top of page

JAMES F.
KENEFICK

JAMES' BLOG
Leadership and Technology Insights and News


The AI Security Playbook Has 20 Threats. 16 Are New.
A widely shared AI security playbook maps twenty enterprise AI threats, from prompt injection to shadow AI. Sixteen of them describe risks that simply did not exist in a pre-AI security program. Here is which threats your existing controls already cover, which ones require new governance entirely, and the four questions every board should ask before approving the next AI deployment.
5 days ago


Cybersecurity Has 12 Domains. Boards Oversee Two.
Most boards equate cybersecurity with firewalls and a compliance checklist, covering perhaps two of the twelve domains a mature program actually requires. API security, third-party risk, and disaster recovery rarely make the agenda, yet they are where the next material incident is most likely to originate. Here is the full map and the four questions every board should be asking.
Aug 5


5 Cybersecurity Frameworks Every Board Should Govern By
Corporate cybersecurity spend keeps climbing, yet the personal perimeter, home networks, personal devices, and family accounts, sits entirely outside it. This piece breaks down why the tools stop at the office door, what boards should ask about executive exposure, and how to close the gap before it becomes a personal accountability requirement.
Jul 28


Why Your SIEM Will Not Stop a BEC Attack
Business email compromise cost organizations 2.77 billion dollars in 2024 alone, and most of it never triggered a SIEM alert. This article explains why log correlation cannot see impersonation or intent, and it outlines the layered, governed program boards should require instead of relying on detection tooling alone to stop fraud.
Jul 14


Family Office Cybersecurity: What Leaders Get Wrong
Family offices carry concentrated wealth and fragmented environments across investments, households, and advisors, yet many equate discretion with defense. This article breaks down the five blind spots behind family office cybersecurity failures, from under protected identities to ungoverned trusted relationships, and outlines the governance model leadership needs to close the gap before it becomes a crisis.
Jul 9


Retail Under Siege, Protecting Customer Data Starts in the Boardroom
Retail boards must own cybersecurity strategy to protect customer data, prevent brand damage, and ensure compliance with evolving regulations.
Jul 22, 2025


Energy and Infrastructure Boards, Cybersecurity Is Now Critical Infrastructure
Cybersecurity is no longer optional for energy and infrastructure boards. With nation-state threats and regulatory scrutiny rising, digital resilience is now core to fiduciary duty, operational safety, and national stability.
Jul 1, 2025


What Every Board Should Prioritize, Cybersecurity as Risk Management in Global Finance
Cybersecurity is no longer a technical function hidden within the IT department—it is a core element of financial risk management. For...
Jun 25, 2025


Cybersecurity for Small Businesses, Why Size Doesn’t Matter to Hackers?
In today's interconnected digital economy, the concept of cybersecurity often evokes images of large corporations battling sophisticated...
Sep 5, 2024
bottom of page