Vertically Capable, Horizontally Dysfunctional: The Myths of Cyber Resilience

80% of what you will read about “cyber resilience” on LinkedIn today is nonsense. It will not make…

Rule of Two: New Subject, Same Old Mistakes

You may have seen Meta’s “Rule of Two” floating around, as a mental model for agentic security. Don’t…

Who thinks their own job is BS?

What should you do if you think your own job is BS?

What we think “good” looks like in SecOps is actually part of the problem

Shrinking the gap between events and impacts is the wrong strategy.

Growth that Builds, Growth that Breaks

You've probably heard it said that "healthy things grow". That's not true. Cancer also grows. What we can say for sure is that alive (or dynamic) things grow; whether that growth is beneficial or destructive is a different question.

How Focusing on Strategy Perpetuates the Problem

Strategy is easy. Execution is where the wheels come off.

Cybersecurity is a System

China found out the hard way that no one escapes the interdependencies of complex systems. We make the same mistakes in cybersecurity today.

Connect/Okta and Identity Sync Hardening

One area commonly overlooked (by defenders, but not by attackers) is identity sync infrastructure. If you harden your AD but don't do this, you are wasting your time.

G before RC

The order of the letters in "GRC" is not arbitrary. If you don't Govern your environment well, you cannot manage Risk and Compliance well.