Insights

Research, analysis,
and practitioner notes.

Foundational research papers, regulatory analysis, and practical guides. Primary-source anchored. All free to read and download. No email required to access anything.

Foundational Research — May 2026

Three papers. Primary sources. Built for practitioners.

Each paper establishes the analytical and governance framework for its pillar. Subsequent implementation guides and assessments reference these documents.

ARI-2026-001
Emerging Technology Governance

Post-Quantum Cryptography and the Governance Imperative

NIST published FIPS 203, 204, and 205 in August 2024. The governance gap — no CBOM inventory, no owner, no vendor mandate, no board briefing — is what prevents migration. This paper establishes why PQC migration fails at the governance layer and builds the framework for mid-market organizations. Includes sector-specific analysis for healthcare, defense, and financial services. Updated with ASD LATICE framework and CBOM (ECMA-424) coverage.

PQCNIST IR 8547CBOM CNSA 2.0LATICEHIPAA
ARI-2026-002
Privacy Governance

Privacy in the Age of Machine Learning

Privacy law was designed for human-controlled data processing. Machine learning systems don't satisfy that assumption. This paper maps the foundational tensions between GDPR, CPRA, HIPAA, and the EU AI Act against actual ML system architecture. Includes the Article 32 + HNDL argument — why Harvest Now, Decrypt Later makes quantum risk a present-tense GDPR compliance obligation for organizations holding long-lived sensitive data.

GDPR Art. 22GDPR Art. 32EU AI Act CPRAHIPAAHNDL
ARI-2026-003
Emerging Infrastructure Security

Commercial Space and the Cybersecurity Governance Deficit

Commercial space is critical infrastructure by function — GPS timing, satellite imagery, LEO communications — regardless of formal designation. Most dependent organizations have never assessed satellite operators as vendor risk. Built around the Viasat KA-SAT incident, GPS spoofing as systemic threat, and software supply chain risk as the underexamined vector. Includes a four-phase governance framework aligned to NIST IR 8401.

NIST IR 8401GPS RiskKA-SAT CMMCSPD-5
Articles & Analysis

Regulatory analysis. Practitioner guides. No fluff.

Deep-dives into specific governance questions — built for the executive who needs to act, the legal counsel who needs to advise, and the practitioner who needs to implement.

A paper raised a
specific question?

The assessments give you a scored starting point in under ten minutes. The discovery call goes deeper into what's specific to your organization.