CISO Suite
Essay — Effort Is No Longer a Defense
No longer can you check a box and walk away. NIS2 is changing the game. Image: Nano Banana 2.From Board to Breach: The Accountability Chain NIS2 Just Made ExplicitFor nineteen years, Verizon’s Data Breach ...
Managing Open Source Software Risks With the HeroDevs EOL Dashboard
Modern software delivery runs on open source. But as dependency graphs expand and application lifecycles stretch across years, end-of-life (EOL) components are becoming a structural security challenge ...
Why strategic CISOs need proactive risk reduction, not reactive GRC reporting
Security and GRC teams have no shortage of risk mitigation activities. They are carrying more work than ever, yet many still lack confidence in the data and recommendations produced by all that ...
The Exception Economy: When Security Teams Stop Protecting and Start Negotiating
There is a term that has quietly become the most accurate description of how enterprise security operates in 2026, and it did not come from a CISO, a standards body, or a ...
One step at a time
One step at time. Post 6 in the Factory Series.Factory Series Part 6In 2007, I walked into a Scandinavian food-production facility and reached the production floor in under an hour. No badge. No appointment ...
Mythos AI: What Security Leaders Should Do Next
The recent discussion around Anthropic’s Claude Mythos Preview and Project Glasswing has caught the attention of the cybersecurity industry for good reason. Mythos is not just another AI announcement. It is being ...
The Compound Effect
When incidents stack, the effect is multiplied.The Factory Series — Part 5So far in this series, I’ve treated the threats one at a time. The physical walk-through. The geopolitical shift. The fuel reserves. The digital ...
The Shadow AI Governance Crisis: Why 80% of Fortune 500 Companies Have Already Lost Control of Their AI Infrastructure
80% of Fortune 500 companies now run active AI agents. Only 10% have a clear strategy to manage them. Here is what the other 90% face - and the 5-part framework that ...
The Shadow AI Governance Crisis: Why 80% of Fortune 500 Companies Have Already Lost Control of Their AI Infrastructure
80% of Fortune 500 companies now run active AI agents. Only 10% have a clear strategy to manage them ...
You Don’t Need Legs Anymore
No physical access is required in 2026. Everything is connected.The Factory Series post 4In 2007, I walked into a food-processing factory in Northern Europe without showing identification to a single person. The only ...

