{"id":34297,"date":"2025-11-18T09:19:53","date_gmt":"2025-11-18T14:19:53","guid":{"rendered":"https:\/\/poole.ncsu.edu\/thought-leadership\/?page_id=34297"},"modified":"2026-05-04T11:20:26","modified_gmt":"2026-05-04T15:20:26","slug":"managing-cyber-risk","status":"publish","type":"page","link":"https:\/\/poole.ncsu.edu\/thought-leadership\/managing-cyber-risk\/","title":{"rendered":"Managing Cyber Risk"},"content":{"rendered":"\n\n\n\n\n<h2 class=\"wp-block-heading\">Risk Meets Reality<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Editor\u2019s Note: This is the latest in a series from the Poole College of Management and <a href=\"https:\/\/erm.ncsu.edu\/\">the Enterprise Risk Management Initiative<\/a> that taps experts from across NC State to explore societal issues through the lens of risk management.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The scope and cost of cyberattacks are staggering. Global losses from data breaches are measured in the hundreds of billions, and the average breach costs an organization $4.4 million, <a href=\"https:\/\/www.ibm.com\/reports\/data-breach\">according to IBM<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But the cost of cyber risk is only one part of the picture. Cyberattacks affect every industry; in the last few months alone, they&#8217;ve <a href=\"https:\/\/www.wsj.com\/business\/airlines\/european-airline-stocks-fall-after-cyberattacks-on-airports-dd2f2f37\" data-type=\"link\" data-id=\"https:\/\/www.wsj.com\/business\/airlines\/european-airline-stocks-fall-after-cyberattacks-on-airports-dd2f2f37\">brought European air travel to a standstill<\/a> and <a href=\"https:\/\/www.wsj.com\/business\/autos\/a-cyberattack-crippled-range-rover-production-the-reboot-is-proving-tough-09663dcf?mod=lead_feature_below_a_pos1\" data-type=\"link\" data-id=\"https:\/\/www.wsj.com\/business\/autos\/a-cyberattack-crippled-range-rover-production-the-reboot-is-proving-tough-09663dcf?mod=lead_feature_below_a_pos1\">crippled Jaguar Land Rover&#8217;s automobile production<\/a>. Those were malicious attacks, but unintentional cybersecurity breaches are a major source of risk, too.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;It&#8217;s inevitable,&#8221; said Laurie Williams, Goodnight Distinguished University Professor of Security Sciences and director of NC State&#8217;s <a href=\"https:\/\/s3c2.org\/\">Secure Software Supply Chain Center<\/a> (S3C2). &#8220;There are vulnerabilities, and you&#8217;re going to have to react to them.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">S3C2 and the <a href=\"https:\/\/wspr.csc.ncsu.edu\/\">Wolfpack Security and Privacy Research Lab<\/a> (WSPR) \u2014both part of the computer science department \u2014 are two major NC State research efforts that develop tools and approaches to help protect software makers and users from malicious and unintentional threats.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Risk Meets Reality: Managing Cyber Risk\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/Z3EsNDQg1sE?feature=oembed&#038;enablejsapi=1&#038;origin=https:\/\/poole.ncsu.edu\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><figcaption class=\"wp-element-caption\">Mark Beasley, Alan T. Dickson Professor and Director of the Enterprise Risk Management Initiative at the Poole College of Management, recently interviewed NC State computer scientists Laurie Williams and William Enck about cybersecurity risks business leaders may want to monitor. In this video, they outline strategies and techniques business leaders can take to enhance organizational agility and resilience in the face of inherent cyber vulnerabilities.<\/figcaption><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Open Source, AI and Vulnerabilities<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Every piece of software is built on \u2014 and with \u2014 layers of other pieces of software. Each component in the software supply chain, from databases to developer tools, could introduce vulnerabilities for the organization that creates the software and the customers who use it.<\/p>\n\n\n<div class=\"ncst-fancy-paragraph-fifty is-text wp-block-ncst-fancy-paragraph\">\n      \n<div class=\"text-only wp-block-ncst-fp-accompaniment\">\n    \n\n<p class=\"wp-block-paragraph\">Eighty percent of any piece of software, Williams said, is made by third parties. And many of the links in that software supply chain are open-source. Open-source software is written by a person or community and shared for others to use or adapt the code.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And it&#8217;s an essential part of the modern software ecosystem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cNearly every organization is relying on open-source software,\u201d said Will Enck, Goodnight Distinguished Professor in Security Sciences and director of the WSPR Lab. \u201cTo some extent, it\u2019s foolish not to. Reimplementing what already exists is reinventing the wheel.&#8221;<\/p>\n\n\n  <\/div>\n\n\n<div class=\"wp-block-ncst-fp-accompaniment\">\n    \n<aside class=\"floated-spotlight-aside-container\">\n  <div class=\"floated-spotlight-contents\">\n    <a\n    class=\"ncst-content-card wp-block-ncst-fp-spotlight-card has-custombg-two-background-color with-image with-cta\"\n    href=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2026\/05\/Developing-a-Cyber-Breach-Response-Playbook-SEPT-22-2025.docx\"\n  >\n  \n          <div class=\"content-card__image-container\">\n        <div class=\"content-card__image-background\">\n          <img loading=\"lazy\" decoding=\"async\" width=\"1500\" height=\"844\"\n            class=\"content-card__image wp-image-34326\"\n            alt=\"\"\n            src=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Cyber-risk-ERM-promo-image-1.jpg\"\n            style=\"aspect-ratio: 16\/9; object-fit: cover; \"\n srcset=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Cyber-risk-ERM-promo-image-1.jpg 1500w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Cyber-risk-ERM-promo-image-1-300x169.jpg 300w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Cyber-risk-ERM-promo-image-1-1024x576.jpg 1024w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Cyber-risk-ERM-promo-image-1-768x432.jpg 768w\" sizes=\"auto, (max-width: 1500px) 100vw, 1500px\" \/>\n        <\/div>\n      <\/div>\n    \n    <div class=\"content-card__text-container\">\n      \n                        <h3 class=\"content-card__headline\">Probe Your Cyber Risk<\/h3>\n              \n\n              \n\t      \t        <p class=\"content-card__teaser\">Vulnerabilities are inevitable. Start aligning people and processes to address them with our conversation guide.<\/p>\n\t      \t    \n              <p class=\"content-card__cta\"><span class=\"text\">Download the tool<\/span><span class=\"arrow-indicator\"><svg class=\"wolficon wolficon-arrow-right-bold\" role=\"img\"  aria-hidden=\"true\">\n\t\t\t\n\t\t\t<use xlink:href=\"#wolficon-arrow-right-bold\">\n\t\t<\/svg><\/span><\/p>\n          <\/div>\n\n  <\/a>\n  <\/div>\n<\/aside>\n\n\n  <\/div>\n\n\n    <\/div>\n  \n\n\n\n<p class=\"wp-block-paragraph\">Increasingly, though, open-source components of the software supply chain are being targeted by attackers, Enck said. Bad actors can corrupt open-source file libraries with tactics that look a lot like phishing scams, Enck said. Think of an email that looks like official communication from Amazon or Microsoft, but includes links that give the sender access to the user\u2019s personal information or control over their computer.<\/p>\n\n\n<blockquote class=\"has-custombg-six-text-color wp-block-ncst-testimonial\">\n        <div class=\"testimonial-container\">\n          <p class=\"testimonial__content\">&#8220;You\u2019ve got to make sure that the ecosystem of open-source software that we depend on is being maintained.&#8221;<\/p>\n          <div class=\"testimonial__attribution-container has-image\">\n                          <figure class=\"testimonial__image-container\">\n                <img width=\"150\" height=\"150\" fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-34319\" src=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/William-Enck-1500x844-1-150x150.jpg\" alt=\"William Enck\">\n              <\/figure>\n                        <div class=\"attribution-title-name-container\">\n               \n                <p class=\"attribution-name\">William Enck<\/p>\n                             \n                <p class=\"attribution-title\">Goodnight Distinguished Professor in Security Sciences\u00a0<br>Director, Wolfpack Security and Privacy Research Lab<\/p>\n                                        <\/div>\n          <\/div>\n        <\/div>\n      <\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Hackers make similar attempts on software developers by subtly loading corrupted libraries into a popular open-source package, Enck said. These attacks can play out over long time periods. In February 2024, users of a popular Linux utility called xz found a sophisticated backdoor. The malicious actor who added it had spent three years earning the trust of the people who managed the xz utility. The backdoor was only found when an xz user working at Microsoft noticed that it was running a few hundred milliseconds slower than usual.<\/p>\n\n\n<div class=\"wp-block-ncst-parallax-container\">\n    <div\n      class=\"ncst-parallax-container__container ncst-parallax-container__image\"\n      style=\"background-image:url(https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/09\/PTL-ERM-risk-survey.jpg); background-position: center center;\">\n              <div class=\"ncst-parallax-container__content \" style=\"visibility:visible\">\n          \n<div class=\"wp-block-ncst-cta-statement\">\n    <div class=\"ncst-cta-statement__container\">\n      <p class=\"ncst-cta-statement__statement\"><\/p>\n      \n\n\n    <\/div>\n  <\/div>\n\n\n        <\/div>\n          <\/div>\n  <\/div>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s incumbent on users of open-source software to actively support the communities that maintain it, Enck said. That support could be financial, or it could mean encouraging their teams to contribute to those communities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThere&#8217;s this saying that you need to think about open-source software as &#8216;free as in puppy, not free as in beer,&#8217;\u201d Enck said. \u201cThere&#8217;s a maintenance cost that goes with it, and it&#8217;s not just making sure you&#8217;re getting the security patches. You\u2019ve got to make sure that the ecosystem of the software that we depend on is being maintained.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Artificial intelligence compounds the challenge of monitoring software supply chain risk. Increasingly, software developers use coding assistants to speed up their code development. In doing so, they may be sacrificing security. The data those assistants are trained on, Williams said, is vulnerable. Existing code makes up a large share of that training data, and it can be compromised accidentally (if the underlying code isn\u2019t secure) or intentionally (by bad actors injecting vulnerabilities).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cA lot of people using coding assistants say they\u2019re 10x more productive,\u201d Williams said. \u201cBut you&#8217;d better check the security of the code you\u2019re generating.&#8221;<\/p>\n\n\n<div class=\"ncst-askew-media-text has-custombg-five-background-color wp-block-ncst-mini-story\">\n    <div class=\"ncst-askew-media-text__container\">\n      \n<div class=\"wp-block-ncst-text-column\">\n    <h2 class=\"ncst-text-column__heading\">Turning Risk Into Opportunity<\/h2>\n    <p class=\"ncst-text-column__teaser\">Businesses, markets and the climate itself are changing faster than ever. NC State&#8217;s Enterprise Risk Management Initiative offers organizations the tools, methodologies and expertise to thrive in an endlessly evolving world. <\/p>\n          \n<div class=\"is-text wp-block-ncst-buttons\">\n    \n<div class=\"is-style-secondary wp-block-ncst-button\">\n      <a\n        class=\"ncst-block__button-link btn\"\n        href=\"https:\/\/erm.ncsu.edu\/\"\n        data-ncst-lightbox=\"false\"\n                      >\n                  <span class=\"text\">Learn how<\/span><span class=\"arrow-indicator\"><svg class=\"wolficon wolficon-arrow-right-bold\" role=\"img\"  aria-hidden=\"true\">\n\t\t\t\n\t\t\t<use xlink:href=\"#wolficon-arrow-right-bold\">\n\t\t<\/svg><\/span>\n              <\/a>\n    <\/div>\n  \n\n  <\/div>\n\n\n      <\/div>\n\n\n<div class=\"wp-block-ncst-media\">\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2024\/11\/ERM-summit-group-1024x576.jpg\" alt=\"group of people talking at ERM Roundtable Summit\" class=\"wp-image-32963\" srcset=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2024\/11\/ERM-summit-group-1024x576.jpg 1024w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2024\/11\/ERM-summit-group-300x169.jpg 300w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2024\/11\/ERM-summit-group-768x432.jpg 768w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2024\/11\/ERM-summit-group.jpg 1500w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n<\/div>\n\n    <\/div>\n  <\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Improving Your Risk Posture<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As organizations in every sector deepen their dependence on software, cyber risk management must become a core part of enterprise strategy. Williams and Enck agree that the question isn\u2019t whether vulnerabilities will appear, but when \u2014 and how prepared an organization is to respond.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Companies that maintain awareness of emerging threats and have defined processes for identifying and remediating vulnerabilities are far better positioned to recover quickly. In contrast, those without such systems often spend months struggling to contain the damage.<\/p>\n\n\n<blockquote class=\"has-custombg-six-text-color wp-block-ncst-testimonial\">\n        <div class=\"testimonial-container\">\n          <p class=\"testimonial__content\">&#8220;Security is everyone&#8217;s job. It has to be built in from the beginning.&#8221;<\/p>\n          <div class=\"testimonial__attribution-container has-image\">\n                          <figure class=\"testimonial__image-container\">\n                <img width=\"150\" height=\"150\" fetchpriority=\"high\" decoding=\"async\" class=\"wp-image-34318\" src=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Laurie-Williams-1500x844-1-150x150.jpg\" alt=\"Laurie Williams\">\n              <\/figure>\n                        <div class=\"attribution-title-name-container\">\n               \n                <p class=\"attribution-name\">Laurie Williams<\/p>\n                             \n                <p class=\"attribution-title\">Goodnight Distinguished University Professor of Security Sciences<br>Co-Director, Secure Software Supply Chain Center<\/p>\n                                        <\/div>\n          <\/div>\n        <\/div>\n      <\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cComputers have gotten smaller, and software is running in small devices connected wirelessly to the cloud. We don\u2019t see those connections \u2014 but they\u2019re everywhere: in finance, transportation and public utilities.\u201d Given that ubiquity, Enck argues, cybersecurity spending shouldn\u2019t be seen as a cost center but as essential infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Education and awareness are also key. Williams advocates for company-wide security education and clear accountability at every stage of software development.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSecurity is everyone\u2019s job,\u201d she said. \u201cThere can\u2019t be a mindset of, \u2018I\u2019ll build the functionality and someone else will find the vulnerabilities.\u2019 It has to be built in from the beginning.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5 Key Topics for Boards and Executives<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Cyber criminals increasingly target popular open-source software to embed malicious code. Board and CEOs can improve their risk posture by discussing these topics with their CTOs, according to Enterprise Risk Management Initiative Director Mark Beasley:<\/p>\n\n\n<div class=\"is-text wp-block-ncst-accordion\" >\n    <div class=\"accordion isLinked\" id=\"ncst-accordion-52y9vw\">\n          \n<details class=\"wp-block-ncst-accordion-item\" name=\"52y9vw\"  >\n      <summary class=\"accordion-item__header\">\n        <span class=\"accordion-item__expansion-indicator\">\n          <span class=\"ncst-plus-minus-toggle\"><\/span>\n        <\/span>\n                  <h2 class=\"accordion-item__label h6\">Dependence on open-source software<\/h2>\n              <\/summary>\n      <p>\n        \n\n<p class=\"wp-block-paragraph\">To what extent are our most critical software systems comprised of open-source software components?<\/p>\n\n\n      <\/p>\n  <\/details>\n\n\n<details class=\"wp-block-ncst-accordion-item\" name=\"52y9vw\"  >\n      <summary class=\"accordion-item__header\">\n        <span class=\"accordion-item__expansion-indicator\">\n          <span class=\"ncst-plus-minus-toggle\"><\/span>\n        <\/span>\n                  <h2 class=\"accordion-item__label h6\">Software supply chain security<\/h2>\n              <\/summary>\n      <p>\n        \n\n<p class=\"wp-block-paragraph\">How are we identifying and monitoring potential vulnerabilities in the open-source software we use for key operations?<\/p>\n\n\n      <\/p>\n  <\/details>\n\n\n<details class=\"wp-block-ncst-accordion-item\" name=\"52y9vw\"  >\n      <summary class=\"accordion-item__header\">\n        <span class=\"accordion-item__expansion-indicator\">\n          <span class=\"ncst-plus-minus-toggle\"><\/span>\n        <\/span>\n                  <h2 class=\"accordion-item__label h6\">Assessing risk from third-party products<\/h2>\n              <\/summary>\n      <p>\n        \n\n<p class=\"wp-block-paragraph\">When we evaluate vendor software products, to what extent do we assess their use of open-source components and how they monitor ongoing vulnerabilities that might be in their software code?<\/p>\n\n\n      <\/p>\n  <\/details>\n\n\n<details class=\"wp-block-ncst-accordion-item\" name=\"52y9vw\"  >\n      <summary class=\"accordion-item__header\">\n        <span class=\"accordion-item__expansion-indicator\">\n          <span class=\"ncst-plus-minus-toggle\"><\/span>\n        <\/span>\n                  <h2 class=\"accordion-item__label h6\">Procedures and processes<\/h2>\n              <\/summary>\n      <p>\n        \n\n<p class=\"wp-block-paragraph\">What procedures do we have in place to ensure we are updating our software with patches on a timely basis when new vulnerabilities are disclosed?<br><\/p>\n\n\n      <\/p>\n  <\/details>\n\n\n<details class=\"wp-block-ncst-accordion-item\" name=\"52y9vw\"  >\n      <summary class=\"accordion-item__header\">\n        <span class=\"accordion-item__expansion-indicator\">\n          <span class=\"ncst-plus-minus-toggle\"><\/span>\n        <\/span>\n                  <h2 class=\"accordion-item__label h6\">Ongoing cybersecurity assesment<\/h2>\n              <\/summary>\n      <p>\n        \n\n<p class=\"wp-block-paragraph\">Do we regularly conduct security testing that includes open-source components?<br><\/p>\n\n\n      <\/p>\n  <\/details>\n\n\n    <\/div>\n  <\/div>\n\n\n<div class=\"ncst-labeled-section wp-block-ncst-featured-content ncst-featured-content is-card-style layout-three-column\">\n  <div class=\"ncst-labeled-section__background\">\n    <div class=\"ncst-labeled-section__container\">\n               <div class=\"ncst-labeled-section__header\">\n                      <h2 class=\"ncst-labeled-section__heading\">Get to know our experts<\/h2>\n                            <\/div>\n            <div class=\"ncst-labeled-section__content\">\n        \n<div class=\"wp-block-ncst-featured-content\"><a\n    class=\"ncst-content-card wp-block-ncst-content-card with-image with-cta\"\n    href=\"https:\/\/csc.ncsu.edu\/people\/lawilli3\/\"\n  >\n  \n          <div class=\"content-card__image-container\">\n        <div class=\"content-card__image-background\">\n          <img loading=\"lazy\" decoding=\"async\" width=\"1500\" height=\"844\"\n            class=\"content-card__image wp-image-34318\"\n            alt=\"Laurie Williams\"\n            src=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Laurie-Williams-1500x844-1.jpg\"\n            style=\"aspect-ratio: 16\/9; object-fit: cover; \"\n srcset=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Laurie-Williams-1500x844-1.jpg 1500w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Laurie-Williams-1500x844-1-300x169.jpg 300w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Laurie-Williams-1500x844-1-1024x576.jpg 1024w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/Laurie-Williams-1500x844-1-768x432.jpg 768w\" sizes=\"auto, (max-width: 1500px) 100vw, 1500px\" \/>\n        <\/div>\n      <\/div>\n    \n    <div class=\"content-card__text-container\">\n      \n                        <h3 class=\"content-card__headline\">Laurie Williams<\/h3>\n              \n\n              \n\t      \t        <p class=\"content-card__teaser\">Goodnight Distinguished University Professor<br>Department of Computer Science<\/p>\n\t      \t    \n              <p class=\"content-card__cta\"><span class=\"text\">Read more<\/span><span class=\"arrow-indicator\"><svg class=\"wolficon wolficon-arrow-right-bold\" role=\"img\"  aria-hidden=\"true\">\n\t\t\t\n\t\t\t<use xlink:href=\"#wolficon-arrow-right-bold\">\n\t\t<\/svg><\/span><\/p>\n          <\/div>\n\n  <\/a>\n\n\n<a\n    class=\"ncst-content-card wp-block-ncst-content-card with-image with-cta\"\n    href=\"https:\/\/csc.ncsu.edu\/people\/whenck\/\"\n  >\n  \n          <div class=\"content-card__image-container\">\n        <div class=\"content-card__image-background\">\n          <img loading=\"lazy\" decoding=\"async\" width=\"1500\" height=\"844\"\n            class=\"content-card__image wp-image-34319\"\n            alt=\"William Enck\"\n            src=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/William-Enck-1500x844-1.jpg\"\n            style=\"aspect-ratio: 16\/9; object-fit: cover; \"\n srcset=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/William-Enck-1500x844-1.jpg 1500w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/William-Enck-1500x844-1-300x169.jpg 300w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/William-Enck-1500x844-1-1024x576.jpg 1024w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/William-Enck-1500x844-1-768x432.jpg 768w\" sizes=\"auto, (max-width: 1500px) 100vw, 1500px\" \/>\n        <\/div>\n      <\/div>\n    \n    <div class=\"content-card__text-container\">\n      \n                        <h3 class=\"content-card__headline\">William Enck<\/h3>\n              \n\n              \n\t      \t        <p class=\"content-card__teaser\">Goodnight Distinguished Professor in Security Sciences<br>Department of Computer Science<\/p>\n\t      \t    \n              <p class=\"content-card__cta\"><span class=\"text\">Read more<\/span><span class=\"arrow-indicator\"><svg class=\"wolficon wolficon-arrow-right-bold\" role=\"img\"  aria-hidden=\"true\">\n\t\t\t\n\t\t\t<use xlink:href=\"#wolficon-arrow-right-bold\">\n\t\t<\/svg><\/span><\/p>\n          <\/div>\n\n  <\/a>\n\n\n<a\n    class=\"ncst-content-card wp-block-ncst-content-card with-image with-cta\"\n    href=\"https:\/\/erm.ncsu.edu\/about\/erm-initiative-team\/mark-beasley\/?_gl=1*1tzl3zp*_ga*NzY5MzgyNzYwLjE3NTg1NjUzMzg.*_ga_52ZBXKJW18*czE3NjMwNDg0NjUkbzIkZzEkdDE3NjMwNDkxMTEkajYwJGwwJGgw*_gcl_au*OTM1MDU3Njc2LjE3NjMwNDA0Njc.\"\n  >\n  \n          <div class=\"content-card__image-container\">\n        <div class=\"content-card__image-background\">\n          <img loading=\"lazy\" decoding=\"async\" width=\"1500\" height=\"844\"\n            class=\"content-card__image wp-image-34323\"\n            alt=\"\"\n            src=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/mark-beasley-1500x844-2.jpg\"\n            style=\"aspect-ratio: 16\/9; object-fit: cover; \"\n srcset=\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/mark-beasley-1500x844-2.jpg 1500w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/mark-beasley-1500x844-2-300x169.jpg 300w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/mark-beasley-1500x844-2-1024x576.jpg 1024w, https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/mark-beasley-1500x844-2-768x432.jpg 768w\" sizes=\"auto, (max-width: 1500px) 100vw, 1500px\" \/>\n        <\/div>\n      <\/div>\n    \n    <div class=\"content-card__text-container\">\n      \n                        <h3 class=\"content-card__headline\">Mark Beasley<\/h3>\n              \n\n              \n\t      \t        <p class=\"content-card__teaser\">Alan T. Dickson Distinguished Professor of Accounting<br>Director, Enterprise Risk Management Initiative<\/p>\n\t      \t    \n              <p class=\"content-card__cta\"><span class=\"text\">Read more<\/span><span class=\"arrow-indicator\"><svg class=\"wolficon wolficon-arrow-right-bold\" role=\"img\"  aria-hidden=\"true\">\n\t\t\t\n\t\t\t<use xlink:href=\"#wolficon-arrow-right-bold\">\n\t\t<\/svg><\/span><\/p>\n          <\/div>\n\n  <\/a>\n<\/div>\n\n              <\/div>\n    <\/div>\n  <\/div>\n<\/div>\n\n\n<div class=\"ncst-labeled-section wp-block-ncst-posts-feed ncst-featured-content is-card-style layout-two-column\">\n  <div class=\"ncst-labeled-section__background\">\n    <div class=\"ncst-labeled-section__container\">\n               <div class=\"ncst-labeled-section__header\">\n                      <h2 class=\"ncst-labeled-section__heading\">More tech insights from Poole<\/h2>\n                            <\/div>\n            <div class=\"ncst-labeled-section__content\">\n        <a\n    class=\"ncst-content-card \"\n    href=\"https:\/\/poole.ncsu.edu\/thought-leadership\/article\/can-we-trust-ai-global-research-team-offers-framework-for-tackling-this-question\/\"\n  >\n  \n    \n    <div class=\"content-card__text-container\">\n              <p class=\"content-card__meta\">\n                      <span class=\"content-card__date\">August 25, 2025<\/span>\n                            <\/p>\n      \n                        <h3 class=\"content-card__headline\">Can We Trust AI? Global Research Team Offers Framework for Tackling this Question<\/h3>\n              \n\n              \n\t      \t        <p class=\"content-card__teaser\"><span class=\"text\">An international team of researchers has put forward a framework to answer one of the biggest questions facing artificial intelligence technologies: can AI be trusted?<\/span><span class=\"arrow-indicator\"><svg class=\"wolficon wolficon-arrow-right-light\" role=\"img\"  aria-hidden=\"true\">\n\t\t\t\n\t\t\t<use xlink:href=\"#wolficon-arrow-right-light\">\n\t\t<\/svg><\/span><\/p>\n\t      \t    \n          <\/div>\n\n  <\/a>\n<a\n    class=\"ncst-content-card \"\n    href=\"https:\/\/poole.ncsu.edu\/thought-leadership\/article\/how-large-language-models-are-reshaping-cybersecurity-and-not-always-for-the-better\/\"\n  >\n  \n    \n    <div class=\"content-card__text-container\">\n              <p class=\"content-card__meta\">\n                      <span class=\"content-card__date\">June 10, 2025<\/span>\n                            <\/p>\n      \n                        <h3 class=\"content-card__headline\">How Large Language Models Are Reshaping Cybersecurity \u2013 And Not Always for the Better<\/h3>\n              \n\n              \n\t      \t        <p class=\"content-card__teaser\"><span class=\"text\">Poole experts explore how large language models are transforming cybersecurity by enhancing threat detection and response \u2014 but they also introduce new risks.<\/span><span class=\"arrow-indicator\"><svg class=\"wolficon wolficon-arrow-right-light\" role=\"img\"  aria-hidden=\"true\">\n\t\t\t\n\t\t\t<use xlink:href=\"#wolficon-arrow-right-light\">\n\t\t<\/svg><\/span><\/p>\n\t      \t    \n          <\/div>\n\n  <\/a>\n\n              <\/div>\n    <\/div>\n  <\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Risk Meets Reality Editor\u2019s Note: This is the latest in a series from the Poole College of Management and the Enterprise Risk Management Initiative that taps experts from across NC State to explore societal issues through the lens of risk management. The scope and cost of cyberattacks are staggering. Global losses from data breaches are&hellip;<\/p>\n","protected":false},"author":50146,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"source":"","ncst_custom_author":"","ncst_show_custom_author":false,"ncst_dynamicHeaderBlockName":"ncst\/floating-box-header","ncst_dynamicHeaderData":"{\"pageIntro\":\"Software is part of every sector. That means cyber risk is, too.\",\"backgroundColor\":\"red-400\",\"boxPosition\":\"left\",\"ctaNum\":\"one\",\"useCTA\":false,\"imageURL\":\"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-content\/uploads\/sites\/423\/2025\/11\/PTL_erm_cyber.jpg\",\"imageID\":34294,\"imageAlt\":\"A hand reaches out toward a screen, its index finger touching an icon shaped like a lock. Other digital icons are projected onto the screen.\"}","ncst_content_audit_freq":"","ncst_content_audit_date":"","ncst_content_audit_display":false,"ncst_backToTopFlag":"","footnotes":""},"class_list":["post-34297","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-json\/wp\/v2\/pages\/34297","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-json\/wp\/v2\/users\/50146"}],"replies":[{"embeddable":true,"href":"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-json\/wp\/v2\/comments?post=34297"}],"version-history":[{"count":11,"href":"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-json\/wp\/v2\/pages\/34297\/revisions"}],"predecessor-version":[{"id":35305,"href":"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-json\/wp\/v2\/pages\/34297\/revisions\/35305"}],"wp:attachment":[{"href":"https:\/\/poole.ncsu.edu\/thought-leadership\/wp-json\/wp\/v2\/media?parent=34297"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}