So you want to work in <b>Cybersecurity</b>?
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
Top Cybersecurity Marketing Agencies in 2026: The Specialists Who Actually Understand the Industry The post Top Cybersecurity Marketing Agencies in 2026: The Specialists Who Actually Understand the Industry appeared first on Deepak Gupta | AI & Cybersecurity Innovation Leader | Founder's Journey from Code to Scale. Cybersecurity is one of the hardest industries to market. Your buyers are CISOs, security architects, and IT leaders who have seen every pitch, distrust every vendor by default, and can spot a generalist agency within one slide. Generic B2B marketers struggle here because they do not understand the buyer, the threat landscape, or the technical proof points that actually close deals. The right cybersecurity marketing agency brings three things to the table: deep domain knowledge inside the founding and delivery team, proprietary data about how security buyers behave, and a track record with recognized security brands. After reviewing the field, here are the agencies that genuinely earn all three. What Makes a True Cybersecurity Marketing Agency Before the list, a quick filter. A genuine cybersecurity marketing agency should: - Employ former CISOs, security practitioners, or analysts, not just B2B writers. - Understand categories like SIEM, XDR, SASE, Zero Trust, EDR, DSPM, and IAM without needing a glossary. - Own or access first party data on cybersecurity buyer behavior. - Have case studies with named security vendors, not just "an enterprise tech client." - Show up at RSA Conference, Black Hat, and BSides as participants, not tourists. If an agency fails three of those five, keep looking. 1. CyberTheory CyberTheory is the most cybersecurity native agency on the market. It operates as the marketing advisory arm of ISMG (Information Security Media Group), which gives it access to intent data drawn from over 2 million cybersecurity subscribers across 14 media brands and roughly 350 annual events.
Students and faculty in the Department of Computer Science and Software Engineering recently presented research at the 14th International Symposium on Digital Forensics and Security (ISDFS 2026) in Boston, MA, held March 19-20. Their corresponding paper was published by IEEE Xplore. The article, “Porting and Evaluating Return-Oriented Programming Defenses Implemented by the OpenBSD Operating System,” finds that software defenses designed to block a common cyberattack technique may not be as effective as previously believed. The research was conducted through the Monmouth University Cybersecurity Research Center by computer science graduate students Jenna Esposito ’25 and Aaila Arif ’25 and senior computer science student Raul Cortinas, alongside Brian Callahan, Ph.D., specialist professor in the Department of Computer Science and Software Engineering. The study examined protections from the OpenBSD operating system aimed at blocking return-oriented programming (ROP), a method attackers use to exploit existing code in software. After testing two of these defenses in the FreeBSD operating system, the researchers found only modest results. The techniques reduced exploitable code fragments by up to about 3.6% and caused only small increases in program size, with little impact on performance. However, the protections did not stop automated tools from successfully creating attack chains. The researchers concluded that while the defenses add some protection, they are not effective on their own and should be combined with other security measures, especially for older systems lacking modern hardware protections. “Working on boundary-pushing projects like these prepares our graduates to lead the 21st century cybersecurity workforce,” said Callahan. “The depth and variety of our research speaks both to Monmouth’s ability to bring the best and brightest students here and to the University’s support of the Cybersecurity Research Center as we work to make Monmouth the best place in New Jersey to study cybersecurity.” The ISDFS conference offers a platform
As cyberthreats advance, so too must workforce cyber defences to avoid making what are often preventable and costly mistakes. Cybersecurity measures in the workplace never grind to a halt, in that employees and employers must always strive to ensure that their skills and systems are as advanced, if not more so, than those wielded by people with malicious intent. A lot of cybersecurity is arguably common sense – don’t click suspicious links, don’t share sensitive information and so on – but it doesn’t hurt to have a refresher course now and then to keep it all fresh in the mind. To that point, here are some of the most helpful tips to follow if you want to improve or maintain your company’s cybersecurity efforts. Silo your systems This one is specifically for anyone who works from home. It goes without saying that we feel comfortable in our own properties and have tried and tested ways of doing things. But there is such a thing as being too comfortable and employees may forget that their systems should never overlap with the organisations. If you are using company software, keep all activity tied to the workplace. That is to say, don’t download anything not approved by the organisation, or anything you are using in a personal capacity. Furthermore, if you move around and work between locations – for example at home, a cafe, a work hub – do your due diligence first and ensure that the network you are using is secure. This can be easier said than done, as using public Wi-Fi in general can be risky. With that in mind, shared office spaces and hubs tend to be a more secure option. If you are using what could be a potentially non-secure network in a public place, always use a
April 27, 2026 Cybersecurity Awareness Month at UCalgary spotlights AI, data and privacy Editor's note: This is a digital safety message from UCalgary IT. April is Cybersecurity Awareness Month at UCalgary! This is an excellent time to focus on staying up to date with university policies and follow best practices for protecting the university’s information assets. The campaign theme for this month is AI, Data and Cybersecurity: Protecting What Matters, providing an opportunity to look at how AI is impacting cybersecurity at the university. With that in mind, UCalgary’s IT Security and Privacy teams have provided the following resources to better support you: - UCalgary’s IT Security website (it.ucalgary.ca/it-security) – Find resources and tips on cybersecurity and privacy-awareness training. - AI website (ai.ucalgary.ca) – Explore UCalgary’s AI teaching, learning and research resources. - IT Security (ucalgary.ca/it) – Report any suspicious activity by clicking "Report an issue." - Access and Privacy website (ucalgary.ca/legal-services/acess-information-privacy) – Find guidelines and FAQs regarding privacy best practices. UCalgary’s IT Cybersecurity and Privacy teams have also compiled a list of ways to build stronger cyber-safety habits with AI: - Verify before you trust: Always verify AI-generated information through trusted sources before making important decisions. - Protect sensitive data: Never enter sensitive or confidential data into AI tools unless they are officially approved and secure. - Be alert to deepfakes: Be cautious of deepfake audio, video or messages that could impersonate trusted individuals. - Understand AI bias and limitations: Remember that AI can be biased or inaccurate, so review outputs critically before relying on them. - Use approved AI tools only: Use only organization-approved AI platforms to reduce cybersecurity and privacy risks. We appreciate your continued support with building cybersecurity awareness on our campus community. Together, we can build a robust cybersecurity culture at UCalgary.
What happens when students are allowed to use artificial intelligence to solve cybersecurity challenges? That question took center stage as Electrical Engineering and Computer Science (EECS) Professor Endadul Hoque hosted a capture-the-flag (CTF) cybersecurity competition at the College of Engineering and Computer Science, bringing together 20 undergraduate, master’s, and Ph.D. students. Unlike traditional CTF competitions, participants in this event were allowed to use modern AI assistants, such as ChatGPT and Claude, while solving challenges. The competition was designed not only to test technical skills, but also to explore how AI is transforming the way students learn and approach complex cybersecurity problems. “Cybersecurity education is evolving rapidly with the rise of AI tools,” Hoque says. “This competition gave us a unique opportunity to observe how students use AI in real time—whether it helps them think more deeply about problems or simply speeds up solutions. Understanding that distinction is critical for the future of computer science discipline.” Participants competed individually across 10 challenges spanning beginner, intermediate and advanced levels. The top three performers—Weixiang Wang (first place), Annepu Sai Charan (second place) and Armani Isonguyo (third place)—were ranked based on the number of challenges solved and the speed at which they completed them. Students described the experience as both exciting and challenging, noting that AI could guide their thinking but still required careful verification. “This reflects how we approach computer science and cybersecurity education at Syracuse University,” says Alex Jones, the Klaus Schroder Professor and chair of Electrical Engineering and Computer Sciences. “AI tools are only as effective as their operators. They do not replace expertise. Dr. Hoque’s work is a great illustration of this approach. We emphasize deep fundamental knowledge while also encouraging the use of AI. This ensures our graduates can effectively use, evaluate, guide, and validate AI-driven solutions.” To better
Ransomware payouts, supply‑chain breaches, and state‑backed attacks have pushed cybersecurity spending into the category of must‑have corporate expenses rather than optional upgrades. For investors who want exposure to the security budgets that swell after every major breach, thematic ETFs offer a cleaner entry point than trying to pick winners in an industry where market share can shift overnight. This article breaks down three cybersecurity ETFs, what each one actually owns, how their approaches differ, and the tradeoffs that come with each strategy. It also highlights one popular ticker that often gets lumped into the group but doesn’t truly belong in the cybersecurity category. Why security spending keeps compounding Corporate IT budgets can tighten in a downturn, but security spending almost never does. The attack surface keeps widening as companies move more workloads to the cloud, industrial systems come online, and remote employees log in from home networks. That is why cybersecurity stocks often behave like long‑term growth stories even when the broader software sector cools. The ETFs below capture that theme in different ways: one is a globally diversified pure‑play, one is a newer low‑cost option, and one is the largest and most established fund in the space. Global X Cybersecurity ETF (BUG) Global X Cybersecurity ETF (NASDAQ:BUG) tracks the Indxx Cybersecurity Index, a basket built around companies whose core revenue comes from selling security products or services. The fund holds roughly $864 million in net assets and leans heavily toward US-listed names, with 77% in the United States, a meaningful sleeve in Israel at 9%, and Japan at 8%. Holdings tilt toward cloud and endpoint security. Top positions include Palo Alto Networks at 11%, Akamai Technologies at 7%, and Fortinet at 7%. The Israeli allocation comes through Check Point and identity names like CyberArk, giving BUG coverage of a
Top from this category: April 2026 Cyber threats don’t stick to business hours. Learn how ESET MDR extends your existing endpoint protection with 24/7 monitoring, expert-led detection and response, and faster containment, helping your team stay secure, compliant, and focused on what matters most. Don't miss out WHITE PAPERS Compliance Gaps That Put Healthcare Data at Risk Healthcare compliance is complex and even well‑run organizations face security gaps. Learn where healthcare data is most at risk and how to close compliance gaps without stretching already limited teams. PREMIUM CONTENT WHITE PAPERS Definitive Guide to XDR: Current Threats, Challenges & Solutions Cyber threats are evolving fast and traditional defenses can’t keep up. XDR delivers unified visibility, advanced analytics, and automated response to stop attacks before they spread. PREMIUM CONTENT WHITE PAPERS Navigating Ransomware in 2025: Key Insights & Prevention Strategies Stay ahead of ransomware threats! Explore the latest trends, prevention strategies, and discover our new tool—ESET Ransomware & Remediation. Ready for next step? Enter the world of enterprise protection Ready for next step? Enter the world of enterprise protection
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency's Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025 with a new malware called FIRESTARTER. FIRESTARTER, per CISA and the U.K.'s National Cyber Security Centre (NCSC), is assessed to be a backdoor designed for remote access and control. It's believed to be deployed as part of a "widespread" campaign orchestrated by an advanced persistent threat (APT) actor to obtain access to Cisco Adaptive Security Appliance (ASA) firmware by exploiting now-patched security flaws such as - - CVE-2025-20333 (CVSS score: 9.9) - An improper validation of user-supplied input vulnerability that could allow an authenticated, remote attacker with valid VPN user credentials to execute arbitrary code as root on an affected device by sending crafted HTTP requests. - CVE-2025-20362 (CVSS score: 6.5) - An improper validation of user-supplied input vulnerability that could allow an unauthenticated, remote attacker to access restricted URL endpoints without authentication by sending crafted HTTP requests. "FIRESTARTER can persist as an active threat on Cisco devices running ASA or Firepower Threat Defense (FTD) software, maintaining post-patching persistence and enabling threat actors to re-access compromised devices without re-exploiting vulnerabilities," the agencies said. In the investigated incident, the threat actors have been found to deploy a post-exploitation toolkit called LINE VIPER that can execute CLI commands, perform packet captures, bypass VPN Authentication, Authorization, and Accounting (AAA) for actor devices, suppress syslog messages, harvest user CLI commands, and force a delayed reboot. The elevated access afforded by LINE VIPER served as a conduit for FIRESTARTER, which was deployed on the Firepower device before September 25, 2025, allowing the threat actors to maintain continued access and return to the compromised appliance as recently as last month. A Linux ELF binary, FIRESTARTER can
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
Governor McKee Announces Finalization of Settlement with Deloitte Related to RIBridges Cybersecurity Incident Published on Friday, April 24, 2026 PROVIDENCE, RI — Governor Dan McKee today announced that the State of Rhode Island, through the Department of Administration, has finalized a settlement agreement with Deloitte Consulting LLP related to the December 2024 RIBridges cybersecurity incident and the subsequent system restoration efforts. Under the terms of the agreement, at Governor McKee’s and the State’s request, Deloitte has agreed to pay the State an additional $7 million. Early last year, Governor McKee secured a $5 million payment from Deloitte for unexpected expenses related to the incident, bringing the State’s total direct financial recovery to $12 million. Deloitte has also provided $6 million worth of system enhancements, operational support, and business continuity services in response to the incident that were outside the scope of their contract. The State will not incur additional charges for these services. “This agreement reflects a deliberate effort to protect Rhode Island taxpayers while ensuring the State has the resources needed to move forward,” said Governor McKee. “During the cybersecurity incident, my administration worked diligently to ensure Rhode Islanders maintained access to their benefits. Our focus remains on supporting Rhode Islanders who rely on these critical benefits.” “This was a comprehensive and carefully negotiated agreement,” said Thomas Verdi, Acting Director of the Department of Administration. “It ensures the State receives additional financial support while also capturing significant value in additional technological enhancements and operational support services during system restoration.”
LPL Claims Hackers Accessed Client Accounts Through Advisors’ Devices LPL reports that malware from phishing led to unauthorized transactions in client accounts. LPL Financial is the latest firm to reveal a cybersecurity incident. According to a notice submitted to Maine’s Attorney General, the breach led to “unauthorized securities transactions and financial transfers” in some clients’ accounts. According to the data breach notification information on the attorney general’s site, LPL notified affected consumers regarding the breach that occurred on November 10, 2025 and was discovered 10 days later. A sample letter to clients provides details on the breach that affected clients working with “a small number” of the firm’s affiliated financial advisors. (LPL reported that 1,581 total clients were affected, and only two in Maine.) “Our investigation found that malware distributed through phishing messages affected a limited number of individual advisor devices and resulted in unauthorized third-party access to the accounts of those advisors on LPL’s web-based advisor portal,” the sample letter read. LPL stated in the letter that it contacted law enforcement after discovering the breach and conducted an internal investigation. While the firm didn’t identify specific evidence that “sensitive personal information was accessed or acquired by a third party,” it couldn’t rule out the possibility that third parties may have seen some clients’ information during the breach. When LPL found that breach, it stopped the activity, secured the affected accounts, and restored “any impacted accounts to their original financial positions.” The firm also implemented new “technical safeguards” to bolster its existing security and found no evidence that its systems remained compromised. The firm offered affected clients a complimentary two-year Experian credit monitoring membership. According to an LPL spokesperson, the firm "identified unusual activity involving accounts associated with a very small number of affiliated advisors. The activity was promptly contained,
Trump’s twice-chosen pick to run the U.S. federal cybersecurity agency CISA has requested to withdraw from the position, leaving the agency without any clear person to lead it on a permanent basis. In a letter to the White House on Wednesday, Sean Plankey requested that the Trump administration withdraw his nomination, citing a holdup in the Senate, which is required to hold a vote to approve his appointment. Plankey said it has “become clear” that the Senate will not confirm him, more than a year after he was first nominated to lead CISA. The New York Times published a copy of Plankey’s letter on Thursday. Politico first reported Plankey’s decision to withdraw his nomination. Both publications said that Plankey was unlikely to reach a majority vote needed for his appointment as Sen. Rick Scott (R-FL) was blocking his nomination over a Coast Guard contract unrelated to cybersecurity. Plankey previously served as a senior adviser to Coast Guard leadership. Nick Andersen has been the acting director of CISA since the departure of Madhu Gottumukkala in February. Gottumukkala was appointed in May 2025 to oversee the agency on a temporary basis but left less than a year later after a tumultuous tenure in the role. CISA is tasked by Congress with cybersecurity defense and infrastructure protection across the civilian federal government. The agency has faced a challenging year, following at least three government shutdowns, several rounds of furloughs, and budget cuts and staff reductions as directed by the White House, despite a raft of cyberattacks facing the U.S. government and its allies over the past year. Earlier this month, the Trump administration requested to slash CISA’s budget by more than $700 million amid claims that the agency was engaged in “censorship” — referring to CISA’s efforts to counter election misinformation during the
Microsoft and OpenAI tighten cybersecurity pact as AI models reshape defender workflows Microsoft and OpenAI have confirmed a deeper cybersecurity collaboration that will see Microsoft's Office of the Chief Information Security Officer (CISO) gain access to OpenAI's most cyber-capable models through the Trusted Access for Cyber program, the two companies announced on LinkedIn. The pact pairs OpenAI's cyber-focused model work with Microsoft's Secure Future Initiative, formalizing a defender stack that stretches across cloud, identity, productivity and frontier AI. It lands at a moment when AI-assisted attacks are climbing and open-source dependencies remain a persistent weak point across enterprise software. The announcement also signals a broader repositioning of AI labs inside the security supply chain. According to reporting around OpenAI's recent cyber defense expansion, Anthropic has also released a frontier model variant positioned for security use, meaning the top AI labs are increasingly being drawn directly into defender workflows rather than sitting behind hyperscaler partnerships. The Microsoft deal makes that shift explicit for joint customers already running on Azure, Microsoft 365 and Microsoft Security. GPT-5.4-Cyber moves into Microsoft's defender stack Trusted Access for Cyber is OpenAI's tiered program for vetted security teams, built on the principle that advanced cyber tools should be broadly available to defenders under identity verification and organizational validation controls. OpenAI confirmed in its own announcement that the program is scaling to thousands of verified individual defenders and hundreds of teams responsible for defending critical software, and that participants include major enterprises and security vendors across financial services, cloud, and cybersecurity. In a joint statement posted on LinkedIn, Microsoft Security wrote, "AI models are becoming much more capable in cybersecurity, and that progress raises the bar for everyone. As capabilities advance, we're focused on deep collaboration with defenders to make software more resilient." The post confirmed that OpenAI
Google Cloud’s operations chief said the tech giant does not plan to release a separate, cyber‑focused frontier model like Anthropic’s Clause Mythos. Instead, Google believes high‑quality generalist AI models, like Gemini 3.1 Pro, Google’s latest large language model (LLM), are already strong enough across domains to meet cybersecurity needs. Speaking at Google Cloud Next 26, Francis DeSouza, COO of Google Cloud, said that while early thinking in the deployment of generative AI anticipated many domain‑specific frontier models, the reality has now changed. “What we found over time was that the core model was doing really well and that it started to get good across all domains,” he added. “For example, coding is now done incredibly well by Gemini and you don't need a coding specific Gemini model. We are finding that inside our security too, that models themselves are getting better and better. I believe that Gemini is a terrific model for our security. You shouldn't expect to see a cyber version that's different.” The practical path forward, DeSouza argued, is to apply a high‑quality, generalist frontier model together with the right tooling and governance, rather than fragmenting effort into niche frontier models. Read more: Google Introduces Unique AI Agent Identities Google plans to combine the latest Gemini versions with agent and platform capabilities to meet cyber defense needs. DeSouza said that enterprises should focus on integrating strong general models into security workflows, training them with context, wrapping them with access controls and embedding them in automated detection, triage and response pipelines. Yinon Costica, co-founder and VP of product at Wiz, now part of Google Cloud, said that cyber defenders possess richer, more organization‑specific context than attackers and feeding that context into a strong general model produces better defensive outcomes. AI competitors like Anthropic and OpenAI are pursuing specialized paths,
The AI model that Anthropic billed as too dangerous to release has reportedly been accessed by an unauthorized third party, and the incident raises concerns about the future of cybersecurity. The Mythos model was reportedly accessed by a handful of users in a private Discord chat on the day it was announced publicly, Bloomberg reported. Earlier this month, the group was able to access the program in part because one of the members of the group is a third party contractor for Anthropic, according to Bloomberg. Using this access, the group was able to guess where the model was located based on previously leaked knowledge by another group about Anthropic’s past practices, that hackers obtained from AI training startup Mercor. Although the group that accessed it has not been using the model for cyberattacks, it has been using the program continuously since its release and still has access, the outlet reported. Anthropic did not immediately respond to Fortune’s request for comment. A spokesperson from Anthropic told Bloomberg the company was “investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments.” The fact that the model was leaked so quickly doesn’t surprise David Lindner, the chief information security officer at Contrast Security and a 25-year industry veteran. Even though Anthropic intentionally limited the model to a small group of 40 companies—including Microsoft, Apple, and Google— to beef up their security ahead of a wider release, thousands of people likely had access to the program across these companies, which makes a leak nearly inevitable, he said. “It was bound to happen,” Lindner said. “The more they add to this elite group, the more likely it was to get released to someone who shouldn’t probably have access to it.” Anthropic claims its Mythos model is more
Three consecutive Inc. 5000 appearances and back-to-back #1 MSSP honors — now the founder behind 2.5 million protected users earns EY recognition. TAMPA, FL, UNITED STATES, April 23, 2026 /EINPresswire.com/ — When a wave of SonicWall-related attacks hit earlier this year, Ridge IT Cyber‘s clients saw the intrusion attempts detected and contained automatically — identities locked down user by user before attackers could move laterally. Organizations without that identity-first architecture got breached. That outcome — the difference between a contained event and a business-impacting one — is why Ridge IT Cyber co-founder and CEO Chad Koslow has just been named a 2026 finalist for the EY Entrepreneur of the Year® Florida program, which includes entrepreneurs from both Florida and Puerto Rico. Regional winners will be announced June 12, 2026. The thesis that built the company Most cybersecurity vendors sell products against a checklist. Ridge IT Cyber was founded on the opposite premise: the tools only matter if the architecture survives a real attacker. That conviction — forged supporting some of the most demanding government environments in the world — has grown into a firm that today protects more than 2.5 million users across 160 countries, has delivered more than 1,500 Zero Trust implementations in the last three years, and maintains a 99% client retention rate. It’s also why Ridge IT Cyber has stacked recognition most MSSPs never see: • Inc. Magazine’s #1 MSSP in America — back-to-back, 2023 and 2024 • Inc. 5000 national list — three consecutive years (2023–2025) • Inc. Regionals: Southeast — three consecutive years, including 2026 • CRN MSP 500 — 2025 • Zscaler Partner of the Year • Okta Service Delivery Authorized – Okta Workforce Identity (OWI) and Okta Customer Identity (OCI) Why this matters to the people buying security in 2026 The threat landscape
Three consecutive Inc. 5000 appearances and back-to-back #1 MSSP honors — now the founder behind 2.5 million protected users earns EY recognition. TAMPA, FL, UNITED STATES, April 23, 2026 /EINPresswire.com/ — When a wave of SonicWall-related attacks hit earlier this year, Ridge IT Cyber‘s clients saw the intrusion attempts detected and contained automatically — identities locked down user by user before attackers could move laterally. Organizations without that identity-first architecture got breached. That outcome — the difference between a contained event and a business-impacting one — is why Ridge IT Cyber co-founder and CEO Chad Koslow has just been named a 2026 finalist for the EY Entrepreneur of the Year® Florida program, which includes entrepreneurs from both Florida and Puerto Rico. Regional winners will be announced June 12, 2026. The thesis that built the company Most cybersecurity vendors sell products against a checklist. Ridge IT Cyber was founded on the opposite premise: the tools only matter if the architecture survives a real attacker. That conviction — forged supporting some of the most demanding government environments in the world — has grown into a firm that today protects more than 2.5 million users across 160 countries, has delivered more than 1,500 Zero Trust implementations in the last three years, and maintains a 99% client retention rate. It’s also why Ridge IT Cyber has stacked recognition most MSSPs never see: • Inc. Magazine’s #1 MSSP in America — back-to-back, 2023 and 2024 • Inc. 5000 national list — three consecutive years (2023–2025) • Inc. Regionals: Southeast — three consecutive years, including 2026 • CRN MSP 500 — 2025 • Zscaler Partner of the Year • Okta Service Delivery Authorized – Okta Workforce Identity (OWI) and Okta Customer Identity (OCI) Why this matters to the people buying security in 2026 The threat landscape
CISO Diaries: Stefano Pasotti on Cybersecurity as Strategy, Not Cost Cybersecurity is often viewed through the lens of controls, compliance, and incident response, but its real value is much broader. In CISO Diaries, we speak with security leaders around the world to understand how they approach the role beyond the technical domain, particularly on how they make decisions, manage uncertainty, and align security with business resilience. The series explores the routines, habits, and perspectives that shape modern security leadership, revealing the human judgment behind the frameworks. As the role of the CISO continues to expand, the job is increasingly about more than protecting systems. It is about enabling continuity, supporting operational efficiency, and helping organizations make better decisions in the face of complexity. Through these conversations, CISO Diaries highlights how security leaders are not just defending against risk, but helping shape strategy, culture, and long-term competitive advantage. About Stefano Pasotti Stefano Pasotti is CISO and ICT Manager at DN Automotive Italy, where he leads cybersecurity, IT infrastructure, and digitalization initiatives across European operations. His career spans software development, strategic IT leadership, and cybersecurity, with deep experience connecting technology decisions to business outcomes across manufacturing and logistics environments, including WMS, production planning, EDI, and IoT integration. Known for his pragmatic and strategic approach, Stefano views cybersecurity not as a cost center, but as a driver of resilience, efficiency, and competitive advantage. His perspective is shaped by operating in multinational environments where security requires not only technical expertise, but cultural alignment, regulatory awareness, and careful communication. Through that lens, he brings a leadership approach grounded in discipline, continuous learning, and the belief that effective security is inseparable from sound business strategy. How do you usually explain what you do to someone outside of cybersecurity? I say I’m the person who makes sure
Last week, Anthropic announced Project Glasswing, an AI model so effective at discovering software vulnerabilities that they took the extraordinary step of postponing its public release. Instead, the company has given access to Apple, Microsoft, Google, Amazon, and a coalition of others to find and patch bugs before adversaries can. Mythos Preview, the model that led to Project Glasswing, found vulnerabilities across every major operating system and browser. Some of these bugs had survived decades of human audits, aggressive fuzzing, and open-source scrutiny. One had been sitting for 27 years in OpenBSD, generally considered to be one of the world’s most secure operating systems. It's tempting to file this under "AI lab says their AI is too dangerous," the same playbook OpenAI ran with GPT-2. Not so fast; there's a material difference this time. Mythos didn't just find individual CVEs. - It chained four independent bugs into an exploit sequence that bypassed both the browser renderer and the OS sandboxing - It performed local privilege escalation in Linux through race conditions - It built a 20-gadget ROP chain targeting FreeBSD's NFS server, distributed across packets. Claude Opus 4.6, Anthropic's previous frontier model, failed at autonomous exploit development almost entirely.Mythos hit a 72.4% success rate in the Firefox JS shell. This isn't theoretical, nor some new three-to-five-year prediction. This is about to be a real-world engineering reality. Why Project Glasswing Exposes the Real Cybersecurity Gap Here's the number that should keep security leaders awake at night: fewer than 1% of the vulnerabilities found by Mythos were patched. Let that sink in for a moment. The most powerful vulnerability discovery engine ever built ran against the world's most critical software, and the ecosystem couldn't absorb the output. Glasswing solved the finding problem. Nobody solved the problem of fixing. Why Defenders Can't Keep