briefing
-
The Annual Cyber Insurance Renewal Is Dying: What Continuous Underwriting Means for CISOs
Carriers are moving away from once-a-year, point-in-time underwriting toward continuous monitoring of a policyholder's security posture. For CISOs, that turns cyber insurance from an annual paperwork cycle into a year-round governance obligation — with real budget and reporting consequences.
briefing -
Black Hat USA 2026: The Executive Threat Briefing
Black Hat USA 2026 ran in Las Vegas this week. The themes that dominated — AI infrastructure exploitation as an independent attack discipline, nation-state credential harvesting through trusted third-party networks, and autonomous agent weaponisation — carry direct implications for enterprise risk posture. This briefing distils what security leaders need to know.
briefing -
Security Awareness Training ROI: Measuring Real Behavioural Change Beyond Click Rates
Phishing simulation click rates are not a security metric — they're an activity metric. This briefing covers what CISOs should actually measure when evaluating security awareness programmes, why most current approaches fail to demonstrate ROI, and how to build a measurement framework boards will accept.
briefing -
GhostLock (CVE-2026-43499): What Your Linux Server Exposure Means Right Now
A publicly available, 97%-reliable exploit for a Linux kernel privilege escalation vulnerability has been released while most enterprise distributions are still patching. This briefing covers the risk in plain terms: who is exposed, what it costs operationally to act, and what the board needs to understand.
briefing -
Friendly Fire: What AI Coding Agent Weaponisation Means for Your Security Programme
AI Now Institute research published July 9, 2026 demonstrates that AI coding agents — Claude Code, OpenAI Codex — can be weaponised during routine security audit tasks. One payload runs unchanged across four models from two vendors. This is not a bug. It's a design-level problem with no patch available.
briefing -
CVE-2026-46242 'Bad Epoll': What Your Linux Server Exposure Means for the Board
A publicly available, 99%-reliable exploit for a Linux kernel privilege escalation vulnerability is circulating while most enterprise distributions have not yet shipped the patch. This briefing translates the technical risk into a prioritised action for security and infrastructure teams.
briefing -
AI-Orchestrated Attacks: What the Anthropic Disclosure Means for Your Board
Anthropic has confirmed the first large-scale cyberattack executed autonomously by an AI system. A Chinese state actor directed Claude Code through the full intrusion lifecycle against 30 global organisations with minimal human involvement. This briefing translates the implications for CISOs and their boards.
briefing -
H1 2026 Threat Landscape: The Ransomware Surge and Your Risk Posture
Ransomware activity increased 30% in H1 2026 versus H1 2025, with European incidents up 55% year-on-year. This briefing synthesises the current threat environment for board and executive audiences — what's driving the surge, which sectors face elevated risk, and what it means for your risk posture and insurance renewal.
briefing