What happened
The Center for Internet Security released CIS Community Defense Model (CDM) v3.0 (press release dated September 21, 2026; white paper published September 18, 2026). The data-driven framework uses real-world threat intelligence, breach data and MITRE ATT&CK mappings to measure how CIS Critical Security Controls v8.1 Safeguards defend against the five most prevalent attack types (System Intrusion, Social Engineering, Basic Web Application Attacks, Privilege Misuse, Denial of Service). v3.0 adds a new defender-focused component, the CIS Controls Active Defense Lifecycle, showing where Safeguards interrupt attacks across the attack lifecycle.
Why it matters
CDM is the widely-adopted companion to the CIS Critical Security Controls that enterprises use to prioritise which Safeguards to implement against live threats. v3.0 re-baselines control prioritisation against current attack data at a time when AI-assisted and agentic attacks are reshaping the threat landscape and control-selection decisions for AI workloads (which map to CIS Controls v8.1). AI-security programs frequently map agentic-AI controls onto CIS Controls, so the refreshed prioritisation affects where defenders invest. Note: this is a general-security framework update rather than an AI-specific standard, kept for the guidelines track because it gates control selection for AI workloads.
Action needed
Security teams should review the CDM v3.0 white paper and re-run their CIS Controls v8.1 prioritisation against the updated threat and Active Defense Lifecycle guidance when planning AI/agentic workload protections.