Research

Articles

In-depth research for CISOs and security leaders. Frameworks, compliance, and AI security.

Reading about it? Try it.

See how these frameworks map to your security stack

2-minute assessment. 5 board questions. Live domain scan. Personalised before & after.

Start Your CISO Capacity Assessment
AI Agents 20 min read

The 8-Person Security Team Playbook

What AI agents handle vs what still needs humans. 422 weekly hours mapped across 8 roles.

Security OpsCISOPlaybook
February 19, 2026 Read article
CISO 6 min read

The CISO’s AI Agent Security Checklist — 8 Things to Audit This Week

86% of organisations have AI agents running without full security approval. Here are 8 things to audit.

AI AgentsSecurity AuditChecklist
February 19, 2026 Read article
DORA 8 min read

DORA for CISOs: ICT Risk Management When AI Agents Run Your Operations

How CISOs must adapt DORA compliance for AI-augmented operations under BaFin supervision.

Financial ServicesICT RiskAI Agents
February 19, 2026 Read article
EU AI Act 9 min read

The EU AI Act Compliance Playbook — What German Companies Must Do Now

A compliance roadmap for German enterprises navigating phased enforcement and risk classification.

ComplianceGermanyAI Governance
February 19, 2026 Read article
NIS2 15 min read

NIS2 Compliance Automation: Which of the 10 Article 21 Requirements Can AI Agents Monitor

6 of 10 requirements suit continuous AI monitoring. 4 require human oversight. 0 are human-only.

ComplianceAI AgentsAutomation
February 19, 2026 Read article
NIST 800-53 10 min read

Your NIST 800-53 Controls Already Cover AI Agents — The Complete Mapping

47 existing controls across 14 families. 4 trust boundaries. 0 new frameworks needed.

AI AgentsControlsCISO
February 19, 2026 Read article
AI Agents 8 min read

We Replaced Our Team of 6 with AI Agents — Here’s What Actually Happened

A €847K team, 60% mechanical work, and the decision to deploy AI agents on our own operations first.

CISOCase StudyAutomation
February 17, 2026 Read article
AI Governance 5 min read

Shadow AI Is Your Biggest Blind Spot — Here’s How to Fix It

86% of organisations have unapproved AI tools. Average of 17+ shadow AI tools. Zero firewalls catching it.

Shadow AICISOEnterprise
February 17, 2026 Read article
Security Architecture 7 min read

Security Architecture in the AI Era: From SABSA and TOGAF to Agent Trust Boundaries

Your security architecture was designed for humans and systems. It now has a third category of tenant.

SABSATOGAFAI Security
February 15, 2026 Read article
Germany 8 min read

German Cyber Security 2026: NIS2, the AI Act, and the Rise of the AI-Powered CISO

Three major regulations now live. 60–70% of compliance work automatable. Ransomware remains #1.

NIS2EU AI ActAnnual Review
February 12, 2026 Read article
NIST 5 min read

Your NIST 800-53 Controls Already Cover AI Agents

1,189 total controls. 47 apply to AI agents. 14 families. 0 new frameworks needed.

AI SecurityFrameworkGovernance
February 10, 2026 Read article
Vendor Risk 6 min read

Third-Party AI Risk: Your Vendors Are Using AI — Here’s Why That’s Your Problem

Your vendors are using AI. The only question is whether you know and whether you’re managing the risk.

AI GovernanceNIS2Supply Chain
February 8, 2026 Read article
Supply Chain 7 min read

Supply Chain Attacks 2026: From SolarWinds to AI Agent Compromise

Someone poisoned an AI model, and the model did the rest. The supply chain generates payloads now.

AI SecurityIncident Response
February 5, 2026 Read article
GRC 6 min read

Conversational GRC vs Traditional Dashboards: Why Your Team Hates Archer

A senior risk analyst spends 3 days compiling what an AI agent generates in 30 seconds.

AI AgentsRSA ArcherAutomation
February 3, 2026 Read article
NIS2 6 min read

NIS2 Readiness: What German CISOs Actually Need to Do

18 sectors in scope. 24h incident reporting. €10M max fine. 60–70% ISO 27001 overlap.

ComplianceDACHRegulation
January 28, 2026 Read article
ISO 42001 7 min read

ISO 42001 for Practitioners: What the AI Management System Standard Actually Requires

Everyone discusses ISO 42001. Few implement it. Here’s what you actually need to do in 90 days.

AI GovernanceComplianceISO 27001
January 20, 2026 Read article