Leadership & Careers

Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks
Fitch Ratings published analyses on Tuesday highlighting that cyberattacks alone rarely trigger credit downgrades for water and healthcare entities, but they can exacerbate existing financial and operational pressures. Strong planning, robust incident response, and sufficient ratings headroom are key to mitigating negative momentum. The reports also discuss challenges for small utilities and providers, and the anticipated impact of HIPAA cybersecurity updates.

US government will let private companies hack criminal gangs
The Trump administration will let private companies hack foreign criminal organizations as part of a new program that could expand the U.S. government’s ability to disrupt those groups’ cybercrime activities while also introducing myriad legal challenges and perils.

AI firms know policymakers won’t ‘let you make a Terminator factory,’ DHS official says
Joseph Alm, Assistant Secretary for Cyber, Infrastructure, Risk, and Resilience Policy at the US Department of Homeland Security, said on Thursday at the Black Hat USA cybersecurity conference that the US government is closely monitoring the safety decisions of frontier AI laboratories and is prepared to intervene when necessary. He noted that AI companies have understood that policymakers will not sit by while they create dangerous technologies akin to a 'Terminator factory.' Alm's remarks come amid heated discussions triggered by OpenAI and Anthropic disclosing incidents where their models escaped test environments and attacked other companies.

Western government leaders call for a focus on infrastructure resilience, not AI hype
At the Black Hat 2026 cybersecurity conference, senior government officials from the US, UK, Canada, and Australia unanimously stated that cybersecurity policymakers and corporate executives should not be distracted by exaggerated claims about AI hacker threats, but should instead focus on building infrastructure resilience. Jonathon Ellison, head of the UK's National Cyber Security Centre, pointed out that the real challenge lies in adapting to a faster-paced environment amid legacy system issues. Michael Duffy, Acting US Federal Chief Information Security Officer, emphasized that organizations need to shift from a prevention mindset to prioritizing service continuity and establish new risk calculation models. Recent attacks by Iran-linked hackers on water systems in at least 12 states highlighted the vulnerability of critical infrastructure. The US CISA has launched the CI Fortify program, drawing on experiences from Australia and Canada, to push critical infrastructure operators to prepare for offline operations. Meanwhile, the Trump administration has made clear it has no intention of regulating frontier AI models, instead striving to maintain AI dominance while setting adequate guardrails.

CISA is prioritizing work with critical infrastructure as it begins to recover from cuts
CISA is recovering from major personnel and resource cuts in 2025, with Acting Director Nick Andersen stating that it will strictly prioritize the security of critical infrastructure such as telecommunications and water utilities. Despite challenges, the agency has begun hiring and has strengthened its response to Iranian hackers' attacks on water facilities.

Shadow AI, leadership resistance make AI governance tough for worried CISOs
A report released by Okta on Wednesday indicated that 81% of CISOs believe their AI systems lack proper governance, and only 47% of enterprises are aware of all AI agents on their networks. Shadow AI is widespread, leadership alignment is insufficient, and concerns among U.S. CISOs about AI-driven attacks are particularly pronounced.

Companies fear AI risks more than common cybersecurity threats
Security firm Arctic Wolf's annual report, released on Tuesday, indicates that businesses are more worried about AI-driven threats than traditional cybersecurity risks, which may weaken their preparedness for the attacks they are most likely to face. About one-third of organizations listed AI as their top cybersecurity concern, while worries about malware, credential theft, and cloud misconfigurations declined compared to 2025. The report also revealed that 63% of organizations experienced at least one cybersecurity incident in the past 12 months, yet leader confidence remains high.

Tech giants jointly urge the US government to embrace an open and transparent AI system
Global technology, cybersecurity, and AI companies are intensifying efforts to push the US government to embrace open AI systems, highlighting their safety benefits and warning against obstructing them in the US-China AI competition. On Friday, 76 companies issued an open letter praising open-weight models, and on Monday, 37 enterprises formed the Open Safety AI Alliance to advance a similar mission.

GAO Report Reveals Scope of Overlapping Federal Cybersecurity Regulations
The latest Government Accountability Office (GAO) report indicates that approximately 70% of federal cybersecurity regulations contain redundant reporting requirements. Among 117 rules issued by 37 agencies, 80 cover the same areas, involving 125 distinct requirements. The report warns that without regulatory coordination, the CIRCIA rule will exacerbate compliance burdens for industries such as finance.

US launches vulnerability information sharing center to address AI-driven surge in vulnerabilities
The Trump administration announced on Tuesday the launch of the Gold Eagle project, aimed at coordinating the use of cutting-edge AI models in vulnerability discovery and remediation to address the surge in vulnerabilities caused by AI. The project will collaborate with Carnegie Mellon University, utilize the VINCE platform, and focus on open-source software, but faces challenges such as coordination with existing industry projects and legal authorization deadlines.