Fractional CISO working on laptop
Blog

Insights from Security Leaders

Strategy

CISO, fCISO, vCISO, or CISO to the CISO: What's the Difference?

The security leadership market has fragmented. Here's how to tell the difference between a full-time CISO, a fractional CISO, a virtual CISO, and a CISO to the CISO.

3 April 202610 min read
Read article
Threat Intelligence

Iranian Cyber Operations: An Update for CISOs

Handala's shift from wiper malware to native admin tool abuse is a tactical change, not a strategic surprise. What it reminds us about identity, supply chain, and detection.

3 April 20268 min read
Read article
Leadership

A practical guide to your first 90 days as a CISO

The first 90 days in a CISO role set the trajectory for your entire tenure. Here's how to navigate them with purpose, pragmatism, and a plan.

2 April 202610 min read
Read article
Device Security

Morgan McSweeney's Stolen Phone: Lessons for CISOs

When Morgan McSweeney's government phone was stolen in London, it exposed gaps in mobile device security that every CISO should address.

28 March 20266 min read
Read article
Supply Chain Security

LiteLLM Supply Chain Attack: Five Actions for CISOs

On March 24, 2026, LiteLLM version 1.82.8 was compromised on PyPI. Five actions CISOs need to take to address AI-accelerated supply chain threats.

26 March 20265 min read
Read article
Third-Party Risk

Supply Chain Security: When Your Vendors Become Your Weakest Link

The M&S and JLR breaches reveal how attackers bypass your defences by targeting suppliers. How to build a risk management programme that works.

24 March 202614 min read
Read article
Threat Intelligence

The Cyber Dimension of the US-Israel-Iran Conflict: A CISO's Guide

As conflict unfolds between the US, Israel, and Iran, cyber operations are a critical battleground. What CISOs need to know.

11 March 202610 min read
Read article
AI Security

Seven Critical Lessons for CISOs from the McKinsey Lilli Hack

When McKinsey's internal AI platform was compromised via SQL injection, it revealed new classes of vulnerabilities security programmes miss.

10 March 20268 min read
Read article
Strategy

When Does Your Business Need a CISO?

Knowing when to invest in executive security leadership is critical. Key indicators and decision frameworks for when to hire a CISO.

15 January 202612 min read
Read article
Compliance

SOC 2 vs ISO 27001: The Strategic Guide to Choosing Your Security Framework

SOC 2 and ISO 27001 serve different strategic purposes. A decision framework, implementation roadmap, and integration strategies that actually work.

10 January 202615 min read
Read article
Culture

Building a Security-First Culture: The Complete Playbook

Technology alone won't protect your business. A framework for creating a culture where security is intrinsic to how work gets done.

5 January 202618 min read
Read article

Looking for Security Insights for Your Business?

Our fractional CISOs can help you implement the strategies and frameworks discussed in our articles. Book a call to discuss your security needs.