Briefings & Analysis
Regulatory updates, risk analysis, and executive briefings for security leaders
Date Title Category Read time
May 22, 2026
The cyber insurance market has hardened significantly. Insurers are scrutinising security controls more closely than ever, exclusions are expanding, and the gap between policy wording and actual coverage is catching organisations off-guard. What every CISO needs to understand before the next renewal.
Risk Analysis
7 min
May 10, 2026
What CISOs must implement under the EU's NIS2 Directive — sector-specific obligations, board accountability requirements, and the cost of non-compliance.
Regulatory Update
7 min
May 5, 2026
Moving beyond FUD to quantified risk. How CISOs can use FAIR methodology, key risk indicators, and business-aligned language to secure meaningful board engagement.
Risk Analysis
6 min
Apr 28, 2026
Beyond the ransom: a comprehensive breakdown of ransomware incident costs including downtime, legal exposure, regulatory fines, and long-term reputational damage.
Risk Analysis
7 min
Apr 20, 2026
A practical framework for CISOs evaluating AI tool vendors: data residency requirements, model security considerations, and the contractual controls that protect your organization.
Briefing
6 min
Apr 15, 2026
A CISO's guide to the Digital Operational Resilience Act — what financial institutions must implement, how DORA interacts with NIS2, and the oversight regime for critical third-party providers.
Regulatory Update
7 min
Apr 8, 2026
Material incident reporting timelines, annual cybersecurity disclosures, and the CISO's role in SEC compliance — including personal liability considerations for public company security leaders.
Regulatory Update
6 min