No-frills tech news

Crossbow Enterprise <b>Cybersecurity</b> Secures Third Consecutive PCI SSC GEAR Term (2026 ...

Crossbow Enterprise Cybersecurity Secures Third Consecutive PCI SSC GEAR Term (2026-2028), Bringing Nearly 12 Years of Expertise to Global Payment Security BusinessWire India Bengaluru (Karnataka) [India], August 14: Crossbow Enterprise Cybersecurity has been selected to serve on the PCI Security Standards Council's (PCI SSC) 2026-2028 Global Executive Assessor Roundtable (GEAR), marking its third consecutive term on the global payment security forum. Founded in October 2014, Crossbow brings nearly 12 years of experience across cybersecurity consulting, payment security, security assessment, compliance and advisory services. The company works with organizations across India, APAC, the GCC, the UK, Europe and the USA. The PCI SSC Global Executive Assessor Roundtable serves as a direct channel between senior leadership of payment security assessors and PCI SSC senior leadership. Crossbow is one of 33 organizations selected for the 2026-2028 Roundtable. As strategic partners, Roundtable members bring industry, geographical and technical insight to PCI SSC plans and projects on behalf of the assessor community. Strengthening Payment Security Beyond Compliance The growth of digital payments is changing the way organizations approach payment security. Modern payment environments increasingly connect mobile applications, APIs, cloud infrastructure, payment gateways, third-party platforms and customer-facing systems, making payment data protection part of a broader cybersecurity environment. As digital payment models evolve, security controls must advance in tandem by integrating payment protection directly into broader enterprise risk, cybersecurity, and business resilience strategies. Adapting to this shifting landscape demands sustained, active collaboration between standards bodies, assessors, and the organizations tasked with securing modern payment environments. Crossbow's continued role on GEAR enables it to bridge the gap between rapidly evolving payment technologies and global compliance standards, ensuring security frameworks stay practical, resilient, and effective for global enterprises. Gina Gobeyn, Executive Director, PCI Security Standards Council, said: 'The Global Executive Assessor Roundtable brings together experienced industry leaders whose

Trump's move to 'unleash' private sector hackers raises novel oversight, liability questions

The goal is to let private companies take on foreign cyber criminals, but the unprecedented approach raises plenty of questions about oversight and liability. President Donald Trump’s order to “unleash” the private sector to conduct offensive cyber operations against foreign criminal hackers is raising novel questions about government oversight, as well as legal liability and other risks for private companies that enlist in the program. The national security presidential memorandum signed by Trump this week does not enable private sector companies to “hack back” when they face a cyber intrusion. Instead, it establishes a government-run program that will contract with private sector companies and approve any offensive cyber operations conducted by industry participants. The new directive follows the White House’s national cyber strategy, released in March, which says the Trump administration will “unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities.” Trump’s memo directs the National Coordination Center to create and manage a program that authorizes companies to take offensive cyber action against “cyber-enabled transnational criminal organizations.” The Department of Homeland Security and the Justice Department will each designate a program executive director to co-lead the program. “Cyber operations shall only be approved after coordination between the program executive directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the federal government pursuant to the federal government’s lawful authorities,” the memo states. Tonya Ugoretz, former assistant director of intelligence at the FBI’s directorate of intelligence, said the directive is “a novel approach to what’s proved to be an intractable problem of cyber-enabled crime that we know affects every U.S. citizen to the tune of billions of dollars per year.” Ugoretz is currently the leader of PwC’s Cyber & Risk Innovation Institute. “These cybercriminal

Cisco security revenue jumps 14% as agentic AI sharpens cyberattacks | <b>Cybersecurity</b> Dive

Dive Brief: - Cisco's security revenue surged last quarter as the technology giant saw growing demand for products designed to protect businesses against emerging cybersecurity threats, including those enabled by artificial intelligence agents, the company reported Wednesday. - The company posted $17.3 billion in total revenue for its fiscal 2026 fourth quarter ended July 25, a year-over-year increase of 18%. Security revenue rose 14% in the quarter to $2.2 billion from a year earlier. - “The rise of agentic AI is expanding the threat landscape, driving demand for our security and observability solutions to help monitor agent behavior and mitigate evolving threats,” CEO Chuck Robbins said during a Wednesday earnings call. Dive Insight: The revenue surge coincides with increasing reports of AI’s role in cyberattacks. IBM's 2026 Cost of a Data Breach study released last month found that one in four malicious attacks are AI-enabled, up 56% from the prior year. Those breaches cost organizations an average of $6 million, according to the research. “These attacks, compromised of mostly deepfake impersonation and AI-enabled malware, are reshaping breach economics,” IBM said in a press release. “Attacks are getting faster and cheaper to launch, while breaches keep getting more expensive to find and fix.” Meanwhile, identity-verification firm Incode estimates that publicly documented AI-enabled fraud grew more than fivefold between 2023 and 2025. “Reported losses across those catalogued cases approach 900 million dollars, and that figure represents only a fraction of the true total,” Veljko Davidovic, a senior strategy and growth manager for Incode’s North America business, said in a Thursday blog post. Robbins said the evolving threat landscape “presents a unique opportunity” for his company. More than 1,500 customers purchased new Cisco security products including Secure Access and Hypershield, while orders for firewalls grew more than 30%. “When it comes to securing

AI 'Breakout' sparks <b>cybersecurity</b> concerns

About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC

Congressional staff visit highlights DSU's role in rural broadband and <b>cybersecurity</b>

MADISON — Fourteen congressional staff members from across the country visited Dakota State University on Aug. 11 to learn how South Dakota has expanded rural broadband and how DSU helps communities use and protect the technology that connectivity makes possible. Staff members representing U.S. House and Senate offices and congressional committees visited as part of a multistate educational tour focused on broadband’s role in rural communities. At DSU, they heard how connectivity supports education, workforce development, government services, healthcare, agriculture, research, and economic opportunity. ADVERTISEMENT Mike Waldner, DSU’s director of SecureSD and Project Boundary Fence, spoke with the group about South Dakota’s broadband development and the University’s involvement throughout that work. “DSU was intertwined in just about every step along the way,” Waldner said. “We’ve done a lot of things with technology on a statewide basis, and they really wanted to hear the South Dakota story — what we have done dating back to 1999 and 2000, and how that work has grown into all of the technology we’re using now.” Waldner said one of South Dakota’s strengths is its ability to bring organizations together around statewide technology projects. That collaboration allows communities to share resources, reduce costs, and maintain systems that continue to produce value decades later. “I think we do an extremely good job of pulling together,” he said. “If we continue to come together and do these statewide projects, we can create economies of scale and make them less expensive for taxpayers across the entire state.” The visit also gave staff members a look at the next stage of that work: protecting the networks, public services, and sensitive information that increasingly depend on broadband. Waldner said he hopes visitors will take South Dakota’s collaborative approach back to the members of Congress and communities they serve. “I hope

Initiative will pay <b>cybersecurity</b> vendors to protect rural water systems | Facilities Dive

LAS VEGAS — A water industry trade group and a collective of volunteer cybersecurity experts are bringing free security services to small water utilities that desperately need help protecting their systems from hackers. The DEF CON Franklin project on Friday announced that it will pay cybersecurity firms to provide their monitoring and protection products for free to water utilities serving fewer than 10,000 people. Those utilities, which account for more than 90% of the 50,000 community water systems in the U.S., are among the most digitally vulnerable, a danger highlighted by recent Iran-linked attacks on water systems across the country. Five managed detection and response (MDR) providers — Defendify, Legato Security, L1 Secure, Rapid7 and Sentinel Technologies — will initially participate in the program, and they will share the threat intelligence they collect from utilities’ networks through a new Water Watch Center run by the National Rural Water Association (NRWA). When MDR software installed on a utility’s network detects a potential cyberattack or vulnerability, the vendor will alert the utility and provide a report on the problem. The utility can then either fix the problem itself or request help from a volunteer expert on Franklin’s roster. “This is all about scale,” DEF CON Franklin organizer Jake Braun said in a Friday interview here on the sidelines of the DEF CON cybersecurity conference, the birthplace of the volunteer group. “Scaling delivery of cyber is where all the challenges fall.” The MDR offering and watch center represent a significant expansion of Franklin’s work supporting the water sector. In late 2024, the group started dispatching volunteers to help participating water utilities implement basic cybersecurity measures, map their networks and write incident-response plans. But Friday’s announcement marks the beginning of an ambitious new era for the group that will see it directly fund commercial

Data Theft Extortion Is Booming! Hooray!

Data Theft Extortion Is Booming! Hooray! Data Theft Extortion Is Booming! Hooray! The cybercriminal ecosystem is increasingly focusing on data theft and extortion rather than locking up victims' files. That criminals have stumbled across a new lucrative business model is a bittersweet win in the fight against disruptive, encrypting ransomware. Data theft extortion isn't great, but it doesn't leave widespread chaos in its wake like ransomware can. Silent Ransom, aka Luna Moth, is one group currently making big bucks from data theft extortion. Last week The Cyber Risk Insurer reported two law firms had paid substantial ransoms to the group this year: Goodwin Procter and WilmerHale, which paid $10 million and $18 million, respectively. Silent Ransom has been targeting law firms since 2023. It historically used phishing and convinced victims to install legitimate remote access software, which was then used to steal sensitive data. In the past year, however, they've brazenly sent people to compromise systems in person by posing as information technology (IT) support staff. Its data exfiltration process prioritizes speed over completeness. Google's Threat Intelligence Group (GTIG) says the groups' entire attack process, from initial target contact to data theft and extortion, is often completed within a single day. With ransom payments in the millions, that works out to a pretty good hourly rate. Another group that emerged in early 2026 was BlackFile, which now calls itself Redact. The group has also targeted similar organizations, but its data exfiltration is more comprehensive. Redact gains initial access using sophisticated high-volume voice phishing attacks (vishing) to steal credentials from victim organizations. It then uses these credentials to steal data from OneDrive and Sharepoint. It also pivots out to other software-as-a-service applications. GTIG says BlackFile spent April and May this year targeting enterprises in the real estate, health care, and insurance

Monitoring the Midterms: Are midterms safe from <b>cybersecurity</b> threats? | PBS News Hour Classroom

SUMMARY CISA, the federal agency tasked with protecting the cybersecurity of the nation’s critical infrastructure, held a conference call with state election officials to discuss the upcoming midterms. Despite President Trump’s claims about the risk of hackers targeting voting systems, this was one of CISA’s first broad outreach efforts just three months ahead of elections. News Hour's Liz Landers reports. View the transcript of the story. NOTE: If you are short on time, watch the video and complete this See, Think, Wonder activity: What did you notice? What did the story make you think? What do you want to learn more about? You can also make a Google doc copy of these general discussion questions. News alternative: Check our recent segments from the News Hour and choose the story you’re most interested in watching. See the Google doc above for discussion questions. WARM-UP QUESTIONS - What is CISA (Cybersecurity and Infrastructure Security Agency), and what role does it take in national elections? - Who met with CISA to discuss midterms? - Why did some participants think that the call came too late? - How might the security of elections come under threat in 2026, according to this segment? - When did CISA lose a third of its workforce? ESSENTIAL QUESTIONS - What do you think might be the biggest threat to election security in 2026? Did this segment change your opinion at all? - Do you think the federal government should have a role in ensuring secure elections? If so, what should that role be? Media literacy: In this segment, anchor Geoff Bennett speaks with reporter Liz Landers about conversations she had had with election officials regarding their call with CISA. Why do you think this segment focuses on this reporting rather than directly interviewing election officials about the call?

AI <b>Cybersecurity</b> Agents For SMBs: From Deployment To Digital Surface

SMBs from all industries are being hammered in today’s threat landscape. While headlines spotlight high-profile cyberattacks and sophisticated hacks, SMBs are the most impacted sector in cybersecurity. They face the same attacks large companies do, including increasing AI threats, but with far fewer resources. In 2025, the Identity Theft Resource Center found that as threat actors embraced AI, more than 80% of small businesses reported a cybercrime. The trend showed no signs of deceleration in 2026. The 2026 Verizon DBIR noted that a shocking 96% of all ransomware attacks hit SMBs. AI allows cybercriminals to reduce exploitation times from months to hours while scaling attacks to record-high levels. SMBs from all sectors are being targeted, including healthcare, agriculture, commerce, mining, logistics, energy, manufacturing, banking and fintech, software development and other industries. While the cyberattack stats may be discouraging for SMB decision-makers, the advances made in agentic cybersecurity technologies can help them turn the trend around and protect their business. In this report, executives, leaders and experts from HackerOne, 0rcus, Moonlock by Mac Paw and EC-Council guide SMBs on what agentic security tools can do, how they can deploy the tech safely and cost-efficiently and how SMBs can secure their digital surface, from front-end to workers' devices. What Can AI Cybersecurity Agents Do Today? As AI accelerates the speed and volume of threats and attacks, agentic security tools are designed to help companies respond. Until recently, these technologies were only accessible to large, well-funded companies. However, today SMBs can access them through big tech platforms and other vendors at competitive prices. There are a wide range of AI cybersecurity tools in the market for SMBs, including SentinelOne Singularity, Microsoft Defender for Business, Google Agentic SOC, GitHub Copilot Security and others developed by Amazon Web Services (AWS), CISCO, Palo Alto Networks and

State AI Task Force schedule to hold meeting to discuss <b>cybersecurity</b>

State AI Task Force schedule to hold meeting to discuss cybersecurity Artificial Intelligence is changing the way we live, work, and play. The state legislature created the Mississippi Artificial Intelligence Regulation Task Force to study AI’s impact now and in the future. The task force is holding public meetings on a variety of subjects and will issue reports to state leaders. The critical issue of cybersecurity is the next topic up for discussion. We talked to Dr. Kollin Napier, a member of the task force, about the upcoming cybersecurity meeting. The 11-member task force will deliver annual recommendations to the legislature and is set to dissolve on December 31, 2027.

Walton College Students Top National Field in <b>Cybersecurity</b> Challenge | Arkansas News

U of A seniors Conrad Haslauer and Nadine Moustafa earned first place in the KPMG Cybersecurity Challenge in March, a national, industry-sponsored competition that puts students' cybersecurity and business skills to the test. The Walton College students topped teams from universities across the country, providing a strong external measure of how U of A students are being prepared to confront complex cybersecurity challenges facing businesses today. Held as part of the Association for Information Systems Student Chapter Leadership Conference at James Madison University in Harrisonburg, Virginia, the competition challenged students with a realistic financial-services cybersecurity case. Teams analyzed technical vulnerabilities, assessed business risks, considered regulatory requirements and developed recommendations for a business audience. Haslauer and Moustafa took first place, ahead of Brigham Young University in second and James Madison University in third. Judges evaluated teams on problem understanding, risk assessment, mitigation strategy, presentation and a supporting audit report. The judging process makes the result particularly meaningful for Walton College. University-identifying information was prohibited from submissions, allowing the students' work to be evaluated on its merits rather than their institution's name or reputation. The first-place finish provides independent validation of the technical knowledge, business judgment and communication skills Walton College students are developing for a field increasingly critical to businesses across industries. Haslauer and Moustafa were coached by David Reavis, Janaki Koppolu and Daniel Conway, faculty members in Walton College's Department of Information Systems. The win comes as Walton College moves through the approval process to offer its cybersecurity program online. The expansion will broaden access to a program whose students have demonstrated on a national stage their ability to connect cybersecurity expertise with business needs. As AI expands both the power and complexity of cyber threats and quantum computing begins to challenge today's security foundations, the need for skilled cybersecurity

Chicago Tonight | <b>Cybersecurity</b> Expert Talks Recent Water System Hacks | Season 2026

Cybersecurity Expert Talks Recent Water System Hacks Clip: 8/13/2026 | 7m 18sVideo has Closed Captions Several water systems from Minnesota to Georgia suddenly went offline in late July. Several water systems from Minnesota to Georgia suddenly went offline in late July. While officials restored them, cybersecurity experts now say the outages may have been linked to Iranian hacking groups. Problems playing video? | Closed Captioning Feedback Chicago Tonight is a local public television program presented by WTTW WTTW video streaming support provided by members and sponsors. Cybersecurity Expert Talks Recent Water System Hacks Clip: 8/13/2026 | 7m 18sVideo has Closed Captions Several water systems from Minnesota to Georgia suddenly went offline in late July. While officials restored them, cybersecurity experts now say the outages may have been linked to Iranian hacking groups. Problems playing video? | Closed Captioning Feedback Where to Watch Chicago Tonight Chicago Tonight is available to stream on pbs.org and the PBS app. WTTW News Explains In this Emmy Award-winning series, WTTW News tackles your questions — big and small — about life in the Chicago area. Our video animations guide you through local government, city history, public utilities and everything in between. Providing Support for PBS.org Learn Moreabout PBS online sponsorship >> What appeared to be innocent malfunctions and municipal water systems could actually be something more serious at the end of July's several water systems from Minnesota to Georgia. Southern went offline while officials restored them. Cybersecurity experts now say the outages may have been linked to Iranian hacking groups raising larger questions about the security of America's critical resources. Joining us now with more is Jacob Ron executive director of the Cyber Policy Initiative at the University of Chicago and former acting principal cyber director under the Biden administration. Welcome back. Thanks for joining

UH Maui College receives $660K to enhance AI, <b>cybersecurity</b> education

To tackle a critical nationwide shortage of cybersecurity and artificial intelligence (AI) professionals, the University of Hawaiʻi Maui College has secured a three-year, $441,645 National Science Foundation (NSF) award to launch a groundbreaking project: “CyberAI Innovation: AI-Enhanced Cyber Data Analytics Education.” Led by Principal Investigator Debasis Bhattacharya and Co-Investigator Thomas Blamey, the initiative builds on previous NSF-funded efforts and directly addresses a vital local need, as Hawaiʻi currently ranks among the top five states in the nation for unmet cybersecurity workforce demand. “The intersection of AI, data analytics and cybersecurity is a critical frontier for modern digital defense,” said Bhattacharya, who also serves as the director of the Center for Cybersecurity Education and Research. “With Hawaiʻi facing such a steep challenge in meeting cybersecurity job demands, this grant enables us to build robust, early-career pipelines. We are excited to empower local educators and students with the advanced skills needed to protect our critical systems.” New curriculum, training The project will introduce an AI-integrated curriculum by embedding six new modules—including adversarial machine learning, AI-powered threat detection, secure AI pipelines and CyberAI ethics—across six core computer science courses at UH Maui College. Additionally, a three-year professional development program will deliver statewide faculty training across all seven UH community colleges and Hawaiʻi Department of Education (HIDOE) secondary schools. To cultivate early interest, the college will leverage the community of practice created by the NSF Project CSP4Hawaii (a collaboration aimed at improving computer science education at the state level) to expand K–14 academic pathways. The project also extends beyond IT, developing customized cyberAI micro-modules for non-IT fields such as healthcare/nursing, automotive technology and accounting/finance. AI, GenCyber cybersecurity camps UH Maui College has also secured a supplement award of $129,190 from the NSF to host two AI camps during the summers of 2027 and 2028

UnitedHealth Hit By New Lawsuit Allegations Over <b>Cybersecurity</b> and Governance Failings

Shares in healthcare group UnitedHealth (UNH) were flat in pre-market trading after a lawsuit alleged that its board ignored governance risks for years, costing shareholders billions in losses. Claim 55% Off TipRanks - Unlock powerful investing tools with TipRanks Premium to make smarter, more confident investment decisions - Subscribe to TipRanks Smart Investor Newsletter, and discover new investing opportunities with data-backed stock picks Largest U.S. Health Breach According to a report on Bloomberg, an amended complaint in a Minnesota federal court has revealed new information from former insiders about how the company handled cybersecurity after its $7.8 billion acquisition of health data and payments company Change Healthcare. Subsequently, Change suffered a cyberattack, which cost the company billions and exposed the private data of nearly 200 million Americans in the largest U.S. health data breach. It also alleged that UnitedHealth, which owns the largest U.S. health insurer, shut down an internal audit program that showed problems in its Medicare billing. The allegation is that it submitted claims for $200 million in Medicare payments that werenât supported by patientsâ diagnoses.âRather than remediate this damning finding and demand compliance, Defendant Hemsley supported the decision to eliminate an audit program entirely, ensuring that the fraud could continue undetected,â according to the complaint. Hemsley refers to current CEO and board chair Stephen Hemsley. A UnitedHealth representative declined to comment on the allegations. Latest Lawsuit The filing, according to Bloomberg, comes from shareholders including Rhode Islandâs public employee retirement system and the Swedish asset manager Länsförsäkringar Fondförvaltning AB, which owns more than $123 million in UnitedHealth stock. Theyâre suing board members on behalf of the company, claiming directors and officers missed red flags of âmisconduct and serious regulatory concerns, yet took no action to ensure compliance.â They want a judge to order the company to improve

UChicago <b>Cybersecurity</b> Expert on Water System Hacks, Critical Infrastructure Concerns

Crime & Law UChicago Cybersecurity Expert on Water System Hacks, Critical Infrastructure Concerns What appeared to be innocent malfunctions in municipal water systems could actually be something more serious. At the end of July, several water systems from Minnesota to Georgia suddenly went offline. While officials restored them, cybersecurity experts now say the outages may have been caused by Iranian hackers, raising larger questions about the security of America’s critical resources. Jacob Braun, executive director of the Cyber Policy Initiative at the University of Chicago and former acting principal cyber director under the Biden administration, joined “Chicago Tonight” to break down how hackers were able to access the country’s water infrastructure. WTTW News: What happened when these cities first realized something was wrong with their water systems? Jacob Braun: The cyber attack attacked a PLC (Programmable Logic Controller), which is a device that helps control the IT system and its commands to the physical system — so the actual pumps and so on that make the water utility work. As you suggested, the assumption is that the Iranians were behind the attack. And we think this attack is not really about a specific water utility. It’s really trying to send a message to the administration and the American people about where we’re vulnerable. I think that what they’re trying to do is really show the administration that they can shut off the water to our military assets. They can shut off the water to what may be the key economic driver in the country right now, which is our AI data centers. Finally, in a country that’s deeply divided over the war already, they’re showing they can undermine public trust in the government’s ability to perform the most basic lifegiving services like making sure the water turns on. How did

10 Companies Hiring <b>Cybersecurity</b> Analysts | Built In

As modern cloud infrastructure expands and complex digital threats continue to evolve, organizations are investing heavily in safeguarding their critical systems and sensitive data. Cybersecurity analysts serve as a crucial line of defense, monitoring network traffic, investigating suspicious anomalies and patching vulnerabilities before bad actors can exploit them. They’re part of larger security teams that are responsible for streamlining incident response strategies and configuring sophisticated threat-detection tools. With demand for information security professionals growing, finding the right employer can offer career stability and rapid professional growth. Companies ranging from global tech giants to nimble startups across various sectors are actively seeking talent to fill these mission-critical roles. Read on to explore some of the top tech companies hiring cybersecurity analysts to protect their digital infrastructure. Top Companies Hiring Cybersecurity Analysts - CrowdStrike - Microsoft - Rapid7 - Huntress - Zscaler - Optum - Caterpillar - Boeing Top Companies Hiring Cybersecurity Analysts Boeing manufactures commercial airplanes and defense systems while delivering specialized services across training, maintenance and more to customers globally. With a responsibility to protect both enterprise IT networks and connected aviation systems, it oversees security architecture that safeguards critical operational infrastructure from digital disruptions. Northrop Grumman develops advanced defense technologies and aerospace systems for national security clients. The company’s product offerings include solutions for predicting and responding to cyberattacks, helping safeguard military networks, satellite infrastructure and mission-critical intelligence systems. CrowdStrike specializes in cloud-delivered endpoint security, threat intelligence and attack mitigation solutions. Powered by AI, its core security platform defends critical systems against sophisticated threats and breaches across industries including healthcare, financial services, education and state and local government. Zscaler delivers cloud security solutions through a purpose-built zero trust architecture. By providing security capabilities that cover an organization’s users, workloads, branches and devices, the company’s technology defends remote workforces and

<b>Cybersecurity</b> Operations already running on Marshall's campus ahead of the new institute ...

Cybersecurity Operations already running on Marshall’s campus ahead of the new institute building’s completion HUNTINGTON, W.Va. (WSAZ) - A new building rising along 4th Avenue near Marshall University will house the Institute for Cyber Security, and university officials say it will include cutting-edge technology and training once completed. Each floor of the building will have a distinct, defense-driven focus with learning labs, a space for private industry partners and specialized labs. The structure is slated to open in August 2027. Construction is ongoing, but Alexandria Donathan, executive director of the Institute for Cyber Security, said cybersecurity defense work is already taking place at several locations across campus before its doors even open. “If you’re interested in cyber, then just start,” Donathan said. “It’s like a river. Everything is moving so fast.” She said cybersecurity offers broad career opportunities. In June, Intuit launched a Security Operations Center on campus, giving students hands-on experience ahead of the new building’s completion. Cole Perry is one of two full-time employees already working there while still enrolled as a student. “I was going to get an internship out of school, but this jump starts my experience,” Perry said. At the center of the new building will be three Security Operations Centers, or SOCs. Donathan described them as the first layer of defense. “All of the data, any sort of incident or anything, will start within the Security Operations Center,” Donathan said. “So, they should have access to all the network data, the logs, anything that is passing through to identify any sort of incident that could be happening or identify vulnerability, and that will work from there.” Donathan explained how the institute’s ambitions extend beyond the new building. “The physical space of course will be helpful, but we are not paused at growth,” Donathan said.

CCPA <b>Cybersecurity</b> Audits Are Coming: What Companies Should Do Now

The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls are not only designed appropriately, but operating effectively over time. For many companies, this will be the first recurring, regulator-visible audit cycle that ties cybersecurity governance, privacy compliance, executive accountability, and legal defensibility together. Businesses that meet the applicable revenue and data-processing thresholds, including those processing large volumes of Californians’ personal information or sensitive personal information, should be preparing now, because the first audit period is quickly approaching. These audits will require more than a technical controls review. Covered businesses will need to define audit scope, identify relevant systems and data flows, assess third-party and vendor access, document control performance, and support scoping decisions with clear evidence. Legal teams, privacy leaders, security, technology, compliance, and business stakeholders should be aligned early on what is in scope, what evidence will be used, who will own remediation, and how decisions will be documented. Chief legal officers and legal departments have an important role to play here: helping the business interpret regulatory expectations, pressure-test assumptions, assess whether auditor independence requirements are met, and frame the organization’s risk posture in a way that can withstand external scrutiny. Companies can start by revisiting their data maps, identifying systems that collect, store, transmit, or provide access to California residents’ personal information, and comparing existing cybersecurity frameworks against the CCPA’s required audit domains. Organizations with mature compliance programs may have a head start, but even well-resourced companies should expect meaningful work around documentation, evidence standards, remediation tracking, and executive certification. The key is to move from “we have a program” to “we can prove the program works.”