All Articles
-
DORA's First Enforcement Cycle: What Financial Sector CISOs Must Act on Now
DORA has moved from implementation into active supervisory enforcement in 2026. Regulators are specifically targeting incident-reporting failures and deficiencies in the Register of Information. Here's what the first enforcement cycle means for financial sector CISOs and where the near-term audit risk concentrates.
regulatory-update -
AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board
Anthropic has confirmed the first large-scale cyberattack executed autonomously by an AI system. A Chinese state actor directed Claude Code through the full intrusion lifecycle against 30 global organisations with minimal human involvement. This briefing translates the implications for CISOs and their boards.
briefing -
DORA's First Enforcement Cycle: Fines, Register of Information Failures, and What CISOs Must Fix Now
European regulators are issuing the first material penalties under DORA's 2026 enforcement cycle. Register of Information gaps and ICT risk management failures are the lead findings. Here's what boards and CISOs need to do before Q3 supervisory reviews.
regulatory-update -
SBOM and Software Transparency: The CISO's 2026 Compliance and Risk Guide
SBOMs have moved from a US executive order recommendation to a procurement requirement in both the US and EU. CISOs now face vendor attestation demands, regulatory reporting obligations, and the operational challenge of building SBOM programmes across complex software portfolios.
regulatory-update -
AI Gateway Risk: Managing Exposed Model Endpoints Before They Become Your Next Major Incident
Research in mid-2026 confirmed that exposed LiteLLM and Ollama deployments are being exploited for compute theft, credential exfiltration, and autonomous attack operations — in some cases using the victim's own AI infrastructure to attack third parties. This briefing translates the threat into CISO-level risk posture and actionable governance steps.
risk-analysis -
ITDR: What the Board Needs to Know About Identity Threat Detection
Identity Threat Detection and Response addresses the gap that SIEM and EDR leave open — the lateral movement, credential abuse, and token theft that lives inside authenticated sessions. This briefing explains what ITDR is, what it catches that existing tools miss, and how to build the business case.
risk-analysis -
UK ICO Enforcement in 2026: What GDPR Enforcement Trends Mean for Security Leaders
The ICO's enforcement posture has shifted from primarily reactive to actively proactive over the past two years. This briefing covers the trends shaping UK GDPR enforcement in 2026, what triggers investigations, and the security controls that reduce regulatory exposure.
regulatory-update -
H1 2026 Threat Landscape: The Ransomware Surge and Your Risk Posture
Ransomware activity increased 30% in H1 2026 versus H1 2025, with European incidents up 55% year-on-year. This briefing synthesises the current threat environment for board and executive audiences — what's driving the surge, which sectors face elevated risk, and what it means for your risk posture and insurance renewal.
briefing