Deciview identifies it before the next incident forces it.
Every confirmed incident is analysed through six structured lenses — producing one output: the formally frameable governance question that should have been put to the board before the incident occurred.
What actually happened? Confirmed facts only. Every fact classified as Confirmed, Reported, or Claimed.
Not the entry point — the amplifier. What governance absence determined the scale of the damage.
Technical lapse vs decision lapse. The control may have existed. The governance decision to require it did not.
Does the pattern recur? Two unrelated incidents confirm a structural gap — not an isolated failure.
The core output. Specific. Owner-nameable. Board-ratifiable. Anchored in confirmed facts.
Three actions. Named owners. Defined timelines. What good looks like. Board minute as evidence.
Each entry in the GDM is formatted for board ratification — with a named owner, a trigger condition, and a board minute as the required evidence.
Who can do what and under what formally verified conditions. Privileged access. Blast radius. Credential lifecycle.
5 decisionsWhat third parties are formally obligated to do and when. Breach notification timelines. Security equivalence.
4 decisionsThe formally defined required state of every asset. Blast radius governance. Patch accountability.
4 decisionsWhat data is permitted to exist after a confirmed breach. Post-breach review. Incident closure authority.
5 decisionsWhat formal approval precedes any third-party connection. OAuth scope. API access standards.
4 decisionsWho has formal authority for decisions that only arise during a crisis. Ransomware policy. Regulatory notification.
4 decisionsWhen a regulator names a specific AI model as a sector-level threat — what does the board formally decide?
4 decisionsThe full Governance Decision Matrix is being published progressively as each decision is confirmed through the monthly SitRep.
Publishing progressivelyTo learn more about the Governance Decision Matrix or request early access — email hello@deciview.com.
Two foundational pieces on what a governance decision is, why it has never been precisely defined, and the framework for identifying when one was never made.
Governance is defined everywhere in cybersecurity — as a process. A governance decision, as a discrete output, is defined nowhere. This is an attempt to define it precisely.
Read the article →Introducing the SIGNAL Framework — a structured method for identifying the governance decision that was absent before a confirmed incident, and producing the board-ready pack to formally make it.
Publishing June 30thEach edition applies the SIGNAL Framework to one confirmed incident — producing a three-page governance intelligence brief formatted for direct use in board risk committee packs.
One compromised administrator account. Mass device wipe. 79 countries. No malware. No exploit.
GD-03-001 Blast Radius GovernanceHas the board formally defined the maximum blast radius for a single administrator account?
A vendor waited seven months to notify Ericsson of a breach. 15,661 individuals affected.
GD-02-001 Vendor Notification GovernanceDo vendor contracts require notification within a defined number of days of a confirmed breach?
Same attacker. Eight months later. Different entry point. Same data still there.
GD-04-001 Post-Breach Data ReviewWho formally signs off the environment has changed before the incident is declared closed?
The governance decision is a universal concept — it applies to any organisation with a board or leadership team, a CISO, and a regulatory obligation. Deciview is building from India first, where DPDPA enforcement creates the most immediate urgency, with global reach from day one.
Digital Personal Data Protection Act. Enforcement begins May 2027. Data fiduciaries require board-ratified governance evidence.
GD-04 Data GovernanceCyber Security and Cyber Resilience Framework. Board-level accountability for all regulated entities. AI model governance now named.
GD-07 AI GovernanceReserve Bank of India cybersecurity framework for banks and NBFCs. Formal board oversight and cyber risk management required.
GD-06 Response Governance24-hour mandatory incident reporting. AI model threat advisories. Critical infrastructure governance obligations.
GD-06-002 NotificationInsurance Regulatory and Development Authority. Cybersecurity guidelines for all regulated insurance entities.
GD-02 Vendor GovernanceDeciview began with one observation — many major cyber incidents share a governance decision that was available to be made before the incident occurred. Regulators, courts, and boards are now asking why it was not.
After 14 years in security — watching organisations respond to incidents technically while the governance gap remained — I built the framework to name that gap precisely and produce something a CISO can actually table at a board meeting.
The SIGNAL Framework is a structured methodology. The Governance Decision Matrix is the evidence base. The monthly SitRep delivers both, every month, to the security leaders who need them.
Deciview is independent. Bootstrapped. Built on confirmed incident evidence. No vendor relationships. No editorial compromise.