惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Security @ Cisco Blogs
H
Hacker News: Front Page
P
Privacy International News Feed
N
News and Events Feed by Topic
T
Threatpost
Simon Willison's Weblog
Simon Willison's Weblog
S
Schneier on Security
K
Kaspersky official blog
S
Secure Thoughts
V2EX - 技术
V2EX - 技术
Security Latest
Security Latest
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
CERT Recently Published Vulnerability Notes
L
Lohrmann on Cybersecurity
Jina AI
Jina AI
P
Proofpoint News Feed
AI
AI
雷峰网
雷峰网
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Recent Commits to openclaw:main
Recent Commits to openclaw:main
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
博客园 - 叶小钗
Webroot Blog
Webroot Blog
Apple Machine Learning Research
Apple Machine Learning Research
SecWiki News
SecWiki News
罗磊的独立博客
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
Google DeepMind News
Google DeepMind News
Cyberwarzone
Cyberwarzone
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
Schneier on Security
Schneier on Security
The GitHub Blog
The GitHub Blog
S
Security Affairs
Blog — PlanetScale
Blog — PlanetScale
Last Week in AI
Last Week in AI
P
Proofpoint News Feed
月光博客
月光博客
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Securelist
W
WeLiveSecurity
T
Troy Hunt's Blog
A
Arctic Wolf
博客园 - 司徒正美

informationweek

2026 tech company layoffs How Sedgwick scaled AI in legacy claims workflows InformationWeek Podcast: CTOs on using AI in regulated spaces How top CIOs are measuring the real ROI of IT automation What AI must learn from Roosevelt, conservation and 1929 Experian's chief innovation officer gleans AI gains with startup collab ETS CIO on competing with AI startups 'running with scissors' Before the next VMware: How CIOs prepare for vendor shocks The strategic alignment powering cyber-resilient organizations The AI infrastructure bottleneck is becoming a CIO problem InformationWeek Podcast: CTOs on reining in rogue AI agents Workplace equity in the age of AI Why and how to implement an AI asset rationalization strategy Why companies are shifting toward private AI models AI agents in automation: When to build, when to buy Navan CTO AI on trial: The Workday case that CIOs can The AI infrastructure boom is coming for enterprise budgets How CIOs can manage LLM costs: A practical guide What CIOs miss when buying vertical SaaS software InformationWeek Podcast: How CTOs balance AI and their teams Whirlpool, Duke Energy, Cleveland Clinic CIOs on scaling AI Where CIOs get stuck rebuilding the enterprise: What 'Rewired' reveals As AI makes projects harder to track, will CIOs need new controls? Why disaster recovery plans fail in geopolitical crises A silent erosion of enterprise AI by data poisoning Priceline CTO prioritizes engineers able to 'hold a room and a roadmap' InformationWeek Podcast: When CTOs need to restart IT projects Wayfair CTO maps agentic path across digital and brick-and-mortar commerce The AI contract gaps the Google-Pentagon deal just made visible Non-human identity sprawl is agentic AI's real risk Anthropic's Mythos forces a rethink of vulnerability management Outsourcing contracts weren't built for AI. CIOs are renegotiating now The AI spend hangover companies didn't plan for The power of CIO networking in the competitive AI world Why CIOs see AI projects stall: Speed without structure kills scale IT leaders should never let a good crisis go to waste SFO's digital twin maps airport operations from the curb to takeoff CIOs caught in the middle as AI startups disrupt vertical Saas Submit an IT Leadership column to InformationWeek Podcast: Rightsizing AI frameworks to avoid failure modes The invisible labor crisis inside IT: AI work the org chart can't see Why AI teams treat training data like capital Ask the Experts: How CIOs can identify and overcome cultural barriers to innovation Nobody told legal about your RAG pipeline -- why that's a problem Meta's new 'AI Zuckerberg' is a mirror for every C-suite Will the music stop for AI's funding dance? Rethink tech talent: Local is the smartest play for IT InformationWeek Podcast: Catching errors in AI-powered code CIOs can combat talent scarcity with AI-augmented leadership -- Gartner How Bellevue, Wash., is applying AI to streamline a broken permitting process Ignore the hype: Smarter tech bets at speed of change Who controls the fix? Colorado's repair fight tests CIO power Ask the Experts: The red flags that signal an AI project isn't worth pursuing The hidden high cost of training AI on AI Red Hat's Marco Bill: Resource control is key for AI sovereignty InformationWeek Podcast: New IT architecture, cloud, edge and AI Enterprises need Tier 1 provider relationships to deliver on AI How CIOs run and rebuild the business at the same time in the AI era It's not your tech stack, it's your structure -- fix it FinOps: Helpful tool, or a cloud control placebo for CIOs? Cleveland's open data overhaul: From sticky notes to public dashboards As Microsoft expands Copilot, CIOs face a new AI security gap Why build vs. buy doesn't fit modern IT systems InformationWeek Podcast: Is quantum computing slumbering? Your AI vendor is now a single point of failure Vibe coding: Speed without security is a liability A practical guide to controlling AI agent costs before they spiral AI fuels a new wave of technical debt The sunsetting of Sora: A hard lesson in AI portfolio resilience HP pushes broad internal AI use after early productivity gains Why value-based pricing is inevitable InformationWeek Podcast: Safeguarding ecosystems from outsiders Why AI scaling is so hard -- and what CIOs say works Humans are the North Star for AI-native workplaces -- Gartner How IT leaders build a culture for what comes next Compliance costs risk widening the AI gap AI-driven layoffs add new demands on CIOs to prove value AI transformation: Early wins are not enough for CIOs Why CIOs can't let users wait on IT Memory shortage doesn't have to spell disaster for IT budgets Accelerate AI adoption: 3 reasons for adopting MCP How techno-nationalism is complicating IT resilience and supply chains for CIOs InformationWeek Podcast: Compliance crackdown on AI and BYOD Workday’s AI reset: Agents and the race to remake SaaS Why enterprise AI initiatives keep dying before production Metrics of meaning: What do we really measure in AI? Techno-nationalism is reshaping CIO infrastructure strategy Using AI to pick team leaders -- without crossing legal or ethical lines What Oracle's layoffs reveal about running IT with fewer people Chief AI Officer on course-correcting when AI moves too fast Large enterprises need high-performing networks to scale AI InformationWeek Podcast: When do smaller AI models make sense? The future belongs to AI-driven IT Ways AI supercharges risk awareness and data insights for CIOs How automation prepares you for agentic NetOps Should the CIO, CFO or CEO hold the kill switch on AI? The CIO's new mandate: Redesign work itself Ask the Experts: CIOs say they wouldn’t pull workloads back from the cloud How AI is Reshaping the Enterprise
Confidential computing resurfaces as security priority for CIOs
2026-04-03 · via informationweek

Encryption, firewalls and zero-trust architectures are time-tested methods for guarding sensitive data. But there's a catch: in the era of cloud computing and deeply intertwined digital networks, it's increasingly difficult to know where data resides -- and who can view it -- at any given moment.

That's prompting CIOs to turn to confidential computing. The technology addresses a common but often overlooked security gap: organizations generally use encryption for data at rest and in transit, yet the moment it's decrypted, it is potentially visible. This makes it vulnerable to anyone or anything that has access to system memory, including a rogue process, compromised hypervisor or bad actor.

Confidential computing protects data in use by processing it inside a hardware-encrypted trusted execution environment (TEE) -- a secure area within a chip that isolates data from surrounding infrastructure, applications, cloud providers and even privileged users. Think of a TEE as a mailroom without a door or windows: no one can enter, but letters can pass in and out through a safe slot.

Related:Deepfakes become an enterprise risk for CIOs and CISOs

"When we describe confidential computing and people actually understand it, the question is almost always the same: Why wouldn't we use this?" said Mark Bower, chief strategy officer at Anjuna Security and co-chair of the Cloud Security Alliance Confidential Computing Working Group.

As threats worsen and risks grow -- including geopolitical instability -- confidential computing is in the spotlight. A recent survey conducted by IDC Research found that 75% of 600 respondents are adopting confidential computing in some form -- with 18% already in production and 57% testing it. Equally important, 88% of business leaders say it improves data integrity, and 77% believe it dials up key technical assurances. 

"As AI adoption grows, regulatory pressures increase and multi-party analytics gains traction, organizations are looking to close security gaps and future-proof resilience," said Philip Bues, a senior research manager at IDC. "It is becoming a board-level imperative."

Establishing trust in code, protecting data in use

What makes confidential computing so attractive is that it introduces verifiable trust through hardware-rooted attestation. Workloads contain a unique cryptographic identity that proves code is running within a confidential environment. "You avoid injecting secrets into the CI/CD pipeline, which is exactly where they get compromised," Bower said.

Normally, organizations power up software and services with no guarantee that passwords, keys or secrets are intrinsically secure. "There is a 'first secret problem.' How do I know when I set up access control for a system that it is actually trustworthy?" Bower said. "Confidential computing solves this problem. It establishes trust before it ever touches data."

Related:Where CISOs need to hire and develop cybersecurity talent

The technology is already widely used for chip cards and payment platforms, including Apple Pay and Google Pay. It's also built into hardware security modules that store and protect cryptographic keys. Now, as organizations look to wall off intellectual property, regulated analytics workloads, personal and private data, and information that can run through generative AI models, confidential computing is expanding to cloud, hybrid and edge environments.

Confidential computing excels for "sensitive workloads and where data and operational sovereignty are high on the list of concerns," said Bart Willemsen, an analyst at Gartner. This includes finance and banking, healthcare, AdTech and MarTech. There's also growing interest around confidential AI and running smaller, fit-for-purpose open source AI models within a TEE. In fact, Gartner ranked confidential computing among its top three technologies to watch in 2026.

"Confidential computing provides the hardware-enforced boundary that software controls alone cannot," Bower said.

Related:IT mistakes that escalate into serious cyber-risk

How CIOs can adopt confidential computing

Until recently, many CIOs viewed confidential computing as an experimental technology. Early versions required technical expertise to deploy, manage and use systems -- and tools often didn't integrate well with existing workflows. As a result, developers and DevOps teams bristled, and adoption lagged.

What's changed is that modern software stacks support confidential computing within existing runtime environments, including virtual machines and containers. As a result, there's no need to redesign applications and reinvent security protocols from the ground up. TEEs also come with controls that work alongside existing encryption tools rather than replacing them, Willemsen said.

A regulatory structure is also emerging. NIST published an initial public draft in December explicitly recommending confidential computing as a control for sensitive workloads. The NSA -- whose recommendations heavily affect government and enterprise security planning -- has added TEE to its most recent zero-trust guidance. Other initiatives around the world, including the EU's Digital Operational Resilience Act and the Monetary Authority of Singapore, are also promoting the approach.

IDC recommends starting with the most sensitive workloads, spinning up targeted pilot projects, tapping third-party attestation solutions and open source tools to validate the integrity of an environment, and engaging with vendors that support open standards and interoperability. It's important to participate in industry initiatives and collaborate with key stakeholders and invest in training and skills development, Bues said.

Confidential computing's role in the secure enterprise

Confidential computing isn't the only game in town. Other methods, such as homomorphic encryption, secure multiparty computation and privacy-preserving federated learning, are also gaining traction. Yet each introduce performance penalties or implementation complexity. The appeal of confidential computing is that it already operates at scale with infrastructure organizations it owns.

Bower said that as CIOs turn to confidential computing, it's important to stay focused on a crucial fact: ROI doesn't arrive in the form of hard numbers; TEEs reduce risk exposure and improve compliance. They help organizations sidestep potentially devastating -- and expensive -- security and regulatory breakdowns. He suggested turning to industry sources, such as the Confidential Computing Consortium, to gain insight into training, open source tools and other resources that can smooth the transition to confidential workloads.

According to Bues, confidential computing will likely converge with AI Security Posture Management (AI-SPM) and Data Security Posture Management (DSPM) platforms. This would close a critical gap: TEEs securing data in use, while DSPM and AI-SPM manage exposure and governance across the rest of the lifecycle. He predicted that within a few years, a new standard could emerge for how enterprises manage and protect sensitive workloads. The result would be a framework that further integrates security and governance.

"The question is no longer whether confidential computing belongs in the enterprise," Bower said. "It's how quickly CIOs can make it part of the architecture."

About the Author

Samuel Greengard

Contributing Reporter

Samuel Greengard writes about business, technology, and cybersecurity for numerous magazines and websites. He is author of the books "The Internet of Things" and "Virtual Reality" (MIT Press).