All Articles
-
EU Cyber Resilience Act: What CISOs at Software Vendors Must Know
The EU Cyber Resilience Act introduces mandatory cybersecurity requirements for all products with digital elements sold in the EU. Reporting obligations start September 2026; full enforcement begins December 2027. This briefing covers what matters most for CISOs.
regulatory-update -
The 2026 Regulatory Stack: How to Manage NIS2, DORA, CIRCIA, and the UK Cyber Resilience Bill Without Drowning
European and US cyber regulations now overlap substantially, creating a compliance management problem that's as much about operational efficiency as about meeting individual requirements. This brief outlines a unified controls approach that satisfies multiple regimes simultaneously and reduces duplicated audit effort.
risk-analysis -
AI Security Posture Management: What CISOs Need to Know About AISPM
As enterprises deploy AI across every function, a new risk category has emerged: the AI attack surface. AI Security Posture Management (AISPM) is the discipline of continuously assessing that surface — model access, training pipelines, inference infrastructure, and prompt injection exposure — before it becomes a breach.
risk-analysis -
Developer Secrets as Board Risk: The GitHub PAT Exposure Problem in 2026
Developer credentials — GitHub personal access tokens, API keys, cloud IAM secrets — are now a primary initial access vector for data extortion groups targeting enterprises. The FulcrumSec breach pattern illustrates how a single exposed PAT can cascade into multi-terabyte data theft. This briefing frames the risk for board and C-suite reporting.
risk-analysis -
CTEM: Why CISOs Are Moving Beyond Vulnerability Management
Continuous Threat Exposure Management gives security leaders a structured framework for managing exposure rather than just patching CVEs. This briefing covers how CTEM works, its business case, and what a mature programme looks like in 2026.
risk-analysis -
Operational Technology: The Board-Level Risk That Most Governance Frameworks Still Miss
OT environments — SCADA, PLCs, industrial control systems — carry material cyber risk that sits outside most board risk frameworks, insurance programmes, and security investments. This briefing explains what boards need to understand and the governance questions they should be asking.
risk-analysis -
Oracle PeopleSoft Zero-Day: What the ShinyHunters Breach Means for Enterprise ERP Risk
ShinyHunters exploited a critical Oracle PeopleSoft vulnerability for 14 days before Oracle published any patch — breaching 100+ organisations including major universities. This briefing covers what happened, the systemic ERP risk it reveals, and the governance questions boards should be asking.
incident-report -
DORA Compliance in 2026: What Financial Sector CISOs Must Have in Place Now
The EU Digital Operational Resilience Act became applicable in January 2025 across financial services. Enforcement and supervisory scrutiny are intensifying in 2026. This briefing covers the obligations that matter most, the gaps regulators are finding, and how to prioritise.
regulatory-update