risk-analysis
-
IBM's 2026 Breach Report: AI Governance Gaps Are Now a Quantified Board Risk
IBM and Ponemon's 21st annual Cost of a Data Breach Report puts the global average at $4.99 million, with AI-enabled breaches running $1 million higher. The data gives boards a hard number for the AI governance gap they've been debating in the abstract.
risk-analysis -
AgentForger: When a Phishing Link Becomes a Persistent AI Insider
Zenity Labs' disclosure of AgentForger demonstrates that enterprise AI agents can be weaponised from outside the organisation via a single phishing link, creating an attacker-controlled agent that inherits authorised access to email, calendar, Slack, and Teams. OpenAI patched the specific flaw in June — but the governance problem is structural and ongoing.
risk-analysis -
LAUNDRY BEAR: What the NCSC Zero-Click Advisory Means for Your Email Security Posture
The joint NCSC advisory AA26-204A naming LAUNDRY BEAR represents a materially different email threat model than phishing: no link to click, no attachment to execute. CISOs running Zimbra need to act now; those who aren't face similar risks from analogous techniques. Here's the executive brief.
risk-analysis -
The 2026 Cyber Insurance Renewal: What Underwriters Are Now Requiring
Cyber insurance underwriters have substantially tightened requirements since 2022. The questions have become more technical, the exclusions more specific, and the attestations more consequential. This briefing outlines what underwriters expect in 2026 and how security leaders should prepare.
risk-analysis -
Building an Insider Threat Programme: A CISO Playbook
Insider threats account for a disproportionate share of high-impact data loss events. Building a detection and response programme requires balancing UEBA technology, HR integration, legal frameworks, and employee privacy rights. This briefing covers programme design, governance, technology selection, and the organisational challenges CISOs consistently underestimate.
risk-analysis -
SAP ERP: The Attack Surface Your Security Programme Probably Under-Indexes
SAP environments are among the highest-value targets in enterprise IT — they hold payroll, financials, supply chain, and HR. Yet many security programmes treat SAP as an IT infrastructure question rather than a board-level risk. This briefing covers the real attack surface and what CISOs need to ask.
risk-analysis -
Cyber Insurance in 2026: Coverage Gaps, Exclusion Clauses, and What CISOs Need to Negotiate Before the Claim
Cyber insurance pricing has stabilised after years of volatility, but coverage exclusions have become more complex. War exclusions, systemic event exclusions, and ransomware sublimits are the terms most likely to leave organisations without the cover they assumed they had. This briefing prepares security leaders for the conversations that matter.
risk-analysis -
Cyber Due Diligence in M&A: What CISOs Must Assess Before Deal Close
Cyber risk has become a dealbreaker in M&A transactions. Hidden liabilities — undisclosed breaches, inherited ransomware, regulatory exposure — regularly surface after close when they are most expensive to address. This guide covers what a CISO-led cyber due diligence programme should examine and what findings warrant deal renegotiation.
risk-analysis