Analysis library
Clear analysis for consequential cybersecurity decisions.
Browse independent analysis of cybersecurity architecture, business risk, resilience, AI, and emerging technology.
-

Securing AI Agents: Moving From One-Time Approval to Continuous Assurance
Why this matters now Organizations are beginning to use AI agents for activities that extend beyond generating or summarizing information.…
-

Modernizing Enterprise Security Architecture Beyond Framework Compliance
A practical model for connecting business outcomes, risk decisions, security capabilities, architecture patterns, controls, evidence, and measurable improvement.
-

Autonomous AI as a Cyber Threat: What Leaders Should Prepare For
Agentic AI can plan, use tools, and adapt across multiple steps. Leaders should constrain identity, authority, data, execution, telemetry, and…
-

Short-Lived TLS Certificates: Preparing for the 47-Day Lifecycle
Publicly trusted TLS certificates are moving to a 47-day maximum by 2029. Prepare with end-to-end discovery, issuance, deployment, validation, and…
-

API Security Is Business Security: Architecture Priorities for Modern Enterprises
Modern API security depends on inventory, fine-grained authorization, abuse-resistant business flows, safe third-party consumption, and end-to-end transaction visibility.
-

Critical Infrastructure Cyber Resilience: Architecture Priorities for Leaders
Critical infrastructure security should preserve essential functions through consequence-driven architecture, controlled access, segmentation, trusted recovery, and realistic exercises.
-

Building a Hybrid Security Operating Model with External Services
External providers can extend security capability, but accountability remains internal. Design explicit outcomes, decision rights, access boundaries, telemetry, and exit…
-

Secure Decommissioning of Wi-Fi and Network Devices
Secure device retirement removes trust as well as data: revoke identities and credentials, sanitize storage, remove management associations, and verify…
-

Cyber Extortion Resilience: Preparing Beyond Ransomware Prevention
Cyber extortion resilience reduces attacker leverage through identity containment, segmentation, trustworthy recovery, data knowledge, and rehearsed executive decisions.
-

Voice Deepfakes and Executive Impersonation: A Verification Playbook
AI voice impersonation makes familiarity unreliable. Protect consequential actions with independent verification, trusted contact paths, and dual control.

