CISO Tradecraft® Newsletter
Newsletter (Digital)
Are you a cybersecurity professional looking to learn how to become an executive leader in cybersecurity? Have you ever aspired to become a Chief Information Security Officer who is knowledgeable about the people, process, and technology issues found in the cybersecurity workplace? If so, please subscribe to the our newsletter. Source
Actions
Media Outlet details
| Scope | National |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesThinking About a Cybersecurity PhD? 5 Surprising Truths You Need to Know First
For seasoned cybersecurity leaders, enterprise architects, and CISOs reaching the upper bounds of their operational careers, a persistent question often emerges: Is pursuing a doctoral credential, whether a PhD or a Doctor of Science, worth the massive investment of personal time and intellectual energy?
Why Your 2026 Security Training is Already Obsolete
The Fatigue of the Familiar: Why We “Buzz Through” For anyone who has spent time in the orbit of the federal government, the imagery is burned into the collective consciousness: the same animated video, year after year, depicting the “dangers” of overseas travel. We all know the script, the same rental car at the airport, the same suspicious cardboard box tucked behind the rear wheel, and the same shadowy sedan tailing the protagonist to their hotel.
How to Create a Leadership Culture
In the high-stakes world of cybersecurity, many organizations mistake “security theater”, the endless checklists, mandatory slide decks, and annual compliance box-checking, for actual security. But security isn’t a checklist; it’s a force field. And that force field is generated by your organizational culture. As a CISO, you cannot afford to be a passive observer of the environment you work in. You must be an intentional architect.
Why You’re Still Coding Like It’s 2022: Surprising Lessons from the AI DevOps Frontlines
The era of hunting for missing semicolons and troubleshooting syntax for hours is not just fading, it is effectively dead. For decades, the software development paradigm was defined by manual labor: computer science majors pulling all-nighters to find a single misplaced colon. Today, that world has been replaced by “loop engineering” and autonomous tools like Claude Code. As we look toward the immediate 2026–2027 horizon, the cybersecurity DevOps landscape is undergoing a tectonic shift.
Why Your CRM is a Better Security Tool Than Your Firewall
For most small-to-medium business (SMB) leaders, the standard cybersecurity manual is a work of fiction. The “enterprise-grade” expectations, bloated frameworks, seven-figure hardware refreshes, and massive dedicated teams, simply do not scale down to a 50-person startup or a 13-person development boutique. When you try to force a mega-corp playbook onto a lean shop, you don’t just fail to secure the company; you alienate the very people you’re trying to protect.
Why Your AI Strategy is Only as Good as Your Network Governance
In the modern enterprise, developers can build and deploy a new application in a single afternoon. AI agents can modify infrastructure in a matter of seconds. Yet, in many organizations, opening the necessary network path for those applications still requires a manual ticket, three meetings, four approvals, and a specific engineer named “Bob” who happens to be on vacation.
Why the AI Revolution Makes Your "Old School" Skills More Critical Than Ever
From Slide Rules to Generative Agents The halls of Black Hat are always buzzing with the “next big thing,” but for those of us who have lived through the cycles, the current AI hype feels like a movie we’ve seen before, just with a much larger budget and far more CGI. I was at Black Hat 1 in 1997 at Caesar’s Palace. Back then, “hacking” was a manual craft. We were doing manual TCP/IP handshakes and wrestling with protocols in their rawest form.
The Invisible Attack Surface: 5 Legal Truths Every Security Leader is Missing
It happens in a single keystroke. An employee, eager to polish a board presentation, pastes your three-year internal product roadmap into a public AI tool to “summarize the key milestones.” In that moment, the perimeter you’ve spent millions defending doesn’t just breach; it dissolves. As security leaders, we’ve been conditioned to view threats through the lens of code, firewalls, and encryption. But this technocentric focus often leaves a massive “Legal Attack Surface” completely unmonitored.
The Agentic Escape: What Happens When AI Decides to Cheat
“It can’t be bargained with, it can’t be reasoned with, it doesn’t feel pity, remorse, or fear, and it absolutely will not stop, ever.” When G Mark Hardy opened a recent discussion with this iconic quote from The Terminator, he wasn’t just indulging in 80s nostalgia. He was framing a turning point in digital history. On July 16, OpenAI’s GPT-5.6 Sol model was placed in an “exploit gym”, a controlled environment meant to test its problem-solving limits.
The Legal Developments Every CISO Needs to Know
The legal landscape for cybersecurity professionals is shifting beneath their feet, often faster than corporate policy can keep pace.