risk-analysis
-
Developer Secrets as Board Risk: The GitHub PAT Exposure Problem in 2026
Developer credentials — GitHub personal access tokens, API keys, cloud IAM secrets — are now a primary initial access vector for data extortion groups targeting enterprises. The FulcrumSec breach pattern illustrates how a single exposed PAT can cascade into multi-terabyte data theft. This briefing frames the risk for board and C-suite reporting.
risk-analysis -
CTEM: Why CISOs Are Moving Beyond Vulnerability Management
Continuous Threat Exposure Management gives security leaders a structured framework for managing exposure rather than just patching CVEs. This briefing covers how CTEM works, its business case, and what a mature programme looks like in 2026.
risk-analysis -
Operational Technology: The Board-Level Risk That Most Governance Frameworks Still Miss
OT environments — SCADA, PLCs, industrial control systems — carry material cyber risk that sits outside most board risk frameworks, insurance programmes, and security investments. This briefing explains what boards need to understand and the governance questions they should be asking.
risk-analysis -
Making the Business Case for Zero Trust: What Your Board Needs to Hear
Zero trust architecture is well understood technically but routinely fails to secure board-level commitment. This briefing gives CISOs the language, metrics, and risk framing to present zero trust as a business investment rather than an IT project.
risk-analysis -
Non-Human Identities Are Now the Board's Problem
KPMG's 2026 cybersecurity report identifies non-human identities — API keys, service accounts, machine credentials — as the top unresolved CISO problem. With NHIs outnumbering human identities by 45:1 in enterprise environments, the governance gap has become a material risk exposure that boards need to understand.
risk-analysis -
Post-Quantum Cryptography: The Migration Decision CISOs Can No Longer Defer
NIST's post-quantum cryptography standards are final, NSA compliance deadlines for national security systems begin in January 2027, and adversaries are already collecting encrypted data for future decryption. This briefing provides CISOs with the governance framework for starting migration now.
risk-analysis -
Geopolitical Cyber Risk in 2026: A Briefing Framework for Boards and CISOs
Nation-state cyber operations have moved from targeted espionage to broad pre-positioning and disruptive campaigns affecting commercial organisations. This briefing provides CISOs with a framework for assessing and communicating geopolitical cyber risk to boards.
risk-analysis -
Shadow AI: The Governance Gap That's Driving Your Next Data Breach
Three quarters of CISOs have already discovered unsanctioned GenAI tools running in their environments. The data suggests the breach hasn't happened yet -- but the conditions are in place.
risk-analysis