Skip to main content

Cybersecurity Quarterly Summer 2026

Page 1


Securing What's Next:

AI, Emerging Threats, and the Future of Cyber Defense

The rapid advances in AI, and the evolving threat landscape surrounding it, require organizations to enter a new phase in their cyber defense strategies. This new paradigm requires security leaders to adapt, prioritize, and stay ahead of the curve in a continuously shifting threat landscape.

Extending the Guidance of the CIS Controls to Help Secure Every Layer of Modern AI Environments

How Drones and AIDriven Threats are Redefining Risks to Major Events

The MS-ISAC Community Continues its Stellar Growth in its Mission to Improve U.S. SLTT Cyber Defense Defending Organizations Against Frontier AI Models' Accelerating Discovery of Exploits

Cybersecurity Quarterly is published and distributed in March, June, September, and December. Founded MMXVII.

Published by Center for Internet Security, Inc., 1712 Route 9, Suite 102, Clifton Park, New York 12065

For questions or information concerning this publication, contact CIS at email@cisecurity. org or call 518.266.3460

© 2026 Center for Internet Security. All rights reserved.

A Milestone Moment for the MS-ISAC Community

The MS-ISAC reached key milestones that highlight a maturing SLTT cybersecurity community that continues to focus on collaboration and resilience in light of changing environments.

Emerging Threats to Large-Scale Events: Unmanned Aircraft Systems (UAS) and Synthetic Media

Drones and AI-driven synthetic media are transforming threats to major events, requiring organizers and public safety officials to adapt planning, detection, and response strategies to protect large-scale gatherings.

An Updated Defender's Guide to the Frontier AI Impact on Cybersecurity Frontier AI is rapidly accelerating vulnerability discovery, requiring organizations to take action to reduce exposure and stay ahead of AI-driven attacks.

Applying the CIS Critical Security Controls to Secure Modern AI Systems

CIS Companion Guides for LLMs, agents, and MCP help organizations extend the CIS Controls to AI while delivering a layered, practical approach to managing emerging security risks.

Summer 2026 Volume 10 Issue 2

Editor-in-Chief

Michael Mineconzo

Managing Editor

Jay Billington

Copy Editors

David Bisson

Autum Pylant

Staff Contributors

Jay Billington

John Cohen

Andrew Dannenberger

Kaitlin Drape

Stephanie Gass

Patrick Johnston

Carlos Kizzee

Thomas Sager

Geneva Sands

Kevin Saupp

Valecia Stocchetti

QuarterlyUpdate with John Gilligan

“Again, this year, the topic of artificial intelligence (AI) and its impacts on organizations was the focus."

We have jumped into summer on the east coast of the United States, with temperatures having reached above 100 degrees at one point. Perhaps my wish for the “endless winter” to end was a bit hasty.

Last month, we held the ISAC Annual Summit in Orlando, FL. The Summit had a great turnout and a wide range of presentations and workshops. Again, this year, the topic of artificial intelligence (AI) and its impacts on U.S. State, Local, Tribal, and Territorial (SLTT) organizations was the focus for several of the sessions. We also had a track for the election community and a day-long session for the National Homeland Security Consortium, an association that includes a broad range of U.S. SLTT leadership roles.

The new Interim MS-ISAC Governance Board has also started meeting. This Board replaces the former MS-ISAC Executive Committee and has representatives from the CIO, CISO, homeland security, emergency manager, and law enforcement communities. The initial tasks of the Governance Board will be to set a vision for the future of the MS-ISAC and to advise the Center for Internet Security® (CIS®) regarding membership models.

FEMA recently issued a clarification on the use of funds provided through the State and Local Cybersecurity Grant Program (SLCGP) and other similar U.S. SLTT grant programs. The clarification specifically permits use of the funds for CIS products and services. However, the clarification indicates that use of funds for memberships that consist of bundled services is problematic, as FEMA has a hard time determining if the costs are reasonable and aligned with the objectives of the grant program. CIS will be working with the Governance Board to determine the best way to meet FEMA’s requirements relative to the current MS-ISAC membership model.

Consistent with the strong interest in the MS-ISAC Annual meeting, the theme of this quarter’s issue of Cybersecurity Quarterly is "AI security."

Leading off this quarter's issue, Carlos Kizzee, our SVP of MS-ISAC Strategy and Plans, recaps some highlights from the ISAC Annual Summit, as well as some

significant recent milestones for the MS-ISAC, including surpassing the 5,000-member milestone and the creation of the Interim Governance Board.

Touching on some of the extensive research and content we've been developing on AI, CIS’s Security Best Practices Team discusses three recent AI companion guides to the CIS Critical Security Controls® (CIS Controls®), the AI Large Language Model (LLM) Companion Guide, AI Agent Companion Guide, and Model Context Protocol (MCP) Companion Guide. Additionally, CIS’s Strategic Projects and Initiatives organization shares findings from two of their recent white papers, Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings and Deepfakes and Synthetic Media: The Emerging Threat to Large-Scale Public Gatherings.

Our partners from Palo Alto Networks explore frontier AI’s impact on cybersecurity. They provide guidance and recommendations for defenders to protect their organizations from previously unknown vulnerabilities and exploits that are now becoming easier to discover with new AI models. This article was drawn from Palo Alto Networks’ role as a launch partner for Project Glasswing and its early access to Anthropic’s Claude Mythos model, as well as its involvement in OpenAI's Trusted Access for Cyber program.

Finally, Stephanie Gass, CIS’s Senior Director for Information Security, discusses how to develop an effective cybersecurity risk tolerance policy that ensures an organization can respond to current and emerging threats.

I hope you enjoy this quarter’s issue.

Best Regards,

NewsBits&Bytes

CIS Honors University of Georgia with 2026 Alan Paller Laureate Award

The Center for Internet Security® (CIS®) has named the University of Georgia as the 2026 recipient of the Alan Paller Laureate Award, awarding $250,000 to support the development of an open-source tool that helps organizations prioritize implementation of CIS Critical Security Controls® (CIS Controls®) v8.1. Led by Dr. Thirimachos Bourlai and Ph.D. candidate Hayat Cue, the project uses cybersecurity assessment data, real-world threat intelligence, and cost considerations to generate clear, threat-informed recommendations for security investments. Designed to support resource-constrained organizations, the open-source tool aims to turn complex assessment results into actionable, prioritized steps that strengthen cybersecurity resilience and improve decision making. Learn more about the project here

CIS Expands Hardened Images to Support AI and High-Performance Computing

The Center for Internet Security® (CIS®) has expanded its CIS Hardened Images® to support artificial intelligence (AI) and high-performance computing (HPC) workloads, introducing secure-by-design cloud images optimized for GPU-driven AI and distributed computing environments. Available in AWS Marketplace, the new offerings provide pre-configured operating systems aligned to the CIS Benchmarks® that enable organizations to deploy AI infrastructure with security built in from the start, reducing risk, improving consistency, and accelerating deployment. Learn more about AI-Optimized CIS Hardened Images here.

CIS and SANS Launch New Product Bundle in AWS Marketplace to Improve Cloud Security

The Center for Internet Security® (CIS®) and the SANS Institute have launched a joint offering in AWS Marketplace that pairs CIS Hardened Images® with SANS cloud security training to help organizations secure cloud migrations from the start. By combining pre-configured infrastructure aligned to the CIS Benchmarks® with hands-on training, the joint offering enables teams to deploy secure AWS environments, reduce misconfigurations and configuration drift, and build the expertise needed to maintain security over time. Designed to address common cloud adoption challenges, the integrated approach supports faster, more secure deployment and ongoing cloud operations. Learn more about the partnership here

CIS Controls and MS-ISAC Insights Featured in Verizon’s 2026 Data Breach Investigations Report

Verizon’s 2026 Data Breach Investigations Report (DBIR) again highlights the critical role of the CIS Critical Security Controls® (CIS Controls®) and incorporates insights from the Multi-State Information Sharing and Analysis Center® (MS-ISAC®). Drawing on more than 31,000 incidents and 22,000 confirmed breaches worldwide, the report underscores that attackers increasingly exploit unpatched vulnerabilities, now the leading entry point in 31% of breaches, while remediation rates remain low and response times continue to grow. The findings reinforce the importance of prioritized security controls and shared threat intelligence to address common attack paths, with ransomware continuing to rise and impacting nearly half of breaches, while MS-ISAC data provides additional visibility into threats facing public sector organizations. Learn more in our recent blog post , podcast episode , and webinar on the DBIR.

A Milestone Moment for the MS-ISAC Community

Following the fundamental changes to the MS-ISAC in 2025, the community remains strong. The MS-ISAC recently reached some important milestones that signal a resilient, coordinated cybersecurity community that continues to equip U.S. SLTTs with the support and resources needed to defend their citizens.

The first half of 2026 has marked a defining chapter for the Multi-State Information Sharing and Analysis Center® (MS-ISAC®), underscoring both the strength of our community and a strong vision for the future. Three recent developments — the MS-ISAC surpassing 5,000 members, the establishment of an Interim Governance Board, and the tremendous success of the 2026 ISAC Annual Summit — collectively signal a maturing, resilient, and increasingly influential cybersecurity ecosystem for U.S. State, Local, Tribal, and Territorial (SLTT) governments nationwide.

5,000 Members: A Testament to Collective Defense

Reaching the 5,000-member milestone under the new member-funded model first introduced in 2025 is far more than a numerical achievement; it is a powerful affirmation of the MS-ISAC’s role as a trusted hub for collaboration, information sharing, and operational support, and demonstrates the continued commitment of the U.S. SLTT community to collective cyber defense. The steady growth reflects both heightened awareness of cyber risk across U.S. SLTT organizations and the demonstrated value of MS-ISAC membership in strengthening defenses against an evolving threat landscape.

Today’s cyber threats are increasingly sophisticated, targeting not just data but critical infrastructure systems that underpin public safety, health services, and essential government operations. In this environment, no single entity can stand alone. The MS-ISAC’s growth highlights a shared commitment among U.S. SLTT organizations to work collectively by leveraging shared intelligence, best practices, and response capabilities to improve resilience nationwide. Each new member enhances the community’s collective visibility into threats and expands the

Three recent developments — the MSISAC surpassing 5,000 members, the establishment of an Interim Governance Board, and the tremendous success of the 2026 ISAC Annual Summit — collectively signal a maturing, resilient, and increasingly influential cybersecurity ecosystem for U.S. State, Local, Tribal, and Territorial (SLTT) governments nationwide.

network of defenders working toward a common goal: securing the nation’s public sector infrastructure.

Governance for the Future: The Interim Board

As the MS-ISAC expands in both scale and strategic importance, governance becomes even more critical. The establishment of the MS-ISAC Interim Member Governance Board represents a proactive step toward ensuring that the organization remains responsive, member-driven, and aligned with the needs of its diverse stakeholders.

The Interim Board provides structured guidance during a period of transition and growth, helping to shape policies, priorities, and long-term direction. Importantly,

Benefits SLTTs Gain From MS-ISAC Membership

The MS-ISAC helps SLTT teams stay ahead of threats, respond faster, and protect the communities they serve.

Statewide Insight into Cybersecurity Progress

1 24x7x365 Expert Cybersecurity Support for Public Organizations

2

Faster Advanced Warning of Verified Cyber Threats

3 Cross-Sector Coordination that Builds Resilience

6

5 Time-Saving Tools and Resources for Every Public Entity

4 Secure Information Sharing across Agencies & Communities

Emerging Threats to Large-Scale Events: Unmanned Aircraft Systems (UAS) and Synthetic Media

As global events draw larger crowds and attention, emerging threats are evolving just as quickly. The CIS Team explores how drones and AI-driven synthetic media are reshaping event risk and what public safety leaders must do to prepare.

Large-scale events and gatherings are especially attractive targets due to their compressed time frame, emotionally charged audiences, and symbolic value, bringing unique challenges for organizers and public safety officials and, at the same time, creating a target-rich environment for threat actors.

This summer, the United States was host, alongside Mexico and Canada, to one of the most watched and attended events in the world, the FIFA World Cup, which kicked off on June 11, 2026. Amid the more than month-long tournament, the United States celebrated its 250th anniversary with major events across the country. Looking ahead, the 2028 Summer

Olympics will be held in Los Angeles, marking the first time the United States has hosted since 2002.

Over the past year, through its expanded intelligence and support related to large -scale public events, the Center for Internet Security® (CIS®) has observed significant emerging threat trends, technological changes, and unseen risks to major gatherings across the globe. Two of those emerging threats include the expanding use of Unmanned Aircraft Systems (UAS) and the rise of synthetic media, spurred on by the advancing artificial intelligence field. Insights in this article are drawn from two CIS white papers, Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings and Deepfakes and Synthetic Media: The Emerging Threat to Large-Scale Public Gatherings.

Emerging Threats to Large-Scale Events

Artificial intelligence (AI)-enabled synthetic media, including deepfake audio, video, imagery, and text, has emerged as one of the most consequential additions to the threat environment for large-scale public gatherings as generative AI (GenAI) tools have sharply lowered the barrier to entry for sophisticated influence operations. Large-scale mass gatherings, including concerts, festivals, political conventions, and sporting events, to include the FIFA World Cup 2026 (FWC26), present especially attractive targets. These venues concentrate large, emotionally charged audiences within compressed information environments where rapid perception shifts can generate disproportionate psychological, operational, and reputational effects.

Meanwhile, the proliferation of commercially available UAS technology has created a viable, diverse, and rapidly evolving threat for major events and gatherings. Large-scale events face heightened UAS threat exposure from a broad spectrum of actors including terrorist organizations, state-sponsored adversaries, transnational criminal organizations/cartels, ideologically motivated extremists, and opportunistic lone actors.

Together, drones and synthetic media create new opportunities for threat actors and require organizers, law enforcement, and other public safety officials to establish baseline awareness; coordinate federal, state, and local partners; and integrate UAS and synthetic media considerations into existing planning, intelligence, and response frameworks.

Evolving UAS Technology and Risk to Large-Scale Public Gatherings

The rapid proliferation and technological maturation of UAS have fundamentally transformed the threat landscape for public safety and event security. Over the past several years, advances in UAS navigation systems, range, speed, video quality, data storage capacity, and payload-carrying capabilities have advanced at accessible price points, decreasing obstacles to adoption, including cost and expertise.

Traditional venue security architectures are designed around ground-level threats. Perimeter fences channel foot traffic through screening points, magnetometers and bag checks detect weapons and prohibited items, and credential systems control access to restricted areas. As the Cybersecurity and Infrastructure Security Agency (CISA) notes, the advanced capabilities of UAS and their ability to bypass traditional ground-based security measures make them a complex and timely concern for critical infrastructure and public gatherings.

The implications of this threat are already evident in routine criminal operations. DroneSec, which partnered with CIS on the white paper, has documented numerous cases of drone-smuggled contraband across international borders and into prisons, including weapons and narcotics. There have been hundreds of documented successful drone delivery operations, often at defended facilities with established security perimeters.

Threat Actors

The UAS threat to large-scale public gatherings can emanate from a diverse spectrum of actors with varying motivations, capabilities, and risk tolerances, including non-state threat actors, such as jihadist terrorist organizations, Mexico-based transnational

The proliferation of commercially available UAS technology has created a viable, diverse, and rapidly evolving threat for major events and gatherings. Large-scale events face heightened UAS threat exposure from a broad spectrum of actors

criminal organizations, state-sponsored and foreign intelligence actors, and domestic violence extremists. For example, Islamic State group (IS) and IS-inspired individuals possess demonstrated intent and capability to employ weaponized UAS against Western targets, including mass gatherings and special events. Additionally, the People’s Republic of China (PRC) represents a distinct but significant UAS-related threat vector operating through the commercial supply chain rather than through direct hostile action.

Tactics, Techniques, and Procedures (TTPs) for Mass Gathering Environments

Security officials and event organizers should remain aware of these TTPs when planning and hosting large gatherings and events.

• Pre-Operational Surveillance and Reconnaissance. Drones equipped with high-resolution cameras and sensors can conduct aerial surveillance of venue layouts, security positions, screening locations, staff patrol patterns, and crowd movement dynamics from standoff distances that preclude visual detection by ground personnel.

• Weaponized Payload Delivery. The weaponization of commercial drones encompasses several distinct attack modalities, each with different technical requirements, detection signatures, and consequence profiles, which include improvised explosive devices (IEDs) and first-person view (FPV) one-way attack.

• Disruption and Crowd Panic Operations. An unauthorized drone violating the temporary flight restrictions over a venue can prompt game delays, trigger evacuation procedures, and induce crowd panic.

• Cyber-Enabled UAS Operations. UAS presents a unique cyber threat vector by providing

proximity-based access to networks and communications systems inside security perimeters that ground-based attackers cannot reach. A drone can carry Wi-Fi exploitation tools, radio frequency (RF) jamming equipment, or rogue access points to within meters of venue network infrastructure, stadium operations centers, or broadcast systems. Learn more about cyber-enabled UAS operations here: Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings Cyber Risks Companion Guide.

Security Planning Considerations for Major Events

A critical gap in the current U.S. counter-UAS posture is the absence of widespread baseline detection capability across state and local jurisdictions. While major event security planning often emphasizes advanced systems, many agencies lack basic airspace awareness tools, limiting their ability to detect, assess, and respond to UAS incidents.

Addressing these gaps requires a distributed, adaptive security posture that prioritizes scalable, cost-effective detection and training to establish baseline capabilities nationwide while extending counter-UAS detection, observation, and public awareness beyond stadiums to fan zones and other open, high-density environments. Small and rural jurisdictions face a distinct risk environment characterized by resource constraints, geographic challenges, and lower perceived risk despite vulnerabilities, necessitating greater emphasis on low-cost, high-impact measures, such as public awareness programs, regional partnerships, and integrated multi-jurisdictional planning.

Deepfakes and Synthetic Media: The Emerging Threat to Large-Scale Public Gatherings

Synthetic content, including deepfakes, can overwhelm information environments, crowd out trusted signals, degrade trust in legitimate communications, and increasingly target broadcast systems, financial markets, and high-visibility individuals in real time. The growing reliance on connected digital infrastructure, including mobile ticketing, high-speed venue connectivity, and Internet of Things (IoT)-enabled services, further expands the risk surface, creating additional pathways through which manipulated, misleading, or synthetic information can influence operational systems, public communications, and real-time decision-making.

Threat Actors and Motivations

A wide range of threat actors are positioned to employ synthetic media against large-scale events. Motivations

and capability levels vary, but most share a common operational logic: exploit the compressed information environment to amplify disruption or shape the narrative at minimal cost. Threat actors include:

• State and state-aligned actors. Russian, Chinese, and Iranian influence networks have repeatedly employed profile imagery and synthetic personas created using generative adversarial networks (GANs) to amplify divisive narratives, according to multiple private-sector research reports reviewed by the FBI.

• Terrorist and violent extremist groups. The National Counterterrorism Center (NCTC), DHS, and FBI jointly assessed that violent extremists are actively exploring use of GenAI for recruitment, radicalization, translation, and content creation. Extremist use of deepfakes to fabricate atrocities, impersonate officials, or amplify grievances ahead of a symbolic target event remains a credible concern.

• Transnational criminal organizations and fraud networks. The FBI’s Internet Crime Complaint Center (IC3) and the Financial Crimes Enforcement Network have noted a steady rise in deepfake-enabled fraud, including real-time face-swapping in video calls, voice-cloning of executives, and synthetic identity creation to bypass Know Your Customer (KYC) checks.

Observed and Anticipated TTPs

Deepfake-enabled operations are increasingly designed as coordinated, multi-stage efforts to shape perception through repetition, emotional engagement, cumulative exposure, and increasingly hyper-personalized targeting that can inhibit timely decision-making.

• Pre-Event Shaping Operations. For example, pre-event operations may include narrative pre-positioning, or the fabricated audio, video, or imagery seeded weeks or months in advance of an event to prime audiences around specific themes.

• Event Exploitation. Exploitation during an event may include impersonation of public officials, law enforcement, or event organizers; the targeting of high-visibility individuals, or fabricated incidents and emergency messaging; or synthetic threat reporting and swatting.

• Post-Event Exploitation. During the post event period, threat actors may fabricate incidents, amplify perceived failures, or increasingly claim that genuinely authentic audio or video is AI-generated.

The rise in availability and accessibility for both drones and synthetic media represents a major shift for threat actors targeting large-scale events, and it marks a turning point for the organizers, public safety officials, and communities protecting public events and gatherings.

The trajectory of GenAI capability strongly suggests the realism, speed, and cost of synthetic media will continue to favor offensive use in the coming years. At the same time, the UAS threat to large-scale public gatherings is a documented, legislatively recognized, and actively resourced national security priority. The convergence of affordable commercial drone technology, battlefield-proven weaponization techniques migrating from global conflict zones, diverse and capable threat actors with demonstrated interest in mass gathering targets, and the unique vulnerabilities of open-air sporting venues creates a risk environment that demands a continuously evolving approach to event security.

Event organizers and public safety officials should treat UAS and synthetic-media risks as a permanent feature of the operational environment, proactively integrating these scenarios into threat mitigation efforts, coordination planning, and public awareness campaigns.

To take a more in-depth look into how these emerging threat vectors are impacting large-scale events, download CIS's recent white papers, Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings and Deepfakes and Synthetic Media: The Emerging Threat to Large-Scale Public Gatherings.

John D. Cohen is Executive Director of the Office of Strategic Programs and Initiatives (OSPI) at the Center for Internet Security (CIS), where he partners with law enforcement, mental health, and civil society organizations to address how online activity impacts crime, violence, community safety, and constitutional protections. He also serves as an adjunct professor at Georgetown University and an ABC News contributor on homeland security issues. With over 40 years of experience across federal, state, and local government, including senior leadership roles at the U.S. Department of Homeland Security, Cohen has led national efforts in counterterrorism, information sharing, and prevention of violent extremism and mass casualty incidents. His career spans public service, policy development, and private sector collaboration, supported by numerous national awards recognizing his impact on public safety and security.

Kaitlin Drape is a Strategic Program Specialist at the Center for Internet Security (CIS), where she focuses

on the multidimensional threat landscape and how cyber and physical threats intersect in an increasingly dynamic threat environment. Drape led CIS's special events coverage for the FIFA World Cup 2026, providing robust threat intelligence to commercial partners, and state and local entities across the United States. Prior to CIS, Drape served as a team lead and open source intelligence specialist at Dataminr.

Geneva Sands is the Senior Director of Community Outreach and Communications for the Office of Strategic Programs and Initiatives (OSPI) at the Center for Internet Security (CIS), where she is shaping strategic communications efforts and supporting information sharing across public and private sector stakeholders. Her work focuses on development of CIS’s special event risk analysis and advisory services alongside advancing a stronger understanding of the multidimensional threat environment. Prior to joining CIS, she spent more than 15 years in journalism, serving in reporting, production, and writing roles at CNN, ABC News, and Bloomberg TV.

Kevin Saupp is a Senior Advisor for the Office of Strategic Programs and Initiatives (OSPI) at the Center for Internet Security (CIS), advising on law enforcement, homeland security, and intelligence matters. He has more than two decades of experience leading national security and public safety initiatives. Saupp previously served in multiple senior roles at the U.S. Department of Homeland Security (DHS), where he focused on counterterrorism, intelligence sharing, and strengthening partnerships across federal, state, local, and private sector communities. His work at CIS focuses on emerging threats, cybersecurity, critical infrastructure protection, and helping organizations build more effective approaches to managing today’s evolving risk environment.

An Updated Defender's Guide to the Frontier AI Impact on Cybersecurity

Frontier AI models are redefining cyber risk, accelerating vulnerability discovery and exploitation timelines. Based on real-world findings from Project Glasswing and the Trusted Access for Cyber program, our partners at Palo Alto Networks provide actions organizations can take to find, fix, and outpace AI-driven threats.

By now, you’ve heard about the latest frontier artificial intelligence (AI) models that are remarkably good at finding vulnerabilities in code and creating potential exploits. So good, in fact, that these models have been significantly limited from general use in an attempt to give defenders time to find and fix vulnerabilities before attackers find and exploit them.

For context, on April 7, 2026, we began testing Anthropic’s Claude Mythos model as a launch partner for Project Glasswing. Our conclusion was clear: The latest models are extraordinarily capable at finding vulnerabilities and changing them into critical exploit paths in near-real time. In Defender's Guide to the Frontier AI Impact on Cybersecurity, I shared our early findings and recommendations.

Since then, we’ve continued testing the latest frontier AI models, including Anthropic’s Mythos and Claude Opus 4.7 along with OpenAI’s GPT-5.5-Cyber as part of the Trusted Access for Cyber (TAC) program. The big question just a few weeks ago was: “Are we overstating the model capabilities?” With more testing, I can confidently say we weren’t. In fact, these models are likely even better at finding vulnerabilities than we initially realized. Today, we’re providing an update on our ongoing research, our learnings uncovered in the process, and the approach we’re taking to protect our customers.

Find and Fix Before Attackers Find and Exploit

We recently released our May “Patch Wednesday” security advisories, our monthly cadence of transparent vulnerability disclosure and remediation. This is the first

The big question just a few weeks ago was: “Are we overstating the model capabilities?”
With more testing, I can confidently say we weren’t. In fact, these models are likely even better at finding vulnerabilities than we initially realized.

time where the majority of findings were the result of frontier AI models scanning our code.

• These are the results of the full, initial scan of over 130 products across all three platforms.

• We’ve patched all important vulnerabilities in our SaaS delivered products, and all customer-operated products now have patches available.

• The May advisory covers 26 CVEs (representing 75 issues) versus our usual volume (typically less than five CVEs in a month), none of which are being exploited in the wild. Note: This excludes CyberArk vulnerabilities, which are disclosed in their normal process.

It's important to understand this isn’t a one-and-done situation. We’re now rescanning, applying all our learnings about how to provide the right context and threat intelligence to the models. We intend to fix every

vulnerability we find before advanced AI capabilities become widely available to adversaries.

While incredibly powerful, AI models aren’t simply magic. To achieve high-fidelity results, you need to build AI scanning harnesses, leveraging context, guardrails, and threat intelligence. We’ve also discovered a variance across models due to differences in their training. A multi-model approach is required to identify the superset of vulnerabilities. And finally, while the immediate priority is finding and fixing the vulnerabilities that organizations currently have, the longer-term shift is incorporating these models directly into the software development lifecycle. This is the light at the end of the tunnel: a future where software is secure by design.

Four Steps Every Organization Needs to Take Immediately

Regardless of the current restricted access, we believe these capabilities will flow more broadly to other models. We now estimate a narrow three-to-five-month window for organizations to outpace the adversary before AI-driven exploits start to become the new norm. This impending vulnerability deluge demands urgency. Organizations that haven’t put appropriate safeguards in place will face an entirely new class of risk. Here’s what we recommend:

1. Find and Fix Vulnerabilities in Your Applications, Products, and Code

Find and fix before attackers find and exploit.

• Leverage AI models to identify vulnerabilities across the entire codebase.

• Apply the same AI scanning to your open-source supply chain and remediate or mitigate findings.

• Run accelerated patching tightly coordinated with product and development teams.

2. Assess, Reduce, and Remediate Your Exposure

Reduce what is reachable by attackers and secure what must be accessible, such as customer-facing applications.

• Attack surface management products, like Cortex Xpanse®, have never been more critical for finding and reducing exposure.

• The latest frontier AI models are very adept (with the right AI scanning harness) at evaluating exposures,

understanding security misconfigurations, and prioritizing attack-path reachability.

• Audit your supply chain, including AI infrastructure, runtime environments, and model dependencies.

3. Ensure Attack Protections

Vulnerability exploits are typically just one step of a multistep attack lifecycle. Ensuring best-in-class protections is now even more important for preventing breaches.

• Map current sensor coverage to identify critical blind spots in detection, prevention, and telemetry.

• Deploy best-in-class Extended Detection and Response (XDR) everywhere with an emphasis on real-time ML-based detection and prevention of attacks with all hosts on-premises and cloud included.

• Deploy agentic endpoint security to secure widescale adoption of vibe coding and AI security across the enterprise (e.g. Prisma AIRS® and our recent acquisition of Koi are now a necessity for securing the agentic endpoint).

• Secure enterprise browsers with AI-based security are a must-have for securing where users now do their work.

• Zero trust and identity security are foundational to securing every user and connection, extending to internal segmentation and outbound application connections.

4. Deploy

Autonomous AI-driven attacks will drive attack lifecycles to minutes requiring every security operations center (SOC) to achieve single-digit mean time to detect (MTTD) and mean time to respond (MTTR).

• Attack detections must be driven by AI and machine learning (ML) to detect even frequently changing and novel attacks at scale.

• These AI detections must operate against a wide range of first-party and third-party data sources. A best-in-class AI SOC must operate on ALL relevant data sources.

• Automation, both natively integrated and throughout the SOC lifecycle, is necessary to achieve single-digit MTTR. This automation will increasingly be agentic.

• This must be delivered as a platform to remove seams and gaps created by point solutions.

• Assess and act as quickly as possible.

Fighting AI with AI: AI Frontier Security Innovations Coming Soon

So far, frontier AI models only find new attacks, not new attack techniques. This means that with the right innovations, we can expand our use of AI to solve the security challenges that organizations are facing and deliver what our customers need to stay ahead of the ever-evolving threat landscape, including:

• Reimagining virtual patching with proactive, high-fidelity content updates across network, endpoint, and cloud security: We expect that across open-source and technology suppliers, there will be a deluge of patches, and virtual patching will provide a mitigation layer necessary to give your teams time to update. We expect to roll out the first phase of capabilities very soon.

• Enhanced attack preventions, including cyberlarge language model (LLM) trained ML and small language models (SML) and behavior protections: Early testing with Cortex XDR® and our network security services, such as WildFire® malware prevention, indicate high-protection coverage from the types of attacks created using these new frontier AI models.

• Using these models to scan our code, applications, and even security configurations: Our intention is to productize these capabilities and incorporate them into our platforms.

Unit 42: We’re Here to Help

We recognize that not everyone has the capacity and/ or expertise to action all of the recommendations to effectively counter frontier AI-driven risks in the short timeframe mandated by AI innovation. Our Unit 42 Frontier AI Defense service is designed to discover and remediate your current exposure before attackers do, strengthen controls that reduce exposure and contain impact, and modernize security operations so teams can detect and respond at machine speed.

This is a pivotal moment for our industry. While the scale of the challenge presented is real, I’m confident in our ability to solve it. We’re here to help our customers navigate this transition and ensure that as the landscape continues to evolve, the advantage remains with the defender.

So far, frontier AI models only find new attacks, not new attack techniques. This means that with the right innovations, we can expand our use of AI to solve the security challenges that organizations are facing.

Since early product inception in 2006, Lee Klarich has served as the head of product management at Palo Alto Networks, overseeing the product strategy and roadmap and playing a key role in delivering our NextGeneration Security Platform. In August 2025, he joined the Palo Alto Networks Board of Directors and became chief product and technology officer with responsibility for driving the company's technology vision and leading both the engineering and product organizations for the company. Prior to Palo Alto Networks, he was the director of product management for Juniper Networks, where he was responsible for firewall/VPN platforms and software. He joined Juniper Networks through the NetScreen Technologies acquisition, where he managed the same product line. Previously, he held various positions at Excite@Home and Packard Bell-NEC. He holds a bachelor's degree in engineering from Cornell University.

Applying the CIS Critical Security Controls to Secure Modern AI Systems

Securing AI isn’t just about the model. As LLMs, agents, and integrations reshape enterprise systems, the CIS Security Best Practices team introduces three companion guides that extend the guidance of the CIS Controls to help security teams apply a layered, practical approach to managing emerging AI risk.

Artificial intelligence is reshaping enterprise operations, but it is also expanding the attack surface faster than most security teams can manage.

From large language models (LLMs) to autonomous agents and integration protocols, organizations are deploying powerful AI capabilities without consistent, practical guidance on how to secure them. Traditional security practices still apply, but they must evolve to address new risks like prompt injection, data poisoning, and unintended autonomous behavior.

To address these challenges, the Center for Internet Security® (CIS®), in collaboration with Astrix Security and Cequence Security, developed actionable cybersecurity guidance that extends the globally recognized CIS Critical Security Controls® (CIS Controls®) into modern AI environments. The result is three new CIS Companion Guides:

• AI Large Language Model (LLM) Companion Guide

• AI Agent Companion Guide

• Model Context Protocol (MCP) Companion Guide

Together, these guides provide a layered, implementation-focused approach to help enterprises adopt modern AI responsibly and securely while staying aligned with the CIS Controls they already use in their cyber defense strategy.

Why AI Security Requires a Layered Approach

AI systems are not monolithic. They are built from interconnected components that each introduce unique vulnerabilities:

• Model layer: Where LLMs are trained, fine-tuned, and deployed

• Agent layer: Where models act autonomously or semi-autonomously

Organizations are deploying powerful AI capabilities without consistent, practical guidance on how to secure them. Traditional security practices still apply, but they must evolve to address new risks like prompt injection, data poisoning, and unintended autonomous behavior.

• Integration layer (MCP): Where models connect to external tools, data, and services

Each layer introduces its own risks, and those risks do not exist in isolation. A weakness in how a model is configured can affect how an agent behaves just as an overly permissive integration can expand the blast radius of a compromised system.

This is why AI security requires a layered approach that applies consistent controls across each dimension of the system while accounting for how those

layers interact. Traditional security best practices like the CIS Controls still apply, but they must be interpreted through an AI-enabled lens and adapted to address AI-specific risks such as prompt injection, data poisoning, tool misuse, and unintended autonomous behavior.

Securing the AI Ecosystem Begins at the Model Layer

The foundation of any AI-enabled system is the model: the LLM or small language model (SLM) responsible for generating responses, transforming text, writing code, handling data, or powering downstream workflows. However, unlike traditional software, models aren’t deterministic. Their behavior shifts with prompts, context windows, retrieval inputs, fine-tuning, temperature settings, or even silent provider updates.

These characteristics fundamentally change the threat model. Attackers no longer need to exploit code paths or vulnerabilities. Instead, they can manipulate inputs, context, data sources, or configuration to influence model behavior in ways that are difficult to detect and even harder to reproduce.

The AI LLM Companion Guide addresses this shift by translating the intent of the CIS Controls into practical expectations for AI systems across their full lifecycle. It also highlights AI-specific risk domains that require explicit operational controls, including prompt and guardrail change control, context boundary enforcement, model and dataset provenance, and the containment levers required to respond quickly when AI-driven workflows behave unexpectedly.

By interpreting the CIS Controls through the lens of textbased generative AI, this guide provides practitioners with a practical, defensible way to secure emerging AI capabilities using the same prioritized framework already used across thousands of enterprises worldwide. The result is a consistent approach that strengthens the security of LLM- and SLM-enabled systems while preserving the flexibility to align with rapidly advancing AI technologies.

Governing and Securing AI Agents Actions

If the model layer is about predicting text, the agent layer is about taking action.

AI agents introduce planning, decision-making, tool invocation, memory, retrieval, and multi-step reasoning, effectively giving AI systems the ability to operate like digital employees. This operational capability is what makes agents so valuable, but it is also what makes them risky.

Unlike stand-alone models, agents operate across the broader enterprise environment. They interact with internal services, external APIs, sensitive data, and user workflows, and they can trigger real-world outcomes. This expanded footprint introduces new risks, including unauthorized actions, data leakage, and unintended system changes, that require security considerations beyond traditional model-centric safeguards.

The AI Agent Companion Guide provides practical, actionable guidance for applying the CIS Controls to the agent layer specifically, focusing on governance and accountability. By aligning established security practices with the unique operational characteristics of AI agents, enterprises can strengthen their security posture while maintaining the flexibility and innovation that AI systems enable. Each section interprets relevant CIS Safeguards in the context of agent behavior, providing clarity on where traditional controls still apply and where new patterns must be considered.

This approach ensures that organizations are not only enabling AI-driven automation but also maintaining control over how that automation operates. As agents become more capable, strong governance becomes essential to ensure they act within defined boundaries.

Securing AI Integrations with Model Context Protocol

If the model layer is about predicting text and the agent layer is about taking action, the protocol layer is about execution. MCP provides a structured, standardized open interface through which AI systems access tools, retrieve data, and interact with services across environments.

Rather than relying on proprietary or model-specific integrations, MCP provides a common, interoperable framework so that different models, agents, and platforms can access the same set of capabilities in a controlled way. This increases modularity, improves auditability, and makes integration behavior more predictable across models and platforms. It also introduces significant risk. Every connection between an AI system and an external resource expands the attack surface, creating potential pathways for unauthorized access, data exposure, or abuse of system capabilities.

The MCP Companion Guide focuses on securing these interactions by applying the CIS Controls to how access is granted, managed, and monitored. In CIS terms, MCP primarily expands the identity, access control, logging, and application security surfaces by formalizing how AI systems discover and invoke privileged capabilities. MCP introduces operational and security considerations that differ significantly from traditional integration models, requiring protections tailored to agent-driven tool execution and context management. This guide interprets the CIS Controls in the context of MCP deployments and highlights additional considerations needed to protect these systems effectively.

By treating integrations as controlled trust boundaries rather than open connections, organizations can ensure that AI systems interact with their environments safely and predictably.

Extending Proven Best Practices to a New Domain

One of the most important aspects of these companion guides is what they do not require. Organizations do not need to adopt a new framework or rethink their entire security strategy. Instead, they can extend the widely used and accepted CIS Controls into the AI domain.

While each companion guide focuses on a specific layer, their true value emerges when applied together. AI systems are interconnected, and weaknesses in one layer can cascade into others. Together, the guides extend the CIS Controls into the realities of modern AI, helping security teams apply familiar, proven principles to new architectures. The outcome is a practical path to innovation without compromising control, ensuring that as AI systems become more powerful, they also remain predictable, auditable, and secure.

Explore the LLM, Agent , and MCP Companion Guides and strengthen your AI security strategy by aligning AI initiatives with the CIS Controls.

Andrew Dannenberger is a Technical Product Support Specialist and AI Standards professional at the Center for Internet Security (CIS), where he focuses on AI standards and guidance for the CIS Benchmarks and CIS Controls. In this role, he tracks emerging AI technologies and threat trends, coordinates with internal subject matter experts to ensure consistency across CIS publications, and supports AI enablement efforts through training development and working sessions. Andrew has led cross-functional AI initiatives at CIS, developed AI-powered tools, and served as a consultant on AI topics to CIS leadership. Prior to CIS, he served as a Senior Training and Development Specialist with Raytheon in Afghanistan, where he developed and led English language training programs in support of NATO and U.S. Department of Defense missions. Andrew holds a Bachelor of Applied Science in Cybersecurity and Forensics from Highline College as well as a Bachelor of Arts in International Studies and Political Science from Virginia Military Institute.

Thomas Sager is a Cybersecurity Engineer for the CIS Critical Security Controls at CIS. In this role, he is dubbed as the team cryptographer for mapping of the CMMC and PCI frameworks to the CIS Critical Security Controls. Prior to joining the CIS Controls team, Sager was a commercial security consultant under a federal contractor, greatly benefiting from the opportunity to work within a variety of client environments.

Valecia Stocchetti is a Senior Cybersecurity Engineer for the Center for Internet Security (CIS). As a member of the CIS Controls team, she has led multiple projects, including the CIS Community Defense Model (CDM) v2.0, the CIS Risk Assessment Method (CIS RAM) v2.1, as well as multiple Living off the Land (LotL) guides and the Blueprint for Ransomware Defense. Prior to joining the team, she led the Computer Incident Response Team (CIRT) at the Multi-State and Elections Infrastructure Information Sharing and Analysis Centers (MS-ISAC® and EI-ISAC®). While managing CIRT, Stocchetti spearheaded multiple forensic investigations and incident response engagements for the MS- and EI-ISAC’s State, Local, Tribal, and Territorial (SLTT) community. Stocchetti came to CIS from the eCommerce field, where she worked complex financial fraud cases. She holds many certifications, including GIAC Certified Forensic Examiner (GCFE), GIAC Certified Forensic Analyst (GCFA), and GIAC Security Essentials Certification (GSEC). Stocchetti earned a bachelor's degree in Digital Forensics at the University of Albany, State University of New York and a master’s degree in Information Security from Champlain College.

www.sans.org/partnerships/sltt

CybersideChat

Building a Cybersecurity Risk Tolerance Policy That Actually Works

Cybersecurity risk is inevitable. No organization can eliminate risk, regardless of its size or budget. What separates a resilient organization from a vulnerable one is not the absence of risk, but a clear, deliberate answer to a critical question:

How much risk are we willing to accept, and under what conditions?

That answer is captured in a cybersecurity risk tolerance policy.

Why It Matters

Organizations often invest heavily in security tools and controls while overlooking a foundational step: defining what level of cyber risk is acceptable to the business. Without that definition, security teams operate in a vacuum. They make judgment calls that should be leadership decisions and spend resources defending against threats that may not align with the organization's highest priorities.

A well-crafted risk tolerance policy bridges the gap between leadership and security operations. It gives leadership a mechanism to communicate strategic priorities, empowers security teams to act with confidence,

Organizations often invest heavily in security tools and controls while overlooking a foundational step: defining what level of cyber risk is acceptable to the business.

and provides auditors and regulators with a documented framework for evaluation. More importantly, it forces organizations to have honest conversations about the trade-offs between security and usability, risk reduction and cost, and ideal outcomes versus practical realities.

What Makes a Good Policy

A cybersecurity risk tolerance policy is not a technical document. It is a business document with security implications. Effective policies share several key characteristics.

• Specific without being rigid: Vague statements such as "we will minimize cybersecurity risk" provide little value. Effective policies define thresholds through acceptable downtime windows, maximum tolerable data exposure, or risk-score ceilings that trigger escalation. At the same time, they allow for context. Risk tolerance may shift based on organizational priorities, such as a major product launch, operational changes, or new regulatory requirements

• Alignment with business objectives: Risk tolerance cannot be established in isolation from organizational goals. For example, a local government entity responsible for sensitive resident data may have a much lower tolerance for confidentiality risks than a K–12 school district focused on protecting student information and maintaining instructional continuity. The policy should explicitly reflect those priorities.

• Differentiates risk types: Operational risks (such as system outages and ransomware), compliance risks (regulatory violations and audit findings), reputational risks (data breach disclosures), privacy risks, and financial risks each carry different weights. A strong

policy acknowledges these distinctions and may establish different tolerance levels for each category.

• Defines ownership and accountability: Risk tolerance decisions should not default solely to security or IT teams. The policy should clearly articulate ownership of risk-related decisions. Typically, leadership establishes overall risk appetite, business unit leaders own operational tolerances, and security teams provide the data, analysis, and recommendations needed to support informed decision-making.

• Remains a living document: Threat landscapes change. Business priorities evolve. A policy that isn't reviewed at least annually, or after a significant incident, organizational change, or regulatory development, can quickly become a liability instead of an asset.

How to Build One

Start with a risk appetite statement that is a high-level declaration of the organization's overall philosophy toward cybersecurity risk. This statement is the foundation on which the rest of the policy is built. An example might read:

"[Organization] accepts low to moderate cybersecurity risk in pursuit of its mission and business objectives, provided that controls are in place to protect residents’ data and maintain regulatory compliance."

From there, work through the following steps:

• Identify what you're protecting: Conduct or reference an asset inventory to determine which systems, data, services, and business processes are most critical to operations. These assets should inform your tolerance thresholds.

• Assess current risk levels: You can't establish meaningful tolerance levels without understanding where you currently stand. Use a risk assessment framework, such as the NIST Cybersecurity Framework (CSF), ISO 27005, or a simpler internal model to establish a baseline of your current exposure.

• Define tolerance thresholds by category: For each major risk category, define what level of risk is acceptable, what requires a management decision, and what is non-negotiable. Many organizations

use a tiered traffic light model: green (acceptable, monitor), yellow (elevated, remediate within a defined period), red (unacceptable, escalate immediately).

• Get leadership sign-off: The policy only carries weight if leadership owns it. Present the policy to leadership, frame discussions around organizational impact rather than technical detail, facilitate discussion around business priorities, and formally document leadership approval.

• Communicate and operationalize: Publish the policy in clear, accessible language. Train relevant stakeholders on its implications and their responsibilities, and integrate the policy into your risk management and incident response processes. The policy should be consulted regularly in decision-making, not shelved.

At the End of the Day

A cybersecurity risk tolerance policy won't prevent every attack, but it ensures clarity. When risks materialize, your organization can respond with purpose rather than confusion. The policy transforms cybersecurity from a purely technical discipline into a shared business responsibility. That shift is often what determines whether an incident becomes a manageable disruption or catastrophic event.

The best time to define your organization's risk tolerance was before your last incident. The second-best time is now.

Stephanie Gass is Senior Director of the Information Security program at the Center for Internet Security (CIS). She oversees security operations, external and internal audits, product risk assessment, and privacy, as well as ensuring CIS aligns to the CIS Critical Security Controls (CIS Controls), SOC 2 Type 2, ISO:IEC 27001/27701, NIST 800-171, and FISMA Moderate. She is a Co-Chair of the Artificial Intelligence Governance Board to promote advancement in AI usage at CIS. Prior to CIS, Gass was the U.S. Information Security Officer and International Traffic in Arms Regulations (ITAR) compliance lead at GlobalFoundries, a global chip manufacturer. She has a master’s degree in Cybersecurity from George Washington University.

UpcomingEvents

July

July 26 – 28

The Small and Rural Law Enforcement Executives Association (SRLEEA), in conjunction with Department of Homeland Security Leadership Academy Associates, the National Association of Professional Staff in Public Safety, and the Volunteer Law Enforcement Officers Alliance, will host the SRLEEA National Conference and Training Summit at the DoubleTree by Hilton Orlando at SeaWorld in Orlando, FL. The event will bring together law enforcement leaders and senior personnel from across the country for training sessions addressing issues facing today’s public safety professionals along with networking and collaboration with peers and industry partners. The CIS team will be onsite sharing our cybersecurity resources for law enforcement agencies. Learn more at https:// smallrural.org/national- conference/.

July 31 – August 1

The National Governors Association (NGA) will host the NGA Summer Meeting in Oklahoma City Convention Center in Oklahoma City, OK. The event will bring together that nation's governors and their staff to share solutions, coordinate on pressing challenges, and discuss opportunities facing the nation's states and territories. Learn more at https:// www.nga.org/americandream/.

August

August

10 – 13

The National Homeland Security Association will host the National Homeland Security Conference at the Kentucky International Convention Center in Louisville, KY. The event brings together professionals in homeland security, law enforcement, fire, and emergency management to learn about emerging trends in homeland security and see the new equipment and technology available to support their mission. Learn more at https:// www.nationalhomelandsecurity.org/.

August 18

The 6th Annual Detroit Official Cybersecurity Summit will take place at the Detroit Marriott at Renaissance Center in Detroit, MI. The event will bring together leaders and cybersecurity professionals to learn about the latest cyber threats from industry experts, engage with leading vendors, and network with peers. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance. swoogo.com/detroit-august-2026.

August 19

The 3rd Annual Portland Official Cybersecurity Summit will take place at the Hyatt Regency Portland in Portland, OR. The event will bring together leaders and cybersecurity professionals to learn about the latest cyber threats from industry experts, engage with leading vendors, and network with peers. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance.swoogo. com/portland-august-2026.

August 23 – 26

GMIS International will host GMIS MEETS at the Williamsburg Lodge in Williamsburg, VA. Created by and for leaders in the public sector IT industry, the event offers informative educational sessions on topics important in today's environment, interaction with industry-leading providers, and networking opportunities with industry peers. Learn more at https://www. gmis.org/page/2026homepage .

August 23 – 26

The National Association of State Technology Directors (NASTD) will host the NASTD Annual Conference at the Sheraton Denver Downtown in Denver, CO. The event will bring together senior state technology leaders to address some of the latest technologies impacting state government and offer ideas on managing the resulting changes. Learn more at https://www.eventsquid. com/event.cfm?event_id=32334

August 23 – 27

The National Real Time Crime Center Association (NRTCCA) will host the NRTCCA Annual Conference at the Phoenix Convention Center in Phoenix, AZ. The event will bring together law enforcement and community leaders to learn from industry experts, gain hands on experience with the latest technology, and engage in real conversations about where real time operations, analytics, AI, and public safety are headed next. The CIS team will be onsite sharing our solutions and resources for law enforcement and community leaders. Learn more at https://www.nrtcccaconference.info/.

September

September 2

The 7th Annual Columbus Official Cybersecurity Summit will take place at the Renaissance Columbus Downtown Hotel in Columbus, OH. The event will bring together leaders and cybersecurity professionals to learn about the latest cyber threats from industry experts, engage with leading vendors, and network with peers. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance. swoogo.com/columbus2026.

September 8 – 10

Billington CyberSecurity will host its 17th Annual Billington Cybersecurity Summit at the Walter E. Washington Convention Center in Washington, D.C. The event is a premier gathering for government cybersecurity leaders and will focus on essential collaborations, convening more than 3,000 attendees and over 300 top speakers across more than 50 sessions and breakouts, delivering critical insights into today’s most pressing cyber challenges, emerging threats, and best practices. Learn more at https://billingtoncybersummit.com/.

September 10

The 8th Edition of the San Diego Official Cybersecurity Summit will take place at the Marriott Marquis San Diego Marina in San Diego, CA. The event will bring together leaders and cybersecurity professionals to learn about the latest cyber threats from industry experts, engage with leading vendors, and network with peers. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance. swoogo.com/san-diego-2026.

September 15

The 13th Edition of the Chicago Official Cybersecurity Summit will take place at the Chicago Marriott Downtown Magnificent Mile in Chicago, IL. The event will bring together leaders and cybersecurity professionals to learn about the latest cyber threats from industry experts, engage with leading vendors, and network with peers. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance. swoogo.com/chicago2026.

September 15 – 16

Amazon Web Services (AWS) will host its AWS Imagine for Education, State, and Local Government Conference at the Hyatt Regency Chicago in Chicago, IL. With more than 20 breakout sessions featuring customer and partner stories highlighting real world solutions and transformative strategies, the event allows state and local government and education technology leaders to envision what’s possible for their organizations. Learn more at https:// hub.awsevents.com/event/a6481973620e-4a44-8153-d0aa60d6477d/.

September 15 – 16

Google Cloud Security will host its Cyber Defense Summit at the Ronald Reagan Building & International Trade Center in Washington, D.C. Crafted for elite security professionals ready to connect and lead the charge in cyber defense, the event equips defenders with the strategies, tools, and insights needed to outmaneuver increasingly sophisticated, AI-enabled adversaries, and build resilient cyber ecosystems. Learn more at https://cyberdefensesummit. mandiant.com/conf2026/home .

September 15 – 17

The Payment Card Industry Security Standards Council (PCI SSC) will host its 2026 North America Community Meeting at the Vancouver Convention Center in Vancouver, BC. The event will bring together payment security leaders from around the world to connect with peers, collaborate with industry leaders, and gain valuable insights into the latest developments shaping global payment security and the PCI Security Standards. Attendees will deepen their knowledge, exchange ideas, and stay informed on the trends, challenges, and innovations influencing the future of the payments industry. The CIS team will be onsite sharing our solutions for adhering to financial industry regulations, including from PCI SSC. Learn more at https://www.pcisscevents.org/ event/2026-vancouver/summary.

September

17

The 10th Edition of the Philadelphia Official Cybersecurity Summit will take place at the Sheraton Philadelphia Downtown in Philadelphia, PA. The event will bring together leaders and cybersecurity professionals to learn about the latest cyber threats from industry experts, engage with leading vendors, and network with peers. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance.swoogo. com/philadelphia-sept-2026.

September 20 – 24

TribalHub will host the 27th Annual TribalNet Conference & Tradeshow at the Hilton Anatole Dallas in Dallas, TX. The event is the annual gathering of the TribalHub community and provides attendees the opportunity to take advantage of a growing network of resources, experience and industry connections, ensuring that enterprise and government leaders are in possession of the tools and information that they need to thrive. Learn more at https://tribalhub.com/ events/tribalnet-conferences/2026tribalnet-conference-and-tradeshow/.

September 22

CyberHuntsville and the North Alabama Chapter of the Information Systems Security Association (ISSA) will host the 17th Annual National Cybersecurity Summit at the Von Braun Center in Huntsville, AL. The event offers unique educational, collaborative, and workforce development opportunities with diverse focus areas, premier speakers, and unmatched accessibility. Learn more at https:// www.nationalcybersummit.com/.

September

24

CISO New York will take place at the W Hoboken in Hoboken, NJ. The event will bring together CISOs and other senior cybersecurity leaders in the New York Metro area to gain critical insights, actionable strategies, and high-value connections to keep their organizations ahead in the fast-evolving world of cybersecurity. CIS VP of Security Operations and Intelligence Randy Rose will speak at the event as part of a panel discussing attack surface expansion through generative AI adoption and governance. Learn more at https:// ciso-east.coriniumintelligence.com/.

September 27 – 30

The National Association of State Chief Information Officers (NASCIO) will host the NASCIO Annual Conference at the Hilton Bayfront San Diego in San Diego, CA. The event brings together state CIOs, their staff, and supporting partners to facilitate relationship building, peer learning, and collaborative problem solving among the organization's members. With a focus on relationship building and sharing leading practices for state technology, it's one of the premier events from state government technology leaders. Learn more at https://www.nascio. org/events/conferences/

September 27 – 30

The Municipal Information System Association of California (MISAC) will host the MISAC Annual Conference at the Monterey Conference Center in Monterey, CA. The event draw together the state's government technology leaders to foster networking, share best practices, build a stronger community, and embrace new technology. Multi-State Information Sharing and Analysis Center® (MS-ISAC®) Community Engagement Manager Heather Doxon will lead a session at the event on cybersecurity resources for local government. Learn more at https://www.misac.org/ mpage/microsite-homepage-live

September 30

The 15th Edition of the Atlanta Official Cybersecurity Summit will take place at the Atlanta Hyatt Regency in Atlanta, GA. The event will bring together leaders and cybersecurity professionals to learn about the latest cyber threats from industry experts, engage with leading vendors, and network with peers. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance. swoogo.com/atlanta-fall-2026

October

October 1

The 12th Edition of the Seattle/ Bellevue Official Cybersecurity Summit will take place at the Atlanta Hyatt Regency Bellevue in Bellevue, WA. The event will bring together leaders and cybersecurity professionals to learn about the latest cyber threats from industry experts, engage with leading vendors, and network with peers. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance.swoogo. com/seattle-bellevue-oct-2026

October 8

The 12th Edition of the Boston Official Cybersecurity Summit will take place at the Westin Copley Place in Boston, MA. The event will bring together leaders and cybersecurity professionals to learn about the latest cyber threats from industry experts, engage with leading vendors, and network with peers. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance. swoogo.com/boston-fall-2026

October 11 – 15

CyberRisk Alliance will host the InfoSec World at the Gaylord Palms Resort and Convention Center in Orlando, FL. The event will bring together cybersecurity leaders and practitioners to explore the next era of cyber risk. Through expert-led sessions, hands-on learning, and meaningful peer connection, attendees gain practical frameworks, real-world perspectives, and a trusted community to help them reduce risk, strengthen resilience, and stay ahead of emerging threats. The CIS team will be onsite sharing our cybersecurity resources and best practices. Learn more and save 30% off registration with code ISW26-CIS30% at https://www.infosecworldusa.com/

October 13

The 12th Edition of the Silicon Valley Official Cybersecurity Summit will take place at the Santa Clara Marriott in Santa Clara, CA. The event will bring together leaders and cybersecurity professionals to learn about the latest cyber threats from industry experts, engage with leading vendors, and network with peers. Through our partnership, U.S. SLTT government entities can receive free admission. Contact the CIS CyberMarket team for more details. Learn more at https://cyberriskalliance. swoogo.com/silicon-valley-2026.

Interested in being a contributor?

Please contact us:

CyberMarket@cisecurity.org

www.cisecurity.org

518.266.3460

cisecurity.org

email@cisecurity.org

518-266-3460

Center for Internet Security

@CISecurity

TheCISecurity

cisecurity

CenterforIntSec

Turn static files into dynamic content formats.

Create a flipbook
Cybersecurity Quarterly Summer 2026 by Cybersecurity Quarterly - Issuu