Insights
Thought leadership themes anchored in executive cybersecurity leadership, resilience, and real incident response experience.
Articles
Revolut Didn't Get Hacked. It Got Asked.
No exploit. No phished admin. Someone emailed from a real government domain asking for customer records, and Revolut sent them.
Most Tabletop Exercises Are Theatre
If your last tabletop produced a report and a warm feeling, you paid for theatre. Here is what a real one looks like.
Gunra Isn't Using a Zero-Day. It's Using the Fortinet Bug You Didn't Patch.
The FBI and CISA just named Gunra, a ransomware crew hitting critical infrastructure on four continents. The front door isn't exotic — it's two Fortinet flaws that already have patches.
The Master Key Problem: Why Your MSP's Best Tool Is a Risk to You
Your MSP holds a master key to everything you own. The N-able N-central exploitation is not an N-able story — it's the predictable result of how the managed services model is built.
Your Session Will Get Stolen. Here's How to Make It Worthless.
A practical Monday-morning checklist for making stolen session tokens useless and catching the after-party fast. Follow-up to the Kali365 piece.
What Makes a Great vCISO?
Every fractional CISO can hand you a strategy deck. The distance between good and great shows up in whose name is actually on the incident report.
Nobody Fires Their MSSP on a Quiet Week. They Fire You the Morning They Heard It From Someone Else.
Retention in managed security isn't won in the quarterly review. It's decided at 4 a.m., on the one night the client finds out whether "we've got you covered" was ever true.
What Makes a Great MSSP?
Every provider can recite the same checklist. The distance between good and great now gets measured in seconds, not features — and it only shows up on the worst week of the year.
Why Your Incident Response Retainer Isn't What You Think It Is
Having an incident response retainer is not the same as being prepared for an incident. Most organizations learn the difference at exactly the wrong time.
What CISOs Get Wrong About Enterprise Resilience
After more than 600 incident response engagements, I've noticed a pattern. The organizations that handle crises worst are rarely the ones with the smallest budgets or the weakest technology.
The Leadership Test Every Cyber Incident Reveals
A cyber incident doesn't create a leadership crisis. It reveals one that was already there. In 600+ incident response engagements, the technical containment is almost never the hardest part.
Core Themes
- The Cyber Resilience Leadership Framework
- What 600+ incident response engagements teach leaders
- The executive role in cybersecurity
- Incident preparedness as a leadership discipline
- Security leadership in the AI era
Featured Concept
The Cyber Resilience Leadership Playbook is a signature thought leadership platform built around lessons from 600+ incident response engagements.