Category: Uncategorized

  • October 2026 Is Your Final Warning: A CISO’s Practical Roadmap to NIS2 and DORA Compliance

    October 2026 Is Your Final Warning: A CISO’s Practical Roadmap to NIS2 and DORA Compliance

    The first NIS2 audit deadline is June 30, 2026. The full compliance deadline is October 2026. DORA has been in force since January 17, 2025. And the European Commission’s Digital Omnibus package is converging NIS2, GDPR, eIDAS, DORA, and the CER Directive into a single incident reporting pathway.

    For CISOs and compliance officers at essential and important entities across Europe, the compliance runway is nearly exhausted. Essential entities face fines up to €10 million or 2% of global annual turnover for failing to meet NIS2 cybersecurity risk-management requirements. Important entities face fines up to €7 million or 1.4% of global turnover. These are not theoretical penalties; national supervisory authorities across Germany, Portugal, and Austria are already actively enforcing.

    This post gives CISOs a clear, action-oriented roadmap: what NIS2 and DORA compliance requires in 2026, where most organizations still fall short, and how agentic automation dramatically shortens the compliance gap.

    What Is NIS2 DORA Compliance in 2026?

    NIS2 (Network and Information Systems Directive 2) is the European Union’s updated cybersecurity framework, requiring essential and important entities to implement at least 10 cybersecurity risk-management measures, including incident response capabilities, supply chain security, access control, and business continuity planning. DORA (Digital Operational Resilience Act) applies specifically to financial entities and their critical ICT third-party providers, mandating digital operational resilience testing, ICT risk management, and incident reporting frameworks. Both are in force in 2026.

    Where Are Organizations Still Falling Short on NIS2 DORA Compliance?

    1. Incident Reporting Timelines Are Not Operationalized

    NIS2 requires notification within 24 hours of becoming aware of a significant incident, with a detailed report within 72 hours. DORA has similar requirements for financial entities. Most organizations have a compliance policy that references these timelines, but lack the automated tooling to generate the required reports at speed during an active incident when security teams are already under maximum pressure.

    2. Supply Chain Security Requirements Are Broadly Unfulfilled

    NIS2 Article 21 includes explicit supply chain security requirements: organizations must assess and manage security risks in their relationships with direct suppliers and service providers. For organizations with dozens or hundreds of third-party integrations, this represents a significant gap. Manual vendor assessments are neither scalable nor continuous.

    3. The 10 Risk-Management Measures Are Partially Implemented

    NIS2 Article 21 mandates at least 10 cybersecurity risk-management measures including: policies on risk analysis and information system security; incident handling; business continuity; supply chain security; security in network and information systems acquisition, development, and maintenance; policies and procedures for assessing cybersecurity risk-management measures effectiveness; basic cyber hygiene practices and cybersecurity training; policies and procedures relating to cryptography; human resources security; access control policies; and asset management. Most organizations can check the policy box. Fewer have operationalized these as measurable, continuously monitored controls.

    4. Management Body Accountability Is Underestimated

    NIS2 explicitly places accountability on the management body of essential and important entities. Senior leadership can be held personally liable for failures to approve and oversee cybersecurity risk-management measures. This is a structural shift from treating cybersecurity as an IT department function.

    What Happens When Organizations Miss the NIS2 DORA Compliance Deadline

    Essential entities face administrative fines up to €10 million or 2% of global annual turnover. Important entities face fines up to €7 million or 1.4% of turnover. Beyond financial penalties, supervisory authorities can issue binding instructions, suspend certifications, and impose temporary prohibitions on individuals in managerial positions from exercising managerial functions. For financial entities under DORA, non-compliance also creates ICT risk management gaps that increase operational resilience requirements under European Banking Authority oversight.

    NIS2 Compliance Gap Analysis: Where Most Organizations Stand Today

    NIS2 Article 21 Requirement Common Compliance Gap
    Incident handling policies Policies exist; automated reporting timelines not operationalized
    Business continuity and crisis management Plans documented; not tested under realistic breach conditions
    Supply chain security assessment Periodic vendor questionnaires; no continuous monitoring
    Risk analysis and information system security Annual assessments; not continuous risk monitoring
    Effectiveness measurement policies No automated metrics collection for control effectiveness
    Cryptography and encryption Policies in place; implementation inconsistency across systems
    Access control MFA deployed for primary systems; gaps in legacy and shadow IT
    Asset management Primary asset inventory maintained; cloud and shadow assets incomplete

    How Peris.ai Helps Close the NIS2 DORA Compliance Gap

    BrahmaFusion: Automated Evidence Collection and Compliance Playbooks

    BrahmaFusion is Peris.ai‘s agentic AI hyperautomation platform. For NIS2 and DORA compliance, BrahmaFusion enables automated evidence collection that continuously documents the operation of cybersecurity controls, compliance playbooks that trigger the correct notification and documentation workflows within NIS2’s 24-hour and 72-hour incident reporting windows, and continuous monitoring across 100+ integrations that generates the asset and control coverage data needed for Article 21 effectiveness measurement.

    A finance startup using BrahmaFusion reduced SOC costs by 40% while increasing detection and documentation coverage, directly addressing the resource constraint that most compliance teams face.

    Peris.ai IRP: Audit-Ready Incident Documentation and Response Timelines

    Peris.ai IRP provides the structured incident case management that NIS2 and DORA notification requirements demand. When an incident is detected, IRP automatically generates a timestamped case record, MITRE ATT&CK mapping, AI-powered incident summaries, and response timeline documentation aligned to regulatory reporting windows. The incident report that supervisory authorities request is generated as part of the response process, not assembled afterward under deadline pressure.

    INDRA CTI: Continuous Threat Intelligence for NIS2 Article 21 Risk Management

    NIS2 Article 21 requires organizations to conduct ongoing risk analysis and information system security assessments. INDRA CTI provides the continuous external threat intelligence that informs this risk analysis: real-time intelligence on vulnerabilities affecting your industry sector, threat actor campaigns targeting your supply chain partners, and early warning on zero-day exploits being weaponized against your technology stack.

    Real-World Scenario: Meeting a 24-Hour NIS2 Notification Requirement Under Pressure

    A financial services essential entity under NIS2 detects at 11pm on a Friday that a threat actor has accessed a customer data environment through a compromised vendor integration. The security team is managing active containment while simultaneously needing to generate a notification to their national supervisory authority within 24 hours.

    Peris.ai IRP’s automated documentation has already compiled: the incident timeline from first detection through containment actions, the affected systems and data categories, the MITRE ATT&CK techniques observed, and the initial impact assessment. BrahmaFusion’s compliance playbook generates a draft NIS2 initial notification aligned to Article 23 requirements, pre-populated with verified incident data.

    The compliance team reviews and submits the notification at 8am Saturday, well within the 24-hour window. The 72-hour detailed report is pre-populated from IRP’s continuous case documentation. No compliance deadline is missed, and the security team’s containment effort is not disrupted by parallel documentation demands.

    Benefits at a Glance

    Benefit Outcome
    Automated NIS2 notification workflows 24-hour and 72-hour reporting deadlines met without crisis documentation scramble
    Continuous control effectiveness documentation Article 21 evidence available for audit without manual compilation
    35% analyst workload reduction via IRP Compliance and response teams maintain capacity during incidents
    INDRA CTI for ongoing risk analysis Continuous external threat intelligence fulfills Article 21 risk assessment requirement
    Supply chain monitoring integration Third-party security assessment automation aligned to NIS2 supply chain requirements
    Management-level reporting dashboards Board-level cybersecurity oversight documentation for management body accountability

    Conclusion

    The NIS2 DORA compliance deadline is not a future problem. It is a present operational requirement. Essential and important entities that have not operationalized their Article 21 controls, automated their incident reporting workflows, and established continuous risk monitoring have months, not years, to close the gap before audit exposure becomes financial liability.

    BrahmaFusion, Peris.ai IRP, and INDRA CTI give compliance teams and CISOs the automation infrastructure to meet NIS2 and DORA requirements at operational speed, without multiplying headcount. The compliance journey starts with visibility. Build it now.

    Learn how platforms like BrahmaFusion by Peris.ai empower compliance teams to automate evidence collection, accelerate incident reporting, and maintain continuous control effectiveness documentation. Want more insights? Visit Peris.ai.

    Frequently Asked Questions

    What is the NIS2 compliance deadline in 2026?

    The first NIS2 audit deadline is June 30, 2026, with full compliance required by October 2026. DORA has been in force across all EU nations since January 17, 2025.

    What are the fines for NIS2 non-compliance?

    Essential entities face fines up to €10 million or 2% of global annual turnover. Important entities face fines up to €7 million or 1.4% of global annual turnover, as well as potential personal liability for management body members.

    What does NIS2 Article 21 require?

    NIS2 Article 21 mandates at least 10 cybersecurity risk-management measures including incident handling, supply chain security, access control, risk analysis, business continuity, cryptography policies, asset management, and effectiveness measurement.

    How does DORA differ from NIS2?

    DORA applies specifically to financial entities and their critical ICT third-party providers, focusing on digital operational resilience testing, ICT risk management frameworks, and ICT incident reporting. NIS2 is broader, covering essential and important entities across multiple sectors with cybersecurity risk-management requirements.

    How can automation help with NIS2 DORA compliance?

    Automation addresses the two biggest compliance execution gaps: incident reporting timelines and continuous control documentation. Platforms like BrahmaFusion by Peris.ai generate compliance-ready documentation during incidents and maintain continuous control evidence that satisfies Article 21 effectiveness measurement requirements without manual compilation.

  • 56 Million Records, 461 Stakeholders, Two Universities Down: What Indonesia’s 2025-2026 Breach Wave Reveals About the Security Maturity Gap

    56 Million Records, 461 Stakeholders, Two Universities Down: What Indonesia’s 2025-2026 Breach Wave Reveals About the Security Maturity Gap

    The Numbers Indonesia Cannot Ignore

    Indonesia recorded 56,128,160 personal data exposures across 461 stakeholders in 2024, according to BSSN’s Indonesian Cyber Security Landscape report. Through August 2025, BSSN counted 3.64 billion cyber attacks. In May 2026, breach disclosures have continued at pace: a high-severity compromise of Brawijaya University internal systems and an active dark-web sale of the Kota Gunungsitoli municipality database have surfaced within days of each other.

    Indonesia is ASEAN’s largest digital market. The threat is growing faster than the maturity. The PDP Law (UU No. 27/2022) has been fully in force since October 17, 2024. BSSN Regulation No. 1/2024 requires 24-hour incident reporting to Nat-CSIRT. The PDP Agency, Indonesia’s new data protection authority, is targeted for operational launch in mid-2026. The regulatory clock is running.

    This post is the executive briefing for any organization with Indonesian operations or Indonesian customer data. It explains the breach landscape, the regulatory expectations now in force, and the specific control upgrades that will determine whether the next incident is contained, public, or punitive.

    What Is Indonesia’s Current Data Protection Regime?

    Indonesia’s data protection framework rests on three pillars in 2026:

    1. UU No. 27/2022 (PDP Law). Fully enforceable since October 17, 2024. Maximum penalty is 2% of annual revenue plus criminal liability.
    2. BSSN Regulation No. 1/2024. Requires reporting of cyber incidents to the Nat-CSIRT within 24 hours, and registration of organizational CSIRTs. BSSN has registered 537 CSIRTs across government and private sector entities.
    3. PDP Agency. Targeted for operational launch in mid-2026 pending Presidential Regulation approval. Will hold enforcement authority including monetary penalties and criminal referral.

    For multinational organizations, Indonesia’s framework now sits alongside GDPR, NIS2, and DORA in a layered global compliance stack. Each adds its own incident classification logic and reporting deadlines.

    The Problem: Indonesia’s Maturity Gap

    Volume is overwhelming structural defenses

    3.64 billion cyber attacks recorded through August 2025 represents an attack volume no manual SOC can absorb. BSSN reports that 90% of attacks in Indonesia originate from malware, but the actual successful intrusions increasingly involve identity abuse and supply chain compromise as well.

    The 24-hour reporting clock leaves no room

    BSSN Regulation No. 1/2024 requires Nat-CSIRT notification within 24 hours of incident detection. For many organizations, that window expires before forensic clarity is achieved. Without pre-built incident classification workflows, the report is either rushed and incomplete or late and punitive.

    Critical sector incidents continue

    The 2024 National Data Centre ransomware attack disrupted 282 government services and was met with a USD 8 million ransom demand. The Brawijaya University compromise alleged in May 2026 and the active dark-web sale of the Kota Gunungsitoli database show that sub-national institutions remain undersecured even as the regulatory environment hardens.

    Compliance documentation is not yet operational

    Many organizations have policies on paper that meet PDP Law on the surface, but no operational evidence pipeline that proves continuous compliance. When the PDP Agency examines incidents in 2026, paper-only programs will not survive.

    What Happens When Indonesian Organizations Do Not Solve This?

    • PDP Law penalties of up to 2% of annual revenue, plus criminal liability for executives.
    • Nat-CSIRT reporting failures, which are publicly traceable and reputationally costly.
    • Customer attrition, particularly for fintech and e-commerce, where data trust is the brand.
    • Cross-border vendor exclusion, as multinational customers limit partnership with non-compliant Indonesian providers.

    Old Way vs. New Way: Indonesia Incident Posture

    Capability Pre-2024 Indonesian Practice 2026 Mandate
    Incident reporting Internal escalation only 24-hour Nat-CSIRT notification, audit-ready
    DPO function Optional or undefined Mandatory under PDP Law for many controllers
    Data classification Inconsistent Documented schema with consent and retention mapping
    CSIRT registration Ad hoc Formal BSSN-registered CSIRT for impacted sectors
    Threat intelligence Generic feeds Indonesia-specific actors, dark-web monitoring

    How Peris.ai Supports Indonesian Compliance Operations

    Peris.ai is registered with BSSN and operates from offices in Jakarta, Singapore, and Abu Dhabi. The platform is engineered to support the specific operational expectations of the PDP Law, BSSN Regulation No. 1/2024, and the incoming PDP Agency. Four components carry the weight.

    IRP for 24-hour Nat-CSIRT-ready reporting

    Peris.ai IRP captures audit-ready incident documentation from the first alert. The case template is aligned to BSSN’s 24-hour Nat-CSIRT submission format, so the report writes itself as the investigation proceeds. A leading Peris.ai client in financial services reported a 35% reduction in analyst workload after IRP rollout.

    BrahmaFusion for automated compliance evidence collection

    BrahmaFusion executes continuous control monitoring playbooks against PDP Law and BSSN regulatory baselines. Evidence is collected continuously, not reactively. A Peris.ai client achieved 40% SOC cost savings after this class of automation.

    INDRA CTI for Indonesia-specific threat intelligence

    INDRA CTI maintains intelligence on actors targeting Indonesian sectors, dark-web sales of Indonesian datasets, and credentials tied to Indonesian organizations. When data attributable to your organization surfaces in a forum, INDRA CTI notifies your team before the breach becomes public.

    Corporate Compliance consultation

    Peris.ai‘s 1-on-1 corporate compliance service supports organizations through PDP Law alignment, BSSN CSIRT registration, ISO/IEC 27001 (BSSN’s recommended reference standard), and PDP Agency readiness.

    Use Case: From Detection to Nat-CSIRT in Under 6 Hours

    A mid-market Indonesian e-commerce company using Peris.ai experiences the following.

    1. INDRA CTI detects a sample of customer email addresses tied to the company appearing in a Telegram channel known to broker Indonesian datasets.
    2. Our XDR confirms an unusual outbound data transfer from one of the company’s customer service tools two days earlier, correlated to an identity that recently failed an AiTM-pattern login defense.
    3. BrahmaFusion contains the impacted identity and isolates the source system.
    4. IRP opens a case, populates the Nat-CSIRT submission template, and pre-fills 80% of required fields from automated evidence.
    5. The compliance team submits the Nat-CSIRT notification within 5 hours 47 minutes of detection, well inside the 24-hour window.

    Outcomes That Matter

    Benefit Outcome
    24-hour Nat-CSIRT alignment Reporting met without scramble
    Continuous control monitoring Compliance evidence captured before audit
    Indonesia-specific threat intelligence Dark-web disclosures detected early
    BSSN-registered CSIRT support Organizational CSIRT operationalized to BSSN expectations
    Multilingual incident response English and Bahasa workflows in one platform

    Conclusion

    Indonesia’s regulatory and threat environment in 2026 will not reward paper compliance. The combination of PDP Law enforcement, BSSN 24-hour reporting, the incoming PDP Agency, and an attack volume measured in billions creates an operational threshold that only autonomous threat detection, hyperautomation SOC, and continuous compliance evidence can meet. Peris.ai is built for that threshold, and operates inside Indonesia, for Indonesian organizations and the multinationals that serve them.

    Learn how platforms like BrahmaFusion by Peris.ai empower lean security teams to automate incident response, scale compliance operations, and build trust where it matters most. Want more insights? Visit Peris.ai.

    FAQ

    What is the PDP Law in Indonesia?

    The PDP Law, UU No. 27/2022, is Indonesia’s comprehensive personal data protection regulation, fully enforceable since October 17, 2024. Penalties include up to 2% of annual revenue and criminal liability.

    When does the PDP Agency launch?

    The PDP Agency is targeted for operational launch in mid-2026, pending Presidential Regulation approval. It will hold enforcement authority over the PDP Law.

    How quickly must Indonesian organizations report cyber incidents?

    BSSN Regulation No. 1/2024 requires reporting to the Nat-CSIRT within 24 hours of detection. BSSN has registered 537 CSIRTs across government and private sector to facilitate this.

    What was the 2024 National Data Centre ransomware impact?

    The attack disrupted 282 government services and was accompanied by a USD 8 million ransom demand, making it one of the most consequential incidents in Indonesian cyber history.

    How does Peris.ai help with Indonesian compliance?

    Peris.ai IRP aligns to BSSN’s 24-hour Nat-CSIRT reporting format. BrahmaFusion automates continuous PDP Law and ISO/IEC 27001 control monitoring. INDRA CTI provides Indonesia-specific threat intelligence. Peris.ai‘s Corporate Compliance service guides PDP Law and PDP Agency readiness.

  • The Agentic SOC: Why Your Alert Queue Is a Relic and What Replaces It

    The Agentic SOC: Why Your Alert Queue Is a Relic and What Replaces It

    Microsoft’s Security Blog published a post in April 2026 with a clear argument: the alert queue is a relic. “The agentic SOC: Rethinking SecOps for the next decade” laid out a fundamental restructuring of how security operations centers should work, one in which autonomous AI agents investigate, triage, and recommend remediation without human analysts manually reviewing every alert in a queue.

    This is not a vendor roadmap item or a 2030 prediction. It is a description of what leading security teams are building right now in 2026. The SIEM, XDR, and SOAR are converging into a single AI-powered detection-investigation-response layer. SOC team structures built around the alert queue model are becoming operationally obsolete.

    This post explains the agentic SOC architecture emerging in 2026, why the two-layer model replacing the alert queue represents a structural improvement, and how Peris.ai‘s BrahmaFusion platform positions security teams at the front of this transition.

    What Is an Agentic SOC?

    An agentic SOC is a security operations center in which AI agents handle routine detection, investigation, and triage decisions autonomously, escalating to human analysts only when genuine judgment or authority is required. The key distinction from traditional automation is the word “agentic”: these systems do not just execute predefined rules. They reason, adapt, and act across multi-step investigation and response sequences.

    In a conventional SOC, an alert fires, lands in a queue, waits for an analyst, gets triaged by a human, and if warranted, triggers an investigation. The bottleneck is the human queue. In an agentic SOC, the AI agent handles the queue autonomously: it investigates the alert, correlates it with threat intelligence and historical context, assesses severity, and either closes it with documentation or escalates it with a full investigation summary for human review.

    The Two-Layer Agentic SOC Architecture

    Microsoft’s April 2026 framework describes two functional layers:

    Layer 1: Deterministic Autonomous Disruption

    This layer handles known, high-confidence threat patterns with fully automated responses. No human review required. Examples include:

    • Known malware signatures detected on an endpoint: automatic isolation
    • Credential stuffing attack against an authentication endpoint: automatic session revocation and MFA enforcement
    • Brute force attempt exceeding threshold: automatic IP block and account lockout

    The defining characteristic of Layer 1 is speed: responses execute in seconds without waiting for any human decision.

    Layer 2: Generative Agentic Triage and Investigation

    This layer handles novel, ambiguous, or multi-step incidents where a reasoning agent is needed to correlate signals, form hypotheses, and develop a recommended response. Examples include:

    • Behavioral anomalies that don’t match known attack signatures
    • Multi-stage attack chains spanning endpoint, network, and identity telemetry
    • Low-and-slow intrusions that look like normal activity when any single signal is viewed in isolation

    Layer 2 AI agents produce investigation summaries with recommended actions, which human analysts review and approve. The analyst’s role shifts from “process every alert” to “review AI-generated case summaries and make final decisions on complex incidents.”

    Why the Alert Queue Model Is Failing

    The Volume Problem

    Modern enterprise environments generate thousands of security alerts per day. No human analyst team can process that volume without significant triage shortcuts. The practical result is alert fatigue: analysts tune out low-priority alerts, miss genuine signals buried in noise, and accumulate backlogs of uninvestigated cases.

    The Speed Problem

    Attackers are not waiting in your analyst queue. A credential theft and lateral movement sequence can complete in minutes. A ransomware pre-cursor can stage across an environment in under an hour. By the time an analyst reviews a queued alert from six hours ago, the attack may already be in its exfiltration phase.

    The Talent Problem

    Experienced SOC analysts are scarce and expensive. Building a human team large enough to process enterprise alert volumes at human review speed is not a viable solution for most organizations. The agentic model reduces the analyst requirement without reducing security coverage.

    What Happens When Teams Stay With the Old Model

    • Alert fatigue leads to missed detections
    • Long mean time to detect (MTTD) allows attackers to complete operations before investigation begins
    • Analyst burnout from repetitive triage work reduces retention
    • Security coverage has a hard ceiling set by team headcount

    The Platform Convergence Happening Now

    The agentic SOC is being enabled by the convergence of tools that were previously separate:

    Old Model New Converged Model
    SIEM (log collection and correlation) Unified AI detection platform
    XDR (cross-domain telemetry) Integrated telemetry layer with agentic analysis
    SOAR (playbook automation) AI agent that builds and executes response workflows
    Threat intelligence platform Embedded CTI that informs every investigation
    Case management tool AI-generated case summaries with recommended actions

    This convergence is what BrahmaFusion by Peris.ai is built on: a single platform that integrates detection, investigation, response automation, and threat intelligence into a unified agentic operating layer.

    How BrahmaFusion Powers the Agentic SOC

    The No-Code AI Playbook Builder

    BrahmaFusion’s no-code AI Playbook Builder allows security teams to define agentic response workflows without engineering overhead. Playbooks trigger on behavioral indicators, execute multi-step investigation sequences, and perform containment actions automatically. The result is Layer 1 and Layer 2 capability without requiring custom integration development.

    A finance startup using BrahmaFusion achieved 40% SOC cost savings by replacing manual triage cycles with automated playbook execution. A leading telco reduced incident response time from 30 minutes to 3.3 minutes.

    XDR Integration for Full-Spectrum Telemetry

    Peris.ai‘s XDR provides the telemetry foundation that agentic investigation requires: behavioral data across endpoint, network, and cloud environments. Without full-spectrum telemetry, an AI agent investigating a complex incident will reach the same dead ends a human analyst reaches when visibility is incomplete. XDR’s cross-domain correlation enables the Layer 2 investigation capability that makes the agentic model work for novel and multi-stage incidents.

    IRP for Human-in-the-Loop Escalation

    Peris.ai IRP provides the case management layer where agentic investigations are escalated to human analysts. Rather than presenting raw alerts, IRP delivers AI-generated investigation summaries with full event timelines, recommended response actions, and supporting evidence. The analyst reviews, approves, and escalates. The investigation work is already done.

    A finance company CEO using Peris.ai IRP reported a 35% reduction in analyst workload, exactly the shift the agentic SOC model is designed to produce.

    100+ Integrations for the Converged Stack

    BrahmaFusion integrates with 100+ security and IT tools, enabling the platform convergence the agentic SOC requires. Whether your environment includes legacy SIEM infrastructure, cloud-native detection tools, or a mix of vendor-specific endpoint solutions, BrahmaFusion connects across the stack and provides the unified agentic layer that the alert queue model never could.

    A Real-World Agentic SOC Scenario

    At 2:47 AM on a Tuesday, an anomalous authentication event fires from a legitimate employee account: the login is from an unfamiliar IP, at an unusual hour, followed immediately by access to a file server the user has never accessed before.

    In a traditional alert-queue SOC: the alert sits in the morning queue. By 9 AM, an analyst picks it up. By 10 AM, they’ve confirmed it’s suspicious. By 11 AM, they’ve initiated containment. The attacker has had eight hours.

    In a BrahmaFusion agentic SOC: within 90 seconds, the AI agent correlates the authentication anomaly with XDR telemetry, identifies the lateral movement pattern, cross-references INDRA CTI for similar TTPs, and executes a Layer 1 playbook: session revocation and endpoint isolation. A Layer 2 investigation summary is generated and queued for analyst review with a complete timeline. The analyst reviews and approves at 9 AM. The incident is already contained.

    Benefits of the Agentic SOC with Peris.ai

    Benefit Outcome
    Automated triage and investigation Eliminates alert queue backlog and fatigue
    Layer 1 autonomous containment Stops known threats in seconds without human review
    Layer 2 AI-generated investigation summaries Analyst reviews conclusions, not raw alerts
    40% SOC cost reduction Documented outcome from BrahmaFusion deployment
    35% analyst workload reduction Documented outcome from Peris.ai IRP deployment

    Conclusion

    The alert queue model served the SOC well for two decades. It is no longer adequate for an environment where attack speed is measured in minutes and alert volume is measured in thousands per day. The agentic SOC is not a future state. Microsoft, Peris.ai, and the organizations running these platforms today are demonstrating that it is the present one.

    If your SOC is still built around a human-reviewed alert queue, you are already behind the operational curve. The transition to an agentic model is not just an efficiency upgrade. It is a structural security improvement.

    Explore the Peris.ai Automation Layer and BrahmaFusion’s no-code AI Playbook Builder at brahma.peris.ai. Visit Peris.ai to see how leading organizations are building the agentic SOC today.

    Frequently Asked Questions

    What is an agentic SOC?

    A security operations center in which AI agents handle detection, investigation, and triage autonomously, escalating to human analysts only for complex or high-stakes decisions. It replaces the human-reviewed alert queue model.

    What are the two layers of the agentic SOC architecture?

    Layer 1 handles known, high-confidence threats with fully automated responses (no human review). Layer 2 handles novel or complex incidents through generative AI investigation, producing summaries that human analysts review and approve.

    Why is the traditional alert queue model failing?

    Alert volume has outpaced human triage capacity, attack speed has outpaced human review cycles, and alert fatigue means genuine threats are regularly missed in high-volume queues.

    How does BrahmaFusion enable the agentic SOC?

    BrahmaFusion provides a no-code AI Playbook Builder, 100+ integrations, and automated response workflows that execute both Layer 1 containment and Layer 2 investigation sequences without requiring custom engineering.

    What is the difference between SOAR and an agentic SOC platform?

    Traditional SOAR executes predefined, rule-based playbooks. Agentic SOC platforms use AI agents that reason, adapt, and handle novel situations that predefined rules cannot anticipate.

  • The Browser Is Now the Battleground: How Chrome Zero-Days Are Targeting Enterprise Users in 2026

    The Browser Is Now the Battleground: How Chrome Zero-Days Are Targeting Enterprise Users in 2026

    Your employees spend more time in Chrome than in any other application. Every SaaS tool, every cloud dashboard, every internal portal runs through the browser. And in March 2026, Google confirmed that two critical Chrome zero-days — CVE-2026-3909 and CVE-2026-3910 — were actively being exploited in the wild before the patch was available.

    The browser has quietly become the most dangerous attack surface in enterprise environments. It runs on every machine. It executes untrusted code constantly. It is the gateway to every cloud application your organization uses. And most security teams do not have meaningful visibility into what happens inside it.

    This post explains why Chrome zero-day exploits have become so valuable, how CVE-2026-3909 and CVE-2026-3910 are weaponized, and what enterprise security teams should do right now to reduce browser-based risk.

    What Are CVE-2026-3909 and CVE-2026-3910?

    CVE-2026-3910 is a type confusion vulnerability in Chrome’s V8 JavaScript and WebAssembly engine. Type confusion occurs when code handles memory allocated for one type of object as if it were a different type, creating conditions for arbitrary read/write operations in memory. In practical terms, a malicious webpage or ad network can trigger CVE-2026-3910 to achieve remote code execution within the Chrome renderer process.

    CVE-2026-3909 is a vulnerability in Chrome’s Skia rendering engine — the graphics library that processes visual elements across the browser. This vulnerability is typically chained with CVE-2026-3910: once the V8 flaw achieves code execution in the renderer, CVE-2026-3909 provides a sandbox escape path, allowing the attacker to break out of Chrome’s security sandbox and reach the underlying operating system.

    Both vulnerabilities were patched in Chrome 134.0.6998.117/118, released March 10, 2026. Both were confirmed with in-the-wild exploitation at the time of disclosure.

    Why Is the Browser Your Most Dangerous Attack Surface?

    The Browser Runs Untrusted Code Constantly

    Every webpage your employees visit executes JavaScript in the browser context. Unlike a desktop application that runs static, reviewed code, the browser is designed to run code from millions of unvetted sources. This is fundamentally different from any other application in your environment, and it is the core reason browsers are so attractive to exploit kit developers.

    A compromised ad network, a watering hole attack on an industry publication, a malicious script injected into a legitimate third-party service — all of these can deliver exploit payloads to your users without any download, attachment, or click-through required. The browser’s trust model was designed for the consumer web and is not compatible with enterprise security requirements.

    The SaaS Attack Surface Amplifier

    81% of corporate data now lives in SaaS applications accessed via browser, according to 2026 cloud security research. Compromising the browser does not just give an attacker code execution on the endpoint — it gives them authenticated access to every web application that browser has an active session with: email, file storage, project management tools, HR systems, financial platforms, and internal dashboards.

    This is why browser zero-days command extraordinary prices on dark web markets: $1 million to $3 million for a full Chrome remote code execution plus sandbox escape chain, according to Zerodium’s 2025/2026 pricing. That pricing reflects the actual value of access: one successful browser exploit can yield access to an entire organization’s cloud infrastructure without touching a single traditional endpoint.

    What Happens When Teams Don’t Solve This

    The enterprise patch lag for browser updates averages 14 days after release. Critical vulnerability exploitation begins within 4.76 days of disclosure. The gap is 9 days of structural exposure, even in organizations that take browser patching seriously.

    For organizations that treat browser updates as low-priority IT maintenance, the exposure window can stretch to weeks or months. During that window, a single visit to a compromised website delivers full compromise to any unpatched user.

    How CVE-2026-3910 Is Weaponized: The V8 Exploit Chain

    For security teams who need to understand the mechanics to inform detection strategy, here is how a V8 type confusion exploit typically operates:

    • Trigger the type confusion. Malicious JavaScript manipulates the V8 engine’s object type tracking through a carefully crafted sequence of operations.
    • Achieve arbitrary read/write. The type confusion creates a “confused” object whose size metadata is incorrect, allowing the attacker to read from and write to arbitrary memory locations.
    • Bypass ASLR. The attacker uses the arbitrary read capability to leak memory addresses, defeating Address Space Layout Randomization.
    • Shellcode execution. With ASLR defeated and write primitives established, the attacker overwrites a function pointer to redirect execution to shellcode.
    • Sandbox escape via CVE-2026-3909. Chrome’s renderer sandbox prevents direct OS access. CVE-2026-3909 provides the escape path via a Skia rendering flaw that reaches GPU process memory and subsequently the OS kernel.

    Old Way vs. New Way: Browser Security Posture

    Old Approach Modern Approach
    Patch browsers on monthly IT cycle Force-update browsers within 24 hours of critical patch
    Block known malicious domains Add browser isolation for high-risk browsing sessions
    Rely on antivirus for post-exploit detection Deploy EDR with behavioral heuristics for renderer process anomalies
    Hope employees don’t visit malicious sites Assume users will visit compromised sites and build detection around post-exploit behavior
    No visibility into browser process activity EDR monitoring of Chrome renderer, GPU process, and child process spawning
    Single-factor SaaS authentication MFA on every SaaS app to limit post-exploit session hijacking

    How Peris.ai Addresses the Browser Threat

    Peris.ai’s integrated platform addresses browser threats across three layers:

    EDR is the primary detection layer for browser exploit chains. Peris.ai’s EDR monitors Chrome renderer process behavior in real time: heap spray activity, unusual memory allocation patterns, child process spawning from the browser context (a classic post-exploitation indicator), and network connections initiated by the renderer process to unexpected destinations. These behavioral signals are detectable without CVE signatures and fire whether the exploit is known or novel.

    INDRA CTI tracks browser exploit kit activity across the threat landscape. When new Chrome zero-day exploitation campaigns emerge, INDRA CTI provides IOCs for the C2 infrastructure, the exploit delivery domains, and the post-exploitation tooling.

    BrahmaFusion automates the response. When EDR detects a compromised browser session, BrahmaFusion’s AI Playbook Builder can automatically isolate the affected endpoint, revoke active SaaS sessions via integrated identity provider APIs, notify the security team, and open an incident case in the Peris.ai IRP, all before an analyst has completed reviewing the first alert.

    Enterprise Browser Security Hardening: A Practical Checklist

    • Force-update Chrome immediately. Patch to 134.0.6998.117 or later. Do not wait for your standard patch cycle for CVSS 8.0+ browser vulnerabilities.
    • Enable Chrome’s Enhanced Safe Browsing. This provides real-time URL checking against Google’s threat databases and is a zero-cost hardening measure.
    • Restrict browser extensions. Enforce allowlisting of approved extensions via Google Workspace or Microsoft Intune policies. Unauthorized extensions are a parallel compromise vector.
    • Monitor child processes spawned from Chrome. PowerShell, CMD, or WScript spawned as a child of the Chrome renderer process is a near-certain indicator of successful exploitation.
    • Deploy behavioral EDR on all endpoints. Signature-based detection cannot catch novel exploit chains. Behavioral heuristics tied to the renderer process are the effective detection layer.
    • Implement MFA on all SaaS applications. Post-exploitation session hijacking is the most common browser exploit follow-on. MFA limits the blast radius of a compromised browser session.
    • Evaluate browser isolation. Remote browser isolation (RBI) eliminates browser zero-day risk by running browser code in an isolated cloud environment. Adoption is still under 12% of enterprises, representing a significant untapped risk reduction opportunity.

    Benefits at a Glance

    Capability Outcome
    EDR renderer process monitoring Detects exploit chains via behavioral heuristics, not signatures
    INDRA CTI browser exploit intelligence IOC context for Chrome exploit campaigns
    BrahmaFusion automated isolation Endpoint contained and SaaS sessions revoked within minutes
    Peris.ai IRP case management Structured investigation for post-exploit forensics
    47% cost savings Measured across Peris.ai client portfolio for contained incidents

    Conclusion

    CVE-2026-3909 and CVE-2026-3910 are a reminder that the browser is not just an application — it is the primary attack surface for the modern enterprise. With 81% of corporate data in SaaS apps and every employee spending most of their day in Chrome, the browser is the highest-value target in your environment.

    Patch immediately. Deploy behavioral EDR. And accept that the question is not whether your users will encounter browser exploit attempts — it is whether your detection stack will catch what happens after one succeeds.

    Explore how Peris.ai’s EDR and BrahmaFusion protect enterprise endpoints from browser-based threats. Visit peris.ai/blog for more enterprise security insights, or explore the full platform at peris.ai.

    Frequently Asked Questions

    What are CVE-2026-3909 and CVE-2026-3910?

    CVE-2026-3910 is a V8 JavaScript engine type confusion vulnerability enabling remote code execution in Chrome. CVE-2026-3909 is a Skia rendering engine flaw used to escape Chrome’s sandbox. Both were exploited in the wild and patched in Chrome 134.0.6998.117 in March 2026.

    Why are Chrome zero-days so expensive on dark web markets?

    A full Chrome RCE plus sandbox escape chain is valued at $1M to $3M because it grants code execution on the victim’s machine and authenticated access to all open browser sessions, effectively bypassing SaaS authentication for every cloud app the user is logged into.

    How can EDR detect Chrome exploit chains without a CVE signature?

    Behavioral EDR monitors Chrome’s renderer process for heap spray activity, unusual memory allocations, unexpected child process spawning (e.g., PowerShell from Chrome), and outbound network connections from the renderer, all of which are indicators of post-exploitation regardless of the specific vulnerability exploited.

    What is the enterprise browser patch lag in 2026?

    Enterprises take an average of 14 days to deploy browser patches after release. Since exploitation of disclosed critical vulnerabilities begins within 4.76 days, organizations face approximately 9 days of structural exposure even with active patch programs.

    What is remote browser isolation (RBI) and how does it help?

    Remote browser isolation runs browser execution in an isolated cloud or server environment, sending only a visual stream to the user’s endpoint. This eliminates local code execution entirely, making browser zero-day exploits ineffective. Adoption remains below 12% of enterprises as of 2026.

  • CVE-2026-42897: How an Unpatched Exchange XSS Becomes a Full Network Compromise

    CVE-2026-42897: How an Unpatched Exchange XSS Becomes a Full Network Compromise

    CVE-2026-42897 is an active CVSS 8.1 XSS flaw in Exchange Server with no patch. Here is your action plan.

    On May 14, 2026, Microsoft disclosed CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Exchange Server 2016, 2019, and the Subscription Edition. This is not a theoretical risk. The flaw scores 8.1 on the CVSS scale, enables unauthenticated network exploitation, and Microsoft has not released a patch. The only available mitigation is the Exchange Emergency Mitigation (EM) Service workaround.

    If your organization runs on-premises Exchange, this is not a disclosure to bookmark for later. It is an active exposure to remediate today.

    What Is CVE-2026-42897?

    CVE-2026-42897 is classified as an improper neutralization of input during web page generation, a reflected or stored XSS flaw in the Exchange web interface. The attack vector is network-accessible and requires no authentication from the attacker.

    In practical terms: an attacker with network-level access to your Exchange Server can craft a malicious HTTP request, inject script into web pages served by Exchange, and use that access to steal session tokens, impersonate users, or escalate to administrative privileges.

    Key technical facts:

    • CVSS score: 8.1 (High)
    • Affected versions: Exchange Server 2016, 2019, Subscription Edition (all on-premises)
    • Attack vector: Network, unauthenticated
    • Flaw class: CWE-79, Improper Neutralization of Input During Web Page Generation (XSS)
    • Patch status: None available as of May 14, 2026
    • Available workaround: Exchange Emergency Mitigation (EM) Service

    Why On-Premises Exchange Remains the Highest-Value Target in Enterprise Networks

    Exchange Server holds email communications, calendar data, contact directories, and deep integration with Active Directory. A compromise of Exchange is, in most organizations, a compromise of the communication backbone and a gateway to lateral movement across the entire network.

    History confirms the pattern. ProxyLogon (2021) and ProxyShell (2021) were exploited within hours of disclosure and resulted in widespread ransomware deployment and persistent access.

    What Happens When Teams Do Not Act Immediately

    • Unpatched Exchange servers are indexed by Shodan and Censys within hours of a CVE disclosure
    • Session token theft via XSS enables attacker access under legitimate user credentials, bypassing perimeter controls
    • Once inside email, attackers conduct BEC campaigns, access credential-sharing threads, and harvest lateral movement intelligence
    • Dwell time on undetected Exchange compromises averaged 197 days in 2025

    How Does CVE-2026-42897 Escalate to a Full Network Compromise?

    Stage 1: Reconnaissance. The attacker scans for on-premises Exchange servers.

    Stage 2: XSS injection. A crafted HTTP request exploits the improper input neutralization. The injected script executes in the victim’s browser context.

    Stage 3: Session token theft. The script exfiltrates the victim’s authentication session token. For administrator accounts, this is immediately catastrophic.

    Stage 4: Authenticated access. Using the stolen token, the attacker impersonates the victim: reads emails, creates inbox rules for persistence, exports contact lists, probes credential threads.

    Stage 5: Lateral movement. With credentials and organizational intelligence from email, the attacker traverses the network using Exchange’s Active Directory integration as a map.

    Stage 6: Ransomware or data exfiltration. With domain-level access established, the attacker deploys ransomware, exfiltrates data for extortion, or establishes long-term persistence.

    Context: May 2026 Enterprise Infrastructure Zero-Day Wave

    CVE-2026-42897 did not arrive alone. In the same disclosure window, Microsoft disclosed CVE-2026-45585, a BitLocker bypass (CVSS 6.8). The same week confirmed active exploitation of CVE-2026-20182, a critical authentication bypass in Cisco Catalyst SD-WAN Controllers. PraisonAI’s CVE-2026-44338 (CVSS 7.3) was exploited within four hours of its disclosure, illustrating how compressed the window between disclosure and attack has become.

    Old Way vs. New Way: Exchange Security Posture

    Approach Old Way New Way
    Patch management Wait for Patch Tuesday Emergency response to zero-day disclosures
    XSS mitigation Rely on WAF rules Enable Exchange EM Service immediately
    CVE awareness Read security blogs Real-time intelligence feeds
    Detection Periodic SIEM review Continuous behavioral monitoring
    Incident response Manual ticket creation Automated playbook on Exchange anomaly
    Attack surface Periodic external scan Continuous ASM with CVE correlation

    How Peris.ai Closes the CVE-2026-42897 Gap

    BimaRed continuously scans your external attack surface, including all exposed Exchange endpoints. When CVE-2026-42897 was disclosed, BimaRed correlates your Exchange version inventory against the CVE profile and flags affected assets within hours, giving your team a prioritized remediation list before an attacker finds you.

    INDRA CTI delivers real-time zero-day intelligence feeds. When a new Exchange CVE drops, INDRA CTI alerts your SOC with indicators of compromise, known attack patterns, and the threat actor profiles most likely to exploit the flaw.

    Peris.ai IRP provides structured incident response workflow. If compromise is detected, IRP creates a unified case aggregating all related alerts, assigns investigation tasks, and tracks remediation through resolution, mapped to MITRE ATT&CK.

    XDR monitors for post-exploitation behaviors: abnormal inbox rule creation, lateral movement from Exchange-connected accounts, privilege escalation attempts, and unusual data access patterns across endpoints and cloud services.

    Use Case: Rapid Triage of CVE-2026-42897 Exposure

    A financial services firm running Exchange Server 2019 receives an INDRA CTI alert at 09:00 on May 14, 2026, tagging CVE-2026-42897 as actively researched by known threat actors. BimaRed immediately correlates the firm’s external Exchange endpoints against the CVE profile and flags three servers as potentially exposed. The security team activates the Exchange EM Service workaround across all three servers by 11:00. XDR continues monitoring for session anomalies and lateral movement through the weekend. Total response window: two hours from disclosure to mitigation deployment. No compromise detected.

    Benefits

    Benefit Outcome
    Real-time CVE intelligence Team knows about CVE-2026-42897 within minutes of disclosure
    Automated attack surface correlation Exposed Exchange assets flagged without manual scanning
    Structured incident response IRP ensures no remediation step is missed
    Continuous behavioral monitoring XDR catches post-exploitation activity that static controls miss

    Conclusion

    CVE-2026-42897 separates prepared organizations from compromised ones. There is no patch. The attack surface is large. The exploitation path is well-understood. Your response window is hours, not days.

    Peris.ai’s combination of BimaRed, INDRA CTI, XDR, and IRP gives your security team the tools to respond at machine speed. Explore the Peris.ai security operations platform at peris.ai/blog and learn how organizations across ASEAN are defending against zero-day threats before they escalate.

    FAQ

    What is CVE-2026-42897?

    CVE-2026-42897 is a CVSS 8.1 cross-site scripting vulnerability in Microsoft Exchange Server 2016, 2019, and Subscription Edition, disclosed May 14, 2026. It allows unauthenticated attackers with network access to inject malicious scripts into Exchange web pages.

    Is there a patch for CVE-2026-42897?

    As of the May 14, 2026 disclosure, no patch exists. The only available mitigation is enabling the Exchange Emergency Mitigation (EM) Service.

    Which Exchange versions are affected by CVE-2026-42897?

    Exchange Server 2016, 2019, and Subscription Edition (all on-premises). Exchange Online (Microsoft 365) is not affected.

    How quickly can attackers exploit CVE-2026-42897?

    Based on the pattern of recent enterprise zero-days, exploitation attempts typically begin within hours of public disclosure. PraisonAI’s CVE-2026-44338 was exploited within four hours of its disclosure in the same timeframe.

    How does Peris.ai help with Exchange zero-day response?

    BimaRed identifies exposed Exchange endpoints and correlates them with CVE profiles. INDRA CTI delivers real-time zero-day alerts. XDR monitors post-exploitation behavior. IRP manages the incident response workflow from detection through remediation.