by Gary Zimmerman | Jun 29, 2026 | AI, Cybersecurity, Governance
On April 17, 2026, the Federal Reserve, OCC, and FDIC issued SR 26-2 — the first rewrite of model risk management guidance since SR 11-7 in 2011. It superseded fifteen years of supervisory expectations. It clarified scope. It introduced a risk-based, proportional...
by Gary Zimmerman | Jun 22, 2026 | AI, Governance, Identity
The CISO role has always carried accountability that outpaced authority. What changed in 2026 is that the accountability became legally enforceable, personally, and the regulatory mechanisms to enforce it are no longer on the horizon. They are active. Splunk’s 2026...
by Gary Zimmerman | Jun 15, 2026 | AI, Cybersecurity, Identity
Your identity governance program almost certainly has a blind spot. It is not a configuration error or a policy gap. It is architectural. The IGA platforms most enterprises run were designed when “identity” meant a person. Joiner-mover-leaver workflows, access...
by Gary Zimmerman | Jun 8, 2026 | AI, Cybersecurity, Governance
Here is the problem with banning shadow AI: the people most likely to ignore the ban are your most senior decision-makers. According to TrustedTech’s Shadow AI in the Workplace report, published in May 2026, 65% of decision-makers use unapproved AI tools — compared...
by Gary Zimmerman | Jun 2, 2026 | AI, Cybersecurity, Identity
The question we keep getting from security architects right now is some version of the same thing: “We have a zero trust program. We have identity governance. We have PAM. Why does none of it cover our AI agents?” The honest answer is that it was never designed to....
Recent Comments