Impact
HIGH
Within the Impact facet, HIGH impact intelligence highlights articles where the expected effect level, operational exposure, or decision relevance is comparable. Readers can use the page to separate routine market updates from higher-consequence governance, infrastructure, security, and investment signals that may affect planning, procurement, policy, or customer exposure. The page connects the consequence band to public evidence, related organisations, regional context, operating dependencies, service continuity, competition, investment timing, compliance, and customer risk. It helps readers decide which developments deserve deeper monitoring, which actors are most exposed, and how a signal may affect operations or market planning.

Story
Cloud Providers as De Facto Address Registries
The cloud did not replace the regional Internet registries. It created another allocation layer below them. A hyperscale provider can decide which customer receives an external address, which account may reserve it, where it can be used, how much it costs, whether it can move…

Story
The Post-Exhaustion Generation Has Never Received an Initial Allocation
An Internet service provider founded after IPv4 exhaustion begins with a different institutional memory from a network that entered when a regional registry could satisfy an ordinary, needs-based request from a free pool. The newer operator may buy address space, lease it…

Story
RPKI Adoption as a Transfer of Institutional Risk
Route origin security has crossed an important threshold. Resource Public Key Infrastructure is no longer best understood as an optional experiment used by a narrow technical community. More address space is covered by Route Origin Authorizations, more networks validate the…

Story
AFRINIC Recovery Without Registry Portability Is Still a Bet
The election of an AFRINIC board in September 2025 was an important institutional repair. Directors could again provide governance, appoint leadership, review finances, restart community functions and guide an organisation that had operated through years of litigation and…

Story
The Next AFRINIC Election Must Publish Its Denominator
An election can produce winners and still fail to prove that the electorate was treated fairly. The missing fact is often not the numerator on the results page but the denominator underneath it: every organisation entitled to participate, every application accepted or refused…

Story
ICP-2 Revision After AFRINIC: Reform or Entrenchment?
The revision commonly called ICP-2 Version 2 is not final as of 15 July 2026. The NRO Number Council's own schedule places work on the final draft in July and August, presentations to RIR communities in September and October, and preparations for ICANN and NRO approval in…

Story
The First Permanent IGF and the Same Old Execution Gap
The Internet Governance Forum became permanent in December 2025, but permanence did not convert discussion into command. The first annual meeting under that status will take place in Nairobi from 14 to 18 December 2026, after this article's publication date. The honest question…

Story
WSIS+20 After the Applause: Which Operational Right Changed?
The twentieth-year review of the World Summit on the Information Society ended with a consensus resolution, a permanent Internet Governance Forum and a long list of commitments on access, human rights, inclusion, cooperation, financing and follow-up. Those are consequential…

Number Resource Society
A Future Registry Worth Leaving
The Number Resource Society (NRS) is a global non-profit membership and advocacy organization. It campaigns for decentralization, supports businesses and represents members that have authorized it in Regional Internet Registry governance. It is not the NRO, an RIR, IANA, a…

Number Resource Society
NRS Growth Without Mandate Laundering
The Number Resource Society (NRS) is a global non-profit membership and advocacy organization. It campaigns for decentralization, supports businesses and represents members that have authorized it in Regional Internet Registry governance. It is not the NRO, an RIR, IANA, a…

Number Resource Society
The Public Evidence Pack NRS Asks Registries to Publish
The Number Resource Society (NRS) is a global non-profit membership and advocacy organization. It campaigns for decentralization, supports businesses and represents members that have authorized it in Regional Internet Registry governance. It is not the NRO, an RIR, IANA, a…

Number Resource Society
Registry Resolution Before Insolvency: The Safeguards NRS Advocates
The Number Resource Society (NRS) is a global non-profit membership and advocacy organization. It campaigns for decentralization, supports businesses and represents members that have authorized it in Regional Internet Registry governance. It is not the NRO, an RIR, IANA, a…

Number Resource Society
The User-Controlled RPKI Model NRS Advocates
The Number Resource Society (NRS) is a global non-profit membership and advocacy organization. It campaigns for decentralization, supports businesses and represents members that have authorized it in Regional Internet Registry governance. It is not the NRO, an RIR, IANA, a…

Global Cloud Services
GitLab made backup-restore proof a developer-platform accountability test
GitLab is a risk and accountability case because the 2017 GitLab.com database incident showed how a hosted developer platform can make backup evidence, restore drills, administrator access, replica separation, and customer communication part of the product trust boundary. The…

Global Cloud Services
Codecov made Bash uploader trust a CI-secret accountability test
Codecov is a risk and accountability case because the 2021 Bash uploader compromise showed how a developer telemetry tool can become a credential collection point inside customer CI environments. The issue is not only that a script was modified. The issue is who controlled…

Global Cloud Services
CircleCI made customer secret rotation a cloud-CI accountability test
CircleCI's January 2023 security incident became a cloud-CI accountability case because the platform did not merely store build metadata. It held customer environment variables, project keys, OAuth tokens, API tokens, SSH keys, and runner secrets that could connect customer code…

Global Cloud Services
Retool made MFA support workflows a social-engineering accountability test
Retool's 2023 social-engineering incident became an enterprise automation accountability case because the failure path did not stop at one phished employee. Retool said the attacker combined SMS phishing, a voice call, a fake identity portal, a one-time code, cloud-synced…

Global Cloud Services
OneLogin made AWS key exposure an identity-provider accountability test
OneLogin is a risk and accountability case because the May 2017 AWS key incident showed how a cloud identity provider can turn one infrastructure credential exposure into a customer-wide trust-chain reset problem. The public record matters for enterprise customers, employees…

Global Institutional
British Library made ransomware recovery a cultural public-service continuity test
British Library is a risk and accountability case because the October 2023 ransomware attack showed that cultural institutions now operate critical digital public services whose continuity must be judged by access to collections, research workflows, public communication, data…

North America Institutional
City of Atlanta made SamSam recovery a municipal-service accountability test
City of Atlanta is a risk and accountability case because the March 2018 SamSam ransomware incident showed how local-government technology debt can turn into public-service delay, emergency procurement, resident burden, and taxpayer cost. The public record matters for residents…
