Writing and thinking about information security. Helping organizations build resilient security postures through assessment, architecture, and compliance.
Comprehensive security solutions tailored to your organization.
Know where you stand before an attacker shows you. Our assessments go beyond automated scans to uncover real risks in your environment.
Build security into your infrastructure from the ground up. We design network architectures that are secure by default and resilient by design.
Compliance does not have to be painful. We help you meet regulatory requirements efficiently while building a governance program that adds real value.
Control who has access to what and when. We help you implement IAM frameworks that balance security with usability.
Thinking out loud about security, risk, and what it means to protect systems.
Your Firewall Might Be the Hole: Why “Supported” Is the Hardest Hardening Move You Will Make This Year On February 5, 2026, CISA issued Binding Operational Directive 26-02 with a deadline you can set your calendar by. Federal civilian agencies now have **90 days** to inventory every edge device running end-of-support software, **12 months** to […]
A finance worker in Hong Kong thought he was on a video call with his company’s CFO. Every face in the meeting was real except none of them were. He authorized 15 wire transfers that day totaling about $25.6 million. The “CFO” was a deepfake. The other participants were deepfakes. The whole thing was a […]
The Network Management Plane Just Became the Most Exploitable Surface You Own Between Tuesday and Thursday of last week, three vendors told the world that the systems meant to control your network are now the easiest way into it. Cisco disclosed a CVSS 10.0 authentication bypass in Identity Services Engine that attackers are using right […]
Ready to get serious about security? Tell me about your situation.