top of page
Search


The Audit Trail That Isn't: Why Agentic AI Incidents Are Forensically Ungovernable
TBDCyber | Agentic AI Security Series This is our seventh article in our Agentic AI Security series. Our first two articles have discussed the problem framework (see The 45 Billion Identity Problem Nobody Is Talking About and The Identity Paradox: Why Agentic AI Breaks IAM by Design). Articles 3-4 mapped internal and external agent risk (Shadow AI Is Already Here, And Your Security Team Doesn't Know It and The Vendor in Your Environment You Didn't Hire: Third-Party Embedded A
3 days ago9 min read


When Your Employee's AI Becomes Your Liability: The Bring Your Own Agent Problem
TBDCyber | Agentic AI Security Series This is our sixth article in our Agentic AI Security series. Our first two articles have discussed the problem framework (see The 45 Billion Identity Problem Nobody Is Talking About and The Identity Paradox: Why Agentic AI Breaks IAM by Design). Articles 3-4 mapped internal and external agent risk (Shadow AI Is Already Here, And Your Security Team Doesn't Know It and The Vendor in Your Environment You Didn't Hire: Third-Party Embedded AI
3 days ago8 min read


Who Governs the Agents You Didn't Build? The Platform Vendor Conflict of Interest
TBDCyber | Agentic AI Security Series This is our fifth article in our Agentic AI Security series. Our first two articles have discussed the problem framework (see The 45 Billion Identity Problem Nobody Is Talking About and The Identity Paradox: Why Agentic AI Breaks IAM by Design). Articles 3-4 mapped internal and external agent risk (see Shadow AI Is Already Here, And Your Security Team Doesn't Know It and The Vendor in Your Environment You Didn't Hire: Third-Party Embedde
Jul 227 min read


The Vendor in Your Environment You Didn't Hire: Third-Party Embedded AI Risk
TBDCyber | Agentic AI Security Series This is the fourth article in our Agentic AI Security Series. Your vendor risk management program knows how to handle third-party software. You conduct security assessments. You review SOC 2 reports. You negotiate data processing agreements. You check for encryption, access controls, and incident notification clauses. For two decades, this model has been the foundation of enterprise third-party risk management. That model was designed for
Jul 227 min read


Shadow AI Is Already Here, And Your Security Team Doesn't Know It
TBDCyber | Agentic AI Security Series In our previous article, The Identity Paradox: Why Agentic AI Breaks IAM by Design, we discussed how agentic AI challenges the key IAM design principles for authentication, authorization, and auditing. In this article, we dive deeper into the Shadow AI challenge. When most security leaders hear "Shadow AI," they picture a developer running a personal ChatGPT subscription to write code, or a sales team pasting customer data into a consumer
Jul 147 min read


The Identity Paradox: Why Agentic AI Breaks IAM by Design
TBDCyber | Agentic AI Security Series In our previous article, The 45 Billion Identity Problem Nobody Is Talking About, we discussed how agentic AI is proliferating a new class of non-human identities that require governance. There is a tempting assumption embedded in most enterprise responses to agentic AI: that the identity governance challenge is essentially a scaling problem. More agents means more identities to manage. The solution is better tooling, more comprehensive d
Jul 146 min read


The 45 Billion Identity Problem Nobody Is Talking About
TBDCyber | Agentic AI Security Series Every CISO has a handle on their human identity estate. You know roughly how many employees, contractors, and privileged accounts you have. You have a joiner-mover-leaver process. You run access certifications. You have someone who owns IAM. Here is the number that process was not designed for: 45 billion. That is the projected volume of non-human and agentic identities by the end of 2026, according to data published by the World Economic
Jul 145 min read


Risk Quantification in Practice
What if your risk register could answer: "What's our probable loss, and what's the cheapest way to reduce it?" In this video, TBDCyber Senior Consultant, Alexandra Reibel walks through how risk quantification works in practice, including modeling frequency and impact as ranges, running simulations, and tying results directly to budget and control decisions. No vibes. Just data.
Mar 161 min read


How TBDCyber Supports the CISO's Agenda
🚨 CISOs are facing more pressure than ever. Are we setting them up for success, or for burnout? In this short video (just under a minute!), TBDCyber Senior Partner, Graeme Payne, shares key insights into the biggest challenges CISOs are grappling with today—from evolving threats to boardroom expectations. With cybersecurity risks increasing and regulatory scrutiny tightening, CISOs need more than just technology—they need the right strategy, support, and execution to succeed
Sep 23, 20251 min read


What is cybersecurity risk management, and why does it matter?
🔐 What is cybersecurity risk management, and why does it matter? In a world where threats evolve daily, cybersecurity risk management helps organizations prioritize what really matters: protecting the systems, data, and operations that drive the business. In this quick video, TBDCyber's senior partner, Graeme Payne, breaks down what cybersecurity risk management means and how it drives security. 🎥 Tune in to hear. At TBDCyber, we help organizations build security programs t
Sep 23, 20251 min read


Is your cybersecurity program actually protecting what matters most?
Is your cybersecurity program actually protecting what matters most? In this short video, TBDCyber's Alexandra Reibel explains why a risk-focused cybersecurity program is the smartest, most effective approach for today’s threat landscape. Too many organizations fall into the trap of chasing the latest threats or checking compliance boxes — but that’s not where true resilience comes from. ⛔ A threat-focused approach keeps you in constant reaction mode. ⛔ A compliance-focused p
Jul 22, 20251 min read


How CISOs Can Navigate Digital Transformation & Cyber Risk
Graeme Payne, Co-Founder and Senior Partner at TBDCyber, shares his thoughts on how CISOs can navigate digital transformation and cyber risk in this short video.
Jul 10, 20251 min read


Unpacking the Changes from NIST CSF 1.1 to 2.0
In the ever-evolving cybersecurity landscape, organizations must stay ahead to protect their digital assets and sensitive information. The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) has been a guiding light for businesses seeking a comprehensive approach to managing and improving their cybersecurity posture. With the release of NIST CSF 2.0, organizations are presented with an updated roadmap designed to address the challenges of an in
Jan 20, 20242 min read
bottom of page