AI audit readiness: a practical checklist for CISOs
AI is already in your estate. The only question is whether you discover it in an AI audit or an incident report.
AI is already in your estate. The only question is whether you discover it in an AI audit or an incident report.
This article breaks down five reasons governance teams are pivoting to self hosted models over ChatGPT style APIs, and two alternatives most overlook: SaaS with BYOK AI backends, and regional providers that satisfy residency requirements.
Swiss banks understood the risks of foreign infrastructure. AI now shows why data sovereignty must cover inference, not just storage.
A practical guide to where ISO 42001 helps, where the EU AI Act bites, and how to use both without building two separate programs.
Malicious LiteLLM releases reached PyPI for about 40 minutes. Here is what the incident reveals about dependency security and detection time.
OpenAI's gated cyber model, GLM-5.3's CyberGym lead, real agent breakouts, EU watermarking rules, and Grok Bot's "coworker" beta—plus what to watch next.
GLM-5.3’s CyberGym result points to faster vulnerability discovery, but we still need human oversight
Two new Apache Struts CVEs show how a bank‑built AI harness for Claude Opus 4.8 can find real, unauthenticated DoS flaws in the legacy Java frameworks powering global banking.
A Cursor coding agent wiped a production database and its backups through a valid API call. Traditional DLP could not catch it.
The EU Cyber Resilience Act mandates 24-hour reporting for actively exploited vulnerabilities from September 2026
From OpenAI's Daybreak to Anthropic's Glasswing: AI Has Accelerated the Wrong Half of Security
How a 60MB .map File Exposed Half a Million Lines of TypeScript — and What Happened Next
Article
In the rush to "go AI," most small and medium-sized enterprises (SMEs) share a common misconception: “We aren’t tech developers, so we don’t need an AI strategy".
EU AI Act
Staying Compliant from Outside the Union
Article
AI agents can read your email, browse the web and execute code. Most small teams have no rules around any of it
Cloud act
But Sovereignty Is Still Mostly in American Hands
Article
"Why most third-party risk programmes are compliance theatre not what the standards actually require."
Article
Phishing Simulations Are Dead . They Won't Save Your Job After a Breach
Article
Who do you call when your network is on fire
Article
A Cybersecurity team's nightmare. Here are a few ways you can detect OpenClaw lurking on your hosts.
Article
From Snowden to Tailgating, Why Physical Security Must Be a Cybersecurity Priority
Article
How password managers like Bitwarden simplify password creation, storage, and usage, while enhancing security.
Article
In this article, I've summarised 28 straightforward tips and examples, to keep you safe from phishing
Article
The best time to improve your Cybersecurity Awareness was 10 years ago, but the second best time is now