Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # Stratsec: Strategic Security Intelligence ## Sitemaps [XML Sitemap](https://stratsec.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Pages - [Digital Assets and Blockchain](https://stratsec.com/coverage/digital-assets-blockchain/): Security and resilience obligations attaching to digital assets, and the awkward places where distributed ledgers meet data protection law. - [Space Systems Security](https://stratsec.com/coverage/space-systems-security/): Security for space systems and, more often, for the organisations that depend on them without owning anything in orbit. Timing and positioning are the dependencies most people forget they have. - [Drone and UAS Security](https://stratsec.com/coverage/drone-uas-security/): Two problems in one domain. Securing the drones you operate, and dealing lawfully with the ones you did not invite over your site. - [Telecommunications and 5G Security](https://stratsec.com/coverage/telecoms-5g-security/): Security obligations for networks, and for the enterprises that have started operating their own. Private 5G moved this domain out of the carrier world and into manufacturing, ports, mining and hospitals. - [Cyber-Kinetic and OT Security](https://stratsec.com/coverage/cyber-kinetic-ot-security/): Where an attack produces a physical consequence. Plant, grid, pipeline, water and manufacturing, where a failure moves something, heats something, or stops something. - [AI Security](https://stratsec.com/coverage/ai-security/): Securing the models, agents and pipelines you deploy. Distinct from AI governance, which covers the paperwork proving a system is lawful. This domain covers the system being attacked or misused. - [Third-Party and Supply Chain Risk](https://stratsec.com/coverage/supply-chain-risk/): The exposure that arrives through someone else, and the obligations that make it yours anyway. This is the busiest domain we cover and the one where regulators have moved fastest. - [Data Security and Privacy](https://stratsec.com/coverage/data-security-and-privacy/): The security obligations inside privacy law, and the point where a privacy regulator starts asking a security question. This domain usually reaches the security team through the data protection office. - [Product Security](https://stratsec.com/coverage/product-security/): Obligations that attach to what you ship out of the door. If your organisation sells anything with software in it, this domain reaches your engineering roadmap, your release process and your vulnerability handling. - [Incident Reporting](https://stratsec.com/coverage/incident-reporting/): Who you have to tell, inside what window, and in what form. This is the domain where an obligation turns into a countdown, and where most organisations discover their process on the day they need it. - [Operational Resilience](https://stratsec.com/coverage/operational-resilience/): Staying able to deliver the service when something fails. This domain treats a cyber incident as one cause of disruption among several, which is why it belongs to the business as a whole. - [Stratsec Radar](https://stratsec.com/stratsec-radar/): Technology risk regulation, reviewed by hand - [AI Use and Editorial Standards](https://stratsec.com/ai-use-and-editorial-standards/): Last updated: 31 August 2026 - [Cancellation and Refunds](https://stratsec.com/cancellation-and-refunds/): Last updated: 31 August 2026 - [Coverage](https://stratsec.com/coverage/): Sixteen domains, four jurisdictions - [Cybersecurity Regulation](https://stratsec.com/coverage/cybersecurity-regulation/): The baseline obligations that decide whether your security programme is adequate in law. For most organisations in Europe this domain arrives as NIS2, through whichever national statute their member state used to implement it. - [Export Controls and Dual-Use Technology](https://stratsec.com/coverage/export-controls/): Restrictions on what technology may move, to whom, and across which border. This is the domain where a research collaboration, a code repository or a support call can become a controlled export. - [Robotics and Autonomous Systems](https://stratsec.com/coverage/robotics-autonomous-systems/): Security obligations for systems that act in the physical world. This is where a security requirement and a safety requirement have to be satisfied at the same time, by the same design. - [Quantum Security](https://stratsec.com/coverage/quantum-security/): The migration away from cryptography a quantum computer would break, and the obligations starting to attach to it. Long lead time, early supervisory interest, and a discovery problem at the front of it. - [AI Governance](https://stratsec.com/coverage/ai-governance/): The obligations that attach to building or deploying an AI system. Governance duties, documentation, transparency and classification, most of which land on legal and compliance with security holding the evidence. - [Terms of Use](https://stratsec.com/terms/): Last updated: 31 August 2026 - [Contact](https://stratsec.com/contact/): Who to write to - [Advisory Board](https://stratsec.com/advisory-board/): The review layer - [Roundtables](https://stratsec.com/roundtables/): Half a day, by invitation - [The Stratsec Circle](https://stratsec.com/circle/): By nomination or invitation - [About](https://stratsec.com/about/): Why Stratsec exists - [Front Page](https://stratsec.com/): New technologies bring new obligations, and a great deal of noise. Stratsec tells you which is which. We are former CISOs, former security practice leaders and practitioners. We track what changes in technology risk regulation, say what it means for your programme, and hand you the board language, supplier questions and governance guidance to act on it. - [Privacy Policy](https://stratsec.com/privacy/): Last updated: 31 August 2026 - [Emerging Threat Monitor](https://stratsec.com/emerging-threat-monitor/): The Stratsec Emerging Threat Monitor is a regular intelligence briefing covering emerging technology developments that create security and risk implications most organisations aren't yet aware of — or are aware of but can't separate the signal from the hype.