30 July 2026
The breach came through the help desk
Why peripheral platforms — the ITSM tools nobody classifies — have become the softest route to your most sensitive client data.
ThirdPartyRiskGRCCyberSecurity
Read the pieceInsights
Short, unhurried commentary on the risks that arrive quietly — written between engagements, and first published on LinkedIn.
30 July 2026
Why peripheral platforms — the ITSM tools nobody classifies — have become the softest route to your most sensitive client data.
1 July 2026
Sixty-four percent of suppliers never disclosed new AI subprocessors. The annual vendor review has quietly stopped working.
23 June 2026
Article 73 of the EU AI Act gives high-risk providers as little as two days to report a serious incident — for a failure mode no SIEM was built to see.
9 June 2026
Consolidation does not reduce risk. It moves it, concentrates it, and turns sprawl you managed into a dependency you cannot unwind.