The Devensa Blog
Practical writing on security, AI, risk, compliance, privacy, and data.

Privacy
Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability
Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.

Data Governance
Who Actually Owns the Data?
Poor data quality costs the average organization $12.9 million a year, according to Gartner. See why the owner-versus-custodian confusion is usually to blame.

Compliance
Who Owns This Requirement?
Nearly 4 in 10 organizations have lost revenue or a bid over missing compliance evidence. See why tracking a requirement isn't the same as owning it.

Risk Management
What Happens When Risk Ownership Isn't Assigned
Firms without board-level risk visibility are 20% more likely to face major risk events. See what happens when a risk register lists departments instead of names.

Cybersecurity
Security Ownership: Why “IT Handles That” Is Usually Wrong
IT and security get treated as one job. They aren't. See where that confusion actually breaks, and what the 2026 DBIR shows about the cost of unassigned risk decisions.

AI Governance
What Happens When No One Owns the AI Policy
A policy without a named owner is a document, not a control. See what shadow AI adoption looks like without real governance behind it.

Data Governance
Five Data Findings That Repeat in Every Audit
Poor data quality costs the average company $12.9M a year. See the five data findings that repeat in audit after audit and what actually fixes them.

AI Governance
Five Signs an AI Deployment Has No Governance Behind It
No model inventory, no owner when things go wrong, no real review before approval. See the five signs an AI deployment has no governance behind it.

Risk Management
Five Signs Your Risk Register Is a Filing Cabinet, Not a Tool
Firms without board-level risk visibility are 20% more likely to face major risk events. See the five signs a risk register has stopped being a tool.
