Mission-critical conversations on AI and cybersecurity
Tuesday, October 13, 2026
11 a.m. – Noon PT
Online
The USC Annenberg Center on Communication Leadership and Policy (CCLP) will host an AI forum titled “Artificial Intelligence: Mission-Critical Conversations on AI and Cybersecurity.” This online-only event will feature Roland Trope, Partner at Trope and Schramm LLP.
This program is open to all eligible individuals. USC Annenberg operates all of its programs and activities consistent with the University’s Notice of Non-Discrimination. Eligibility is not determined based on race, sex, ethnicity, sexual orientation, or any other prohibited factor.
Sep 1, 2026 · via annenberg.usc.edu
In December 2025, when Dooshima Dabo’Adzuana completed her Master of Science in Cybersecurity, it was the natural next step in a career focused on governance and strategy. Today, she brings her strategic perspective to Microsoft as part of the Corporate, External and Legal Affairs, or CELA, group. Working alongside colleagues whose expertise spans national security, cybersecurity, government affairs and global institutions, the group focuses on technology’s ability to improve lives and advance solutions to complex global problems, shaping a more secure and inclusive digital future. Global roots and the path to cyber diplomacy Growing up in Uganda and Nigeria, Dabo’Adzuana established a global foundation early on, earning a bachelor’s degree in management from the University of London. Her interest in cybersecurity began while working at AXA, a French multinational insurance and financial services corporation, during a major data privacy regulation transformation. While her team navigated strict compliance timelines and high-consequence operational shifts, Dabo’Adzuana recognized a compelling discipline that required a blend of negotiation, systemic foresight and behavioral leadership. This interest led her to cyber diplomacy today. “Cyber diplomacy is an emerging field in international security that facilitates international cooperation frameworks, norms of behavior, information sharing and trust-building among industries and nations,” Dabo’Adzuana said. “At its core, it recognizes that new communication technologies offer unprecedented ways to interact with a wider public within an interdependent global network. Cyber diplomacy allows us to address digital opportunities and challenges head-on ensuring tech companies, governments and civil society can collaboratively safeguard digital assets.” She referenced this Georgetown University article for further explanation. Driven to deepen her understanding of the field, Dabo’Adzuana was selected for a prestigious cyber diplomacy fellowship for women hosted by the International Telecommunication Union, or ITU, focusing on technical and policy-focused training. Recognizing that long-term impact required a multidisciplinary academic background,
Sep 1, 2026 · via boisestate.edu
EPA Announces $5.2 Million to Help Protect Drinking Water in California from Cyberattacks and Extreme Weather Events SAN FRANCISCO, Calif. — Today, U.S. Environmental Protection Agency (EPA) announced $5,194,030 in grant funding for midsize and large drinking water systems in California to help protect them from cybersecurity threats and improve resiliency against extreme weather events. This funding, through the Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability grant program, will support four projects in California and affirm EPA’s commitment to ensuring all Americans have access to clean and safe drinking water. “Ensuring that the water coming out of Americans’ taps is safe is a top priority for us at EPA, as our agency is charged with protecting human health,” said EPA Pacific Southwest Regional Administrator Mike Martucci. “This funding will help cities across California safeguard their water supplies in the face of both increasingly frequent cyberattacks and natural disasters that can impact drinking water systems.” The Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability Grant Program supports building resilience against cyberattacks and natural hazards to strengthen vital water infrastructure across the country. Cyberattacks on critical water infrastructure have increased significantly, including high-profile attacks this year targeting more than 100 drinking water and wastewater systems across 12 states. At the same time, water infrastructure must have built-in resiliency to withstand natural hazards, such as wildfires, hurricanes, earthquakes, and flooding so they can continue their mission to deliver safe water uninterrupted to the communities they serve. Awardees for this funding include public water systems that serve a population of 10,000 people or more. EPA anticipates awarding federal grants to these recipients in California after legal and administrative requirements are satisfied: - City of San Diego, CA – $2,375,000 to address natural hazard and cybersecurity vulnerabilities through Programmable Logic
Sep 1, 2026 · via epa.gov
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Sep 1, 2026 · via youtube.com
For decades, advanced cyber capabilities have remained concentrated among nation-state threat actors and sophisticated financially motivated cybercriminals.
Frontier AI models are beginning to change that equation, making powerful cyber capabilities more accessible and easier to deploy.
Meanwhile, attackers are gaining access to increasingly powerful cyber capabilities.
The result is a growing imbalance that can shape the next cyber crisis.
Advanced AI systems are becoming increasingly capable of identifying software vulnerabilities, chaining exploits together and accelerating offensive cyber techniques.
Sep 1, 2026 · via ibm.com
McCrary Institute, U.S. Chamber of Commerce call for a streamlined approach to federal cyber regulations Published: Aug 31, 2026 12:40 PM By Staff report WASHINGTON – The McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University and the U.S. Chamber of Commerce released a new report on Monday, Aug. 31, calling for a more coordinated, commonsense approach to federal cybersecurity regulations arguing that the current system prioritizes compliance over security at the detriment of the nation’s cybersecurity. The new report, “From Fragmentation to Coordination: Operationalizing U.S. Cyber Incident Reporting,” argues that the federal government needs to reduce unnecessary duplication of reporting requirements and points out that the challenge is not a lack of cybersecurity authorities — Congress has granted agencies with the authorities they need. Rather, the challenge is the lack of operational coherence needed to make those authorities work together when cyber incidents demand speed, clarity and coordination. A 2023 Department of Homeland Security report identified 52 federal cyber incident reporting requirements across 22 agencies and developed model definitions and timelines to help address the problem. A more recent Government Accountability Office report from July found that there are now 117 federal cybersecurity regulations that require reporting, 48 of which apply to private industry and they’re spread across 27 different federal agencies. In case after case, a single company may need to provide the same information to multiple federal agencies and, when they’re during a cyberattack, that duplication couldn’t come at a worse time. The report released today argues that this fragmentation is more than a regulatory burden. It is a security problem. The report also notes that the federal government already has a significant foundation on which to build. The U.S. Cybersecurity and Infrastructure Agency (CISA) is finalizing a rule established in The Cyber Incident Reporting
Aug 31, 2026 · via eng.auburn.edu
The long-held dream of having a single sign-on for public-facing federal services is one step closer. A new Office of Management and Budget memo to mandate, whenever possible, that the Login.gov platform serve as the single source for authentication and verification gives agencies their first true path toward providing a consistent way to access federal services since the E-Government days during the George W. Bush administration. “And as use of Login.gov for identity verification increases, the government realizes cost efficiencies from economies of scale and a reduction in duplicative verification costs. Increased use of Login.gov also supports the government’s security posture, enabling deployment at scale of leading technologies and security practices to prevent and respond to emerging threats,” wrote Russ Vought, OMB director, in the memo released Monday. “In the absence of a clear governmentwide strategy, agencies have deployed a range of different solutions and taken inconsistent approaches for managing digital identity, creating unnecessary burden and inefficiencies for the public and government alike. This policy enforces Login.gov as the universal sign-on for accessing public services online, enabling more seamless and efficient service delivery while safeguarding user privacy and supporting resilience against fraud and security threats.” OMB’s mandate to use Login.gov, which the General Services Administration manages, doesn’t apply to every system that touches the public, nor does it apply to those run by the Defense Department or those considered national security systems. The administration specifically called out two exemptions for public facing websites: Organizations, or individuals acting on behalf of an organization, such as businesses, state and local governments Individuals acting on behalf of another individual. “However, agencies are permitted and encouraged to expand the use of Login.gov and conform to the requirements of this memorandum for these other websites, where appropriate. Regardless of the use of Login.gov, agencies remain
Aug 31, 2026 · via federalnewsnetwork.com
| Fortinet Offers Free High School Cybersecurity Curriculum Fortinet Launches Free High School Cybersecurity Curriculum to Build the Next Generation of Cyber Defenders Fortinet Training Instituteâs New Technical High School Cybersecurity Curriculum gives U.S. secondary schools a no-cost, standards-aligned entry point into a two-year cybersecurity pathway Fortinet (FTNT) Training Institute is launching free technical cybersecurity courses for students, the Technical High School Cybersecurity Curriculum Fortinet(NASDAQ: FTNT), the global cybersecurity leader driving the convergence of networking and security, announced that the Fortinet Training Institute is launching free technical cybersecurity courses for students, the Technical High School Cybersecurity Curriculum, available to schools across the United States through the Security Awareness and Training Service. Closing the cybersecurity skills gap starts in the classroom, long before a student enters the workforce. This new curriculum allows high school students the opportunity to build foundational technical skills and knowledge and discover whether a cybersecurity career is right for them, while giving teachers a ready-to-use curriculum they donât have to build on their own. This launch reflects our commitment to making cybersecurity education accessible to every school, and more importantly, every student, regardless of existing resources. - Melonia da Gama, Director of Training and Learning Programs, Fortinet Training Institute. Offered at no cost, the curriculum builds foundational knowledge and career interest while bridging toward industry certifications, giving Career and Technical Education (CTE) leaders, district technology leaders, and teachers a way to expand cybersecurity programming without straining budgets or instructional bandwidth. The curriculum is organized in a two-course format. Each course will take a full school year, approximately 180 days, or 145 hours to complete. These two courses offer students the opportunity to develop core cybersecurity knowledge and prerequisites before learning advanced technical cybersecurity skills. A Foundational On-Ramp to a Two-Course Cybersecurity Pathway School districts face growing pressure
Aug 31, 2026 · via pipelinepub.com
Simmons takes cyber fast track thanks to UNG The path that led Zach Simmons to a career in cybersecurity is marked at every turn by the impact of the University of North Georgia (UNG). Stacy Wright, his STEM teacher at Creekside Christian Academy in Hampton, Georgia, attended one of the first cyber teacher camps at UNG. She returned to Creekside encouraging her students to play CyberStart America, a competition that would allow them to earn scholarships for cyber certifications. Simmons was one of those students. UNG also led CyberStart recruiting efforts in Georgia. After graduating from high school in May 2023, Simmons jumped in headfirst to UNG's cyber program, earning a bachelor's degree in cybersecurity and a master's degree in computer science within a combined span of two and a half years. A December 2025 graduate from the master's program, Simmons now works at Chick-fil-A's corporate offices in vulnerability management. He will begin a new role in cybersecurity engineering with Samaritan's Purse in September. Wright fondly looks back to her student's high school days and remembers letting Simmons know she was ahead of him in the CyberStart game. "He went home that weekend and made sure he was going to beat my score," Wright said. "After that, there was no looking back." Simmons carried the same competitive nature into UNG, regularly participating on teams that earned high honors at national and regional competitions. Between weekly CyberHawks student club meetings, classes and other interactions, Simmons was in an ideal atmosphere. "There was something every day of the week where you could learn from some of our top students," Simmons said. Dr. Hyungbae Park, associate professor of computer science and cybersecurity, marveled at Simmons' commitment to growth and excellence. "He was trying to build as many skill sets as possible," Park said.
Aug 31, 2026 · via ung.edu
On August 26, 2026, U.S. District Judge Yvonne Gonzalez Rogers approved a settlement between Meta Platforms Inc. and 29 state attorneys general in a federal bellwether case concerning alleged harms to children and teens from Facebook and Instagram. The approval ended the advisory jury trial before its fifth day. State Allegations The states alleged that Meta used addictive product features to attract and retain young users, misrepresented or minimized associated risks, and violated state consumer protection laws and the federal Children’s Online Privacy Protection Act (“COPPA”). Meta denied the allegations and did not admit liability or wrongdoing. Consent Decree Under the consent decree, Meta is expected to pay approximately $12.2 billion over 10 years. The total may rise to $17.1 billion if certain conditions are met, including comparable safety obligations and monetary resolutions involving other social media platforms (“SMPs”). The settlement also includes approximately $459 million to resolve outstanding state claims tied to Cambridge Analytica and creates a $75 million fund for participating states’ investigation and litigation costs. Additionally, the settlement requires Meta to implement a 10-year framework addressing youth safety in participating states. These implementation measures include: - Age assurance: Within one year of the settlement’s effective date, Meta must establish an age-assurance framework designed to assess whether users are under 13 (“U13”), and to develop and test a model to identify U13 users, remove identified U13 accounts, and report annually on enforcement results. - Default time limits for teens: During an initial five-year phase, Meta will restrict teens from accessing its SMPs between 12 AM and 6 AM, disable push notifications from 10 PM to 7 AM, and limit access to its SMPs to two hours per day. Parental approval is required to reduce default time limits. - Parental tools: For teen accounts, Meta must inform parents of
Aug 31, 2026 · via hunton.com
MONETT, Mo., Aug. 31, 2026 /PRNewswire/ -- Jack Henry & Associates Inc.® (Nasdaq: JKHY) today issued the following statement on its response to a recent cybersecurity incident: "Jack Henry recently detected a cybersecurity incident within a limited portion of our internal, non-production corporate environment. No client-facing systems, operating systems, core platforms, or daily processing services were accessed or disrupted, and they all remain secure and fully operational. We did not experience any system outages. Protecting the financial institutions we serve and maintaining transparency are fundamental to everything we do at Jack Henry. We recognize and deeply regret any concern this incident may cause to our clients and their accountholders. Based on our investigation to date, personally identifiable information (PII) data for fewer than 10 clients was impacted. We have notified our more than 7,200 clients that an incident occurred, and we are working directly with the affected clients. We are offering two years of credit monitoring services to impacted financial institutions to provide to their accountholders. Based on our investigation, the incident began with a sophisticated social engineering attack commonly known as vishing (voice phishing) initiated by a threat actor identified as ShinyHunters. Our security controls operated as intended to rapidly detect and contain the unauthorized activity. Upon detection, our teams immediately deployed specialized protocols to secure the network, isolate affected systems, and further heighten safeguards. We partnered with an independent third-party cyber forensics firm to support our investigation and response efforts and are actively collaborating with federal law enforcement. This incident involved an extortion attempt, and we are not making any payment to the threat actor. We have determined that the incident is not financially material to the company. Cyber incidents are an industry-wide reality, and our commitment to standing as a vigilant line of defense remains absolute. Through
Aug 31, 2026 · via prnewswire.com
JavaScript is disabled in your browser.
Please enable JavaScript to proceed.
A required part of this site couldn’t load. This may be due to a browser extension, network issues, or browser settings. Please check your connection, disable any ad blockers, or try using a different browser.
Aug 31, 2026 · via expressnews.com
Housed at Anderson University, ICN is a nonprofit public-private partnership and consortium of academic institutions building the state's cybersecurity workforce and defense capabilities.
By David Dungan The cybersecurity industry still has a “workforce development” problem.
They have eliminated the traditional interview process, which is a major impediment for neurodivergent individuals, in favor of skills tests and tryouts.
A recent study by the ISC2 Cybersecurity Workforce Study discovered that 73 percent of neurodivergent individuals believe that the field of cybersecurity is well suited for people like them.
If you are neurodivergent and interested in a career in cybersecurity, know that organizations like SANS are creating a community designed specifically for people like you.
Aug 31, 2026 · via in.gov
Guangzhou Rongtao Medical Technology Co., Ltd. has released an evidence-based framework designed to guide healthcare facilities on whether to patch, segment, isolate, or replace legacy ultrasound systems. Formulated using regulatory data from the US Food and Drug Administration (FDA), the Cybersecurity and Infrastructure Security Agency (CISA), adverse-event registries, and original equipment manufacturer (OEM) notifications, the report argues that equipment age is an ineffective decision metric. Instead, the framework evaluates supportability across five distinct lifecycles: clinical usefulness, OEM product support, software and component support, security-control supportability, and physical serviceability. A central finding from the analysis of 2,066 FDA 510(k) cart and console ultrasound clearances granted between 1977 and mid-2026 reveals that 90.1% predated Section 524B cyber-device statutory requirements, which took effect on 29 March 2023. Furthermore, every system cleared between 2006 and 2020—the vintage band comprising the majority of active fleets—predates the statute. With annual clearance volumes remaining flat at 55 to 83 systems, the pre-statute installed base will not age out naturally within standard planning horizons. CISA advisory records further substantiate the necessity of alternative disposition strategies beyond traditional software patching. Across 18 verified CISA medical advisories covering imaging products, half left at least one named device without a software fix at publication. Crucially, all four advisories explicitly naming ultrasound lines exhibited incomplete patch coverage, directing users toward network restriction, physical access controls, or complete replacement. Concurrently, the federal Known Exploited Vulnerabilities (KEV) catalogue mandates a 21-day median remediation timeline that validated medical devices cannot realistically achieve, whilst listing zero diagnostic-imaging manufacturers amongst its 276 entries. Regulatory safety filings highlight a separate operational dynamic: none of the 8,525 ultrasound adverse-event reports submitted to the FDA since 2019 reference ransomware, hacking, or malware, and the agency records only a single ultrasound cybersecurity recall dating back to 2008. The report notes this
Aug 31, 2026 · via futureiot.tech
Senegal and Gambia Advance Digital Cooperation on Connectivity, Cybersecurity The two sides agreed to adopt a pragmatic, results-oriented approach to the cooperation, with various initiatives to be advanced according to their level of readiness and the priorities identified by both countries. Senegal and The Gambia have taken steps to operationalise their digital cooperation following a working visit by Senegal’s Minister of Telecommunications and Digital Affairs, Samba Diouf, to Banjul. The visit focused on implementing a Memorandum of Understanding (MoU) signed between the two countries covering telecommunications and digital development. Discussions were held with Diouf’s Gambian counterpart and technical teams from both countries to review the implementation roadmap and identify initial priorities for putting the agreement into action. The two sides agreed to adopt a pragmatic, results-oriented approach to the cooperation, with various initiatives to be advanced according to their level of readiness and the priorities identified by both countries. Key areas discussed included connectivity, cybersecurity, capacity building and digital transformation. The cooperation is expected to strengthen collaboration between Senegal and The Gambia as both countries work to expand digital infrastructure and capabilities. The working visit marks another step in efforts by Senegal and The Gambia to translate their digital partnership into concrete programmes aimed at improving telecommunications and digital services for citizens in both countries.
Aug 31, 2026 · via techafricanews.com
More than 100 of the world’s largest technology, cybersecurity and financial companies have issued an unusual warning: The rapid development of artificial intelligence could trigger a new wave of advanced cyberattacks against critical infrastructure within the coming months, including hospitals, water facilities and internet infrastructure. In an open letter signed by companies including Microsoft, Google, OpenAI, Amazon and Anthropic, the firms warn that advanced AI tools are rapidly lowering the threshold required to carry out complex cyberattacks. Capabilities that once required extensive expertise, time and resources could become far cheaper, faster and more accessible even to less sophisticated attackers. According to the companies, the window of opportunity is closing. As AI models continue to improve, so does their ability to identify vulnerabilities, write code and autonomously carry out increasingly large parts of an attack chain. They are therefore calling on governments and companies to begin significantly upgrading their defenses now, rather than wait until such capabilities become even more widespread. Notably absent from the list of signatories are Meta and Elon Musk’s xAI. An attack that once took weeks could be reduced to minutes One of the main concerns involves what are known as “agentic” attacks — attacks in which AI systems do not merely provide answers or write code, but can independently carry out a sequence of actions to achieve a goal. In the letter, the companies warn that AI agents can operate at machine speed, search systems for vulnerabilities, adapt their actions to what they find and move on to the next stage with almost no human intervention. As a result, an attack process that once might have taken days or weeks could, at least in some scenarios, be reduced to minutes. The problem, they argue, is that the computer systems of many organizations are simply not prepared
Aug 31, 2026 · via ynetnews.com
Cybersecurity and resilience in the maritime sector Digital systems have become critical to core operations across the maritime sector. Ports, terminals, shipping companies and logistics operators increasingly rely on interconnected systems for navigation, cargo handling, communication, fleet management and operational coordination. “Maritime businesses are facing growing regulatory requirements relating to cybersecurity and operational resilience.” Maritime businesses are facing growing regulatory requirements relating to cybersecurity and operational resilience. In particular, the EU Network and Information Systems Directive (“NIS2 Directive”) and the Critical Entities Resilience Directive (“CER Directive”) establish comprehensive obligations for organisations operating critical infrastructure and essential services. Whilst the NIS2 Directive primarily focusses on cybersecurity, including risk management, incident reporting and supply chain security, the CER Directive takes a broader resilience perspective, covering physical security, operational continuity, crisis management and recovery capabilities. Together, these frameworks require organisations to adopt a holistic approach to operational risk management. Whilst these instruments establish a harmonised European framework, their implementation across member states will lead to variations in detail. Maritime businesses operating cross-border must therefore be prepared for a multi-layered and evolving regulatory landscape. For many organisations, the key question is no longer whether these frameworks apply. Increasingly, the challenge lies in translating regulatory requirements into practical governance structures, operational procedures, contractual arrangements and incident response frameworks. The focus is therefore shifting towards the effective implementation of these requirements at an organisational and operational level. “Systems that were previously isolated are increasingly connected to wider IT environments and external service providers.” This article outlines the key cybersecurity and resilience expectations arising from these frameworks and highlights the practical challenges maritime businesses face when implementing them in day-to-day operations. DIGITALISATION IS RESHAPING OPERATIONAL RISK STRUCTURES The maritime sector today depends heavily on digital and interconnected systems. Terminal operating systems, crane controls, fleet management platforms, cloud-based
Aug 31, 2026 · via cyprusshippingnews.com
Palo Alto Networks (PANW) Reports Q2: Everything You Need To Know Ahead Of Earnings Radek Strnad / August 31, 2026 Cybersecurity platform provider Palo Alto Networks (NASDAQ:PANW) will be reporting earnings this Tuesday after market hours. Hereâs what investors should know. Palo Alto Networks beat analystsâ revenue expectations last quarter, reporting revenues of $3.00 billion, up 31.1% year on year. It was a very strong quarter for the company, with an impressive beat of analystsâ billings estimates and a solid beat of analystsâ adjusted operating income estimates. Is Palo Alto Networks a buy or sell going into earnings? Read our full analysis here, itâs free for active Edge members. This quarter, the market is expecting Palo Alto Networksâs revenue to grow 32.2% year on year, improving from the 15.8% increase it recorded in the same quarter last year. Analysts covering the company have generally reconfirmed their estimates over the last 30 days, suggesting they anticipate the business will stay the course heading into earnings. Palo Alto Networks has a history of exceeding Wall Streetâs expectations. Looking at Palo Alto Networksâs peers in the cybersecurity segment, some have already reported their Q2 results, giving us a hint as to what we can expect. Qualys delivered year-on-year revenue growth of 11%, beating analystsâ expectations by 2%, and Okta reported revenues up 10.6%, topping estimates by 1.5%. Qualys traded up 13.8% following the results while Okta was also up 26.5%. Read our full analysis of Qualysâs results here and Oktaâs results here. There has been positive sentiment among investors in the cybersecurity segment, with share prices up 14.2% on average over the last month. Palo Alto Networks is up 7.2% during the same time and is heading into earnings with an average analyst price target of $364.01 (compared to the current share price
Aug 31, 2026 · via stockstory.org
Digital Content Editor, Eve Goode speaks exclusively with Tom Exelby, Head of Cyber Security at Red Helix about cybersecurity, AI and crisis management. The longer I spend out of the Army the more I realise how closely military experiences maps to cybersecurity. Three elements really stick out and are currently shaping my career in cybersecurity. The first is risk management under uncertainty. Military operators are taught to think and act decisively under pressure without having complete information upon which to base their decisions. This is exactly the situation an organisation is in when it is dealing with an incident, so being able to advise on how to thrive in this kind of situation has been really useful. The second is complex programme management. Military strategic planning is about coordinating multiple moving parts and competing priorities toward one objective. Cybersecurity within a modern organisation is just as complex, a web of people, process and technology, and third parties, all changing at once. Being comfortable structuring that complexity has been invaluable. The third, and the one people often underestimate, is the interpersonal side. The Army puts you in front of very diverse range of situations, teams and stakeholders, often under pressure. This forces you to learn how to lead and communicate across a wide spectrum. That’s remarkably like cybersecurity, where you move between technical teams, boards who need risk explained in business terms and customers in the middle of a crisis. The ability to read the room and build trust quickly has been as valuable as any technical skill. Innovation and security must not be seen as competing priorities, they are the same priority looked at from two angles. You cannot grow sustainably on weak foundations, and trying to do so usually costs more time and money later than building it in
Aug 31, 2026 · via securityjournaluk.com
Topic: The CISO AI Agenda: Governing Enterprise AI Risk at the Board Level Abstract: Artificial intelligence has rapidly transitioned from an emerging capability to a core enterprise dependency, reshaping how organizations operate, compete, and manage risk. For CISOs, this shift introduces a new governance imperative: AI risk can no longer be managed solely within technical domains—it must be elevated to board-level oversight where strategic, financial, and reputational impacts are defined. This session explores how CISOs can construct and communicate an AI governance agenda that translates technical risk into board-relevant language. It examines the expanding risk surface introduced by AI systems, including model integrity, data exposure, third-party dependencies, regulatory uncertainty, and adversarial machine learning. As AI adoption accelerates, the speed and complexity of risk decisions increasingly outpace traditional security reporting structures. Participants will gain insight into how to align cybersecurity strategy with enterprise governance frameworks, ensuring that AI risk is embedded into executive decision-making processes. The discussion also highlights how CISOs can effectively influence board priorities by quantifying AI-related exposure in business terms such as operational resilience, regulatory liability, and enterprise trust. This session provides CISOs with a strategic framework for governing AI risk at the board level, enabling stronger executive alignment, improved risk visibility, and more informed decision-making in the adoption and scaling of artificial intelligence across the enterprise. Key Takeaways: - How AI is redefining enterprise risk at the board level - The CISO’s evolving role as an AI risk strategist and advisor - How to translate technical AI risks into business and financial impact - Governance models for overseeing AI systems across the enterprise - Approaches to managing model, data, and third-party AI risk exposure - How to build board confidence in AI adoption through structured oversigh Speaker: Dewayne Hart, Speaker Agent | Hire Cybersecurity Speaker Bio: Dewayne
Aug 31, 2026 · via eccouncil.org