Research
In-depth research for CISOs and security leaders. Frameworks, compliance, and AI security.
Your enterprise has 150–300 non-human identities. 70%+ are unmanaged. Here’s the guide to getting them under control.
Two frameworks, one organisation. Four months of audit prep—or eight seconds per control check with AI agents.
Your existing controls cover 80% of AI agent risk. The gap is understanding how they map to new attack patterns.
Every AI agent risk has an existing NIST 800-53 control. You don’t need a new framework.
The $300/day cost reflects architectural inefficiency, not inherent technology costs.
Why CISOs are turning to AI augmentation when a single senior SOC analyst costs €154K–187K in Year 1.
Reading about it? Try it.
2-minute assessment. 5 board questions. Live domain scan. Personalised before & after.
Start Your CISO Capacity AssessmentWhat AI agents handle vs what still needs humans. 422 weekly hours mapped across 8 roles.
86% of organisations have AI agents running without full security approval. Here are 8 things to audit.
How CISOs must adapt DORA compliance for AI-augmented operations under BaFin supervision.
A compliance roadmap for German enterprises navigating phased enforcement and risk classification.
6 of 10 requirements suit continuous AI monitoring. 4 require human oversight. 0 are human-only.
47 existing controls across 14 families. 4 trust boundaries. 0 new frameworks needed.
A €847K team, 60% mechanical work, and the decision to deploy AI agents on our own operations first.
86% of organisations have unapproved AI tools. Average of 17+ shadow AI tools. Zero firewalls catching it.
Your security architecture was designed for humans and systems. It now has a third category of tenant.
Three major regulations now live. 60–70% of compliance work automatable. Ransomware remains #1.
1,189 total controls. 47 apply to AI agents. 14 families. 0 new frameworks needed.
Your vendors are using AI. The only question is whether you know and whether you’re managing the risk.
Someone poisoned an AI model, and the model did the rest. The supply chain generates payloads now.
A senior risk analyst spends 3 days compiling what an AI agent generates in 30 seconds.
18 sectors in scope. 24h incident reporting. €10M max fine. 60–70% ISO 27001 overlap.
Everyone discusses ISO 42001. Few implement it. Here’s what you actually need to do in 90 days.