Case file EOSection: WritingRef. EO-WRTBack to the case file
Essays on Medium
Practitioner essays on breaches, compliance and AI security, written for people who have to make the call.
Articles
In plain English: essays for managers and practitioners about real security decisions.
-
Compliance vs. Reality: When Cybersecurity Controls Are Recommended but Not Practicable
What happens when NIST SP 800-53 and CMMC-mandated controls exist on paper but cannot be implemented? A practitioner’s honest look at the gap.
-
Why Risk Management Matters More Than Ever in the Age of AI
Risk management has long been the backbone of effective cybersecurity, and the rise of AI has made it more complex, and more consequential, than ever.
-
The Ancient Scrolls Warned Us: Patch or Perish
Change Healthcare and UnitedHealth Group looked like they had everything in order. The breach told a different story, and the lessons apply everywhere.
-
Practical Expected Value Review
A full expected value breakdown with cybersecurity context: real-world lessons for risk quantification practitioners and security leaders.
-
Dear Vendor: We’re Breaking Up. It’s Not Us, It’s Your Security Posture
The Salesloft/Drift SaaS breach: a deep dive into third-party risk and vendor security governance.
-
When Nation-State Hackers Target Small Defense Contractors: A Look Through the DREAD Lens
Most assume nation-state attacks only target large institutions. For a security manager at a small U.S. defense contractor, that assumption is dangerous.
-
I Read the Privacy Policy (Said No One Ever)
The F5 breach and the Zscaler 2025 Mobile, IoT & OT Threat Report reveal how the meaning of data privacy has shifted in a connected world.
-
The Faketivism Frontier: Weaponized AI to Attack Trust, Not Servers
The CrowdStrike 2024 Global Threat Report details how nation-states are transforming information warfare, targeting credibility and trust over infrastructure.
Also published
In plain English: other places my writing has appeared.
- MediumCybersecurity as a Growth Engine: Bridging Technical Controls with Business Strategy
- MediumThe Breach Wasn’t in the Plan, Because There Wasn’t a Plan
- MediumThis Update Brought to You by the ‘It Worked on My Machine’ Foundation
- MediumDistributed Spoofing in Critical Infrastructure: Challenges in Cybersecurity
- LinkedIn articleAI Ops and Cyber Security