Roseville, California just provided a case study in what happens when organizations confuse “AI-powered” with “AI-verified.” A Business Insider investigation found that Flock Safety’s AI license plate readers misread plates in 71% of the alerts sent to Roseville police over two years, incorrectly flagging vehicles as stolen or linked to a felony. That number isn’t […]
Two years ago, several of us wrote that Arlington, Massachusetts wasn’t “too small for cybercriminals” after a business email compromise diverted nearly half a million dollars from a town construction project. The criminals didn’t target a major enterprise or a household brand. They found a small municipality with finite staff and resources and even less […]
When an AI evaluation becomes a real-world security incident, leaders can no longer view model testing as a low-risk exercise. The OpenAI and Hugging Face incident reveals how agentic AI can cross trust boundaries, exploit vulnerabilities, and create business risk long before deployment.
Microsoft’s decision to make passkeys the default authentication method in Entra ID signals a broader industry shift: phishing-resistant authentication is no longer optional. Identity and security leaders should use this moment to accelerate passkey adoption, reduce reliance on vulnerable MFA methods, and align authentication strategies with Zero Trust principles.
Interest in build vs. buy for contract lifecycle management (CLM) is resurging, eerily invoking early-2000s vibes (pun intended). AI makes it easy to spin up something that looks like a CLM system — if you squint, you can see it. I keep thinking of a recent article about a Wall Street techie that vibe coded […]
The question is no longer whether organizations should prepare for the quantum era, but how they will prove that they acted in time. New US guidance elevates post-quantum cryptography migration from a technology initiative to a board-level risk management responsibility.
Last week, Forrester released The Forrester Wave™: Extended Detection And Response Platforms, Q2 2026. This is the third iteration of the extended detection and response (XDR) Wave, with prior versions published in 2021 and 2024. This Wave differs significantly from the past, especially because of: The number of vendors. This year, only seven vendors were […]
AI adoption is accelerating, but confidence in its outcomes isn’t. At Forrester’s AI Forum 2026, security and risk leaders will learn how to shift from traditional protection to a trust-and-assurance mandate — with practical frameworks, real-world perspectives, and strategies to secure an increasingly agentic enterprise while enabling innovation.
On Friday, June 12, the same model class covered by our previous blog post went dark. Anthropic suspended Fable 5 and Mythos 5 worldwide after the US Department of Commerce issued an export control directive, which led to requests from prominent cybersecurity pros to undo the action. The bypass that triggered the export controls, per […]
Join us in Singapore or Sydney to learn how to turn AI momentum into measurable advantage. Our AI Forums are geared toward technology, security, marketing, and customer experience leaders and teams.
In 2026, continued political instability coupled with technological advancements being used by cybercriminals will force cybersecurity and risk leaders to adapt their defensive technologies and prepare their workforce for big shifts. Find out more in our 2026 predictions for cybersecurity and risk.
AI red teaming blends offensive security tactics with safety evaluations for bias, toxicity, and reputational harm. It’s messy, fragmented and, most of all, necessary. Get six tips to get started on an AI red team that actually works in this preview of our upcoming Security & Risk Summit.
Why did the UK government extend a £1.5 billion guaranteed loan to Jaguar Land Rover after a debilitating ransomware attack? And what can your security team learn from it? Find out in this post.
The cybersecurity industry is in the middle of a land grab as AI security M&A heats up. In just 18 months, eight major vendors — including Check Point, Cisco, CrowdStrike, F5, and Palo Alto Networks — have spent upwards of $2.0 billion acquiring startups focused on securing enterprise AI. AI for security is already poised to disrupt […]
The 10th annual Splunk .conf took place in Boston recently. From the opening keynote to various new product releases and enhancements, get a full review of the event in this post.
Details have been trickling out about a security issue in Salesloft’s Drift product. Find out what data was compromised and what actions you can take to reduce the threat to your business.
IoT devices are a normal part of business and personal life. In enterprises, it is estimated that there are between six and 10 IoT devices for each employee, ranging from long-standing devices, such as printers and cameras, and industry-specific devices like warehouse scanners and medical infusion pumps to modern air quality monitors and soil moisture […]
We just released The Forrester Wave™: Secure Access Service Edge Solutions, Q3 2025, and the results mark a dramatic shift from the 2023 Wave on Zero Trust edge solutions.
Forrester AI Access is an important milestone in our AI journey, beginning with our 2023 launch of Izola. With AI Access, organizations can validate ideas, innovate, and make smarter decisions faster.
Since insider risk is more about people than PCs, security and insider risk management pros must make an unlikely new ally: their colleagues in HR. Find out how HR can help reduce insider risk in this preview of our upcoming Security & Risk Summit.
Learn how Forrester’s Continuous Risk Management Model can replace outdated risk management methods in this preview of a session at the upcoming Security & Risk Summit.
Learn more about the security strategies that helped Schneider Electric win this year’s Security & Risk Enterprise Leadership Award, which recognizes organizations that have transformed their security, privacy, and risk management functions.
Patchy AI standards and regulations across the globe will result in some organizations faring better than others when it comes to building and maintaining trust. Learn more in this preview of our 2025 trust predictions.
As more worldwide operational resilience regulations take effect, the business resilience landscape is changing. Help us find out how much it's changing by completing a survey we're conducting in collaboration with the Disaster Recovery Journal.
It’s been a banner year for healthcare, and not in a good way. As a healthcare provider, if your patients had trouble filling a prescription, if you struggled to submit claims to generate much-needed revenue, or if you had to ask a patient to reschedule a non-essential medical procedure, your organization has been a victim of healthcare concentration risk.
We’re excited to announce the inaugural release of a Forrester Wave™ evaluation covering attack surface management (ASM) solutions. We evaluated the 11 most significant ASM vendors in what is currently a rapidly evolving market segment. Forrester covers ASM and periphery markets such as exposure management and vulnerability risk management (VRM), as these segments all contribute […]
Contrary to expectations the enterprise firewall continues to thrive. and vendors have made significant progress in keeping up with rapid innovations. Learn more in this preview of the recently published report, The Forrester Wave™: Enterprise Firewall Solutions, Q4 2024.
Last week, Visa announced the acquisition of Featurespace, a UK based enterprise fraud management and AML vendor. Forrester estimates the acquisition price to be between $350-450M. Founded in 2008, Featurespace employs 400+ people. The move comes as a bit of surprise, since Visa’s Cybersource solution already addresses eCommerce and Retail Fraud Management / Digital Fraud […]
With cybercrime expected to cost $12 trillion in 2025, regulators will take a more active role in protecting consumer data while organizations pivot to adopt more proactive security measures to limit material impacts. Find out more in our 2025 predictions for cybersecurity, risk, and privacy.
Forrester is once again partnering with Women in Security and Privacy to provide free admission to our Security and Risk Summit for four women looking to break into cybersecurity. Learn the details and find out how to apply for the scholarship here.
Risks posed by and to humans such as deepfakes, data exfiltration by insiders, and misuse of generative AI are expected to accelerate and become more complex. Learn how to discern and manage these human element risks in this preview of an upcoming report.
Data security is both a high priority and struggle for many organizations. Find out why and get some next steps in this preview of our upcoming Security & Risk Summit, December 9–11 in Baltimore.
European businesses, much like their global counterparts, are caught in a delicate dance, with CISOs coping with sector-specific vulnerabilities, a regulatory maze, and geopolitical complexity. Forrester’s report, European Cybersecurity Threats, 2024, offers European security leaders some much-needed clarity. Security Fundamentals Matter More Than Security Theater Technology and security professionals often find themselves captivated by the […]
We started our evaluation of human risk management solutions knowing that vendors and customers were at different stages of adoption. We faced resistance – the level of which depended on where vendors were in achieving their own vision of HRM.
Looking for ways to improve your fraud management capabilities? Learn six key ways generative AI can help in this preview of a session at our upcoming Security & Risk Summit in Baltimore December 9-11.
The Security & Risk Enterprise Leadership Award recognizes orgs that transformed the security, privacy, and risk management. Learn more about the award and find out how to apply.
Public cloud may be the major underpinning of enterprise infrastructure strategies, but it comes with risks. Learn the top three cloud trends that CISOs and security leaders need to be aware of in this preview of our upcoming Security & Risk Summit on December 9–11.
In recognition of National Insider Threat Awareness Month, we’ve gathered up some helpful focus areas and next steps to reduce your exposure to insider risk. Learn more at our upcoming Security & Risk Summit in Baltimore on December 9–11.
As a former hockey mom, I assure you that there is nothing quite as pungent as a travel-team hockey bag. Adolescent sweat, steamy equipment, and skates with remnants of ice all shoved into a giant bag with no ventilation makes for a breeding ground for fungus and bacteria. But ask any player, coach, or hockey […]
As global interconnectedness exponentially increases the number of commercial and business relationships between organizations, the speed of innovation is also reshaping how they operate. In other words, for an organization to execute on its generative AI (genAI) strategy (and for the record, the absence of a genAI strategy is a genAI strategy), they’ll need to […]
Learn how to build, improve, repair, or elevate your relationship with your technology counterparts in this preview of our upcoming Security & Risk Summit in Baltimore, December 9–11.
Sandy, Allie, Paddy, Erik, and Cody assembled in Vegas last week for BlackHat. We spent the week attending sessions; meeting with clients; looking for trends, highlights, and lowlights in the festival of vendor marketing (on the show floor and in the convention center hallways); and we made sure to drink a lot of water to […]
With the July 19th incident that impacted CrowdStrike Falcon® customers globally, CrowdStrike has significantly damaged customer trust. CrowdStrike’s initial Post Incident Review outlines a number of reasonable steps they plan to take to regain that trust including: Improved testing protocols Staged deployments External QA of both its code and its end-to-end processes. It will, however, […]
The majority of security technology decision-makers anticipate further budget increases in 2025. Learn three key areas for CISOs to focus on in the year ahead in this preview of our 2025 Budget Planning Guide for security leaders.
Tech leaders considering migrating critical systems away from Windows to other operating systems in the wake of CrowdStrike might want to give that strategy some thought. Find out why.
CrowdStrike's recent global incident underscores businesses' need to have robust crisis communication plans in place before a crisis occurs.
What We Know – And What To Do Now Technology leaders to find that a software update by cybersecurity vendor CrowdStrike had gone badly wrong and disrupted major systems at organizations across both countries. The impact has spread globally, with airports, governments, financial institutions, hospitals, ports, transportation hubs, and media outlets facing significant operational disruptions. […]
“Resilience” an oft quoted and reasonable ideal that technology professionals and by extension, the businesses they serve strive for. However as anyone that works in the tech industry knows, our digital systems are often anything but and security threats loom like the sword of Damocles. Business and technology leaders often manage risk by building systems […]
Our Planning Guides will steer you toward budgeting decisions that set you up for success in 2025. Get a preview of what to expect when the guides launch on August 1.
In a world of Scattered Spiders and Midnight Blizzards and UNC2452s, why is Arlington’s BEC important? Because it’s happening all the time to towns, municipalities, regional health systems, and small businesses lacking the resources to prepare for such an event.
Electricity, water, internet … and (now) incident response are must-have utilities. In a threat-glutted 2024, incident response (IR) services are practically a utility, but unlike the providers of the former, these services don’t come from some form of a monopoly. In fact, security leaders have a vast array of choices of highly competent providers, 14 […]
Navigate the choppy and always exciting waters of artificial intelligence (AI) with Forrester’s analysts. Forrester’s multi-episode webinar series on AI delves into the profound impact AI has – and will continue to have – both on how data scientists and software engineers approach their work and how other job functions will have to adapt to […]
An organization’s single biggest risk is not knowing how much risk it has. That's why cyber risk quantification is on the rise. Learn the basics of how to build a CRQ business case in this post.
They say hindsight is 20/20 and certainly that holds true for regulations and safeguards in the US healthcare system. For rules to change, the risk must have been realized and pain must be felt acutely. In other words, that event/incident/disruption that everyone feared most, already happened, leaving long lasting damage for patients, healthcare providers, health […]
Ask a room full of CISOs about cyber risk ratings (CRR) platforms, and you’ll find no shortage of opinion — hot or cold but never indifferent. Like a judges’ panel in a “Top Chef” culinary competition, customers critique missing or poorly planned components of the “dish.” And like the competing chefs, ratings vendors often struggle […]
Systemic risk events may be outside your control but how you respond is up to you. Learn the top systemic risks of 2024 in this preview of a new report.
RSAC gives security startups two structured opportunities to distinguish themselves, and Forrester always finds it revealing to see which startups make the cut.
Today, LogRhythm and Exabeam announced their intent to merge into a single company. This is another big change for the Security Analytics Platform market, which has been undergoing a rollercoaster of activity the past few years, from Microsoft announcing Sentinel in 2019, to Cisco’s acquisition of Splunk, to XDR vendors shooting their shot, to vendor […]
RSA Conference (RSAC) 2024 boasted 41,000 attendees, 600 exhibitors on the show floor, 425 sessions, and plenty of dashing around Moscone Center and its surrounding area for our analysts. The event, still the top dog of cybersecurity events, was packed with announcements and press releases galore. This blog contains some of the key themes we […]
In 2022, I examined the anti-money laundering (AML) landscape in Asia Pacific, highlighting the key trends and technologies. Since then, much has changed. New hotspots have emerged for money launderers, while innovative technology has also emerged to fight back against them. Notably, generative AI has catapulted itself into the forefront of this fight. Forrester sees […]
Forrester announces the opening call for our annual Security & Risk Enterprise Leadership Award. This award recognizes organizations that have transformed the security, privacy, and risk management functions into capabilities that fuel the organization’s long-term success. Learn more about the award and how to apply here.
Struggling to decide which security conferences to attend? To help you make an informed choice as conference season approaches, Forrester analyzed the content of eight leading security conferences from 2018 to 2023. Get a preview of that analysis here.
The cybersecurity industry continues to focus almost exclusively on technology at the expense of dealing with the heart of cyberdefenses: the people. Yet the stress of expectations, limited resources, and detriments to well-being continues to cause havoc with the mental and physical health, productivity, and retention of the cybersecurity workforce.
As the cloud landscape adapts to new changes, there is a renewed interest in cloud governance programs. But implementation of cloud governance may prove to be more difficult than expected. Find out why.
High-performance IT rests on a foundation of security, privacy, and resilience that is necessary to build trust. Having a digital sovereignty strategy can help. Learn three key digital sovereignty considerations to keep in mind.
US federal agencies must now have a chief artificial intelligence officer responsible for operationalizing the safe use of AI. Learn more about this move and the implications in this blog post.
Generative AI offers an opportunity for risk management to reinvent itself from the department of “no” to the discipline of “go.” Find out how in this blog post.
Get six key learnings about Southeast Asia cybersecurity trends and challenges following a series of roundtables with CISOs and security leaders in the region.
We analyze the key trends and drivers of the digital asset custody market, key tech supporting digital asset custody, the core capabilities of representative custody providers, and early good practices for integrating these solutions.
Microsoft announced the launch date of Copilot for Security. Find out what this means for security professionals and how you can prepare.
As digital threats grow more sophisticated and European and international regulatory landscapes more intricate, the role of cybersecurity consulting services is critical. Hence, I’m excited to announce The Forrester Wave™: Cybersecurity Consulting Services In Europe, Q1 2024 (available for Forrester clients). In this report, my colleagues and I scrutinize the offerings of major players in […]
Toxic leadership and poor or inadequate communication can fuel frustration, confusion, burnout, and a lack of trust in the cybersecurity organization. Learn the value of soft skills in this blog post.
One of Forrester’s best practices for managing insider risk is to turn your employees into advocates for the program. Get five tips for how to do that in this preview of our upcoming Security & Risk event in November.
Learn how focusing on proactive security behaviors can relieve the ongoing security intrusions that reactive security teams must address.
Three factors are certain to influence your cyber security program today: regulations, third-party partners, and cyber insurance. Increasingly stringent requirements, exclusions, and policy premium costs may appear as a trifecta of pain launched your way from insurers. But cyber insurance is really an opportunity. Security leaders can wield cyber insurance not only as risk transfer […]
The current relationship status between marketing and security and risk (S&R) pros is best described as “it’s complicated.” This may seem cheeky and slightly exaggerated, until you learn that a whopping 78% of B2C marketing leaders say that they don’t know anyone on their security, risk, and compliance team. Apart from a martech vendor assessment […]
A few weeks ago, I spoke on a podcast with some of my former colleagues about my experiences in the security industry as a young woman. Tl;dr — it’s not always great, and that’s true for many women in the industry. We showed that in our research on Best Practices: Recruiting, Retaining, And Advancing Women […]
Data is everywhere. What constitutes sensitive data for organizations today has greatly expanded in type and format. In my latest report, The State Of Data Security, 2023, we reviewed and analyzed Forrester survey data to identify the key data security trends of the year. This includes diving into the causes of breaches, the types of […]
Cyber insurance is a common tool for risk transfer today. It’s also a key driver for cybersecurity program investment today. But who has cyber insurance and what benefits do organizations see from it? Analyzing Forrester data on cyber insurance adoption and breach response trends, we find that: Most organizations do not have standalone cyber insurance […]
Last month, Forrester announced its inaugural Security & Risk Enterprise Leadership Award. As former CISOs, my Forrester colleague Brian Wrozek and I are sharing our thoughts about why you should apply. There are tangible benefits to you, your team, your organization, and the greater security community. You should apply — and apply now — for […]
This week, we are thrilled to release new research: Build Trust And Lasting Emotional Bonds With Empathy. This report delves into empathy, one of the most critical of the seven levers of trust defined in the trust imperative. Forrester defines empathy as: The perception that an organization is emotionally connected to its customers, employees, […]
Vulnerability management, like flossing, is not fun, exciting, or sexy, but we know that it’s a necessary component of good hygiene. There’s a ton of evidence and research to strongly substantiate its benefits, and yet we frequently struggle to do it despite clearly understanding the consequences — we certainly don’t want a root canal! Yet, […]
In June, Forrester announced our inaugural Security & Risk Enterprise Leadership Award. Today, we’re extending the deadline for submissions to September 12 to give applicants time to finish their much-needed summer vacations and complete the application process. The Security & Risk Enterprise Leadership Award will recognize organizations — and their leaders — that have transformed the […]
The security operations center (SOC) has reached the same tipping point that software development faced many years ago: It’s dealing with too much data (big data and log management), struggling to innovate and update monolithic software (detection and incident response processes), and lacking ownership beyond initial deployment (content management). When the software world reached this […]
Security & risk leaders beware, the Biden administration released the next major step in its plan to implement the National Cybersecurity Strategy (NCS) on July 13, 2023. The National Cybersecurity Strategy Implementation Plan (NCSIP) includes 65 federal initiatives across 5 pillars aimed at increasing cybersecurity investment, assigning federal agencies to specific initiatives, and giving timelines […]
Forrester data shows that fewer than 10% of enterprises are advanced in their insights-driven capabilities. Find out why in this blog post.
Every year, Forrester fields the Forrester Analytics Business Technographics® Security Survey, which provides insight into security decision-makers’ current state, challenges, and forward-looking priorities. We analyzed the 2022 data to assess data breaches across seven primary industries: manufacturing; retail and wholesale; business services and construction; utilities and telecommunications; financial services and insurance; public sector and healthcare; and […]
I am thrilled to announce that we have updated one of the first pieces of research I published when I joined Forrester in 2018: what we then called “Harden Your Human Firewall.” This is now replaced with these three reports (available to Forrester clients only): Influence And Engage Executives, Influence And Engage Technology And Business […]
While it might seem like generative AI is the only use case for AI around today, just a few years ago deepfakes wore the mantle for attention and hype in the AI universe. That’s fallen off considerably today, but we will likely see a resurgence in interest based on attacks using deepfakes to scam and […]
Kubernetes is the de facto standard for deploying and managing application workloads and containers. Lee has written quite a bit about the power of Kubernetes as an innovation platform, but while development and architecture teams are bullish on Kubernetes, security teams can find themselves scrambling to secure Kubernetes environments as they hurtle towards production. The […]
Forrester is thrilled to announce its inaugural Security & Risk Enterprise Leadership Award, which will recognize security organizations that have transformed the security, privacy, and risk management functions to fuel long-term success. Learn how to apply here.
The Forrester Wave™: Enterprise Email Security, Q2 2023 is live! Practically dormant for a decade, the enterprise email security market sprung to life over the with mass customer migration to cloud email, rapid adoption of machine learning, and the widespread use of APIs to connect systems, bolster platforms, and share data. These market forces aligning […]
When buy-in goes wrong – perspectives from a former CISO/CSO In my last blog, I talked about how “it takes a village” from the perspective of the job being bigger than any one person and the many benefits of being involved in the CISO community to leverage the collective power of a broad support base. […]
We’re excited to announce our latest research on Vulnerability Risk Management (VRM) and Security Operations Center (SOC) teams. VRM and SOC teams are pivotal parts of the security organization with different responsibilities but shared challenges. When Allie and I kicked off our research on interlocks between these teams earlier this year, we weren’t sure what […]
When thinking of markets on the cusp of disruption, legal tech — and especially contract management — is not likely what comes to mind. But it should, and here’s why: Contracts are the heart and soul of commerce and business relationships. When the very nature of how businesses buy, sell, partner, hire, innovate, and facilitate […]
What do organizations use VRM for? Learn the five top use cases in this preview of our new report: The Vulnerability Risk Management Landscape, Q2 2023.
“On the internet, nobody knows you are a dog” is an oft quoted maxim from the 90s attributed to Peter Steiner. First appearing in The New Yorker, this meme illustrates the difficulty of establishing identity and, by extension, validating claims on the internet. Over three decades later, we still face the same challenges. In this […]
Ever catch yourself thinking that there are a thousand channels but there’s still nothing to watch on television? In the era before dedicated networks, streaming services, and on-demand programming, cartoon binge-watching consisted of five hours every Saturday morning, featuring tiny blue creatures, crime-fighting teenagers (and a mangy mutt), and superheroes. Among our favorites were the […]
Lone Wolf Or Wolf Pack? Perspectives From A Former CISO/CSO One of the most valuable, important, and rewarding things I did during my tenure as a CISO/CSO was becoming involved in the CISO community. There are plenty of leaders who choose to go down the CISO path primarily on their own, and perhaps for some, […]
Cybersecurity threats continue to plague organizations, multiplying like Mogwai in the 1984 hit movie “Gremlins” (just don’t feed them after midnight). Forrester data shows that almost three-quarters of organizations reported one or more data breaches in the past 12 months. Forrester’s recently published report, Top Cybersecurity Threats In 2023, examines five cybersecurity threats — established […]
At some point in every organization’s security journey, the problem of asset management inevitably comes up. Solutions are often cosmetic and don’t tackle fundamental issues or provide real visibility. As more organizations chart their zero trust course, the asset management problem comes up a lot more as you cannot mediate what you do not know. […]
On 18 April 2023, the European Commission adopted a proposal for the EU Cyber Solidarity Act to strengthen cybersecurity capabilities in the EU. The proposed act will support detection and awareness of cybersecurity threats, bolster preparedness of critical entities, reinforce solidarity, and improve crisis management and response capabilities across member states. Additionally, the Commission presented […]
Last week, Forrester’s published its first report on what cybersecurity vendors’ quarterly earnings means for technology executives. This research involved analysis of earning calls from ten publicly listed cybersecurity service providers. This information showcases existing trends and strategies and hopefully saves you some time by highlighting the most important interpretations. Even though most cybersecurity vendors’ […]
Oracle has again changed licensing rules for its widely used Java product. On January 23, 2023, the company introduced a new license metric, the SE Universal Subscription. It offers all the benefits of the legacy Java SE subscription, plus universal use rights (desktop, server, and third-party cloud) and triage support for customers’ entire Java portfolio, […]
Ransomware Vulnerability Warnings Are Coming To A Critical Infrastructure Near You The US Cybersecurity and Infrastructure Security Agency (CISA) launched the Ransomware Vulnerability Warning Pilot (RVWP) in January 2023 in response to ongoing concerns about the threat of ransomware. This is the CISA’s ransomware-centric take on external attack surface management for critical infrastructure. The RVWP pilot […]
I don’t follow the Eurovision Song Contest closely, but I know that ABBA famously won decades ago with “Waterloo” and that a few other contest winners — Celine Dion, Måneskin — have achieved global success afterwards. This year, though, an article about Eurovision got my attention. It seems that tickets to the live Eurovision performances […]
As part of Forrester’s research into securing what you sell, we have long advocated for security leaders to overlay their own activities with the rest of the product team and to engage in the product lifecycle before the product has even been defined. Last year, we reached out to product management decision-makers to learn more […]
Last week, we published Forrester’s third CISO Career Paths report. This research involved an analysis of the career paths of Fortune 500 CISOs, looking into their education, tenures, and prior experiences of security leaders at some of the world’s largest companies. This data showcases existing trends and helps forecast what CISO roles will look like […]
Forrester recently published Top Recommendations For Your Security Program, 2023 for CISOs and other senior cybersecurity and technology leaders. This year’s overarching theme involves protection (as you might expect) — but not exactly in the way you’d think in the context of security. In 2023, our recommendations fall into three major strategic themes for security […]
Until recently, discussions about Zero Trust (ZT) in Europe focused on the what and why. The last year has seen a significant shift in the market, and organizations have now begun focusing on the how. European organizations see significant value in adopting Zero Trust and have taken steps to prioritize adoption. This trend is driven […]
This blog outlines Forrester’s existing Security & Risk research to help organizations navigate, manage, and prepare their organizations for the implications of the National Cybersecurity Strategy.
2022 didn’t let up on the security incidents — according to Forrester’s Security Survey, 2022, 74% of security decision-makers experienced at least one data breach at their firm in the previous 12 months. As we looked at the top breaches and privacy violations of 2022 — and there was activity right up to the end […]
Perspectives From A Former CISO/CSO For my second blog in this series, I wanted to share my thoughts on one of my favorite subjects: third-party risk management (TPRM). More specifically, I’m going to primarily focus on the receiving side of the equation — i.e., responding to and dealing with external inquiries about your organization as […]
All businesses rely on contracts. Unlike customer-facing functions, however, the software that powers the creation, execution, and management of these commercial obligations hasn’t made the shift toward digital … until now! In my new report, The Contract Lifecycle Management Landscape, Q1 2023, I looked at the 26 notable contract lifecycle management (CLM) vendors that procurement, […]
Unless you’re a floppy disk aficionado, Tom Persky isn’t likely to be a familiar name. Tom is what you’d call a “last man standing,” as he’s the only bulk seller of floppy disks left, and his business of recycling, stripping, and reselling floppy disks is booming. You may be thinking, so what? Do they still […]
Forrester has been researching future fit organizations for the past few years, those organizations that have evolved their technology strategy to enable their firm’s customer-obsessed business strategy. Tech organizations fall into three tech strategy buckets: Traditional tech orgs are driven by cost, act as order-takers, and typically follow waterfall methodologies; modern tech orgs evolve to […]
What do Live Nation’s Taylor Swift ticketing debacle and cyber risk have in common? Bad assumptions. Whether you confidently believe that you can anticipate record ticket demand or believe that your payment processing infrastructure is secure enough to handle it, that belief is based on an assumption, and that assumption is based on the past […]
We ended 2022 with the announcement of a vulnerability within SiriusXM Connected Vehicle Services, which has a broad impact because of the ubiquity of these units. In 2023 the vehicle-related software vulnerabilities just keep on coming, this time within API endpoints used by vehicles’ telematics systems, an issue with a wide impact across 16 different […]
CISOs must use this period of austerity to reinforce security as a core competency that drives growth and protects revenue.
Over the last 12 months, “risk dashboards” became all the rage in cybersecurity, with varied titles such as “risk index,” “security baseline,” “security posture,” and “risk posture.” These dashboards appear in a vendor’s user interface and purport to help security programs improve. Some even offer coveted “benchmark data” that leaders can share with boards and […]
As new types of digital commerce and novel payment methods have proliferated and digital finance has become the norm in APAC, transaction fraud has become significantly more frequent and sophisticated. The COVID-19 pandemic has further increased this risk as fraudsters take advantage of a rich variety of digital channels. The post-pandemic economic downturn also increased […]
The External Attack Surface Management Landscape, Q1 2023 is now available! Forrester clients can view the report to dive deeper into the benefits of EASM and key functionalities to assess when selecting an EASM vendor. As Jess Burn and I finalized this report, we couldn’t help but think that organizations that are blind to what’s […]
Learn the benefits of implementing a minimum viable security strategy and get some clear next steps on putting it into practice at your organization.
So 2022 is officially done and dusted, for better or worse. But before getting too far into 2023, let’s take a moment to look back at what we achieved over the previous year. More specifically, I wanted to share some thoughts from our research associate, Aidan Riga, since he did such an outstanding job supporting […]
Building a robust vulnerability risk strategy takes input from multiple resources. More importantly, it requires input on factors specific to your company.
Happy holidays from the DevOps theme team! Our merry band of Forrester analysts covering enterprise architecture, infrastructure, application development, application security, and technology strategy meets periodically to share research, debate trends, and dive into breaking news. What are a few of the trends and themes that have caught our attention this year? Let’s dive in […]
I’ve been in the IT industry long enough to remember the start of the “browser wars,” when Internet Explorer took on Netscape in the late 1990s. Product names such as Mosaic, Netscape, “IE,” and Mozilla (and its next iteration with Firefox) were all part of the browser market development. Safari came along for Mac in […]
On top of the usual challenges, in 2023, security pros will see more risk coming from internal forces, such as enabling anywhere work and the future of the office. Learn more in our 2023 predictions.
In 2023, the risk function will rise at European organisations, but one major firm will lose employee trust through misuse of tech. Find out more in our 2023 cybersecurity predictions.
At first glance, the web application firewall (WAF) market — populated by long time vendors with robust partner programs, extensive supporting services, and a slew of customer engagement opportunities — may seem like a space that has topped out. However, changes in how organizations develop and deploy applications — more hybrid cloud, more APIs, more […]
Learn how to reduce the three most common types of insider threats in this Security & Risk event preview.
Local governments have become frequent targets of cyber attacks, and funding and planning for preventing for more attacks have been left largely to the local level. A new initiative is changing that.
Learn how to redefine data security in an age of multicloud, anywhere work, edge computing, and changing privacy regulations.
What does minimum viable product planning have to do with security and customer trust? Find out in this preview of our upcoming Security & Risk North America event.
What Topics Will You Be Covering At Forrester? I am very excited to be covering identity and access management (IAM), with a focus on the workforce environment (business to employee). I will also collaborate with Forrester’s other IAM analyst, Andras Cser. Some areas and topics that I hope to explore include: How to optimize workforce […]
Which security technologies should be getting the investment in 2023, and which ones should you be scaling back on? Find out in Forrester’s Planning Guide 2023: Security & Risk.
Learn the value of decentralized digital identities in this preview of Forrester’s Security & Risk event, November 8–9.