Archive for July, 2026

EY Canada makes leading investment in Quantum Computing

Posted in Commentary with tags on July 30, 2026 by itnerd

EY Canada today announced the expansion of its quantum computing capabilities to help clients solve increasingly complex business challenges in areas of optimization, fraud detection and large-scale risk management. The investment in an on-site quantum computer further enables the processing of highly sensitive workloads within Canadian borders, helping organizations meet growing security, privacy and regulatory requirements.

Moving from experimentation to real-world application

EY is continuing its Client Zero approach, developing and testing quantum-enabled solutions within its own environment to help move visionary ideas toward practical use for clients. Owning the system in-house helps organizations meet stringent regulatory, privacy and industry requirements that cloud-based alternatives cannot always address.

The new capability provides dedicated access and greater control over the development of new applications, including where data resides, how it is managed and who can access it. This includes enhancing the testing, refinement and validation of quantum-enabled solutions in areas such as financial optimization, advanced fraud detection, data protection and large-scale system planning. These applications span financial services, energy, supply chain and government, where organizations increasingly need to balance operational complexity with data sovereignty, privacy and regulatory requirements.

This investment builds on EY’s recent quantum patent and strengthens the ability to help clients identify where quantum can deliver measurable value while advancing Canada’s position in the global quantum tech ecosystem through local innovation.

Driving global innovation forward

The new quantum capability is part of EY’s global investment of more than US$3 billion in AI and next-generation technologies, helping clients move beyond experimentation to unlock new opportunities in forecasting, optimization, decision intelligence and risk management. The investment also aligns with ey.ai The Reimagination Engine, EY’s AI-led technology system designed to help organizations transform with confidence.

Check Point Revolutionizes the Firewall Market: New AI Network Firewall Closes the Network’s AI Blind Spot — Everywhere 

Posted in Commentary with tags on July 30, 2026 by itnerd

Check Point Software Technologies Ltd. (NASDAQ: CHKP), a pioneer and global leader of cyber security solutions, today announced the Check Point AI Network Firewall, delivered as part of Check Point firewall software release R82.20. AI has introduced a new class of network traffic — prompts, autonomous agent actions, and sensitive business context — that traditional firewalls were never designed to see or secure. The AI Network Firewall closes that gap from the Check Point firewall organizations already run, delivered through Check Point’s AI Defense Plane with no new infrastructure and no rearchitecting. 

The exposure is already universal. Check Point Research’s AI Security Report 2026 found that between 87% and 93% of organizations experience at least one high-risk generative-AI interaction every month and the share of prompts carrying sensitive corporate, personal, or regulated data doubled in a year to one in every 25 interactions. Organizations are adopting AI faster than they can govern it, and the activity that needs governing is already moving across the network. 

Turning existing firewalls into immediate AI protection 

Unlike alternatives that require a separate virtual firewall deployed alongside existing infrastructure, Check Point delivers this protection directly from the physical or virtual firewalls customers already operate and scales across branches, data centers, cloud, and multi-cloud environments. For Check Point firewall customers, the AI Network Firewall turns existing firewall investments into immediate AI protection across three domains: 

  • Employee AI use: Discover AI apps, agents, and tools in use — both shadow and sanctioned — gain visibility into how AI is being used and prompt use-cases and intents, govern access to safe and sanctioned tools, and stop sensitive data from leaving the network based on the prompt’s use case. Check Point Research found organizations now run an average of ten AI applications per month, many outside any formal process 
  • AI Tools (MCP): Discover Model Context Protocol (MCP) communication, gain full visibility into servers and used tools, and enforce policies to control access across every interaction. Check Point Research found security weaknesses in 40% of 10,000 MCP servers reviewed 
  • AI Application and LLM: Prevent prompt injection and adversarial inputs, blocking malicious prompts before they reach the LLM. This happens inline, with no application changes required. Check Point Research identified 15,300 indirect-injection payloads planted in public web pages, roughly 70% of them hidden in parts of the page no human ever sees 

Part of the AI Defense Plane: one architecture across the enterprise 

The AI Network Firewall becomes part of Check Point’s AI Defense Plane, a unified control plane for discovering, governing, and protecting AI across the network, endpoints, cloud, applications, and APIs. Together, the AI Defense Plane delivers: 

  • Discovery, governance, and protection for AI across web, desktop, coding assistants, and AI agents 
  • Local AI agent discovery and control 
  • SaaS AI agent discovery and control 
  • Runtime protection and governance for AI applications 
  • Risk detection and guardrails to protect homegrown and deployed AI 

Additional enforcement points across the AI Defense Plane span standalone API for self-managed applications, endpoint for employees, containerized firewall for AI data centers, and WAF – giving organizations consistent AI security across public and private clouds, branch offices, remote users, and data centers. 

Unified, agentic management across a hybrid, multi-vendor environment 

Following the recent announcement of its agentic network security orchestration platform, Check Point is also extending central policy management to Check Point SASE and SD-WAN, with dynamic, always-accurate zero-trust policy enforcement across IT, OT, and micro-segmentation tools including Illumio and others: 

  • One console manages on-premises firewalls, cloud firewalls, AWS native firewalls, SD-WAN, and SASE with consistent policy and a unified audit trail across every environment 
  • SD-WAN connectivity and security policy are managed together, ending the operational split that forces teams to juggle separate tools 
  • Open-platform integrations keep firewall rules current as the environment changes, without manual reconciliation  

Check Point AI Network Firewall is available now. Learn more here

BreachLock Publishes 5th Annual Penetration Testing Intelligence Report Mapping Critical Attack Paths and Actionable Cyber Resilience Strategies

Posted in Commentary with tags on July 30, 2026 by itnerd

BreachLock, the only offensive security platform combining agentic AI-powered autonomous penetration testing, expert-led, agentic AI-accelerated penetration testing services, and continuous Attack Surface Management (ASM), today announced the release of its 2026 Penetration Testing Intelligence Report, the company’s fifth annual analysis of real-world security findings across global organizations. Based on data from 4,970 penetration tests and 531,770 individual security findings, the report provides a comprehensive analysis of the vulnerabilities, attack patterns, and emerging risks shaping the cybersecurity landscape in 2026 and beyond.

Among the report’s most significant findings is the emergence of AI as a major enterprise attack surface. BreachLock’s inaugural AI penetration testing dataset found that 100% of AI applications tested contained vulnerabilities aligned with the OWASP Top 10 for LLMs. Prompt injection (LLM01) was the most prevalent and impactful finding in the dataset, present in 28% of tested applications.

The report also identifies a sharp shift in how attackers are targeting web applications. Insecure Design and business logic flaws (OWASP A04) rose from 8% to 16% of findings year over year, a trend-defining increase in the 2026 web application dataset. Testers observed attackers exploiting race conditions in checkout flows, escalating privileges through parameter manipulation, and bypassing approval workflows outright. These issues do not appear on automated scanner reports. Finding them requires testers who understand how an application is supposed to behave and can reason through how that logic can be subverted.

Cloud environments produced the highest concentration of severe risk in the dataset. Cloud security audits carried a Critical finding rate of 1.34%, thirteen times higher than the rate found in web application testing, driven largely by exposed S3 buckets, leaking Lambda functions, and disabled GuardDuty monitoring.

Mobile applications showed a similarly narrow but severe risk profile. Hardcoded credentials in iOS applications accounted for 97% of all Critical mobile findings this year. These credentials can be extracted with free, publicly available tools in minutes, and credential-related vulnerabilities continue to be a top attack vector in headlines this year.

The report also highlights industry-specific risk trends across manufacturing, telecommunications, financial services, healthcare, retail, and technology organizations.

BreachLock’s 2026 report is designed to help security leaders benchmark their programs against real-world offensive security data while providing actionable recommendations for reducing exposure through continuous testing, adversarial validation, cloud governance, mobile application security, and AI security assessments.

Download the BreachLock 2026 Penetration Testing Intelligence Report or read the blog for highlights.

Cinchy Joins AI Partnerships Partner Network to Help Enterprises Accelerate Trusted AI Adoption

Posted in Commentary with tags on July 30, 2026 by itnerd

As enterprises race to deploy artificial intelligence across every part of the business, one reality is becoming increasingly clear: successful AI adoption requires more than powerful models. It requires a trusted ecosystem of strategy, implementation, governance and security working together to help organizations deploy AI with confidence.

Today, Cinchy announced it has joined the AI Partnerships (AIP) network, expanding access to PeriMind through a growing ecosystem dedicated to helping enterprises accelerate trusted AI adoption.

PeriMind is Cinchy’s AI Action Governance platform. AI Action Governance is an emerging layer of enterprise AI infrastructure that provides runtime governance, policy enforcement and operational oversight for AI systems as they interact with enterprise data, applications and business processes. By helping organizations understand, control and audit every AI action, PeriMind enables enterprises to move AI from experimentation into trusted business operations.

The partnership reflects an important shift in the enterprise AI market. Organizations have largely moved beyond asking whether AI can create business value. Instead, they are focused on how to deploy AI securely, govern AI actions across the enterprise and build the operational trust required to move from isolated pilots to production-scale AI.

Through its AI Action Governance, PeriMind offers a new operational layer that provides visibility, policy enforcement, runtime controls and complete auditability for AI systems operating across enterprise data, applications and business processes.

Enterprise AI is becoming too complex for any single vendor to solve alone. Organizations increasingly need strategic advisors, implementation specialists, governance platforms, security technologies and integration partners working together to support successful AI adoption. The AI Partnerships partner network brings together complementary expertise that helps customers move more quickly (and more safely) from experimentation to enterprise-wide deployment.

Through the partnership, organizations working with AI Partnerships will have access to PeriMind’s AI Action Governance capabilities, including:

  • Runtime governance for AI systems and autonomous agents
  • Secure connectivity between AI and enterprise data and applications
  • Continuous visibility into AI actions and interactions
  • Policy enforcement and human oversight
  • Comprehensive audit trails supporting compliance, accountability and operational trust

Together, Cinchy and AI Partnerships will help enterprises address one of AI’s biggest adoption challenges: ensuring AI remains secure, governed and accountable as it begins making recommendations, initiating workflows and taking actions across critical business systems.

For Cinchy, the partnership represents another step in advancing its vision of trusted AI adoption, helping organizations bridge the gap between AI innovation and enterprise operations through governance that enables, rather than slows, AI transformation.

AI Is Creating a Trust Gap in Business Email, Exclaimer Research Finds

Posted in Commentary with tags on July 30, 2026 by itnerd

Exclaimer has released research showing that AI is weakening a basic assumption of business communication: that a polished, professional email reflects the authority and identity of the person who sent it.

The nationally representative OnePoll study of 1,000 US adults found that 65% now use AI in some aspect of their communications. At the same time, 36% have questioned whether a message they received was genuine, while 14% say they do not trust emails from external companies at all. The findings point to a growing gap between how credible an email appears and how confidently recipients can verify who is behind it.

AI is in the inbox and not just for productivity

AI has quickly become a routine part of how Americans communicate. Nearly two-thirds (65%) now use AI in some aspect of their communications, most commonly to improve grammar and spelling (20%) or make their writing sound more professional (19%).

But the research suggests AI is doing more than helping people write better. It is increasingly shaping how they present themselves. Sixteen percent use AI to sound more confident in their communications, 12% use it to soften difficult messages, 10% use it to avoid awkward conversations, and 9% use it to hide uncertainty. That means the tone of an email may no longer reliably reflect the sender’s own judgment or authority.

The more professional the email looks, the easier it is to trust

Trust in company email is already under pressure. More than a third (36%) say they have questioned whether a message they received was genuine, while 14% do not trust emails from external companies at all.

That uncertainty is changing what we look for when deciding whether to believe an email. Rather than relying solely on the quality of the writing, recipients increasingly judge the sender. Full contact details (40%), a professional email address on a company domain (35%), and a clear sender name (30%) are the strongest trust signals.

One finding stands out. Nearly one in four (23%) say a professional, branded email signature makes a company email feel more trustworthy. They ranked it ahead of legal disclaimers (17%) and consistent formatting (16%), suggesting that recipients see the signature as more than a visual flourish.

A verified company domain, a named individual, and a consistent branded signature help recipients distinguish between a message that simply looks convincing and one that comes from a real, identifiable, and accountable person.

Email continues to carry some of the most important communications between organizations and the employees and customers they serve. It is the preferred channel for employer updates (35%), formal complaints to a company (33%), and healthcare information (27%). Its value also lies in permanence. When employees need information they can keep or refer back to, 43% choose email, more than twice the proportion who select any other platform. A further 33% have deliberately used email instead of another channel because they wanted a permanent record.

When recipients cannot tell whether a message is genuine or identify the person responsible for sending it, the reliability of that communication begins to break down.

Sender identity is becoming business infrastructure

The platform carrying a message already influences how people receive it. Forty-three percent say the channel affects how trustworthy a communication feels, while 39% say it shapes their view of its professionalism and authenticity.

For businesses, securing the domain is no longer enough. Organizations also need consistent control over how sender identity is presented in every email, including the name, contact details, company information, and the attached signature. As AI makes professional communication easier to produce at scale, governance must ensure that every message can still be traced to a real person, a legitimate organization, and an accountable source.

Access Exclaimer’s full When it Matters: How People Really Communicate study.

Read the blog here.

FAA issues American Airlines nationwide ground stop over IT outage

Posted in Commentary with tags on July 30, 2026 by itnerd

American Airlinesand its regional carriers resumed flights ‌on Tuesday evening after a brief nationwide halt to departures over an IT issue, the airline said.

The Federal ​Aviation Administration issued a ground stop for ​American Airlines flights due to an IT ⁠outage that took effect around 6:30 p.m. ​ET (2230 GMT) and was canceled at 7:18 p.m.

The issue ​delayed hundreds of flights because planes could not depart until it was resolved, and it came as many U.S. ​East Coast airports were experiencing significant delays ​and ground stops due to thunderstorms.

Reuters has a story here on this: https://www.reuters.com/world/faa-issues-american-airlines-nationwide-ground-stop-over-it-outage-2026-07-28/

Jamie Beckland, CPO at APIContext, had this comment: 

“Even a brief technology failure can immediately become a nationwide operational event. Organizations cannot wait for customers or frontline employees to discover that a critical service has stopped working.

Operational readiness requires proactive, continuous monitoring of the complete services a business depends on—from networks and APIs to third-party platforms and the workflows employees use to keep operations moving. Monitoring must show not simply whether individual components are online, but whether the organization can still perform critical actions safely and successfully from the locations where they matter.

We see these service interruption issues increasing as AI places additional demand on data centers, networks and shared cloud infrastructure while also increasing the pace and complexity of technology change. Organizations need to test their operational readiness continuously, identify degradation before it becomes an outage, and understand their dependencies well enough to isolate and recover from failures quickly”.

I would get used to this sort of thing happening as everything is interdependent on everything else. Cloud services for example. That is until organizations develop redundancy so that these sort of issues do not happen.

BreachLock Adds Human Verification Layer to Autonomous Penetration Testing for Machine Speed with Expert Accountability

Posted in Commentary with tags on July 30, 2026 by itnerd

BreachLock announced today that BreachLock AEV customers can now get human-verified results on any autonomous penetration testing engagement. One toggle adds a certified BreachLock penetration testing expert as the final checkpoint to review every objective, finding, and vulnerability, effectively eliminating false positives.

BreachLock Adversarial Exposure Validation (AEV) is the company’s agentic AI-powered autonomous pentesting solution trained on 40,000+ real-world penetration testing engagements. Its skilled agents think, adapt, and safely chain exploits across network and web environments in production the way a senior pentester would.

Customers rely on AEV to continuously prove which risks are exploitable and can be chained together with supporting evidence and targeted mitigation actions. Nothing about how AEV runs, exploits, or proves exploitability changes when the toggle is on. Human-verified results add an optional final checkpoint on top, for organizations that want expert accountability behind the deliverable, supplied by BreachLock rather than their own team.

Human-verified results are built for security teams that launch autonomous penetration testing engagements on their own schedule. BreachLock Penetration Testing as a Service (PTaaS) remains the expert-led, AI-accelerated option, in which certified in-house pentesters direct the engagement, go deeper on business logic flaws and complex attack paths, and validate every finding by default. With AEV, the agents run the assessment, and the customer chooses whether a certified expert verifies the results before delivery.

Human-verified results are available now to all BreachLock AEV customers and can be requested with a single toggle, labeled “Get Human-Verified Results,” during engagement setup. BreachLock outlines the new human-verified results feature in a new blog post.

To learn more about BreachLock AEV and the company’s suite of offensive security solutions, visit BreachLock.com.

FCC blocks new foreign-made robots over security risks

Posted in Commentary with tags on July 29, 2026 by itnerd

The FCC has added foreign-produced advanced robotic devices to its Covered List, preventing new models from receiving the equipment authorization required for importation, marketing and sale in the U.S. The action follows national security determinations that the products pose unacceptable supply chain and cybersecurity risks.

According to the FCC, network-connected robots could be exploited to manipulate physical operations, collect sensitive data, conduct surveillance or be remotely commandeered, while connected power inverters could create vulnerabilities affecting critical infrastructure.

The restrictions apply only to new device models and do not affect previously authorized products already in the U.S. market.

Matt Wyckhouse. Founder & CEO, Finite State:

“We’re supportive of the FCC’s direction here. Supply chain resilience and onshoring of critical technology manufacturing matter to U.S. national security, and the risks documented in the government’s determinations, remote commandeering, surveillance, pre-installed backdoors, are real, not hypothetical. The additional measure we’d advocate is objectivity: pairing these steps with true security assessment of the devices themselves.

“From analyzing the firmware inside thousands of connected products, we see the same pattern everywhere. Security is a property of engineering, not geography. There is rigorously engineered, secure software coming out of foreign countries, and there is deeply insecure software shipping from U.S. companies. Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what’s actually in a device is what separates the secure from the vulnerable. That’s why the FCC’s proposed software and hardware bill-of-materials requirements are an encouraging step, and why pairing them with the substantive security requirements already developed under the Cyber Trust Mark, much as the EU is doing through the Cyber Resilience Act, would give the U.S. an approach that is both resilient and objective: one that strengthens the supply chain while raising the security bar for every device sold here, wherever it’s built.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.

“Taken together with recent guidance from the Five Eyes and other federal agencies, this decision reflects a growing emphasis on the cybersecurity of cyber-physical systems and the resilience of the critical infrastructure that depends on them. We should pay close attention to these signals. They are likely indicative of how governments assess the evolving threat environment and where they see strategic risk increasing.

“Industrial robots are increasingly more than just machines, they are connected computers capable of sensing, deciding, and acting in the physical world. Many of today’s advanced robots have significant operational dependencies on cloud connectivity, AI services, remote management, identity systems, and vendor-operated infrastructure. The security question is not simply whether someone can hack the robot; it’s also what happens if the cloud, the vendor, or the communications path the robot depends on is compromised or unavailable.”

Seemant Sehgal, Founder & CEO, BreachLock:

“The FCC drew a line at the import stage, which is the wrong place to draw it if the goal is reducing risk. There are already authorized devices operating in U.S. networks that carry the same trust relationships, the same firmware update dependencies, and the same remote access capabilities as anything on the new restricted list. Blocking future imports without a plan for what is already inside the perimeter is a procurement policy dressed up as a security measure.”

John Strand, Owner, Black Hills Information Security, Inc.:

“I think these technology-specific bans feel very arbitrary. The security concerns people raise about robotics are the same concerns we’ve had with automobiles, drones, industrial control systems, smartphones, and just about every other connected technology. If it has software, it will have vulnerabilities. That’s simply the reality of modern computing.

“If the standard is that a technology could someday be exploited by a foreign adversary, then almost every technology would qualify. That’s why these policies can feel less like a coherent cybersecurity strategy and more like market protectionism wrapped in the language of national security. The focus should be on building resilient systems, validating software and hardware, and reducing risk regardless of who manufactures the technology, instead of singling out one category while ignoring the fact that the same security challenges exist across the entire technology ecosystem.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Nation-state attackers have spent a decade moving up the supply chain. Software exploits get patched. Firmware backdoors get caught in audits. Hardware is where verification breaks down, because you cannot audit a fabrication line you do not control.

“That is the security argument behind the FCC adding foreign-produced robots and power inverters to its Covered List this week. Network-connected humanoid robots carry cameras, LiDAR, and persistent connectivity. Inverters sit between solar panels, batteries, data center equipment, and the grid. Both create attack surface that defenders can monitor but cannot fully inspect when the hardware ships from a geopolitical competitor.

“I’ve done enough embedded-device assessments to know that firmware review catches what you can reach, and on hardware imported from an adversary nation, there are layers you simply cannot reach. Software backdoors exist in every copy, find one and you’ve found them all. Hardware is different.

“One unit gets pulled off the line or intercepted in shipping, altered with a modified chip, and put back. Intelligence agencies, including ours, have been doing this for years. You can tear down a sample unit, certify it clean, and have no way of knowing the next unit off the same line hasn’t been touched.

“The FCC has banned three product categories in seven months using the same Secure Networks Act written in 2019 for Huawei and ZTE. Drones in December, routers in March, now robots and power inverters. A White House interagency body issues a National Security Determination, the FCC updates its list, and the ban takes effect without new legislation.

“Watch the Conditional Approval list over the next 90 days. Fifteen non-Chinese UAS vendors cleared approval within months of the drones ban. Netgear and eero passed the router review within a month. Zero Chinese manufacturers have received approval in either category, and that ratio will hold for robots and inverters.”

For the record, China has reacted negatively to this and it sounds like they’re going to retaliate. Therefore it is unlikely that this is over.

Secure.com Names Cybersecurity Veteran Nicholette Brown Hill as Founding General Manager, Americas

Posted in Commentary with tags on July 29, 2026 by itnerd

Secure.com today announced that Nicholette Brown Hill has been named Founding General Manager, Americas and Head of Sales for Global Strategic Markets. The newly created executive role reflects the company’s push to accelerate growth and customer acquisition across North and South America as it expands its AI-native cybersecurity platform globally.

In her new role, Nicholette will oversee Secure.com’s growth strategy across the Americas while leading sales efforts for global strategic markets. She will focus on expanding customer acquisition, developing channel and alliance partnerships, and strengthening Secure.com’s position as a leader in cybersecurity risk visibility and continuous security validation.

Nicholette joins Secure.com with more than 20 years of experience leading sales organizations, strategic partnerships, corporate development, and go-to-market strategy across the cybersecurity, cloud, and enterprise technology sectors. Most recently, she served as Chief Strategy Officer at GUARDDOG.AI, where she led market expansion and built partnerships advancing AI-driven cybersecurity adoption.

Prior to GUARDDOG.AI, Nicholette held several executive leadership roles at Meriplex, including Vice President of Corporate Development and Strategic Alliances and Vice President of Sales and Channel. During her tenure, she drove brand development, built strategic partnerships, and executed growth strategies. She also supported the company’s successful recapitalization by Vitruvian Partners.

Her experience also includes executive sales roles at VMware and Rackspace, where she consistently delivered growth across enterprise, cloud, networking, and security markets.

Nicholette is expected to attend Black Hat USA in Las Vegas, August 3-5, where she will be available to meet with press, partners, and customers.

The appointment comes as Secure.com continues to expand its portfolio of cybersecurity risk management solutions designed to help organizations proactively identify vulnerabilities, assess exposure, and continuously improve resilience against evolving cyber threats.

The CISA issues guidance to isolate critical systems during cyberattacks

Posted in Commentary with tags on July 29, 2026 by itnerd

The CISA, in coordination with international partners, has released new CI Fortify guidance to help critical infrastructure organizations isolate vital operational technology (OT) and supporting systems during cyberattacks or periods of heightened cyber threat.

The guidance is intended to help operators maintain essential services while containing cyber incidents and recovering compromised systems.

The guidance recommends identifying critical operational systems and customers, establishing predefined network isolation points, preparing to operate disconnected from third-party networks for weeks to months, and regularly testing recovery plans.

The CISA said organizations should assume internet; telecommunications, vendors and other external dependencies may become unavailable during a major cyber incident or geopolitical crisis.

Donald McFarlane, Advisory Board Member, Xcape, Inc.

“This guidance is more than a checklist. The Five Eyes are telling critical infrastructure operators to prepare for the possibility that they may have to intentionally isolate from the Internet, vendor connectivity, telecommunications providers, and other external dependencies in order to continue delivering essential services during a major cyber incident or geopolitical crisis.

“Some FVEY partners are recommending planning for up to three months of isolated operations. That’s less a prediction of duration than a recognition that operators must be prepared to sustain essential services for as long as necessary.

“Perhaps the most significant shift is the planning assumption. For years, cyber defense has focused primarily on protecting the internet edges. This guidance recognizes that the operational edge is much broader. Critical infrastructure operators should increasingly view the communications fabric connecting remote sites, substations, treatment facilities, vendors, and control centers, including private telecommunications and point-to-point links, not simply as infrastructure they depend upon, but as part of the attack surface itself.

“Resilience should be engineered before a crisis. Organizations need to identify their critical systems, understand hidden dependencies, establish and exercise isolation procedures, and ensure they can continue operating safely when connectivity becomes a liability instead of an asset.”

Seemant Sehgal, Founder & CEO, BreachLock:

“What stood out to me is the instruction to treat carrier-provided services as untrusted and potentially hostile. Most OT operators have longstanding relationships with their telecoms vendors and have built operational trust into those relationships over years. That trust does not translate to technical assurance, and in a geopolitical crisis or major incident, the carrier network itself may be the vector, the casualty, or both.”

John Strand, Owner, Black Hills Information Security, Inc.:

“This really feeds into something I’ve been talking about for quite a while. We’re entering the age of agentic attacks and agentic AI, where vulnerabilities are being discovered and weaponized faster than organizations can respond. In many cases, there won’t be a patch immediately. Sometimes there won’t be a patch at all, especially when we’re talking about operational technology that’s decades old and can’t realistically be upgraded.

“That leaves every CISO with one unavoidable question. What are your compensating controls?

That’s why it’s encouraging to see CISA putting more emphasis on isolation and compensating controls. It shows a shift in thinking that’s been needed for years. We have to move beyond the idea that every security problem can be solved with EDR, firewalls, and patch management alone. Organizations need layered defenses that assume vulnerabilities will exist, patches will be delayed, and some systems simply cannot be fixed. The future of cybersecurity isn’t just about preventing compromise. It’s about building resilient environments that continue to protect critical systems even when traditional approaches no longer work.”

Dahvid Schloss, Chief Operating Officer, Suzu Labs:

“Most everything stated in the guidance has been common language and advice from security professionals for years, if not decades. That being said, it is quite refreshing that government agencies are finally stating the obvious and, in some places, going above and beyond in ways that most would loosely recommend but not push for enforcement.  There are two pieces within the guidance that I appreciated more than others. The first was explicitly calling out MPLS(Multiprotocol Label Switching) as not a security boundary. This is a common argument between IT and Security folks when talking Layer 2/3 security, but in the same way VLANs aren’t treated as a security boundary, neither can MPLS, so kudos to the ASD and others for calling that out in writing.

“The other great piece here is the recommendation to separate encryption from the OT devices themselves, and instead recommend prioritizing and implementing a dedicated crypto device to handle traffic. This is very much needed, especially with how quickly technology is advancing and how it may accelerate the rate at which modern encryption mechanisms become obsolete. OT devices average a 20-year lifecycle; the ability to upgrade and protect the network without a full tech refresh, which comes with its own set of availability risks, is key to future-proofing the security of the network. They also state that crypto should terminate on the OT-side router and not somewhere more convenient, which is a common trend I’ve seen when testing.

“Every time I’ve brought this up as a finding in the past, it was always a “yeah, we know, but it’s easier to manage this way”. If anything, changing the way CI implements crypto within the network would improve security 10-fold in my opinion.  Overall, this release is old guidance many security professionals have been screaming from the rafters for decades, but hey, hopefully this will create the change we have been asking for.”

Matt Wyckhouse. Founder & CEO, Finite State:

“We’re supportive of the FCC’s direction here. Supply chain resilience and onshoring of critical technology manufacturing matter to U.S. national security, and the risks documented in the government’s determinations, remote commandeering, surveillance, pre-installed backdoors, are real, not hypothetical. The additional measure we’d advocate is objectivity: pairing these steps with true security assessment of the devices themselves.

“From analyzing the firmware inside thousands of connected products, we see the same pattern everywhere. Security is a property of engineering, not geography. There is rigorously engineered, secure software coming out of foreign countries, and there is deeply insecure software shipping from U.S. companies. Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what’s actually in a device is what separates the secure from the vulnerable. That’s why the FCC’s proposed software and hardware bill-of-materials requirements are an encouraging step, and why pairing them with the substantive security requirements already developed under the Cyber Trust Mark, much as the EU is doing through the Cyber Resilience Act, would give the U.S. an approach that is both resilient and objective: one that strengthens the supply chain while raising the security bar for every device sold here, wherever it’s built.”

Organizations need to take what the CISA has done and not only build their own playbooks from it, but practise it and use it if required. That way it will reduce the level of pwnage if it comes to that.