top of page

ARTICLES
Got questions about technology, cyber threats, or changes in compliance? We have you covered. Dissect the latest developments, guidance, and trends with our expert insights.

Search


Most AI Governance Programs Die Post-Assessment, Pre-Action
The average score in our Securance 11 Peer Benchmark was 11.8 out of 100. Five of the 11 domains came back at a flat zero across every organization assessed. Knowing that changes nothing by itself. This is the part of AI governance nobody warns you about. The assessment is the easy half. You get a number, it’s worse than you hoped, and then the work stalls — because 11 domains scored at once looks like 11 projects, and no CIO has capacity for 11 projects. The score goes into
Aug 113 min read


The Case for a Remediation Portal in Every Assessment
A remediation portal shouldn't be a premium add-on. Why structured, consultant-supported remediation belongs in every cybersecurity assessment engagement. (154 characters)
Aug 73 min read


Everyone Published a Position on AI. Almost Nobody Scored on It.
Most public sector and higher ed organizations have now published something about AI. A statement of principles. A page on the IT site. A paragraph in the strategic plan about responsible use. Almost none of them can evidence it. In our Securance 11 Peer Benchmark — eight organizations assessed against the standard — Domain 11, Ethics and External Positioning, scored 0.0 out of 9 in state and local government and 3.0 out of 9 in higher education. The higher education figure c
Jul 284 min read


HHS Just Gave You An Extra Year On The HIPAA Security Rule. Here's What To Do With It.
The HIPAA Security Rule Delay Isn’t a Pause. It’s a Head Start. The Department of Health and Human Services (HHS) just handed the healthcare industry something it rarely gets: more time. The Office of Management and Budget’s regulatory agenda now shows a final action date of July 2027 for the updated HIPAA Security Rule, a full year later than the May 2026 target HHS had originally set. For compliance teams staring down a 125-page proposed rule with mandatory encryption, mult
Jul 274 min read
.png)