Security Insights
Practical GRC, AI Governance & Security Leadership
Direct perspective from running compliance programs, AI governance, and security operations in the field. No vendor pitches, no recycled frameworks.
- Enterprise AI Deployment: Where the Governance Boundaries Have to Beby Cody KellerEvery large organization is somewhere on the enterprise AI deployment curve right now. Some are running Copilot across tens of thousands of employees. Some are piloting internal models in controlled environments. Some have deployed AI agents into operational workflows. And a significant number have done all of the above, in different corners of the organization, without a unified governance framework connecting any of it. That last scenario is where the real risk lives — and… Read more: Enterprise AI Deployment: Where the Governance Boundaries Have to Be
- CJIS Has a Compliance Model Problem: Here’s What Should Replace Itby Cody KellerThe Criminal Justice Information Services Security Policy is one of the most substantive compliance frameworks in the US federal ecosystem. It protects fingerprints, criminal histories, biometric data, warrants, and case files — information that carries serious real-world consequences if mishandled. The FBI has invested significant effort in modernizing the policy, and its recent alignment with NIST 800-53 Rev. 5 represents a genuine improvement in technical rigor. The compliance model built around that policy is a… Read more: CJIS Has a Compliance Model Problem: Here’s What Should Replace It
- SOC 2 Type 2: What It Actually Tells You and What It Doesn’tby Cody KellerSOC 2 Type 2 has become the de facto trust signal for technology and service organizations. Enterprise buyers require it before vendor onboarding. Investors reference it during due diligence. Boards treat it as assurance that their third-party security posture is managed. The problem is that most people requesting SOC 2 Type 2 reports — and many receiving them — don’t fully understand what the report actually says, what it leaves out, and what questions it… Read more: SOC 2 Type 2: What It Actually Tells You and What It Doesn’t
- What Boards Get Wrong About Cybersecurity Riskby Cody KellerThere’s a version of board cybersecurity oversight that looks great on paper and doesn’t work at all in practice. The CISO presents to the board once a quarter. The slides have charts, metrics, and a risk heat map. The board nods, asks a few questions, and moves on to the next agenda item. Everyone checks the governance box. The problem is that this model measures the wrong thing. And in 2026, with regulators explicitly evaluating… Read more: What Boards Get Wrong About Cybersecurity Risk
- OT Security: The Gap Most GRC Programs Haven’t Closedby Cody KellerMost GRC programs are built around IT assets — endpoints, servers, cloud environments, SaaS platforms. The risk register covers data breaches, ransomware, and regulatory compliance. That scope is appropriate for most of what the program governs. The problem is that a significant and growing category of risk sits outside that scope entirely: operational technology. And the threat actors targeting it stopped being theoretical a long time ago. In 2025, adversaries targeting operational technology crossed a… Read more: OT Security: The Gap Most GRC Programs Haven’t Closed