Writing

Essays from the field.

Post-quantum cryptography. The changing CISO role. Agentic AI risk. Cyber-trafficking. What I'm watching and what I think leaders should do about it. New posts every Tuesday.

Enterprise Cybersecurity & Risk

Your Third-Party Risk Program Is a Spreadsheet. Attackers Know It.

Vendor questionnaires do not tell you what will happen at 2 a.m. Here is the risk view I want on a CISO's desk.

Sept 22, 20267 min read
Humanitarian Technology

Your Fraud Queue Is Hiding a Trafficking Signal

A forced operator can look like an abusive account. Security leaders need a safer way to read the signal.

Sept 15, 20266 min read
Humanitarian Technology

Scam Farms Are a Cybersecurity Problem. Treat Them That Way.

The people trapped behind the screen are part of the threat model. Leaders need to connect fraud controls, platform design, and survivor support.

Sept 8, 20266 min read
Post-Quantum Cryptography

The Quantum Deadline Isn't 2038. It's Today.

Harvest-now-decrypt-later is not a future threat. Long-lived encrypted data being stolen this quarter will be readable the moment a real quantum computer arrives. What every CISO should do about it, right now.

Sept 6, 20269 min read
Enterprise Cybersecurity Leadership

The CISO's New Job Description: Chief Cryptographic Officer

Cryptography used to be an appendix. In the PQC era it is the CISO's number one architectural risk. And agentic AI is the accelerant. Why the role is being rewritten in real time.

Sept 6, 20268 min read
Emerging Technology

The Three Technologies That Will Define the Next Decade of Risk

Quantum computing. Agentic AI. Biometric and genetic data. Each one is a category-shifting change in what "sensitive data" means. The next generation of leaders will be judged on what they saw coming.

Sept 6, 202610 min read