Skip to main content

Tag: governance

89 articles

board-level readiness: Must-Have Critical Wake-Up

board-level readiness: Must-Have Critical Wake-Up

The NCSC and ministers have warned FTSE 350 chiefs that many boards are leaving the digital front door wide open—it’s time for executives to treat cyber as a strategic priority, not an IT problem. Stronger board-level accountability, realistic testing and smarter supplier checks can stop breaches from becoming boardroom crises.

Analyst 207
artificial intelligence risk: Essential, Costly Warning

artificial intelligence risk: Essential, Costly Warning

UK firms are feeling the sting of unmanaged AI — EY finds an average hit of £2.9m per organisation from faulty models, data breaches and regulatory slip-ups. It’s a wake-up call: invest in governance, oversight and clear accountability now or watch innovation turn into costly disruption.

Analyst 207
semiconductor sovereignty: Must-Have Defense or Risky Move

semiconductor sovereignty: Must-Have Defense or Risky Move

When the Netherlands slapped special measures on Nexperia, it turned a wafer fab into a test case for Europe’s chip sovereignty — a move meant to stop sensitive know‑how from slipping overseas while forcing a rethink of how to balance open investment with national security. The decision signals tougher oversight ahead, with big implications for investors, manufacturers and Europe’s tech future.

Analyst 207
AI-capable workforce: Stunning Best Practices

AI-capable workforce: Stunning Best Practices

At the AIX Summit, technologists, agency leaders and vendors wrestled with the real challenge of scaling AI in government—not just the tools, but the people, policies and protections that make deployments safe and effective. Three practical takeaways emerged—hire hybrid-skilled teams, build layered governance for agentic systems, and make security and workforce resilience non-negotiable—offering an immediate roadmap for moving from pilots to production.

Analyst 207
sensitive information Shocking Prospect Breach Reveals Risk

sensitive information Shocking Prospect Breach Reveals Risk

A cyber gaffe at Prospect exposed sensitive details — including sexual orientation and disability status — for up to 160,000 members. Now the union must act fast with clear fixes and transparent support to rebuild trust and protect vulnerable members.

Analyst 207
observability and threat hunting: Must-Have Critical Fixes

observability and threat hunting: Must-Have Critical Fixes

The NCSC warns many organisations are blind to attackers already inside their networks and is urging urgent improvements in observability and threat hunting. Its practical guidance shows how better telemetry, retention and detection engineering can help teams find, contain and recover from breaches faster.

Analyst 207
cyber incident: Explosive FEMA Cover-Up Risk

cyber incident: Explosive FEMA Cover-Up Risk

Leaked emails and logs now cast doubt on FEMA’s insistence that last month’s sweeping security firings weren’t cyber-related, raising urgent questions about hidden breaches, operational risk, and public trust. As investigators sift the evidence, people deserve clear, timely answers about whether critical disaster systems or personal data were exposed.

Analyst 207
digital ID Must-Have or Risky? Exclusive Warning

digital ID Must-Have or Risky? Exclusive Warning

The UK says its new digital ID will be optional — a welcome reassurance after a 2.76 million-signature petition — but critics warn voluntariness won’t mean much without strong legal safeguards, inclusive design and independent oversight. Whether it stays a genuine choice or becomes a de facto requirement will come down to implementation, privacy protections and how businesses adopt the system.

Analyst 207
agentic AI Must-Have Defense: Risky Breach Guide

agentic AI Must-Have Defense: Risky Breach Guide

Forrester warns agentic AI could spark a major breach by 2026, so now’s the time for boards and security teams to treat agentic risk as design — not a checkbox — by locking down privileges, boosting observability, and baking in human-in-the-loop controls before autonomous agents can act maliciously at scale.

Analyst 207
Autonomous AI: Exclusive Must-Have Safety After Risky Stall

Autonomous AI: Exclusive Must-Have Safety After Risky Stall

Gartner’s latest research shows enterprises are hitting the brakes on autonomous AI—only a tiny fraction plan to deploy agents—making this a crucial moment to prioritize safety, governance and human oversight. It’s an opportunity to build systems that are not just smart, but trustworthy and secure before handing them more control.

Analyst 207
AI security Must-Have: Best Defense Tactics

AI security Must-Have: Best Defense Tactics

PwC finds organizations are now prioritizing AI security over cloud and network defenses, reallocating budgets to protect models, training data and inference pipelines from novel attacks. That shift means stronger governance, adversarial testing and monitoring are needed to make AI a strategic asset rather than a new liability.

Analyst 207
Agentic AI: Must-Have Efficiency, Risky Governance

Agentic AI: Must-Have Efficiency, Risky Governance

Overstretched federal IT teams are piloting agentic AI — systems that can take initiative to automate help‑desk tickets, procurement steps and incident response — promising to cut weeks off workflows and free staff for higher‑value work. But those efficiency gains come with real governance, security and accountability questions that agencies must solve before scaling.

Analyst 207
CSP diversity: Must-Have for Best Multi-Cloud Resilience

CSP diversity: Must-Have for Best Multi-Cloud Resilience

The Air Force’s Cloud One shows how CSP diversity can turn vendor lock-in into resilience, speed, and mission-fit—letting developers choose the best environment while keeping security and operations consistent. That flexibility pays off only with disciplined governance, shared tooling, and a culture that treats interoperability and observability as nonnegotiable.

Analyst 207
AI agents: Must-Have Best Practices for Security

AI agents: Must-Have Best Practices for Security

You likely have forgotten service accounts, API keys, and AI agents running everywhere that quietly widen your attack surface — but with a clear inventory, short‑lived credentials, and assigned ownership you can start regaining control. Begin small: catalog a critical app, enforce least privilege, and measure detection and remediation to prove the approach scales.

Analyst 207
AI control plane: Must-Have Shield Against Risky Agents

AI control plane: Must-Have Shield Against Risky Agents

As AI agents take on more autonomy, Astrix’s new AI control plane promises centralized visibility, policy enforcement and fast remediation—so security teams can rein in rogue agent actions and reduce risk without sacrificing productivity.

Analyst 207
Identity Governance and Administration: Stunning Best Guide

Identity Governance and Administration: Stunning Best Guide

Who has the keys? Identity Governance and Administration puts that question to rest by giving you centralized visibility into who can access what, why they have it, and when to revoke it — so you can reduce risk, streamline onboarding, and prove compliance.

Analyst 207
Rewiring Democracy: Must-See Tour Dates & Best Talks

Rewiring Democracy: Must-See Tour Dates & Best Talks

Join the Rewiring Democracy tour this fall—four can’t-miss events in Cambridge, online, Strasbourg and Toronto where the author turns ideas into lively public debate through talks, signings and forums; check host pages for registration and updates.

Analyst 207
CVE program: Must-Have Global Control Sparks Risky Debate

CVE program: Must-Have Global Control Sparks Risky Debate

CISA wants a bigger role running the CVE vulnerability list — promising more stability and coordination but sparking worries that government control could politicize a vital global standard.

Analyst 207
national digital ID: Risky Must-Have That Fails

national digital ID: Risky Must-Have That Fails

A national digital ID might streamline services and cut fraud, but it also risks turning everyday life into a constant identity check — concentrating power, widening surveillance and still doing little to stop small‑boat crossings. Without strong legal safeguards, decentralised design and real alternatives, a BritCard could trade convenience for serious privacy and security dangers.

Analyst 207
CVE program Must-Have Roadmap for Best Security

CVE program Must-Have Roadmap for Best Security

CISA just released a roadmap to modernize the CVE program, insisting on public stewardship and vendor neutrality while calling for broader industry–government collaboration to keep vulnerability tracking trustworthy and scalable. If implemented well, it could speed up patching, reduce disputes and harden defenses — but success depends on sustainable funding, transparency and real buy-in from all stakeholders.

Analyst 207
Rewiring Democracy Exclusive Must-Have Signed Copies

Rewiring Democracy Exclusive Must-Have Signed Copies

Grab a limited signed copy of Bruce Schneier’s Rewiring Democracy—pre-orders are open now and will ship the week of October 20, so secure this collectible that connects you directly to a timely, must-read guide for defending democracy in the digital age.

Analyst 207
in-space circular economy: Exclusive Must-Have for Safety

in-space circular economy: Exclusive Must-Have for Safety

Could we build a thriving market in orbit where satellites are repaired, parts recycled, and space resources harvested—without turning Earth’s skies into a junkyard? At NIST’s second seminar, engineers, policymakers, and industry leaders pushed the conversation from big ideas to practical standards, incentives, and next steps to make that vision real.

Analyst 207
Wi‑Fi location data: Risky Exclusive Campus Surveillance

Wi‑Fi location data: Risky Exclusive Campus Surveillance

The University of Melbourne reportedly used campus Wi‑Fi logs to identify student protesters, turning everyday network access into a powerful surveillance tool. That episode raises urgent questions about privacy, academic freedom and how universities should balance security with transparent, limited data governance.

Analyst 207
Munk School: Exclusive, Must-Have Lessons on AI Risk

Munk School: Exclusive, Must-Have Lessons on AI Risk

A year at the Munk School showed me how bridging rigorous tech research with messy policy and everyday life can turn abstract AI and cybersecurity risks into practical solutions. From reading groups to Citizen Lab collaborations, the experience proved that durable governance comes from interdisciplinary practice, public engagement, and patient, evidence-driven work.

Analyst 207