Blog

Security leadership and compliance insights.

Articles on security leadership, audit readiness, email security, CMMC, and AI governance for regulated and trust-sensitive organizations. Each article cites its primary sources.

Topics
Data ProtectionSep 23, 2026

The Morgan Stanley Leak Wasn't a Hack. That's the Problem.

An accidental email containing a live deal pipeline shows why access control alone is not enough, and why classification, DLP, encryption and endpoint controls have to work together.

7 min readRead article
CMMCSep 22, 2026

CMMC Level 2 readiness after the Phase 2 suspension.

The Department of War suspended CMMC Phase 2 on July 13, 2026, but Level 2 self-assessment and NIST SP 800-171 obligations remain in force. Five readiness gaps affect whether a contractor's affirmation will hold up.

3 min readRead article
AI Risk ManagementSep 1, 2026
The AI RMF Field Guide, Part 5 of 5

MANAGE: Where AI Risk Management Earns Its Keep

The MANAGE function of the NIST AI RMF explained: risk prioritization, deployment gates, AI incident response, vendor monitoring, and decommissioning.

4 min readRead article
AI Risk ManagementAug 18, 2026
The AI RMF Field Guide, Part 4 of 5

MEASURE: Working Is Not the Same as Trustworthy

The MEASURE function of the NIST AI RMF explained: TEVV, bias and fairness testing, adversarial evaluation, drift monitoring, and documenting tradeoffs.

4 min readRead article
AI Risk ManagementAug 4, 2026
The AI RMF Field Guide, Part 3 of 5

MAP: Why Many AI Failures Are Context Failures

The MAP function of the NIST AI RMF explained: intended use, AI system documentation, stakeholder impact analysis, and risk identification, including generative AI risks.

4 min readRead article
AI Risk ManagementJul 21, 2026
The AI RMF Field Guide, Part 2 of 5

GOVERN: The AI RMF Function That Decides Whether the Other Three Matter

The GOVERN function of the NIST AI RMF explained: accountability, AI policy, risk tolerance, AI inventories, and third-party oversight, and the gap between paper and practice.

4 min readRead article
AI Risk ManagementJul 7, 2026
The AI RMF Field Guide, Part 1 of 5

What Is the NIST AI Risk Management Framework? A Plain-English Field Guide

The NIST AI Risk Management Framework (AI RMF 1.0) explained: the four functions, the seven trustworthy AI characteristics, and how to start using it.

4 min readRead article
Email SecurityJun 30, 2026

Moving to DMARC enforcement without disrupting legitimate email.

Many organizations publish a DMARC record at p=none and never advance it. A sequenced approach, grounded in aggregate reports and sender alignment, allows a domain to reach enforcement with controlled risk.

4 min readRead article
AI Risk ManagementMay 19, 2026

AI governance for regulated organizations: inventory, tiering, and oversight.

An acceptable use policy alone does not establish AI governance. Regulated organizations need an AI system inventory, a risk-tiering rule, and an approval process aligned with the NIST AI Risk Management Framework.

4 min readRead article
Audit ReadinessMar 24, 2026

Audit evidence: designing controls that produce their own records.

Audit findings frequently trace to missing operating records rather than weak control design. Building evidence into routine work prepares an organization for SOC 2 Type 2 examinations, HIPAA reviews, and NIST-based assessments.

4 min readRead article
vCISOFeb 10, 2026

A 90-day plan for a fractional CISO engagement.

The first quarter of a fractional CISO engagement should establish accountability, document the organization's obligations, and put core processes into operation. This plan outlines the priorities for each 30-day phase.

4 min readRead article
AI Risk ManagementFeb 26, 2025

The NIST AI Risk Management Framework: Safeguarding Your Organization in the Age of Artificial Intelligence

AI introduces risks that traditional risk management approaches may not address. The NIST AI Risk Management Framework gives organizations a structured way to identify and mitigate them.

3 min readRead article
Start a conversation

Connect security leadership, audit readiness, email trust, AI governance, and documentation into a practical program.

Tell us what you are dealing with now, what kind of support you may need, and whether you are looking for a focused project, ongoing advisory, or both.

Start a conversation Explore services