top of page

JAMES F.
KENEFICK

JAMES' BLOG
Leadership and Technology Insights and News


The Personal Perimeter: Where Corporate Cybersecurity Stops
Corporate cybersecurity spend keeps climbing, yet the personal perimeter, home networks, personal devices, and family accounts, sits entirely outside it. This piece breaks down why the tools stop at the office door, what boards should ask about executive exposure, and how to close the gap before it becomes a personal accountability requirement.
9 hours ago


The Deepfake CEO: A Board Risk Hiding in Plain Sight
A deepfake CEO fraud incident cost one company twenty five million dollars in a single video call. This piece breaks down why convincing fakes work, what boards should ask about verification controls, and how to build a process that holds even when the face and voice on the call look completely real.
6 days ago


The AI Security Playbook Has 20 Threats. 16 Are New.
A widely shared AI security playbook maps twenty enterprise AI threats, from prompt injection to shadow AI. Sixteen of them describe risks that simply did not exist in a pre-AI security program. Here is which threats your existing controls already cover, which ones require new governance entirely, and the four questions every board should ask before approving the next AI deployment.
Aug 10


The AI Tool Settings Executives Need to Govern
A popular checklist of AI tool settings promises better results in minutes: model choice, connectors, memory, custom instructions. Most of it is harmless. One setting, granting an AI assistant OAuth access to email and files, is a governance decision that deserves far more scrutiny than a toggle switch usually gets. Here is how to tell the difference.
Aug 6


Cybersecurity Has 12 Domains. Boards Oversee Two.
Most boards equate cybersecurity with firewalls and a compliance checklist, covering perhaps two of the twelve domains a mature program actually requires. API security, third-party risk, and disaster recovery rarely make the agenda, yet they are where the next material incident is most likely to originate. Here is the full map and the four questions every board should be asking.
Aug 5


How to Explain Agentic AI to Your Board
Most executives conflate agentic AI with chatbots or automation, and the confusion shows up first in governance, not technology. Here is a four-layer model, moving from AI and ML through generative AI and simple agents to full agentic autonomy, that gives boards and leadership teams a shared, accurate vocabulary before they approve the next AI investment.
Jul 30


AI Voice Cloning: What Executives Must Govern First
Executives are quietly building AI clones of their own writing voice, uploading years of best work so Claude can draft in their tone. Done well, it scales authentic communication across emails, LinkedIn posts, and scripts. Done carelessly, it creates an accountability gap the board has not yet named. Here is the governance framework leaders need before they turn it on.
Jul 29


5 Cybersecurity Frameworks Every Board Should Govern By
Corporate cybersecurity spend keeps climbing, yet the personal perimeter, home networks, personal devices, and family accounts, sits entirely outside it. This piece breaks down why the tools stop at the office door, what boards should ask about executive exposure, and how to close the gap before it becomes a personal accountability requirement.
Jul 28


The New CIO Mandate: From Technology Steward to AI Operating Architect
The role of the CIO is rapidly evolving. As Agentic AI becomes embedded across enterprise operations, technology leaders must move beyond managing infrastructure and applications to orchestrating data, governance, security, and autonomous workflows. This article explores why the modern CIO must become an AI Operating Architect and how organizations can build the operating models needed to scale AI safely, efficiently, and strategically.
Jul 16


Why Your SIEM Will Not Stop a BEC Attack
Business email compromise cost organizations 2.77 billion dollars in 2024 alone, and most of it never triggered a SIEM alert. This article explains why log correlation cannot see impersonation or intent, and it outlines the layered, governed program boards should require instead of relying on detection tooling alone to stop fraud.
Jul 14


Family Office Cybersecurity: What Leaders Get Wrong
Family offices carry concentrated wealth and fragmented environments across investments, households, and advisors, yet many equate discretion with defense. This article breaks down the five blind spots behind family office cybersecurity failures, from under protected identities to ungoverned trusted relationships, and outlines the governance model leadership needs to close the gap before it becomes a crisis.
Jul 9


Healthcare IT Compliance Is a Program, Not a Project
Too many healthcare organizations still treat compliance like a project: finish the assessment, close the gaps, pass the review, move on. That satisfies a plan, not reality. HIPAA is not a once a year checklist; it is a daily operating posture across systems, people, and vendors. This article explains why healthcare IT compliance is a program, and how cadence, ownership, and governance keep the environment defensible as it changes.
Jul 3
bottom of page