Intelligence for Security Leaders

CISO Brief

Regulatory compliance, cyber risk, and board-level security strategy

Recent Analysis View all ›

Geopolitical Cyber Risk in 2026: A Briefing Framework for Boards and CISOs

Nation-state cyber operations have moved from targeted espionage to broad pre-positioning and disruptive campaigns affecting commercial organisations. This briefing provides CISOs with a framework for assessing and communicating geopolitical cyber risk to boards.

Shadow AI: The Governance Gap That's Driving Your Next Data Breach

Three quarters of CISOs have already discovered unsanctioned GenAI tools running in their environments. The data suggests the breach hasn't happened yet -- but the conditions are in place.

CIRCIA Is Live: What the 72-Hour Reporting Rule Means for Your Organisation

The Cyber Incident Reporting for Critical Infrastructure Act final rule took effect in May 2026, establishing mandatory 72-hour incident reports and 24-hour ransomware payment disclosure for covered entities. Here's what CISOs need to have in place before an incident.

NIS2 Supply Chain Security: What Article 21 Actually Requires -- and What Most Organisations Are Getting Wrong

NIS2 Article 21 mandates supply chain security as a core cybersecurity obligation for essential and important entities. This briefing covers what the directive requires, the implementation gaps most organisations have, and what boards need to understand before their national regulator comes looking.

Nightmare-Eclipse: What the Windows Zero-Day Campaign Means for Your Board

Six actively exploited Windows vulnerabilities, three confirmed in live attacks, and a credible remote-code-execution threat arriving in June. A plain-English board briefing for security leaders.

The AI Vulnerability Wave: What Every CISO Needs to Tell the Board Right Now

Anthropic's Project Glasswing found 10,000+ critical vulnerabilities in open source in a single month. The NCSC has warned of a forced correction of technical debt. What this means for board risk posture, vendor expectations, and patch SLAs that are already obsolete.