Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

AI Supply Chain Security: Why an SBOM Cannot Cover It

A software bill of materials works because software changes through a build. Someone bumps a dependency, the pipeline runs, the manifest updates and a scanner compares the new list against known vulnerabilities. Every part of that loop assumes a rebuild is the thing that changes behavior. ‍ AI systems break that assumption at the point it matters most. Editing a system prompt changes what a model does, swaps no dependency, triggers no build and produces no new manifest.

From AI Findings to Action: How Security Teams Should Triage AI-Discovered Vulnerabilities

Security teams didn’t need a headline to tell them that vulnerability volumes continue to be problematic. The CVE database now contains over 354,000 records. Annual disclosure rates have climbed steadily for more than a decade. And remediation backlogs have long been recognized not as an aberration, but as a fixture of the job.

Continuous risk monitoring in third-party risk management is non-negotiable: Here's why

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Human in the Loop: How to Tell If the Review Is Real

Human oversight is the only control in an AI program that can stop working while producing exactly the same evidence as when it worked. A failed encryption control throws errors. A monitoring pipeline that breaks stops delivering alerts. A review step that has become a formality still generates approvals, timestamps and sign-offs, and the compliance file looks identical. ‍ The asymmetry makes the design question secondary to the measurement one.

One Loss Distribution, Two Very Different Charts

A cyber loss model produces one distribution. How that distribution gets drawn changes what a reader can see in it, and the conventional projection hides the part most decisions depend on. ‍ The two views below contain identical data. One of them is close to unreadable for anything except the extreme tail, and the difference is worth understanding before the next time somebody asks what the number means. ‍

Legacy GRC can't keep up. Cyber risk assurance can.

Enterprise security teams need to secure a risk surface that is constantly changing. However, the tools in their stack were built to check only a fraction of that risk. For confirmation, they rely on static snapshots and annual attestations. I now see this as the defining problem in GRC. When 451 Research (S&P Global) initiated coverage of TrustCloud in this space, they described a clear and growing divide.

The 12 Best Third-Party Risk Management Software Solutions (2026)

‍Last updated: August 20, 2026‍ A supplier breach or a tough question from a regulator can force a rushed third-party risk management (TPRM) evaluation. You need an answer before the next steering meeting. This list compares the 12 best third-party risk management tools in 2026, based on the capabilities that separate them in daily use, so you can shortlist faster. Whether you're an analyst running early research or a CISO approving the budget, you're working from the same criteria.

What Counts as One AI Asset? Getting the Unit Right

Two teams inventory the same organization and return different numbers. One counts forty-one AI assets, the other counts one hundred and twelve. Neither is wrong, because they counted different things, and nobody had decided what a row represents. ‍ Guidance on building an AI inventory covers which fields a row should carry and skips what a row is. That question determines the count, the risk scores, the regulatory classification and whether two inventories can ever be reconciled.

Maturity Is a Lagging Indicator. Here's a Leading One.

A maturity score answers where a program has been. It reports the state of documented process at the moment somebody assessed it, on a cadence measured in quarters or years, using a scale that describes organization rather than outcome. Every property that makes it useful for planning makes it useless as an early warning. ‍ The interesting question is what a leading indicator would look like instead, and the answer requires separating two problems that get treated as one.

How To Build An AI Risk Management Framework

Every AI approval a security team makes feels reasonable in isolation. A security architect signs off on a generative AI writing tool for marketing. An engineering lead spins up an agent to triage support tickets. A finance team connects a copilot to its planning software. Individually, none of these decisions looks risky.