Standing up an innovation team

Archive for August, 2026

Standing up an innovation team

Posted by

Expect security execs’ remits to include greater risk responsibilities and opportunities to elevate the business as organizations look to accelerate innovation in an increasingly challenging cyber world.

Excerpt from: What the CISO role will look like in 2029

Like many long-term security execs, Goerlich has seen plenty of changes within the profession. He’s bracing for more.

“For the future I see growing the role of CISO to be the pacesetter for innovation, to be in the board room and executive conversations advising them on how to take smart, calculated risks with technology, including AI,” says Goerlich, who is now a public sector CISO and a faculty member with IANS Research.

Goerlich sees this as the next step for a role that has continuously evolved since its inception in 1995.

“It’s gone from the ‘department of no’ to ‘let’s slow down’ to ‘let’s take smarter risks based on our understanding of them,’” he adds. “How exciting is this? To be the one to say, ‘You want to take more risk? Let us help you. We can help you make smarter decisions.’”

Goerlich isn’t the only one with such observations. Others similarly believe that the responsibilities assigned to the typical CISO will change in the upcoming years.

Despite a broad consensus on change, predictions vary on how that change will play out in terms of the CISO’s roles and responsibilities. Mirroring the traditional three-year look for strategic planning at many organizations, security leaders see a range of possibilities for the CISO position evolving by 2029. Regardless, all agree that the CISOs of tomorrow will have to work at a faster pace, contend with more threats, and bear more strategic responsibility than they do today.

Research confirms this outlook.

Goerlich is experiencing that shift already, having been tasked with standing up an innovation team that includes architecture and engineering professionals as well as security practitioners.

CEOs and boards increasingly recognize that having security in those leadership roles accelerates — rather than slows — innovation because “security knows how to help them take risks,” he says.

Read the full article: https://www.csoonline.com/article/4208210/what-the-ciso-role-will-look-like-in-2029.html

Wolf’s Additional Thoughts

I’m excited about my new innovations lab. As I shared with CSO, the CISO can be the pace car or the pit stop of innovation. The pace car is more fun. If you’re doing something similar, reach out, let’s compare notes.


This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.

Synced passkey security issues could allow account takeover

Posted by

The attacks can misuse trusted workflows to take over passkey-protected accounts, but the attacker must have first breached defenses and planted malware; analysts say the issue is flaws in supporting processes.

Excerpt from: Passkey security issues could allow account takeover

Some have argued that the lack of sufficiently robust support processes actually weakens passkey capabilities and undermines the whole point of such systems.

J. Wolfgang Goerlich, a member of the faculty of IANS and a longtime cybersecurity consultant, pointed out that the original FIDO2 spec eliminated credential theft by binding the private key to a physical authenticator. Synced passkeys reintroduced credential portability and therefore reintroduced the form of credential theft risk cited in the Palo Alto report.

“A passwordless system is exactly as strong as the flow that re-establishes it,” he said. “Both serious techniques here start by forcing a device to re-enroll. Many security teams have never modeled, never monitored and never rehearsed a response to this.”

Goerlich’s advice to CISOs is to require device-bound authenticators, such as hardware tokens or computers, for all privileged and sensitive access. They may consider allowing wallets for lower risk access, he said, “however, much like passwords in Web browsers have long been at risk, we must now consider passkeys in the browsers an unacceptable risk.”

Read the full article: https://www.computerworld.com/article/4205809/enterprise-passkey-security-under-threat-from-malware.html

Wolf’s Additional Thoughts

In 2021-2023, in presentations such as Street Cred and Mistaken Identity, I warned of this exact type of attack. Credential theft and re-use is only possible when the authenticator can be copied, cloned, and replayed. That’s exactly what synced passkeys allow. It’s frustrating but entirely unsurprising to see this happen. If you must shared passkeys, use enterprise credential managers like 1Password and others.


This post is an excerpt from a press article. To see other media mentions and press coverage, click to view the Media page or the News category. Do you want to interview Wolf for a similar article? Contact Wolf through his media request form.