Skip to content

Insights

Thought leadership themes anchored in executive cybersecurity leadership, resilience, and real incident response experience.

Articles

Filtered byincident response

Revolut Didn't Get Hacked. It Got Asked.

social engineeringfintechdata protectionincident response· 7 min read· Sep 15, 2026

No exploit. No phished admin. Someone emailed from a real government domain asking for customer records, and Revolut sent them.

Most Tabletop Exercises Are Theatre

incident responsetabletop exercisesboard governanceresilienceMSP· 6 min read· Sep 8, 2026

If your last tabletop produced a report and a warm feeling, you paid for theatre. Here is what a real one looks like.

Gunra Isn't Using a Zero-Day. It's Using the Fortinet Bug You Didn't Patch.

ransomwarethreat intelligenceincident responseFortinetMITRE ATT&CK· 7 min read· Aug 12, 2026

The FBI and CISA just named Gunra, a ransomware crew hitting critical infrastructure on four continents. The front door isn't exotic — it's two Fortinet flaws that already have patches.

The Master Key Problem: Why Your MSP's Best Tool Is a Risk to You

MSPRMMsupply chainthird-party riskincident response· 7 min read· Aug 10, 2026

Your MSP holds a master key to everything you own. The N-able N-central exploitation is not an N-able story — it's the predictable result of how the managed services model is built.

Your Session Will Get Stolen. Here's How to Make It Worthless.

identity securityMicrosoft 365conditional accessMFAincident response· 7 min read· Jul 29, 2026

A practical Monday-morning checklist for making stolen session tokens useless and catching the after-party fast. Follow-up to the Kali365 piece.

What Makes a Great vCISO?

vCISOleadershipgovernanceliabilityincident response· 7 min read· Jul 27, 2026

Every fractional CISO can hand you a strategy deck. The distance between good and great shows up in whose name is actually on the incident report.

Nobody Fires Their MSSP on a Quiet Week. They Fire You the Morning They Heard It From Someone Else.

MSSPretentionincident responseMDRleadership· 8 min read· Jul 22, 2026

Retention in managed security isn't won in the quarterly review. It's decided at 4 a.m., on the one night the client finds out whether "we've got you covered" was ever true.

What Makes a Great MSSP?

MSSPMDRincident responsevendor managementleadership· 8 min read· Jul 21, 2026

Every provider can recite the same checklist. The distance between good and great now gets measured in seconds, not features — and it only shows up on the worst week of the year.

Why Your Incident Response Retainer Isn't What You Think It Is

incident responseretainerpreparednessvendor management· 5 min read· Mar 31, 2026

Having an incident response retainer is not the same as being prepared for an incident. Most organizations learn the difference at exactly the wrong time.

What CISOs Get Wrong About Enterprise Resilience

resilienceCISOincident responseenterprise security· 4 min read· Feb 10, 2026

After more than 600 incident response engagements, I've noticed a pattern. The organizations that handle crises worst are rarely the ones with the smallest budgets or the weakest technology.

The Leadership Test Every Cyber Incident Reveals

incident responseleadershipcrisis management· 4 min read· Jan 22, 2026

A cyber incident doesn't create a leadership crisis. It reveals one that was already there. In 600+ incident response engagements, the technical containment is almost never the hardest part.

Core Themes

  • The Cyber Resilience Leadership Framework
  • What 600+ incident response engagements teach leaders
  • The executive role in cybersecurity
  • Incident preparedness as a leadership discipline
  • Security leadership in the AI era

Featured Concept

The Cyber Resilience Leadership Playbook is a signature thought leadership platform built around lessons from 600+ incident response engagements.