Black Kite announced the release of its AI Agent

Posted in Commentary with tags on November 19, 2025 by itnerd

Black Kite today announced the release of Black Kite AI Agent, a super agent that automatically investigates, assesses, and reports on third-party risk. Black Kite has achieved record growth, with a 5-year Compound Annual Growth Rate (CAGR) of 70%, driven by customer success and satisfaction scores that exceed industry standards. These results are quantitative proof that organizations see Black Kite as an indispensable partner. Building on this momentum, the newly released Black Kite AI Agent empowers security teams to be more effective and automated in managing third-party risk.

Super Agent Investigates, Assesses, and Reports on Third-Party Risk

Black Kite was founded with a mission to give security professionals a complete and accurate view of their cyber ecosystem risk. From the very beginning, AI has played a central role in achieving that mission. The Black Kite AI Agent exposes these advanced AI capabilities directly to customers, enabling security teams to investigate, assess, and report on third-party risk more efficiently. With this new capability, Black Kite continues to set itself apart and lead the future of Third-Party Cyber Risk Management (TPCRM).

Fully embedded across the platform, Black Kite AI Agent enables users to ask questions in the context of any page or use pre-built “Blueprints” to launch deep investigations, generate custom reports, and more. Black Kite AI Agent is powered by a network of sub-agents so that when a user asks a question or uses a Blueprint, the appropriate sub-agents are automatically launched to handle the task.

Key features and benefits include:

  • Deep Investigations: Investigates vendor findings, changes in risk scores, cyber ratings, RSI™, and the impact of breaches on third-party networks.
  • Executive and Board Reporting: Generates custom reports and board communication packages with risk trends, concentration areas, and impact with charts and metrics.
  • Procurement Decision Support: Benchmarks prospective vendors with side-by-side risk scores, RSI™, breach history, and financial impact analysis to support onboarding decisions and contract negotiations. 
  • Navigation Guidance: Provides instant answers, guidance, and navigation tips based on best practices, help articles, and support tickets to maximize platform utilization and value.
  • Build and Scale TPRM: Gives expert TPRM advice to guide in building and scaling a third-party risk management program, such as key processes, team structure, and R&Rs.
  • Vendor Prioritization: Ranks vendors by severity and business impact, analyzing findings, FocusTags™, score changes, RSI™, and more to highlight the most urgent cases for action.
  • Document Q&A: Enables the ability to query vendor documents (e.g., SOC 2 reports, ISO certifications, policies) by asking plain-text questions (e.g., “Do they require MFA?”) to extract control-specific information. 

The Trusted Choice for Third-Party Cyber Risk Intelligence

Black Kite has achieved a 5-year Compound Annual Growth Rate (CAGR) of 70%. Further fueling Black Kite’s momentum, the company surpassed key milestones, including expansion of its leadership team, high customer satisfaction scores that go beyond industry standards, recognition by leading industry analysts, and winning prestigious cybersecurity awards for innovation and excellence.

Key highlights include:

  • Achieved a 5-year Compound Annual Growth Rate (CAGR) of 70%.
  • Achieved record high industry standards in customer satisfaction, including: NPS score of 74-plus; 93% Customer Satisfaction Score (CSAT) for onboarding; and consistently receiving a 100% CSAT in customer support for 12 months with a 96% first call resolution rate.
  • A 100% channel-first organization, Black Kite has a powerful network that includes 300-plus partners. From global resellers and managed services providers to GRC leaders and technology integrators, partners include Aravo, Guidepoint, Optiv, Onspring, Avertium, ServiceNow, LogicGate, CGS CyberDefense, and Carahsoft, to name a few.
  • Black Kite Bridge™, the industry’s first solution enabling customer-vendor collaboration, has built a strong community of thousands of third parties, growing over 100% quarter over quarter.
  • Expanded its leadership with Jack Jones, originator of the industry’s standard risk measurement model known as Factor Analysis of Information Risk (FAIR) and the FAIR Controls Analytics Model (FAIR-CAM), who joined as Strategic Advisor. Additionally, appointed Jessica Stanford as Chief Marketing Officer (CMO) and David Sauer as Vice President of Strategic Alliances to drive growth, enhance brand positioning, and expand strategic partnerships in the cybersecurity industry. 
  • Recognized as a Sample Vendor in the Gartner® Hype Cycle™ for Cyber-Risk Management, 2025, which we feel validates that Black Kite’s focus on evidence-based, quantifiable, and transparent risk intelligence is precisely where industry analysts see the market heading. 

For more information on Black Kite AI Agent, visit https://blackkite.com/ai.

Legacy Tech/Shadow AI Jeopardizes Healthcare

Posted in Commentary with tags on November 19, 2025 by itnerd

A new survey of 1,000+ frontline healthcare professionals has revealed that outdated legacy technology jeopardizes healthcare cybersecurity with nearly all (98%) of respondents reporting inefficient technology creates delays or errors in patient care.

You can find more details here: https://www.presidio.com/news/presidios-new-healthcare-ai-report-reveals-industry-is-facing-a-technology-crisis/

Henrique Teixeira, SVP of Strategy at cybersecurity company Saviynt, commented:

“Shadow AI is quickly becoming a bigger danger than shadow IT. Spinning up unsanctioned SaaS apps was already a problem, but AI reaches far more users. Essentially everyone in a hospital or university touches AI tools every day. Many are creating and using AI agents that behave and have permissions similar to employees. Research from Presidio shows that more than 60% of frontline healthcare professionals say their systems are outdated and inefficient, and nearly 90% say their tools don’t meet their needs. Meanwhile, 55% of U.S. healthcare workers are planning to switch jobs in 2026.

“Healthcare is, in my view, one of the most complex identity environments: doctors will continue to switch jobs, and many juggle multiple hospital roles and even patient-identities. Add unmanaged ‘shadow AI agents’ into that mix and the attack surface explodes. Organizations need an identity program that unifies the governance of humans, machines and AI agents because least privilege principles must apply to everyone, and everything. Including our AI coworkers, sanctioned or not.”

This is another example of healthcare getting the short end of the stick and as a result, there are knock on effects in terms of tech which in turn affects people who need care. This needs to change. But you knew that already.

Quorum Cyber Strengthens Leadership Team with New Senior Appointments

Posted in Commentary with tags on November 18, 2025 by itnerd

 Quorum Cyber has made a series of appointments to its senior leadership team to meet its strategic goals. 

John Bruce has joined the Microsoft-only company as Chief Information Security Officer (CISO), Mike LaPeters as Chief Revenue Officer (CRO), Stacey Sweeney as Chief Marketing Officer (CMO), and Melissa Webb as Vice President – Microsoft Partnership. 

The company has grown from a specialized cybersecurity startup into one of the fastest-scaling cybersecurity providers in the market. As a preferred Microsoft security partner and a mission-driven defender for mid-market and enterprise organizations, Quorum Cyber continues to invest aggressively in senior leadership to support accelerating demand across North America, the United Kingdom, and emerging global markets. 

These appointments reflect the company’s commitment to building a world-class executive team capable of scaling operations, strengthening its customers’ cybersecurity and cyber resilience, and advancing its leadership in the Microsoft security ecosystem.

As a seasoned risk and cybersecurity executive with over 25 years’ experience, John Bruce joined as the company’s CISO to further strengthen defenses across the business. He has previously held CISO roles at Places for People Group and CGI as well as senior global partner and director positions at IBM, Lloyds Banking Group, and Royal Bank of Scotland Group. 

Chief Revenue Officer Mike LaPeters has 30 years’ experience in building and leading sales and marketing organizations and channels for security, storage and infrastructure software products. Prior to Quorum Cyber, Mike held a number of senior leadership roles, including CRO at both Huntress and Domotz, VP of Worldwide Sales for VeloBit, VP of North American Sales for AVG Technologies, and VP of Worldwide Sales for Winternals. 

Stacey Sweeney brings nearly 30 years of cybersecurity marketing leadership experience to the Chief Marketing Officer role. She has built high-performing teams to shape and revitalize brands. Her previous leadership roles span emerging to mature companies including Akamai, Quantum Xchange, SANS Institute, and General Dynamics.

With more than two decades of senior leadership experience in the enterprise technology sector, Melissa Webb’s role as Vice President – Microsoft Partnership will drive and grow Quorum Cyber’s strategic partnership globally. Her previous positions include Global Alliance Executive for Microsoft Azure at Red Hat, Director of Business Development for Microsoft Azure, and Director of Global Strategic Alliance Marketing at VMware. 

Software vendor serving 700+ banks hacked, credit union says

Posted in Commentary with tags on November 18, 2025 by itnerd

Comparitech has reported that Marquis Software Solutions suffered a data breach in August that compromised Social Security numbers, tax ID numbers, account numbers, and dates of birth. This is according to a notice published yesterday from Community 1st Credit Union, one of the impacted banks.

Rebecca Moody, Head of Data Research at Comparitech, commented: 

“This attack highlights how companies not only face the ongoing threat of ransomware attacks within their own systems but also through the systems of third-party vendors they use to carry out various services. It’s also why these types of companies appeal to hackers, as they can often access hundreds of companies’ data through just one target.

While we don’t yet know how extensive this breach is, the notification issued by Community 1st Credit Union does appear to imply that a number of financial institutions have been impacted in the attack. Therefore, it’s likely we’ll see the current figure of 6,876 (the total affected via C1st) growing in the coming weeks.”

Ah, supply chain attacks. This is becoming the bread and butter of threat actors as they can hit a bunch of targets with ease. This means that organizations need to ensure that their partners are as secure as they are, otherwise bad things will happen to them.

Liquibase Secure Extends AI Governance to the Database Layer, Closing the Gap Between AI Safety and Data Integrity

Posted in Commentary with tags on November 18, 2025 by itnerd

Liquibase today announced new AI governance capabilities in Liquibase Secure, extending enterprise control to the database layer. The update addresses a growing blind spot in AI strategy: ungoverned database changes made by AI agents, automation scripts, and large language models that now interact directly with production data.

AI Governance Stops at the Model, but Risk Lives in the Database

As enterprises move faster with AI, most governance frameworks focus on model bias, explainability, and privacy. The greater risk often hides at the data layer. AI agents that can write or modify database queries can alter or delete production data, introduce schema drift, or corrupt AI training sets before traditional security controls ever detect them.

According to the 2025 State of Database DevOps Report, 78% of organizations struggle with AI-driven data challenges, while Gartner estimates that 40% of agentic AI projects will be canceled by 2027 if they lack clear governance at the data layer. The conclusion is unavoidable: AI governance that stops at the model is incomplete.

Liquibase Secure: Database-Layer Controls for AI Workloads

Liquibase Secure provides the automation and governance infrastructure that makes AI adoption safe, compliant, and auditable.

  • Automated Policy Enforcement: Blocks destructive AI-generated changes before production across 60+ database platforms
  • Role-Based Approval Enforcement: Integrates with enterprise CI/CD and access controls to ensure all database changes, including those generated by AI, are reviewed and approved prior to deployment.
  • Automated Drift Detection: Identifies unauthorized schema modifications and environment inconsistencies before they affect downstream systems or model training.
  • Tamper-Evident Audit Trails: Creates a verifiable record of every change for frameworks such as SOX, HIPAA, GDPR, NIST AI RMF, and the EU AI Act.
  • Targeted Rollback: Reverses problematic changes in minutes instead of hours
  • Schema-Level Data Lineage: Captures the full history of structural evolution, which is critical for AI model provenance and regulatory audits.

Liquibase’s observability and rollback capabilities ensure that even AI-driven changes remain explainable, reversible, and fully traceable, providing a foundation for responsible AI at scale.

Extending AI Capabilities to Database Governance

Liquibase Secure also introduces new AI-powered tools that accelerate delivery while maintaining control. The AI Changelog Generator, built from Liquibase’s frontline experience supporting enterprise database teams, converts natural language descriptions into validated changelogs that align with governance policies. It helps developers move from idea to production-ready change in seconds while preserving auditability and consistency.

The Liquibase Secure Developer Extension for VS Code brings schema management, history review, and policy enforcement directly into the IDE so developers can work faster without sacrificing traceability or compliance.

Together, these capabilities show how Liquibase is using AI to enhance governance, productivity, and developer experience across the database lifecycle.

MongoDB Partnership: Eliminating the Speed vs. Control Trade-Off

Liquibase also announced a new strategic technology integration with MongoDB, the unified data platform that powers modern, data-intensive, and AI-driven applications.

MongoDB’s flexible document model is a powerful enabler for rapid iteration and experimentation in dynamic AI environments. As agility drives growth, managing and tracking evolving schemas across many projects becomes a critical governance need. Issues like inconsistent field names or untracked schema drift can quietly disrupt analytics pipelines, corrupt training data, or derail audits over time.

Liquibase Secure integrates directly with MongoDB to provide continuous governance without slowing innovation. Every collection change runs through automated policy checks. Drift detection flags unapproved updates before they spread. Structured, tamper-evident logs deliver a single source of truth for auditors and data scientists.

Regulatory Pressure Makes Database Governance Imperative

Emerging regulations demand database-layer governance. The EU AI Act requires rigorous data traceability for high-risk AI systems. NIST’s AI Risk Management Framework establishes federal and private sector baselines. Traditional frameworks, SOX, HIPAA, PCI DSS, GDPR,  and DORA now intersect with AI workloads, creating compound compliance obligations.

Without database-layer controls, organizations face higher compliance costs, extended audits, and increased exposure to AI-amplified data errors.

Strategic Leadership: New Head of AI Strategy & Technology Innovation

Liquibase has appointed Kristyl Gomes as Head of AI Strategy and Technology Innovation, a newly created leadership role. Gomes brings more than 15 years of experience spanning database engineering, DevSecOps, and infrastructure automation.

Most recently, she served as Liquibase’s VP of Engineering, where she led development of the company’s cloud-native platform, expanded its multi-cloud footprint, and launched the first wave of AI-powered developer tools. In her new role, Gomes will guide how Liquibase applies AI across its product suite, from accelerating schema management and compliance automation to redefining AI governance at the data layer.

From Risk to Readiness

Liquibase Secure transforms databases into AI-ready systems that balance speed, safety, and compliance. By governing schema changes across platforms such as MongoDB, PostgreSQL, Snowflake, and Databricks, Liquibase helps enterprises accelerate delivery while maintaining the trust their AI initiatives depend on.

Availability

Liquibase Secure’s MongoDB integration is available today. Learn more at https://www.liquibase.com/mongodb

Early Black Friday Deals from Anker SOLIX

Posted in Commentary with tags on November 18, 2025 by itnerd

With Black Friday coming up, here’s a round-up of early Black Friday Deals from Anker SOLIX, the global leader in power delivery and energy storage solutions. 

These offers start today November 18 and run to December 1 (end of day).  

C1000 Gen 2 Portable Power Station – 1,024Wh | 2,000W 

  • Black Friday Price: $589 (save $610) 

A compact 1-kWh unit with a sub-1-hour full recharge and 2,000W output. It’s designed to handle high-draw devices and essentials.

C2000 Gen 2 Portable Power Station – 2,048Wh | 2,400W 

  • Black Friday Price: $1,099 (save $900) 

A 2-kWh unit with expandable capacity, 2,400W output, and RV-ready ports – suited for home backup, cottage/off-grid power, and more demanding workloads.  

F3000 Portable Power Station 3,072Wh | 3,600W 

  • Black Friday Price: $1,999 (save $1,900) 

A high-capacity 3-kWh power station with expansion up to 24kWh, dual solar input for faster recharging, and built-in wheels and handle for easier transport. It’s designed to power everything from everyday devices to mini fridges, tools, and RV essentials – and can provide half a day of home backup on its own, or up to two days when expanded.  

All models offer solid performance, fast charging, and practical capacity for everyday scenarios, making the Black Friday pricing worth noting for readers looking at dependable backup power or entry-level to mid-range portable energy systems. 

TELUS brings back Buy One, Give One offer

Posted in Commentary with tags on November 18, 2025 by itnerd

There’s a uniquely Canadian, purpose-driven campaign from TELUS that’s giving a new meaning to the traditional concept of BOGO. This Black Friday weekend (Nov 28-30), for every new or certified pre-owned phone purchased, TELUS will give a free phone and plan to a Canadian youth transitioning out of government care through its Mobility for Good program

Now in its 5th year, TELUS’ Buy One, Give One initiative empowers Canadians to shop with purpose –  knowing their purchase is helping bridge digital divides and keep vulnerable youth connected. The offer is available online, by phone, and at select stores. Since its launch in 2017, the Mobility for Good program has provided support for over 69,000 people. 

Together, these initiatives reflect TELUS’ ongoing commitment to giving back and making a positive impact on customers and communities across Canada.

OpenText Unveils Next-Generation AI Data Platform for Secure Information Management

Posted in Commentary with tags on November 18, 2025 by itnerd

OpenText today announced its vision for the future of enterprise AI with the introduction of the OpenText AI Data Platform (AIDP). OpenText AI Data Platform addresses the convergence of data and AI to deliver secure and scalable enterprise capabilities.

As volumes of proprietary data grow exponentially, organizations face mounting pressure to manage, secure, and activate their private information. Moreover, according to McKinsey’s annual State of AI study, 51% of organizations using AI have experienced at least one negative consequence and inaccuracy, underscoring the need for information governance. OpenText’s innovation roadmap focuses on helping customers establish contextual data foundations to fuel accurate AI results to accelerate business outcomes.

A Vision for Contextual AI

OpenText’s AI strategy is built on nearly 35 years of being the custodians of data for its customers. Practical enterprise AI requires agents to understand the specific situation, environment, and task it operates within to be effective. With the right context, OpenText can bring new life to old data, while solving relevancy and avoiding false confidence.

OpenText business applications assist enterprises in managing their largest data sets today including documents, commerce trades, IT tickets, and security signals. This can be human generated content, machine generated content, or content between organizations. OpenText ensures that information has metadata tags to provide data lineage, data rights, and data retention policies. With data security and identity access management wrapped around it, these contextual elements are critical to driving accuracy with any enterprise AI model.

OpenText Aviator then sits on top of this contextually rich data to enable automated workflows with agentic AI. OpenText’s Aviator is unique because it adheres to three core standards:

  • Multi-cloud: Supports on-premises, cloud, and hybrid deployments
  • Multi-model: Compatible with any AI model (LLM, SLM), including bring-your-own-model
  • Multi-application: Deep integration with ERP, CRM, and other enterprise platforms

This open architecture ensures that organizations can tailor their AI strategies to their specific business, industry, and compliance needs. Furthermore, OpenText is working across the ecosystem with alliance partners like SAP, Microsoft, Google, Salesforce, Oracle, and more on deep integrations to drive an agent-to-agent roadmap.

Today, OpenText also announced it will be expanding its partnership with Databricks, the Data and AI company. OpenText already builds solutions on the Databricks Data Intelligence Platform with OpenText Threat Detection and Response. Now OpenText and Databricks will be working to co-innovate on the OpenText AI Data Platform through technical integrations and Delta Sharing. Together, customers can seamlessly unify, govern, and analyze all their enterprise data, empowering them to unlock trusted AI insights and drive innovation at scale.

Showcasing Innovation at OpenText World 2025

At its annual flagship event, OpenText World 2025, the company also introduced several groundbreaking innovations and outlined its 18-month roadmap (releases OT 26.1 – OT 27.2) that redefine how enterprises will interact with data and AI:

  • OpenText AI Data Platform (AIDP) – An open, unified data and AI framework with a governance orchestration layer that enables AI agents (Aviators) to help customers unlock new value.
  • OpenText Aviator Studio – A no-code platform to build, govern, and connect enterprise AI agents to empower organizations to realize ROI from AI faster.
  • OpenText Knowledge Discovery – A set of tools to ingest structured and unstructured data, automate meta-data tagging, and connect to rich data sources in real-time.
  • OpenText Data Compliance – A suite of services including AI readiness assessments, data redaction and PII controls, data tokenization, data encryption and privacy protection, and threat detection and response.
  • OpenText Aviator AI Services – A team of OpenText Professional Services experts to help customers on the journey from discovery to deployment to adoption of purpose-built agents to realize business value.

Get Started

Organizations can take advantage of OpenText Aviator today for practical use cases from fraud detection to claims management to predictive maintenance. Learn more here.  

OpenText Aviator entry tier package will be included with an upgrade to OT 26.1 of Content ManagementService Management, and Communications Management at no additional fee.

OpenText Aviator will also be available on-premises starting OT 26.1 for Content ManagementCommunications ManagementService ManagementDevOps Management, and Application Security.

Lastly, OpenText continues to partner with customers to navigate through complex requirements for sovereignty data and AI. Learn more here.

Cloudflare Goes Down And Takes A Lot Of The Internet With It

Posted in Commentary with tags on November 18, 2025 by itnerd

If you were trying to get to Twitter, ChatGPT, Salesforce, or any number of other sites and you were having issues, it wasn’t you. Cloudflare, who are a content delivery network that also provides network and security products to companies took a dive. If you have a look at their status page, they acknowledge that they had an issue, but it is in the process of being resolved. But as I type this, there are still scattered reports of issues. Chances are, these issues will likely go away as the day goes on.

The folks at Cisco ThousandEyes have an outage map. I also got this statement from them regarding what they observed:

On November 18, 2025, at approximately 11:30 UTC, Cisco ThousandEyes began observing a global outage affecting cloud and CDN provider Cloudflare, impacting multiple Internet services including X, OpenAI, and Anthropic. While network paths to Cloudflare’s front-end infrastructure appeared clear of any elevated latency or packet loss, Cisco ThousandEyes observed a number of timeouts and HTTP 5XX server errors, which is indicative of a backend services issue. While Cloudflare has confirmed they are implementing remediation, the outage is still ongoing. Sample service impacted by the outage: https://cs.co/604475xqg

Thus for those who were hoping for a digital snow day, sorry.

2026 Predictions From Kognitos

Posted in Commentary with tags on November 18, 2025 by itnerd

Binny Gill, CEO and Founder of Kognitos, and Neeraj Mathur, Vice President of AI Solutions Engineering at Kognitosoffer their perspective on how in 2026, software and work alike will shift toward experience-driven models where AI handles the repetitive tasks and flexible automation frees people and businesses to focus on higher-value creativity and impact.

Binny Gill, CEO and Founder, Kognitos

“The software industry will start to look a lot like the restaurant business. You can cook a meal at home if you want, or you can go out to eat. Building software in-house is like cooking; buying software is like dining out. Both will exist. Some companies will cook more, some will buy more, but the question isn’t about features anymore. It’s about experience. A restaurant isn’t popular because it has the most dishes; it’s popular because people love the experience. That’s how software will evolve. It won’t be about build versus buy, it’ll be about the kind of experience the customer wants to have.”

Neeraj Mathur, Vice President of AI Solutions Engineering at Kognitos

“AI will not replace people, but it will absolutely replace the parts of work that keep people from thinking. The goal should never be to remove humans from the process. It should be to remove the repetitive, time-consuming steps that add no real value. When employees see that AI can take care of the small tasks, they start to use their creativity and judgment more. That is when real transformation begins. The future of work is not machines running everything; it is humans using AI as a partner to think and move faster.”