Essays from the field.
Post-quantum cryptography. The changing CISO role. Agentic AI risk. Cyber-trafficking. What I'm watching and what I think leaders should do about it. New posts every Tuesday.
Your Third-Party Risk Program Is a Spreadsheet. Attackers Know It.
Vendor questionnaires do not tell you what will happen at 2 a.m. Here is the risk view I want on a CISO's desk.
Your Fraud Queue Is Hiding a Trafficking Signal
A forced operator can look like an abusive account. Security leaders need a safer way to read the signal.
Scam Farms Are a Cybersecurity Problem. Treat Them That Way.
The people trapped behind the screen are part of the threat model. Leaders need to connect fraud controls, platform design, and survivor support.
The Quantum Deadline Isn't 2038. It's Today.
Harvest-now-decrypt-later is not a future threat. Long-lived encrypted data being stolen this quarter will be readable the moment a real quantum computer arrives. What every CISO should do about it, right now.
The CISO's New Job Description: Chief Cryptographic Officer
Cryptography used to be an appendix. In the PQC era it is the CISO's number one architectural risk. And agentic AI is the accelerant. Why the role is being rewritten in real time.
The Three Technologies That Will Define the Next Decade of Risk
Quantum computing. Agentic AI. Biometric and genetic data. Each one is a category-shifting change in what "sensitive data" means. The next generation of leaders will be judged on what they saw coming.