All Articles
-
NIS2 Directive: What CISOs Must Have in Place as EU Enforcement Intensifies
The EU's NIS2 Directive has been national law across member states since October 2024. Enforcement is accelerating in 2026. This briefing covers the obligations CISOs must meet, the personal liability exposure for management, and how to prioritise if you are behind.
regulatory-update -
Making the Business Case for Zero Trust: What Your Board Needs to Hear
Zero trust architecture is well understood technically but routinely fails to secure board-level commitment. This briefing gives CISOs the language, metrics, and risk framing to present zero trust as a business investment rather than an IT project.
risk-analysis -
DORA ICT Third-Party Risk: What Financial Services CISOs Must Have in Place Before the First Supervisory Reviews
The Digital Operational Resilience Act's ICT third-party risk management requirements impose specific contractual, oversight, and incident reporting obligations on financial entities and their critical ICT providers. With DORA fully in effect and supervisors beginning substantive reviews, here's what CISOs need to have in place — and where the most common gaps are.
regulatory-update -
UK Cyber Security and Resilience Bill: What CISOs Need to Know Before It Becomes Law
The UK Cyber Security and Resilience Bill will extend mandatory incident reporting to a wider set of organisations, expand the regulated sector scope beyond NIS, and introduce new board accountability obligations. With parliamentary progress accelerating in 2026, this briefing covers what the legislation requires, how it differs from NIS2, and what UK security leaders should be doing now.
regulatory-update -
Third-Party AI Tool Risk: What CISOs Need in Vendor Contracts and Procurement Reviews
AI coding assistants, document summarisers, and meeting intelligence tools are now in every business unit — usually without security review. This briefing covers the five risk categories that matter, the contract language that transfers liability, and the governance model that keeps AI tool sprawl from becoming a data exposure problem.
briefing -
NIS2 Personal Liability: What Boards and CISOs Must Understand Before October 2026
NIS2 creates direct personal liability for management body members when cybersecurity failures occur at covered organisations. With enforcement ramping up in October 2026, here is what boards and CISOs need to know about their individual exposure, obligations, and how to document their oversight.
regulatory-update -
Non-Human Identities Are Now the Board's Problem
KPMG's 2026 cybersecurity report identifies non-human identities — API keys, service accounts, machine credentials — as the top unresolved CISO problem. With NHIs outnumbering human identities by 45:1 in enterprise environments, the governance gap has become a material risk exposure that boards need to understand.
risk-analysis -
NIS2 Enforcement Is Underway: What Early EU Penalties Mean for Your Organisation
EU member states have begun issuing formal NIS2 enforcement actions. Germany has issued 47 formal notices, France has ordered remediation across energy and transport, and personal liability for senior executives is now active. What CISOs need to bring to the board.
regulatory-update