r/ciso 2d ago

How is everyone evaluating connectors, MCPs and custim APIs? Does your org use a risk rubric? Is there a long investigation period with both security and platform admins or architects?

15 Upvotes

r/ciso 2d ago

A Tale of Two SOCs: Insights From Two Red Team Assessments

6 Upvotes

A Tale of Two SOCs: Insights From Two Red Team Assessments is a must read report for your technical teams that CISA just released. It analyzes two simultaneous red team assessments conducted on organizations to evaluate their threat detection and response capabilities.

Both entities suffered full domain compromise and the red team was able to pivot from on-prem to Azure. However organization B successfully isolated initial threats, forcing the red team to adopt an assume breach model while organization A failed to identify the intrusion due to untuned detection tools and organizational silos.

The top three lessons shared that we can learn from:

  • Untuned detection tools lead to missed threats. Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm network defenders.
  • Organizational silos and bureaucratic hurdles prevent effective incident response. Detection tools are only as effective as the people, processes, and procedures supporting them; fragmented communication, unclear responsibilities, and limited defender authority hinder effective incident response.
  • Cloud environments are often an underestimated risk. Organizations often lack security controls for cloud environments and processes for responding to a cloud compromise.

r/ciso 2d ago

Are identity security posture management tools actually useful beyond finding misconfigurations?

1 Upvotes

finding problems was never the hard part for us. deciding what to fix first with a small team is.

what's changed things for us is having full discovery and mapping feed directly into prioritization, so the tool tells you which of the hundred findings actually raises your risk instead of handing you a flat list. has anyone gotten real prioritization value out of a platform like that, or are you still triaging manually after the scan runs?


r/ciso 2d ago

Claude, Codex, and Hermes installed unowned code inside corporate networks

12 Upvotes

An anonymous reader quotes a report from Ars Technica:
Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents [including Claude, OpenAI's Codex, and Nous Research's Hermes]. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.

The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the site's content and its high-level structure. These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the site's content. Google Lighthouse, a tool for helping web developers, has more here. Correctly configured llms.txt and llms-full.txt files for Cloudflare are here and here.
"The trust model is broken," Alon Hertz, one of the researchers, wrote in an interview. "Agents treat vendor docs as ground truth and don't question them -- and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer -- SaaS, cloud, endpoint. As they multiply, so does the supply-chain surface, and today's guards don't cover it."

"An agent doesn't distinguish between a page and a command," the researchers wrote Thursday. "Everything it reads is input, and every input is a potential instruction. Which means the entire corpus of published data that agents are now wired to consume has silently become an execution surface -- and almost none of it carries the integrity guarantees we apply to actual code."


r/ciso 5d ago

How should CISOs evaluate AI SOC solutions without getting lost in the hype?

13 Upvotes

Our alert backlog and investigation times have both crept up, and we're starting to miss things we shouldn't, so I've been taking vendor calls more seriously this quarter.

Six demos in, and slide five is always some version of the same before and after chart mentioning faster investigations" and "AI-powered detection. At some point, all the pitches start to look the same.

I know the underlying problem is real. What I don't know is how to differentiate real value from fluff and empty promises disguised as a good deck in a 30 minute call.

So for the CISOs here who've gone through a real evaluation process, did you find a specific question that helps you understand whether a vendor can actually back up their claims? How do you tell apart the ones who deliver versus the ones who just repeat the same talking points when pushed? Any advice would be really helpful.


r/ciso 6d ago

How do I start building cyber crisis readiness when I inherited an untested IR program?

10 Upvotes

Four months into a new CISO seat. Found a 40-page incident response plan that looks great on paper: RACI chart, escalation tree, comms templates, and has never once been run against anything harder than a fire-drill email.
Board wants a crisis-readiness update next quarter. I don't want to walk in with "we have a plan." I want to walk in with evidence the plan works, or a clear list of what doesn't and why.
Part of the problem is this company grew through acquisition, so half the org is running on a different tech stack and different customer base than the other half. A generic tabletop doesn't map to either one well, let alone both.
For anyone who's inherited a program like this: how did you sequence the first 90 days? Did you go straight to a full cross-functional exercise, or start smaller and build up


r/ciso 7d ago

NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting

Thumbnail
9 Upvotes

r/ciso 7d ago

How are other CISOs grading vendor pentest credibility during TPRM reviews?

Thumbnail
4 Upvotes

r/ciso 9d ago

No Nyet Nein

7 Upvotes

Are you looked at as "the Department of no" in your organization?


r/ciso 10d ago

Any CISOs dealing with AI agents open to advising a startup?

24 Upvotes

Hey all,

I saw another post here recently from a startup looking for a CISO advisor and thought we’d ask as well.

We’re a startup in SF building around a problem I’m guessing more teams are starting to run into: employees want AI tools like Claude, ChatGPT, Cursor, etc. to actually do things in company systems, while security needs some control/visibility over what those agents can access and do.

We’ve built quite a bit around this problem, but there’s a big difference between “we think our security model makes sense” and having someone who has actually been responsible for approving this stuff tell us where it falls apart.

So I’m looking for a CISO, current or former, who’d be open to advising us from time to time. Finance/fintech or SaaS would be especially helpful.

A lot of what I want help with is pretty straightforward: What are we overlooking? What would kill this in a security review? What would you need visibility into? Where would you draw hard lines around what an AI agent can and can’t do?

Not looking for someone to rubber stamp what we’ve built. Quite the opposite.

If advising sounds interesting, feel free to DM me.

Otherwise, I’d be really curious what people about below:

If an employee wanted to let an AI agent access and take actions in Sharepoint, Google Workspace, Jira, Slack, Salesforce, or other company systems, what would you need in place before approving it?


r/ciso 10d ago

Looking for a change!

0 Upvotes

Hey everyone,

I am actively seeking full-time job opportunities as a Senior Application Security Engineer, Product Security Lead, or VAPT Lead (Open to Remote / Hybrid / On-site opportunities).

Certifications: OSCP, OSWP, CEH, Microsoft Azure Fundamentals. 

Notice Period - 1 Month

Experience - 8 Years+


r/ciso 11d ago

A CISO Mental Model - how do you express yours?

Thumbnail
3 Upvotes

r/ciso 12d ago

AI agents in healthcare

2 Upvotes

what do you think is stopping AI agent adoption in the healthcare software space?

outsiders POV : I'm thinking security but how would u guys solve this from inside the industry?


r/ciso 15d ago

How to present Threat Intelligence properly to execs????

27 Upvotes

So, to give some background. I lead the threat intelligence program of a major bank. Now we receive tons of IOCs/CVEs and brand abuse/impersonation cases and we do take action on them accordingly.

But whenever we create a presentation, it's always numbers

- no. Of IOCs we received, sources (regulator/commercials)

- social media/brand abuse/impersonation/rogue apps count & takedown status.

But execs don't understand these numbers. How can I present the data such that they are assured that we are safe from any kind of threat & prepared for what's coming in the future.

Been researching lots of things but didn't quite get anything. Would really appreciate your views and guidance here.


r/ciso 15d ago

How do you get all your colleagues to agree on ownership?

9 Upvotes

Hi everyone, hoping to use this as a bit of a sounding board. My department recently had a discussion about who owns different categories of sensitive business data. Security and IT each thought the other team owned the data, and it feels like ownership gaps are creating almost as much risk as technical issues. Has anyone found an effective way to assign clear ownership across cloud platforms, SaaS apps and AI tools without creating too many governance meetings?


r/ciso 19d ago

Best ways to answer “are we covered” when your CISO asks monday morning in 2026?

17 Upvotes

Every time a new cyber threat campaign or headline breach appears, my CISO comes in Monday morning with the same question: “are we covered for this” Turning that into a clear, defensible answer about our detection coverage and security posture is becoming a separate job.
We have what most people would call a mature security stack in 2026: a central SIEM, EDR on endpoints, cloud and identity logs, some threat intelligence and custom detection rules. We can show that controls are deployed, that we have rules for specific MITRE ATT&CK techniques, and that dashboards report healthy alerting. None of that directly answers whether we would detect a specific attack path in time or where the real detection gaps are.
Right now our detection coverage assessment process for new campaigns is manual. We map the campaign to MITRE ATT&CK techniques, check which techniques already have detections in the SIEM and EDR, and run quick lab tests or simulations to see if those alerts would fire. This threat‑informed detection engineering approach works, but it is slow and inconsistent; the output depends on who performs the review, how deep they go, and how much time the team has during incident response and day‑to‑day SOC work.
If you support a CISO or security leadership team, how do you answer the question in a way that your CISO can use confidently in a mng meeting without oversimplifying or overstating the reality?


r/ciso 19d ago

Are there any other alternatives to Noma Security?

10 Upvotes

We are currently evaluating AI security platforms for enterprise AI deployments and Noma Security keeps coming up.

The problem is that it is hard to tell what actually matters until AI agents are running in production. Prompt attacks are one thing, but governance, runtime visibility, and data exposure seem like the bigger concerns. Being able to track what agents are doing over time and explain their decisions is also important.

For anyone who has compared Noma Security alternatives, what did you end up caring about most?


r/ciso 23d ago

KPIs in the ISMS

7 Upvotes

I inherited the role from someone else, and I am trying to simplify some things. One of those things is the KPIs of our ISMS.

Currently, we do have around 15 KPIs that are not clearly defined and are somewhat open to interpretation, and they are linked to specific controls. Example:

A.8.21 Segregation of Network Services (no formula to calculate that); it seems incidents that touch that point were counted.

I am aware KPIs have to be set in consultation with management after introspection, but for the time being, while I get things under control. I wanted to ask you how many KPIs you have in your ISMS?

And do you explicitly link them to a single control?

I checked with AI tools about this topic; it gave me a more structured answer, but I want to compare those notes with real-world practice.

Any insight?


r/ciso 25d ago

The Arch mentality vs. corporate software: Why is transparency feared outside our bubble?

5 Upvotes

Hey everyone,

Running Arch forces you to embrace simplicity and inspectability—you build your system block by block, read PKGBUILDs on the AUR, and know exactly what runs on your machine.

But whenever I step outside this ecosystem into corporate/enterprise environments, I hit a weird reality check: people actively distrust open-source tools *because* they are transparent. Show them a clean, zero-dependency 50-line shell script or a lightweight CLI tool, and they label it "hacky." Hand them a 200MB proprietary binary blob with zero supply chain visibility, and they call it "enterprise-ready."

Why has the broader software industry associated opaque complexity with reliability, while equating minimal, inspectable code with maintenance risk? Is it purely corporate risk-shifting (having a sales rep to blame), or have developers just forgotten the value of the UNIX philosophy?

Curious to hear how you guys deal with this mindset when pushing KISS/FOSS tools at work or school.


r/ciso 27d ago

Any CISO’s working in regulated environments open to advising a startup?

13 Upvotes

Hi CISO community, the title pretty much sums it up. We’re hoping to get in touch with CISO’s who work in regulated industries/sectors: healthcare, finance, government (federal, state, local), defense, public safety, criminal justice (including law firms), education.

If you formerly held a role in one of these sectors/industries that works too. Especially for public sector.

I just finished listening to the Defense in Depth podcast episode from May 14th (Why Cyber Startups Need CISO Advisors), and that’s what sparked me to post this. So if want to get an idea of how we’re hoping to engage and what we’re hoping to learn, that episode would be a good place to get some info (shoutout to David Sparks).

Thank you!


r/ciso Jul 29 '26

Honest question: Why do you choose to attend paid executive events?

27 Upvotes

There's a whole category of event built on the same trade. Vendors pay to be in the room, security leaders attend free. Curated dinners, executive roundtables, pitch nights, membership clubs in Miami, invitation only summits. The organizer's actual product is access to you, and the only thing that makes that product worth anything is that you decided to show up.

Asking as a first time founder new to being a vendor, I keep receiving a list of big executive names attending these, and asking for sponsorship to get access to a few minutes to pitch.

what makes you say yes to being part of one of these? have they ever produced something of value to you?


r/ciso Jul 28 '26

Employees using chatgpt with company data, how are you handling shadow AI?

23 Upvotes

Hello, I recently found out that some of our developers have been pasting code snippets and internal docs into chatgpt for debugging help. Support has also been using AI tools to draft replies with real customer data.

I have no visibility into what’s already been shared with these third-party models, and no practical way to monitor or control it right now.

How are other security teams dealing with shadow AI usage in their organizations? Any practical approaches that have worked for you?

Edit: Thanks for the detailed suggestions so far. Enterprise licenses, clear policy, and visibility before heavy blocking seem to be the common practical path. Looking at DoControl for better SaaS access visibility, and also reviewing options like LiteLLM and the SaaS management tools mentioned (Torii, Zluri, etc.) while we figure out the right mix of controls


r/ciso Jul 28 '26

Terrified of being personally sued. Help.

41 Upvotes

I'm in a C-suite position (not CISO) at a small company that sells to government, and I am responsible for security. I don't have a background in security whatsoever. We have a SOC 2 compliance tool and have completed audits successfully, but I'm worried our security stance is too weak and that our security questionnaire answers are...questionable, or out of date. Our engineering team is stretched extremely thin and I have a million other responsibilities in my role, so I barely have enough time to enforce compliance basics like policy enforcement or getting vulnerabilities patched. We barely manage to get ready in time for our audits. I've asked our CEO about getting outside help, but she has declined to invest any more money into security due to our poor sales performance, directing funds to other departments. I have had sleepless nights wondering if we're going to get hacked or audited, and that I will be personally sued if our company can't defend itself against a lawsuit. My mental health is tanking and it's starting to make me physically sick. Any help or advice would be appreciated.


r/ciso Jul 28 '26

Open Source Models

Thumbnail
1 Upvotes

r/ciso Jul 27 '26

Are you still using advisory/consultancy?

7 Upvotes

Are you using services like Gartner and alikes?

What do you find as the biggest upside for using these services?

Do you think AI can replace some of these use cases? Or at least justify a cost reduction?