No articles match these filters.
August 31, 2026
What Actually Goes in an AI System Register
Every AI governance framework asks a deployer for a register. None of them ships a template. Here is what the columns have to be, and why a list of tool names fails the first question an assessor asks.
August 6, 2026
Does Your SaaS Vendor Train on Your Data?
Finding shadow AI is the easy half. The question your DPO, your auditor, and your board ask next is whether the AI in use — sanctioned or not — feeds your data back into someone else's model.
July 6, 2026
The New CISO's First 90 Days: A Field Guide
A complete, week-by-week playbook for the first quarter in a new security leadership seat — the listening tour, the ground-truth technical assessment, the risk and maturity work, and the day-90 board presentation. Vendor-neutral best practices, with the parts most new CISOs get wrong called out.
July 5, 2026
The Metrics That Actually Measure Exposure Management
Most vulnerability programs report activity — patches applied, scans run, CVEs closed. None of that tells you whether your exposure is going down. These are the metrics that do, and the one thing they all depend on: knowing what you have and what it's worth.
July 2, 2026
Why Every Framework Starts With Control 1: Know Your Assets
NYDFS, CMMC, PCI, HIPAA — they all demand an asset inventory first. There's a reason. In the CIS Controls, inventory is literally Control 1, and every other control depends on it.
July 2, 2026
CMMC Scoping Lives or Dies on Your Asset Inventory
Every CMMC assessment starts with an asset inventory and a network diagram. Miscategorize what touches CUI — or miss an asset entirely — and the assessment is over before it begins.
July 2, 2026
Coverage Gaps: When Every Dashboard Is Green and You're Still Exposed
A coverage gap doesn't trigger an alert. It's an asset a control was never applied to — invisible to the tool that should protect it, because that tool never knew it existed.
July 2, 2026
HIPAA Is About to Make Asset Inventory Mandatory
For 20 years the Security Rule stayed vague about knowing your systems. A 2025 proposal would end that — requiring a technology asset inventory and a network map of how ePHI moves.
July 2, 2026
The Minimum Viable Organization: What Has to Come Back First
When ransomware takes the environment down, you won't restore everything at once. Your MVO is the smallest version of the company that still functions — and it's a dependency problem, not a list.
July 2, 2026
Shadow AI: The Exposure Your Tools Aren't Reporting
AI entered your environment through the side door — browser tabs, OAuth grants, and API keys no one inventoried. Here's why single tools miss it and how to find it.
July 2, 2026
NYDFS Now Requires an Asset Inventory. Most Firms Can't Produce One.
As of November 1, 2025, Section 500.13 of NYDFS Part 500 makes a complete, accurate asset inventory a rule — not a best practice. Here's what it demands and why it's the hardest part.
July 2, 2026
In PCI DSS, Your Asset Inventory Decides How Big the Audit Is
PCI DSS 4.0 made an in-scope system inventory an explicit requirement. It's also the lever that sets your scope — and every asset you can't account for makes the assessment bigger.
July 2, 2026
Shadow IT: You Can't Ask Your Way to a Complete Inventory
Shadow IT is defined by not being on your list. The forgotten server, the unsanctioned SaaS, the cloud account no one approved — you can't inventory it by asking, because no one will raise their hand.
July 2, 2026
Tool Rationalization: You're Paying Twice and Still Uncovered
The average enterprise over-buys and under-covers at the same time — redundant tools stacked on some assets, none on others. You can't fix either without knowing coverage per asset.
← All resources