Can You Explain Why You Are Secure — Without Slides?
Cybersecurity leadership is tested when the slides disappear. This article explores why CISOs must explain security through clarity, judgment, assumptions, and ownership — not only through dashboards, heat maps, and polished board reports.
AI in the SOC: Why We Didn’t Gain Control — We Scaled Complexity
AI promised control, speed, and automation in the SOC. Instead, many organizations scaled complexity. Why the future of security operations is not about more intelligence—but about governance, explainability, and decision quality.
The Most Dangerous Sentence in Information Security? “That’s Not in Scope.”
The most dangerous security gap is often not a vulnerability—it is an exclusion. Why ISMS scope is not documentation, but a governance decision that determines what an organization chooses to see, govern, and ultimately protect.
Annex A Is Not a Security Strategy
Most organizations mistake Annex A for a security strategy. It isn’t. The greatest cybersecurity failures of the next decade may not come from missing controls, but from unchallenged assumptions about cloud, AI, resilience, and dependency.
The Security Requirements Nobody Wants to Write
Security is no longer defined by the controls you implement, but by the dependencies you govern. The modern CISO’s role is not merely to protect systems—it is to ensure the organization remains in control when its assumptions fail.
Digital Markets Act (DMA) and AI: Impact on Platform Operators
The Digital Markets Act reshapes AI platform governance in Europe. This article explains how gatekeeper obligations, interoperability, data-sharing, self-preferencing rules and AI Act overlaps affect competition, compliance and innovation.