-

When Marketplace Policies Aren’t Evidence
Amazon’s response to New York City’s crackdown on prohibited e-bikes and scooters exposes a larger governance question: when companies have compliance policies, can they prove…
-

The Governance Test I Applied to an Executive Recruiter
Part II follows the evidence beyond the recruiting emails. Public records, domain history, website analysis, and unanswered questions reveal why governance depends on verification—not persuasion.
-

The Governance Test I Applied to an Executive Recruiter
What happens when you apply the same evidence-based governance principles used in cybersecurity and AI oversight to an executive recruiting process? In Part I, I…
-

The End of Predictable Ransomware: What Boards Need to Know About the New Threat Landscape
The ransomware landscape is changing. As major criminal groups fragment into smaller and less predictable actors, boards must shift their focus from prevention alone to…
-

The AI Governance Gap: When Policies Exist but Oversight Doesn’t
Many organizations have AI policies, but few can demonstrate effective oversight. As regulators, insurers, and auditors focus on accountability, governance must move beyond documentation to…
-

The Defensible Organization
Organizations cannot eliminate every cyber risk or prevent every incident. The goal of effective governance is not perfection—it’s defensibility. Learn the five pillars of a…
-

Cyber Insurance Is Becoming a Governance Examination
Cyber insurance is no longer just about transferring risk. Insurers increasingly evaluate governance, oversight, accountability, and evidence when determining coverage and reviewing claims.
-

The Board’s Cyber Dashboard: Five Metrics That Actually Matter
Boards are often overwhelmed with cybersecurity data but lack meaningful insight. Discover the five metrics that help leaders understand risk, resilience, preparedness, and governance effectiveness.
-

What Investigators Look for After a Cyber Incident
Most organizations prepare for cyberattacks. Few prepare for cyber investigations. Discover what regulators, insurers, auditors, attorneys, and investigators look for after a cybersecurity incident and…
-

Third-Party Risk and the Myth of Shared Responsibility
Modern organizations depend on vendors, cloud providers, managed service providers, and software platforms. While services can be outsourced, accountability cannot. Learn why effective third-party risk…
-

The Evidence Gap: Why Good Security Programs Still Lose in Investigations
Organizations invest heavily in cybersecurity controls, yet many struggle to prove what they did when regulators, insurers, auditors, or investigators come calling. Discover why evidence—not…