Expert Analysis – Help Net Security

Expert analysis Archives – Help Net Security Daily information security news with a focus on enterprise security.

  • 338 million attack simulations reveal the state of enterprise defense
    by Help Net Security on August 12, 2026 at 5:00 am

    First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have barely moved the needle at all against the quiet ones. This data, and a lot more, comes straight from the newly published Blue Report 2026, the fourth annual comprehensive study from Picus Labs. Based on more than 338 million attack simulations run in real production environments in … More → The post 338 million attack simulations reveal the state of enterprise defense appeared first on Help Net Security.

  • Who will be the Stanislav Petrov in your organization?
    by Help Net Security on August 11, 2026 at 6:00 am

    The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported that the United States had launched nuclear missiles towards the Soviet Union. The officer on duty, Stanislav Petrov, did something computers still struggle to do. He applied context, experience, and human judgement to determine the warning … More → The post Who will be the Stanislav Petrov in your organization? appeared first on Help Net Security.

  • August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
    by Help Net Security on August 7, 2026 at 6:00 am

    July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs were identified in the Security Updates Guide. Interestingly, only two CVEs were reported as exploited zero-days and only one as publicly disclosed, but we’ll get back to that later in this article. There were 405 CVEs reported against Windows 11 … More → The post August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? appeared first on Help Net Security.

  • Shadow AI is becoming enterprise security’s biggest blind spot
    by Help Net Security on July 23, 2026 at 6:00 am

    Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly every business function. Microsoft’s 2026 Work Trend Index found that employees often adopt AI faster than their organizations can adapt to it. As AI is integrated into team members’ daily jobs, businesses are struggling to keep pace with governance, management practices, … More → The post Shadow AI is becoming enterprise security’s biggest blind spot appeared first on Help Net Security.

  • The MDR renewal question: What changes when AI can handle the alerts
    by Help Net Security on July 15, 2026 at 5:00 am

    For most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response to a provider who could. It solved a resources problem, and the alternatives (hiring a team you couldn’t afford or keeping a functional set of SOAR playbooks across an expanding alert surface) were worse. But a growing number of security leaders are looking at their next MDR … More → The post The MDR renewal question: What changes when AI can handle the alerts appeared first on Help Net Security.

  • Why SBOMs, signing, and provenance still don’t tell you if software is safe
    by Help Net Security on July 13, 2026 at 6:30 am

    We have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces back to Executive Order 14028, which pushed agencies, contractors and enterprises to invest in SBOMs, signing and provenance. All of that matters, but it is not enough. The current software trust model still stops short of the question that determines risk at execution: What is this code capable of doing if … More → The post Why SBOMs, signing, and provenance still don’t tell you if software is safe appeared first on Help Net Security.

  • July 2026 Patch Tuesday forecast: Is CVE tracking still practical?
    by Help Net Security on July 10, 2026 at 7:30 am

    I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers in both common applications like Office and SharePoint Server as well as the host of development tools and libraries like Visual Studio and .NET. Will the … More → The post July 2026 Patch Tuesday forecast: Is CVE tracking still practical? appeared first on Help Net Security.

  • How to implement a continuous offensive security testing program
    by Help Net Security on July 8, 2026 at 4:30 am

    The hard part was never finding the exposure. It was deciding what to do about it: whether to patch, mitigate, monitor, or accept, and banking that that decision would still hold tomorrow. A penetration test answers this question for the day it runs, then quietly expires. The environment shifts, a control drifts, a new technique lands, and the report now describes a network that no longer exists. That gap, between finding an exposure and trusting … More → The post How to implement a continuous offensive security testing program appeared first on Help Net Security.

  • How to prioritize AI agent security by business impact
    by Help Net Security on July 6, 2026 at 6:30 am

    Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected to a spend management application to reconcile invoices, summarize vendor contracts and flag unusual payment activity. The breakdown occurred when the employee who configured it left and the OAuth grant remained active, allowing the agent to … More → The post How to prioritize AI agent security by business impact appeared first on Help Net Security.

  • What a financial planner taught me about cybersecurity
    by Help Net Security on July 1, 2026 at 6:30 am

    When I spoke at a recent cybersecurity awareness event for financial planners and tax advisors, the audience really engaged with the subject. As happens at conferences the world over, people often come up to speakers to ask follow-up questions, or just give their feedback about points made during the presentation. This time, it struck me how many of them said they had been scared by what they heard during my talk. As I made my … More → The post What a financial planner taught me about cybersecurity appeared first on Help Net Security.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.