Articles
Short, practical series on cyber risk written for the people who have to make the decisions — not for security specialists.
4 series · 17 articles
Risk in Plain Language
A five-part series on cyber risk for small businesses and nonprofits — why size is no shield, how attacks actually unfold, where to start with no security team, which common beliefs are working against you, and the questions leadership should be asking.
Read the seriesAI Risk & Governance
A four-part series on adopting AI without losing control of it — why ignoring AI and winging it are both mistakes, what your team is already doing with tools you never approved, the five questions to ask before adopting any AI tool, and a one-page use policy your team will actually read.
Read the seriesIncident Response
A four-part series on being ready for the incident you can't prevent — why "we're too small to be a target" is the most expensive assumption a small organization can make, what the first 24 hours of a real breach actually look like, how to build a one-page response plan in a single afternoon, and how to keep that plan honest through tabletop exercises and board oversight.
Read the seriesVendor & Third-Party Risk
A four-part series on the risk you inherit from everyone you do business with — how two real breaches began at a vendor rather than the victim, the five questions to ask before you sign with anyone, why outsourcing IT to an MSP does not outsource your security responsibility, and what a board should be asking about who has your data.
Read the series