The December 2023 political agreement on the EU AI Act sets the regulatory trajectory for AI deployment across European enterprises. The compliance timeline and the implications for AI investment deserve immediate attention.
NIS2 Strategic Series (3/5): Board Liability Under Article 20 — What Senior Management Must Understand Before the Deadline
The single most strategically significant element of NIS2 is its personal accountability provisions. Management bodies must approve cybersecurity risk management measures and can be held personally liable for infringements.
Translating Cloud Security Risk Into Financial Exposure: The Executive Briefing Framework
Security risk quantification is one of the most valuable and most underused capabilities in enterprise security programmes. This is the framework that makes cloud security risk legible to CFOs and boards.
NIS2 Strategic Series (2/5): The Regulatory Landscape — How NIS2, DORA, CER, and the EU AI Act Interact
NIS2 does not exist in isolation. EMEA enterprise technology leaders must navigate an overlapping system of directives and regulations with different scopes, different enforcement mechanisms, and different relationships to each other.
Enterprise AI Strategy One Year After ChatGPT: What Has Changed and What Boards Are Still Missing
One year after ChatGPT's launch, the enterprise AI landscape has changed dramatically in some dimensions and barely at all in others. The honest assessment that boards need is not the one most technology leaders are giving them.
Shift-Left in 2023: Why the Conversation Has Moved to the Board but the Practice Hasn’t Moved to the Team
Board-level security conversations now routinely include shift-left security. The operational reality is that security practice has moved marginally left in most enterprises without the process and cultural change that genuine shift-left requires.
NIS2 Strategic Series (1/5): Why NIS2 Is Not a Compliance Exercise — It Is a Security Strategy Decision
Most enterprise NIS2 programmes are being run by legal and compliance teams, not by security and technology leaders. That framing is wrong, and it will produce compliance documentation rather than improved security posture.
End-to-End Observability for Cloud-Native Applications: The Business Case Beyond Engineering
Observability investments are typically justified on engineering grounds. The more compelling business case connects end-to-end observability to revenue, customer satisfaction, and regulatory compliance in ways that dwarf the engineering productivity benefits.
NIS2 Preparation: The 12-Month Programme European Enterprises Should Have Already Started
With the October 2024 national transposition deadline approaching, European enterprises in NIS2 scope that haven't started their compliance programmes are already behind schedule. This is the 12-month programme that addresses the real requirements.
Data Security Posture Management: The Control Nobody Had Until AI Made It Non-Negotiable
Data Security Posture Management existed as a niche security practice before AI changed the data risk landscape. AI workloads that ingest and process sensitive data at scale have made DSPM a mainstream security requirement.
