Skip to content

Blog

Operating notes on evidence-backed cyber-risk decisions.

PE portfolio operations, AI adoption, referenced news, research papers, and the method notes that keep a loss-exposure range challengeable. Read the sources, inspect the sample decision memo, or request a platform demo.

Research papers 10 min read

Who Can Send as the S&P 1500? Mapping the SPF Supply Chain of 1,210 Public Companies

A passive measurement of the SPF supply chain of 1,210 S&P Composite 1500 companies: sender concentration, shared address space, dynamic delegation, permanent errors and a dangling-authorization check. Measured October 7, 2026.

PE portfolio operations 6 min read

Private equity cyber risk: beyond the vishing alert

Turn a vishing warning into a post-close cyber-budget decision: verify identity gaps, compare treatment costs, assign owners, and test the changes you fund.

PE portfolio operations 4 min read

Portfolio Review Notes: AI Governance and Board Oversight

Two August 2026 governance publications raise practical questions for PE operators: who owns AI decisions, what evidence reaches the board, and which gaps need funding?

Referenced news 7 min read

CISA’s Gunra advisory: what a PE operator should ask

A joint CISA/FBI StopRansomware note on Gunra is a control-freshness question, not a loss number. Here is what to ask one portco this week — and what the advisory does not prove.

PE portfolio operations 8 min read

What a PE operator should take from NACD’s 2026 cyber-risk handbook

The fifth edition is a board-oversight document, not a scoring product. Here is how an operating partner can use its six principles at a portfolio company without pretending the handbook priced the hold period.

PE and AI 8 min read

NIST’s AI RMF is a governance language. PE still has to price the exposure.

AI RMF 1.0 gives portfolio companies a voluntary vocabulary — Govern, Map, Measure, Manage. It does not tell an operating partner what residual loss remains if a portco agent is allowed to act.

Research papers 8 min read

What Open FAIR actually standardizes — and what a PE operator still decides

The Open Group’s Open FAIR Body of Knowledge is a taxonomy and an analysis process, not a loss number. Read it that way and the IC conversation gets shorter.

CMMC and federal 7 min read

CMMC Phase II Timeline: What Changed in July 2026

The government suspended Phase II on July 13 and began a 60-day review. Here is what changed, what Phase I still requires, and what to watch next.

CMMC and federal 8 min read

CMMC Phase II Is Suspended: Why Contractors Should Not Wait

The government paused Phase II for a 60-day review. Phase I and the underlying security duties remain, so contractors should use the pause to build evidence.

CMMC and federal 8 min read

How Much Does CMMC Level 2 Certification Cost?

CMMC Level 2 has no single sticker price. Scope, remediation, assessment, and sustainment determine the budget; this guide shows what moves each one.

CMMC and federal 8 min read

CUI Scoping: Drawing the Boundary That Shrinks Your CMMC Assessment

The single biggest lever on the cost and difficulty of a CMMC Level 2 assessment is not a control — it is where you draw the CUI boundary. Here are the five asset categories, the enclave strategy, and the discipline that keeps a tight scope honest.

CMMC and federal 8 min read

C3PAO Assessment: What Your Evidence Package Needs

A Level 2 assessment tests 320 objectives against real artifacts. Learn what a C3PAO examines and how to build a defensible evidence package.

CMMC and federal 10 min read

POA&M Under CMMC: What's Allowed and the 180-Day Clock

CMMC POA&Ms are narrow: an 88-point floor, limited eligible requirements, and a 180-day closeout clock. Here is what 32 CFR 170.21 allows.

CMMC and federal 10 min read

How to Calculate and Improve Your SPRS Score

The DoD Assessment Methodology turns 110 security requirements into a single number between −203 and 110. Here is exactly how the arithmetic works, what the score does and does not prove, and the highest-leverage way to raise it without gaming it.

Disclosure and insurance 6 min read

Cyber Insurance Renewal: Build a Reviewable Evidence File

Prepare a renewal evidence register with source, scope, freshness, exceptions and ownership. Keep modeled loss and policy review separate from acceptance or pricing.

Disclosure and insurance 9 min read

SEC Cyber-Materiality: Why a Defensible Dollar Beats Adjectives

What Item 1C and the four-day 8-K clock actually require, why "material" is a financial total-mix question, and where a method-stamped quantification helps counsel decide.

Board and IC 6 min read

The Board Cyber Brief: A Funding Decision with Evidence

Use a board decision brief to compare costed cyber actions, explain modeled mean and P95 loss, record assumptions and assign the next review.

Cyber loss exposure 5 min read

CVSS Tells You Severity. It Won't Tell You What to Fix First.

Combine vulnerability severity with business evidence, action costs and a budget objective. Learn why a reduction-per-dollar ranking alone can select the wrong plan.

Cyber loss exposure 6 min read

From a Security Finding to a Funding Decision

Connect a finding to its business loss scenario, compare affordable actions and require post-change evidence. Modeled loss is not an EBITDA adjustment.

Cyber loss exposure 8 min read

Cybersecurity Investment Prioritization: A FAIR Worked Example

Compare cyber investments within a $100,000 budget. A reproducible FAIR-based example shows why average annual loss and P95 can favor different actions.

Operating notes 4 min read

Public Setup Guides and Protected Workspace Documentation

Review Valty evidence sources, permission boundaries and evaluation requirements publicly. Keep credentials, customer configuration and tenant evidence access controlled.

Operating notes 7 min read

Proof before positioning

Why cyber-risk marketing needs claim state, source coverage, confidence, and publication boundaries next to the strongest copy, and why a product that gates its own outputs should hold its marketing to the same standard.