Skip to main content

risk-analysis

  • Security Operations Cost Management: Build vs. Buy vs. MDR — The 2026 CISO Framework

    Security Operations Cost Management: Build vs. Buy vs. MDR — The 2026 CISO Framework

    Security operations is the largest line item in most security budgets and the most contested. As MDR providers mature and internal SOC costs rise, CISOs face a structural decision about how to deliver detection and response at sustainable cost. A framework for thinking through the options.

    risk-analysis
  • Vulnerability Prioritization in 2026: CVSS, EPSS, and CISA KEV for Enterprise Security Leaders

    Vulnerability Prioritization in 2026: CVSS, EPSS, and CISA KEV for Enterprise Security Leaders

    CVSS scores alone generate patch queues no organisation can work through. EPSS and the CISA Known Exploited Vulnerabilities catalogue add exploitation likelihood and confirmed real-world abuse to the picture. This briefing explains how to combine all three into a prioritization framework that actually reduces risk.

    risk-analysis
  • Januscape: Why Your Cloud Provider's Patch Schedule Now Matters to the Board

    Januscape: Why Your Cloud Provider's Patch Schedule Now Matters to the Board

    CVE-2026-53359 allows a compromised virtual machine to escape to the host server, threatening the isolation guarantees that underpin multi-tenant cloud and private data centre security. A board-level briefing on what Januscape means for enterprise risk.

    risk-analysis
  • M&A Cyber Due Diligence: The Hidden Liabilities Acquirers Miss

    M&A Cyber Due Diligence: The Hidden Liabilities Acquirers Miss

    Cyber risk in acquisitions frequently goes unquantified until after deal close, when undisclosed breaches, inherited vulnerabilities, and regulatory exposure surface as material liabilities. This briefing outlines what CISOs need from the target company before signing, and how to structure cyber risk in deal governance.

    risk-analysis
  • AI Gateway Risk: Managing Exposed Model Endpoints Before They Become Your Next Major Incident

    AI Gateway Risk: Managing Exposed Model Endpoints Before They Become Your Next Major Incident

    Research in mid-2026 confirmed that exposed LiteLLM and Ollama deployments are being exploited for compute theft, credential exfiltration, and autonomous attack operations — in some cases using the victim's own AI infrastructure to attack third parties. This briefing translates the threat into CISO-level risk posture and actionable governance steps.

    risk-analysis
  • ITDR: What the Board Needs to Know About Identity Threat Detection

    ITDR: What the Board Needs to Know About Identity Threat Detection

    Identity Threat Detection and Response addresses the gap that SIEM and EDR leave open — the lateral movement, credential abuse, and token theft that lives inside authenticated sessions. This briefing explains what ITDR is, what it catches that existing tools miss, and how to build the business case.

    risk-analysis
  • The 2026 Regulatory Stack: How to Manage NIS2, DORA, CIRCIA, and the UK Cyber Resilience Bill Without Drowning

    The 2026 Regulatory Stack: How to Manage NIS2, DORA, CIRCIA, and the UK Cyber Resilience Bill Without Drowning

    European and US cyber regulations now overlap substantially, creating a compliance management problem that's as much about operational efficiency as about meeting individual requirements. This brief outlines a unified controls approach that satisfies multiple regimes simultaneously and reduces duplicated audit effort.

    risk-analysis
  • AI Security Posture Management: What CISOs Need to Know About AISPM

    AI Security Posture Management: What CISOs Need to Know About AISPM

    As enterprises deploy AI across every function, a new risk category has emerged: the AI attack surface. AI Security Posture Management (AISPM) is the discipline of continuously assessing that surface — model access, training pipelines, inference infrastructure, and prompt injection exposure — before it becomes a breach.

    risk-analysis