Skip to main content

briefing

  • The Annual Cyber Insurance Renewal Is Dying: What Continuous Underwriting Means for CISOs

    The Annual Cyber Insurance Renewal Is Dying: What Continuous Underwriting Means for CISOs

    Carriers are moving away from once-a-year, point-in-time underwriting toward continuous monitoring of a policyholder's security posture. For CISOs, that turns cyber insurance from an annual paperwork cycle into a year-round governance obligation — with real budget and reporting consequences.

    briefing
  • Black Hat USA 2026: The Executive Threat Briefing

    Black Hat USA 2026: The Executive Threat Briefing

    Black Hat USA 2026 ran in Las Vegas this week. The themes that dominated — AI infrastructure exploitation as an independent attack discipline, nation-state credential harvesting through trusted third-party networks, and autonomous agent weaponisation — carry direct implications for enterprise risk posture. This briefing distils what security leaders need to know.

    briefing
  • Security Awareness Training ROI: Measuring Real Behavioural Change Beyond Click Rates

    Security Awareness Training ROI: Measuring Real Behavioural Change Beyond Click Rates

    Phishing simulation click rates are not a security metric — they're an activity metric. This briefing covers what CISOs should actually measure when evaluating security awareness programmes, why most current approaches fail to demonstrate ROI, and how to build a measurement framework boards will accept.

    briefing
  • GhostLock (CVE-2026-43499): What Your Linux Server Exposure Means Right Now

    GhostLock (CVE-2026-43499): What Your Linux Server Exposure Means Right Now

    A publicly available, 97%-reliable exploit for a Linux kernel privilege escalation vulnerability has been released while most enterprise distributions are still patching. This briefing covers the risk in plain terms: who is exposed, what it costs operationally to act, and what the board needs to understand.

    briefing
  • Friendly Fire: What AI Coding Agent Weaponisation Means for Your Security Programme

    Friendly Fire: What AI Coding Agent Weaponisation Means for Your Security Programme

    AI Now Institute research published July 9, 2026 demonstrates that AI coding agents — Claude Code, OpenAI Codex — can be weaponised during routine security audit tasks. One payload runs unchanged across four models from two vendors. This is not a bug. It's a design-level problem with no patch available.

    briefing
  • CVE-2026-46242 'Bad Epoll': What Your Linux Server Exposure Means for the Board

    CVE-2026-46242 'Bad Epoll': What Your Linux Server Exposure Means for the Board

    A publicly available, 99%-reliable exploit for a Linux kernel privilege escalation vulnerability is circulating while most enterprise distributions have not yet shipped the patch. This briefing translates the technical risk into a prioritised action for security and infrastructure teams.

    briefing
  • AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board

    AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board

    Anthropic has confirmed the first large-scale cyberattack executed autonomously by an AI system. A Chinese state actor directed Claude Code through the full intrusion lifecycle against 30 global organisations with minimal human involvement. This briefing translates the implications for CISOs and their boards.

    briefing
  • H1 2026 Threat Landscape: The Ransomware Surge and Your Risk Posture

    H1 2026 Threat Landscape: The Ransomware Surge and Your Risk Posture

    Ransomware activity increased 30% in H1 2026 versus H1 2025, with European incidents up 55% year-on-year. This briefing synthesises the current threat environment for board and executive audiences — what's driving the surge, which sectors face elevated risk, and what it means for your risk posture and insurance renewal.

    briefing