Connect with us

Tech News

Boston Consulting Group Unveils Report on Global Cybersecurity Talent Shortage at Global Cybersecurity Forum 2024

Published

on

BCG

Boston Consulting Group (BCG), in collaboration with Global Cybersecurity Forum (GCF), unveiled its “2024 Global Cybersecurity Workforce Report” at the GCF Annual Meeting 2024. Titled “The Global Cybersecurity Workforce Shortage and Skills Gap: A Threat We Cannot Ignore,” the report highlights a significant global shortfall in cybersecurity professionals despite considerable infrastructure and talent development investments. The GCF Annual Meeting 2024, themed “Advancing Collective Action in Cyberspace,” focuses on enhancing multi-stakeholder collaboration to address key cybersecurity challenges.

Cybersecurity Workforce Crisis

The report highlights that only 72% of cybersecurity roles are currently filled, leaving organizations vulnerable to rising cyber threats. The global cybersecurity workforce stands at 7.1 million professionals, with Asia-Pacific holding the largest share, while Africa faces severe underrepresentation with fewer than 300,000 professionals.

Amidst this workforce shortage, Generative AI (GenAI) is transforming the cybersecurity landscape, with 70% of organizations already incorporating AI into their cybersecurity frameworks. This shift presents both opportunities and challenges. While AI can help address some workforce gaps, it also introduces new complexities. 58% of cybersecurity leaders express concern about AI-enabled adversarial techniques, such as more sophisticated phishing attacks or automated vulnerability exploitation, which could outpace traditional defenses. To address these evolving challenges, 60% of organizations are focused on continuous training and upskilling, aiming to equip their limited workforce with the skills needed to leverage AI effectively while defending against AI-enhanced threats.

Shoaib Yousuf, Managing Director and Partner at BCG emphasized the GCC’s advancements in the face of an increasingly complex cyber threat landscape: “The region’s cybersecurity capabilities have evolved significantly, driven by government initiatives like Saudi Arabia’s Cybersecurity Workforce Framework (SCyWF), embedding a strategic focus on capacity building through the recently announced UAE and Qatar national cybersecurity strategies. These initiatives highlight a steadfast commitment to protecting critical infrastructure and safeguarding sensitive data. Through targeted investments, international collaborations, and a proactive planning, the GCC is advancing its cybersecurity landscape and contributing to the evolving standards for a secure global cyberspace. By refining its cybersecurity frameworks and addressing emerging threats head-on, the region is solidifying its position as a global leader in cybersecurity, paving the way for a secure, future-ready digital ecosystem.”

Call to Action: A Roadmap to Success

The report emphasizes the urgent need to attract new talent, especially among underrepresented groups such as women, who comprise just 24% of the cybersecurity workforce globally. To address these challenges and build a future-ready workforce, the report outlines key strategic recommendations:

  • Targeted and strategic outreach to underrepresented groups
  • Embedding cybersecurity into organizational DNA
  • National & academic campaigns for cybersecurity careers
  • Building an inclusive, diverse, and supportive culture
  • Clear career progression and development
  • Adopting skills-based hiring practices
  • Expanding the talent pool with inclusive practices
  • Fostering a culture of lifelong learning
  • Integrating cybersecurity education from the ground up
  • Evolving curriculum to meet industry needs

Vanessa Lyon, Managing Director and Senior Partner at BCG emphasized the importance of collaboration: “To shape the cybersecurity workforce of tomorrow, leaders must collaborate to integrate cybersecurity into education, continuously upskill talent, and create opportunities for underrepresented groups. Building a future-ready workforce means fostering a culture of continuous learning, ensuring we have the skilled defenders to support global security and economic stability in the face of rapidly evolving technologies.”

The “2024 Global Cybersecurity Workforce Report” presented at the GCF Annual Meeting 2024 aligns with the Meeting’s theme of “Advancing Collective Action in Cyberspace.” This collaboration contributes crucial insights into the human capital required to navigate the evolving cybersecurity landscape. The report’s findings and recommendations provide a foundation for addressing key challenges in the cybersecurity domain, from talent shortages to integrating emerging technologies.

Tech News

Cloudera and Mistral Partner to Bring Specialized, Sovereign Intelligence to Enterprise Data

Published

on

Cloudera, the only company bringing AI to data anywhere, and Mistral, a global frontier AI lab, today announced a landmark strategic partnership to bring secure, sovereign AI directly to enterprise data wherever it resides.

Cloudera and Mistral will combine Cloudera’s hybrid data and AI platform with Mistral’s sovereign AI models to give enterprises a secure path to build, customize, and run AI using their own private data. The collaboration will enable organizations to bring intelligence directly to their data across cloud, on-premises, edge, sovereign, and air-gapped environments—without requiring sensitive information to leave their control.

For enterprises managing the world’s largest and most sensitive data estates, this approach provides greater control, choice, and flexibility over how and where AI runs. Organizations can run inference privately, customize AI using proprietary data, and deploy AI applications within their existing security and governance boundaries, while gaining greater control over the economics of AI at scale.

“Enterprise AI is entering a new phase where organizations need more than access to powerful models, they need the freedom to unlock specialized intelligence using their data, on their terms,” said Abhas Ricky, Chief Business Officer & GM, Applied AI at Cloudera. “Together with Mistral, we are giving enterprises the ability to run AI where their data lives, customize it with their own intellectual property,  and maintain control over their data, infrastructure, and economics. That combination of intelligence and control is essential to moving AI from experimentation into production.”

Bringing Intelligence to the Data

For enterprises operating in highly regulated and data-intensive industries, moving sensitive or proprietary information to external AI services can introduce regulatory, security, and operational challenges.

Cloudera and Mistral are addressing these challenges by bringing secure, sovereign AI directly to the enterprise data perimeter.

Mistral’s suite of frontier models and tools will be integrated with Cloudera’s hybrid data and AI platform, enabling customers to run their own custom AI models and applications across 30 exabytes of data. Enterprises will have the deployment flexibility across public, private, on-premises, and fully air-gapped environments, while maintaining consistent governance and control over their context.

The partnership will span Mistral’s broad portfolio of frontier AI models and tools, including reasoning, chat, coding, document intelligence, and voice, giving Cloudera customers greater choice in how they apply AI to their enterprise data.

By enabling organizations to run inference within their own environments, the collaboration also gives customers greater flexibility over the economics of AI. Enterprises can choose the deployment model and infrastructure that best fit their workloads rather than depending exclusively on public API consumption models as AI usage scales.

From Private Inference to Proprietary Intelligence

Through the integration of Mistral Forge, a system for enterprises to build frontier-grade AI models grounded in their proprietary knowledge, organizations utilizing Cloudera’s platform will be able to customize and train models against large volumes of private enterprise data within controlled environments. For enterprises with petabytes of proprietary information, this creates an opportunity to transform decades of institutional data and domain expertise into differentiated AI while maintaining ownership and sovereignty over both the data and resulting intelligence.

Developers and practitioners will also be able to securely build AI-powered experiences using private enterprise data within local environments—from conversational access to governed data to AI-assisted software development and agentic workflows—without exposing sensitive business context or intellectual property to external environments.

Cloudera and Mistral also intend to collaborate on the next generation of AI at the edge, bringing increasingly capable inference closer to where enterprise data is created. This will enable organizations to explore intelligent applications across disconnected, latency-sensitive and resource-constrained environments where relying on centralized cloud infrastructure is not practical.

“Our mission is to make frontier AI available to enterprises without requiring them to give up control over their data, infrastructure, or intellectual property,” said Kamal Brar,  SVP of Partnerships and Alliances at Mistral. “Cloudera manages some of the world’s most valuable enterprise data estates, making this partnership a powerful opportunity to bring our technology directly to where that data lives. Together, we can give customers the ability to build AI that reflects their own data and expertise and deploy it securely wherever their business requires.”

Expanding Choice for Enterprise AI

The partnership also expands the Cloudera Enterprise AI Ecosystem, through which Cloudera works with leading AI models, infrastructure, application, and technology providers to give customers flexibility in how they build and deploy enterprise AI.

Mistral adds a significant new dimension to that ecosystem by enabling customers to access and customize its models and AI capabilities directly alongside their governed enterprise data. The partnership reinforces both Cloudera’s and Mistral’s commitment to an open approach to enterprise AI, giving customers choice across models, infrastructure, and deployment environments rather than locking their data or AI strategy into a single technology stack.

The joint Cloudera and Mistral solutions will be available through Cloudera’s enterprise sales team and partner ecosystem, with additional integrations and capabilities rolling out over time.

Continue Reading

Spotlight

New Cequence & EMA Research: 94% of Enterprises Trust Their AI Agents Aren’t Over-Provisioned. Only 33% Actually Enforce It.

Published

on


Nearly every enterprise believes its AI agents are properly scoped. Only a third have actually made sure of it.

Today, new research from Cequence Security, the leader in application, API, and agentic AI protection, and Enterprise Management Associates (EMA) found that 94% of enterprise IT and security leaders are confident their AI agents do not have more access than they need, yet only 33% actually provision agents with least-privilege access. The remaining two-thirds run on broad standing permissions that are reviewed periodically, rarely reviewed, or never reviewed at all.

That gap between confidence and practice is already showing up in production, not a theoretical risk, but as incidents enterprises are living with right now. Among the organizations surveyed:

  • 65% have experienced an AI agent take an action outside its intended scope, including 29% with measurable business impact, including data exposure, financial loss, operational disruption, or reputational damage. Another 36% caught a near-miss before it caused damage.
  • Only 32% can detect and contain an out-of-scope agent action within minutes through automated means; 55% need hours and manual steps to respond.
  • In approximately 4% of organizations surveyed, the first sign of trouble came from a customer or outside partner, not an internal system.

The findings point to one clear story. Governance has not kept pace with the speed of agentic AI deployment, and that gap is showing up at every stage of the agent lifecycle, from how agents are provisioned, to how their actions are authorized, to how they are decommissioned once a pilot ends. Other key findings from the report include:

Enterprises Have Moved Past the Pilot Stage

The scale of deployment makes the gap more urgent. 46% of organizations report they are already scaling agentic AI across multiple departments and production workflows, and 79% are running generative and agentic AI simultaneously. Further, more than 92% report an increase in AI and bot-driven traffic targeting customer-facing applications and APIs.

Authorization is Checked at the Wrong Time, Or Not At All

That governance gap extends to how access is enforced in the moment an agent acts. Only 34% of organizations evaluate an AI agent’s authorization at the moment it attempts a specific action. The majority rely on periodic policy reviews or standing permissions set once at provisioning and never revisited, meaning an agent’s access can quietly outlive the task it was originally granted for, and keep working long after anyone signed off on it.

Abandoned Pilots Are Leaving Live Credentials Behind

Additionally, there’s an increasing risk in how enterprises manage agents that don’t make it to production. 31% of agentic AI pilots have been paused indefinitely, discontinued, or abandoned. Many were real deployments with real system access and credentials that were never cleaned up. Every abandoned pilot with live credentials is exposure nobody is actively watching.

External Connectivity Carries the Same Risk

14% of organizations allow AI agents to connect to outside tools and data sources via the Model Context Protocol (MCP) without restriction. Among the majority who do limit those connections to an approved list, fewer than half, just 49%, have a dedicated team actively maintaining and auditing that list on a regular basis.

Christopher M. Steffen, CISSP, CISA, VP of Research at EMA, said: “This research shows enterprises have moved well past experimentation with agentic AI right into production, and governance has not kept pace with that shift. The gap isn’t a lack of awareness; most organizations have policies in place and express real confidence in them. The gap is between what’s written down and what’s enforced when an agent takes an action nobody approved. That disconnect shows up most clearly in how organizations authorize agent actions and monitor them once they’re live, and it’s the reason incidents are happening at a rate the industry hasn’t fully reckoned with.”

Shreyans Mehta, Co-founder and CTO at Cequence, said: “The number that jumped out to me is the 92% being confident in their governance frameworks. Confidence like that is a trap; it’s exactly why organizations stop looking for problems, stop investing in monitoring, and let authorization checks lapse until an incident forces the conversation. This is the exact blind spot Cequence is built to close, giving security teams real-time visibility into what AI agents are actually doing and enforcing authorization at the moment an agent acts, not after the fact.”

Continue Reading

Tech News

Anomali to Address the Next Phase of AI-Led Cyber Defense at GISEC 2026

Published

on

Anomali, the leading global Managed Intelligence and Agentic SOC platform, announced its participation at GISEC Global 2026, taking place through 16-18 September at Dubai Exhibition Centre (DEC), Expo City.

The company’s discussions at GISEC will center on Autonomous SOC with Governed AI, Agentic AI, Actionable Threat Intelligence and Unified Security Data Lake capabilities that are changing the manner in which security teams investigate threats, manage workflows and make decisions.

Samer Jadallah, Vice President, Middle East & Africa at Anomali, will represent the company at GISEC and will focus on the growing impact of AI on both attackers and defenders, emerging shifts in the threat landscape, including the need to counter CEO impersonation attacks as well as key challenges facing modern security teams. He will also highlight AI’s role is helping organizations respond more effectively to evolving threats, Anomali’s commitment to the region and ongoing product innovation and plans to expand adoption of the Anomali platform across global enterprises and government organizations.

A key focus at this year’s event will be the changing nature of cyberattacks. As threat actors promptly adopt AI to scale campaigns and further accelerate attacks, security operations centers (SOC) are under growing pressure to process rising volumes of alerts with limited resources. To help with this, Anomali will demonstrate how AI can support analysts in multiple ways like surfacing higher- value insights, reducing manual effort and enabling quicker, informed responses.

Visitors can find Anomali at Booth E156 and Booth A80.

  • Event: GISEC Global 2026
  • Booths: E156 and A80
  • Location: Dubai Exhibition Centre (DEC), Expo City
  • Dates: 16 th to 18 September 2026
  • Time: 9:00 am to 5:00 pm GST
Continue Reading

Trending

Copyright © 2023 | The Integrator