Skip to main content

All Articles

  • Cyber Due Diligence in M&A: What CISOs Must Assess Before Deal Close

    Cyber Due Diligence in M&A: What CISOs Must Assess Before Deal Close

    Cyber risk has become a dealbreaker in M&A transactions. Hidden liabilities — undisclosed breaches, inherited ransomware, regulatory exposure — regularly surface after close when they are most expensive to address. This guide covers what a CISO-led cyber due diligence programme should examine and what findings warrant deal renegotiation.

    risk-analysis
  • Security Operations Cost Management: Build vs. Buy vs. MDR — The 2026 CISO Framework

    Security Operations Cost Management: Build vs. Buy vs. MDR — The 2026 CISO Framework

    Security operations is the largest line item in most security budgets and the most contested. As MDR providers mature and internal SOC costs rise, CISOs face a structural decision about how to deliver detection and response at sustainable cost. A framework for thinking through the options.

    risk-analysis
  • Vulnerability Prioritization in 2026: CVSS, EPSS, and CISA KEV for Enterprise Security Leaders

    Vulnerability Prioritization in 2026: CVSS, EPSS, and CISA KEV for Enterprise Security Leaders

    CVSS scores alone generate patch queues no organisation can work through. EPSS and the CISA Known Exploited Vulnerabilities catalogue add exploitation likelihood and confirmed real-world abuse to the picture. This briefing explains how to combine all three into a prioritization framework that actually reduces risk.

    risk-analysis
  • FTC AI Accuracy Policy: What Boards and CISOs Need to Know Before July 31

    FTC AI Accuracy Policy: What Boards and CISOs Need to Know Before July 31

    The Federal Trade Commission's new AI Accuracy Policy Statement establishes that AI-generated outputs causing consumer harm may constitute unfair or deceptive practices under existing FTC Act authority. With the public comment period closing July 31 2026, now is the time to assess your AI deployment exposure.

    regulatory-update
  • Friendly Fire: What AI Coding Agent Weaponisation Means for Your Security Programme

    Friendly Fire: What AI Coding Agent Weaponisation Means for Your Security Programme

    AI Now Institute research published July 9, 2026 demonstrates that AI coding agents — Claude Code, OpenAI Codex — can be weaponised during routine security audit tasks. One payload runs unchanged across four models from two vendors. This is not a bug. It's a design-level problem with no patch available.

    briefing
  • Januscape: Why Your Cloud Provider's Patch Schedule Now Matters to the Board

    Januscape: Why Your Cloud Provider's Patch Schedule Now Matters to the Board

    CVE-2026-53359 allows a compromised virtual machine to escape to the host server, threatening the isolation guarantees that underpin multi-tenant cloud and private data centre security. A board-level briefing on what Januscape means for enterprise risk.

    risk-analysis
  • CVE-2026-46242 'Bad Epoll': What Your Linux Server Exposure Means for the Board

    CVE-2026-46242 'Bad Epoll': What Your Linux Server Exposure Means for the Board

    A publicly available, 99%-reliable exploit for a Linux kernel privilege escalation vulnerability is circulating while most enterprise distributions have not yet shipped the patch. This briefing translates the technical risk into a prioritised action for security and infrastructure teams.

    briefing
  • M&A Cyber Due Diligence: The Hidden Liabilities Acquirers Miss

    M&A Cyber Due Diligence: The Hidden Liabilities Acquirers Miss

    Cyber risk in acquisitions frequently goes unquantified until after deal close, when undisclosed breaches, inherited vulnerabilities, and regulatory exposure surface as material liabilities. This briefing outlines what CISOs need from the target company before signing, and how to structure cyber risk in deal governance.

    risk-analysis