Governance Intelligence for Security Leaders

Many major incidents share one absent governance decision.

Deciview identifies it before the next incident forces it.

Editions Published 3 SitReps
Governance Decisions 30 in GDM
Incidents Analysed 50+ confirmed
The Core Insight
"An absent governance decision is not a gap waiting to be filled. It is a risk already accepted — silently, by default, without board knowledge."

Six lenses. One absent decision.

Every confirmed incident is analysed through six structured lenses — producing one output: the formally frameable governance question that should have been put to the board before the incident occurred.

S Situation

What actually happened? Confirmed facts only. Every fact classified as Confirmed, Reported, or Claimed.

I Impact

Not the entry point — the amplifier. What governance absence determined the scale of the damage.

G Gap

Technical lapse vs decision lapse. The control may have existed. The governance decision to require it did not.

N Narrative

Does the pattern recur? Two unrelated incidents confirm a structural gap — not an isolated failure.

A Absent Decision ★

The core output. Specific. Owner-nameable. Board-ratifiable. Anchored in confirmed facts.

L Lead Decision

Three actions. Named owners. Defined timelines. What good looks like. Board minute as evidence.

30 governance decisions.
Six domains. Anchored in confirmed incidents.

Each entry in the GDM is formatted for board ratification — with a named owner, a trigger condition, and a board minute as the required evidence.

GD-01
Identity Governance

Who can do what and under what formally verified conditions. Privileged access. Blast radius. Credential lifecycle.

5 decisions
GD-02
Vendor Governance

What third parties are formally obligated to do and when. Breach notification timelines. Security equivalence.

4 decisions
GD-03
Asset Governance

The formally defined required state of every asset. Blast radius governance. Patch accountability.

4 decisions
GD-04
Data Governance

What data is permitted to exist after a confirmed breach. Post-breach review. Incident closure authority.

5 decisions
GD-05
Integration Governance

What formal approval precedes any third-party connection. OAuth scope. API access standards.

4 decisions
GD-06
Response Governance

Who has formal authority for decisions that only arise during a crisis. Ransomware policy. Regulatory notification.

4 decisions
GD-07 — Emerging
AI Model Governance

When a regulator names a specific AI model as a sector-level threat — what does the board formally decide?

4 decisions
Full GDM
30 decisions across six domains

The full Governance Decision Matrix is being published progressively as each decision is confirmed through the monthly SitRep.

Publishing progressively

To learn more about the Governance Decision Matrix or request early access — email hello@deciview.com.

Defining the governance decision.

Two foundational pieces on what a governance decision is, why it has never been precisely defined, and the framework for identifying when one was never made.

What Is a Governance Decision — And Why Does It Matter?

Governance is defined everywhere in cybersecurity — as a process. A governance decision, as a discrete output, is defined nowhere. This is an attempt to define it precisely.

Read the article →
The Governance Decision That Was Never Made

Introducing the SIGNAL Framework — a structured method for identifying the governance decision that was absent before a confirmed incident, and producing the board-ready pack to formally make it.

Publishing June 30th

One incident. One absent decision.
Every month.

Each edition applies the SIGNAL Framework to one confirmed incident — producing a three-page governance intelligence brief formatted for direct use in board risk committee packs.

Vol. 001 · March 2026
Stryker MDM Attack

One compromised administrator account. Mass device wipe. 79 countries. No malware. No exploit.

GD-03-001 Blast Radius Governance

Has the board formally defined the maximum blast radius for a single administrator account?

Vol. 002 · April 2026
Ericsson Vendor Notification

A vendor waited seven months to notify Ericsson of a breach. 15,661 individuals affected.

GD-02-001 Vendor Notification Governance

Do vendor contracts require notification within a defined number of days of a confirmed breach?

Vol. 003 · May 2026
Instructure Canvas Breach

Same attacker. Eight months later. Different entry point. Same data still there.

GD-04-001 Post-Breach Data Review

Who formally signs off the environment has changed before the incident is declared closed?

India first. Built for any organisation with an absent governance decision.

The governance decision is a universal concept — it applies to any organisation with a board or leadership team, a CISO, and a regulatory obligation. Deciview is building from India first, where DPDPA enforcement creates the most immediate urgency, with global reach from day one.

DPDPA 2023

Digital Personal Data Protection Act. Enforcement begins May 2027. Data fiduciaries require board-ratified governance evidence.

GD-04 Data Governance
SEBI CSCRF

Cyber Security and Cyber Resilience Framework. Board-level accountability for all regulated entities. AI model governance now named.

GD-07 AI Governance
RBI IT Framework

Reserve Bank of India cybersecurity framework for banks and NBFCs. Formal board oversight and cyber risk management required.

GD-06 Response Governance
CERT-In Directions

24-hour mandatory incident reporting. AI model threat advisories. Critical infrastructure governance obligations.

GD-06-002 Notification
IRDAI

Insurance Regulatory and Development Authority. Cybersecurity guidelines for all regulated insurance entities.

GD-02 Vendor Governance
"The technical response fixes the entry point. The governance decision determines what the attacker finds next time."
Girish Yellappa
Founder, Deciview · 14 years security experience

Deciview began with one observation — many major cyber incidents share a governance decision that was available to be made before the incident occurred. Regulators, courts, and boards are now asking why it was not.

After 14 years in security — watching organisations respond to incidents technically while the governance gap remained — I built the framework to name that gap precisely and produce something a CISO can actually table at a board meeting.

The SIGNAL Framework is a structured methodology. The Governance Decision Matrix is the evidence base. The monthly SitRep delivers both, every month, to the security leaders who need them.

Deciview is independent. Bootstrapped. Built on confirmed incident evidence. No vendor relationships. No editorial compromise.

Monthly Situation Report

Get the monthly SitRep.

One confirmed incident. One absent governance decision. Delivered monthly.
Email hello@deciview.com to Subscribe