August 2 came and went. If you spent the last several months building toward that deadline, here’s the update you may have missed: the EU AI Act’s high-risk AI system requirements are no longer due August 2, 2026. On May 7, 2026, EU lawmakers reached political agreement on revisions to the AI Act, pushing the…
The 4th of July just wrapped up. Somewhere between the cookout and the fireworks show, your organization ran on skeleton crew coverage, half your security team was on PTO, and a meaningful chunk of your workforce was connecting from personal devices on home networks, hotel Wi-Fi, or wherever the holiday took them. That’s not a…
August 2 is five days from when this publishes. That’s the date the EU AI Act’s major provisions — including the full requirements for high-risk AI systems — become applicable. If you’ve been tracking it as an upcoming deadline, it’s no longer upcoming. We covered the strategic overview in April. This post is for the…
Six months in. It’s a reasonable moment to step back from the tactical and look at the rest of the year as a whole — what’s coming, what’s already behind schedule, and where security and GRC programs need to be positioned heading into Q3 and Q4. This isn’t a predictions post. It’s a planning post.…
Third-party risk has been a fixture of security program conversations for years. Most organizations with a mature GRC function have a vendor risk management process — tiering, assessments, questionnaires, contractual requirements. The process exists. The problem is that the scale and nature of supply chain attacks have outpaced what those processes were built to handle.…
Summer is operationally the most complicated season for security teams, and it’s rarely discussed that way. The conversation tends to focus on threat actors and external risks. The more immediate problem is internal: interns onboarding with broader access than they need, senior staff on extended PTO, temporary employees hired for seasonal peaks, and an organizational…
If your organization has been tracking state privacy legislation as a “watch and monitor” item, that posture is overdue for a change. Twenty states now have comprehensive consumer privacy laws in effect. Three more — Connecticut, Arkansas, and Utah — have significant updates or new provisions taking effect July 1, 2026. That’s thirty days from…
Ransomware response has been a standard component of incident response planning for nearly a decade. Most organizations with a mature security program have a ransomware playbook — escalation paths, isolation procedures, backup recovery processes, and a decision framework around payment. The problem is that the environment those playbooks were written for has changed significantly, and…
Most organizations have mature processes for managing human identities. Onboarding, offboarding, access reviews, least privilege — these are established practices, even if execution is inconsistent. The problem is that human identities are no longer the majority of what’s accessing your systems. Service accounts, API keys, OAuth tokens, automation scripts, and now AI agents — non-human…
The AI governance conversation has been running in the background for most organizations — something to monitor, something to address eventually, something for legal to sort out. That posture has an expiration date, and for many businesses, it’s August 2026. The EU AI Act’s major provisions go fully into effect on August 2, 2026. Organizations…