Desk overview
01 / Topic area
Security Leadership & Strategy
Security programs, operating models, organization design, executive communication, investment, prioritization, adoption, and leadership lessons rooted in security and technology experience.
02 / Topic area
AI & Emerging Technology
Enterprise AI, agents, local models, AI architecture, experimentation, and the implications of emerging technology for technology and security leaders.
03 / Topic area
Security Operations & Architecture
SOC, detection, telemetry, SIEM and data platforms, infrastructure, cloud, identity, endpoint, and operational security tooling.
04 / Topic area
Risk, Governance & GRC
Enterprise risk management, governance frameworks, and the GRC platforms and processes that connect security strategy to day-to-day execution.
05 / Topic area
Product & Application Security
Product security and application security practices — the reviews, tooling, and processes that build security into what gets shipped.
Security Leadership & Strategy
Security Leadership & Strategy Security programs, operating models, organization design, executive communication, investment, prioritization, adoption, and leadership lessons rooted in security and technology experience.
article · Featured
The CyberSecurity & Evolving Threats
A general-audience tour of the threats that dominated 2022 — ransomware, malware, and phishing — and the baseline controls that reduce exposure to them.
22 Dec, 2022
Open document : The CyberSecurity & Evolving Threatsarticle · Featured
Top 5 things for a Successful Cyber Response 'IR' Plan
Having an incident response plan at all is associated with a 43% reduction in breach cost. Here are the five things that separate a plan that holds up under pressure from one that sits unread — with practical examples for each.
11 Jan, 2022
Open document : Top 5 things for a Successful Cyber Response 'IR' Planarticle
Your Decisions Are the Bottleneck, Not Your AI
AI can do security work in seconds, but the work still waits in queues and SLAs built for human speed. Compare each SLA with how fast AI can do the same step, automate the steps that need no judgment, and set clear rules for when containment blocks and when it goes to a person.
26 Sep, 2026
Open document : Your Decisions Are the Bottleneck, Not Your AInote
How Do Security Leaders Learn to Talk Business? An Open Question
Security leaders lose decisions when they report on controls instead of choices. A question-stage note: why I think the translation fails, what the SEC's 2023 rule implies about who carries it, and a way to start practising this week.
26 Sep, 2026
Open document : How Do Security Leaders Learn to Talk Business? An Open Questionframework
Mountain Maturity Communication Model
A mountain-climbing analogy that translates NIST CSF maturity levels into a five-stage narrative — Basecamp through Summit Standard — that boards and executives grasp without a framework briefing.
21 Sep, 2026
Open document : Mountain Maturity Communication Modelexperiment
I Scanned 16 MCP Servers for Safety Hints. The Scanner Flagged Every One.
On 2026-05-21 I scanned 16 public MCP servers for tool annotations, the hints agent clients use to decide when a human approves an action. The scanner flagged all 16, and one of those results is wrong. Here is what the gap means for approval gates, and what to check before you adopt a server.
20 May, 2026
Open document : I Scanned 16 MCP Servers for Safety Hints. The Scanner Flagged Every One.article
4 Essentials for Executive & Business Buyin on your Incident Response Plan
Four things an incident response plan needs before executives will stand behind it: response SLAs the business agrees to, a clear split between operational and strategic plans, formalization of processes you already run rather than net-new invention, and a signature from the C-suite.
22 Dec, 2022
Open document : 4 Essentials for Executive & Business Buyin on your Incident Response PlanAI & Emerging Technology
AI & Emerging Technology Enterprise AI, agents, local models, AI architecture, experimentation, and the implications of emerging technology for technology and security leaders.
experiment
I Ran 849 Tests on AI Context Files. Here's What Actually Works.
849 controlled tests across three corpus sizes and five folder structures found that a single flat folder with descriptive filenames beats nested hierarchies at every scale — and that keyword or summary indexes actively hurt accuracy once a corpus passes 300K words.
05 Feb, 2026
Open document : I Ran 849 Tests on AI Context Files. Here's What Actually Works.article
Claude Code Has Two New CVEs — Here's What They Exploit and How to Harden Your Setup
Check Point disclosed two Claude Code CVEs exploiting hooks and MCP config files. Here's what the attack chains look like and how to harden your environment.
04 Mar, 2026
Open document : Claude Code Has Two New CVEs — Here's What They Exploit and How to Harden Your Setuparticle
Pre-Selection Beats Post-Selection: How I Made Claude Code 10-30x Faster
Guidance that arrives before a decision beats guidance buried in instructions. By intercepting tool choices before they happen, I cut code-navigation searches from ~300ms to ~50ms — a 10-30x improvement that compounds across hundreds of searches a day.
04 Feb, 2026
Open document : Pre-Selection Beats Post-Selection: How I Made Claude Code 10-30x Fasterarticle
Your Decisions Are the Bottleneck, Not Your AI
AI can do security work in seconds, but the work still waits in queues and SLAs built for human speed. Compare each SLA with how fast AI can do the same step, automate the steps that need no judgment, and set clear rules for when containment blocks and when it goes to a person.
26 Sep, 2026
Open document : Your Decisions Are the Bottleneck, Not Your AIexperiment
I Scanned 16 MCP Servers for Safety Hints. The Scanner Flagged Every One.
On 2026-05-21 I scanned 16 public MCP servers for tool annotations, the hints agent clients use to decide when a human approves an action. The scanner flagged all 16, and one of those results is wrong. Here is what the gap means for approval gates, and what to check before you adopt a server.
20 May, 2026
Open document : I Scanned 16 MCP Servers for Safety Hints. The Scanner Flagged Every One.tool
Claude Code Doesn't Know What Time It Is — So I Fixed It
Claude Code can't tell whether you left for two minutes or eight hours, so it picks up stale threads as if nothing changed. claude-prompt-timer is a small hook that tells it how long you've been away. Install it in three steps and confirm it works in one.
08 Apr, 2026
Open document : Claude Code Doesn't Know What Time It Is — So I Fixed Itarticle
The Math Problem AI Just Changed for Security Testing
Security testing has always been an economics problem: defenders can only test what they can afford to test. AI changed the cost of testing, and that changes which assumptions about coverage still hold.
22 Mar, 2026
Open document : The Math Problem AI Just Changed for Security Testingarticle
I Scanned 152 Files of My Own AI-Generated Code for Invisible Unicode Malware
GlassWorm hid malicious code in invisible Unicode characters. I scanned 152 files of my own AI-generated code to see whether the same trick was already sitting in my repositories — and built a pre-commit check from what I found.
17 Mar, 2026
Open document : I Scanned 152 Files of My Own AI-Generated Code for Invisible Unicode Malwarearticle
How I Made Claude Code Safer (And You Can Too)
Claude Code validates which tools can run, not what they write. That gap cost me a crashed project and a malformed config file — so I built a plugin that validates content before it hits disk, and it turned out to teach Claude to stop repeating the same mistakes.
10 Feb, 2026
Open document : How I Made Claude Code Safer (And You Can Too)tool
Document Guard
An open-source Claude Code plugin that inspects every file edit before it hits disk — catching credential leaks, silently dropped Markdown sections, and broken configs that permission rules alone don't stop.
09 Feb, 2026
Open document : Document GuardPage 1 of 2
Security Operations & Architecture
Security Operations & Architecture SOC, detection, telemetry, SIEM and data platforms, infrastructure, cloud, identity, endpoint, and operational security tooling.
article · Featured
Four Generations of Broken Promises: Why AI SOC Agents Might Actually Be Different
Three generations of security tooling promised to fix the analyst shortage. All three failed. The fourth — AI SOC Agents — operates on a different principle, but CISOs who ignore twenty years of lessons will repeat the same expensive mistakes.
18 Mar, 2026
Open document : Four Generations of Broken Promises: Why AI SOC Agents Might Actually Be Differentarticle · Featured
The SIEM Cost Trap — Why Your Data Lake + AI Agents Will Win
The per-gigabyte SIEM pricing model punishes growth. A tiered architecture — hot data for detection, cold storage in a data lake, AI agents bridging the gap — breaks the cost trap without sacrificing security outcomes. Here's how to make the case to your leadership.
01 Apr, 2026
Open document : The SIEM Cost Trap — Why Your Data Lake + AI Agents Will Winarticle
Your Decisions Are the Bottleneck, Not Your AI
AI can do security work in seconds, but the work still waits in queues and SLAs built for human speed. Compare each SLA with how fast AI can do the same step, automate the steps that need no judgment, and set clear rules for when containment blocks and when it goes to a person.
26 Sep, 2026
Open document : Your Decisions Are the Bottleneck, Not Your AIarticle
What AI Is Actually Doing in Your SOC — and What It Shouldn't Be Doing Yet
Only 9% of security practitioners are "very confident" in AI-generated alerts — yet adoption is accelerating. The gap comes down to a distinction the demos never make: AI at decision points in a workflow is not the same as AI replacing the workflow. Here is which use cases earn their keep.
27 Apr, 2026
Open document : What AI Is Actually Doing in Your SOC — and What It Shouldn't Be Doing Yetarticle
Your Data Lake Is Only as Useful as Its Ability to Answer a Question
You moved security data to a lake and cut costs. Then an investigation hit and your team spent two weeks finding what should have taken hours. The difference between a cheap archive and a queryable security asset comes down to three architecture decisions most organizations haven't made yet.
09 Apr, 2026
Open document : Your Data Lake Is Only as Useful as Its Ability to Answer a Questiontool
Claude Code Doesn't Know What Time It Is — So I Fixed It
Claude Code can't tell whether you left for two minutes or eight hours, so it picks up stale threads as if nothing changed. claude-prompt-timer is a small hook that tells it how long you've been away. Install it in three steps and confirm it works in one.
08 Apr, 2026
Open document : Claude Code Doesn't Know What Time It Is — So I Fixed ItRisk, Governance & GRC
Risk, Governance & GRC Enterprise risk management, governance frameworks, and the GRC platforms and processes that connect security strategy to day-to-day execution.
Nothing published here yet.
Product & Application Security
Product & Application Security Product security and application security practices — the reviews, tooling, and processes that build security into what gets shipped.
Nothing published here yet.