Monday, March 16, 2026

The Human IOC: Why Security Professionals Struggle with Social Vetting

In the security field, we focus so much on vetting data and information. Yet, when it comes to people or organizations, we invest far less in vetting them. Why is that and how can we improve? I discuss in my latest SecurityWeek piece: https://www.securityweek.com/the-human-ioc-why-security-professionals-struggle-with-social-vetting/.

Wednesday, February 11, 2026

Security in the Dark: Recognizing the Signs of Hidden Information

Security in the Dark: Recognizing the Signs of Hidden Information - My latest piece in SecurityWeek discusses that security failures don’t always start with attackers, sometimes they start with missing truth. https://www.securityweek.com/security-in-the-dark-recognizing-the-signs-of-hidden-information/.

Thursday, January 8, 2026

The Loudest Voices in Security Often Have the Least to Lose

Beware of security advice that comes from people or organizations that have no stake in the outcome, nothing to lose, and won't bear any of the consequences. What do I mean? I discuss in my latest SecurityWeek piece: https://www.securityweek.com/the-loudest-voices-in-security-often-have-the-least-to-lose/.

Wednesday, December 3, 2025

The Great Disconnect: Unmasking the ‘Two Separate Conversations’ in Security

Have you ever observed two people talking to one another, yet having two entirely different conversations? I discuss how this can harm security in my latest SecurityWeek piece: https://www.securityweek.com/the-great-disconnect-unmasking-the-two-separate-conversations-in-security/.

Thursday, September 25, 2025

Perspective: Why Politics in the Workplace is a Cybersecurity Risk

Have you stopped to consider how bringing politics into the workplace is a security risk? I discuss in my latest SecurityWeek piece: https://www.securityweek.com/perspective-why-politics-in-the-workplace-is-a-cybersecurity-risk/.

Wednesday, August 20, 2025

Slow and Steady Security: Lessons from the Tortoise and the Hare

What can Aesop’s fable “The Tortoise and the Hare” teach us about security? A lot I would argue, particularly about ignoring hype and building security programs that are consistent, resilient, and effective. I discuss in my latest SecurityWeek piece: https://www.securityweek.com/slow-and-steady-security-lessons-from-the-tortoise-and-the-hare/.