Services About Insights Schedule Consultation

Latest perspectives

Deep dives on the topics that keep operators and investors up at night.

CIRCIA’s Final Rule Is Due This Fall: The 72-Hour Breach Clock Mid-Market Fintechs Aren’t Ready For

CIRCIA’s final rule lands soon: 72 hours to report an incident, 24 for ransom payments, 316,244 entities in scope. What fintech and SaaS teams must do now.

The Texas AG’s AI Complaint Portal Is Live: What TRAIGA Enforcement Means for Your Fintech

Texas TRAIGA’s complaint portal is live. Penalties run $10K–$200K per violation plus $2K–$40K/day. What fintech and SaaS teams must do now.

Washington's AI Warning Shot: Distillation Advisory Meets Congressional Action

NSA, CISA and the FBI flagged industrial-scale AI distillation days before Congress aligned on AI risk. What regulated companies should do this quarter — and the control set that survives both an audit and an exam.

Read more →

NYDFS Makes AI Adoption a Risk-Assessment Trigger Event

The Sept 10, 2026 industry guidance shows examiners exactly what a risk assessment must prove. What fintech and crypto firms under NYDFS should document before their next exam — especially if AI is in the stack.

Read more →

The EU AI Act Got Delayed. Post-Market Monitoring Didn't.

Articles 72 and 73 went live 2 August 2026 despite the Digital Omnibus delay. What deployers owe right now: monitoring plans, incident reporting clocks, and the evidence trail that survives an audit.

Read more →

California's AI Auditor Registry: SB 813 & AB 1405 Explained

The first US Independent Verification Organization regime for AI is here — designated auditors, a public registry from 2029, and covered audits for deployers. What fintech and SaaS teams operating in California should do before 2028.

Read more →

Agentic AI Governance: Closing the Trust Gap

86% of companies deploy AI agents; only 34% trust them. Five governance controls mid-market fintech and SaaS teams can adopt before an auditor or insurer asks — mapped to EU AI Act, ISO/IEC 42001 and NIST AI RMF.

Read more →

How Much Does a Fractional CISO Cost in 2026?

Published market ranges by model and company size, what drives the 5x spread, and the fractional vs full-time breakeven math — with the honesty note that every public figure is a market list-price range, not an audited survey.

Read more →

You Can't Govern AI You Haven't Found

Shadow AI is the part of your AI risk nobody budgeted for. A four-pass discovery method that finds it, and the six-week program that makes it governable before the diligence question arrives.

Read more →

CISO Priorities for FinTech, Payments & Digital Assets

Seven priorities for fintech security leaders, ordered by what breaks first when it goes wrong. Custody, PCI scope, vendor concentration, exam evidence, AI governance, fintech-specific incident response, and board reporting that earns its agenda slot.

Read more →

The Security Question That Killed a Term Sheet

A founder told me his Series B term sheet was delayed 6 weeks because of one security question. Not a breach. Not a failed audit. Just a question he couldn't answer well. Here's what it was, and how to make sure you're not the next story.

Custody questions like this one come straight from our digital asset cybersecurity practice.

Read more →

Why Your SOC 2 Auditor Might Be the Wrong One

Most crypto companies fail SOC 2 on key management and access control — not because they're sloppy, but because the auditor doesn't understand digital assets. Here's how to evaluate whether your auditor understands your business model before you waste $30K.

The audit is one slice of the program — our fractional CISO for fintech services cover the rest.

Read more →

The Pre-Series B Security Checklist for Crypto Companies

The 5 areas that generate the most friction in Series B security diligence. What investors actually look for, and how to pass the test before they ask.

  • Compliance & audit readiness
  • Crypto-specific security controls
  • Incident response & operational resilience
  • Third-party & supply chain risk
  • Board reporting & governance

Based on 20+ investor diligence calls and the security program that took a crypto company public via SPAC and IPO.

No spam. Unsubscribe anytime. We never share your email.

Want these delivered to your inbox?

I send one practical security briefing per month — no fluff, no product pitches, just what I'm seeing across diligences, audits, and boardrooms.

Join the List