Skip to main content

CISO Daily — Executive Cyber Intelligence for Security Leaders

AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board

AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board

Anthropic has confirmed the first large-scale cyberattack executed autonomously by an AI system. A Chinese state actor directed Claude Code through the full intrusion lifecycle against 30 global organisations with minimal human involvement. This briefing translates the implications for CISOs and their boards.

Briefing
about 1 month ago

Post-Quantum Cryptography: The Migration Decision CISOs Can No Longer Defer

NIST's post-quantum cryptography standards are final, NSA compliance deadlines for national security systems begin in January 2027, and adversaries are already collecting encrypted data for future decryption. This briefing provides CISOs with the governance framework for starting migration now.

Risk Analysis
3 months ago
Post-Quantum Cryptography: The Migration Decision CISOs Can No Longer Defer

Latest News

View all
  • IBM's 2026 Breach Report: AI Governance Gaps Are Now a Quantified Board Risk

    IBM's 2026 Breach Report: AI Governance Gaps Are Now a Quantified Board Risk

    IBM and Ponemon's 21st annual Cost of a Data Breach Report puts the global average at $4.99 million, with AI-enabled breaches running $1 million higher. The data gives boards a hard number for the AI governance gap they've been debating in the abstract.

    risk-analysis
  • Black Hat USA 2026: The Executive Threat Briefing

    Black Hat USA 2026: The Executive Threat Briefing

    Black Hat USA 2026 ran in Las Vegas this week. The themes that dominated — AI infrastructure exploitation as an independent attack discipline, nation-state credential harvesting through trusted third-party networks, and autonomous agent weaponisation — carry direct implications for enterprise risk posture. This briefing distils what security leaders need to know.

    Briefing
    7 min read
    AgentForger: When a Phishing Link Becomes a Persistent AI Insider

    AgentForger: When a Phishing Link Becomes a Persistent AI Insider

    Zenity Labs' disclosure of AgentForger demonstrates that enterprise AI agents can be weaponised from outside the organisation via a single phishing link, creating an attacker-controlled agent that inherits authorised access to email, calendar, Slack, and Teams. OpenAI patched the specific flaw in June — but the governance problem is structural and ongoing.

    Risk Analysis
    7 min read
    Zero Trust Is No Longer Optional: The Regulatory Mandates Making It a Compliance Requirement

    Zero Trust Is No Longer Optional: The Regulatory Mandates Making It a Compliance Requirement

    Zero Trust Architecture has moved from best practice to mandatory requirement. OMB M-22-09 federal deadlines are now enforceable, CISA's updated Zero Trust Maturity Model defines the measurement framework, and DORA, CIRCIA, and the UK Cyber Security and Resilience Bill are converging on the same underlying controls. Here's what the board needs to understand about where ZTA compliance now sits.

    Regulatory Update
    6 min read
    The 2026 Cyber Insurance Renewal: What Underwriters Are Now Requiring

    The 2026 Cyber Insurance Renewal: What Underwriters Are Now Requiring

    Cyber insurance underwriters have substantially tightened requirements since 2022. The questions have become more technical, the exclusions more specific, and the attestations more consequential. This briefing outlines what underwriters expect in 2026 and how security leaders should prepare.

    Risk Analysis
    7 min read