Justin Kirsch

BSA/AML compliance and Microsoft 365 configuration guide for financial institutions

12 min read

BSA/AML Compliance and Your Microsoft 365 Environment: What Financial Institutions Must Configure

In This Article Your Microsoft 365 Tenant Is a BSA Evidence Repository The Five-Year Rule: What Records BSA Actually Requires SAR Support Documentation: The Hidden Retention Obligation How Microsoft Purview Satisfies BSA Record Retention The April...

Read More
Financial services automation workflow with hidden risk indicators

15 min read

The Hidden Risks in Financial Services Automation

In This Article How Automation Expands Your Attack Surface The Agentic AI Risk Multiplier Data Breach Patterns in Financial Services AI Bias and Fair...

Read More
Microsoft 365 device code phishing attack pathway showing token replay from Railway PaaS infrastructure to a compromised financial institution tenant

26 min read

M365 Device Code Phishing: MFA Is Being Bypassed at Scale

Prefer to watch? Every security control did its job. The tokens still went to the attacker. Watch the 26-second Short, then the 10-minute walkthrough...

Read More
Kerberos RC4 to AES migration countdown showing April 14 2026 deadline with service account authentication and encryption security concept

11 min read

Kerberos RC4 to AES: The April Patch That Will Break Your Service Accounts

In This Article What CVE-2026-20833 Actually Changes The Three-Phase Timeline The 15-Minute Audit That Prevents the Outage What the Encryption Values...

Read More
Microsoft 365 Data Loss Prevention architecture for financial services showing GLBA sensitive information detection and Purview compliance monitoring for examiner readiness

14 min read

M365 DLP for Financial Services: The Configuration Guide Your Examiner Expects

In This Article Why Alert, Not Block Guardian's Two-Stack DLP Architecture The Four GLBA Sensitive Information Types The Configuration Guide Your...

Read More
Third-party AI connectors evaluated for Microsoft 365 tenant access showing Claude and ChatGPT integration governance decision framework for CISOs at financial institutions

11 min read

Should You Connect Claude or ChatGPT to Your M365 Tenant? A CISO Decision Framework

In This Article The Permission Models Are Not Equal Conditional Access Policies for Third-Party AI The 5-Question CISO Framework Data Residency and...

Read More
Microsoft Copilot prompt injection attack concept showing AI security warning with data exfiltration risk for financial institutions using M365

12 min read

Is Microsoft Copilot Safe? The Prompt Injection Risk Your Financial Institution Must Address

In This Article How Prompt Injection Works Against Copilot Why Prompt Injection Is an Industry Problem What Your Governance Team Needs to Do How...

Read More
Copilot governance dashboard showing AI usage monitoring analytics with Purview compliance metrics and security controls for financial institutions

13 min read

Copilot Governance Dashboard: How to Monitor AI Usage in Your M365 Tenant

Prefer to watch? Your examiner asks who is using Copilot and what data it has touched. Watch the 30-second version for the stakes, or the longer...

Read More
Entra ID security assessment concept showing identity management audit with seven queries and Microsoft Azure AD security posture visualization

11 min read

Entra ID Security Assessment: 7 Queries That Replace 2 Hours of PowerShell

In This Article 7 Queries That Run a Complete Entra ID Audit What to Fix First: Remediation by Priority Entra ID P1 vs P2 for Financial Institutions...

Read More
AI readiness data showing Frontier Firms outperform laggards across financial institutions

9 min read

The Data Behind AI Readiness: What Frontier Firms Know That Laggards Don't

In This Article The Frontier Gap: 88% vs. 23% The BYOAI Compliance Bomb Ticking Inside Your Network Copilot ROI Math: 223% Over Three Years The...

Read More