Publications

Selected public documents (PDF). Some are provided openly.

Papers & Briefs

  • CISO Board & C-Suite Briefings (PDF) — A practical reference on framing cybersecurity discussions at board and executive level, focusing on decisions, trade-offs, and accountability rather than tools.
  • Board-Level Security Strategy: A Practical Template (PDF) — A board-level reference document outlining how security strategy should be framed, governed, and challenged, focusing on decisions, accountability, and trade-offs rather than controls or tooling.
  • AI Governance: Minimum Viable Control Model (PDF) — A board-level reference model defining the minimum governance controls required to approve, oversee, challenge, and withdraw AI systems without relying on technical implementation detail.
  • Incident Readiness for Executives (PDF) — A board-level reference on executive decision-making before, during, and after major incidents, focusing on escalation, authority, and defensible judgement under pressure.
  • Assurance of Complex Systems (PDF) — A board-level reference on how confidence and assurance are obtained for complex, regulated, and non-fail-fast systems beyond point-in-time audits or compliance checklists.