Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Does Cyber Insurance Cover AI Incidents?

The answer changed on a specific date. Until the start of 2026, most organizations were covered for AI losses by silence rather than by grant, because policies neither affirmed nor excluded AI and the question would have been argued at claim time. On January 1, 2026 the standard forms organization introduced generative AI exclusion endorsements for commercial general liability, and carriers began attaching them at renewal. ‍

The Cloud Controls Matrix (CCM): Manual vs. AI-Assisted Vendor Assessment

Most teams that assess cloud vendors already have a general idea of the Consensus Assessment Initiative Questionnaire (CAIQ) and Cloud Controls Matrix (CCM). However, you may not have a good answer for what it takes to run that assessment. Turning a vendor's trust center page, SOC 2 report, and security policy into a structured, defensible view of CCM control coverage is a different problem entirely.

AI Cyber Readiness for Financial Institutions

Advanced AI models are changing the cyber threat landscape by accelerating vulnerability discovery, exploit development, and attacker decision-making. Regulators like the ECB have made clear: action plans are necessary. Financial institutions need to understand whether their existing cyber risk programs can keep pace, not only across their own attack surface, but across the critical third parties and software dependencies they rely on.

Insurance Is Still in the Crosshairs: What Recent Dark Web Chatter Says About Sector Targeting

Insurance has always been a data-rich industry. But recent threat intelligence makes it clear that attackers are not only going after insurers because they are large organizations. They’re going after them because insurance touches some of a threat actor’s favorite things: money, identity, healthcare, legal claims, third-party relationships, and highly sensitive customer records.

Building a Security Budget Case With Return on Security Investment

Security budget requests fail on arithmetic rather than on argument. A finance function asked to approve spending wants the same information it requires from every other proposal, being what it costs, what it returns and over what period. Most security cases supply the first, describe the second qualitatively, and omit the third. ‍ Return on security investment closes that by expressing the benefit as reduced modeled loss rather than as reduced likelihood of an unspecified bad outcome.

AI Security Posture Management: What It Covers and What It Misses

AI Security Posture Management arrived as a term before it arrived as a definition. Vendors announced products under the label through 2025 and in volume at RSA Conference 2026, each describing a somewhat different scope, and buyers now evaluate a category whose boundaries depend on who is selling. The lineage is evident, since AI-SPM follows cloud and data security posture management, and the inherited assumptions are where the difficulty starts.

How to Modernize Your School Without Security Gaps

Schools need better tools, but every new platform, vendor, device, or portal adds something to manage. A grading tool, facilities upgrade, payment system, or classroom app may solve one problem while creating another. The goal is not to avoid modernization. It is to modernize with a clear view of data, access, and vendor risk.

Reporting AI Risk to the Board: What Directors Want to See

Directors ask for AI risk reporting because oversight failure is personally actionable. Under the Caremark line of cases, a board that cannot demonstrate it monitored a material risk carries exposure of its own, and AI has moved into that category for most enterprises. The request is rarely curiosity about the technology. ‍ The framing determines what belongs in the pack.

NIST AI RMF vs ISO 42001: Choosing Your AI Governance Framework

NIST AI RMF and ISO/IEC 42001 answer different questions, so the choice is rarely about which one is better. One gives you a risk process your engineering teams can run. The other gives you a management system an auditor can certify. Organizations that treat them as rival options usually pick the wrong one for the problem in front of them. ‍

The Invisible Expansion of the Attack Surface: Shadow AI, MCP, and Third-Party Risk

AI adoption is moving faster than most of us anticipated and, more importantly, faster than most organizations can govern it. Organizations are implementing the use of AI-enabled applications, browser extensions, coding assistants, and automated agents to enable employees to work faster. In many cases, these tools are adopted without security review, procurement approval, or a clear understanding of where organizational data is being sent.