ZeroHour

Search: “spending”

6 stories in the last 24h

Security spending is growing — except for the typical CISO

IANS/Artico survey of 500+ CISOs finds median security budget growth of 0% despite a 5% average, with AI the top spending priority.

The IANS and Artico Search 2026 Security Budget report, based on responses from over 500 security executives between April and August 2026, found average security budget growth of 5% but median growth of 0%. 64% of CISOs requested increases, yet only 45% received one. AI was the top net-new priority for 69% of CISOs, though only 24% track AI as a separate security budget line, with 38% embedding it in the security budget and 38% funding it through IT, data, or innovation. A major breach was cited by just 3% of CISOs whose budgets grew.

CSO Online · 22h agoIndustry

12 Best Multi-Cloud Security Platforms Compared (2026): Features & Pricing

A buyer's guide compares pricing and features of 12 multi-cloud security platforms including Wiz, Prisma Cloud, FortiCNAPP, and Defender for Cloud.

The GBHackers roundup profiles 12 multi-cloud security platforms, including Wiz, Fortinet FortiCNAPP, Palo Alto Prisma Cloud, Sysdig, Microsoft Defender for Cloud, Uptycs, and Check Point CloudGuard. It focuses on cross-cloud billing parity, connector fees, ELA absorption, and negotiation tactics for procurement teams. The article notes Ermetic has consolidated into Tenable Cloud Security and that Google's acquisition of Wiz is finalized.

GBHackers · 5h agoTools 10 sources

98% of fraudulent hires have company credentials by the time they’re caught

HYPR report finds 98% of fraudulent hires already hold company credentials when detected, exposing an unowned identity-risk gap between hiring and onboarding.

HYPR's State of HR Identity Fraud Detection report says 98% of HR leaders have experienced candidate fraud and that fraudulent hires typically receive corporate credentials and network access before being identified. Third-party security tools detect only 53% of identity-based and AI-driven attacks, and ownership of pre-hire identity risk is undefined during the hiring-to-onboarding transition. Most companies need one to three weeks to resolve a hiring fraud incident, and roughly 60% of identity verification and MFA spending is triggered by a breach rather than proactive investment.

Everybody's Lost Their Minds

A veteran security engineer argues AI-driven vulnerability discovery is not making organizations safer because patching and basic security hygiene remain the real bottleneck.

The author, a long-time security practitioner, criticizes the industry's rush into AI-assisted vulnerability research, noting that Anthropic and OpenAI programs like Glasswing, Daybreak, Athena, and Akrites consumed millions of dollars of engineering time and surfaced thousands of vulnerabilities, only a fraction of which were reported upstream. He argues that finding vulnerabilities was never the bottleneck; patching, asset inventory, and attack surface management remain the true problems. The post also critiques AI hype, agentic workflows, anthropomorphic media coverage, and AI companies' calls for their own regulation.

Strong fundamentals make next-gen security possible

A former CISO for Hyatt and United Airlines argues foundational controls—asset inventory, identity, resilience—outperform repeatedly buying new security tools.

The author, a former security leader at Hyatt and United Airlines, argues that mastering foundational controls delivers more impact than cycling through expensive new tools. The piece highlights asset discovery with a single source of truth, identity hardening via MFA and passkeys, and risk-based prioritization using frameworks like CIS CSC. It also stresses resilience and recovery planning, including secure backups and regularly practiced incident processes.

CSO Online · 5h agoIndustry

How Pentest Companies Adapt In The Era of AI

Opinion piece urges pentest firms to adopt self-hosted AI like Qwen3-Coder via Ollama, warning client findings pasted into cloud models breach confidentiality.

The article argues penetration testers are already using AI tools, and pasting client findings, scope documents, or credentials into cloud models like ChatGPT or Claude risks NDA breaches and GDPR/HIPAA compliance violations. It recommends self-hosted models on firm-controlled infrastructure instead of banning AI. The piece promotes PentestPad, a pentest reporting platform offering managed, self-hosted, and air-gapped deployment, an MCP server exposing fourteen typed tools, and a writing assistant that can target a local LLM. PentestPad's own team reportedly runs Qwen3-Coder through Ollama with OpenCode or Claude Code as the agent harness.

GBHackers · 9h agoIndustry