<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="https://nhimg.org/wp-sitemap.xsl" ?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"><url><loc>https://nhimg.org/glossary/evidence-provenance/</loc><lastmod>2026-06-03T16:58:22+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-should-security-teams-govern-data-access-for-ai-workloads/</loc><lastmod>2026-06-03T16:58:38+00:00</lastmod></url><url><loc>https://nhimg.org/faq/why-does-ai-make-data-classification-more-important-for-iam/</loc><lastmod>2026-06-03T16:58:50+00:00</lastmod></url><url><loc>https://nhimg.org/faq/what-breaks-when-organisations-expand-data-access-for-ai-too-quickly/</loc><lastmod>2026-06-03T16:59:05+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-do-organisations-know-whether-ai-data-governance-is-working/</loc><lastmod>2026-06-03T16:59:18+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/data-democratization/</loc><lastmod>2026-06-03T16:59:29+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/data-visibility/</loc><lastmod>2026-06-03T16:59:40+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/data-reuse-boundary/</loc><lastmod>2026-06-03T16:59:52+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-should-security-teams-govern-prompts-submitted-to-browser-based-ai-tools/</loc><lastmod>2026-06-03T17:00:08+00:00</lastmod></url><url><loc>https://nhimg.org/faq/what-do-security-teams-get-wrong-about-browser-ai-risk/</loc><lastmod>2026-06-03T17:00:22+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-do-enterprise-dlp-and-browser-ai-governance-fit-together/</loc><lastmod>2026-06-03T17:00:36+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/prompt-level-governance/</loc><lastmod>2026-06-03T17:00:48+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/identity-aware-enforcement/</loc><lastmod>2026-06-03T17:01:00+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/browser-mediated-ai-risk/</loc><lastmod>2026-06-03T17:01:12+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/inline-blocking/</loc><lastmod>2026-06-03T17:01:23+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-should-security-teams-investigate-sensitive-file-exposure-when-data-is-copie/</loc><lastmod>2026-06-03T17:01:43+00:00</lastmod></url><url><loc>https://nhimg.org/faq/why-do-ai-generated-summaries-and-derivatives-create-extra-governance-risk-for-s/</loc><lastmod>2026-06-03T17:01:57+00:00</lastmod></url><url><loc>https://nhimg.org/faq/what-do-security-teams-get-wrong-about-point-in-time-file-monitoring/</loc><lastmod>2026-06-03T17:02:11+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-can-organisations-reduce-repeat-exposure-of-the-same-sensitive-file/</loc><lastmod>2026-06-03T17:02:24+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/propagation-boundary/</loc><lastmod>2026-06-03T17:02:36+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/derivative-artefact/</loc><lastmod>2026-06-03T17:02:48+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/root-cause-containment/</loc><lastmod>2026-06-03T17:02:59+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-should-security-teams-govern-ai-prompts-that-include-sensitive-data/</loc><lastmod>2026-06-03T17:03:19+00:00</lastmod></url><url><loc>https://nhimg.org/faq/why-do-traditional-audit-trails-struggle-with-ai-generated-file-changes/</loc><lastmod>2026-06-03T17:03:35+00:00</lastmod></url><url><loc>https://nhimg.org/faq/what-do-security-teams-get-wrong-about-mcp-connected-assistants/</loc><lastmod>2026-06-03T17:03:48+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-do-organisations-decide-where-ai-data-security-controls-should-sit/</loc><lastmod>2026-06-03T17:04:02+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-should-security-teams-govern-employee-use-of-public-ai-tools-in-the-browser/</loc><lastmod>2026-06-03T17:04:16+00:00</lastmod></url><url><loc>https://nhimg.org/faq/why-do-ai-agents-create-governance-problems-that-normal-access-reviews-miss/</loc><lastmod>2026-06-03T17:04:30+00:00</lastmod></url><url><loc>https://nhimg.org/faq/what-breaks-when-security-teams-only-track-file-access-and-not-file-lineage/</loc><lastmod>2026-06-03T17:04:42+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-do-security-teams-decide-whether-to-let-ai-agents-automate-investigations/</loc><lastmod>2026-06-03T17:04:56+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/browser-level-ai-visibility/</loc><lastmod>2026-06-03T17:05:08+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/derivative-data/</loc><lastmod>2026-06-03T17:05:20+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-should-security-teams-handle-reader-role-access-in-administrative-control-pl/</loc><lastmod>2026-06-03T17:05:39+00:00</lastmod></url><url><loc>https://nhimg.org/faq/why-do-hardcoded-secret-protection-modes-create-long-term-identity-risk/</loc><lastmod>2026-06-03T17:05:53+00:00</lastmod></url><url><loc>https://nhimg.org/faq/what-breaks-when-a-control-plane-exposes-signing-keys-or-configuration-secrets/</loc><lastmod>2026-06-03T17:06:10+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-can-organisations-reduce-the-blast-radius-of-middleware-identity-flaws/</loc><lastmod>2026-06-03T17:06:24+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/token-forgery/</loc><lastmod>2026-06-03T17:06:36+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/secret-reversibility/</loc><lastmod>2026-06-03T17:06:48+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/management-plane-blast-radius/</loc><lastmod>2026-06-03T17:07:01+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-should-security-teams-govern-ai-agents-that-can-change-actions-at-runtime/</loc><lastmod>2026-06-03T17:07:19+00:00</lastmod></url><url><loc>https://nhimg.org/faq/why-do-traditional-iam-and-dlp-controls-fail-for-autonomous-ai-systems/</loc><lastmod>2026-06-03T17:07:34+00:00</lastmod></url><url><loc>https://nhimg.org/faq/what-do-security-teams-get-wrong-about-ai-driven-insider-risk/</loc><lastmod>2026-06-03T17:07:47+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-can-organisations-tell-whether-their-ai-security-model-is-actually-working/</loc><lastmod>2026-06-03T17:07:59+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/contextual-trinity/</loc><lastmod>2026-06-03T17:08:10+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/synthetic-insider/</loc><lastmod>2026-06-03T17:08:24+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/autonomous-execution-layer/</loc><lastmod>2026-06-03T17:08:37+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-should-security-teams-prioritise-restoration-after-a-ransomware-event/</loc><lastmod>2026-06-03T17:08:52+00:00</lastmod></url><url><loc>https://nhimg.org/faq/why-does-data-visibility-matter-to-iam-and-governance-teams/</loc><lastmod>2026-06-03T17:09:04+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-do-organisations-know-whether-dspm-is-actually-improving-resilience/</loc><lastmod>2026-06-03T17:09:18+00:00</lastmod></url><url><loc>https://nhimg.org/faq/what-is-the-difference-between-data-classification-and-backup-protection/</loc><lastmod>2026-06-03T17:09:31+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/cyber-resilience/</loc><lastmod>2026-06-03T17:09:42+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/data-blast-radius/</loc><lastmod>2026-06-03T17:09:54+00:00</lastmod></url><url><loc>https://nhimg.org/faq/why-do-service-accounts-and-automation-create-hidden-data-access-risk/</loc><lastmod>2026-06-03T17:10:17+00:00</lastmod></url><url><loc>https://nhimg.org/faq/what-breaks-when-identity-governance-is-separated-from-data-security/</loc><lastmod>2026-06-03T17:10:31+00:00</lastmod></url><url><loc>https://nhimg.org/faq/who-is-accountable-when-an-ai-agent-accesses-regulated-data-improperly/</loc><lastmod>2026-06-03T17:10:45+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/data-aware-least-privilege/</loc><lastmod>2026-06-03T17:10:57+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/identity-data-convergence/</loc><lastmod>2026-06-03T17:11:09+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-should-security-teams-implement-fine-grained-api-authorization-across-servic/</loc><lastmod>2026-06-03T17:11:26+00:00</lastmod></url><url><loc>https://nhimg.org/faq/why-do-bearer-tokens-create-replay-risk-in-distributed-systems/</loc><lastmod>2026-06-03T17:11:40+00:00</lastmod></url><url><loc>https://nhimg.org/faq/what-breaks-when-apis-skip-consistent-audience-and-issuer-validation/</loc><lastmod>2026-06-03T17:11:53+00:00</lastmod></url><url><loc>https://nhimg.org/faq/how-do-organisations-know-whether-their-authorization-model-is-actually-working/</loc><lastmod>2026-06-03T17:12:05+00:00</lastmod></url><url><loc>https://nhimg.org/glossary/policy-decision-point/</loc><lastmod>2026-06-03T17:12:17+00:00</lastmod></url></urlset>
