惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Webroot Blog
Webroot Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
SecWiki News
SecWiki News
S
Secure Thoughts
V2EX - 技术
V2EX - 技术
T
Tor Project blog
H
Hacker News: Front Page
P
Privacy International News Feed
Google DeepMind News
Google DeepMind News
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
V
Vulnerabilities – Threatpost
C
CERT Recently Published Vulnerability Notes
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
C
Cyber Attacks, Cyber Crime and Cyber Security
Help Net Security
Help Net Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
H
Heimdal Security Blog
AI
AI
PCI Perspectives
PCI Perspectives
Cyberwarzone
Cyberwarzone
P
Privacy & Cybersecurity Law Blog
AWS News Blog
AWS News Blog
Attack and Defense Labs
Attack and Defense Labs
The Last Watchdog
The Last Watchdog
K
Kaspersky official blog
T
The Exploit Database - CXSecurity.com
C
CXSECURITY Database RSS Feed - CXSecurity.com
Security Latest
Security Latest
Schneier on Security
Schneier on Security
Scott Helme
Scott Helme
L
Lohrmann on Cybersecurity
Cisco Talos Blog
Cisco Talos Blog
The Hacker News
The Hacker News
N
News and Events Feed by Topic
S
Schneier on Security
Simon Willison's Weblog
Simon Willison's Weblog
F
Fortinet All Blogs
T
Threatpost
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
Apple Machine Learning Research
Apple Machine Learning Research
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
云风的 BLOG
云风的 BLOG
博客园_首页
Recent Announcements
Recent Announcements
G
Google Developers Blog
Martin Fowler
Martin Fowler

Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS What CISOs need to get right as identity enters the agentic era Stopping AiTM attacks: The defenses that actually work after authentication succeeds EDR-Software – ein Kaufratgeber Microsoft patched an ‘agent-only’ role that was not AI is reshaping DevSecOps to bring security closer to the code The 'manager of agents': How AI evolves the SOC analyst role 4 Wege aus der Security-Akronymhölle New US House privacy bills raise hard questions about enterprise data collection Scattered Spider co-conspirator pleads guilty Security-KPIs und -KRIs: So messen Sie Cybersicherheit Bitwarden CLI password manager trojanized in supply chain attack 3 practical ways AI threat detection improves enterprise cyber resilience The curious case of Sean Plankey’s derailed CISA nomination Google gets agent-ready for the Mythos age Google drafts AI agents secure systems against AI hackers CNAPP – ein Kaufratgeber Riddled with flaws, serial-to-Ethernet converters endanger critical infrastructure NFC tap-to-pay gets tapped by hackers Anthropic bets on EPSS for the coming bug surge SBOM erklärt: Was ist eine Software Bill of Materials? Thousands of Apache ActiveMQ instances still unpatched, weeks after an actively exploited hole discovered Prompt injection turned Google’s Antigravity file search into RCE Why identity is the driving force behind digital transformation Top techniques attackers use to infiltrate your systems today The thin gray line: Handala, CyberAv3ngers and Iran’s proxy ops Attackers abuse Microsoft Teams to impersonate the IT helpdesk in a new enterprise intrusion playbook CISOs reshape their roles as business risk strategists Copilot & Agentforce offen für Prompt-Injection-Tricks Claude Mythos – ist der Hype gerechtfertigt? Für Cyberattacken gewappnet – Krisenkommunikation nach Plan Critical sandbox bypass fixed in popular Thymeleaf Java template engine White House moves to give federal agencies access to Anthropic’s Claude Mythos Another Microsoft Defender privilege escalation bug emerges days after patch Palo Alto’s Helmut Reisinger sees a cyber sea change ahead as AI advances Positiv denken für Sicherheitsentscheider: 6 Mindsets, die Sie sofort ablegen sollten NIST cuts down CVE analysis amid vulnerability overload Was bei der Cloud-Konfiguration schiefläuft – und wie es besser geht The endless CISO reporting line debate — and what it says about cybersecurity leadership Behind the Mythos hype, Glasswing has just one confirmed CVE Insurance carriers quietly back away from covering AI outputs RCE by design: MCP architectural choice haunts AI agent ecosystem Critical nginx UI tool vulnerability opens web servers to full compromise Copilot and Agentforce fall to form-based prompt injection tricks The deepfake dilemma: From financial fraud to reputational crisis 7 biggest healthcare security threats The need for a board-level definition of cyber resilience Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action 13 Fragen gegen Drittanbieterrisiken April Patch Tuesday roundup: Zero day vulnerabilities and critical bugs 4 questions to ask before outsourcing MDR 5 trends defining the future of AI-powered cybersecurity EU regulators largely denied access to Anthropic Mythos China-linked cloud credential heist runs on typos and SMTP How AI is transforming threat detection The AI inflection point: What security leaders must do now Cyber-Inspekteur: Hybride Attacken nehmen weiter zu Anthropic’s Mythos signals a structural cybersecurity shift Seven IBM WebSphere Liberty flaws can be chained into full takeover CISOs tackle the AI visibility gap Was ist Federated Identity Management? Old Docker authorization bypass pops up despite previous patch Hacker Unknown now known, named on Europol’s most-wanted list The cyber winners and losers in Trump’s 2027 budget CMMC compliance in the age of AI Claude uncovers a 13‑year‑old ActiveMQ RCE bug within minutes Was CISOs von Moschusochsen lernen können Hackers have been exploiting an unpatched Adobe Reader vulnerability for months New ClickFix variant bypasses Apple safeguards with one‑click script execution Cloudflare ‘actively adjusting’ quantum priorities in wake of Google warning Patch windows collapse as time-to-exploit accelerates So geht Post-Incident Review 6 Winter 2026 G2 Leader Badges prove this DDoS protection stands out Arelion employs NETSCOUT Arbor DDoS protection products
Security considerations for adopting Claude Code and Cowork for SMBs
Max Graupner · 2026-06-19 · via Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

If your SMB is adopting Claude, roll out features gradually and protect your API keys, because you cannot outsource your security risks.

You are a security leader at a small or medium-sized business (SMB), and your organization has decided to adopt Claude. If you are like me, after the initial “surprise” wears off, you probably want to quickly get your arms around what adopting Claude means for the business, and for security specifically. Below are some lessons I learned, witnessed as a bystander or heard from fellow security leaders in the SMB space. The business wants to move fast, and Security is tasked with keeping up with that velocity.

Know what you are buying and accept that things are changing fast

Make sure you really understand what the organization is trying to achieve and which Claude plan you are buying. Understanding the Claude plan you are on, or planning to purchase, is important because most security necessities do not become available until the Team plan or higher. For example, while the Team plan provides SSO, the Compliance API is available only on the Enterprise plan. Claude Code (“Code”), Cloud Cowork (“Cowork”) and Claude Chat (“Chat”) are different products with different use cases and outcomes. The strategy here is to manage the blast radius. Most likely, every user will ask for “Claude” without knowing which plan or product they need to accomplish the task. I have found that an analogy works well here: Finance probably has a low appetite for giving everyone in the organization a corporate credit card with unlimited spending and no expense policy.

Along those same lines, it might not be necessary to equip everyone with a Claude license, and while some users might have a business case for using Cowork, not everyone will need Code. Provisioning these products is not always clear-cut. My recommendation is to stand up an agile approval process to determine who needs a Claude license in the first place, which products they need and how to initially control the blast radius that way. A word of warning, though: while it might seem that the user with the Claude license is now riskier than the one without it, that might not actually be true. Unless you can tightly control shadow AI use, the unlicensed user might be using Claude’s free plan or a different AI product altogether. Roughly half of employees are using shadow AI tools, while some other surveys say it could be even higher (in the 80th percentile).

Also, accept that keeping up with the ever-changing AI landscape is difficult, especially as an SMB security leader. Claude pushes updates almost daily, and functions and features move around within the organizational settings. Just keeping up with the speed of innovation is daunting, so do not feel bad if you do not have all the answers right away. We are all learning how to use and secure AI at the same time.

Shortcut tip: Unsure where to start? Ask Claude. Prompt it to explain your Claude plan’s features, which security features are available to you and what an implementation plan could look like for your organization. Also, if someone has a question for you, ask them, “Have you asked Claude?” Delegating at its finest.

Don’t enable everything all at once, and guard your keys

What I found works well is to risk-rank Claude’s features. If the advice above is related to blast radius, you can think of this as assessing the “attack vectors.” Undoubtedly, users will ask to have all Claude features enabled at once, but I recommend a phased approach. It is very easy in Claude’s organizational settings to simply toggle features on and off, and while there are some warnings about how a feature could impact security, it is not always clear how the feature works across Claude products or within them.

Enabling egress comes with a warning banner; enabling web search or a browser extension does not. However, the risk of indirect prompt injection is real and still emerging. A hard “no” might not work for the business, but a well-explained “maybe later” might. My recommendation is to go through Claude’s features and risk-rank them (or better yet, have Claude risk-rank them first) and build a roadmap from there. I ended up with three tranches: “enable now,” “enable with additional controls and monitoring,” and “do not enable until risk can be better controlled,” but yours might look different. A valuable resource we used was this implementation guide for Cowork, but there are others out there, and this one is for Cowork only.

One of the more confusing parts is how to manage API keys. Do not hand out the Anthropic API key; depending on who the “primary owner” of the Claude account is, that person controls the keys to the kingdom. Enabling a safe and structured way to administer API keys was difficult to figure out, since instructions are nowhere to be found in the organizational (admin) settings. Since this is a very complex topic, know that there are different kinds of API keys, and Anthropic has introduced the concept of workspaces. Further, the Admin API requires a special API key (starting with sk-ant-admin…) versus a standard key (sk-ant-api…). Access is always an area of high risk, so make sure to understand how the organization is issuing, managing and reviewing API keys. I recommend keeping the pool of people who can create API keys small, especially in the beginning.

Shortcut tip: Drop a pic. Did you know that Claude can analyze screenshots? If you are unsure what a specific Claude feature means for security, take a screenshot of the setting and prompt Claude to assess what that feature means based on your security policies, SOC 2 and so on. The more context you provide, the better the results.

You still can’t outsource the security risk, and the elephant in the room is still data

Do not assume security is automatically baked into Claude products, and getting visibility from a security standpoint can be a challenge. While Anthropic continuously improves security controls and guardrails for its products, just like in the early days of the internet, controls and guardrails are still being built, but that does not mean you are relieved of the responsibility to understand the security risks and concerns. For example, enabling Skills could lead to the execution of malicious code. While Anthropic issues guidance on how to author skills, there is no out-of-the-box solution yet. With the help of Claude Code, we created our own “skills auditor,” a mini workflow to automatically submit a skill for review. It uses internal documentation and Anthropic’s best-practice guide to audit the skill, identify potential issues and provide recommendations to fix them.

We are now looking to enhance the skill even further so it can provide an updated skill rather than just recommendations. The big challenge remains having good controls and governance around your data— not only what is going into Claude, but also what is coming out. And honestly, that might be one of the trickiest problems to solve, so if you have figured it out, call me. Web search in Cowork essentially acts like a proxy for web traffic. Websites or web content that you blocked or filtered with traditional tools might now bypass your controls. Also, LLMs are people pleasers: if they do not know the answer, they might make it up (aka hallucinate). Users are often inclined or tempted to take the output as truth. Not only can that create security issues, but it can also lead to bad business outcomes.

Shortcut tip: Leverage your existing tools and vendors as much as possible. Push them on emerging questions. They, just like you, have to adjust to new products and AI developments. Do not feel like you are on an island.

As security practitioners, I believe we all dream of the day when vulnerabilities get fixed automatically long before they hit production, but with implementation choices comes the possibility of doing it “wrong.” However, I also believe that as a security leader in the SMB space, you already have the skills and repetitions needed to make the right choices. You are probably used to less red tape, more agile compliance and a quicker time to market. That means you are constantly walking the line between risk and reward, and this is no different. All the best— you’ve got this!

This article is published as part of the Foundry Expert Contributor Network.
Want to join?

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.