Principles for Cybersecurity Metrics
“For every metric, there should be another ‘paired’ metric that addresses adverse consequences of the first metric.” - Andy Grove We talk...
Principles for Cybersecurity Metrics
The Uncanny Valley of Security (or Why We Might Never Finish Anything)
Cybersecurity Macro Themes for the 2020’s - Updated
Why Cybersecurity Budget Benchmarks are a Waste of Time
Vulnerability Management - Updated
Building Balanced Security Teams: The Rule of Thirds
Security for More than Security’s Sake - The Need for Adjacent Benefits
The Most Important Mental Models for CISOs - Simple Steps for Outsize Effects
The Rising Tide and the Case for Security Optimism
Raise the Baseline by Reducing the Cost of Control
Taking Inventories to the Next Level - Reconciliation and Triangulation
Security Budgets - Supply and Demand Thinking