- Cybersecurity Docket
- Posts
- Trump Re-Nominates Sean Plankey to Lead CISA
Trump Re-Nominates Sean Plankey to Lead CISA
Plus cyber incidents rank as the number one global business risk for the fifth consecutive year.

Good morning! Here’s what’s up.

People
Nicole Ozer has joined the California Privacy Protection Agency Board.

Clips ✂️
Sean Plankey re-nominated to lead CISA
President Donald Trump re-nominated Sean Plankey to lead the Cybersecurity and Infrastructure Security Agency on Tuesday, after Plankey’s bid for the position ended last year stuck in the Senate. It’s not clear whether or how Plankey’s resubmitted nomination will overcome the hurdles that left many observers convinced his chance of becoming CISA director had likely ended, but it does definitively signal that the Trump administration still wants Plankey to have the job. Plankey’s nomination was included in a batch sent to the Senate announced on Tuesday.
👉 CISA has been without a Senate-confirmed director since January 2025.
US cybersecurity weakened by congressional delays despite Plankey renomination
The White House moved to restart an urgent stalled priority by renominating well-regarded Coast Guard and Energy Department cyber veteran Sean Plankey as CISA director. Experts say the step offers some relief but does not go far enough to resolve the broader congressional inaction still straining the nation’s cyber defenses.
Some have faulted the White House for a lack of engagement in cyber issues and their advancement through Congress, while others say congressional dysfunction is the larger problem. Referring to the Trump administration’s broader approach to cyber policy, Jim Lewis, SVP and director of the technology and public policy program at the Center for Strategic and International Studies (CSIS), tells CSO, “Cyber isn’t a priority for these guys.”
Cyber tops global business risks as AI surges
Allianz Risk, part of the Allianz Group and a provider of insurance solutions and risk consulting for commercial and corporate clients, has published the Allianz Risk Barometer 2026, outlining the most significant risks expected to affect businesses worldwide over the coming year.
The findings show that cyber incidents continue to be the dominant concern for organisations, while artificial intelligence (AI) has rapidly become one of the most prominent emerging risks.
According to Allianz Risk, cyber incidents rank as the number one global business risk for the fifth consecutive year, cited by 42% of survey participants. This is the highest level recorded for cyber risk since the barometer was introduced and reflects a growing gap between cyber threats and all other risk categories.
House subcommittee hearing examines offensive cyber operations, limits of cyber deterrence
The U.S. Subcommittee on Cybersecurity and Infrastructure Protection met Tuesday to examine how the nation can strengthen its approach to offensive cyber operations within a broader national security framework, including the evolving roles of federal agencies and the private sector. The hearing underscored a reality that policymakers increasingly acknowledge that deterrence in cyberspace is not credible without lawful, clearly defined, and operational offensive cyber capabilities.
Witnesses at the hearing include Joe Lin, co-founder and chief executive officer at Twenty Technologies; Emily Harding, vice president, defense and security department at the Center for Strategic and International Studies; Frank Cilluffo, director at the McCrary Institute for Cyber and Critical Infrastructure Security, Auburn University; and Drew Bagley, chief privacy officer at CrowdStrike.
“Defense alone is not sufficient. Resilience alone is not sufficient. Public attribution alone is not sufficient,” Andy Ogles, a Tennessee Republican and chairman of the subcommittee, wrote in his opening statement. “For more than a decade, the United States has invested heavily in cyber defense, information sharing, and resilience. Those investments are necessary, and they have improved our ability to withstand attacks. But they have not altered adversary behavior. Malign cyber actors continue to penetrate American networks, steal sensitive data, surveil communications, and position themselves inside critical infrastructure with little fear of meaningful consequence.”
Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say
Chinese authorities have told domestic companies to stop using cybersecurity software made by roughly a dozen firms from the U.S. and Israel due to national security concerns, two people briefed on the matter said.
As trade and diplomatic tensions flare between China and the U.S. and both sides vie for tech supremacy, Beijing has been keen to replace Western-made technology with domestic alternatives.
The U.S. companies whose cybersecurity software has been banned include Broadcom-owned (AVGO.O), opens new tab VMware, Palo Alto Networks (PANW.O), opens new tab and Fortinet (FTNT.O), opens new tab, while the Israeli companies include Check Point Software Technologies (CHKP.O), opens new tab, the sources said.
AI Reality Check: What Business Leaders Think of Artificial Intelligence
With artificial intelligence dominating global business news, we wanted to gain insight into how corporate executives are thinking about AI implementation. Is AI a good or bad thing? How much are they using AI, and what benefits are they seeing? How are they adjusting organizational processes and structures in light of AI?
In conjunction with The Official Board, we sent a survey to corporate executives in June 2025. We received 240 responses, well diversified by industry and region. What we learned is that there is a disconnect between the splashy AI news headlines and what executives are seeing in practice. According to these executives, the AI myths do not reflect the AI reality.
'Most Severe AI Vulnerability to Date' Hits ServiceNow
Authentication issues in ServiceNow potentially opened the door for arbitrary attackers to gain full control over the entire platform and access to the various systems connected to it.
ServiceNow is a Fortune 500 company that, according to its promotional materials, acts as an IT services management platform for 85% of the companies that comprise the rest of the Fortune 500. That alone makes it a critical supply chain risk to the US business sector.
Beyond that, ServiceNow is deeply integrated into its customers' broader IT infrastructure, more so than most vendors: ServiceNow's tentacles spread through HR, customer service, security, and the various other systems that keep a company running. To an attacker, it's both an ideal launchpad for lateral movement and a treasure trove of sensitive operational and customer data in its own right.
