Author: Souma Sadhu

HomeArchives

SOC 2 report cannot replace PCI DSS compliance

As cybersecurity and compliance budgets come under increasing scrutiny, many SaaS companies believe that obtaining a SOC 2 report proves they are effectively compliant with PCI DSS as well. This belief often arises when a SaaS application accepts online payments,...

Continue Reading  

Governing Autonomous AI Agents: Closing the Executive Identity Risk Gap

Autonomous AI agents are moving beyond content generation into operational decision-making. They query customer databases, update records, interact with cloud infrastructure, call business APIs, and communicate with employees or third parties. This changes the enterprise risk model. Cyber risk is...

Continue Reading  

The Hidden Attack Surface: Governing Legacy Client Data in Insurance Brokerages

Insurance brokerages retain sensitive information such as policy schedules, claims histories, identity records, financial disclosures and correspondence. When historical data sits in forgotten servers, backup platforms, inherited systems or former branch environments, it creates a hidden attack surface. The key...

Continue Reading  

Why Network Infrastructure Requires Continuous Technical Validation

Risk committees often assume routers and firewalls are secure once deployed, patched, and logged in the risk register. But network devices are control points, not static assets, they drift from approved baselines through firmware age, legacy services, exposed management interfaces,...

Continue Reading  

Third-Party Access in Aviation: Who Owns the Risk?

Temporary vendor access becomes a governance risk when no one remains accountable for its continued use. Aviation organisations depend on maintenance providers, ground-handling companies, software suppliers and specialist engineers to support complex operational environments. These relationships require external access to...

Continue Reading  

The Price of Assumption: Why Testing Cyber Controls Costs Less Than a Lockout

Treating corporate defence as a discretionary cyber security expense rather than a core operational baseline creates an unacceptable structural liability for industrial supply chains. When corporate boards rely on unverified assumptions regarding their defensive capabilities, they expose their entire production...

Continue Reading  

The Rise of AI-Powered Cyberattacks: What You Need to Know

Artificial intelligence is changing cybersecurity on both sides of the battlefield. While organisations use AI to improve detection and efficiency, threat actors are using the same technologies to automate reconnaissance, scale social engineering, and increase the speed of attack execution....

Continue Reading  

Synthetic Borrowers Are Breaking Traditional Identity Verification

Financial institutions have long relied on a simple assumption: the more identity data collected, the greater the confidence in a customer’s authenticity. That assumption is becoming increasingly unreliable. Digital lending platforms, banks, credit unions, and FinTech providers now operate in...

Continue Reading  

The Mythos Effect: When Threat Detection Outpaces Executive Decision-Making

Organisations frequently confuse threat visibility with operational resilience. Equipping a security operations centre with advanced tools to identify risks faster is essentially meaningless if the executive response framework is too slow to authorise action. This operational disconnect is coming into...

Continue Reading  

Securing Your Organisation: How Cybernetic GI Helps You Comply

Cyber threats grow more complex every single day. New Zealand businesses face constant risks from global attackers. Hackers do not knock before they break in. To help businesses fight back, the National Cyber Security Centre (NCSC) released the Minimum Cyber...

Continue Reading