If Part 8 answered the question 'what does a vCISO do?', this article answers the one that tends to follow it: 'why not just hire a proper CISO?'
If Part 8 answered the question 'what does a vCISO do?', this article answers the one that tends to follow it: 'why not just hire a proper CISO?'
At this point in the series, the governance gap should be a familiar concept. You understand why certifications are not enough, why your MSP cannot fill it, why the board needs to...
There is a specific skill at the centre of cyber governance that does not get enough attention.
Risk does not wait for an owner to be appointed before it starts accumulating. That is perhaps the most important thing to understand about the governance gap.
If your organisation has a managed security service, you are in reasonable company. The majority of UK SMEs now outsource at least some element of their security operations — and...
Cyber Essentials is genuinely useful. That needs to be said clearly, because this article is about its limits - and those limits only matter in the context of something worth...
There is a phrase that comes up in almost every conversation about cyber risk with business leaders: 'We've got that covered.'
You sit in the quarterly review. The slide deck is full of numbers. Patch rates. Vulnerability scores. Incident counts. The person presenting knows exactly what it means. You nod.