<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CISO Brief</title><description>Executive Cyber Intelligence for Security Leaders</description><link>https://ciso-brief.pages.dev/</link><language>en-us</language><item><title>Cyber Insurance in 2026 — What CISOs Need to Know Before Renewal</title><link>https://ciso-brief.pages.dev/articles/cyber-insurance-market-2026/</link><guid isPermaLink="true">https://ciso-brief.pages.dev/articles/cyber-insurance-market-2026/</guid><description>The cyber insurance market has hardened significantly. Insurers are scrutinising security controls more closely than ever, exclusions are expanding, and the gap between policy wording and actual coverage is catching organisations off-guard. What every CISO needs to understand before the next renewal.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>risk-analysis</category><category>cyber-insurance</category><category>risk-transfer</category><category>underwriting</category><category>coverage</category><category>exclusions</category><category>renewal</category><category>ciso</category></item><item><title>NIS2 Directive: The CISO&apos;s Compliance Roadmap by Sector</title><link>https://ciso-brief.pages.dev/articles/nis2-directive-ciso-compliance-guide/</link><guid isPermaLink="true">https://ciso-brief.pages.dev/articles/nis2-directive-ciso-compliance-guide/</guid><description>What CISOs must implement under the EU&apos;s NIS2 Directive — sector-specific obligations, board accountability requirements, and the cost of non-compliance.</description><pubDate>Sun, 10 May 2026 00:00:00 GMT</pubDate><category>regulatory-update</category><category>NIS2</category><category>EU regulation</category><category>compliance</category><category>governance</category><category>CISO obligations</category></item><item><title>How to Present Cyber Risk to the Board: A Framework That Works</title><link>https://ciso-brief.pages.dev/articles/board-cyber-risk-reporting-framework/</link><guid isPermaLink="true">https://ciso-brief.pages.dev/articles/board-cyber-risk-reporting-framework/</guid><description>Moving beyond FUD to quantified risk. How CISOs can use FAIR methodology, key risk indicators, and business-aligned language to secure meaningful board engagement.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><category>risk-analysis</category><category>board reporting</category><category>FAIR</category><category>risk quantification</category><category>KRIs</category><category>governance</category></item><item><title>The True Cost of a Ransomware Incident in 2026</title><link>https://ciso-brief.pages.dev/articles/ransomware-incident-cost-analysis-2026/</link><guid isPermaLink="true">https://ciso-brief.pages.dev/articles/ransomware-incident-cost-analysis-2026/</guid><description>Beyond the ransom: a comprehensive breakdown of ransomware incident costs including downtime, legal exposure, regulatory fines, and long-term reputational damage.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>risk-analysis</category><category>ransomware</category><category>incident cost</category><category>cyber insurance</category><category>business continuity</category><category>risk quantification</category></item><item><title>Vendor Risk Management When Adopting AI Tools</title><link>https://ciso-brief.pages.dev/articles/vendor-risk-management-ai-tools/</link><guid isPermaLink="true">https://ciso-brief.pages.dev/articles/vendor-risk-management-ai-tools/</guid><description>A practical framework for CISOs evaluating AI tool vendors: data residency requirements, model security considerations, and the contractual controls that protect your organization.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>briefing</category><category>AI security</category><category>vendor risk</category><category>data residency</category><category>third-party risk</category><category>procurement</category></item><item><title>DORA: ICT Risk Management Requirements for Financial Entities</title><link>https://ciso-brief.pages.dev/articles/dora-financial-sector-ict-requirements/</link><guid isPermaLink="true">https://ciso-brief.pages.dev/articles/dora-financial-sector-ict-requirements/</guid><description>A CISO&apos;s guide to the Digital Operational Resilience Act — what financial institutions must implement, how DORA interacts with NIS2, and the oversight regime for critical third-party providers.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate><category>regulatory-update</category><category>DORA</category><category>financial services</category><category>ICT risk</category><category>operational resilience</category><category>EU regulation</category></item><item><title>SEC Cybersecurity Disclosure Rules: What CISOs Must Know in 2026</title><link>https://ciso-brief.pages.dev/articles/sec-cyber-disclosure-rules-2026/</link><guid isPermaLink="true">https://ciso-brief.pages.dev/articles/sec-cyber-disclosure-rules-2026/</guid><description>Material incident reporting timelines, annual cybersecurity disclosures, and the CISO&apos;s role in SEC compliance — including personal liability considerations for public company security leaders.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate><category>regulatory-update</category><category>SEC</category><category>disclosure</category><category>public company</category><category>material incident</category><category>CISO liability</category></item></channel></rss>