Insight Search Search Submit Sort by: Relevance Date Search Sort by Relevance Date Order Asc Desc Insights paper March 24, 2026 Finance to the Defense and Aerospace Industry: The Sanctions Risk Assessment Model as a Strategic Lever for Risk Management Leverage the sanctions risk assessment model to strengthen strategic risk management in the defense and aerospace industry amid evolving regulatory demands. Whitepaper March 26, 2026 Where fraud meets compliance: Building a stronger line of defense Efforts by the financial services industry to merge the management of fraud and compliance risk — particularly, but not exclusively, anti-money laundering (AML) risk — have been evolving over the last quarter century. There are examples, frequently unsuccessful, from the early 2000s of financial institutions — from traditional banks to insurance companies — that sought to integrate their fraud… Blogs July 14, 2023 Cybersecurity risk assessments vs. gap assessments: Why both matter This blog post was authored by Rob Woltering - Associate Director, Security and Privacy on the technology insights blog. As cybersecurity incidents continue to make headlines, whether involving the breach of sensitive information or the halting of an enterprise’s operations, cybersecurity risks remain top of mind for many organisations. To this end, organisations are continuously… Blogs July 14, 2023 Smart contracts part 1: What is a smart contract? In recent years, there’s been considerable talk of blockchain and its use cases in the business world. While some of these topics have specific use cases – metaverse, decentralised finance, etc – there is one topic that underpins everything in the blockchain and decentralised space: smart contracts. Smart contracts are behind-the-scenes applications that route data, track changes and settle… Blogs June 30, 2023 Metrics’ role in cyber transformation We’ve all heard the saying, “what gets measured gets done,” meaning that regular measurement and reporting helps to keep organisations focused on the information that matters. But with so many data points available to measure security, it is difficult to know where to begin. Security practitioners must constantly question what data they collect and why. Only by providing relevant measures can we… Blogs June 30, 2023 A house divided: Key differences in cybersecurity implementation for IT and OT This blog post was authored by Justin Turner - Director, Security and Privacy on the technology insights blog. Anyone who has spent a significant amount of time in any U.S. state where college football is popular, has likely seen a “house divided” bumper sticker or license plate cover, with contrasting university logos. Many of us (and our friends and families) enjoy spirited rivalries (Roll… Blogs April 4, 2023 Modernising applications: The importance of reducing technical debt Technical debt is no longer just a “technical” problem. As recent, widely publicised events have shown, it is a business problem that can have serious consequences for organisations. The government and Congress are taking notice of unfair consumer experiences, and it is crucial for businesses to address their technical debt and minimise the risk of negative press, government fines and damaged… Blogs May 5, 2023 Creating a resilient cybersecurity strategy: The governance lifecycle approach Cybersecurity governance should do more than manage cyber risk. Good cybersecurity governance creates efficiencies by clarifying the outcomes expected from its processes and establishing boundaries of responsibility among cybersecurity practitioners, frontline operational areas, senior leaders and board members. Recently, numerous crises have drawn senior leaders and board members down… Blogs April 19, 2023 Achieving Diversity’s Benefits in Cybersecurity Could any security organisation benefit from greater innovation? Or from responding more effectively to diverse internal customers? How about benefitting by retaining the talent its leaders have so carefully nurtured, by accessing more diverse capabilities, or by improving problem-solving capabilities within the team? Blogs April 6, 2023 3 Steps to Understanding IAM Challenges in Securing the DevSecOps Ecosystem DevSecOps is an organisational software engineering culture and practice that aims at unifying software development (Dev), application security (Sec), and operations (Ops). The main characteristic of DevSecOps is to monitor and apply security at all phases of the software lifecycle: Planning, development, integration, delivery, deployment and production. Looking at DevSecOps through an IT… Load More