| There’s just one problem: there aren’t that many. |
 Presented By |  |
It’s Friday. If you’re worried about your AI spending, it could pay (literally) to set up, A, procurement triggers, and B, dashboards for better visibility into AI consumption. Otherwise you might become a cautionary tale. In today’s edition: ✅ CISO wish list 📽️ IT Brew movie club: The Net 🌐 Don’t drop it! —Brianna Monsanto, Billy Hurley, Caroline Nihill |
|
IT STRATEGY More C-AI-SOs  Getty Images | What do companies want? CISOs skilled in agentic AI. When do they want it? Now. Although actually finding one is proving difficult for many. According to research from executive recruitment firm Christian & Timbers, the demand for AI-native CISOs and CSOs jumped 256% in the first seven months of the year compared to the same period last year. The findings are based on roughly 100 conversations between Christian & Timber partners and C-suite executives between January and July. Where’s the supply? While more companies want CISOs with agentic expertise, supply has yet to match that demand, according to Christian & Timbers President JC Christian. “For basically any AI-native role, supply is very scarce,” Christian said. “The very best is able to command a premium as a result.” CISO supply issue.—BM |
|
|
Sponsored By SentinelOne You can’t secure what you can’t see  | Teams are adopting AI faster than they can secure it. Shadow AI, leaky prompts, and exposed infrastructure are the new blind spots. SentinelOne’s Securing AI Bootcamp was created to help support the security pros tackling the security gap. Join the free virtual event on Sept. 29–30 for sessions covering everything from employee AI usage and shadow AI to cloud + AI infrastructure security and threat intelligence. Plus, you can earn free CPE credits for every session you attend. Want a sneak peek at the speaker lineup? Day 1 includes four keynotes on the AI threat landscape, emerging security frameworks, + more. Day 2 is full of live global workshops about applying security frameworks and guardrail techniques in practice. Save your spot. |
|
|
CYBERSECURITY ‘Net’ worth  Illustration: Morning Brew Inc, Photos: Sony Pictures Releasing | If you were a systems analyst in 1995, you brought two towels to the beach: one for you and one for your giant laptop. That’s what an IT pro’s day off looks like in the dial-up-era movie The Net. The thriller begins with hacker and loner Angela Bennett (played by Sandra Bullock) going on a rare vacation and meeting a suave stranger—someone who has also brought his tech gear to the beach. He even, she learns, enjoys a Gibson cocktail—her favorite. Too good to be true? Or is this meet-cute actually a meet-phish? Since this is a thriller, of course it’s the latter: the man on the beach is none other than villainous, just-check-his-last-name Jack Devlin (Jeremy Northam). Nothin’ but The Net.—BH |
|
|
CYBERSECURITY Drop it like it’s hot  Anna Kim | As a web developer, you might be tasked with setting up a temporary website for a company event. But when the website’s no longer needed, what happens if you lose track of the domain? If a company somehow misses the warning emails to renew, the domain will be rereleased to the public, where anyone can register it—opening the door to “dropcatch attacks,” or malicious actors who use the domain to redirect users to scams and malware. In a blog post, IT automation and cybersecurity company Infoblox reported that it had observed more than 50,000 dropcatched domains (i.e., a domain name expiring, becoming available to the public, and someone securing it) per day among generic top-level domains—that is, .com, .org, .net, .biz, and .info—in the first half of 2026. While not all of those dropcatches were necessarily linked to attacks, it shows the scope of the potential problem when businesses shut down, miss renewal notices, or forget email accounts tied to web addresses. Stop, drop, and roll.—CN |
|
|
patch notes  Francis Scialabba | Today’s top IT reads. Stat: 100+. That’s how many internet-exposed water systems were targeted by cyberattacks in July, according to the Cybersecurity and Infrastructure Security Agency. (SecurityWeek) Quote: “Agents embedded in applications can operate through existing permissions, OAuth grants, and workflow access, creating toxic combinations that expose data and trigger actions beyond what any owner approved.”—Ofer Klein, CEO of AI security vendor Reco, on AI tools operating with no IT oversight (Infosecurity Magazine) Read: A deeper dive into why OpenAI’s agents hacked Hugging Face. (MIT Technology Review) Close security gaps: Security teams can’t protect against threats they can’t see. Join SentinelOne on Sept. 29–30 for Securing AI Bootcamp. Attendees will get the scoop on emerging threats, security frameworks, + guardrail techniques. RSVP here.* *A message from our sponsor. |
|
|
|
|