CISO Briefing 2026-07-19

Today’s Stories, Governance Lens — July 19, 2026 Coca-Cola Unit Becomes 17th US Cyber Incident This Year — pymnts.com Industry reacts to Gold Eagle vulnerability management plan — Techtarget.com Human-led, AI-assisted testing: Why AI won’t replace penetration testers…yet. — TechRadar US companies face rise in cyber attacks — The Times of India Low cost data poisoning attacks compromise open weight AI models — 4sysops.com CISA mandates urgent patching for exploited SharePoint remote code execution flaw — 4sysops.com Fresh SharePoint Vulnerability Exploited Soon After Disclosure — Securityweek.com CISA urges immediate action on actively exploited Fortinet flaws — BleepingComputer CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV — Internet The rising cost of cybercrime is a concern for any company with sensitive data. According to the latest statistics, Coca-Cola Unit has become the 17th US cyber incident this year. This is a stark reminder that even large organizations are not immune to cyber threats. ...

July 19, 2026 · 2 min · Jason, Cyber Professional

The Cost of a Bad Prompt: How Prompt Engineering Saves Real Money

Every token an LLM API processes has a price tag, on the way in and on the way out. That fact turns “write better prompts” from a productivity tip into a line item. Most organizations treat AI spend as an unavoidable cost of doing business; in practice, a meaningful chunk of it is just badly engineered prompts paying for their own inefficiency. ...

July 19, 2026 · 5 min · Jason, Cyber Professional

CISO Briefing 2026-07-18

Today’s Stories, Governance Lens — July 18, 2026 Coca-Cola Unit Becomes 17th US Cyber Incident This Year — pymnts.com Industry reacts to Gold Eagle vulnerability management plan — Techtarget.com Human-led, AI-assisted testing: Why AI won’t replace penetration testers…yet. — TechRadar US companies face rise in cyber attacks — The Times of India Low cost data poisoning attacks compromise open weight AI models — 4sysops.com CISA mandates urgent patching for exploited SharePoint remote code execution flaw — 4sysops.com Fresh SharePoint Vulnerability Exploited Soon After Disclosure — Securityweek.com CISA urges immediate action on actively exploited Fortinet flaws — BleepingComputer CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV — Internet Coca-Cola Unit Becomes 17th US Cyber Incident This Year The increasing number of high-profile cyber incidents, such as the Coca-Cola unit breach, highlights the growing threat landscape and the need for robust security measures. As businesses expand globally, they become increasingly vulnerable to targeted attacks. CISOs should prioritize incident response planning and ensure that board members are informed about potential risks. ...

July 18, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 1: Where AI Data Actually Comes From

Every AI model is, at its core, a direct product of its training data. Long before a system answers its first prompt or makes its first real-world prediction, decisions about data collection, sourcing, and processing have already permanently shaped its behavior. ...

July 9, 2026 · 3 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 2: Vulnerabilities You Can't Patch Out

In Part 1 we looked at how little organizations actually know about where their AI training data comes from. This time, we look at what happens once that unverified data gets baked directly into a model. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 4: The Fine-Tuning Inheritance Tax

So far this series has covered the data going into a model and the technical choices made while training it. Now: what happens when your organization doesn’t build a model at all, but fine-tunes someone else’s. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 5: Navigating the Black Box with Model Cards

The first four parts of this series covered where AI training data comes from, what gets permanently baked into a model, how training and optimization choices introduce risk, and how fine-tuning inherits all of it. This part covers a harder problem: you often can’t check any of it yourself. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 6: A Practitioner's Checklist

This series started with a simple idea: every AI model is a direct product of its training data, and most organizations deploying AI have no real visibility into what that data actually was. Over five parts, we traced that problem from raw data collection all the way through to the documentation that’s supposed to make it transparent. ...

July 9, 2026 · 3 min · Jason, Cyber Professional

Using AI Safely in a SOC: Part 3 — The Manager's Guide

AI adoption in SOCs is largely happening bottom-up. Analysts are finding tools that help them work faster. Engineers are integrating models into pipelines. This is happening whether or not there’s an organizational policy governing it — and in most cases, the policy comes after the adoption, not before. ...

April 15, 2026 · 7 min · Jason, Cyber Professional

AI Governance Frameworks & Risk: A Complete Landscape

Understanding AI Frameworks and the Risks of Artificial Intelligence A blog post drawing on current frameworks, research, and the MIT AI Risk Repository Introduction Artificial Intelligence is no longer a niche technology. It is embedded in healthcare diagnostics, hiring decisions, financial systems, law enforcement tools, and the everyday software most of us use without a second thought. With that reach comes serious responsibility — and serious risk. Governments, standards bodies, researchers, and international organizations have responded by developing a growing ecosystem of frameworks designed to identify, categorize, and manage those risks. ...

March 31, 2026 · 7 min · Jason, Cyber Professional