top of page
Search
Oct 21, 202312 min read
Career Development: 13 Formative Moments (Part 2)
The skills for your role and your leadership style build up throughout your career. But I’ve found, personally and in talking to others,...
1,140
Oct 7, 202316 min read
Career Development: 13 Formative Moments (Part 1)
The skills for your role and your leadership style build up throughout your career. But I’ve found, personally and in talking to others,...
3,027
Sep 23, 20237 min read
Is Complexity the Enemy of Security?
Since the last post about leverage points in managing complex systems I thought it would be good to revisit and update a post from a few...
2,400
Sep 9, 202314 min read
Leverage Points - A Cybersecurity Perspective
Security is an emergent property of the complex systems we inhabit. In other words, security isn’t a thing that you do, rather it's a...
2,948
Aug 26, 20236 min read
Security Budgets - Supply and Demand
Unless you’re doing continuous or quarterly budgeting, which some organizations do, then you’ll no doubt be getting ready for the long...
4,372
Aug 12, 20234 min read
Building Balanced Security Teams - Updated
As an industry we spend a lot of time talking about workforce development and skills shortages. However, we tend not to talk about how to...
2,961
Jul 29, 202314 min read
Confessions of a Public Speaker - Tips for Security Practitioners
Many of us have to regularly speak in public at a range of events large and small, public and private, staged and ad-hoc. As your career...
6,041
Jul 15, 202313 min read
Resilience Engineering - Step by Step
Resilience Engineering: Concepts and Precepts is an excellent collection of standalone essays, woven into a consistent whole on the...
2,657
Jul 1, 20233 min read
AI Consequence and Intent - Second Order Risks
There is a lot of good discussion and emerging methods to manage the risks of AI in various forms from training data protection, model...
1,297
Jun 17, 202319 min read
Work / Life Balance
I have always struggled to balance work and life. Many years ago I realized I wasn’t so much struggling to achieve an effective balance,...
9,042
Jun 3, 20238 min read
Delivering Security at Scale: From Artisanal to Industrial
Maturing a security program in any type of organization is not just to increase specific control effectiveness but also to increase its...
7,207
May 20, 202310 min read
You Only Get 3 Metrics - Which Ones Would You Pick?
Just over a year ago I put out this blog post on the 10 fundamental (but really hard) security metrics. Since then I’ve discussed this...
9,126
bottom of page