Skip to the main content.
Watch Demo Meet With Our Team

Lucas Hathaway

Lucas Hathaway has 10+ years of experience in information security. He is the Chief Revenue Officer at Rivial Data Security. He has worked with Rivial clients for years leading the consulting team and now leads the growth team with a focus on client success ensuring that Rivial’s platform exceeds client expectations.

8 min read

Every Vendor Has an AI Feature. Here's How to Assess It

A risk leader at a large financial institution said something on a call this year that we have heard some version of at almost every institution since: "I don't think we're adequately assessing vendors who have an AI element to their offering." That...

Read More
Cybersecurity Risk Register

8 min read

How to Build a Cybersecurity Risk Register

For CISOs, IT risk leaders, compliance officers, and vCISOs, a cybersecurity risk register is the single source of truth that turns scattered...

Read More

5 min read

Quantitative vs Qualitative Cyber Risk Assessment: What Is the Difference?

Quick answer: A qualitative cyber risk assessment rates risk with labels like high, medium, and low, often on a color-coded heat map. A quantitative...

Read More

7 min read

AI Governance and AI Risk Management: A Complete Guide for 2026

Quick answer: AI governance is the set of policies, owners, and controls that decide how your organization adopts and runs AI. AI risk management is...

Read More
AI Acceptable Use Policy

6 min read

How to Build an AI Acceptable Use Policy

For CISOs, IT risk leaders, compliance teams, and privacy and audit stakeholders, an AI acceptable use policy is fast becoming the line between...

Read More
Vendor Due Diligence Checklist

8 min read

Vendor Due Diligence Checklist for Financial Institutions

For CISOs, risk leaders, compliance teams, and internal audit stakeholders at credit unions and community banks, vendor due diligence is one of the...

Read More

9 min read

NCUA Cybersecurity Exam Prep 2026: What RISOs Say Examiners Look For

Quick Answer: NCUA examiners prioritize a mature, quantitative risk assessment methodology above all else, regardless of your credit union's asset...

Read More
AI Inventory Template

6 min read

AI Inventory Template for Financial Institutions

For CISOs, risk leaders, compliance teams, and internal audit stakeholders at financial institutions, an AI inventory is quickly becoming a practical...

Read More

8 min read

The Vendor Risk Framework That Outperforms SOC 2-Only Reviews

Quick Answer: SOC 2 reports alone are insufficient for vendor risk assessment. Organizations should map vendor controls to their own security...

Read More
SOC Assessments

7 min read

Complete Guide to SOC Assessments

For CISOs and security leaders, a SOC assessment is a critical tool for evaluating vendor risk, strengthening audit readiness, and supporting...

Read More