#governance
20 stories taggedgovernance.

Four Gaps That Are Keeping AI Out of Your Security Team's Hands
Security operations centres are spending big on artificial intelligence, but most are not seeing results. Here is why the problem is not the technology.

Varonis pitches 'intent-based' guardrails for AI agents that stray off task
Agent IBAC watches what an AI agent is trying to do, not just what it is allowed to touch, and pulls the brakes when the two drift apart.

AI agents are approving transactions and nobody is watching
A new report finds most companies have handed financial controls to AI systems they cannot audit, trace, or investigate in real time.

The Cheapest Way to Beat an AI Security System Is to Read Its Rulebook
Confidence in autonomous hacking tools has collapsed. A researcher says the real problem runs deeper: the governance rules we write to keep AI security systems safe can become a weapon in an attacker's hands.

Your ransomware playbook is probably putting the wrong person in charge at 4 a.m.
A growing body of evidence shows that the real damage in ransomware incidents often comes not from the attack itself, but from who gets to decide whether to pull the plug on a business-critical system.

Boards Do Care About Cybersecurity. They Just Don't Understand It.
Security chiefs and company directors want the same thing. A language gap between them is leaving organisations dangerously exposed.

Your AI Is Moving Faster Than Your Security Team Can Follow
Boards want CISOs to greenlight AI projects at speed. The problem is that the tools to track what those AI systems actually touch, and whether they are behaving safely, have not kept up.

The Two-Speed SOC: Why Autonomous AI and Analyst Copilots Need Different Guardrails
A design question inside a Fortune 50 security team points to a bigger governance gap for AI in the security operations centre.

Your AI Coding Bots Are Running Unsupervised and Nobody Knows What They Did Last Night
AI agents inside software development teams can write, test, and deploy code on their own, often with no human checking what they did. Most companies have no way to answer a simple question: who authorised that change?

AI Is Making Decisions at Work. Most Companies Have No Rules for That.
Security expert Stephen Wilson says businesses are handing AI tools more and more independence, but treating them with the same loose oversight they used when AI just answered questions.

The Cybersecurity Skills Gap Is Real. But We're Measuring the Wrong Thing.
Companies keep buying courses and certifications. Breaches keep happening anyway. The problem is not a shortage of trained people. It is a shortage of people who have actually practised under fire.

RSnake's Case for a CISO Code of Ethics
Robert Hansen argues that kickbacks, no-show jobs, and shelfware deals aren't just embarrassing — they're a national security problem.

When Legacy Infrastructure Becomes the Soft Underbelly of Your AI Agent Stack
Governance frameworks like NIST AI RMF and the EU AI Act assume the pipes under the model are secure. They often aren't.

CISOs Are Being Handed the Business Risk Portfolio. Most Aren't Ready.
Security chiefs at Appfire, JumpCloud, and BECU describe how they're learning to own risks that finance and operations used to call their own.

Old Risk Frameworks Can't Handle AI. Here Are the New Ones That Try.
From ISO 42001 to NIST's AI RMF and ENISA's layered playbook, a clutch of frameworks is competing to define how organizations govern AI risk — each targeting a different gap.