top of page

ARTICLES
Got questions about technology, cyber threats, or changes in compliance? We have you covered. Dissect the latest developments, guidance, and trends with our expert insights.

Search


Who Owns the Output? IP, Copyright, and AI in Government and Higher Education
Two questions follow every AI output your organization produces: who owns it, and what rights did you transfer to the vendor to create it? Most have answered neither. In our 2026 AI Governance Benchmark of five city governments and three universities, Intellectual Property (Domain 8 of the Securance 11) averaged 1.1 of a possible 9 points — and the higher education institutions in the group scored a flat zero. Composite AI governance maturity across all 11 domains averaged 11
Aug 184 min read


Most AI Governance Programs Die Post-Assessment, Pre-Action
The average score in our Securance 11 Peer Benchmark was 11.8 out of 100. Five of the 11 domains came back at a flat zero across every organization assessed. Knowing that changes nothing by itself. This is the part of AI governance nobody warns you about. The assessment is the easy half. You get a number, it’s worse than you hoped, and then the work stalls — because 11 domains scored at once looks like 11 projects, and no CIO has capacity for 11 projects. The score goes into
Aug 113 min read


The Case for a Remediation Portal in Every Assessment
A remediation portal shouldn't be a premium add-on. Why structured, consultant-supported remediation belongs in every cybersecurity assessment engagement. (154 characters)
Aug 73 min read


Everyone Published a Position on AI. Almost Nobody Scored on It.
Most public sector and higher ed organizations have now published something about AI. A statement of principles. A page on the IT site. A paragraph in the strategic plan about responsible use. Almost none of them can evidence it. In our Securance 11 Peer Benchmark — eight organizations assessed against the standard — Domain 11, Ethics and External Positioning, scored 0.0 out of 9 in state and local government and 3.0 out of 9 in higher education. The higher education figure c
Jul 284 min read


HHS Just Gave You An Extra Year On The HIPAA Security Rule. Here's What To Do With It.
The HIPAA Security Rule Delay Isn’t a Pause. It’s a Head Start. The Department of Health and Human Services (HHS) just handed the healthcare industry something it rarely gets: more time. The Office of Management and Budget’s regulatory agenda now shows a final action date of July 2027 for the updated HIPAA Security Rule, a full year later than the May 2026 target HHS had originally set. For compliance teams staring down a 125-page proposed rule with mandatory encryption, mult
Jul 274 min read


Remediation Tracking: Why Spreadsheets Aren't Enough
Every cybersecurity assessment ends the same way: a report is delivered, findings are documented, and the consulting team moves on to the next engagement. What happens next is largely up to you. For most security teams, the answer is a spreadsheet. It starts reasonably enough — a tab for each finding, columns for owner, status, target date. But within a few weeks, the limitations become clear. Evidence gets attached to emails. Status updates happen in Slack threads that no on
Jul 233 min read


How to Build a Defensible IT Risk Assessment for a County or City
If your IT risk assessment is a spreadsheet with three colors and no methodology, your audit committee already knows. Here's what "defensible" actually looks like. The IT risk assessment is the load-bearing wall of your multi-year IT audit plan. If it's weak, everything on top of it is weak. And in our experience, most local-government IT risk assessments have at least one of three problems: there's no real methodology behind the rankings, they're not current, or they're not
Jul 207 min read


CMMC Phase II Is Suspended. Your Compliance Obligations Are Not.
The Department of War just suspended CMMC Phase II certification requirements — but don't mistake a paused deadline for an eliminated obligation. NIST 800-171 and DFARS 7012 are still fully enforced. Here's what actually changed, and what contractors should do in the next 60 days.
Jul 143 min read


Build vs Buy vs Embed: The AI Decision Matrix
The AI decision you keep making without noticing Call it what it is: "AI strategy" is the phrase leaders reach for to put off a decision they're already making. It implies there's one big moment coming, some strategic juncture you'll schedule once the timing's right. There isn't. The decision that truly shapes your AI posture is smaller, quieter, and you're making it repeatedly. Usually without a framework — sometimes without noticing you've made it at all. It's this: when a
Jul 135 min read
.png)