Resources
Notes on the ICT estate.
How vendors, systems, agents, and data flows actually get governed. Written for security, legal, and GRC: one audience, one picture.
Registers go stale
DORA Registers of Information fail when they are homework. A living graph makes reporting day an export.
ReadThe vendor is the agent
Third parties now act through agents. TPRM that stops at the vendor row misses the new entity.
ReadOWASP's Agentic AI Report Shows Governance Needs Instrumentation
OWASP's State of Agentic AI Security and Governance shows that agent failures are now production incidents, not hypotheticals. The operational answer starts with inventory, observability, unified telemetry, and defensible reporting.
Read2nd Party Risk: Same Fundamentals, Shifting Ground
AI-assisted development tools have created a new asset class that sits between first-party and third-party risk. The fundamentals of security still apply — discover, review, monitor, prove — but the surface they must cover has fundamentally changed.
ReadGovernance Isn’t a Dashboard. It’s Instrumentation.
Policy-first AI governance fails because you are asked to govern something you cannot see. The case for building real accountability from discovery, observability, and proof — not frameworks and dashboards.
ReadGovern MCP Tools from Slack: Request, Review, Onboard, and Offboard Without Leaving the Channel
MCP tool sprawl is the fastest-growing source of shadow AI risk in agent-first organisations. Ethira's Slack integration puts the full tool lifecycle — request, review, approve, onboard, and offboard — into the channel your team already works in, with a complete audit trail behind every decision.
ReadShadow Subcontractors: The Hidden Vendors Inside Your SaaS Tools
Every SaaS tool your employees use talks to dozens of other services you never vetted. This post explains why those hidden fourth-party vendors are a compliance liability under GDPR and DORA, and how the Ethira browser extension surfaces them automatically.
ReadHow to Find Shadow AI and Shadow SaaS in Your Organisation
The average enterprise runs 261 unsanctioned applications before it knows they exist. This guide explains how SSO integration and a browser extension surface every AI and SaaS tool your workforce is using — and who owns each one.
ReadHow to Connect the Ethira MCP to Claude and Manage Your Inventory
A five-minute walkthrough for connecting your Ethira workspace to Claude.ai as a custom connector, then using Claude to keep your systems, products, datasets, and microservices inventory current — without leaving the chat.
ReadWhen a Company MCP Server Meets a Personal ChatGPT Account
MCP lets any employee connect a corporate SaaS — GitHub, Jira, Salesforce — to their personal ChatGPT account in under two minutes. This post explains why traditional security tools miss it entirely, and how the Ethira browser extension detects it through five correlated browser-level signals.
Read