The briefing we wanted and could not find

Stratsec was built by people who spent their careers as CISOs, as security practice leaders, and in counter-intelligence. They kept hitting the same problem. When a new obligation appeared, there was nowhere to get a straight answer about what it actually required, of whom, and by when.

Vendors called every development an emergency. The trade press amplified the most dramatic reading of it. Analyst firms published forty-page reports that arrived after the deadline they described. The CISO was left working out alone whether this one meant an emergency board briefing or a note to file.

Stratsec exists to answer that question. We read the instrument and say what it requires, of whom, and by when. We also say what is still unsettled, and hand you the board language, the supplier questions and the policy updates you need to act on it.

What we believe

01

Most new obligations need better evidence, not new tools

When a new instrument lands, the answer is usually to document and test controls you already run. Occasionally it is to build something you do not have. We tell you which one you are looking at, and why.

02

Overreacting costs more than most obligations do

Treating an exaggerated requirement as an emergency wastes budget, attention and your credibility with the board. Missing a real one creates exposure you will have to explain later. Calibration is the whole job.

03

Analysis you cannot act on is noise

We do not write to impress other analysts. We write for the person who has a risk committee on Thursday and needs to know whether this week’s development changes anything. That person also needs the board language and the supplier questions to do something about it.

Who we are

Our reviewers are former CISOs of Forbes Global 2000 companies, and former global and regional cybersecurity practice leaders from the Big Four, IBM and Accenture. They read material in the sectors they ran security for, which is why an item tells you what a requirement costs to implement and not only what the text says. They also take calls with subscribers.

Stratsec was founded by Marin Ivezic. He spent thirty years across law enforcement and counter-intelligence, held interim CISO and CTO roles at Fortune Global 500 organisations, and led cybersecurity practices at IBM, Accenture, PwC and KPMG. He coined the term cyber-kinetic security for the risk that a cyber attack produces physical consequences. He has also built emerging technology risk labs for NATO, allied defence departments and Big Four firms.

Stratsec sells one subscription and nothing else. No billable hours follow a briefing item, and no product is recommended at the end of one. That is why the answer is often cheaper than a vendor would like it to be.

How we work

We start with the instrument: a new regulation, a delegated act, a consultation that closes in six weeks, or a supervisory statement that changes what an examiner will ask you.

We work out what it actually requires, starting with who is in scope, in the words the instrument itself uses. Whether it is proposed, adopted, in force or applicable, and which of those the date refers to. Whether it applies directly or has to be transposed, because a statement about the European Union can be wrong in Germany. AI models watch the sources across four jurisdictions and write the first draft, because the composite picture is invisible to anyone following one regulator.

A person approves it, every time. A named analyst reads every item against its primary source and approves it before publication, and a former CISO reviews it in their sector. Nothing reaches a subscriber that no person has read.

We tell you what to do, and it is never “review your risk posture”. You get a specific step and the role that should own it. Often that step is to evidence something you already do. Sometimes it is to build something new. Where the answer is not yet knowable, we say what is unclear and what would settle it.

We give you the tools to act, starting with a governance briefing that maps the obligation to your risk register, your budget and your policies. Board language you can use at your next risk committee. Supplier assurance questions you can send on Monday. Team readiness checklists, tabletop scenarios, and a board slide you can drop into your deck.

The Stratsec Radar

Technology risk regulation across sixteen domains and four jurisdictions, read and approved by people who have run security programmes.

See what the Radar covers