Deep TrustGovernance Series

Governance that holds up under pressure.

175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.

DTG-DS24 · Data Security · 5 min

The Exfiltration Was Slow, Quiet, and Consistent for Eight Months

The forensic analysis determined that data had been leaving the environment since the previous March. Not in bulk transfers that would have triggered volume-based alerts.

DTG-DS21 · Data Security · 5 min

You Labeled the Data. Now What?

The data classification program is complete. Every data store has been assessed. Labels have been applied: public, internal, confidential, restricted.

DTG-DS19 · Data Security · 4 min

Building a Data Security Program That Survives Organizational Change

The data security program that was mature eighteen months ago may be significantly less capable today if the organization went through a major reorganization, acquired a…

DTG-DS18 · Data Security · 4 min

API Security Is Data Security. Most Programs Treat Them Separately

APIs are how personal data moves between systems today. The customer data that leaves the CRM for the marketing platform leaves through an API.

DTG-DS10 · Data Security · 5 min

Key Management Is Where Encryption Programs Quietly Fail

The encryption is strong. AES-256 at rest, TLS 1.3 in transit, end-to-end for sensitive communications. The cryptographic standards are current.

DTG-DS08 · Data Security · 4 min

Securing Data at the Container Level While It Flows Freely Inside

Container security is a well-developed discipline. Images are scanned for vulnerabilities. Runtime behavior is monitored. Network policies restrict container-to-container…

DTG-DS06 · Data Security · 5 min

The Developer Who Copied Production Data into a Test Environment

The developer needed realistic data to reproduce a bug that only appeared with production-scale record volumes and production-specific data patterns.

DTG-DS02 · Data Security · 4 min

The Backup That Couldn't Be Restored When It Actually Mattered

The backup job had been completing successfully for two years. The monitoring dashboard showed green every morning. The storage utilization reports confirmed that backup…

DTG-CB19 · Cross-Border Data · 4 min

The API Call That Crossed a Border and Triggered an Obligation Nobody Anticipated

The integration was straightforward: the new analytics vendor's API received event data from the organization's mobile application. The API call was a standard HTTP reque…

DTG-CB17 · Cross-Border Data · 4 min

US State Privacy Laws Are Converging on Principles and Diverging on Everything Else

Twenty states have enacted comprehensive consumer privacy laws. More are in progress. The laws share a common conceptual architecture: consumer rights, controller and pro…

DTG-CB14 · Cross-Border Data · 4 min

Incident Response Across Jurisdictions: Different Clocks, Different Regulators, Same Breach

The breach affected customer data across fourteen countries. The incident response team started the 72-hour GDPR notification clock from the moment awareness was establis…

DTG-CB12 · Cross-Border Data · 4 min

Data Sovereignty Is a Boardroom Issue That Gets Delegated to Legal and Forgotten

Data sovereignty is the principle that data is subject to the laws and governance of the jurisdiction in which it is located. For organizations operating globally, data s…

DTG-CB11 · Cross-Border Data · 4 min

Government Access Requests Across Jurisdictions: What Your Privacy Policy Doesn't Say

Privacy policies describe how the organization handles personal data. They describe the purposes of processing, the legal bases, the rights individuals can exercise, and…

DTG-CB08 · Cross-Border Data · 4 min

The Schrems II Implications That Your Legal Team and Engineering Team Still Haven't Resolved

Schrems II was decided in July 2020. Standard contractual clauses were updated in June 2021. Transfer impact assessments were introduced as a requirement for demonstratin…

DTG-CB04 · Cross-Border Data · 4 min

Data Localization at Enterprise Scale Is an Architectural Problem, Not a Legal One

Data localization requirements tell organizations where data must be stored. They are legal requirements created by legislators. The compliance response to data localizat…

DTG-CB03 · Cross-Border Data · 5 min

Where Is Your Customer Data Right Now, in Which Country, and Under Which Law?

Answer the question precisely. Not in general terms — not 'primarily in the EU' or 'stored in our cloud provider's data centers.' Name the countries.

DTG-AI34 · AI Governance · 4 min

Using AI to Govern AI: Promise, Limitation, and Practical Reality

The proposition has intuitive appeal: if AI systems are too complex and too fast-moving for human governance processes to keep pace with, use AI to govern them.

DTG-AI31 · AI Governance · 5 min

Prompt Injection Is Not a Niche Threat. It Is a Governance Gap

Prompt injection is an attack technique in which malicious instructions are embedded in content that an AI system reads and processes, causing the system to follow the ma…

DTG-AI29 · AI Governance · 5 min

AI Supply Chain Risk Is Third-Party Risk at a New Level of Complexity

Third-party risk management was built around a manageable abstraction: the vendor has access to data or systems, the vendor's security practices affect the organization's…

DTG-AI28 · AI Governance · 5 min

The Privacy Risk Nobody Modeled: What AI Inference Can Reconstruct

Privacy law is built around data. Personal data is collected, processed, stored, and shared — and each of these activities creates obligations.

DTG-AI26 · AI Governance · 4 min

When the AI Model Becomes a Regulatory Subject

The EU AI Act came into force in August 2024. Its first wave of obligations — prohibitions on unacceptable-risk AI systems — applied from February 2025.

DTG-AI23 · AI Governance · 4 min

The Vendor Said the Model Was Safe. Safe for Whom?

AI vendor safety claims are expressed as general properties: the model has been red teamed, content safety filters are applied, the model has been evaluated on standard b…

DTG-AI22 · AI Governance · 4 min

Rethinking Model Risk Management for the Generative AI Era

Model risk management was developed in financial services to govern the quantitative models used in credit scoring, trading, and risk calculation.

DTG-AI15 · AI Governance · 6 min

Agentic AI Has Arrived. Your Governance Program Has Not

AI agents are not chatbots. They are autonomous systems that plan multi-step tasks, use tools to interact with external systems, make decisions without human approval at…

Put it into practice

See your own scorecardMonitor your own attack surface the way buyers and auditors see it.Get my scorecard
View your vendors' scorecardsRatings, exposures and privacy posture for the vendors you rely on.See vendor scorecards
Publish your Trust CenterYour rating, policies and certifications in one shareable page.Preview my Trust Center