
“Passwords must change every 90 days.”
Maybe not.
The Desk
Practical perspectives on cybersecurity, governance, risk and regulation — without the corporate noise.

Good governance isn't just compliance. It's a competitive advantage.
This week at the desk
01
Ransomware is becoming a board decision
02
Your policies may not be your biggest governance problem
03
AI is changing how credit risk is assessed
The desk's take
Sharp insights. Practical advice. No fluff.
“If your organisation cannot answer who makes the decision during a cyber incident, your plan isn't finished.
“You don't improve security by buying more tools. You improve it by making better decisions.
“Security is everyone's responsibility. Governance is leadership's responsibility.
Explore the desk
Dive into the themes that matter most.
Not everything you've been told is true.
Contrarian takes on common assumptions.

“Passwords must change every 90 days.”
Maybe not.

“Compliance means you're secure.”
It doesn't.

“The board doesn't understand cybersecurity.”
Perhaps we're explaining it badly.

“You need more security tools.”
Maybe you need better decisions.
Desk note · 2 min
Your SOC generated 14,000 alerts last month. How many resulted in an actual business decision?
Desk note · 2 min
If your risk register has more than 25 items, it's not a register. It's a dumping ground.
Desk note · 2 min
MFA rollout is not a security strategy. It's table stakes.
Desk note · 2 min
Cyber resilience is not about technology. It's about rehearsed decisions.
Join leaders who want clarity, not noise.
No spam. Unsubscribe anytime.