CST-360: Protecting what matters

What we are thinking about

Notes on cyber and AI risk, written for the person who has to make the decision, not for the vendor selling into it.

BI ≠ AI: When Data Governance Is Built for Reports, Not Agents

A data organisation can spend years getting business intelligence right: a clean warehouse, sensible reporting, permissions that make sense for the analysts reading…

Use caseAI governanceData management
Read article →

Cloud-Native Is Not the Same as Cloud-Secure

Moving core infrastructure to the cloud is often treated as a security upgrade in itself. It is not. It moves the trust boundary; it does not remove the need to prov…

Use caseCloud securityCompliance
Read article →

Modernising Security Oversight of Legacy Systems in a Shipping Environment

A national shipping and logistics operator runs a mix of decades-old operational systems alongside modern IT, the kind of estate where the two have never been asses…

Use caseResilienceRisk
Read article →

AI Agents: New Opportunity or New Risk?

The shift has begun. Over the past year, a profound transformation has taken place in enterprise technology. We’re moving from AI tools to AI agents.…

AI agentsAI governanceRisk
Read article →

Why Organizations Needs Strong AI Governance

Every aspect of our lives is being influenced by artificial intelligence systems.…

AI governanceNIST AI RMFAccountability
Read article →

The world is changing

With the rise of agent-based artificial intelligence, executive roles are being reshaped like never before. The skills, responsibilities, and challenges are complete…

Business riskStrategy
Read article →

Is your AI environment trustworthy?

The Vercel incident was very simple. An employee connected an external AI tool to the company's Google Workspace through OAuth, and an attacker took over the account…

AI governanceTrustAssurance
Read article →

Organizational Capability Vs Execution?

Today, many organizations invest in their cloud infrastructure projects, standards and regulatory compliance projects, and of course, there are dozens if not hundred…

ResilienceStrategy
Read article →

Governance Against Malware

In the past two weeks, all we hear are #WannaCry, #WannaCrypt, and the world’s biggest cyberattack.…

MalwareGovernanceControls
Read article →

Cyber Hygiene Basics

Can you see the connection between personal body cleanse and computer network weaknesses?…

Cyber hygieneControls
Read article →

Cyber Hygiene Actions

On this post I will tell you how simple hygiene actions (with no additional tools required) can be implemented within your network, preventing digital illness and un…

Cyber hygieneOperations
Read article →

Cyber Hygiene - Cloud

Do teeth brushing and cloud security correlate? Can teeth brushing save us money?…

Cyber hygieneCloud securityIdentity
Read article →

CST-360 Protecting What Matters

We base our consultancy on vast experience in implementing various IT and Security practices, standards and frameworks. Mainly (but not subject to), the NIST (Nation…

PrioritisationStrategy
Read article →

Security Software as a Service

In the just ended decade cyberspace has change the way we live and operate.…

SaaSCloud securityThird-party risk
Read article →

Is office space part of your strategy?

Could it be that organizations do not need office space anymore?…

Physical securityStrategy
Read article →

2019 - New Year Predictions

Humbly and with respect, I admit that 2018 was very good for us @ CST-360. We had some new fascinating engagements that started and will continue into the new year w…

PredictionsStrategy
Read article →