Insights on cybersecurity leadership
Practical guidance on cybersecurity leadership, governance, risk and regulatory readiness, written to be useful whether you set the strategy, approve it or carry it out.
- Written for
- Anyone accountable for a security decision: executives, boards, counsel, compliance, IT and security teams.
- Subjects
- Governance, cyber risk, regulatory readiness and executive reporting.
- Every article
- Carries its author, its publication date and the date it was last substantively revised.
The archive
Every article
- Cloud Security
- 1
- Compliance
- 6
- Compliance and Audit Readiness
- 1
- Compliance and Governance
- 1
- Governance
- 5
- Governance & Compliance
- 3
- Governance and Leadership
- 1
- Managed Security Services
- 1
- Regulatory Compliance
- 2
- Regulatory and Framework Readiness
- 6
- Risk Management
- 2
- Published
- 29
-
How NIST SP 800-171 Rev 3 Changes Assessment Methodology for Defense Contractors
NIST SP 800-171 Revision 3 restructures assessment procedures to align with NIST SP 800-53A and introduces scoring changes that defense contractor executives must understand. Leadership accountability for controlled unclassified information protection requires clarity on what changed, who owns compliance, and how progress is measured. -
What PCI DSS 4.0 Changed for Service Providers and When It Takes Effect
Payment service providers face new PCI DSS 4.0 requirements with specific transition deadlines. Leadership needs clear accountability for continuous compliance, not just annual assessments. -
When Cloud Misconfigurations Become Reportable Breaches Under State Law
Cloud misconfigurations can trigger breach notification obligations under state law before any threat actor touches the data. This article explains when an exposure becomes reportable, who decides, and how executive leadership should establish accountability for these determinations. -
How HIPAA Security Rule Enforcement Changed in 2023 and 2024
The Office for Civil Rights has shifted how it evaluates HIPAA Security Rule compliance, moving from checklist audits to outcome-based assessments tied to enterprise risk management. Healthcare executives must now demonstrate that security decisions reflect documented risk, that governance is clear, and that technical safeguards match the organization's actual risk profile. -
What SOC 2 Type II Auditors Actually Test in Access Controls
SOC 2 Type II auditors evaluate whether access controls meet trust services criteria over a sustained period, not just on paper. Leadership must understand what evidence auditors require, who owns the control environment, and how to demonstrate operating effectiveness before the examination begins. -
What the SEC's Cybersecurity Disclosure Rules Require in Form 8-K and Form 10-K
Public companies must now disclose material cybersecurity incidents on Form 8-K within four business days of determining materiality, and describe their cybersecurity risk management, governance and board oversight annually on Form 10-K. The rules assign clear accountability but create an execution problem: leadership is responsible for outcomes in a domain where they often lack technical fluency, internal ownership is fragmented, and the materiality determination requires judgment that technical staff cannot make alone. -
What an Assessor Looks for in Managed Security Services
Security assessors evaluating managed security services focus on whether the provider can demonstrate compliance with specific regulatory requirements, such as NIST SP 800-171 for organizations handling Controlled Unclassified Information. Leadership must understand that an assessor's role is independent verification of security controls, not implementation advice, and that responsibility for compliance outcomes remains with the organization even when technical work is delegated to a managed service provider. -
What CMMC 2.0 Requires Before Your First Assessment
Defense contractors face CMMC certification deadlines with unclear accountability for security readiness. This article explains what must be in place before assessment, who owns certification readiness inside your organization, and how executive leadership ensures compliance without delays. -
Who Owns Incident Response When a Security Event Occurs
Incident response planning requires executive ownership of decisions that cross departments, involve regulatory obligations, and directly affect business continuity. This article explains what incident readiness and response planning entails, which leaders are accountable, and the practical steps to establish governance before an event occurs. -
Identity and Access Management Strategy: What Changed and What Leadership Must Know
Identity and access management has shifted from a technical implementation detail to a board-level governance question. This article explains what executives are now accountable for, who should own the strategy, and the practical decisions required to meet regulatory and operational expectations. -
What Current Regulation Requires Around Cloud Security Architecture and Governance
U.S. organizations moving to cloud infrastructure face regulatory requirements that demand clear governance structures, defined security architectures and documented accountability. No single regulation prescribes cloud security architecture in detail, but sector-specific frameworks impose enforceable obligations around access controls, data protection, audit trails and vendor management. Leadership is accountable for establishing the governance function, even when technical execution is delegated. This article explains what compliance actually requires, who owns what inside the organization, and how to establish the executive control that regulators expect. -
What to Put in Place First for Regulatory and Framework Readiness
Regulatory and framework readiness is the work of aligning your organization's cybersecurity practices with external requirements and recognized standards. Without clear executive ownership, this work stalls, accountability fragments, and leadership cannot measure progress toward outcomes that auditors, regulators and boards expect. This article explains what regulatory and framework readiness means in practical terms, why it matters to the business, who should own it, and what leadership should do next.