Skip to main content

CISO Daily — Executive Cyber Intelligence for Security Leaders

AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board

AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board

Anthropic has confirmed the first large-scale cyberattack executed autonomously by an AI system. A Chinese state actor directed Claude Code through the full intrusion lifecycle against 30 global organisations with minimal human involvement. This briefing translates the implications for CISOs and their boards.

Briefing
about 1 month ago

Post-Quantum Cryptography: The Migration Decision CISOs Can No Longer Defer

NIST's post-quantum cryptography standards are final, NSA compliance deadlines for national security systems begin in January 2027, and adversaries are already collecting encrypted data for future decryption. This briefing provides CISOs with the governance framework for starting migration now.

Risk Analysis
3 months ago
Post-Quantum Cryptography: The Migration Decision CISOs Can No Longer Defer

Latest News

View all
  • The Annual Cyber Insurance Renewal Is Dying: What Continuous Underwriting Means for CISOs

    The Annual Cyber Insurance Renewal Is Dying: What Continuous Underwriting Means for CISOs

    Carriers are moving away from once-a-year, point-in-time underwriting toward continuous monitoring of a policyholder's security posture. For CISOs, that turns cyber insurance from an annual paperwork cycle into a year-round governance obligation — with real budget and reporting consequences.

    briefing
  • Black Hat USA 2026: The Executive Threat Briefing

    Black Hat USA 2026: The Executive Threat Briefing

    Black Hat USA 2026 ran in Las Vegas this week. The themes that dominated — AI infrastructure exploitation as an independent attack discipline, nation-state credential harvesting through trusted third-party networks, and autonomous agent weaponisation — carry direct implications for enterprise risk posture. This briefing distils what security leaders need to know.

    Briefing
    7 min read
    AgentForger: When a Phishing Link Becomes a Persistent AI Insider

    AgentForger: When a Phishing Link Becomes a Persistent AI Insider

    Zenity Labs' disclosure of AgentForger demonstrates that enterprise AI agents can be weaponised from outside the organisation via a single phishing link, creating an attacker-controlled agent that inherits authorised access to email, calendar, Slack, and Teams. OpenAI patched the specific flaw in June — but the governance problem is structural and ongoing.

    Risk Analysis
    7 min read
    Zero Trust Is No Longer Optional: The Regulatory Mandates Making It a Compliance Requirement

    Zero Trust Is No Longer Optional: The Regulatory Mandates Making It a Compliance Requirement

    Zero Trust Architecture has moved from best practice to mandatory requirement. OMB M-22-09 federal deadlines are now enforceable, CISA's updated Zero Trust Maturity Model defines the measurement framework, and DORA, CIRCIA, and the UK Cyber Security and Resilience Bill are converging on the same underlying controls. Here's what the board needs to understand about where ZTA compliance now sits.

    Regulatory Update
    6 min read