The Illusion of Control: Dashboards, Metrics, and False Confidence

Walk into the boardroom of almost any modern organization and you will find dashboards.  Cybersecurity, risk, compliance, and operational dashboards have become central to executive decision-making.  They transform thousands of alerts, vulnerabilities, control assessments, audit findings, and security events into a collection of charts, scores, trend lines, and performance indicators Read more

By Eric Vanderburg, ago

The Hidden Discipline Behind Security: Why Mental Models Matter More Than Tools

Cybersecurity is routinely approached as a technology acquisition problem.  Organizations invest heavily in endpoint detection platforms, SIEMs, identity systems, firewalls, and threat intelligence feeds.  They map controls to frameworks, generate compliance reports, and track remediation metrics.  On paper, the environment appears structured and defensible.  Yet breaches continue to occur, often Read more

By Eric Vanderburg, ago

Shadow AI in Healthcare: Clinical Data Risks From Unsanctioned AI

Artificial intelligence adoption in healthcare has accelerated faster than governance maturity. Clinicians, administrators, and operational teams are increasingly integrating AI tools into daily workflows for documentation, research, triage support, and administrative automation. However, a parallel phenomenon has emerged as a material enterprise risk. This phenomenon is shadow AI.  Shadow AI Read more

By Eric Vanderburg, ago