Nine AI security lessons for CISOs on agents, identity, governance, compliance, cognitive risk, open source and human resilience.
Featured
In his CYBR.SEC.CON. 2026 keynote, Joe Marshall introduces the Human Incident Response Framework, a practical playbook for recognizing cybersecurity burnout, secondary traumatic stress, vicarious trauma and moral injury — and responding before the human incident becomes a crisis.
Entergy CISO Ann Delenela used her CYBR.SEC.CON. 2026 keynote to argue that AI and accelerating change demand something technology cannot provide: deliberate, accountable human leadership.
Community Corner
See allFrom the CYBR.SEC.Community
Cybersecurity Coherence Reduces Cognitive Risk, But Is Not Perfect
Three teams are talking at once. An attacker may still be active. The logs disagree. The current owner is on vacation. A cloud console shows one state, the SIEM shows another, and the incident commander has a spreadsheet that was copied from a spreadsheet that was correct last quarter.
How 9/11 Led Me to Cybersecurity — and What 25 Years Has Taught Me
Twenty-five years after the Sept. 11 attacks, I look back at how 9/11 changed my life, led me into cybersecurity and shaped how I see our responsibility to protect the systems and civilization we depend on.
Your Security Architecture May Be a Sideways Driveway
Security architecture accumulates “adaptation debt” when local fixes, exceptions and compensating controls force users, systems and now AI agents to work around designs that no longer match how identity, authority and data actually flow.
What Radio Jamming Taught Me About DDoS
From Army signal intelligence and radio jamming to modern DDoS defense, the same lessons in reconnaissance, timing, disruption and adaptation reveal how attackers overwhelm networks — and how defenders can stay ahead.
The Human Factor in IAM: Why Identity Programs Succeed or Fail
Most IAM failures don't start with a broken platform. They start with a person making a reasonable decision under bad conditions.
Latest Articles
See all
Work-Life Balance in CybersecurityMental Health
Cybersecurity Work-Life Balance Starts With Actually Turning Off
Cybersecurity professionals cannot defend organizations indefinitely without real downtime. CYBR.SEC.Community co-founder and OT security veteran Sam Van Ryder says employers and practitioners share responsibility for making sure defenders actually disconnect.
CYBR.SEC.CONCYBR.SEC.Media weekly UpdatesAbove the Packet: Field Notes from the Meaning Layer9-11Agentic AIAI GovernanceAI SecurityAI SOCAI security risksCISOLeadership
Cybersecurity’s Human Breaking Point: AI, Burnout and Cognitive Overload
CYBR.SEC.CON. 2026 put cybersecurity’s human toll front and center, from AI-driven cognitive overload to leadership, burnout and defender resilience.
AI and ComplianceCyber ResilienceAI Governance
Cyber Compliance Is Not Cyber Resilience. AI Is Widening the Gap
RegScale CISO Dale Hoak explains why point-in-time cybersecurity compliance cannot keep pace with AI-driven threats — and why continuous controls, risk management and resilience must replace the checkbox mindset. (Sponsored by RegScale)
CISOLeadership
Does the CISO Need a Board Seat? That's Not the Real Question
RegScale CISO Dale Hoak says the cybersecurity leadership debate should focus less on reporting lines and more on ensuring cyber risk reaches the board — while security, compliance and engineering stop fighting separate battles. (Sponsored by RegScale)
Open-Source SecuritySuricataCYBR.SEC.CON
Open Source Security Runs The Internet. Kelley Misata Says Code Is Only Half The Battle
At CYBR.SEC.CON 2026, OISF President Kelley Misata explains why critical open source security projects like Suricata depend on more than developers — and why funding, governance, licensing and succession planning are now cybersecurity issues.
Hugging FaceAI GovernanceAI security risks
OpenAI Agents Left a Wider Trail on Hugging Face
OpenAI agents left a larger public trail on Hugging Face than the company documented in its account of unauthorized activity earlier this year, according to a new SentinelLabs investigation.
LaunchPadCYBR.SEC.CON
Astelia wins CYBR.SEC.CON 2026 LaunchPad competition
The exposure management startup beat four other early-stage cybersecurity companies at CYBR.SEC.CON 2026, pitching an approach that focuses remediation on vulnerabilities attackers can actually reach.
Podcasts & Video
See all
Podcast
Log Off with Sam Van Ryder
Podcast
Compliance Whack-a-Mole with Dale Hoak
Video
Trust in the Age of AI
Video
CometJacking and Domain Swarms: Hunting AI Attacks in the Staging Phase
Video
You Can’t Automate Judgment: The Limits of AI in Cyber Threat Intelligence
Podcast
From Used Car Sales to Counterterrorism with Christian Schnedler
Video