All Articles
-
The 2026 Cyber Insurance Renewal: What Underwriters Are Now Requiring
Cyber insurance underwriters have substantially tightened requirements since 2022. The questions have become more technical, the exclusions more specific, and the attestations more consequential. This briefing outlines what underwriters expect in 2026 and how security leaders should prepare.
risk-analysis -
Building an Insider Threat Programme: A CISO Playbook
Insider threats account for a disproportionate share of high-impact data loss events. Building a detection and response programme requires balancing UEBA technology, HR integration, legal frameworks, and employee privacy rights. This briefing covers programme design, governance, technology selection, and the organisational challenges CISOs consistently underestimate.
risk-analysis -
DORA Operational Resilience Testing: What Financial Sector CISOs Must Deliver
DORA's Threat-Led Penetration Testing requirements under Article 26 apply to significant financial entities across the EU and have extraterritorial reach for UK firms with EU operations. Here's what CISOs need to have in place, the testing scope requirements, and how to manage third-party ICT provider involvement.
regulatory-update -
SAP ERP: The Attack Surface Your Security Programme Probably Under-Indexes
SAP environments are among the highest-value targets in enterprise IT — they hold payroll, financials, supply chain, and HR. Yet many security programmes treat SAP as an IT infrastructure question rather than a board-level risk. This briefing covers the real attack surface and what CISOs need to ask.
risk-analysis -
Security Awareness Training ROI: Measuring Real Behavioural Change Beyond Click Rates
Phishing simulation click rates are not a security metric — they're an activity metric. This briefing covers what CISOs should actually measure when evaluating security awareness programmes, why most current approaches fail to demonstrate ROI, and how to build a measurement framework boards will accept.
briefing -
Oracle EBS CVE-2026-46817: When the Finance System Itself Becomes the Attack Vector
CISA added CVE-2026-46817 to the Known Exploited Vulnerabilities catalogue on July 15 with a 72-hour federal deadline -- the tightest ever imposed on an Oracle ERP vulnerability. For CISOs with Oracle E-Business Suite deployments, this is a board-level risk requiring immediate escalation.
incident-report -
Cyber Insurance in 2026: Coverage Gaps, Exclusion Clauses, and What CISOs Need to Negotiate Before the Claim
Cyber insurance pricing has stabilised after years of volatility, but coverage exclusions have become more complex. War exclusions, systemic event exclusions, and ransomware sublimits are the terms most likely to leave organisations without the cover they assumed they had. This briefing prepares security leaders for the conversations that matter.
risk-analysis -
GhostLock (CVE-2026-43499): What Your Linux Server Exposure Means Right Now
A publicly available, 97%-reliable exploit for a Linux kernel privilege escalation vulnerability has been released while most enterprise distributions are still patching. This briefing covers the risk in plain terms: who is exposed, what it costs operationally to act, and what the board needs to understand.
briefing