CISO

Why NIS2 belongs in your AI governance and why "which plan" matters

Short answer: If your organisation falls under NIS2, every generative AI tool your employees use is part of your regulatory risk surface. The single most important thing to know is what AI is being used and on which plan — because a personal or free GenAI account handles your data very differently from a business plan, and that difference can turn everyday productivity into a compliance gap.
CISO
Governance

AI Strategy as a Portfolio of Initiatives

AI initiatives are quite often governed company-wide, but identifying different characteristics in the initiative is essential to ensure focus to right execution and get improved results.
Governance
Productivity

Want to get GenAI right? Start with how your people use it

Your colleagues are using GenAI right now—but probably not in the way your IT team intended. From data leaks to app overload, organizations are learning that enabling GenAI isn’t just about buying a license—it’s about rethinking policy, trust, and productivity. Here’s what we’ve learned.
Governance
Productivity

AI policy is done, how to go about enforcing it?

Before diving into the how of security and governance tooling, you must first understand the what of enforcement. Evaluating tools based solely on their technical features and implementation details won’t deliver meaningful results. Success in GenAI governance starts with clearly defining what needs to be enforced—only then can you determine how to do it effectively.
CISO
Governance

CISO Guide to Securing Employee Use of GenAI

Best Practices for Securing Public GenAI Apps and LLM Apps in the Enterprise
User behavior risks
Visibility