Insights
Practical security thinking.
Notes on strategy, assessments, and building a security program that holds up — written for the people who have to make the decisions.
In the pipeline
Application SecurityReading a penetration test report without panicking
DraftingRisk & ComplianceSOC 2 readiness: what actually moves the needle
DraftingVulnerability Mgmt"Patch everything" is not a strategy
PlannedThreat ModelingThreat modeling for teams that have never done it
Planned