Practical briefings for the people accountable.
Short, direct pieces on the cyber risk, governance, resilience, and regulatory questions that reach the board, written for the people who have to decide.
Answering the NIS2 scope question before you commit to a programme
Scope is the first question NIS2 raises and the one most organisations answer too late. A short diagnostic settles it before the budget is set.
Zero Trust starts with discovery, but many programmes skip it
The most common way a Zero Trust programme fails is buying technology before establishing where you stand. A discovery phase establishes it first.
The software supply chain is now a board issue
The software your organisation depends on is largely built by others. Recent attacks and new regulation have turned that dependency into a board-level risk.
Zero Trust on the cloud you already run
Zero Trust is what regulators and insurers increasingly expect, and for organisations already on a major cloud platform, much of the capability is already available. The work is sequencing and governance.
Cloud adoption needs somewhere safe to land
Moving workloads to the public cloud is a board decision. Whether they land in a secure, governed environment or an improvised one is what determines the risk.
