Risk management

Risk management service

AI Compliance Cybersecurity Infrastructure Security Risk management Security

AI lowers the barrier for attacks on industrial systems

U.S. security agencies warn of active cyber threats targeting Siemens S7 PLCs, used across energy, water, manufacturing, and other critical infrastructure. Attackers are leveraging AI-generated exploits and internet scanning to identify and target exposed or poorly secured industrial control systems. AI makes ICS attacks faster and more accessible, reducing the level of specialized OT expertise […]

Multifactor Authentication Password Management Risk management Vulnerability

Passkeys are strong, but not untouchable

Researchers have uncovered new attack vectors that can undermine passkey authentication, challenging the idea that passwordless automatically means attack-proof. The attacks focus on weaknesses around the authentication flow and implementation, rather than breaking the underlying cryptography. Manipulation of WebAuthn processes, fallback mechanisms and compromised environments can potentially allow attackers to bypass or weaken passkey protection. […]

AI Compliance Information Security Risk management

Open-Source AI tools are strong on security, but Governance remains human

A new study maps 21 open-source AI risk tools against 32 risk categories, including Promptfoo, Garak, PyRIT, NeMo Guardrails and Langfuse. The ecosystem performs particularly well in AI testing, red teaming, content safety, data governance and post-deployment monitoring. But major gaps remain in board oversight, regulatory compliance, legal remedies and financial/market controls, areas software alone […]

AI Cybersecurity Risk management

Africa’s cyber threat surge: where AI supercharges digital crime

Cybercrime across Africa is evolving into a highly organized, AI-enabled ecosystem, with ransomware, business email compromise (BEC), online scams, data breaches, and digital sextortion driving unprecedented financial and societal damage. AI is accelerating phishing, deepfakes, identity fraud, and cybercrime-as-a-service, while weak legislation, limited cyber capabilities, and fragmented cross-border cooperation continue to benefit criminals. Financial services, […]

Cybersecurity Information Security Risk management Vulnerability

ENISA’s new CRA Maturity Model is a practical roadmap for SME Cyber Resilience

The European Union Agency for Cybersecurity (ENISA) has released a practical Cyber Resilience Maturity Assessment Model to help SMEs prepare for the Cyber Resilience Act (CRA) before it becomes fully applicable in December 2027. The model focuses on five key domains: governance, secure-by-design risk management, vulnerability & patch management, product lifecycle management, and cybersecurity skills. […]

Cybersecurity Hack Information Security Risk management Vulnerability

Autonomous AI agent breach signals a new era of cyber threats

Hugging Face disclosed a groundbreaking cyberattack in which an autonomous AI agent independently executed the entire intrusion—from initial compromise to privilege escalation and lateral movement. The attacker exploited vulnerabilities in the dataset-processing pipeline, performing more than 17,000 automated actions over a single weekend without direct human control. Although public models, datasets, and the software supply […]

AI Cybersecurity Information Security Risk management

Why AI governance will define tomorrow’s winners in the board room

AI has evolved from a technology initiative into a board-level strategic and enterprise risk that demands continuous oversight, not periodic reviews. Boards must establish clear governance, accountability, and AI risk appetite while ensuring innovation is balanced with responsible use. Traditional cybersecurity alone is no longer sufficient, organizations must protect AI-driven decision-making, data, identities, and autonomous […]

AI Ethics Uncategorized Privacy Risk management

EU AI Act to address the potentially harmful effects of artificial intelligence

The European Parliament has passed a draft law known as the A.I. Act, which aims to regulate artificial intelligence (AI) and its riskiest uses.The draft law would impose new restrictions on facial recognition software and require AI system developers to disclose more about the data used in their programs. The European Union has been debating […]