1. How to Threat-Model a System You Have Never Seen Before

    Most threat-modelling advice assumes you have weeks, a working relationship with the engineering team, and a system that is stable. None of those apply when you are walking into a new environment on a Tuesday afternoon. Here is the version that does

    Purple Teaming

  2. What a CISO Actually Does on a Tuesday Afternoon

    The CISO job description reads like a strategy role. The actual job is mostly operational. Here is what a competent CISO does on a typical Tuesday afternoon, and what the things look like in practice

    Purple Teaming

  3. Why Most Threat Intelligence Programmes Are Not Worth the Money

    Threat intelligence is one of the most expensive parts of a security programme and one of the most under-used. Most programmes pay for feeds they do not read, run platforms they do not use, and produce reports that do not change anything. Here is the honest version of the work

    Purple Teaming

  4. The Insider Threat Problem Is Not What You Think

    Your insider threat programme is aimed at the wrong target

    Insider Threat Detection Engineering

  5. How to Scope a Red Team Engagement That Tells You Something Real

    Most red team engagements produce an impressive document and a set of \"critical findings\" that the security team could have predicted before the first phishing email was sent

    Red Team Purple Teaming