NIST CSF 2.0, FAIR quantification, DORA compliance, and supply-chain cyber risk after Log4j and SolarWinds.
NIST CSF 2.0's Govern function, Zero Trust framing for the board, and control mapping that holds up in audit.
FAIR-based loss modeling that turns "high/medium/low" into numbers a CFO can plan against.
Supply-chain concentration, cloud exit strategies, and the new risk surface of AI systems.