Dataminr BLOG

Black Hat 2026: What CISOs Kept Telling Us

Black Hat 2026 made one shift explicit: organizations are moving toward a more preemptive security posture, built to get ahead of the speed of exploitation instead of reacting to it. Here's what that means in practice, backed by our own research.

Black Hat 2026: What CISOs Kept Telling Us
DATE August 11, 2026
AUTHOR Tim Miller, Global Field CTO and Chief Cybersecurity Strategist, Dataminr
SHARE
CYBER DEFENSE

Black Hat USA closed out its 2026 run this week in Las Vegas. One theme came up in nearly every conversation with CISOs on the show floor: the push toward a more preemptive security posture; one built to get ahead of the speed of exploitation rather than chase it. 

The CISOs and other cyber security professionals I met with talked about two things. First: patching faster is a strategy from a different era. What matters now is identifying and prioritizing vulnerabilities and risk against an organization’s own internal controls, using real-time early indicators of exploitation instead of a static patch queue, in terms a board can act on.

Second: intelligence that already knows an organization’s own environment, so analysts aren’t left correlating external signal against internal assets and alert history by hand. Both are exactly what the Dataminr 2026 Cyber Threat Landscape Mid-Year Report found in its own research, released just ahead of the show.

Shifting to Continuous Monitoring and Better Vulnerability Prioritization

Start with the push to get ahead of exploitation speed. Our report found that median time-to-patch stretched from 32 to 43 days in the first half of 2026, even as average breakout time (how fast an attacker moves once inside) fell under 30 minutes. Per the 2026 Verizon DBIR, vulnerability exploitation has overtaken stolen credentials as the top breach entry point for the first time in 19 years.

CVSS-driven triage alone can’t close that gap, and real-world incidents are making the case in real time. Anthropic’s Mythos model alone surfaced 1,752 high- or critical-severity vulnerabilities in open-source code within its first months of existence. OpenAI’s session at Black Hat detailed how its own AI agents found and exploited a flaw in a connected file repository, using it as a makeshift message board for weeks. Both examples show how fast that volume turns into real exploitation. 

More vulnerability findings isn’t the same as more protection. Without a way to filter that volume, it buries the handful of exposures that actually matter under a pile of ones that don’t. The fix isn’t more scanning. It’s catching exploitation signals as they emerge and weighing them against what an organization’s own controls actually cover.

That same discipline is what boards are now asking for directly. New research released during the show found that just 12.5% of security leaders are very confident their board understands the true state of the program after a briefing, and 55% of boards have never formally defined the cyber risk they’re willing to accept. Dataminr’s Balaji Yelamanchili raised the same point when he sat down with ISMG during the show: security teams face more signals than they can act on, and boards now demand answers in business terms, not technical ones. Intelligence that’s already tied to real controls and real exposure doesn’t need to be translated after the fact.

A Single Place to Understand External Signals Against Your Internal Environment

The second area showed up just as often, especially for teams without a dedicated threat-intel function: external signal that doesn’t know an organization’s own environment isn’t actionable on its own. It’s another feed to check against asset lists, controls, and alert history before anyone can act on it. That’s the case for fusing external threat data with what’s actually deployed and already flagged inside an organization, so intelligence arrives already relevant instead of requiring an analyst to look it up first.

Government leaders faced a version of the same shift. Cybersecurity Dive reported that officials used a Wednesday panel to urge infrastructure operators to plan for compromise rather than hope to prevent it, with CISA narrowing its focus to water and telecom. Our own report tracked the same pattern. Nation-state and hacktivist activity tied to the Iran-Israel-U.S. conflict, from Iran-linked Handala’s March attack on medical device maker Stryker to Iranian-affiliated actors probing U.S. water, energy, and government-facility operators via exposed Rockwell Automation PLCs, per FBI, CISA, and NSA. Black Hat’s Thursday panels added to the warning: CISA is still finding water-system controls exposed online, and attackers are growing more willing to destroy operational technology environments outright, not just disrupt them. You can’t defend everything equally, so knowing what’s reachable and what it would cost matters most.

That’s the thesis underneath everything else we saw this week: intelligence and detection are necessary, but they aren’t the same as knowing what to do next, or being able to explain that decision to the people who fund it.

It’s time to stop working harder at what already isn’t working. The organizations that come out ahead in the second half of 2026 won’t be the ones patching the most. They’ll be the ones that stop chasing CVSS scores and start prioritizing by exploitability, exposure, and business impact, in real time, against their own environment and controls. They’ll also treat every claim, whether it’s an attacker’s boast or an AI model’s output, as a lead to corroborate, not a fact to act on.

Adversaries aren’t cutting their headcount, and AI’s job on our side of the fight is to make the team you already have sharper: less time finding, more time judging what matters against an organization’s own controls, in real time. That’s the shift we built Dataminr for Cyber Defense to support: fusing external threat signal with an organization’s own environment and controls to prioritize risk in real time. In practice, that means detecting vulnerability exploits an average of 12 days ahead of CISA adding them to its Known Exploited Vulnerabilities catalog, putting teams days ahead of the headlines instead of hours behind them.

Dataminr 2026 Mid Year Cyber Threat Landscape Report

Dataminr’s 2026 Cyber Threat Landscape Mid-Year Report pulls from 4,500 threat actors tracked, 73,000 vulnerabilities detected, and over 2 million alerts processed per month to surface what actually mattered in H1 and what teams need to prepare for in H2.

Get the Report
Aug 11, 2026

SHARE
  • Cyber Defense
  • Cyber Risk
  • Blog