Why First Nations Organizations Are Higher-Value Targets Than They Think
The comparison to a similarly-sized municipality doesn't hold. The federal funding relationship creates a risk profile that most IT conversations miss entirely.
The Five Eyes joint statement on AI and cyber risk names a real shift in the threat landscape. First Nations and SMBs have an opportunity to lead the response.
The comparison to a similarly-sized municipality doesn't hold. The federal funding relationship creates a risk profile that most IT conversations miss entirely.
Deploying an LLM or AI tool isn't just an IT decision. It's a risk decision. A practical look at the new exposure categories AI introduces and what governance controls actually matter.
Saying 'we have backups' means nothing unless you can prove you can recover. This article digs into the realities most teams miss: restores that were never tested, recovery times that ignore the math, and backups quietly crossing borders they shouldn't.
Your vulnerability scanner just flagged 437 issues. Which ones actually put your business at risk? Learn how to prioritize remediation based on real-world threat data and business impact - not just CVSS scores.
The latest Verizon DBIR shows why traditional patch management and vulnerability remediation cannot keep pace with automated exploitation. Here is what leaders need to change.
A personal reflection on reading, reckoning, and identity. When the literary foundations we lean on shift, how do we handle the complexity, look past the shelf, and find the ground beneath our feet?
Showing 6 of 16 articles
These articles are written by Dustyn Martin-Ross, a Mi'gmaq cybersecurity practitioner holding CISM, CISA, CRISC, CISSP, and PMP credentials, with more than four years of enterprise security governance experience at Deloitte. The perspective here is practitioner-first: every piece is grounded in real engagements, real frameworks, and real client challenges. You will not find recycled vendor content or theoretical frameworks detached from operational reality.
Coverage spans cybersecurity governance, risk management, compliance frameworks, and Indigenous data sovereignty, with a particular focus on regulated organizations, First Nations communities navigating federal IT security requirements, and technology decision-makers who need defensible, practical guidance. Articles are written in plain language for readers who are accountable for outcomes, not just familiar with the theory.
No new articles will be published for the time being. If an article addresses a challenge you are working through, or if there is a subject you would like covered, direct outreach is welcome at [email protected].
No new articles will be published for the time being.
New articles on cybersecurity strategy, Indigenous digital sovereignty, and governance, delivered when we publish.
Subscribe via RSS to get new articles in your feed reader.
New articles on cybersecurity strategy, Indigenous digital sovereignty, and risk management, directly from our team.
Need direct support after reading? ExploreCybersecurity & Risk Management,Governance & Compliance, orFractional CISO services.
Back to HomeContent on this page is informational and does not constitute legal, regulatory, or professional advice. Review ourLegal & Privacy page for terms, disclaimers, and privacy details.
The views shared in these articles are the author's own and do not reflect the views of any other organization or employer.