特色:
随着云基础设施、人工智能、分布式系统以及日益复杂的数字环境的扩展,网络安全正在被重塑。随着组织管理更多的身份、设备、数据和面向互联网的基础设施,安全重心正转向持续的可见性、控制力以及大规模响应风险的能力。
本报告考察了核心网络安全领域如何因这一转变而演变。在身份安全、遥测数据管理、人为安全、终端管理、人为风险情报、暴露面管理、电子邮件与域名安全、联网设备安全、AI原生安全运营以及云安全等领域,报告探讨了组织如何适应那些日益跨越系统、身份和基础设施流动,而非针对单一故障点的威胁。
在此阅读完整报告:https://report.papryon.com/thehackernews
身份安全 — Keeper Security
身份已成为现代组织中最重要的安全边界之一。随着云基础设施、远程工作、自动化和AI代理扩展了需要访问权限的身份数量,组织正朝着持续治理、最小权限原则以及对人类和非人类身份实施更强控制的方向发展。
“管理多个互不相连的工具本身就是一种安全负债。”
——Darren Guccione,Keeper Security首席执行官兼联合创始人
网站:keepersecurity.com
LinkedIn:https://www.linkedin.com/company/keeper-security
遥测与数据管理 — Cribl
安全团队生成的遥测数据比以往任何时候都多,但仅仅收集更多数据并不一定能带来更好的可见性。组织越来越关注如何控制遥测数据在各类安全工具中的路由、结构化、保留和重用方式,而人工智能则为安全数据的质量和监控提出了新的要求。
“2026年及以后的获胜安全项目,并非那些摄入数据最多的项目,而是那些能够按需路由、重塑和重用数据的项目。”
——Nicole Beckwith,Cribl安全工程与运营高级总监
网站:cribl.io
LinkedIn:https://www.linkedin.com/company/cribl
终端管理 — Automox
随着组织管理着日益分散的终端环境,安全团队需要缩短从发现弱点到应用有效控制之间的时间。持续修补、配置管理、自动补救以及跨Windows、macOS和Linux系统的可见性正成为终端安全的核心要素。
“修补可修补的,缓解不可修补的,并持续治理终端。”
——Justin Talerico,Automox首席执行官
网站:automox.com
LinkedIn:https://www.linkedin.com/company/automox
人为风险情报 — Nisos
安全团队日益超越传统的控制技术,以了解新兴威胁背后的人。人为风险情报结合了调查专业知识、数字归因和外部情报,以识别涉及员工、高管、候选人和第三方的风险。
“身份完整性是新的防火墙。”
——Ryan LaSalle,Nisos首席执行官
网站:nisos.com
LinkedIn:https://www.linkedin.com/company/nisos
暴露面管理 — Surf AI
暴露面管理正从发现漏洞转向持续减少关键的暴露面。随着环境变得愈发复杂,组织需要了解各个弱点如何相互关联、谁拥有它们以及哪些行动可以安全地降低风险。
“发现已商品化。中间环节很难。”
——Yair Grindlinger,Surf AI联合创始人兼首席执行官
网站:surf.ai
LinkedIn:https://www.linkedin.com/company/surf-ai
人为安全 — Adaptive Security
由人工智能驱动的社会工程学使得钓鱼攻击、语音克隆、深度伪造和冒充攻击的创建与规模化变得更加容易。因此,人类安全正从年度意识培训转向持续的、个性化的模拟,以及针对电子邮件、语音、短信和视频的风险干预。
“传统的意识项目并非为当今的威胁而设计。人类安全必须是持续的、个性化的,并能对现实世界的风险做出响应。”
—— Andrew Jones,Adaptive Security 联合创始人兼首席产品官
网站:adaptivesecurity.com
LinkedIn:https://www.linkedin.com/company/adaptivesecurity
电子邮件与域名安全 — Red Sift
数字冒充日益成为一个基础设施问题,而不仅仅是电子邮件问题。攻击者可以结合欺诈性域名、DNS滥用、网站和电子邮件活动来冒充组织,这使得对更广泛的面向互联网环境的可见性变得越来越重要。
“链条中的每个部分——电子邮件、域名、DNS、证书——都是在公共基础设施中做出的信任决策。”
—— Rahul Powar,Red Sift 联合创始人兼首席执行官
网站:redsift.com
LinkedIn:https://www.linkedin.com/company/red-sift
连接设备安全 — Asimily
随着连接环境的扩展,组织正在管理其基础设施中日益复杂的设备组合。安全团队需要了解哪些设备暴露在外、漏洞如何被利用,以及哪些控制措施可以在不扰乱运营的情况下降低风险。对于连接环境而言,持续的可见性、补救和强制执行至关重要。
“知道设备有风险必须以强制的控制措施告终,并且当设备规模翻倍时,这种控制必须依然有效。”
—— Shankar Somasundaram,Asimily 首席执行官
网站:asimily.com
LinkedIn:https://www.linkedin.com/company/asimily
AI原生安全运营 — SentinelOne
安全运营正面临现代攻击速度与人类团队调查能力之间日益扩大的差距。人工智能正越来越多地应用于安全运营中心(SOC),以自动化调查、连接证据,并减少理解事件所需的人工工作量。
“人工智能加速、支持并提出建议,但不会取代人类的判断。”
—— Paolo Cecchi,SentinelOne 地中海区域销售副总裁
网站:sentinelone.com
LinkedIn:https://www.linkedin.com/company/sentinelone
云安全 — CrowdStrike
随着 adversaries 利用凭证、配置和云控制措施在组织内部移动,云环境正成为身份驱动攻击的主要目标。因此,安全团队正转向针对身份、终端和云环境的统一实时保护。
“依赖静态风险模型和日志批处理的传统 CDR(云检测与响应)能力……对于当今的威胁格局来说实在太慢了。”
—— Kartik Shahani,CrowdStrike 印度及南亚区域副总裁
网站:crowdstrike.com
LinkedIn:https://www.linkedin.com/company/crowdstrike
在此下载报告全文:https://report.papryon.com/thehackernews
觉得这篇文章有趣吗?
本文由我们的一位宝贵合作伙伴供稿。请关注我们以阅读更多独家内容:
Google News,
Twitter 和
Featuring:
Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, security is shifting toward continuous visibility, control, and the ability to respond to risk at scale.
This report examines how core areas of cybersecurity are evolving in response to that shift. Across identity security, telemetry management, human security, endpoint management, human risk intelligence, exposure management, email and domain security, connected device security, AI-native security operations, and cloud security, it explores how organizations are adapting to threats that increasingly move across systems, identities, and infrastructure rather than targeting a single point of failure.
Read the full report here: https://report.papryon.com/thehackernews
Identity Security — Keeper Security
Identity has become one of the most important security boundaries in modern organizations. As cloud infrastructure, remote work, automation, and AI agents expand the number of identities requiring access, organizations are moving toward continuous governance, least privilege, and stronger control over both human and non-human identities.
“Managing multiple disconnected tools is itself a security liability.”
— Darren Guccione, CEO & Co-Founder, Keeper Security
Website: keepersecurity.com
LinkedIn: https://www.linkedin.com/company/keeper-security
Telemetry & Data Management — Cribl
Security teams are generating more telemetry than ever, but simply collecting more data does not necessarily create better visibility. Organizations are increasingly focused on controlling how telemetry is routed, structured, retained, and reused across security tools, while AI is creating new requirements for the quality and monitoring of security data.
“The winning security programs in 2026 and beyond aren't the ones ingesting the most data. They're the ones who can route, reshape, and reuse it on demand.”
— Nicole Beckwith, Senior Director, Security Engineering & Operations, Cribl
Website: cribl.io
LinkedIn: https://www.linkedin.com/company/cribl
Endpoint Management — Automox
As organizations manage increasingly distributed endpoint environments, security teams need to reduce the time between identifying a weakness and applying an effective control. Continuous patching, configuration management, automated remediation, and visibility across Windows, macOS, and Linux are becoming central to endpoint security.
“Patch what's patchable, mitigate what isn't, and govern the endpoint continuously.”
— Justin Talerico, CEO, Automox
Website: automox.com
LinkedIn: https://www.linkedin.com/company/automox
Human Risk Intelligence — Nisos
Security teams are increasingly looking beyond traditional technical controls to understand the people behind emerging threats. Human risk intelligence combines investigative expertise, digital attribution, and external intelligence to identify risks involving employees, executives, candidates, and third parties.
“Identity Integrity is the new firewall.”
— Ryan LaSalle, CEO, Nisos
Website: nisos.com
LinkedIn: https://www.linkedin.com/company/nisos
Exposure Management — Surf AI
Exposure management is shifting from discovering vulnerabilities toward continuously reducing the exposures that matter. As environments become more complex, organizations need to understand how individual weaknesses connect, who owns them, and what actions can safely reduce risk.
“Discovery is commoditized. The middle is hard.”
— Yair Grindlinger, Co-Founder & CEO, Surf AI
Website: surf.ai
LinkedIn: https://www.linkedin.com/company/surf-ai
Human Security — Adaptive Security
AI-powered social engineering is making phishing, voice cloning, deepfakes, and impersonation attacks easier to create and scale. Human security is therefore moving beyond annual awareness training toward continuous, personalized simulations and risk-based intervention across email, voice, SMS, and video.
“Traditional awareness programs weren’t built for today’s threats. Human security must be continuous, personalized, and responsive to real-world risk.”
— Andrew Jones, Co-Founder & CPO, Adaptive Security
Website: adaptivesecurity.com
LinkedIn: https://www.linkedin.com/company/adaptivesecurity
Email & Domain Security — Red Sift
Digital impersonation is increasingly an infrastructure problem rather than an email problem alone. Attackers can combine fraudulent domains, DNS abuse, websites, and email campaigns to impersonate organizations, making visibility across the wider internet-facing environment increasingly important.
“Every part of the chain — email, domain, DNS, certificate — is a trust decision made in public infrastructure.”
— Rahul Powar, Co-Founder & CEO, Red Sift
Website: redsift.com
LinkedIn: https://www.linkedin.com/company/red-sift
Connected Device Security — Asimily
As connected environments expand, organizations are managing an increasingly complex mix of devices across their infrastructure. Security teams need to understand which devices are exposed, how vulnerabilities could be exploited, and which controls can reduce risk without disrupting operations. For connected environments, this makes continuous visibility, remediation, and enforcement essential.
“Knowing a device is at risk has to end in an enforced control, and it has to hold as the fleet doubles.”
— Shankar Somasundaram, CEO, Asimily
Website: asimily.com
LinkedIn: https://www.linkedin.com/company/asimily
AI-Native Security Operations — SentinelOne
Security operations are facing a growing gap between the speed of modern attacks and the capacity of human teams to investigate them. AI is increasingly being applied within the SOC to automate investigation, connect evidence, and reduce the manual workload required to understand incidents.
“AI accelerates, supports and suggests, but does not replace human judgment.”
— Paolo Cecchi, Area VP Sales, Mediterranean Region, SentinelOne
Website: sentinelone.com
LinkedIn: https://www.linkedin.com/company/sentinelone
Cloud Security — CrowdStrike
Cloud environments are becoming a central target for identity-driven attacks as adversaries exploit credentials, configurations, and cloud controls to move through organizations. Security teams are therefore moving toward unified, real-time protection across identity, endpoint, and cloud environments.
“Traditional CDR capabilities that rely on static risk models and log batch processing... are simply too slow for today's threat landscape.”
— Kartik Shahani, Vice President of India & SAARC, CrowdStrike
Website: crowdstrike.com
LinkedIn: https://www.linkedin.com/company/crowdstrike
Download The Full Report Here: https://report.papryon.com/thehackernews
Found this article interesting?
This article is a contributed piece from one of our valued partners. Follow us on
Google News ,
Twitter and
LinkedIn to read more exclusive content we post.
首次收录 · 2026-10-04 · 9.4 分