Insights · page 2
Board-level security writing
Third-party AI risk management
12 June 2026
A practical guide to third-party AI risk: how to vet providers, what to contract for, and how to manage concentration before a regulator asks.
AI Security Guardrails for Fintech
20 April 2026
Ship production AI agents in regulated fintech: the three guardrail layers, the model-risk register, and board-ready evidence that survives audit.
DORA and the AI Rulebook for Fintech
20 April 2026
DORA, the EU AI Act, SM&CR and PCI DSS mapped into one control layer, with evidence a board and an auditor both accept.
vCISO vs Fractional CISO vs BISO
20 April 2026
How a regulated fintech buys security leadership: vCISO, fractional CISO, or BISO, with engagement models, pricing, and a board-ready ROI case.
Implementing ISO 27001 for regulated fintech
4 November 2024
An end-to-end ISO 27001:2022 implementation for fintech operators on a 26-week timeline, covering scope, controls, audit, and an operating model.
Secure CI/CD pipelines for regulated fintech
12 September 2024
Seven baseline controls that turn a fintech CI/CD pipeline from supply-chain liability into an audit-ready asset, with practical auditor-focused patterns.
Mitigating insider threats in regulated fintech
10 August 2024
Most insider-threat programmes default to surveillance. The ones that work default to design. A framework for fintech CISOs.
Cybersecurity risk frameworks for financial institutions
22 May 2024
How fintech operators reconcile NIST, ISO 27005, FAIR, and DORA's risk requirements without running four parallel programmes.
Agile risk management: integrating risk into agile boards
15 March 2024
How to weave ICT risk management into agile delivery cadence without halting the team. Practical patterns for fintech CTOs and CISOs.