Blog
Operating notes on evidence-backed cyber-risk decisions.
PE portfolio operations, AI adoption, referenced news, research papers, and the method notes that keep a loss-exposure range challengeable. Read the sources, inspect the sample decision memo, or request a platform demo.

Who Can Send as the S&P 1500? Mapping the SPF Supply Chain of 1,210 Public Companies
A passive measurement of the SPF supply chain of 1,210 S&P Composite 1500 companies: sender concentration, shared address space, dynamic delegation, permanent errors and a dangling-authorization check. Measured October 7, 2026.

Private equity cyber risk: beyond the vishing alert
Turn a vishing warning into a post-close cyber-budget decision: verify identity gaps, compare treatment costs, assign owners, and test the changes you fund.

Portfolio Review Notes: AI Governance and Board Oversight
Two August 2026 governance publications raise practical questions for PE operators: who owns AI decisions, what evidence reaches the board, and which gaps need funding?

CISA’s Gunra advisory: what a PE operator should ask
A joint CISA/FBI StopRansomware note on Gunra is a control-freshness question, not a loss number. Here is what to ask one portco this week — and what the advisory does not prove.

What a PE operator should take from NACD’s 2026 cyber-risk handbook
The fifth edition is a board-oversight document, not a scoring product. Here is how an operating partner can use its six principles at a portfolio company without pretending the handbook priced the hold period.

NIST’s AI RMF is a governance language. PE still has to price the exposure.
AI RMF 1.0 gives portfolio companies a voluntary vocabulary — Govern, Map, Measure, Manage. It does not tell an operating partner what residual loss remains if a portco agent is allowed to act.

What Open FAIR actually standardizes — and what a PE operator still decides
The Open Group’s Open FAIR Body of Knowledge is a taxonomy and an analysis process, not a loss number. Read it that way and the IC conversation gets shorter.

CMMC Phase II Timeline: What Changed in July 2026
The government suspended Phase II on July 13 and began a 60-day review. Here is what changed, what Phase I still requires, and what to watch next.

CMMC Phase II Is Suspended: Why Contractors Should Not Wait
The government paused Phase II for a 60-day review. Phase I and the underlying security duties remain, so contractors should use the pause to build evidence.

How Much Does CMMC Level 2 Certification Cost?
CMMC Level 2 has no single sticker price. Scope, remediation, assessment, and sustainment determine the budget; this guide shows what moves each one.

CUI Scoping: Drawing the Boundary That Shrinks Your CMMC Assessment
The single biggest lever on the cost and difficulty of a CMMC Level 2 assessment is not a control — it is where you draw the CUI boundary. Here are the five asset categories, the enclave strategy, and the discipline that keeps a tight scope honest.

C3PAO Assessment: What Your Evidence Package Needs
A Level 2 assessment tests 320 objectives against real artifacts. Learn what a C3PAO examines and how to build a defensible evidence package.

POA&M Under CMMC: What's Allowed and the 180-Day Clock
CMMC POA&Ms are narrow: an 88-point floor, limited eligible requirements, and a 180-day closeout clock. Here is what 32 CFR 170.21 allows.

How to Calculate and Improve Your SPRS Score
The DoD Assessment Methodology turns 110 security requirements into a single number between −203 and 110. Here is exactly how the arithmetic works, what the score does and does not prove, and the highest-leverage way to raise it without gaming it.

Cyber Insurance Renewal: Build a Reviewable Evidence File
Prepare a renewal evidence register with source, scope, freshness, exceptions and ownership. Keep modeled loss and policy review separate from acceptance or pricing.

SEC Cyber-Materiality: Why a Defensible Dollar Beats Adjectives
What Item 1C and the four-day 8-K clock actually require, why "material" is a financial total-mix question, and where a method-stamped quantification helps counsel decide.

The Board Cyber Brief: A Funding Decision with Evidence
Use a board decision brief to compare costed cyber actions, explain modeled mean and P95 loss, record assumptions and assign the next review.

CVSS Tells You Severity. It Won't Tell You What to Fix First.
Combine vulnerability severity with business evidence, action costs and a budget objective. Learn why a reduction-per-dollar ranking alone can select the wrong plan.

From a Security Finding to a Funding Decision
Connect a finding to its business loss scenario, compare affordable actions and require post-change evidence. Modeled loss is not an EBITDA adjustment.

Cybersecurity Investment Prioritization: A FAIR Worked Example
Compare cyber investments within a $100,000 budget. A reproducible FAIR-based example shows why average annual loss and P95 can favor different actions.

Public Setup Guides and Protected Workspace Documentation
Review Valty evidence sources, permission boundaries and evaluation requirements publicly. Keep credentials, customer configuration and tenant evidence access controlled.

Proof before positioning
Why cyber-risk marketing needs claim state, source coverage, confidence, and publication boundaries next to the strongest copy, and why a product that gates its own outputs should hold its marketing to the same standard.