Practical guidance based on 20+ years in security leadership and the work of taking a crypto company public.
Deep dives on the topics that keep operators and investors up at night.
CIRCIA’s final rule lands soon: 72 hours to report an incident, 24 for ransom payments, 316,244 entities in scope. What fintech and SaaS teams must do now.
Texas TRAIGA’s complaint portal is live. Penalties run $10K–$200K per violation plus $2K–$40K/day. What fintech and SaaS teams must do now.
NSA, CISA and the FBI flagged industrial-scale AI distillation days before Congress aligned on AI risk. What regulated companies should do this quarter — and the control set that survives both an audit and an exam.
Read more →The Sept 10, 2026 industry guidance shows examiners exactly what a risk assessment must prove. What fintech and crypto firms under NYDFS should document before their next exam — especially if AI is in the stack.
Read more →Articles 72 and 73 went live 2 August 2026 despite the Digital Omnibus delay. What deployers owe right now: monitoring plans, incident reporting clocks, and the evidence trail that survives an audit.
Read more →The first US Independent Verification Organization regime for AI is here — designated auditors, a public registry from 2029, and covered audits for deployers. What fintech and SaaS teams operating in California should do before 2028.
Read more →86% of companies deploy AI agents; only 34% trust them. Five governance controls mid-market fintech and SaaS teams can adopt before an auditor or insurer asks — mapped to EU AI Act, ISO/IEC 42001 and NIST AI RMF.
Read more →Published market ranges by model and company size, what drives the 5x spread, and the fractional vs full-time breakeven math — with the honesty note that every public figure is a market list-price range, not an audited survey.
Read more →Shadow AI is the part of your AI risk nobody budgeted for. A four-pass discovery method that finds it, and the six-week program that makes it governable before the diligence question arrives.
Read more →Seven priorities for fintech security leaders, ordered by what breaks first when it goes wrong. Custody, PCI scope, vendor concentration, exam evidence, AI governance, fintech-specific incident response, and board reporting that earns its agenda slot.
Read more →A founder told me his Series B term sheet was delayed 6 weeks because of one security question. Not a breach. Not a failed audit. Just a question he couldn't answer well. Here's what it was, and how to make sure you're not the next story.
Custody questions like this one come straight from our digital asset cybersecurity practice.
Read more →Most crypto companies fail SOC 2 on key management and access control — not because they're sloppy, but because the auditor doesn't understand digital assets. Here's how to evaluate whether your auditor understands your business model before you waste $30K.
The audit is one slice of the program — our fractional CISO for fintech services cover the rest.
Read more →The 5 areas that generate the most friction in Series B security diligence. What investors actually look for, and how to pass the test before they ask.
Based on 20+ investor diligence calls and the security program that took a crypto company public via SPAC and IPO.
I send one practical security briefing per month — no fluff, no product pitches, just what I'm seeing across diligences, audits, and boardrooms.
Join the List