top of page
Search


Shadow AI Is Already Here, And Your Security Team Doesn't Know It
TBDCyber | Agentic AI Security Series In our previous article, The Identity Paradox: Why Agentic AI Breaks IAM by Design, we discussed how agentic AI challenges the key IAM design principles for authentication, authorization, and auditing. In this article, we dive deeper into the Shadow AI challenge. When most security leaders hear "Shadow AI," they picture a developer running a personal ChatGPT subscription to write code, or a sales team pasting customer data into a consumer
3 days ago7 min read


The Identity Paradox: Why Agentic AI Breaks IAM by Design
TBDCyber | Agentic AI Security Series In our previous article, The 45 Billion Identity Problem Nobody Is Talking About, we discussed how agentic AI is proliferating a new class of non-human identities that require governance. There is a tempting assumption embedded in most enterprise responses to agentic AI: that the identity governance challenge is essentially a scaling problem. More agents means more identities to manage. The solution is better tooling, more comprehensive d
3 days ago6 min read


The 45 Billion Identity Problem Nobody Is Talking About
TBDCyber | Agentic AI Security Series Every CISO has a handle on their human identity estate. You know roughly how many employees, contractors, and privileged accounts you have. You have a joiner-mover-leaver process. You run access certifications. You have someone who owns IAM. Here is the number that process was not designed for: 45 billion. That is the projected volume of non-human and agentic identities by the end of 2026, according to data published by the World Economic
3 days ago5 min read


How to Build a Board Cybersecurity Report That Actually Works: A Deep Dive into TRIP
In a recent post, we introduced TRIP, our framework for structuring board-level cybersecurity reporting around four components: Threats, Risks, Incidents, and Program. The core idea is that metrics alone don't tell the board what they need to know. Context does. And TRIP provides a repeatable narrative structure that gives the board context, exposure, evidence, and action in a logical sequence they can follow every quarter. This post goes deeper. If you're building or rebuild
3 days ago11 min read


The Six Questions Every Board Is Now Asking CISOs About AI
By TBDCyber | CISO & Executive Advisory Something has shifted in boardrooms over the past 18 months. It used to be that a CISO could walk into a board meeting, present a security update, field a few questions about ransomware or regulatory compliance, and walk out. The questions were predictable. The conversation was manageable. That's no longer the case. AI has upended the boardroom dynamic, not because boards have suddenly become cybersecurity experts, but because AI has be
Jul 86 min read


Cybersecurity Metrics That Actually Tell the Board Something Useful
By Bahaa Kutub, Director TBDCyber Most CISOs walk into their quarterly board presentation with a slide full of numbers. Vulnerabilities patched. Phishing simulation click-rates. Mean time to detect. Percentage of endpoints covered by EDR. The board nods. Nobody asks a follow-up question. And everyone walks away having learned nothing useful about whether the organization is secure. This isn't a board problem. It's a metrics problem, and it's one we see constantly when working
Jun 187 min read


Is Your Tabletop Exercise Actually Preparing You for a Real Incident?
Most organizations run tabletop exercises. Far fewer run effective ones. There's a significant distinction between merely ticking off the compliance box and truly testing your capability to respond effectively when issues arise. Having conducted IR exercises across various industries for years, we've observed everything from sessions that identify crucial gaps and lead to substantial change, to exercises that produce a refined after-action report that remains unaddressed. Wha
Jun 152 min read


Risk Quantification in Practice
What if your risk register could answer: "What's our probable loss, and what's the cheapest way to reduce it?" In this video, TBDCyber Senior Consultant, Alexandra Reibel walks through how risk quantification works in practice, including modeling frequency and impact as ranges, running simulations, and tying results directly to budget and control decisions. No vibes. Just data.
Mar 161 min read


Now Available: Cyber Smokehouse Podcast
We’re thrilled to provide the Cyber Smokehouse, a brand-new podcast from TBDCyber where we grill the minds, dig into the experience, and serve up the stories of leaders shaping the cybersecurity world. 🎙️ Hosted by Ernie Anderson and Graeme Payne, Cyber Smokehouse isn’t your typical cybersecurity show; it’s a place where real conversations, no-fluff insights, and the lived experience of today’s cyber leaders take center stage. Whether you’re in governance, risk, operations,
Jan 281 min read


Hardening Your Microsoft 365 Tenant: A Practical Four-Pillar Approach
Setting up a Microsoft 365 (M365) tenant is often straightforward, thanks to the quick-start wizards. While ease and convenience are great, they don't always translate into strong security. When we created TBDCyber, we set up our M365 tenant in a matter of minutes. We had immediate access to all the productivity applications we needed, from Outlook to Teams. We had all the ease and convenience we needed to start operating our business, but the next question was: Are we doing
Jan 264 min read


Cybersecurity Risk Quantification: A Logical Approach
In today’s boardrooms, cybersecurity leaders are being asked questions they were never trained to answer with confidence: How much risk are we carrying? What is the financial impact of a breach? Are we investing in the right controls? Too often, cyber risk is still communicated using subjective ratings like “high,” “medium,” or “low.” While useful at a technical level, these labels fail to support executive decision-making, budget prioritization, and risk ownership at the ent
Jan 122 min read


Outsourcing Third-Party Risk Management: Faster, Cheaper, and More Effective Vendor Risk Reduction
In today’s interconnected business environment, organizations rely on hundreds, sometimes thousands, of third parties to deliver critical services. Each of these relationships introduces potential risk: data breaches, operational disruption, regulatory violations, and reputational damage. According to SecurityScorecard’s 2025 Global Third-Party Breach Report, approximately 35% of breaches in 2024 involved a third party. Why Third-Party Risk Management Matters A well-structure
Sep 24, 20252 min read


Vulnerability Management Shouldn't Be an Afterthought
🚨 Why do most organizations only focus on Vulnerability Management after a major incident? In this short video, TBDCyber's Jeff Caranna highlights a hard truth: too often, the trigger for revamping a Vulnerability Management (VM) program is a security breach or significant incident. Post-incident reviews frequently reveal the cause—an unpatched or known vulnerability that could have been addressed earlier. At TBDCyber, we believe VM shouldn’t be an afterthought. It’s a core
Sep 23, 20251 min read


How TBDCyber Supports the CISO's Agenda
🚨 CISOs are facing more pressure than ever. Are we setting them up for success, or for burnout? In this short video (just under a minute!), TBDCyber Senior Partner, Graeme Payne, shares key insights into the biggest challenges CISOs are grappling with today—from evolving threats to boardroom expectations. With cybersecurity risks increasing and regulatory scrutiny tightening, CISOs need more than just technology—they need the right strategy, support, and execution to succeed
Sep 23, 20251 min read


What is cybersecurity risk management, and why does it matter?
🔐 What is cybersecurity risk management, and why does it matter? In a world where threats evolve daily, cybersecurity risk management helps organizations prioritize what really matters: protecting the systems, data, and operations that drive the business. In this quick video, TBDCyber's senior partner, Graeme Payne, breaks down what cybersecurity risk management means and how it drives security. 🎥 Tune in to hear. At TBDCyber, we help organizations build security programs t
Sep 23, 20251 min read


Entra ID P2 Secure Your Admin Accounts Now!
🔑 Admin Accounts Deserve Extra Protection In this short clip, TBDCyber's Microsoft trusted advisor, Chris Goosen, explains why organizations should consider enabling Entra ID P2 licensing—especially for administrator accounts. 💬 Key takeaway: Instead of always-on admin privileges, Entra ID P2 allows just-in-time access through Privileged Access Management (PAM). That means: ✔️ Admin accounts start with zero privileges by default ✔️ Elevated access is granted only when need
Sep 23, 20251 min read
bottom of page