AI-security claims are easy. Independent evidence is harder.
Meet SecureIQLab at Black Hat to discuss AI Security CyberRisk Validation v1.0 before the next cohort closes.
https://t.co/ffdebST0LI
#BHUSA#BlackHat#AISecurity#Cybersecurity
Issue 5 of ๐๐ฉ๐ฆ ๐๐ข๐ญ๐ช๐ฅ๐ข๐ต๐ช๐ฐ๐ฏ ๐๐ข๐บ๐ฆ๐ณ breaks it down, with the public ACFW data.ย
Read Issue 5:ย https://t.co/HicwDO22ho
Get the report:ย https://t.co/QOvZHT6lGs
One firewall category. One identical battery: ~4,500 attacks across 59 categories. Security efficacy ran from 44.81% to 99.07%. A 54-point spread between products sold to solve the same problem. ๐งต
So for any control answered with "we red-teamed it," ask a second question: has it been measured against a published methodology, applied identically to comparable products, and scored in the open? Different evidence.
So the question stops being "is it deployed" and becomes "what proves it defends."
Issue 4 of The Validation Layer widens that question to every control on your diagram:ย
https://t.co/uHwm0eAQrm
A question for your next architecture review:
When a control is deployed, what published, independent evidence proves it can detect, block, log, and support response against a real attack path, not just that it's installed? ๐งต
The standard is converging across domains: someone other than the seller signs the test. One published method, applied identically, scoring you can inspect.
Regulators and procurement are all moving in the same direction.
Deployed, patched, on schedule, doing exactly what its owner believes. And still a doorway, not a defense.
Edge devices keep landing on CISA's exploited-vulnerabilities list. Deployed status and defended status are two different facts.
https://t.co/yLPBLgByjP
"Independent validation" is an asset, not a threat.
If your control performs, a published-method test you didn't run yourself answers the procurement questionnaire before it's mandatory.
The strong end of the range has every reason to prove it.
https://t.co/vScALNW6nd
The ACFW CyberRisk Validation 2.0 report is out! ๐ก๏ธ
12 cloud firewall vendors tested on real AWS infrastructure.
Independent, AMTSO-compliant data on threat defense & performance.
Briefings at #RSA2026 this week!
Book/Download:
https://t.co/MrlNphbNKu
https://t.co/KHNuRM0bQB
AI attacks up 89% YoY. Breakout time: 29 mins. ๐
Vendors at #RSA2026 have demos, but independent validation is the missing piece. At RSAC we share new metrics that show what stops these attacks.
Book a private briefing:
https://t.co/V2CcgUbLpW
#AISecurity#CyberSecurity
๐๐ฐ๐ฐ๐ผ๐๐ป๐ฐ๐ฒ๐ฑ ๐๐ผ๐ฑ๐ฎ๐: SOCx expandedโAI Security is our 4th methodology. 32 validation scenarios. Testing starts in April. Results targeted for Black Hat USA 2026.๐ก๏ธ
Demos at #RSA2026:
๐ https://t.co/rU5J0RxloX
Read the press release here:
๐ฐ https://t.co/Uo0NQVmYJB
@SecureIQlab is at #RSA2026!๐ก๏ธ
Here at RSA, the hype is on โhigh"...but what is real?
We're bringing claims back to earth with neutral tools and reports you can trust.
Check out our blog for the key questions to ask & to book a meeting:
https://t.co/cbeD1m7rVa
#rsa2026
Independent validationโthe layer your stack is missing.
At #RSA2026 with real data:
๐ ACFW Reportโ12 vendors
๐ค 1st Independent AI Security Validation
๐ WAAP 5.0โAI Tests AI
๐ป SOCx Live Demo
๐๐ผ๐ผ๐ธ ๐ฎ ๐ฏ๐ฟ๐ถ๐ฒ๐ณ๐ถ๐ป๐ด
https://t.co/yJ21cnzkfy
#CyberSecurity#AISecurity
Every vendor at RSA will pitch you AI-powered threat detection this year.
Ask them this instead: what's your block rate on OWASP Top 10 attacks that have been documented for over a decade?
If you're heading to RSA, come find us.
https://t.co/7aGsjll0vG