top of page


Open-Source AI Regulation: Why Risk Should Guide the Decision
Theresa Payton explains why AI model decisions should start with testing, governance, resilience, and evidence-based risk.
JV
Aug 188 min read


Critical Infrastructure Cybersecurity: What Water Utility Attacks Reveal About Operational Resilience
Water utility attacks show why critical infrastructure cybersecurity depends on operational resilience, clear decisions, and prepared teams.
JV
Aug 137 min read


36 Months to Shape the Next 50 Years of AI: What are the Risks of AI Agents?
Former White House CIO Theresa Payton explains the risks of AI agents and six guardrails leaders need to maintain control.
JV
Aug 39 min read


Department of War Suspends CMMC Phase 2 Requirements and Launches 60-Day Review
CMMC Phase 2 Requirements are paused, but self-assessments, NIST SP 800-171, SPRS reporting, and CUI protections still apply.
JV
Jul 304 min read


The AI Agent That Went Looking for the Answer Key: The OpenAI and Hugging Face Security Incident
The OpenAI Hugging Face security incident exposed autonomous AI risk and urgent governance questions for boards and executives.
JV
Jul 284 min read


Red Team vs Blue Team vs Purple Team: What Executives Need to Know About Cybersecurity Services
Cybersecurity services like red, blue, and purple teams test exposure, response, and readiness before a real incident.
JV
Jul 148 min read


Novo Nordisk Cyberattack: What Healthcare Leaders Should Know About Cyber Extortion
What the Novo Nordisk cyberattack reveals about clinical trial data, cyber extortion, and leadership readiness.
JV
Jun 308 min read


Why You Should Care When You Receive a Healthcare Data Breach Notice
What breach notices reveal about patient risk, hospital preparedness, and the duty to protect healthcare data. When a healthcare data breach notice arrives, many people read the email apology, receive an offer of free credit monitoring, and move on. What they rarely see is what came before it: the compromised vendor, the system that was quietly accessed, and the healthcare organization working to understand what happened, maintain patient data protection, and continue deliver
JV
Jun 2310 min read


What Does a Cybersecurity Expert Do? What PAM Means, and Why Everyday Risks Matter
What does a cybersecurity expert do? What PAM means, how OT and macros create risk, and why everyday decisions matter.
JV
Jun 210 min read


Cyber Incident Response: What Executives Need to Know Before a Breach
Executive guide to cyber incident response, breach decisions, and Incident Commander support before a crisis escalates.
JV
May 269 min read
bottom of page