Cyber Essentials — Issue #45 (07 Sep 2026)
AI agents, bug bounties and Langflow RCE put cyber risk back in the boardroom: push for AI-ready governance, budget control and Langflow exposure cleanup now
AI agents, bug bounties and Langflow RCE put cyber risk back in the boardroom: push for AI-ready governance, budget control and Langflow exposure cleanup now
A practical AI due diligence checklist for SaaS buyers. Thirteen questions you can realistically get answered, with the reasoning behind each one.
This week’s AI security and compliance brief for boards and security leaders: cheap Chinese chips, slow regulation, shifting cyber cover and rising infra risk.
A plain-English guide to what AI governance means, why it matters now, the core principles, and how organisations can put it into practice.
The NIS2 Directive raises the EU's cybersecurity baseline across 18 sectors, makes senior management personally accountable, and puts hard clocks on incident reporting. Here is what it requires, who it applies to, and how to prepare.
Shadow AI is quietly eroding AI security, compliance, and data governance. This article breaks down what it really is, why it’s worse than shadow IT, and how CISOs can take back control.
Ox Alpha appeared on OpenRouter on August 20, 2026. No flashy launch. No big tech logo. Just a ‘reasoning model for coding, long-horizon agentic work, and production workloads.
This issue connects a stealth new LLM, messy enterprise AI usage, looming EU transparency rules and fragile agent sandboxes into one pragmatic CISO threat picture.
AI is already in your estate. The only question is whether you discover it in an AI audit or an incident report.
This article breaks down five reasons governance teams are pivoting to self hosted models over ChatGPT style APIs, and two alternatives most overlook: SaaS with BYOK AI backends, and regional providers that satisfy residency requirements.
Swiss banks understood the risks of foreign infrastructure. AI now shows why data sovereignty must cover inference, not just storage.
A practical guide to where ISO 42001 helps, where the EU AI Act bites, and how to use both without building two separate programs.