DeepDive

Practice, at length.

A Speak to It™ term tells you what something is. This is where the same subject is worked through properly: what good looks like, what to require, how to evidence it, and where most teams get it wrong.

289 written, 1405 more commissioned. Free to read, because a common professional vocabulary should not depend on ability to pay.

AI governance

AI API Key Exposure

Developer Portal. Jupyter Notebook. GitHub. Public Repository. Bot. Six Weeks.

6 min read · 15 Sep 2026

Compliance

Assurance vs Validation

SOC 2 Provides Assurance. Your Specific Risk Requires Validation.

6 min read · 15 Sep 2026

Security

API Identity Misuse

The Application Is Decommissioned. The API Key Still Works. Somebody Else Is Using It.

7 min read · 14 Sep 2026

Privacy

Cross-Border Data Flow Risks

The DPA Covers the Transfer. Nobody Covers Where the Data Goes After That.

9 min read · 14 Sep 2026

AI governance

AI Adversarial Attacks

97% Benchmark Accuracy. Adversarial Perturbation: Invisible to Humans. Model Confidence on Wrong Classification: 97.3%.

4 min read · 13 Sep 2026

Third-party oversight

Build Pipeline Integrity

Production Environment: Secured. CI/CD Pipeline: 12 Third-Party Integrations. 7 Running on Production Credentials. 1 With Authentication Bypass.

4 min read · 13 Sep 2026

Compliance

Audit Evidence Quality

Screenshot of MFA Enabled. One Role. Test Environment. Eleven Months Ago.

6 min read · 12 Sep 2026

Privacy

Data Access Logging Gaps

The Access Controls Are Strong. Nobody Is Watching What They Access.

9 min read · 12 Sep 2026

Security

Access Certification Effectiveness

100% Completion Rate. 11.7 Seconds Per Account. The Review Was a Checkbox.

6 min read · 11 Sep 2026

Third-party oversight

Vendor Patch Cadence Reality

Patch Policy: 30 Days. Average Actual Patch Time: 73 Days. Unpatched Critical Vulnerabilities: 4 of 14. Policy: Confirmed. Adherence: Not Measured.

4 min read · 11 Sep 2026

AI governance

AI Attack Surface Expansion

Three AI Vendors. Each Assessed Independently. Aggregate Data Access: Complete Customer Profile. Aggregate Assessment: Not Conducted.

5 min read · 10 Sep 2026

Compliance

Audit Scope Limitations

Three Samples Passed. Forty-Five Were Not Tested. The Conclusion Was Effective.

7 min read · 10 Sep 2026

Security

Access Policy Misconfigurations

The Policy Was Correct at Deployment. The System It Governs Changed. The Policy Did Not.

6 min read · 9 Sep 2026

Privacy

Data Access Privilege Creep

Each Grant Was Reasonable. The Accumulation Is Not.

6 min read · 9 Sep 2026

AI governance

AI Bias in Risk Decisions

Objective Risk Score. Training Data: Historical Assessments. More Intensive Assessment: More Findings. Score: Circular.

6 min read · 8 Sep 2026

Third-party oversight

Artifact Registry Security

Artifact: Signed. Registry: Mutable. Write Access: 17 Accounts. Former Employee Accounts: 3 Still Active.

4 min read · 8 Sep 2026

Compliance

Compliance Automation Gaps

Compliance Dashboard: Green. New Cloud Region Not Connected. New Auth System Not Integrated.

6 min read · 7 Sep 2026

Privacy

Data Access via APIs

The Database Controls Are Strong. The API Returns Everything to Everyone.

8 min read · 7 Sep 2026

Security

Alert Fatigue Across Ecosystems

Twelve Hundred Alerts. Forty-Five Seconds Each. Critical Indicator: Alert 1173.

5 min read · 6 Sep 2026

Third-party oversight

Supply Chain Attack Detection

SOC Coverage: Excellent. Detection Infrastructure: Production-Focused. Build Pipeline: Not Monitored. Compromise: 8 Months Undetected.

5 min read · 6 Sep 2026

AI governance

AI Compliance Enforcement

AI Policy: Eighteen Months Active. Reviewed Systems: Seven. Unreviewed Production Systems: Four. Enforcement: Absent.

5 min read · 5 Sep 2026

Compliance

Compliance vs Security Gap

PCI-DSS Compliant. Breached Through an Out-of-Scope System. Both True.

6 min read · 5 Sep 2026

Security

Alert Prioritisation Gaps

Static Medium Priority. Current Context: Primary TTP of Active Threat Actor. Four-Hour Review Queue.

6 min read · 4 Sep 2026

Privacy

Data Anonymization Myths

The Dataset Was Anonymized. 87% of Records Were Re-Identified in Two Weeks.

9 min read · 4 Sep 2026

AI governance

AI Compliance vs Security Gap

GDPR: Confirmed. SOC 2: Confirmed. Article 22 Right to Explanation: Model Cannot Provide It.

6 min read · 3 Sep 2026

Third-party oversight

Branch Protection and Code Review Bypasses

Branch Protection: Configured. Admin Access: Never Revoked from Incident Response. Bypass: Direct Push to Main. Code Review: None. Hardcoded Key and Path Traversal: Introduced.

5 min read · 3 Sep 2026

Compliance

Continuous Compliance Reality

All Controls Green. Friday Misconfiguration Detected Monday. Sixty-Three Hours.

6 min read · 2 Sep 2026

Privacy

Data Auditability Challenges

They Are Compliant. They Cannot Prove It. Both Are True.

7 min read · 2 Sep 2026

Security

Attack Dwell Time via Vendors

Forty-Eight Days Across Three Organisations. Customer Data Was the Final Target.

5 min read · 1 Sep 2026

Third-party oversight

Code Signing and Its Limits

Signature: Valid. Certificate: From Recognised CA. Key: Compromised 11 Months Prior. All Releases Since: Potentially Attacker-Signed.

5 min read · 1 Sep 2026

AI governance

AI Continuity and Exit Planning

Model Sunset: 90 Days. Training Data: Not Maintained. Feature Engineering: Undocumented. Alternatives: Not Evaluated. Continuity Plan: None.

5 min read · 31 Aug 2026

Compliance

Continuous Monitoring Gaps

Assessed Twelve Months Ago. Forty-Three Point Rating Drop Since. Nobody Noticed.

6 min read · 31 Aug 2026

Security

Authentication vs Authorization Confusion

Authentication Confirmed Identity. Authorization Determines What They Can Do.

6 min read · 30 Aug 2026

Privacy

Data Breach Notification Gaps

The Vendor's 72-Hour Clock Is Also Your 72-Hour Clock.

9 min read · 30 Aug 2026

AI governance

AI Data Lineage Issues

AI Detected at 2:17am. Response Started 9:15am. Seven Hours. Attacker: Still Present.

6 min read · 29 Aug 2026

Third-party oversight

Container Image Supply Chain

Application Code: Reviewed. Container Base Image: 4 Months Outdated. System Library CVEs: 17. Critical RCEs: 2.

4 min read · 29 Aug 2026

Compliance

Contractual vs Actual Controls

The Contract Requires MFA. Nobody Has Verified It Is Enforced.

6 min read · 28 Aug 2026

Privacy

Data Deletion Validation

The Deletion Was Confirmed. The Evidence Was a Screenshot of the Wrong Table.

9 min read · 28 Aug 2026

Third-party oversight

Dependency Confusion Attacks

Internal Package: acme-internal-utils. Job Posting: Mentioned Internal Tooling. Public Registry: Attacker Published Same Name, Higher Version. 23 Applications: Compromised.

4 min read · 27 Aug 2026

Security

Vendor Backup Storage Exposure

The Copy of Your Data That Nobody Assessed

10 min read · 27 Aug 2026

AI governance

AI Data Retention Risks

M&A Targets Uploaded for Summarisation. Retained Thirty Days. Zero Retention: Not Configured.

6 min read · 26 Aug 2026

Compliance

Control Duplication

Three Teams. Three Controls. All Doing the Same Thing. None Knowing About the Others.

6 min read · 26 Aug 2026

Security

Breach Attribution Challenges

Three Hypotheses. All Consistent With Evidence. Attribution May Never Be Definitive.

5 min read · 25 Aug 2026

Privacy

Data Exfiltration Paths

The Sophisticated Attack Vector Is a Spreadsheet Attached to a Gmail.

9 min read · 25 Aug 2026

AI governance

AI-Driven Automation Risks

847 Renewal Offers. 312 Sent to Customers Who Had Cancelled. Automation: Correct. Integration: Missing.

5 min read · 24 Aug 2026

Third-party oversight

Dependency Pinning vs Floating Versions

Version Spec: >=2.0.0. New Version Published Thursday: 2.4.0. Tests: Passed Thursday. Production: Deployed Different Software Friday.

4 min read · 24 Aug 2026

Compliance

Control Inheritance Misunderstandings

ISO 27001 Certified. The Certification Scope Does Not Cover Your Service.

6 min read · 23 Aug 2026

Privacy

Data Governance Tooling Gaps

The Policies Are Excellent. The Tools That Would Enforce Them Were Never Bought.

6 min read · 23 Aug 2026

Security

Breach Simulation Gaps

Simulation: Scripted Scenario. Real Breach: Unknown Scenario, Uncooperating Attacker, Uncertain Detection.

5 min read · 22 Aug 2026

Third-party oversight

Vendor Development Environment Security

Production: Secured. Developer Workstations: Local Admin. Credentials in Dotfiles. Personal GitHub Accounts for Work. Malicious VSCode Extensions Installed.

4 min read · 22 Aug 2026

AI governance

AI Explainability Challenges

SHAP Values: What the Model Used. Why Those Features Are Valid Credit Risk Indicators: Not Answerable from Outputs.

4 min read · 21 Aug 2026

Compliance

Control Mapping Inconsistencies

One Control Mapped to Five Frameworks. The Mapping Accuracy Varies by Framework.

6 min read · 21 Aug 2026

Security

Cloud Security

Vendor Access, Misconfigurations, and the Risk You Invited In

7 min read · 20 Aug 2026

Privacy

Data Governance vs Enforcement

The Policy Was Approved Three Years Ago. Nobody Has Checked Compliance Since.

8 min read · 20 Aug 2026

AI governance

AI Governance Frameworks

AI Ethics Policy: Confirmed. Model Review Process: Described. Implementation Evidence: Not Requested.

5 min read · 19 Aug 2026

Third-party oversight

Vendor Security Disclosure Programmes

Disclosure Programme: Published. Report: Submitted. Acknowledged: Yes. Patched Within 7 Months: No. Advance Notice to Customers: Zero.

4 min read · 19 Aug 2026

Compliance

Control Testing Depth

No Critical Vulnerabilities Found. Internal Network Not in Scope. Neither Was the Cloud.

6 min read · 18 Aug 2026

Privacy

Data Inventory Completeness

The Inventory Has Seven Systems. The Environment Has Twenty-Three.

8 min read · 18 Aug 2026

Security

Conditional Access Gaps

Strong Authentication. Unmanaged Device. Untrusted Network. Sensitive Data Downloaded.

6 min read · 17 Aug 2026

Third-party oversight

The Future of Software Supply Chain Security

Current Programme: Current for Today. AI-Generated Code: In Vendor Pipelines Now. Post-Quantum: On the Timeline. Regulatory Acceleration: Already Landed.

4 min read · 17 Aug 2026

AI governance

AI Governance Gaps

AI Ethics Committee: Reviewed and Approved. EU AI Act High-Risk Classification: Not Assessed.

7 min read · 16 Aug 2026

Compliance

Control vs Implementation Gap

The Penetration Test Programme Exists. The Last Test Was Fourteen Months Ago.

6 min read · 16 Aug 2026

Security

Coordinated Response Failures

Vendor Plan: Preserve Everything. Customer Plan: Service Restored in Twenty-Four Hours. Both Correct. Both Impossible.

5 min read · 15 Aug 2026

Privacy

Data Lifecycle Mismanagement

Creation Is Governed. Retention Is Optional. Deletion Is Nobody's Job.

9 min read · 15 Aug 2026

AI governance

AI Hallucination Risk in Decisions

Credit Denied. Reason: Fourteen Features. Dominant Feature: Payment Timing Meets Geographic Mobility. Appeal: Dismissed.

6 min read · 14 Aug 2026

Third-party oversight

Infrastructure-as-Code Supply Chain Risk

IaC: Reviewed. Third-Party Terraform Modules: 14 Months Stale. Security Group: Management Ports Open to 0.0.0.0/0. Module Review: Not Conducted.

4 min read · 14 Aug 2026

Privacy

Data Lineage Across Third Parties

You Approved the First Hop. Where Did the Data Go After That?

10 min read · 13 Aug 2026

Compliance

Evidence vs Attestation

The Attestation Was Accurate for Two of Three Databases. One Was Different.

6 min read · 13 Aug 2026

Security

Cross-Org Response Timelines

Same Threat. Two IR Teams. Seven IOCs and Four IOCs. No Sharing. Ten Total Missed.

5 min read · 12 Aug 2026

Third-party oversight

Supply Chain Incident Response

IR Programme: Mature for Production Incidents. Supply Chain Playbook: None. Affected Release Identification: No Process. Customer Deployment Inventory: Not Maintained.

4 min read · 12 Aug 2026

AI governance

AI Incident Response Gaps

AI Decision Incident. IR Playbook: Data Breach, Ransomware, Outage. AI Incident: Not Covered.

5 min read · 11 Aug 2026

Compliance

Exception Management Abuse

Forty-One Exceptions. Thirty-Seven Are Engineering Deferrals. Four Over a Year Old.

6 min read · 11 Aug 2026

Security

Cross-Platform Visibility

Vendor Monitors AWS. DevOps Provider Monitors the Cluster. Both Assume. Neither Confirms.

5 min read · 10 Aug 2026

Privacy

Data Minimization Failures

You Sent Everything. The Vendor Needed Some of It. The Breach Exposed All of It.

9 min read · 10 Aug 2026

AI governance

AI Inference Data Leakage

Zero Retention Configured. In-Session Context Window: Customer Data Accessible to Crafted Prompts.

6 min read · 9 Aug 2026

Third-party oversight

Open Source License Risk

Platform Deployed: 18 Months. AGPL Component: Discovered by Legal. Disclosure Requirement: Potentially Applies to Vendor's Proprietary Code. Legal Review: 6 Months.

4 min read · 9 Aug 2026

Privacy

Data Ownership Ambiguity

Your Data Trained the Model. The Vendor Owns the Model.

8 min read · 8 Aug 2026

Compliance

GRC Tooling Limitations

The GRC Platform Manages What You Put Into It. It Does Not Know What You Left Out.

7 min read · 8 Aug 2026

Security

Cross-System Identity Propagation

Deprovisioned in Azure AD. Active in the Jira Instance Nobody Added to the Connector.

6 min read · 7 Aug 2026

Third-party oversight

Supply Chain Risk in Mergers and Acquisitions

Platform Acquired. Open-Source Dependencies: 1,247. Critical Vulnerabilities: 73. Unresolvable Due to EOL: 14. Runtime: 3 Major Versions Behind. Due Diligence: No Supply Chain Assessment.

4 min read · 7 Aug 2026

AI governance

AI Logging and Traceability

Audit Log: API Called. Decision Returned. Model Version: Not Captured. Input Features: Not Captured. Decision: Unreconstructable.

6 min read · 6 Aug 2026

Compliance

Governance Accountability Gaps

RACI Matrix Exists. Nobody Made the 11pm Call. Nobody Read the Contract.

6 min read · 6 Aug 2026

Security

Cross-Tenant Access Risks

When Your Vendor Serves Other Customers , and Their Risk Becomes Yours

8 min read · 5 Aug 2026

Privacy

Data Replication Risks

The Primary Database Has Eleven Copies. How Many Are Governed?

9 min read · 5 Aug 2026

AI governance

AI Misuse by Vendors

Support AI. Historical Training Labels. Historical Bias Encoded as Normal. Production Outage: Low Priority.

5 min read · 4 Aug 2026

Third-party oversight

Supply Chain Security Maturity Assessment

SBOM: Level 3. SCA: Level 3. SLSA: Level 0 (Unaware). Build Pipeline Security: Level 1. Supply Chain Monitoring: Level 0.

4 min read · 4 Aug 2026

Privacy

Data Residency vs Access

The Data Lives in Germany. The Support Team Is in Manila. Both Are True.

9 min read · 3 Aug 2026

Compliance

Governance Ownership Ambiguity

Three Teams Own the Vendor. None of Them Owned the Incident Response.

6 min read · 3 Aug 2026

Security

Cross-Tenant Attack Detection

Customer A Breached. Investigation: Did Not Spread. Customer B Notified Three Weeks Later.

5 min read · 2 Aug 2026

Third-party oversight

NIST SP 800-161 for Practitioners

NIST 800-161: Reviewed and Considered Aligned. Implementation Tier: Not Assessed. Controls Implemented: Not Verified.

4 min read · 2 Aug 2026

AI governance

AI Misuse Scenarios

AI Sales Tool: Approved. Personalised Outreach: Generated. Prospect Research: Autonomous, Undisclosed, Unconsented.

5 min read · 1 Aug 2026

Compliance

Policy vs Enforcement

Twelve-Character Policy. Eight-Character Configuration. Both Active Simultaneously.

6 min read · 1 Aug 2026

Security

Data Exfil Detection Gaps

Twelve Transfers. Eleven Gigabytes. All Below the DLP Threshold. No Alerts.

6 min read · 31 Jul 2026

Privacy

Data Segregation Failures

The Tenant Isolation Is a WHERE Clause. One Bug and It Is Gone.

8 min read · 31 Jul 2026

AI governance

AI Model Supply Chain Risk

The Model Works Perfectly. The Risk Is in What It Was Trained On and Who Has Access to It.

8 min read · 30 Jul 2026

Third-party oversight

Vendor Open Source Contribution Risk

Engineer: 3 Years Trusted Contributions. Employee Status: Departed. PR: Backdoor. Merge: Approved Based on Reputation. Affected Vendors: 14.

4 min read · 30 Jul 2026

Privacy

Data Sovereignty Enforcement

The Data Is Sovereign. The Parent Company Is Not.

7 min read · 29 Jul 2026

Compliance

Questionnaire Fatigue vs Real Risk

400 Questions. Three Weeks. The Specific Risk Was Never Asked About.

5 min read · 29 Jul 2026

Security

Delegated Admin Risks

Delegated Admin Granted at Onboarding. Configuration Ended. Access Remains.

7 min read · 28 Jul 2026

Third-party oversight

Package Registry Trust Model

Package: Legitimate. Maintainer: Compromised via Social Engineering. Version Update: Bug Fix + Credential Harvesting. Downloads: 14,000 Weekly.

4 min read · 28 Jul 2026

AI governance

AI Model Version Control

Foundation Model: Eleven Months Outdated. Security Patches: Three. Privilege Escalation: Unpatched. Validation Cycle: Three to Four Months.

6 min read · 27 Jul 2026

Compliance

Regulatory Blind Spots

US Customer. US Vendor. Irish Data Storage. GDPR Applies. Was Never Assessed.

6 min read · 27 Jul 2026

Privacy

Data Tagging Inconsistencies

Confidential in the Source System. Public in the Analytics Platform. Same Data.

6 min read · 26 Jul 2026

Security

Detection Blind Spots

Platform Sees Everything Configured. Configuration Set at Deployment. New Services: Not Configured.

7 min read · 26 Jul 2026

AI governance

AI Operational Risks

94% Accuracy. 6% Missed. Missed Records: Systematically the Most Complex. Human Review: Assumed Comprehensive.

5 min read · 25 Jul 2026

Third-party oversight

Supply Chain Security in Regulated Industries

FDA SBOM Requirement: Met. Critical CVEs in SBOM: 17. VEX Documentation: Not Provided. Regulatory Review Delay: 4 Months.

4 min read · 25 Jul 2026

Privacy

Data Usage Monitoring

You Know What You Sent. You Have No Idea What They Do With It.

7 min read · 24 Jul 2026

Compliance

Regulatory Interpretation Gaps

Five Years From Collection. Five Years From Last Transaction. Both Claim Compliance.

5 min read · 24 Jul 2026

Security

Detection Engineering Gaps

Default Rules. Platform Inherited. No Customisation. Attacker Uses Industry-Specific Techniques.

6 min read · 23 Jul 2026

Third-party oversight

Reproducible Builds in Practice

500 Packages Analysed. 312: Reproducible. 188: Not Reproducible. The 188: Source Code Does Not Uniquely Determine Binary.

4 min read · 23 Jul 2026

AI governance

AI Output Data Leakage

AI Draft. Confident Statements. Factually Incorrect. Published as Analysis.

6 min read · 22 Jul 2026

Compliance

Regulatory Overlap Confusion

HIPAA or PCI-DSS? Both. The More Stringent Requirement Applies.

6 min read · 22 Jul 2026

Security

Detection vs Prevention Balance

Zero Breaches. Three Near-Misses. Prevention Working. Breach Record Not Telling the Story.

5 min read · 21 Jul 2026

Privacy

Encryption at Rest vs In Use

AES-256 Confirmed. The DBA Reads It in Plaintext. Both Are True.

8 min read · 21 Jul 2026

AI governance

AI Plugin Vulnerabilities

94% Detection Rate. 56 Hours of False Positive Investigation. 23 Missed Anomalies. None of It in the Dashboard.

7 min read · 20 Jul 2026

Third-party oversight

Supply Chain Risk Quantification

Risk Ratings: High, Medium, High. Financial Exposure: Not Calculated. Board Communication: Not Possible. Investment Justification: Not Available.

4 min read · 20 Jul 2026

Privacy

Insider Access at Vendors

The Threat That Has Valid Credentials, Authorized Access, and Four Months of Patience.

9 min read · 19 Jul 2026

Compliance

Reporting vs Insight

Four Consistent Numbers. Six Months of Reports. Zero Decisions Informed.

6 min read · 19 Jul 2026

Security

Device Trust for Vendor Access

Perfect Authentication. Unmanaged Device. Customer Data on a Personal Laptop.

6 min read · 18 Jul 2026

Third-party oversight

Programming Language Runtime Security

Platform: Well-Patched Application Code. Runtime: Python 3.9, EOL October 2025. Critical Runtime CVEs: 3. Future Patches: None.

4 min read · 18 Jul 2026

AI governance

AI Risk Scoring Reliability

Risk Score: 73. Historical Accuracy at This Range: Unknown. Confidence Interval: None. Trend: Not Available.

6 min read · 17 Jul 2026

Compliance

Risk Acceptance Misuse

Accepted Three Years Ago. Still Accepted. Nobody Has Reviewed It.

6 min read · 17 Jul 2026

Security

Forensics Access Challenges

Forensic Access Requested. Legal Hold In Place. Investigation Blocked for Three Weeks.

6 min read · 16 Jul 2026

Privacy

Metadata Exposure Risks

The Data Was Protected. The Metadata Told Them Everything They Needed.

9 min read · 16 Jul 2026

AI governance

AI Security Monitoring

Weekly Reports: Alert Volumes, Resolution Rates, Coverage Statistics. Gaps, Limitations, Human Supplement Needed: Not Shown.

6 min read · 15 Jul 2026

Third-party oversight

Software Bill of Materials Automation

847 SBOM Documents. 7 Formats. 93% Never Parsed. 41% Over 12 Months Old. Supply Chain Visibility: None.

4 min read · 15 Jul 2026

Compliance

Risk Appetite Misalignment

Risk Appetite: No Vendor Over Fifteen Percent. One Vendor at Forty-Two. Predates the Policy.

6 min read · 14 Jul 2026

Privacy

Sensitive Data Discovery Gaps

The Vendor Does Not Know They Have Your Sensitive Data. Neither Do You.

8 min read · 14 Jul 2026

Security

Identity Anomaly Detection Gaps

2am. Lagos. Seventeen Apps. Six Hundred Files. No Alert.

7 min read · 13 Jul 2026

Third-party oversight

Software Bill of Materials , Beyond the Mandate

SBOM: Provided. Critical Vulnerabilities Listed: 14. SBOM Age: 6 Months. Vulnerability Status: Not Included. Regulator: Not Satisfied.

4 min read · 13 Jul 2026

AI governance

AI Security Testing Gaps

SOC 2: Infrastructure Covered. Pentest: Web App Covered. Code Review: Application Covered. AI Model: Not Tested.

6 min read · 12 Jul 2026

Compliance

Risk Communication Gaps

The Risk Was Identified. It Was Documented. It Was Never Communicated to the People Who Could Have Done Something About It.

7 min read · 12 Jul 2026

Security

Identity Attack Surface Expansion

One IdP Three Years Ago. Seven Authentication Systems Today. Who Is Mapping Them?

6 min read · 11 Jul 2026

Privacy

Structured vs Unstructured Data Risk

The Database Is Governed. The Shared Drive Is Not. Both Hold Your Data.

9 min read · 11 Jul 2026

AI governance

AI Supply Chain Dependencies

Four AI Pipeline Libraries. Three Well-Audited. One: Single Maintainer, Eight Months Inactive, Arbitrary Code Execution.

6 min read · 10 Jul 2026

Third-party oversight

Software Composition Analysis Gaps

SCA Configured: Main Branch, Python Only, CVE IDs Only. Uncovered: 7 Repositories, Go and Java Services, Non-CVE Issues.

4 min read · 10 Jul 2026

Compliance

Risk Prioritisation Failures

Twelve High-Priority Items. One Matters Most. None Are Being Treated Differently.

6 min read · 9 Jul 2026

Privacy

Tokenization vs Masking Confusion

The Token Is Safe. The Token Vault Is the Database. Who Can Query the Vault?

9 min read · 9 Jul 2026

Security

Identity Compromise Blast Radius

The Compromise Will Happen. The Blast Radius Is What You Govern Now.

6 min read · 8 Jul 2026

Third-party oversight

Third-Party SDK Risk

SDK Evaluated at Integration. Vendor Acquired 18 Months Later. SDK Updated: New Data Collection. Enterprise Privacy Policy: Not Reflecting New Collection.

4 min read · 8 Jul 2026

AI governance

AI Threat Detection Gaps

Detection Dashboard: All Green. Novel Technique Category: Not on the Dashboard. Attacker: Undetected.

6 min read · 7 Jul 2026

Compliance

Risk Quantification Challenges

Score of 47. Probability of Breach: Unknown. Financial Impact: Unknown.

6 min read · 7 Jul 2026

Security

Identity Federation Trust Risks

You Federated with Their IdP. Their Security Posture Is Now Part of Your Perimeter.

7 min read · 6 Jul 2026

Privacy

Vendor Analytics Access Risks

Read Access to Everything Is Still Access to Everything.

9 min read · 6 Jul 2026

AI governance

Supply Chain AI Trust Boundaries

Finance AI Trusted to Answer Policy Questions. Attacker with Compromised Credentials: Also Trusted. AI Cannot Tell the Difference.

5 min read · 5 Jul 2026

Third-party oversight

What Is SLSA and Why Your Vendors Should Care

SLSA Compliant: Confirmed. SLSA Level: 1. What Level 1 Means: Build Process is Documented. What It Doesn't Mean: Build Is Tamper-Resistant.

6 min read · 5 Jul 2026

Compliance

Risk Register Accuracy

Ninety-Three Entries. Zero Closed in Eighteen Months. Not a Risk Picture. An Archive.

6 min read · 4 Jul 2026

Privacy

Vendor Backup Data Risk

The Backup Is Your Production Data. It Just Lives Somewhere Nobody Governs.

9 min read · 4 Jul 2026

Security

Identity Governance Gaps

The IGA Covers Joiners, Movers, and Leavers. Vendor Identities Are in a Spreadsheet.

7 min read · 3 Jul 2026

Third-party oversight

Software Supply Chain for SaaS Products

Installed Software: SBOM, SCA, Provenance Verification. SaaS Platform: Same Supply Chain Risk. Visibility: None.

4 min read · 3 Jul 2026

AI governance

AI Vendor Lock-In Risks

API Deprecation Notice: 30 Days. Migration Plan: None. Alternative Evaluated: None. Calibration Reproducible: No.

5 min read · 2 Jul 2026

Compliance

Risk Scoring Subjectivity

Same Evidence. Same Vendor. Score of 34. Score of 67. Both From Your Team.

6 min read · 2 Jul 2026

Security

Identity-Based Lateral Movement

One Developer Credential. Four Identity Hops. Production Database.

6 min read · 1 Jul 2026

Privacy

Vendor Data Access Reviews

The Review Was Completed. Every Account Was Approved. Half of Them Should Not Exist.

9 min read · 1 Jul 2026

AI governance

API-Based AI Exposure

Vendor Confirmed Data Security. Data Was Flowing to OpenAI. Enterprise Had Never Assessed OpenAI.

6 min read · 30 Jun 2026

Third-party oversight

Secrets in Source Code

Policy: No Hardcoded Credentials. Git History: AWS Key, Database Credentials, RSA Key , 31 Months. Status: Technically Still There.

4 min read · 30 Jun 2026

Compliance

SLA vs Enforcement

Four SLA Breaches in Eighteen Months. Four Service Credits Issued. Behaviour Unchanged.

6 min read · 29 Jun 2026

Privacy

Vendor Data Aggregation Risks

Your Dataset Is Fine. Forty of Them Combined Is a Competitive Intelligence Weapon.

8 min read · 29 Jun 2026

Security

Identity Logging Gaps

Authentication Succeeded. The Sixty-Eight Failed Attempts Before It Are Nowhere in the Log.

7 min read · 28 Jun 2026

Third-party oversight

Sigstore and the Transparency Log Revolution

Signing Key: File on Build Server, 3 Years Unrotated. Sigstore: Free, Short-Lived Certificates, Public Audit Log. Vendor Awareness: None.

4 min read · 28 Jun 2026

AI governance

LLM Integration Risks

LLM Connected to 140,000 Documents. Service Account Access Broader Than User Permissions. Context Window: Exfiltration Channel.

6 min read · 27 Jun 2026

Compliance

Third-Party Audit Reliance

Big Four SOC 2. Clean Report. The Auditor's Mandate Was Not Your Risk.

6 min read · 27 Jun 2026

Security

Identity Proofing of Vendors

The Credential Belongs to Alex Chen. Who Is Alex Chen?

7 min read · 26 Jun 2026

Privacy

Vendor Data Enrichment Risks

You Sent Names and Emails. The Platform Added Thirty-Seven Data Points.

9 min read · 26 Jun 2026

AI governance

Model Access Control

Authenticated API. Rate Limiting: None. Query Volume: 500,000. Model: Reconstructed by Competitor.

6 min read · 25 Jun 2026

Third-party oversight

Software Provenance Verification

Signature: Valid. Delivery: HTTPS. Download URL: Legitimate. Distribution Infrastructure: Compromised 3 Weeks Prior. Software: Attacker's.

5 min read · 25 Jun 2026

Compliance

Third-Party vs Fourth-Party Risk

Your Vendor Is Assessed. Their Subprocessor Processes Half Your Data. Unassessed.

6 min read · 24 Jun 2026

Privacy

Vendor Data Lake Exposure

Designed for Maximum Accessibility. Filled with Maximum Sensitivity.

9 min read · 24 Jun 2026

Security

Identity Trust Assumptions

Trust Was Established at Onboarding. It Has Been Assumed Ever Since.

6 min read · 23 Jun 2026

Third-party oversight

The SolarWinds Lessons Still Unlearned

SolarWinds: 2020. Assessment Checklist: Same Questions as 2019. Build Pipeline: Not Asked About.

4 min read · 23 Jun 2026

AI governance

Model Drift Risks

Metrics: Stable. Detection Rate: Good. Behaviour: Quietly Changed Over Eight Months.

6 min read · 22 Jun 2026

Compliance

Vendor Audit Rights Enforcement

Right-to-Audit: Three Years in the Contract. Three Years Never Exercised.

6 min read · 22 Jun 2026

Security

Incident Communication Breakdowns

Seven Emails. Three Weeks. No Technical Detail. Exposure Assessment Incomplete.

6 min read · 21 Jun 2026

Privacy

Vendor Data Retention Practices

The Contract Ended. The Data Did Not.

8 min read · 21 Jun 2026

AI governance

Model Theft Risks

Model Secured. Vendor API Secured. Enterprise Customer Application: Not Secured. Model: Accessed Through the Customer.

6 min read · 20 Jun 2026

Third-party oversight

Threat Intelligence for Supply Chain Attacks

Threat Intel Report: Received. CI/CD and SDK Targeting: Described. Vendor Assessments Updated: No. Two Vendors Targeted: 6 Months Later.

4 min read · 20 Jun 2026

Compliance

Vendor Control Drift

Assessed Two Years Ago. Sixty Percent Security Turnover Since. Drifting.

6 min read · 19 Jun 2026

Privacy

Vendor Data Transformation Risks

You Sent Customer Records. The Vendor Made Something New From Them.

6 min read · 19 Jun 2026

Security

Incident Escalation Across Vendors

Vendor Classifies P2. Customer Regulatory Clock Starts at Hour Zero. Customer Learns at Hour Thirty-Six.

6 min read · 18 Jun 2026

Third-party oversight

Transitive Dependency Risk

Direct Dependencies: Zero Critical Vulnerabilities. Transitive Dependency Depth 4: Critical Vulnerability. SCA Scope: Direct Dependencies. Depth 4: Out of Scope.

4 min read · 18 Jun 2026

AI governance

Prompt Injection via Vendors

Customer Service Chatbot. Attacker Sends an Inquiry. LLM Follows the Attacker's Instructions.

7 min read · 17 Jun 2026

Compliance

Vendor Reassessment Frequency

Assessed Eighteen Months Ago. Three Hundred Million More Records Since. Still Tier 2.

6 min read · 17 Jun 2026

Security

Incident Ownership Confusion

Legal Says Business Owns It. Business Says IR Owns It. IR Says Legal Owns It. Clock Running.

5 min read · 16 Jun 2026

Privacy

Vendor Reporting Data Leaks

The Dashboard Is Beautiful. The Export Behind It Is Unprotected Customer Data.

6 min read · 16 Jun 2026

AI governance

Third-Party AI Integrations

Salesforce Einstein. HubSpot AI. Workday AI. Enabled by Default. Assessed as SaaS. Never as AI.

6 min read · 15 Jun 2026

Third-party oversight

Typosquatting in Package Registries

Legitimate Package: lodash. Typosquatted: lodash-utils. Downloads: 43,000. Production Deployments: 312. CVE: None. SCA Alert: None.

4 min read · 15 Jun 2026

Security

Incident Playbook Gaps

Step Four: Isolate Per Appendix C. Weekend. Nobody Has Appendix C. Forty Minutes Lost.

6 min read · 14 Jun 2026

Compliance

Vendor Risk Aggregation

Three Low-Risk Vendors. Same Cloud Provider. Same Dataset. Same Production Access. Not Low Risk.

6 min read · 14 Jun 2026

Third-party oversight

Software Update Mechanism Security

Auto-Update: Enabled by Default. Certificate: Compromised 3 Months Prior. Updates Applied: Potentially Compromised. Enterprise Aware: No.

4 min read · 13 Jun 2026

AI governance

Training Data Poisoning

The Model Learned from Three Years of Data. One Year Was Labelled Wrong. The Model Learned That Too.

7 min read · 13 Jun 2026

Security

Incident Response SLAs

Forty-Seven Hours Fifty-Nine Minutes. SLA Met. Scope Unknown. Customer Cannot Respond.

5 min read · 12 Jun 2026

Compliance

Vendor Tiering Inaccuracies

Tier 3: Office Supplies. Also: Real-Time Warehouse System Integration. Both True.

6 min read · 12 Jun 2026

Third-party oversight

VEX , Vulnerability Exploitability eXchange

SCA Findings: 312. Actually Exploitable: 23. VEX Available: No. Triage Time: 3 Weeks.

4 min read · 11 Jun 2026

AI governance

Vendor AI Usage Transparency

AI Features: Disclosed. AI Used to Score, Classify, and Route the Enterprise: Not Disclosed.

6 min read · 11 Jun 2026

Security

Insider Threats at Vendors

Legitimate Access. Personal Cloud Account. Seventeen Thousand Records. Three Months.

6 min read · 10 Jun 2026

Third-party oversight

Zero Trust for Software Supply Chains

Network: Zero Trust. Dependencies: Pulled Without Publisher Verification. Build Agents: Broad Credentials. Software Updates: Server Identity from HTTPS Certificate Only.

5 min read · 10 Jun 2026

Security

Just-in-Time Access vs Standing Access

Standing Access Runs 720 Hours a Month. It Is Needed for Four.

7 min read · 9 Jun 2026

Third-party oversight

Software Supply Chain Security

SLSA, SBOM, and the Hidden Risk in Every Line of Code You Trust

6 min read · 9 Jun 2026

Security

Least Privilege in Vendor Access

You Gave Them Admin Because It Was Easier. It Was Never Revoked.

8 min read · 8 Jun 2026

Third-party oversight

Vendor Access Creep Over Time

Original Access: Read-Only Names and Emails. Three Years Later: Five Data Categories. Four Expansions: Zero TPRM Reviews.

4 min read · 8 Jun 2026