Logo
Monitor Illustration
Blog

News, Article, and Solution in Cybersecurity Realms.

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape
Cybersecurity

Why Annual Penetration Testing Is No Longer Enough in Today's Threat Landscape

ITSEC AsiaITSEC Asia
|
Jan 09, 2026 — 7 minutes read

If you only went to the doctor once a year, you probably would not assume you were perfectly healthy for the other 364 days. Health changes over time. New conditions can develop, existing issues can worsen, and unexpected problems may arise between checkups. That is why people increasingly rely on regular monitoring and preventive care rather than waiting for an annual appointment to discover something has gone wrong. Cybersecurity works in much the same way. For many years, annual penetration testing has been considered a cybersecurity best practice. Organizations schedule an assessment, receive a report, address the findings, and repeat the process the following year. In relatively static environments, this approach provided a reasonable level of assurance. Modern organizations, however, no longer operate in static environments. Cloud adoption has accelerated. APIs have become essential to digital services. Development teams deploy updates continuously, and third-party integrations have become increasingly common. As organizations move faster, their attack surfaces evolve just as quickly. A system that was secure six months ago may look very

Professor IllustrationAndroid IllustrationMonitors Illustration

Recent Highlights

The Cybersecurity Talent Pipeline Needs More Than More Graduates
Cybersecurity

The Cybersecurity Talent Pipeline Needs More Than More Graduates

ITSEC AsiaITSEC Asia
|
Okt 09, 2026 — 3 minutes read

Cybersecurity has no shortage of reasons to attract new talent. There are technical roles, policy roles, incident response, digital forensics, security engineering, governance and an expanding set of jobs around AI. Yet access to those paths isn’t evenly distributed. ITU’s Her CyberTracks programme puts a specific number against the problem: women accounted for 22% of the global cybersecurity workforce in 2025. ITU also identifies unequal access to training, a lack of strong female role models and limited awareness of cybersecurity career options among barriers to greater participation. ITU [https://www.itu.int/en/ITU-D/Cybersecurity/Pages/Skills-Development/Her-CyberTracks.aspx?utm_source=chatgpt.com] The programme’s fourth edition, running from May to October 2026, is designed around that gap. It combines technical and policy training with mentorship, networking and practical exercises. Its Asia-Pacific regional training is scheduled for 12–16 October in Bangkok. ITU [https://www.itu.int/en/ITU-D/Cybersecurity/Pages/Skills-Development/Her-CyberTracks.aspx?utm_source=chatgpt.com] The useful lesson for workforce planning is simple: talent development needs an ecosystem around the learner. TRAINING GETS PEOPLE STARTED. MENTORSHIP HELPS THEM STAY. A cybersecurity course can teach someone how incident response works. It can’t automatically show them what a career in incident response

Your Incident Response Team Has an AI Problem to Rehearse
Cybersecurity

Your Incident Response Team Has an AI Problem to Rehearse

ITSEC AsiaITSEC Asia
|
Okt 07, 2026 — 3 minutes read

An AI assistant connected to internal data starts returning information it shouldn’t reveal. What does the incident responder collect first? Traditional evidence still matters, but the investigation may also require prompts, model outputs, retrieval sources, system instructions, access permissions and records of actions taken through connected tools. Disabling an endpoint won’t necessarily answer what the model accessed or what information it produced. Recent workforce data suggests many teams haven’t rehearsed that situation. ISACA’s 2026 State of Cybersecurity research, based on more than 1,800 cybersecurity professionals globally, found that only 8% of organizations regularly conduct AI specific response exercises. The same research found that 45% see LLM SecOps as a skills gap, up 12 percentage points from 2025 and 21 points from 2024. ISACA [https://www.isaca.org/about-us/newsroom/press-releases/2026/only-8-percent-of-organizations-global-enterprises-conduct-regular-ai-specific-response-exercises?utm_source=chatgpt.com] AI security is becoming operational work rather quickly. AI CHANGES THE EVIDENCE NIST convened an AI Incident Management Workshop in May because a new class of incidents is emerging as AI systems become embedded in critical infrastructure, cybersecurity and other operational environments. Its work covers incident definitions, lifecycles, taxonomies, existing playbooks

“Knows Cybersecurity” Is Too Vague to Be Useful
Cybersecurity

“Knows Cybersecurity” Is Too Vague to Be Useful

ITSEC AsiaITSEC Asia
|
Okt 07, 2026 — 3 minutes read

Imagine two SOC analysts who both list incident response as a skill. One can follow a documented investigation procedure, collect evidence and escalate a suspicious event. The other can investigate an unfamiliar attack, correlate evidence across systems, challenge the initial hypothesis and guide colleagues through containment. Both legitimately have incident response skills. They clearly shouldn’t be described as having the same level of capability. ENISA is addressing exactly this problem in its ongoing revision of the European Cybersecurity Skills Framework. The current ECSF organizes cybersecurity work into 12 professional role profiles, covering responsibilities, skills, knowledge and relationships between roles. The revised framework will add proficiency levels to support workforce assessment, career development and training pathways. ENISA [https://www.enisa.europa.eu/press-office/press-and-media/european-cybersecurity-skills-framework-ecsf?utm_source=chatgpt.com] That seemingly small addition could change how organizations think about the skills gap. A SKILL LIST TELLS YOU WHAT. A LEVEL TELLS YOU HOW FAR. Consider penetration testing. A beginner might understand reconnaissance, use established testing methods and reproduce common vulnerabilities in a controlled environment. Someone further along should be able to choose an appropriate methodology, adapt testing to

Editor's Choice

Whitepapers

Oktober 5, 2026
No article found

Receive weekly
updates on new posts

Subscribe