Intelligence

VCRI Blog

Vendor risk intelligence, regulatory analysis, and supply chain security research. Written by the VCRI team.


New · Free Guide · AI Security June 19, 2026 · 4 min read

Using AI Safely: The Settings That Matter

Nobody can track every setting in every AI tool. So here's the short list that actually protects you — across ChatGPT, Gemini, and Copilot — and a plain-language why for each. Vendor-neutral, tuned for risk-aware-but-not-paranoid individuals and small businesses.

Read → By Cairn Viktor
New · Cognitive Security August 5, 2026 · 7 min read

The Agent Ends. Its Accounts Don’t.

A UK AI Security Institute incident report shows an AI agent’s accounts, credentials and repositories outliving the agent itself, and being found and trusted by other vendors’ agents. Permanence of damage has a third location, and it sits outside the system entirely.

Read → By Cairn Viktor
New · Free Guide · AI Security June 19, 2026 · 4 min read

Questions to Ask Your IT/Security Provider About AI

Outsource your IT or security? A plain-language checklist for asking your MSP/MSSP how they use AI on your behalf — data, training, governance, access, accountability — with the green and red flags to listen for. No technical background needed.

Read → By Cairn Viktor
New · State of Supply Chain Q2 2026 May 26, 2026 · 4 min read

Two Clocks: our inaugural State of Supply Chain report is out

By the time you hear about an exploit, you're already 11 days too late. Two independent 2026 findings — Seal Security (commit→advisory) and GreyNoise (exploit-surge→advisory) — measured opposite sides of the system and got the same 11-day gap. The advisory is the lagging indicator. Our inaugural quarterly report on abandonment, compromise, and the window between them.

Read → By Cairn Viktor · links to the full report + PDF
Featured · Q2 SCSC Companion May 23, 2026 · 5 min read

Three Eras of Zero-Day Economics, and Why the Advisory Falls Further Behind

Two independent 2026 findings — Seal Security on the commit side, GreyNoise on the exploit side — converge on the same number: 11 days. AI compresses one side of that gap to hours and minutes. The other side stays slow. The defender's window of safety has structurally collapsed. Companion piece to the Q2 State of Supply Chain report, dropping Tuesday 2026-05-26.

Vendor Risk Intelligence March 3, 2026 · 8 min read

Why Vendor Risk Regulation Is Converging Globally — And Why It Had To

Independent regulatory bodies across the EU, US, and Japan have all arrived at roughly the same answer to the same question at roughly the same moment. That convergence is not coincidence. It's causation — a sequence of structural changes that matured at the same historical moment and forced the same policy response across jurisdictions simultaneously.

Read → (Draft — Joshua's review pending)
Vendor Risk Intelligence March 3, 2026 · 7 min read

The US Government Just Mandated the Data VCRI Is Built to Use

In January 2026, FedRAMP released six Requests for Comment that represent the most significant restructuring of federal cloud security authorization in the program's history. Two of them validate a thesis that VCRI has been built on from the beginning: point-in-time, self-reported vendor security data is structurally insufficient.

Read → (Draft — Joshua's review pending)
Vendor Risk Intelligence March 3, 2026 · 6 min read

The EU Just Told the World What Good Vendor Risk Looks Like. Is Anyone Listening?

On February 13, 2026, the European Commission formally adopted the EU ICT Supply Chain Security Toolbox — tied directly to Article 22 of the NIS2 Directive. The EU just described, in regulatory language, the infrastructure problem that most organizations still treat as an aspiration.

Read → (Draft — Joshua's review pending)

Stay Informed

Get VCRI Intelligence

New research, regulatory analysis, and supply chain security briefings — direct to your inbox.

Subscribe →