Skip to main content

CISO Daily — Executive Cyber Intelligence for Security Leaders

AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board

AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board

Anthropic has confirmed the first large-scale cyberattack executed autonomously by an AI system. A Chinese state actor directed Claude Code through the full intrusion lifecycle against 30 global organisations with minimal human involvement. This briefing translates the implications for CISOs and their boards.

Briefing
about 7 hours ago

Post-Quantum Cryptography: The Migration Decision CISOs Can No Longer Defer

NIST's post-quantum cryptography standards are final, NSA compliance deadlines for national security systems begin in January 2027, and adversaries are already collecting encrypted data for future decryption. This briefing provides CISOs with the governance framework for starting migration now.

Risk Analysis
about 2 months ago
Post-Quantum Cryptography: The Migration Decision CISOs Can No Longer Defer

Latest News

View all
  • Zero Trust Is No Longer Optional: The Regulatory Mandates Making It a Compliance Requirement

    Zero Trust Is No Longer Optional: The Regulatory Mandates Making It a Compliance Requirement

    Zero Trust Architecture has moved from best practice to mandatory requirement. OMB M-22-09 federal deadlines are now enforceable, CISA's updated Zero Trust Maturity Model defines the measurement framework, and DORA, CIRCIA, and the UK Cyber Security and Resilience Bill are converging on the same underlying controls. Here's what the board needs to understand about where ZTA compliance now sits.

    regulatory-update
  • The 2026 Cyber Insurance Renewal: What Underwriters Are Now Requiring

    The 2026 Cyber Insurance Renewal: What Underwriters Are Now Requiring

    Cyber insurance underwriters have substantially tightened requirements since 2022. The questions have become more technical, the exclusions more specific, and the attestations more consequential. This briefing outlines what underwriters expect in 2026 and how security leaders should prepare.

    Risk Analysis
    7 min read
    Building an Insider Threat Programme: A CISO Playbook

    Building an Insider Threat Programme: A CISO Playbook

    Insider threats account for a disproportionate share of high-impact data loss events. Building a detection and response programme requires balancing UEBA technology, HR integration, legal frameworks, and employee privacy rights. This briefing covers programme design, governance, technology selection, and the organisational challenges CISOs consistently underestimate.

    Risk Analysis
    9 min read
    DORA Operational Resilience Testing: What Financial Sector CISOs Must Deliver

    DORA Operational Resilience Testing: What Financial Sector CISOs Must Deliver

    DORA's Threat-Led Penetration Testing requirements under Article 26 apply to significant financial entities across the EU and have extraterritorial reach for UK firms with EU operations. Here's what CISOs need to have in place, the testing scope requirements, and how to manage third-party ICT provider involvement.

    Regulatory Update
    7 min read
    SAP ERP: The Attack Surface Your Security Programme Probably Under-Indexes

    SAP ERP: The Attack Surface Your Security Programme Probably Under-Indexes

    SAP environments are among the highest-value targets in enterprise IT — they hold payroll, financials, supply chain, and HR. Yet many security programmes treat SAP as an IT infrastructure question rather than a board-level risk. This briefing covers the real attack surface and what CISOs need to ask.

    Risk Analysis
    7 min read