-
How to Threat-Model a System You Have Never Seen Before
Most threat-modelling advice assumes you have weeks, a working relationship with the engineering team, and a system that is stable. None of those apply when you are walking into a new environment on a Tuesday afternoon. Here is the version that does
-
What a CISO Actually Does on a Tuesday Afternoon
The CISO job description reads like a strategy role. The actual job is mostly operational. Here is what a competent CISO does on a typical Tuesday afternoon, and what the things look like in practice
-
Why Most Threat Intelligence Programmes Are Not Worth the Money
Threat intelligence is one of the most expensive parts of a security programme and one of the most under-used. Most programmes pay for feeds they do not read, run platforms they do not use, and produce reports that do not change anything. Here is the honest version of the work
-
The Insider Threat Problem Is Not What You Think
Your insider threat programme is aimed at the wrong target
-
How to Scope a Red Team Engagement That Tells You Something Real
Most red team engagements produce an impressive document and a set of \"critical findings\" that the security team could have predicted before the first phishing email was sent