top of page
Search


The Six Questions Every Board Is Now Asking CISOs About AI
By TBDCyber | CISO & Executive Advisory Something has shifted in boardrooms over the past 18 months. It used to be that a CISO could walk into a board meeting, present a security update, field a few questions about ransomware or regulatory compliance, and walk out. The questions were predictable. The conversation was manageable. That's no longer the case. AI has upended the boardroom dynamic, not because boards have suddenly become cybersecurity experts, but because AI has be
2 days ago6 min read


Five Questions Every CISO Should Ask Before the Next AI Platform Renewal
TBDCyber | Agentic AI Security Series This is the tenth and final article in our Agentic AI Security series. Our first two articles discussed the problem framework (see The 45 Billion Identity Problem Nobody Is Talking About and The Identity Paradox: Why Agentic AI Breaks IAM by Design). Articles 3 and 4 mapped internal and external agent risk (Shadow AI Is Already Here, And Your Security Team Doesn't Know It and The Vendor in Your Environment You Didn't Hire: Third-Party Emb
Aug 239 min read


Introducing The Human Error: Why Cybersecurity Failures Are Never Just a Technology Problem
TBDCyber co-founder Graeme Payne's new book is available Every major breach of the last decade followed the same sequence. A risk was acknowledged. A control was inadequately implemented. The gap was deprioritized. An attacker found it. SolarWinds. Colonial Pipeline. MGM. The technology changes. The human and organizational conditions that turn threats into catastrophes do not. That pattern is the subject of The Human Error: Why Cybersecurity Failures Are Never Just a Technol
Aug 173 min read


Mapping the Market: What the Agentic AI Security Vendor Landscape Actually Covers (And What It Doesn't)
TBDCyber | Agentic AI Security Series This is our ninth article in our Agentic AI Security series. Our first two articles discussed the problem framework (see The 45 Billion Identity Problem Nobody Is Talking About and The Identity Paradox: Why Agentic AI Breaks IAM by Design). Articles 3 and 4 mapped internal and external agent risk (Shadow AI Is Already Here And Your Security Team Doesn't Know It and The Vendor in Your Environment You Didn't Hire: Third-Party Embedded AI Ri
Aug 1110 min read


Your Cyber Policy Probably Doesn't Cover This: The Agentic AI Insurance Gap
TBDCyber | Agentic AI Security Series This is our eighth article in our Agentic AI Security series. Our first two articles have discussed the problem framework (see The 45 Billion Identity Problem Nobody Is Talking About and The Identity Paradox: Why Agentic AI Breaks IAM by Design). Articles 3-4 mapped internal and external agent risk (Shadow AI Is Already Here, And Your Security Team Doesn't Know It and The Vendor in Your Environment You Didn't Hire: Third-Party Embedded A
Aug 119 min read


The Audit Trail That Isn't: Why Agentic AI Incidents Are Forensically Ungovernable
TBDCyber | Agentic AI Security Series This is our seventh article in our Agentic AI Security series. Our first two articles have discussed the problem framework (see The 45 Billion Identity Problem Nobody Is Talking About and The Identity Paradox: Why Agentic AI Breaks IAM by Design). Articles 3-4 mapped internal and external agent risk (Shadow AI Is Already Here, And Your Security Team Doesn't Know It and The Vendor in Your Environment You Didn't Hire: Third-Party Embedded A
Jul 309 min read


When Your Employee's AI Becomes Your Liability: The Bring Your Own Agent Problem
TBDCyber | Agentic AI Security Series This is our sixth article in our Agentic AI Security series. Our first two articles have discussed the problem framework (see The 45 Billion Identity Problem Nobody Is Talking About and The Identity Paradox: Why Agentic AI Breaks IAM by Design). Articles 3-4 mapped internal and external agent risk (Shadow AI Is Already Here, And Your Security Team Doesn't Know It and The Vendor in Your Environment You Didn't Hire: Third-Party Embedded AI
Jul 308 min read


Who Governs the Agents You Didn't Build? The Platform Vendor Conflict of Interest
TBDCyber | Agentic AI Security Series This is our fifth article in our Agentic AI Security series. Our first two articles have discussed the problem framework (see The 45 Billion Identity Problem Nobody Is Talking About and The Identity Paradox: Why Agentic AI Breaks IAM by Design). Articles 3-4 mapped internal and external agent risk (see Shadow AI Is Already Here, And Your Security Team Doesn't Know It and The Vendor in Your Environment You Didn't Hire: Third-Party Embedde
Jul 227 min read


The Vendor in Your Environment You Didn't Hire: Third-Party Embedded AI Risk
TBDCyber | Agentic AI Security Series This is the fourth article in our Agentic AI Security Series. Your vendor risk management program knows how to handle third-party software. You conduct security assessments. You review SOC 2 reports. You negotiate data processing agreements. You check for encryption, access controls, and incident notification clauses. For two decades, this model has been the foundation of enterprise third-party risk management. That model was designed for
Jul 227 min read


Shadow AI Is Already Here, And Your Security Team Doesn't Know It
TBDCyber | Agentic AI Security Series In our previous article, The Identity Paradox: Why Agentic AI Breaks IAM by Design, we discussed how agentic AI challenges the key IAM design principles for authentication, authorization, and auditing. In this article, we dive deeper into the Shadow AI challenge. When most security leaders hear "Shadow AI," they picture a developer running a personal ChatGPT subscription to write code, or a sales team pasting customer data into a consumer
Jul 147 min read


The Identity Paradox: Why Agentic AI Breaks IAM by Design
TBDCyber | Agentic AI Security Series In our previous article, The 45 Billion Identity Problem Nobody Is Talking About, we discussed how agentic AI is proliferating a new class of non-human identities that require governance. There is a tempting assumption embedded in most enterprise responses to agentic AI: that the identity governance challenge is essentially a scaling problem. More agents means more identities to manage. The solution is better tooling, more comprehensive d
Jul 146 min read


The 45 Billion Identity Problem Nobody Is Talking About
TBDCyber | Agentic AI Security Series Every CISO has a handle on their human identity estate. You know roughly how many employees, contractors, and privileged accounts you have. You have a joiner-mover-leaver process. You run access certifications. You have someone who owns IAM. Here is the number that process was not designed for: 45 billion. That is the projected volume of non-human and agentic identities by the end of 2026, according to data published by the World Economic
Jul 145 min read


How to Build a Board Cybersecurity Report That Actually Works: A Deep Dive into TRIP
In a recent post, we introduced TRIP, our framework for structuring board-level cybersecurity reporting around four components: Threats, Risks, Incidents, and Program. The core idea is that metrics alone don't tell the board what they need to know. Context does. And TRIP provides a repeatable narrative structure that gives the board context, exposure, evidence, and action in a logical sequence they can follow every quarter. This post goes deeper. If you're building or rebuild
Jul 1411 min read


The Six Questions Every Board Is Now Asking CISOs About AI
By TBDCyber | CISO & Executive Advisory Something has shifted in boardrooms over the past 18 months. It used to be that a CISO could walk into a board meeting, present a security update, field a few questions about ransomware or regulatory compliance, and walk out. The questions were predictable. The conversation was manageable. That's no longer the case. AI has upended the boardroom dynamic, not because boards have suddenly become cybersecurity experts, but because AI has be
Jul 86 min read


Cybersecurity Metrics That Actually Tell the Board Something Useful
By Bahaa Kutub, Director TBDCyber Most CISOs walk into their quarterly board presentation with a slide full of numbers. Vulnerabilities patched. Phishing simulation click-rates. Mean time to detect. Percentage of endpoints covered by EDR. The board nods. Nobody asks a follow-up question. And everyone walks away having learned nothing useful about whether the organization is secure. This isn't a board problem. It's a metrics problem, and it's one we see constantly when working
Jun 187 min read


Is Your Tabletop Exercise Actually Preparing You for a Real Incident?
Most organizations run tabletop exercises. Far fewer run effective ones. There's a significant distinction between merely ticking off the compliance box and truly testing your capability to respond effectively when issues arise. Having conducted IR exercises across various industries for years, we've observed everything from sessions that identify crucial gaps and lead to substantial change, to exercises that produce a refined after-action report that remains unaddressed. Wha
Jun 152 min read
bottom of page