important as the headline figure is the report&#8217;s treatment of AI as a distinct risk category rather than a modifier &mdash; ungoverned AI adoption is now associated with its own cost premium, the empirical mirror image of the governance-gap findings elsewhere this week. Cybersecurity Dive&#8217;s read of the data draws the line explicitly: the organizations moving fastest to deploy AI without controls are the ones absorbing the steepest breach economics when something goes wrong.<\/p>\n<p>For a security leader, the value of the report is less the shock of the total than its usefulness as leverage. A board that treats AI-governance controls as friction on innovation responds differently to a defensible, third-party dollar figure attached to the alternative &mdash; and the report converts &ldquo;we should govern our AI&rdquo; from a security preference into a quantified risk-reduction argument with a return attached. The practical move is to pair the breach-cost data with the organization&#8217;s own AI inventory: which deployments carry the highest blast radius, which have the weakest controls, and what the modeled exposure looks like if one of them is the entry point. That is the conversation the number is built to start.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.cybersecuritydive.com\/news\/data-breach-costs-ai-governance-ibm\/826463\/\">Cybersecurity Dive<\/a> &middot; <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/30\/ibm-cost-of-a-data-breach-2026\/\">Help Net Security<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>3. Regulation arrives on real dates: the EU AI Act, US openness, and a federal policy surge<\/h4>\n<p class=\"meta\">European Commission &middot; Cybersecurity Dive &middot; CyberScoop &middot; July 27&ndash;August 1, 2026<\/p>\n<p>The AI-governance debate stopped being hypothetical on a specific day. The European Commission began enforcing the AI Act&#8217;s transparency obligations on August 2, turning model-disclosure and documentation duties into live compliance rather than a future deadline &mdash; a hard date that gives multinational CISOs an immediate, auditable obligation to map. In counterpoint, a coalition of major US technology companies pressed Washington to keep AI development open and transparent, arguing against restrictions that would push capability behind closed doors; the two stories together frame the strategic tension of the year, between disclosure-driven governance and openness-driven governance, that every enterprise AI policy now has to take a position within.<\/p>\n<p>The US federal agenda widened on the same beat. CyberScoop reported the White House flagging supply-chain strain in the post-quantum migration race &mdash; a reminder that PQC is now a logistics and procurement problem, not just a cryptography one &mdash; and, separately, CISA issuing open-source software security recommendations for federal agencies, formalizing expectations that will cascade to contractors and, eventually, commercial norms. The most consequential single item may be Senator Ron Wyden&#8217;s demand that agencies purge every legacy, internet-facing VPN within two years, enforced through a binding CISA operational directive, NIST zero-trust standards, and procurement rules that would bar non-compliant network gear from federal contracts entirely. For CISOs the signal is directional and clear: the &ldquo;patch the VPN again&rdquo; era is being legislated toward zero-trust network access, and the procurement lever means vendors &mdash; and the enterprises that follow federal baselines &mdash; will feel it well beyond government.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/news\/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august\">European Commission<\/a> &middot; <a href=\"https:\/\/www.cybersecuritydive.com\/news\/ai-open-source-weights-tech-industry-promote\/826240\/\">Cybersecurity Dive<\/a> &middot; <a href=\"https:\/\/cyberscoop.com\/white-house-quantum-supply-chain-challenges\/\">CyberScoop (post-quantum)<\/a> &middot; <a href=\"https:\/\/cyberscoop.com\/cisa-open-source-software-security-guidance\/\">CyberScoop (open-source)<\/a> &middot; <a href=\"https:\/\/cyberscoop.com\/wyden-calls-for-federal-legacy-vpn-purge-zero-trust\/\">CyberScoop (Wyden VPN purge)<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>4. Board-level horizon: AI and quantum as joint risk, and lessons from the waterfront<\/h4>\n<p class=\"meta\">Forbes &middot; Dark Reading &middot; July 28&ndash;29, 2026<\/p>\n<p>Forbes made the case that boards can no longer treat AI risk and quantum risk as separate agenda items filed under &ldquo;emerging&rdquo; &mdash; they are converging inputs to enterprise cyber risk that require coordinated preparation now. The argument for CISOs is a sequencing one: the &ldquo;harvest now, decrypt later&rdquo; threat means data with a long confidentiality lifespan is already exposed to future quantum decryption, while AI is simultaneously accelerating the discovery and exploitation of the vulnerabilities that expose that data in the first place. Presented to a board, the two risks reinforce each other into a single planning mandate &mdash; cryptographic inventory and migration on one axis, AI-risk governance on the other, both started before either threat fully matures.<\/p>\n<p>Dark Reading&#8217;s look at the Coast Guard&#8217;s new maritime cybersecurity rules offered a more grounded companion. The specifics are sector-bound &mdash; vessels, ports, and the operational technology that runs them &mdash; but the structure of the rules (mandated cybersecurity plans, designated accountable officers, incident-reporting obligations) is a template any CISO standing up a critical-infrastructure or OT-adjacent program can learn from. The transferable lesson is that prescriptive, sector-specific regulation is increasingly where the practical baselines are being written first; leaders in adjacent industries can read the maritime rules as a preview of the accountability structures likely headed their way.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.forbes.com\/sites\/chuckbrooks\/2026\/07\/28\/ai-and-quantum-are-impacting-cyber-risk-boards--cisos-must-prepare\/\">Forbes<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/coast-guards-cybersecurity-rules-lessons-cisos\">Dark Reading<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>5. The role keeps shifting: the CISO-as-CFO argument, rising liability, and a Meta hire<\/h4>\n<p class=\"meta\">CSO Online &middot; iTWire &middot; Cybersecurity Insiders &middot; The Next Web &middot; July 7&ndash;23, 2026<\/p>\n<p>The foundational reading this week circled the shape of the job. CSO Online&#8217;s argument that the modern CISO is becoming the next CFO captures a real trajectory: as security becomes a board-level financial risk, the role is expected to speak in quantified exposure, portfolio trade-offs and return-on-control terms rather than technical status &mdash; a stewardship posture that looks far more like the finance chair than the old firewall-and-SOC remit. iTWire pushed the same idea to its friction point, asking who actually owns AI risk when it straddles the CISO and the CFO, and Cybersecurity Insiders supplied the pressure behind it: CISO personal-liability fears have nearly doubled as AI-governance mandates expand, formalizing the individual accountability that used to be implicit. The composite picture is a role gaining strategic altitude and legal exposure at the same time &mdash; more influence, more risk, and not always more authority to match.<\/p>\n<p>The people filling the seat are turning over accordingly. Meta hired Assaf Keren, previously a senior security leader at Qualtrics and PayPal, as its new CISO, replacing Guy Rosen after a 13-year run &mdash; a marquee move that signals how large platforms are recruiting for the broader, risk-and-governance-heavy version of the job. A Dark Reading interview with former Citigroup CISO Brian Blauner distilled the throughline into leadership advice: the effective security chief is measured less by technical depth than by the ability to translate risk into business terms and build durable trust with the board. And at the newer edge of the profession, the Solana Foundation&#8217;s incoming CISO warned that AI is making crypto and social-engineering scams markedly more convincing &mdash; a reminder that even as the role rises strategically, the front-line threat it answers for keeps getting harder.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.csoonline.com\/article\/4193375\/the-modern-ciso-is-becoming-the-next-cfo.html\">CSO Online<\/a> &middot; <a href=\"https:\/\/itwire.com\/guest-articles\/guest-opinion\/the-ciso-cfo-and-ai-who-owns-the-risk-now\">iTWire<\/a> &middot; <a href=\"https:\/\/www.cybersecurity-insiders.com\/ciso-personal-liability-ai-governance\/\">Cybersecurity Insiders<\/a> &middot; <a href=\"https:\/\/thenextweb.com\/news\/meta-hires-assaf-keren-ciso-qualtrics-paypal\">The Next Web<\/a> &middot; <a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/former-citigroup-ciso-blauner-great-security-leader\">Dark Reading<\/a> &middot; <a href=\"https:\/\/www.coindesk.com\/tech\/2026\/07\/31\/solana-foundation-s-new-ciso-warns-ai-is-making-crypto-scams-more-convincing\">CoinDesk<\/a><\/p>\n<\/p><\/div>\n<div class=\"article\">\n<h4>6. CMMC Phase 2 paused: contractors in a compliance limbo<\/h4>\n<p class=\"meta\">TechRepublic &middot; Federal News Network &middot; July 14&ndash;15, 2026<\/p>\n<p>The Pentagon suspended CMMC Phase 2 requirements and launched a 60-day review of the program, and the pause created a subtler risk than the mandate itself did. Federal News Network reported the suspension as a genuine reset &mdash; obligations that contractors had been racing to meet are on hold pending a rethink &mdash; while TechRepublic&#8217;s framing captured the trap: a paused mandate is not a cancelled one, and defense contractors now face planning uncertainty on top of the original compliance burden. Do they keep investing to meet a standard that may change, or stand down and risk a scramble if the requirements return largely intact?<\/p>\n<p>For CISOs at contractors and their subcontractors, the defensible read is to treat the pause as a timing change rather than a reprieve. The underlying expectation &mdash; demonstrable cybersecurity maturity as a condition of defense work &mdash; is not going away, and the controls that CMMC codified are good practice regardless of the certification calendar. The prudent posture is to continue the substantive security work while deferring only the certification-specific spend that a revised program might render moot, and to watch the 60-day review for whether the requirements tighten, loosen, or simply slip to a later date. In an in-between period, documented, standards-aligned progress is what protects both the contract and the security chief who signed off on the plan.<\/p>\n<p style=\"font-size:13px;color:#6b7280;margin:0;\">Sources: <a href=\"https:\/\/www.techrepublic.com\/article\/news-cmmc-pause-ai-governance-defense-contractors\/\">TechRepublic<\/a> &middot; <a href=\"https:\/\/federalnewsnetwork.com\/cybersecurity\/2026\/07\/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program\/\">Federal News Network<\/a><\/p>\n<\/p><\/div>\n<p>            <!-- Watch list --><\/p>\n<div class=\"watchlist\">\n<h2>On our watch list<\/h2>\n<ul>\n<li><strong>Whether AI-agent governance gets real controls.<\/strong> Watching if the shadow-AI and financial-workflow findings push organizations from written policy toward runtime enforcement &mdash; live agent inventories, least-privilege scoping, and monitoring that can reconstruct what an agent actually did.<\/li>\n<li><strong>How the IBM breach-cost number gets used.<\/strong> Watching whether the record $4.99M figure (and its AI premium) actually shifts board budgets toward AI-governance controls, or becomes another stat that gets nodded at and filed.<\/li>\n<li><strong>EU AI Act enforcement in practice.<\/strong> Watching the first transparency-obligation actions under the August 2 rules &mdash; how aggressively they&#8217;re enforced, and how quickly US-headquartered enterprises map their exposure.<\/li>\n<li><strong>Wyden&#8217;s VPN purge and the procurement lever.<\/strong> Watching whether a binding CISA directive and zero-trust procurement rules materialize &mdash; and how far the vendor-attestation requirement reshapes the network-access market beyond government.<\/li>\n<li><strong>Post-quantum as a supply-chain problem.<\/strong> Watching whether the White House&#8217;s supply-chain warning translates into concrete procurement and inventory mandates, and how far behind the median organization turns out to be once migration is actually measured.<\/li>\n<li><strong>CISO personal liability moving from fear to precedent.<\/strong> Watching for the first enforcement actions or board policies that formally name the security chief as the accountable owner for AI harm &mdash; the point where the doubled liability fear stops being a survey result.<\/li>\n<li><strong>The CMMC 60-day review outcome.<\/strong> Watching whether Phase 2 requirements tighten, loosen, or simply slip &mdash; and how contractors sequence their security spend through the uncertainty.<\/li>\n<\/ul><\/div>\n<\/td>\n<\/tr>\n<p>        <!-- Footer --><\/p>\n<tr>\n<td class=\"footer\">\n<p class=\"brand\">The CISO Brief<\/p>\n<p>A weekly intelligence bulletin from Security Radar LLC.<br \/>\n            Curated by Paul Davis &middot; <a href=\"mailto:paul.davis@security-radar.com\">paul.davis@security-radar.com<\/a><\/p>\n<p>&copy; 2026 Security Radar LLC. All rights reserved.<\/p>\n<p>Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.<\/p>\n<p>*|LIST:ADDRESS|*<\/p>\n<p><a href=\"*|ARCHIVE|*\">View this email in your browser<\/a> &middot; <a href=\"*|UNSUB|*\">Unsubscribe<\/a><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>August 2, 2026 &middot; Weekly Edition The CISO Brief AI governance stops being a slide and becomes the CISO&#8217;s operational problem &mdash; shadow agents reaching into finance systems, boards misaligned on risk, and a record breach bill to prove the cost; regulation arrives on real dates as the EU AI&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,12,42],"tags":[],"class_list":["post-5612","post","type-post","status-publish","format-standard","hentry","category-editorial","category-regulations","category-security-industry-news"],"_links":{"self":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5612","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5612"}],"version-history":[{"count":1,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5612\/revisions"}],"predecessor-version":[{"id":5636,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5612\/revisions\/5636"}],"wp:attachment":[{"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5612"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5612"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cybersecurityinstitute.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5612"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}