Peachtree Corners, GA, Aug. 12, 2026 (GLOBE NEWSWIRE) -- Senteon is proud to announce that during Black Hat USA 2026, the company was named a finalist in both the Top InfoSec Innovator Awards and Top 25 Most Innovative Cybersecurity Companies in the World 2026 by Cyber Defense Magazine (CDM), a leading electronic information security magazine. 2026 Top 25 Most Innovative Cybersecurity Companies In The World Judging continues through October 2026, with winners to be announced online, in print, and during CyberDefenseCon 2026, taking place October 20–21, 2026, at The Ritz-Carlton in Orlando, Florida. A select group of winners will have the opportunity to showcase their innovative solutions to top global CISOs during the invitation-only conference. Learn more at https://www.cisoconference.com. “Being named a finalist among some of the most innovative cybersecurity companies in the world is an incredible honor,” said Henry Zhang, CEO of Senteon. “Organizations are managing thousands of security configurations across constantly changing environments, and even a single configuration change can introduce unnecessary risk. At Senteon, we’re focused on making endpoint hardening and configuration integrity continuous, measurable, and manageable at scale. This recognition reinforces our belief that preventing configuration drift and maintaining hardened systems should be a fundamental part of every organization’s cybersecurity strategy.” “Senteon embodies three major features we judges look for with the potential to become winners: understanding tomorrow’s threats, today, providing a cost-effective solution and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. Senteon is honored to be included among this distinguished group of finalists in the Cyber Defense Awards. About Cyber Defense Awards This is Cyber Defense Magazine’s thirteenth year of honoring InfoSec innovators from around the globe. Submission requirements are open to startups, early-stage,
Aug 12, 2026 · via daily-tribune.com
Cybersecurity company Rapid7 is cutting around 12 per cent of its workforce. The company is restructuring its organisation and redirecting resources towards its core platform and AI-led security capabilities. The restructuring began in the second quarter of 2026 and is aimed at simplifying the company’s organisational structure and aligning teams more closely with its Core Platform Solutions. Around 12 per cent of employees have been informed that their roles will be affected. Rapid7 expects the restructuring to result in charges of approximately $10 million to $11 million. Most of the costs are expected to come from employee severance and related expenses. The workforce reduction comes as Rapid7 accelerates a broader shift towards an AI-first approach to cybersecurity. The company has strengthened its leadership team with the new appointments. Rapid7 is also expanding its use of generative and agentic AI in security operations. Through OpenAI’s Trusted Access for Cyber programme, the company is incorporating models including GPT-5.5 into its Agentic SOC workflows. Rapid7 said the technology has helped speed up the process of analysing security telemetry and cut false-positive queue times by 25 per cent. The company has also joined Anthropic’s Project Glasswing, where it will work on defensive engineering, detailed code reviews and automated vulnerability remediation. The restructuring comes as Rapid7 manages modest declines in key financial metrics. The company reported quarterly revenue of $210.9 million and annual recurring revenue (ARR) of $824 million, both slightly lower than the previous year. Despite the workforce reduction and restructuring costs, Rapid7 generated $31.9 million in free cash flow during the quarter. It ended June with $702.6 million in cash, cash equivalents and government securities. The changes indicate a broader shift in the company’s workforce strategy, with resources being moved away from existing organisational structures and towards AI-driven products and cybersecurity capabilities.
Aug 12, 2026 · via hrkatha.com
OpenAI's (OPENAI) series of cybersecurity-focused models, Daybreak, are now available through the Amazon Web Services (AMZN) Bedrock platform, the company announced today.
This includes Daybreak Blue and Daybreak Red. Daybreak Blue provides access to frontier general-purpose models, including GPTâ5.6 Sol, with safeguards
Aug 12, 2026 · via seekingalpha.com
Darlington Co. investigating cybersecurity incident affecting some services DARLINGTON COUNTY, S.C. (WPDE) — Darlington County officials are investigating a cybersecurity incident affecting some county computer systems and limiting certain services. Darlington County Administrator Marion “Charles” Stewart III said some systems have been proactively taken offline as officials work to address the incident. As a result, some county services are available in a limited capacity. Emergency services remain fully operational, Stewart said. The incident has not affected the county’s 911 communications center or its ability to receive calls and dispatch emergency responders. MORE: Former Florence teacher accused of solicitation of a minor, deputies say Darlington County is working with third-party cybersecurity specialists and law enforcement agencies at multiple levels to investigate the incident and restore full functionality to the county’s network as quickly and securely as possible. “The investigation remains active and ongoing, and we have significant resources dedicated to this process,” Stewart said in a statement. Stewart said the county continues to provide services to residents and the public while working to restore the affected systems. The following statement was released by the Darlington County Government: "We are working with third-party cybersecurity specialists and law enforcement agencies at all levels to restore full functionality to our network as quickly and securely as possible. As part of our response process, certain systems have been proactively taken offline, and some County services are available in a limited capacity. The investigation remains active and ongoing, and we have significant resources dedicated to this process." County officials said additional updates will be provided as more information becomes available.
Aug 12, 2026 · via wpde.com
COMMENTARY: For more than a decade, the cybersecurity industry has told itself the same story: there aren't enough skilled people to do the work, and to fix it we need more hiring, more training programs, more pipeline investment.Every year the workforce gap gets cited again, slightly larger than the year before, as proof the strategy isn't working fast enough. Maybe it's time to consider a less comfortable explanation: the strategy was never going to work, because hiring was never the actual constraint.[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]Security operations centers (SOCs) don't have a people problem. They have a throughput problem, and the two look identical on a staffing report while being completely different in cause.Alert volume scales with attack surface — more cloud services, more endpoints, more third-party integrations, more identities to track — and attack surface has been growing exponentially for years. Headcount, even in a generous hiring environment, grows linearly at best. We cannot out-hire an exponential curve. No SOC has ever closed this gap by adding analysts faster than the alert volume grew, and none ever will, because the two are growing on different curves entirely.What that means in practice: the "shortage" isn't a shortage of qualified people. It's a mismatch between a triage workload that scales with infrastructure and a workforce that scales with budget cycles. Framing it as a hiring problem set the entire industry chasing a fix that was structurally incapable of closing the gap, no matter how much was spent on it.Where the actual bottleneck livesMost SOC analyst time doesn't go to the high-judgment work — the actual threat hunting, the incident response that requires real expertise. It goes to triage: Is this alert real? Does it matter?
Aug 12, 2026 · via scworld.com
Managing Cybersecurity Risk is a Non-Negotiable for Organizations – But Can Be Expensive Cybersecurity is no longer a "nice to have" for organizations; it is a must. And the resources required to build, maintain, and monitor a layered cybersecurity architecture around the clock are costly. Now more than ever, organizations are outsourcing their cybersecurity needs to third-party vendors to the tune of more than $200 billion globally in 2025. Not only is outsourcing cybersecurity needs often a more cost-efficient strategy, but it is also a means for organizations to transfer some of their cybersecurity risk. Organizations often rely on the belief, and provide assurances of the same to customers and regulators, that their networks, systems, and data are safe with their cybersecurity vendors on guard to detect and respond to suspected threats. However, it is only when something goes wrong that the effectiveness of the risk transfer is fully understood. When cybersecurity service agreements fail to capture and transfer the intended risks, the resulting legal consequences can be costly, leaving organizations managing regulatory scrutiny and litigation on multiple fronts, including with their own cybersecurity vendors. To avoid these costly battles, organizations should scrutinize the cybersecurity vendor agreements from both a legal and technical point of view. How these agreements define the scope of the services and obligations of the parties or otherwise limit liability can be the difference of millions of dollars when something goes wrong. Scope of Services The starting point for any cybersecurity services agreement is a clear understanding of exactly what the vendor is responsible for doing – and just as importantly, what it is not responsible for doing. The broad umbrella of "managed security services" can sound all-encompassing, but agreements often differ in terms of the functions and duties the vendor is obligated to perform. While
Aug 12, 2026 · via bakerdonelson.com
The Cybersecurity and Infrastructure Security Agency (CISA) on Aug. 12 released a new package of cybersecurity resources to help K-12 schools and districts prevent, mitigate, and respond to cyber threats. The K-12 Cybersecurity Foundations Resource Package includes guides, a six-part video series, and quick-reference materials tailored to school leaders, non-technical staff, and cybersecurity and IT professionals, according to a press release from the agency. “Cyberattacks on K-12 schools and districts jeopardize not only the integrity of our educational mission, but the safety and security of our students and teachers as well,” said Nick Andersen, CISA’s acting director. “These impacts are often felt well beyond the classroom.” “The K-12 Cybersecurity Foundations Resource Package empowers school communities with practical strategies and supports our school safety mission,” Andersen added. “CISA is helping the K-12 community proactively defend against cyber threats, minimize disruption and better protect the systems our nation’s children, parents and educators depend on every day.” CISA said schools and districts face increasing cybersecurity threats because they maintain sensitive student and staff data, depend on a range of technologies and systems, and have users with varying access privileges. The agency also pointed to limited resources for cybersecurity programs as a risk for K-12 institutions. Cyber incidents can disrupt school operations and learning, compromise student privacy and safety, and consume limited resources, CISA said. The package features a Getting Started Guide and a more detailed Implementation Guide. The guides organize cybersecurity practices around eight objectives: - Protecting login credentials - Safeguarding devices and assets - Testing backups - Strengthening incident response capabilities - Improving cybersecurity training - Appropriately managing sensitive data - Aligning investments with recognized cybersecurity frameworks - Developing customized long-term plans “K-12 cybersecurity has evolved beyond an IT department concern and must now be recognized as a fundamental pillar of school
Aug 12, 2026 · via meritalk.com
Hong Kong SFC Takes Enforcement Action Against Firm for Cybersecurity Deficiencies Client Alert | August 12, 2026 This is, in our view, intended as a pointed reminder to the market that the SFC expects licensed corporations to maintain robust cybersecurity frameworks – and is willing to take action against firms whose frameworks fail to meet their expectations, even if clients are not directly affected. On July 28, 2026, the Securities and Futures Commission (SFC) reprimanded and fined Luk Fook Securities (HK) Limited (LFSHK) HK$2.1 million for failing to implement adequate and effective cybersecurity control measures.[1] While the fine itself is not large, this matter is notable given that it is the first known example of the SFC taking disciplinary action against a licensed corporation because of a cyberattack against the firm’s trading systems. Importantly, the SFC took action notwithstanding the absence of client asset misappropriation, unauthorized trading, client complaints or client financial loss – factors which the SFC treated as mitigating rather than exculpatory. This is, in our view, intended as a pointed reminder to the market that the SFC expects licensed corporations to maintain robust cybersecurity frameworks – and is willing to take action against firms whose frameworks fail to meet their expectations, even if clients are not directly affected. I. SFC ENFORCEMENT ACTION LFSHK is licensed to carry on Type 1 (dealing in securities), Type 4 (advising on securities) and Type 9 (asset management) regulated activities. During the COVID-19 pandemic, LFSHK enabled remote working through a VMware virtual environment, which allowed employees, third-party vendors, and IT staff to access office systems remotely. On September 19, 2022, a hacker exploited the VMware environment to gain access to LFSHK’s Active Directory (AD) server. The SFC described the resulting disruption to LFSHK’s critical IT infrastructure as sweeping, extending to its file
Aug 12, 2026 · via gibsondunn.com
Lawmakers enacted House Bill 5638 in mid-March, altering West Virginia’s cybersecurity program to give the state chief information security officer (CISO) greater authority over cyber policies, risk management, and other security responsibilities across most state agencies. As agencies respond to the changes, which took effect June 12, state CIO Heather Abbott is focused on what they will mean for departments — and for the state’s broader cybersecurity strategy. The law requires agencies to do yearly cybersecurity reviews. It protects sensitive cybersecurity information from public disclosure and requires the CISO to report annually to the governor and legislators on the program’s progress. It applies to all state entities except higher education institutions, state police, some constitutional officers, the Legislature and the Judiciary. The modifications, Abbott said, are less about creating a new security program than making sure agencies actually follow through on the one that already exists. What shifted, she said, was the language around the annual reviews, which had left too much room for agencies to treat participation as optional. “It says that, you know, the agency shall do this,” Abbott said. “And it really didn’t put any onus on the agencies to do it.” The annual reviews were originally intended to give the state a regular look at each agency’s cybersecurity readiness and broader security environment — and under the previous language, agencies were supposed to participate in at least one review with the Office of Technology each year. The new requirements, Abbott said, are designed to strengthen that process by putting more responsibility on agencies to participate and address the findings that emerge. The distinction matters because the reviews are not simply a paperwork exercise. Some agencies do not have the expertise to handle the work on their own which is why the updated law makes their participation
Aug 11, 2026 · via govtech.com
Daybreak models are now available on AWS Earlier this year, OpenAI frontier models and Codex became generally available on AWS, giving enterprises a new path to bring advanced AI into production. Today, we’re sharing the next step in our work with AWS: making Daybreak capabilities available through Amazon Bedrock. With Daybreak Access, defenders can use frontier cyber models within their existing AWS environments. Daybreak Blue and Daybreak Red access levels are both available in AWS: - Daybreak Blue provides access to frontier general-purpose models, including GPT‑5.6 Sol, with safeguards tailored to authorized defensive security work. - Daybreak Red provides access to our purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing. These models help accelerate vulnerability research, detection engineering, and incident response, from initial discovery through a validated fix. They also support complex workflows such as exploit reproduction and mitigation development. For enterprises, adopting specialized cybersecurity capabilities requires more than model performance. It also requires security review, governance, procurement, access controls, and an operating model teams can support. Through Amazon Bedrock, eligible customers can use Daybreak, including Daybreak Red and Daybreak Blue, within the AWS environments where they already build, secure, and operate software. This gives security teams a clearer path to apply frontier AI through familiar AWS security, governance, and operational workflows. Together, OpenAI and AWS are helping more organizations put advanced cybersecurity capabilities to work in production. Daybreak Red and Daybreak Blue require enrollment in Daybreak Access. Once approved, you can access the model through the Amazon Bedrock console or the Responses API using the bedrock-mantle endpoint. To learn more, see the documentation.(opens in a new window)
Aug 11, 2026 · via openai.com
WASHINGTON – U.S. Senators Todd Young (R-Ind.) and Adam Schiff (D-Calif.), members of the Senate Committee on Small Business and Entrepreneurship, introduced the Small Business Cybersecurity Assistance Evaluation Act, bipartisan legislation to improve the federal cybersecurity tools that protect small businesses against cyber threats – helping integrate the technology, resources, and programs they need to stay protected in a changing digital landscape, according to information provided. “Small businesses are increasingly targeted by cybercriminals, but too many owners don’t know where to turn for help,” said Senator Young. “This commonsense legislation will identify gaps, improve coordination, and ensure small businesses have access to the tools they need to defend themselves from evolving cyber threats. When small businesses are better protected, they can spend less time responding to cyberattacks and more time creating jobs and growing our economy.” “As small businesses face a growing threat of cyberattacks and phishing schemes, we must give them the tools they need to stop hacks and lower their risk. Our bipartisan legislation will improve federal cybersecurity resources to help small businesses mitigate their cybersecurity vulnerabilities,” said Senator Schiff. The Small Business Cybersecurity Assistance Evaluation Act will require the Government Accountability Office (GAO) to develop a report on all federal cybersecurity resources, initiatives, programs, tools, and services available to small business owners. This report must include: Information on the most common cybersecurity threats faced by small businesses; A description and assessment of the different levels of awareness, use, coordination, and integration of the federal resources; A list of foundational cybersecurity concepts absent from federal resources; and Recommendations on how to improve the effectiveness of these tools.
Aug 11, 2026 · via newsbug.info
Cyber Storm X: 20 Years of Readiness, Resilience, and Real‑World Impact This year marks the 20th year of Cyber Storm, a full-scale national cybersecurity exercise that for two decades has brought together the people who defend the systems Americans rely on. Held every two years, Cyber Storm X arrives as threats from geo-political activity, compromised edge devices, AI risks, and more present new challenges to our nation’s critical infrastructure. As the nation’s largest cybersecurity exercise, Cyber Storm plays a vital role in preparing for potential cybersecurity incidents by testing and strengthening the nation’s ability to coordinate a unified cyber response. Participants from private and public organizations work together through a simulated crisis. Together, they learn as a team and build stronger relationships that will speed response during an actual event. Importantly, organizations can also update their response plans based on lessons learned during the exercise. Building Partnerships for a More Secure Nation Cyber Storm began with 500 participants 20 years ago as a national effort to bring government and industry together in one place when our nation needed a way to understand how a major cyber incident could unfold across many sectors at once. This number has grown, and this fall’s Cyber Storm exercise will bring together 2,000 critical infrastructure owners and operators from around the country, spanning everything from large national companies to local utilities. Participants include legal teams, crisis communication, IT managers, and organizational leaders. For many of them, this exercise is the first time they meet those who they will need to work with during a cybersecurity crisis. How Organizations Practice for Real Events Cyber Storm features a simulated attack on the services our nation counts on every day. These are services that keep communities moving and can’t afford downtime. For example, in 2024's Cyber Storm IX,
Aug 11, 2026 · via cisa.gov
Dive Brief: - The 2027 edition of the National Fire Protection Association’s Health Care Facilities Code includes significant changes to protocols for electrical systems, medical gas systems, cybersecurity and more, experts said at an information session in Minneapolis last week. - Chad Beebe, deputy executive director for the American Society for Health Care Engineering, told a capacity crowd at the ASHE 2026 Health Care Facilities Innovation Conference that health care facilities managers should familiarize themselves with the updates to NFPA 99 even if their organizations expect to follow earlier versions of the code for the moment. - State and local governments may force the issue by adopting portions of new NFPA codes into law or regulation, as California did with a 2024 law that requires most hospitals to install weapons detection systems at entrances by next year, Beebe said. Dive Insight: “When one state does something, others may follow,” Beebe said. “We’ll likely see more and more states consider these [weapons screening requirements] over the next five years.” The California weapons screening requirement mirrors a provision in the National Fire Protection Association’s Life Safety Code, known as NFPA 101, that left hospital facility managers and administrators concerned about bulky new security infrastructure impeding traffic flows at critical access and evacuation points, Beebe said. Beebe said ASHE representatives brought up those concerns with NFPA, leading to a “tentative” amendment to NFPA 101 in May that specified minimum door width and floor level requirements for egress corridors with fixed or portable weapons screening systems. That experience underscores why it’s important for health care facilities managers to get involved with ASHE and other advocates with influence on code development processes, he said. In general, staying up to date on code changes that affect hospital and clinic operations helps facility administrators and managers make
Aug 11, 2026 · via facilitiesdive.com
A sign posted to Suisun City Hall states City Hall will be closed for the week due to a network issue, Tuesday, Aug. 11, 2026. (Aaron Rosenblatt/Daily Republic) SUISUN CITY — Fixing the city's IT network, following a cyberattack will not be quick, City Manager Bret Prebula said at an early morning City Council meeting on Tuesday. He estimated, hopefully, it would be all "systems go" around Halloween. In the interim, City Hall is closed for the remainder of the week as employees work from home so they can access the Cloud. There is no conclusion, yet, Prebula said, whether personal information of Suisun City residents is at risk. At roughly 5:45 a.m. Friday, malicious software infected and compromised Suisun City IT systems. The cybersecurity incident hit critical public safety operations, including 911 routing, police and fire dispatch, records and city services. To contain the threat and preserve evidence for a federal investigation, the city shut down its entire IT network. The city activated its Emergency Operations Center and is working alongside federal, state and regional agencies, including the FBI, Department of Homeland Security and California Office of Emergency Services to maintain emergency services, investigate the incident and restore systems. Keep it Clean. Please avoid obscene, vulgar, lewd, racist or sexually-oriented language. PLEASE TURN OFF YOUR CAPS LOCK. Don't Threaten. Threats of harming another person will not be tolerated. Be Truthful. Don't knowingly lie about anyone or anything. Be Nice. No racism, sexism or any sort of -ism that is degrading to another person. Be Proactive. Use the 'Report' link on each comment to let us know of abusive posts. Share with Us. We'd love to hear eyewitness accounts, the history behind an article. (1) comment So this headline is ok, however the first paragraph needs proof reading, what’s going
Aug 11, 2026 · via dailyrepublic.com
Cybersecurity for Startups: Five Risks You Can’t Ignore Cybersecurity is a critical priority for startups because they can be prime targets for cyberattacks, face severe financial and survival risks, and require verified security compliance to win clients and funding. One overlooked vulnerability is all it takes to undo months of hard-won progress, and for a startup, the fallout can be existential. Cybersecurity isn’t a back-office afterthought; it’s a frontline safeguard, and startups can meaningfully strengthen their security posture by understanding the risks they face, taking proactive steps to address them, and keeping pace with emerging trends. Below, we outline five key cybersecurity risks every startup should keep on its radar: 1. Social Engineering and Ransomware Let’s be honest: your business’s data is valuable, and that makes it a target. Cybercriminals know this too, and their tactics for obtaining it are increasingly difficult to detect. What is social engineering? Think of social engineering as digital con artistry. A scammer might call pretending to be tech support (vishing), send an email that looks like it’s from your bank (phishing), or text a link disguised as a delivery notice (smishing). The tactics vary, but the goal is always the same: trick you into handing over the keys to your data. Once a scammer talks their way into your systems, they can lock you out of your own technology and demand a hefty payment before handing back the keys (if at all). Verizon’s 2025 Data Breach Investigations Report found that ransomware was present in 44% of breaches overall, and in a striking 88% of breaches affecting small and medium-sized businesses specifically. Human involvement factored into roughly 60% of all breaches, including social engineering and credential abuse. So what’s your best defense? Stay a little skeptical. Think twice before clicking a link from someone you
Aug 11, 2026 · via teknovation.biz
TAMPA BAY, Fla.--(BUSINESS WIRE)--Aug 11, 2026-- KnowBe4, the leader in digital workforce security, securing both AI agents and humans, today released its free resource kit in support of Cybersecurity Awareness Month 2026. This year’s toolkit casts employees as “Secret Agents” in the elite Workforce Risk Division and provides IT leaders with tools to build organizational resilience against evolving cyber threats. kAm~3D6CG65 6G6CJ ~4E@36C[ k2 9C67lQ9EEADi^^4ED]3FD:?6DDH:C6]4@>^4E^r%n:5lD>2CE=:?<U2>AjFC=l9EEADTbpTauTauDE2JD276@?=:?6]@C8TauAC@8C2>DTau4J36CD64FC:EJ\2H2C6?6DD\>@?E9TauU2>Aj6D966EldcdgdeahU2>Aj?6HD:E6>:5la_ae_g``fd`g_cU2>Aj=2?l6?\&$U2>Aj2?49@ClrJ36CD64FC:EJZpH2C6?6DDZ|@?E9U2>Aj:?56Il`U2>Aj>5dl_d`e456f`beegh2f3e6e6445a7hh45f6Q C6=lQ?@7@==@HQ D92A6lQC64EQmrJ36CD64FC:EJ pH2C6?6DD |@?E9k^2m :D 2? :?E6C?2E:@?2= :?:E:2E:G6 =65 3J E96 k2 9C67lQ9EEADi^^4ED]3FD:?6DDH:C6]4@>^4E^r%n:5lD>2CE=:?<U2>AjFC=l9EEADTbpTauTauHHH]4:D2]8@GTauU2>Aj6D966EldcdgdeahU2>Aj?6HD:E6>:5la_ae_g``fd`g_cU2>Aj=2?l6?\&$U2>Aj2?49@ClrJ36CD64FC:EJZ2?5Zx?7C2DECF4EFC6Z$64FC:EJZp86?4JU2>Aj:?56IlaU2>Aj>5dld66he__af2c4536da2_b436cdae37ea5Q C6=lQ?@7@==@HQ D92A6lQC64EQmrJ36CD64FC:EJ 2?5 x?7C2DECF4EFC6 $64FC:EJ p86?4Jk^2m Wrx$pX 2?5 E96 k2 9C67lQ9EEADi^^4ED]3FD:?6DDH:C6]4@>^4E^r%n:5lD>2CE=:?<U2>AjFC=l9EEADTbpTauTauHHH]DE2JD276@?=:?6]@C8TauU2>Aj6D966EldcdgdeahU2>Aj?6HD:E6>:5la_ae_g``fd`g_cU2>Aj=2?l6?\&$U2>Aj2?49@Cl}2E:@?2=ZrJ36CD64FC:EJZp==:2?46U2>Aj:?56IlbU2>Aj>5dl3677_3_e6g2`bgd562afc7f3c__ff367Q C6=lQ?@7@==@HQ D92A6lQC64EQm}2E:@?2= rJ36CD64FC:EJ p==:2?46k^2m] %96 42>A2:8? AC@G:56D @C82?:K2E:@?D H@C=5H:56 2? @AA@CEF?:EJ E@ DEC6?8E96? E96:C D64FC:EJ 4F=EFC6 3J 5C:G:?8 2H2C6?6DD 2C@F?5 D@4:2= 6?8:?66C:?8[ 2CE:7:4:2= :?E6==:86?46 E9C62ED[ 52E2 D64FC:EJ 2?5 24E:G6 E9C62E C6A@CE:?8]k^Am kAm“rJ36CD64FC:EJ pH2C6?6DD |@?E9 :D 2? @AA@CEF?:EJ 7@C E96 D64FC:EJ 4@>>F?:EJ E@ AC6D6?E 6?828:?8[ ?6H 4@?E6?E E@ E96:C FD6CD 2?5 5C:G6 9@>6 E96 :>A@CE2?46 @7 DE2J:?8 D64FC6[ 6G6? :7 E96J 92G6 6I:DE:?8 D64FC:EJ 2H2C6?6DD EC2:?:?8[” D2JD tC:49 zC@?[ rx$~ 25G:D@C 2E z?@Hq6c] “(:E9 4J36C4C:>:?2=D 25@AE:?8 px\5C:G6? E24E:4D DF49 2D 566A72<6D 2?5 25G2?465 D@4:2= 6?8:?66C:?8[ E9C62ED 2C6 4@?E:?F@FD=J 6G@=G:?8 2?5 @C82?:K2E:@?D ?665 7C6D9[ 6?828:?8 H2JD E@ <66A FD6CD G:8:=2?E] %9:D J62C’D <:E EFC?D D64FC:EJ 2H2C6?6DD :?E@ 2? :?E6C24E:G6 >:DD:@?[ 6>A@H6C:?8 6>A=@J66D E@ D66 E96>D6=G6D 2D 24E:G6 5676?56CD]”k^Am kAmQrJ36CD64FC:EJ pH2C6?6DD |@?E9 :D 2 C6>:?56C E92E 4J36CD64FC:EJ :D >@C6 E92? 2? x% :DDF6[” D2:5 {:D2 !=2886>:6C[ 6I64FE:G6 5:C64E@C[ }2E:@?2= rJ36CD64FC:EJ p==:2?46] “rJ36CD64FC:EJ D<:==D 2C6 =:76 D<:==D] tG6CJ A6CD@?[ 72>:=J[ 2?5 @C82?:K2E:@? 92D 2 C@=6 E@ A=2J :? 4C62E:?8 2 D276C 5:8:E2= H@C=5] (6VC6 8C2E67F= E@ A2CE?6CD =:<6 z?@Hq6c H9@ 96=A 6IA2?5 E96 C6249 @7 E9:D :>A@CE2?E H@C< 2?5 >2<6 :E A@DD:3=6 E@ 6BF:A >@C6 A6@A=6 H:E9 AC24E:42= 8F:52?46]”k^Am kAmz?@Hq6c’D 6:89E9 2??F2= rJ36CD64FC:EJ pH2C6?6DD |@?E9 C6D@FC46 <:E @C82?:K6D ~4E@36C :?E@ 7@FC H66<\=@?8 4J36C >:DD:@?D[ 7@4FD:?8 @? A9:D9:?8 U2>Aj D@4:2= 6?8:?66C:?8[ px D276EJ U2>Aj 566A72<6D[ 52E2
Aug 11, 2026 · via ncnewsonline.com
Professor Klinkner Presents on Cybersecurity and Privacy at Regional Summit
Law professor shares practical guidance with Midwest professionals on protecting data and navigating cybersecurity obligations.
Professor Blake A. Klinkner recently presented “Cybersecurity & Privacy Essentials: What Every Young Professional Should Know to Safely Manage Their Data” at the 2026 Young Professionals Regional Summit in Grand Forks. Speaking to several hundred professionals from across the Midwest, Professor Klinkner discussed the cybersecurity and privacy responsibilities of professionals and the organizations in which they work. He also offered practical best practices to help attendees strengthen their cybersecurity and privacy awareness in both their professional and personal lives.
Aug 11, 2026 · via blogs.und.edu
The cybersecurity talent shortage has reached a scale that organizations can no longer absorb or ignore. According to ISC2’s 2024 Cybersecurity Workforce Study, there are approximately 4.8 million unfilled cybersecurity positions globally, a workforce gap that continues to widen year over year. That number isn’t abstract — it represents actual vulnerabilities in working organizations, from small businesses to critical infrastructure to government systems. As digital threats grow more sophisticated and more frequent, the gap between the employable professionals and open positions — continues to widen. Higher education has a central role to play in closing it, and at National University, that’s exactly the work we’ve built our cybersecurity programs around. Key Takeaways - The cybersecurity talent shortage is driven by a persistent skills gap that headcount alone can’t solve - Employers need job-ready professionals with hands-on, applied experience, not just credentials - Universities play a critical role in preparing the next generation of cybersecurity professionals for today’s threat landscape Understanding the Cybersecurity Workforce Shortage The cybersecurity talent gap in the U.S. is one of the largest in the world. Despite steady growth in training programs, certifications, and university degree offerings, demand for talent continues to outpace supply. The shortage hits hardest in sectors like healthcare, finance, and government, where the sensitivity of data and regulatory requirements create the highest security stakes. The scope of the problem extends across organizations of every size. According to ISC2’s 2024 Cybersecurity Workforce Study, only 69 percent of organizations have entry-level cybersecurity professionals working within their team, a figure that drops to 64 percent in smaller companies. And when roles do open up, they don’t fill quickly. Almost half of all companies take more than six months to fill a cybersecurity vacancy, according to the same study. For organizations facing active threats, six months is
Aug 11, 2026 · via nu.edu
Virginia Cyber Range celebrates 10 years of advancing cybersecurity education The ninth annual Virginia Cybersecurity Education Conference brought together educators, government agencies, industry leaders, nonprofit organizations, and students from across Virginia to explore emerging technologies, share ideas, and prepare the next generation of cybersecurity professionals. Hosted by the Virginia Cyber Range, part of Virginia Tech’s Division of Information Technology, the two-day conference was held at Virginia Tech’s Academic Building One in Alexandria. This year’s event also celebrated the program’s first decade of expanding access to hands-on cybersecurity education. Attendees participated in hands-on workshops, keynote presentations, networking opportunities, and a Capture the Flag competition while exploring topics including artificial intelligence, cybersecurity workforce development, emerging technologies, and innovative approaches to cybersecurity education. Shannon Beck, director of the Virginia Cyber Range, said preparing educators and students for rapidly evolving technologies remains central to the program's mission. "We're always trying to prepare for that next wave of technology. Where is this information going? How do we keep our systems secure especially in light of ever emerging threats and technology, including artificial intelligence?" Beck said. Over the past decade, the Virginia Cyber Range has helped reshape cybersecurity education across the Commonwealth by making hands-on learning more accessible, scalable, and affordable. Through cloud-based learning environments, curriculum, capture the flag competitions, and professional development opportunities, the program has expanded access to practical cybersecurity instruction for educators and students alike. Today, the platform supports approximately 11,000 students each academic semester, making it easier for schools to deliver sophisticated cyber labs without the expense and maintenance of traditional infrastructure. Looking back on the conference's beginnings, David Raymond, associate vice president and chief information security officer at Virginia Tech, said the vision was always to create a community where educators could learn from one another. "This annual conference is one
Aug 11, 2026 · via news.vt.edu
Not long ago, passing an audit was treated as the finish line - a checkbox that told an organization it was secure. That assumption still lingers in a lot of boardrooms. Today, breaches keep happening at organizations that were fully compliant at the time. PCI DSS certified companies get breached. ISO 27001 certified companies get breached. Organizations that passed every SOC 2 audit still end up in the headlines. Compliance didn't fail them by accident - it was never designed to do what people assumed it was doing. The result isn't a rare exception worth a footnote. It's a pattern worth paying attention to. Compliance is neither useless nor sufficient. Its value depends on understanding exactly what it does - and, just as importantly, what it doesn't. Why Compliance and Security Aren't the Same Thing - Compliance Is a Point-in-Time Snapshot An audit measures whether controls were in place on the day it was conducted. Security is a continuous state that has to hold up every day in between. A network can be compliant on audit day and misconfigured a week later - and nothing about the certification changes that. - Compliance Defines a Minimum, Not a Ceiling Regulatory frameworks are built to apply across entire industries, which means they set a baseline broad enough to fit almost everyone. That baseline is rarely enough to stop a determined, targeted attacker - it was never designed to be the hardest bar to clear, just a common one. - Checklists Don't Account for Context A control that's appropriate for one organization's risk profile may be inadequate for another's. Compliance frameworks ask "is this control in place?" far more often than they ask "is this control enough for what you're actually protecting?" Two organizations can pass the same audit with very different real-world
Aug 11, 2026 · via crowe.com