Under Pressure to Demonstrate AI ROI, Too Often Organizations Come Up Short

Close-up portrait of a woman with blonde hair, wearing a black jacket and light-colored sweater.
Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• Concerns about missing the AI boat have many corporate executives pushing AI application development mandates.

• However, research indicates that far too few organizations are realizing the kind of expected dividends in terms of cost savings, revenue generation, productivity gains, and innovation. What can they do differently to make the most of their investments?

To say artificial intelligence (AI) has become ubiquitous is almost an understatement. Just under 90% of all enterprises today use AI to support at least one corporate function, according to consulting firm McKinsey and Company, with 56% of all organizations applying the technology across three or more discrete tasks. This pace of adoption is unprecedented. Stanford University’s 2026 AI Index Report says 53% of the global population had been using generative AI (GenAI) within three years of widespread availability. For comparison’s sake, it was 12 years before the personal computer reached 40% of the population.

Continue reading “Under Pressure to Demonstrate AI ROI, Too Often Organizations Come Up Short” →

Despite Meta’s $17.1 Billion Lawsuit Settlement, Questions Linger About Reducing Negative Social Media Effects for Children

A professional headshot of a woman with blonde hair, wearing a black jacket and a light-colored turtleneck sweater, smiling towards the camera.
Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• In August, Meta admitted liability regarding social media’s addictive qualities on children, reaching a $17.1 billion settlement with US states and the District of Columbia.

• While seen as a victory by critics, the settlement is insufficient to introduce the sweeping changes needed to have a measurable effect.

Just weeks after Meta, the parent company of social media giants Instagram and Facebook, promised to restrict access to some of the more controversial features of its platform to settle a multi-billion dollar lawsuit, California Governor Gavin Newsom signed a bill tightening social media controls for children. The California law, which goes into effect in 2028, mandates social media accounts for users under age 16 be private, limits algorithmic feeds for minors, masks children’s location data, and turns off overnight notifications for underage users. Unlike similar legislation passed by other states like Illinois, the California law allows parents to amend social media restrictions. Newsom also signed a bill that requires AI companies to reveal to minors whether they are communicating with a non-human entity. The legislation also prevents children from accessing risky content on subjects like self-harm.

Continue reading “Despite Meta’s $17.1 Billion Lawsuit Settlement, Questions Linger About Reducing Negative Social Media Effects for Children” →

Public Opposition to New Data Centers Disrupts but Doesn’t Derail US Facilities’ Expansion

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

  • As rapid advances in AI application development drive demand for more processing capacity, US-based cloud providers are investing heavily in building out facilities to support these deployments.
  • But not everyone is on board with expansion plans, with public criticism stalling some development efforts, forcing hyperscalers to pivot to new locations, often in more remote areas.

AI is changing the cloud landscape, creating the near-term need for a vast increase in processing power and storage space. Hyperscalers are responding with substantial facility construction plans. Just this year alone, Amazon Web Services, Google, and Microsoft Azure are pouring a total of $500 to $700 billion into extensions of their data center footprints. Given AI’s dominance in enterprise technology investment plans, this is a logical track. However, not everyone is on board with these aggressive development plans -and AI plays a role in that resistance.

Continue reading “Public Opposition to New Data Centers Disrupts but Doesn’t Derail US Facilities’ Expansion” →

UK Plans Teen Social Media Ban, but the Action Raises Questions About Enforceability – and Privacy

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets

• Following the lead of other nations including Australia, the UK is getting set to restrict access to social media sites for minors 16 years and younger, starting in 2027.

• Comparable rules in other countries have proven to be difficult to execute, with teenagers finding workarounds. However, UK government officials say their efforts will leverage highly effective technology to enforce the ban, including biometric facial age estimation.

When UK Prime Minister Keir Starmer announced plans to introduce legislation later this year that will bar teenagers and children from social media access, critics offered immediate comparisons to a similar action by Australia in 2025, which has largely been deemed a failure. Though initially Australia touted the fact that 4.7 million accounts held by children under 16 had lost access to social media platforms like TikTok and Snapchat, research shows that just months later, the ban had very little effect. A University of New Castle study of 408 12 to 17 year olds found that due to “limited implementation, incomplete compliance, and substantial circumvention of social media restrictions, the ban has been largely unsuccessful.”

Continue reading “UK Plans Teen Social Media Ban, but the Action Raises Questions About Enforceability – and Privacy” →

Verizon DBIR: Adversaries Weaponize AI in Stealth Attacks by Targeting Points of Exposure

A close-up portrait of a woman with light brown hair, wearing a black blazer and a light-colored turtleneck sweater, smiling softly against a light blue background.
Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

  • Bad actors are raising their intelligence quotient with AI, tapping it to find vulnerabilities faster and to power mobile-centric phishing campaigns.
  • Supply chains are a weak link with partner network weaknesses linked to nearly half of all breaches.

An already volatile threat landscape is becoming even more dangerous as threat actors tap AI to accelerate and improve the success of their attacks on enterprises. Verizon’s 2026 Data Breach Investigations Report (DBIR) reveals how effective adversaries have become in using AI to capitalize on enterprise weaknesses. Exploiting software vulnerabilities was the initiating factor in 31% of all breaches, notable because this is the first time in almost 20 years that it has overtaken compromised credentials as the most frequent entry point for an attack.

Continue reading “Verizon DBIR: Adversaries Weaponize AI in Stealth Attacks by Targeting Points of Exposure” →

Lumen Research Paints a Dark Picture of the Threat Landscape in 2026

A professional headshot of a woman with long blonde hair, smiling gently while wearing a black jacket over a light-colored top.
Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• As the operator of one of the world’s largest global internet backbones, Lumen has a view into 99% of the public IPv4 addresses; its threat research team Black Lotus Labs monitors 2.3 million threats daily.

• Lumen’s 2026 Defender Threatscape Report underscores the highly organized and effective tactics cybercriminals are using to infiltrate the enterprise by exploiting network and edge vulnerabilities.

Long gone are the days when it was a question of if, not when, an organization would be breached. Most enterprise security practitioners are painfully aware of how successful threat actors have become in evolving their techniques to outwit some of the best defensive tools. But if anything, Lumen’s 2026 Defender Threatscape report, highlights that the real security challenge is only beginning. Leveraging research from its Black Lotus Labs threat intelligence unit including data from investigations, network telemetry, and campaigns between September 2024 and January 2026, Lumen notes that in response to the increasing effectiveness of endpoint detection solutions, cybercriminals have changed their strategies to leverage camouflaged proxies, vulnerable edge devices, and generative AI (GenAI) to set up attacks.

Continue reading “Lumen Research Paints a Dark Picture of the Threat Landscape in 2026” →

Akamai Research Shows AI-Powered Attacks are Targeting Undersecured APIs

Headshot of a woman with long blonde hair, wearing a black jacket over a beige sweater, smiling against a light blue background.
Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• APIs are an alluring target for threat actors now with the average number of daily API attacks soaring by 113% versus last year.

• More than 60% of the attacks in 2025 were affiliated with unauthorized workflows and activity that veered from the norm; indicators that are cybercriminals shifted from conventional web breaches to behavior-based incidents.

AI is changing the threat landscape, and it is doing so at lightning speed. Aggressive threat actors are putting the technology to work to expedite endpoint discovery and improve overall efficiencies. This has left enterprises flat-footed, often missing breaches until the real losses are finally discovered.

Continue reading “Akamai Research Shows AI-Powered Attacks are Targeting Undersecured APIs” →

EY Survey Reveals Enterprises are Investing in AI to Repel Adversaries Weaponizing the Very Same Technology

A professional portrait of a woman with long blonde hair, wearing a black jacket and a light-colored top, smiling against a soft blue background.
Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• Ninety-six percent of the security leaders surveyed see AI as a core element in their cybersecurity strategy that they are already deploying

• However, that same number perceive AI-driven attacks as serious threats to their organization

Cybersecurity is a delicate balancing act, requiring organizations to mount multi-layered defenses without causing the kind of friction that can impede productivity. An effective defense also requires the adequate funding to ensure the appropriate technical and personnel resources are in place to protect enterprise assets. With AI as an active part of the cybersecurity conversation, there are more angles for IT organizations to consider as both a proactive tool and an offensive weapon.

Continue reading “EY Survey Reveals Enterprises are Investing in AI to Repel Adversaries Weaponizing the Very Same Technology” →

IBM X-Force Threat Index 2026: Adversaries Use AI as a Weapon in Scaling Attacks

A professional headshot of a woman with long blonde hair, smiling softly while wearing a black blazer and a light-colored turtleneck.
Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• New research from the IBM X-Force threat intelligence team said the most sweeping developments in cybersecurity are threat actor exploiting exposed systems, gaps in supply chain defenses and fissures in interlinked application and cloud ecosystems to increase the volume and effectiveness of their attacks.

• IBM X-Force saw a dramatic rise in the number of active ransom groups, noting that cybercriminals are employing leaked tools and playbooks while using AI to automate attacks.

It is no secret that the enterprise is under threat from ambitious and aggressive cybercriminals, and that these threats have been escalating. Recently published research from IBM X-Force bears that out, highlighting the fact that adversaries are quick to exploit some major vulnerabilities to breach their targets. Compiling data from incident response, penetration tests, the dark web, and other intelligence, the newly published X-Force Threat Intelligence Index 2026 uncovered that the most common entry point for bad actors is publicly-facing applications. Citing the increasing complexity of applications and the frequency of misconfigurations, these applications are easily breached. There was a 44% increase in the number of publicly facing applications breached this year versus last.

Continue reading “IBM X-Force Threat Index 2026: Adversaries Use AI as a Weapon in Scaling Attacks” →

Cisco Research Finds AI Is Revolutionizing the Privacy Landscape

Amy Larsen DeCarlo – Principal Analyst, Security and Data Center Services

Summary Bullets:

• The overwhelming majority of organizations say they are benefiting from privacy investments in a myriad of ways, including helping increase customer trust.

• But most acknowledge data localization efforts increase the cost and complexity – and risk – to cross-border data transfers.

Data privacy is top of mind for most organizations, and not just because of a stormy geopolitical climate that is putting pressure on businesses to meet stringent regulatory requirements around data residency. Security concerns about protecting both customer data and intellectual property have companies expanding privacy programs. There is also growing recognition that customers place a premium on knowing their data will be protected.

Continue reading “Cisco Research Finds AI Is Revolutionizing the Privacy Landscape” →