Every large organization is somewhere on the enterprise AI deployment curve right now. Some are running Copilot across tens of thousands of employees. Some are piloting internal models in controlled environments. Some have deployed AI agents into operational workflows. And a significant number have done all of the above, in different corners of the organization,…
The Criminal Justice Information Services Security Policy is one of the most substantive compliance frameworks in the US federal ecosystem. It protects fingerprints, criminal histories, biometric data, warrants, and case files — information that carries serious real-world consequences if mishandled. The FBI has invested significant effort in modernizing the policy, and its recent alignment with…
SOC 2 Type 2 has become the de facto trust signal for technology and service organizations. Enterprise buyers require it before vendor onboarding. Investors reference it during due diligence. Boards treat it as assurance that their third-party security posture is managed. The problem is that most people requesting SOC 2 Type 2 reports — and…
There’s a version of board cybersecurity oversight that looks great on paper and doesn’t work at all in practice. The CISO presents to the board once a quarter. The slides have charts, metrics, and a risk heat map. The board nods, asks a few questions, and moves on to the next agenda item. Everyone checks…
Most GRC programs are built around IT assets — endpoints, servers, cloud environments, SaaS platforms. The risk register covers data breaches, ransomware, and regulatory compliance. That scope is appropriate for most of what the program governs. The problem is that a significant and growing category of risk sits outside that scope entirely: operational technology. And…
November 4 is eleven weeks away. The 2026 midterms are the kind of event that most private sector security teams treat as background noise — something for government agencies and campaigns to worry about. That assumption is worth reconsidering. The threat environment around major election cycles doesn’t stay contained to election infrastructure. It bleeds into…
Hacker Summer Camp wrapped up last week. Black Hat USA 2026 ran August 1-6 at Mandalay Bay, DEF CON 34 followed August 6-9 at the Las Vegas Convention Center, and somewhere north of 50,000 security professionals spent the better part of two weeks in 105-degree heat talking about the things that are going to show…
August 2 came and went. If you spent the last several months building toward that deadline, here’s the update you may have missed: the EU AI Act’s high-risk AI system requirements are no longer due August 2, 2026. On May 7, 2026, EU lawmakers reached political agreement on revisions to the AI Act, pushing the…
The 4th of July just wrapped up. Somewhere between the cookout and the fireworks show, your organization ran on skeleton crew coverage, half your security team was on PTO, and a meaningful chunk of your workforce was connecting from personal devices on home networks, hotel Wi-Fi, or wherever the holiday took them. That’s not a…
August 2 is five days from when this publishes. That’s the date the EU AI Act’s major provisions — including the full requirements for high-risk AI systems — become applicable. If you’ve been tracking it as an upcoming deadline, it’s no longer upcoming. We covered the strategic overview in April. This post is for the…