Insights

Thinking at the intersection of security and AI.

Original analysis for CISOs and security leaders. No link dumps — every article is a deep dive.

Filter: AI AgentsAI GovernanceAI SecurityAnnual ReviewAutomationCISOCase StudyComplianceCyber TerrorismDACHEU AI ActEnterprise SecurityFrameworkGRCGermanyGovernanceISO 27001ISO 42001Incident ResponseNIS2NISTRSA ArcherRegulationSABSASecurity ArchitectureServiceNowShadow AISupply ChainTOGAFThird-Party RiskVendor Risk
AI AgentsCISO

We Replaced Our Team of 6 with AI Agents — Here's What Actually Happened

We didn't just build AI security agents for clients — we deployed them on ourselves first. Here's the honest story: what worked, what didn't, and why every CISO should pay attention.

Feb 17, 2026 Read more →
AI GovernanceShadow AI

Shadow AI Is Your Biggest Blind Spot — Here's How to Fix It

Your employees are using AI tools you don't know about, feeding them data you can't track. A practical framework for discovering and governing Shadow AI before it becomes your next incident.

Feb 17, 2026 Read more →
Security ArchitectureAI Security

Security Architecture in the AI Era: From SABSA and TOGAF to Agent Trust Boundaries

The frameworks you already know — SABSA, TOGAF, OSA — still apply. But AI agents introduce new trust boundaries, non-human identities, and autonomous decision-making that your current architecture doesn't cover.

Feb 15, 2026 Read more →
GermanyNIS2

German Cyber Security 2026: NIS2, the AI Act, and the Rise of the AI-Powered CISO

Our annual review of the German cyber security landscape. NIS2 enforcement is here, the EU AI Act is live, and CISOs are discovering that AI agents are both the threat and the solution.

Feb 12, 2026 Read more →
FrameworkNIST

Your NIST 800-53 Controls Already Cover AI Agents

47 existing controls, 14 control families, mapped directly to AI agent architecture. Not a new framework — a practical security pattern.

Feb 10, 2026 Read more →
Vendor RiskAI Governance

Third-Party AI Risk: Your Vendors Are Using AI — Here's Why That's Your Problem

Your vendors are deploying AI agents you can't see, processing your data in ways you haven't approved. NIS2 Article 21(2)(d) makes this your responsibility. Here's how to get ahead of it.

Feb 8, 2026 Read more →
Supply ChainCyber Terrorism

Supply Chain Attacks 2026: From SolarWinds to AI Agent Compromise

SolarWinds compromised 18,000 companies through one vendor update. Now imagine the same attack vector through AI agents with autonomous data access. The supply chain threat has evolved.

Feb 5, 2026 Read more →
GRCAI Agents

Conversational GRC vs Traditional Dashboards: Why Your Team Hates Archer

RSA Archer costs €500K/yr and nobody uses it. ServiceNow GRC needs 3 consultants to configure. What if your GRC system was just... a conversation?

Feb 3, 2026 Read more →
NIS2Compliance

NIS2 Readiness: What German CISOs Actually Need to Do

Practical guide to NIS2 compliance for German enterprises. What Article 21 requires, who's in scope, and how AI can accelerate your readiness.

Jan 28, 2026 Read more →
ISO 42001AI Governance

ISO 42001 for Practitioners: What the AI Management System Standard Actually Requires

ISO 42001 is the world's first AI management system standard. Most guidance online is theoretical. Here's the practical version — what you actually need to implement, and how it maps to ISO 27001.

Jan 20, 2026 Read more →