{"id":3063,"date":"2024-04-12T08:02:31","date_gmt":"2024-04-12T13:02:31","guid":{"rendered":"https:\/\/cyberscoop.com\/?p=80121"},"modified":"2024-04-12T08:02:31","modified_gmt":"2024-04-12T13:02:31","slug":"what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/04\/12\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns\/","title":{"rendered":"What keeps CISOs up at night? Mandiant leaders share top cyber concerns"},"content":{"rendered":"<p><head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <meta name=\"robots\" content=\"index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1\"> <!-- This site is optimized with the Yoast SEO Premium plugin v21.7 (Yoast SEO v21.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ --> <title>What keeps CISOs up at night? Mandiant leaders share top cyber concerns | CyberScoop<\/title> <meta name=\"description\" content=\"Speaking during a press conference at Google Cloud\u2019s Next technology conference this week, Mandiant CEO Kevin Mandia convened Sandra Joyce, vice president of Mandiant Intelligence, and Jurgen Kutscher, vice president of Mandiant Consulting, to share their perspectives on the threat landscape and how it\u2019s evolving.&nbsp;\"> <link rel=\"canonical\" href=\"https:\/\/cyberscoop.com\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns\/\"> <meta property=\"og:locale\" content=\"en_US\"> <meta property=\"og:type\" content=\"article\"> <meta property=\"og:title\" content=\"What keeps CISOs up at night? Mandiant leaders share top cyber concerns\"> <meta property=\"og:description\" content=\"Speaking during a press conference at Google Cloud\u2019s Next technology conference this week, Mandiant CEO Kevin Mandia convened Sandra Joyce, vice president of Mandiant Intelligence, and Jurgen Kutscher, vice president of Mandiant Consulting, to share their perspectives on the threat landscape and how it\u2019s evolving.&nbsp;\"> <meta property=\"og:url\" content=\"https:\/\/cyberscoop.com\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns\/\"> <meta property=\"og:site_name\" content=\"CyberScoop\"> <meta property=\"article:published_time\" content=\"2024-04-12T13:02:31+00:00\"> <meta property=\"og:image\" content=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg\"> <meta property=\"og:image:width\" content=\"3797\"> <meta property=\"og:image:height\" content=\"2153\"> <meta property=\"og:image:type\" content=\"image\/jpeg\"> <meta name=\"author\" content=\"mbracken\"> <meta name=\"twitter:card\" content=\"summary_large_image\"> <!-- \/ Yoast SEO Premium plugin. --> <link rel=\"dns-prefetch\" href=\"\/\/securepubads.g.doubleclick.net\">\n<link rel=\"dns-prefetch\" href=\"\/\/use.typekit.net\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Feed\" href=\"https:\/\/cyberscoop.com\/feed\/\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Comments Feed\" href=\"https:\/\/cyberscoop.com\/comments\/feed\/\"> <link rel=\"stylesheet\" id=\"all-css-2\" href=\"https:\/\/cyberscoop.com\/wp-includes\/css\/dist\/block-library\/style.min.css?m=1712700738g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-6\" href=\"https:\/\/cyberscoop.com\/wp-content\/mu-plugins\/search\/elasticpress-next\/dist\/css\/related-posts-block-styles.min.css?m=1712258582g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-8\" href=\"https:\/\/cyberscoop.com\/wp-content\/themes\/scoopnewsgroup\/dist\/css\/frontend.css?m=1711866546g\" type=\"text\/css\" media=\"all\">\n<link rel=\"stylesheet\" id=\"typekit-css\" href=\"https:\/\/use.typekit.net\/itk2qbh.css?ver=74528d75ce0daeb8628a\" media=\"all\"> <link rel=\"https:\/\/api.w.org\/\" href=\"https:\/\/cyberscoop.com\/wp-json\/\"><link rel=\"alternate\" type=\"application\/json\" href=\"https:\/\/cyberscoop.com\/wp-json\/wp\/v2\/posts\/80121\"><link rel=\"EditURI\" type=\"application\/rsd+xml\" title=\"RSD\" href=\"https:\/\/cyberscoop.com\/xmlrpc.php?rsd\">\n<meta name=\"generator\" content=\"WordPress 6.5.2\">\n<link rel=\"shortlink\" href=\"https:\/\/cyberscoop.com\/?p=80121\">\n<link rel=\"alternate\" type=\"application\/json+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fwhat-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns%2F\">\n<link rel=\"alternate\" type=\"text\/xml+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fwhat-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns%2F&amp;format=xml\"> <!-- Google Tag Manager --> <!-- End Google Tag Manager --> <link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=32\" sizes=\"32x32\">\n<link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=192\" sizes=\"192x192\">\n<link rel=\"apple-touch-icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=180\">\n<meta name=\"msapplication-TileImage\" content=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=270\"> <\/head><body class=\"post-template-default single single-post postid-80121 single-format-standard\" id=\"readabilityBody\"> <a href=\"https:\/\/cyberscoop.com\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns\/#main\" class=\"skip-to-content-link visually-hidden-focusable\">Skip to main content<\/a> <\/p>\n<div class=\"ad ad--top ad--top-desktop\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p> <main id=\"main\" role=\"main\" tabindex=\"-1\"> <\/p>\n<div class=\"ad ad--top ad--top-mobile\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<section id=\"stickybar\" class=\"stickybar stickybar--newsletter js-stickybar\" readability=\"0.82\"> <button class=\"stickybar__close js-stickybar-close\" aria-controls=\"stickybar\"> <svg class=\"icon icon--close\" width=\"21\" height=\"22\" viewBox=\"0 0 21 22\" fill=\"none\"><path d=\"m.822.518-.805.805L9.695 11 .017 20.678l.805.805 9.678-9.678 9.677 9.678.806-.805L11.305 11l9.678-9.677-.806-.805-9.677 9.677L.822.518Z\" fill=\"currentColor\" \/><\/svg> <span class=\"visually-hidden\">Close<\/span> <\/button> <\/section>\n<article class=\"single-article content\">\n<div class=\"single-article__container js-single-article-content\">\n<header class=\"single-article__header \" readability=\"26.058823529412\">\n<div class=\"single-article__header-content\" readability=\"31.815261044177\">\n<p> A trio of top brass for Mandiant shared the emerging advanced tactics, techniques and procedures that they see troubling cyber professionals. <\/p>\n<\/p><\/div>\n<div class=\"single-article__cover-wrap\">\n<figure class=\"single-article__cover\"> <img data-recalc-dims=\"1\" fetchpriority=\"high\" width=\"640\" height=\"363\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns.jpg?resize=640%2C363&#038;ssl=1\" class=\"single-article__cover-image wp-post-image\" alt decoding=\"async\" fetchpriority=\"high\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg 3797w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg?resize=300,170 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg?resize=768,435 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg?resize=1024,581 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg?resize=1536,871 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg?resize=2048,1161 2048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg?resize=600,340 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg?resize=296,168 296w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg?resize=594,337 594w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg?resize=1190,675 1190w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-2.jpg?resize=1487,843 1487w\" sizes=\"(max-width: 1190px) 100vw, 1190px\"><figcaption> From left, Mandiant&#8217;s Jurgen Kutscher, Kevin Mandia and Sandra Joyce participate in a panel discussion at the Google Cloud\u2019s Next technology conference in Las Vegas on April 9, 2024. (Scoop News Group photo) <\/figcaption><\/figure>\n<\/p><\/div>\n<\/header>\n<div class=\"single-article__content\">\n<div class=\"single-article__content-inner has-drop-cap\"> <html readability=\"113.5269121813\"><body readability=\"229\"><\/p>\n<p><strong>LAS VEGAS \u2014 <\/strong>An increasing volume of zero days \u2014 97 total in the last year. The evolution of cyber extortion to now include physical threats and advanced coercion. More and more threat actors \u201cliving off the land.\u201d<\/p>\n<p>These are but a few of the top concerns that keep chief information security officers up at night, according to the top leaders of cybersecurity firm Mandiant, now a subsidiary of Google Cloud.<\/p>\n<p>Speaking during a press conference at Google Cloud\u2019s Next technology conference this week, Mandiant CEO Kevin Mandia convened Sandra Joyce, vice president of Mandiant Intelligence, and Jurgen Kutscher, vice president of Mandiant Consulting, to share their perspectives on the threat landscape and how it\u2019s evolving.&nbsp;<\/p>\n<p>\u201cThere\u2019s more of everything bad,\u201d Mandia said of the cyber threat landscape, though he reasoned, \u201cthat doesn\u2019t mean we\u2019re at the trough of cybersecurity over the last couple of years.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cWe\u2019re bringing far more awareness to the problems\u201d and the cybersecurity industry has made \u201ca lot of improvements,\u201d he said.&nbsp;<\/p>\n<p>That said, there\u2019s \u201cmore malware, more threat actors, they\u2019re better at what they do and they\u2019re more impactful when they\u2019re successful,\u201d Mandia explained.<\/p>\n<p>CyberScoop compiled a list of the top concerns the Mandiant executives see CISOs experiencing today.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-more-zero-days\">More zero days<\/h2>\n<p>According to Kutscher, zero days are increasing in number and sophistication, and that\u2019s a big problem for security professionals who want a good night\u2019s sleep.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cI think when we look back at the last couple of years, quite honestly, right, there have been a lot of interesting trends in the cybersecurity space that CISOs have been struggling with. One of them, of course, is the number of zero days that we\u2019ve seen in the last couple of years,\u201d he said. \u201cAnd that has given the attackers a new way of maintaining persistence.\u201d<\/p>\n<p>In particular, hackers are targeting security appliances and network perimeter devices to gain long-term access, Kutscher said, adding that traditional security technologies aren\u2019t advanced enough to detect an intrusion on those devices.<\/p>\n<p>\u201cIt makes detection very, very difficult,\u201d he said.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-artificial-intelligence-favors-defense\">Artificial intelligence favors defense<\/h2>\n<p>While all the buzz in the tech industry is around the great potential and major risks of emerging artificial intelligence capabilities, Joyce said of the more than 1,000 incidents Mandiant responds to in a year, \u201cnot a single one of them yet has AI as a major or essential component of it.\u201d<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cSo we\u2019re still in sort of an experimental phase when it comes to what threat actors are doing with AI,\u201d she said. \u201cAnd that creates an opportunity for \u2026 defenders to really lean into this.\u201d<\/p>\n<p>Because threat actors really haven\u2019t taken a position of advantage in the AI space, Joyce said \u201cthe opportunity is now.\u201d<\/p>\n<p>Both she and Kutscher believe that head-to-head, AI currently favors the ability to defend against attacks.<\/p>\n<p>\u201cVery clearly, it\u2019s giving us the upper hand,\u201d Kutscher said. \u201cI can\u2019t predict the future of when attackers are going to start focusing on leveraging more AI \u2014 obviously, that remains to be seen. But as Sandra said, right now we have the advantage. It\u2019s a benefit.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-living-off-the-land\">Living off the land<\/h2>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>Mandia said bad actors have gotten very good at imitating credentialed users. \u201cThere\u2019s better OPSEC by the attackers,\u201d he said.&nbsp;<\/p>\n<p>So-called \u201cliving off the land\u201d techniques make it so that \u201cyou can\u2019t distinguish between an attacker very easily and a threat actor. And that\u2019s a problem because it means you don\u2019t detect the attacks and they\u2019re much more surreptitious,\u201d he said.<\/p>\n<p>\u201cIt\u2019s one of the biggest changes that I think I\u2019ve seen between 2023 and now,\u201d Mandia said, and it\u2019s led to breaches having far worse impact on victims because an attacker goes undetected for longer periods of time.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-cyber-threats-go-beyond-cyber\">Cyber threats go beyond cyber<\/h2>\n<p>Joyce pointed to the rising levels of extortion that Mandiant has seen in recent years as one of the biggest concerns in the space.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cThe aggressiveness by which cyber criminals are operating, particularly groups that we\u2019ve been tracking recently, are making a CISO\u2019s job really, in some cases, a nightmare that they have to live through because they don\u2019t just have to think about stolen data \u2014 they have to think about the well-being of the people that work for them as well,\u201d Joyce said.<\/p>\n<p>Years ago, cyberattacks were more \u201csmash and grab,\u201d she said, where \u201ccyber criminals were asking for, you know, a small amount of cryptocurrency and then they give me back access to your photos of your grandparents.\u201d<\/p>\n<p>But in recent years, in the event of ransomware, \u201cwhat CISOs are looking at now is not just the theft of data, not just the destruction of their operations, but it could be threats to their person, it could be threats to family members, very brutal coercion,\u201d Joyce said.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-outdated-multifactor-authentication\">Outdated multifactor authentication<\/h2>\n<p>As cybercriminals become more sophisticated, they\u2019re also increasingly targeting cloud infrastructure, Kutscher said. And that\u2019s exacerbated when organizations rely on dated multifactor authentication tools.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cWe\u2019re seeing a lot more focus on cloud infrastructure, which is not surprising given that a lot of organizations are in the cloud, right? We\u2019re definitely seeing a lot more focus from attackers on that,\u201d he said. \u201cWe\u2019re also seeing them bypass multifactor authentication much more effectively, especially the more dated multifactor authentication technologies, for example, like sending SMS messages with a six-digit code, etc. We\u2019ve seen attackers getting really, really good at bypassing those types of controls.\u201d<\/p>\n<p>Kutscher explained that \u201ca lot of organizations still have a lot of these dated multifactor authentication technologies in use, and now we\u2019re looking at, what do we need to do to mitigate the risks around that? Because we are seeing attackers being very effective at bypassing those to access cloud infrastructure, but also just simply gain access to any sort of environment.\u201d&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-burnout\">Burnout<\/h2>\n<p>One of Joyce\u2019s big takeaways from a recent trip to Ukraine was the level of burnout experienced by the nation\u2019s cyber defenders, which can extend to its general population as well. She said it\u2019s a direct result of the increased sophistication of attacks and the growing volume of zero days, which make it something that the average CISO has to deal with as well.<\/p>\n<p>\u201cSo if you think about zero-day usage, it\u2019s not just that the zero days are used,\u201d Joyce said. \u201cThink about the workflows that have to happen to ensure that that is patched, to determine how critical it is for that specific organization. That\u2019s a spin-up of activity. And when we\u2019re at something like the last year, over 90 zero days that were used.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cNew techniques mean that defenders have to be on the ball,\u201d she said. \u201cNow take the stakes way up and make that something where you\u2019re defending in a conflict. So let\u2019s say you\u2019re in Ukraine \u2014 that just becomes even more of a burden in that space.\u201d<\/p>\n<p>In Ukraine, Joyce witnessed Russia using advanced cyber techniques concurrently with a missile strike on a power plant, a tactic that she said \u201cterrified\u201d Ukrainian citizens \u201cbecause the lights are now off, it gives them the sense that their government can\u2019t protect them.\u201d<\/p>\n<p>\u201cBut it\u2019s all sort of intertwined with these advanced techniques that we\u2019re talking about. So whether you\u2019re a CISO thinking about this or whether you\u2019re a Ukrainian defender or the Ukrainian population, these techniques have very far-reaching consequences,\u201d Joyce said.&nbsp;<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-supply-chain\">Supply chain&nbsp;<\/h2>\n<p>Supply chain attacks are nothing new, but their sophistication is growing, with some threat actors now moving through multiple levels of a supply chain before taking action against a victim.&nbsp;<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>\u201cTrying to trace that back, trying to understand where the attackers came from is extremely difficult,\u201d Kutscher said. It\u2019s one thing to spot them in your environment, he said, \u201cbut how would you eliminate them from your environment understanding where they actually came from and how they got there? It\u2019s extremely difficult.\u201d&nbsp;<\/p>\n<p>Mandia said the growing volume of zero days and the change in targets \u2014 traditionally hackers would attack major technology firms like Apple, Google and Microsoft \u2014 to smaller software service providers is a reflection of cybercriminals looking to take advantage of weak supply chains.&nbsp;<\/p>\n<p>\u201cIt\u2019s more of the enterprise software companies and other software companies that are providing a service to somebody else. So you\u2019re seeing kind of a tilting of the scales,\u201d he said. \u201cSupply chain is a big problem \u2014 CISOs are worried about it. Because all of the small companies that are making the innovative software today, a lot of these startups don\u2019t have security staff. \u2026 So it creates sort of a backdoor insecurity to some extent.\u201d<\/p>\n<p><\/body> <\/p>\n<footer class=\"single-article__footer\" readability=\"6.2575757575758\">\n<div class=\"author-card\" readability=\"19\">\n<div class=\"author-card__avatar\">\n<figure class=\"author-card__image-wrap\"> <img data-recalc-dims=\"1\" decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns-1.jpg?w=640&#038;ssl=1\" alt=\"Billy Mitchell\"> <\/figure>\n<\/p><\/div>\n<p><h4 class=\"author-card__name\">Written by Billy Mitchell<\/h4>\n<p> Billy Mitchell is Senior Vice President and Executive Editor of Scoop News Group&#8217;s editorial brands. He oversees operations, strategy and growth of SNG&#8217;s award-winning tech publications, FedScoop, StateScoop, CyberScoop, EdScoop and DefenseScoop. Prior to joining Scoop News Group in early 2014, Billy embedded himself in Washington, DC&#8217;s tech startup scene for a year as a tech reporter at InTheCapital, now known as DC Inno. After earning his degree at Virginia Tech and winning the school&#8217;s Excellence in Print Journalism award, Billy received his master&#8217;s degree from New York University in magazine writing while interning at publications like Rolling Stone. <\/p>\n<\/p><\/div>\n<div class=\"single-article__tags-container\">\n<h4 class=\"single-article__tags-title\">In This Story<\/h4>\n<\/p><\/div>\n<\/footer>\n<p> <\/html><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"single-article__ads js-single-article-sidebar\">\n<div class=\"ad ad--sidebar js-single-article-sidebar-5 ad--rightrail_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-4 ad--rightrail_2 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-3 ad--rightrail_3 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div><\/div>\n<\/article>\n<div class=\"popular-stories popular-stories--single-post\">\n<div class=\"popular-stories__container\">\n<h2 class=\"popular-stories__title\"> More Scoops <\/h2>\n<p> <!-- .popular-stories__stories --> <\/div>\n<p><!-- .popular-stories__inner -->\n<\/div>\n<p><!-- .popular-stories --> <\/p>\n<section class=\"latest-podcasts\">\n<h2 class=\"latest-podcasts__title\"> Latest Podcasts\t<\/h2>\n<\/section>\n<div class=\"top-categories\">\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Government<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Technology<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Geopolitics<\/h3>\n<\/p><\/div>\n<\/p><\/div>\n<p> <\/main> <\/p>\n<div class=\"ad ad--bottom \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div id=\"interstitial\" class=\"welcome__container\"> <button id=\"close-modal-1\" class=\"welcome__clickable_area\"><\/button> <\/p>\n<div class=\"welcome__ad_wrapper\">\n<p> <button id=\"close-modal-3\" class=\"welcome__continue-button\">Continue to CyberScoop<\/button> <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p> <!-- Start of HubSpot Embed Code --> <!-- End of HubSpot Embed Code --> <\/body> <a href=\"https:\/\/cyberscoop.com\/what-keeps-cisos-up-at-night-mandiant-leaders-share-top-cyber-concerns\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What keeps CISOs up at night? Mandiant leaders share top<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[235,384,78,1865,646,1866,1170],"tags":[236,388,86,1867,650,1868,1171],"class_list":["post-3063","post","type-post","status-publish","format-standard","hentry","category-ai","category-artificial-intelligence-ai","category-cybersecurity","category-living-off-the-land","category-mandiant","category-supply-chain-attacks","category-zero-days","tag-ai","tag-artificial-intelligence-ai","tag-cybersecurity","tag-living-off-the-land","tag-mandiant","tag-supply-chain-attacks","tag-zero-days"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Cyber Scoop","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/cyberscoop\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/ai\/\" rel=\"category tag\">AI<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/artificial-intelligence-ai\/\" rel=\"category tag\">artificial intelligence (AI)<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/living-off-the-land\/\" rel=\"category tag\">living off the land<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/mandiant\/\" rel=\"category tag\">Mandiant<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/supply-chain-attacks\/\" rel=\"category tag\">supply chain attacks<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/zero-days\/\" rel=\"category tag\">zero-days<\/a>","tag_info":"zero-days","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3063","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3063"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3063\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}