By:
Nick Rundhaug
September 10th, 2026
Insights from a conversation with Nick Rundhaug, Managing Director and Federal Practice Leader at Schellman. See his full interview here.
By:
Joe Sigman
September 9th, 2026
AI governance has become one of the most consequential disciplines impacting enterprise-level organizations today. It determines not only whether organizations can manage AI-related risks, but whether they can build and prove the trust, accountability, and operational confidence needed to use AI effectively. Despite its importance, governance is often treated as a supporting function focused on policies, checkbox compliance procedures, and assigned responsibility.
By:
Schellman
September 3rd, 2026
Former Chase Chief Risk Officer and McKinsey and BCG senior partner brings decades of risk governance and growth-stage leadership as Schellman builds toward its next chapter.
By:
Matt Hungate
August 31st, 2026
FedRAMP's modernization effort, known as FedRAMP 20x, is continuing to advance. On August 31, 2026, the FedRAMP 20x program opened Class B and Class C as the next phase of its rollout. Under the program's official Consolidated Rules for 2026 (CR26), Class B pipeline replaces the old Low impact level for small-scale cloud services, and the Class C pipeline replaces the old Moderate impact level for common enterprise services.
By:
Nick Rundhaug
August 25th, 2026
This article was drafted based on a LinkedIn Live discussion between Schellman’s Nick Rundhaug and SecureIT's Tim Sandage and Corey Clements. View their full conversation here.
By:
Philip Holbrook
August 24th, 2026
I made it back from Las Vegas with a pile of notes, way too many stickers, three new badges around my neck, and a list of research rabbit holes long enough to keep me busy until next August. This year's floor leaned hard into AI-assisted red teaming, autonomous attack chains, and some of the most practical social engineering research I've seen at a con.
By:
Joe Sigman
August 20th, 2026
Most enterprises have a sense of who owns AI risk, yet few know what happens when that risk turns into an incident.