Ben Ennis
Founder, Ennis Studio · Editor, Change Risk Intel
Independent research on IT change management, operational risk, and ITSM/GRC tooling.
Bio
Ben Ennis is a software entrepreneur and product builder based in Grand Rapids, Michigan. He spent part of his career at ServiceNow as a Partner Technology Advisor, working with implementation partners on the ITSM platform that a large share of enterprise change management actually runs on. That is the direct source of the CAB mechanics, CMDB modelling, and change-workflow detail covered on this site.
He now runs Ennis Studio, where he builds and operates SaaS products in adjacent infrastructure and security domains. CertIndex is a Certificate Transparency log API and MCP data service; GuardHound is a consumer domain security monitoring product. Both keep him working in the same territory this site covers — cloud infrastructure, API reliability, certificate and TLS plumbing, and the operational risk that surfaces when any of it changes without warning.
At Change Risk Intel, Ben writes and edits coverage of IT change management, operational risk intelligence, and ITSM/GRC tooling, with a focus on the practical mechanics that CAB leads, SREs, and risk teams use in production rather than the vendor-facing version of the same topics.
How I approach coverage
Ben's approach to coverage starts with understanding the domain deeply, citing primary sources, and staying vendor-neutral. Change Risk Intel is the editorial expression of that philosophy — applied across ITSM, GRC, and operational risk.
- Domain-deep — no thin summaries or AI-only rewrites.
- Primary-source cited — CISA, NIST, vendor status pages, SEC filings.
- Vendor-neutral — no undisclosed affiliate or sponsor influence.
- Practical — written for the CAB lead, SRE, or risk officer, not the boardroom.
Areas of expertise
- Change management and CAB operations
- Enterprise ITSM platforms, including ServiceNow
- IT service management (ITSM) and GRC tooling
- Operational and cyber risk intelligence
- SaaS architecture and compliance technology
- Certificate Transparency and TLS infrastructure
- Cloud infrastructure, CI/CD, and API reliability
Additional notes
Change Risk Intel is edited from Grand Rapids, Michigan. If you have a tip, a correction, or want to reach the desk, use the contact page.
Recent articles
- This Week in Change Risk — Week of Aug 31, 2026
AI infrastructure hit the CISA KEV catalog hard this week: LiteLLM, Kestra, and JFrog joined nine new exploited CVEs. Plus SonicWall, PaperCut, and DORA.
- Asset Inventory Reconciliation: The Quarterly Change
Running an external asset view against your internal inventory once a quarter turns shadow assets into a change queue. Here is the exact process.
- Asset Exposure Discovery Tools Compared: 4 Approaches
Shodan, Censys, runZero, and cloud-native inventory each answer BOD 26-04's 'is it publicly exposed?' question differently. Here is how they compare.
- This Week in Change Risk — Week of Aug 24, 2026
A CVSS-10.0 Oracle flaw with CISA's tightest three-day deadline, six more KEV entries, GitHub's outage pledge, and PagerDuty's SRE-agent drop.
- BOD 26-04: Pre-Wire Your Emergency Change Before the Clock
CISA's BOD 26-04 sets a 16-row deadline table. Here is how a CAB pre-authorizes the ECAB so a 3-day KEV clock never catches you improvising.
- The Compensating Controls Register Auditors Accept
You deferred a control and promised a compensating one. Here is the register entry that PCI, SOC 2, and NIST assessors sign off on instead of flagging.
- This Week in Change Risk — Week of Aug 17, 2026
Eight new CISA KEV entries led by a critical VMware vCenter flaw, GitHub's near-8-hour outage post-mortem, and NIS2's October deadline closing in.
- Asset Criticality Scoring: ACR vs CMDB vs FIPS 199
Your scanner rates asset criticality, your CMDB has a field for it, and NIST has a standard. Here is how the three approaches actually compare.
- Risk-Based Patching: How to Defend It to an Auditor
You skipped a Critical CVSS because EPSS said low-risk. Here is the evidence trail that keeps a PCI, SOC 2, or SOX auditor satisfied.
- Securing Self-Hosted BI Tools: A Change-Control SOP
Metabase, Grafana, Superset and Redash hold credentials to every database they query. A change-managed SOP to get them behind SSO and off the internet.