What changed on this desk
A reference is only worth citing if you can tell when it last moved. Everything below is dated: what shipped, what was re-checked against its source, and what was wrong and had to be corrected.
One correction has been issued since launch. Each one stays on the page it affected, with the previous wording still legible.
- Corrected
Shadow AI card repointed from Verizon DBIR to BlackFog and Sapio Research
The card claimed 45% of employees use unsanctioned AI tools, citing the 2026 DBIR. That report measures frequency of AI use on corporate devices, not whether a tool was sanctioned, so the card had joined an adoption series to an approval claim no source made. It now cites a survey that asks employees the question the card was making, and the figure is 49%.
- Changed
Every benchmark card now states what kind of claim it is
Survey, forecast, regulatory date, observed telemetry, or synthesis, rendered as a label with a line on what the reader can do with it. A synthesis is somebody's assembly of other people's numbers, and the build now refuses to let a desk page cite one as evidence.
- Shipped
Board-ready sentence on every benchmark card
Each card carries a spoken-form sentence pairing the figure with its source and date, plus a field for your own comparable number. Presenting a metric without a peer comparison invites the room to supply one from memory.
- Shipped
This changelog, and dated correction notices on affected pages
A published figure is never edited silently. When one changes, the prior wording stays visible on the page with the date and the reason, and the change is listed here.
- Changed
Audience hubs became ordered reading paths
The three hubs were filtered query results, which made two of them substantially the same list under different headings. Each is now a curated sequence capped at eight pieces, with a stated reason to read each one in that position, plus its own questions and the benchmarks that apply.
- Changed
Fixed the social preview image path on this portal
Open Graph images resolved against the wrong base path, so link previews for pages under /ciso/ fell back to the site default rather than the page's own card.
- Shipped
Reciprocal links between this desk and the Guides library
Implementation-level guides now link up to the decision pieces here, and the desk links down to them, so the boundary between deciding and doing is navigable in both directions.
- Shipped
The CISO Desk opened with 19 pieces, 10 benchmark cards, and 2 tools
Three desks live at launch: Buying and Evaluation, Identity and Access Leadership, and Security Leadership in SaaS. Budget and Board and AI Governance were scoped but held back rather than shipped thin.
Common questions
- How often does this desk change?
- Benchmark cards are re-checked on a rolling schedule rather than all at once, so something on the portal is under review most weeks. Editorial pieces change when the underlying facts change, not on a content calendar. Every change of either kind appears on this page with its date.
- What happens when a published figure turns out to be wrong?
- The page carries a dated correction block showing the previous wording, the current wording, and the reason it changed. Nothing is edited silently. The correction is also listed here, so a reader can audit the whole history without knowing in advance which page was affected.
- Why publish your own errors?
- Because a reference that appears never to have made a mistake is either very young or not looking. Publishing corrections costs a little credibility once and earns more of it permanently, and it lets anyone citing this desk see whether the figure they copied has since moved.
The rules behind these changes, including what blocks a page from publishing, are on the methodology page.