Rolling with the Punches: Why Cybersecurity is Backgammon, Not Chess

It is tempting to compare cybersecurity to a chess game. Two adversaries facing each other, plotting strategy and tactics. Move and counter move, anticipating actions and grinding out a win. In reality, in our complex world of dependencies, supply chains, constantly shifting technology platforms and unpredictable attackers, this is all way more haphazard. Indeed, a better analogy is backgammon, where you position yourself for many different possible outcomes to maximize your chance of...

8/23/2026
Read more

A Coming Incident Crisis?

We’re all talking about the tidal wave of vulnerabilities that is upon us, with repeated waves likely coming. As I’ve covered here, we can respond to this in various ways including ramping up speed across our entire defensive stack, which is as much about structural defense-in-depth than just faster patching. I’ve covered that here as well. But, there’s a question as to whether the leading indicator of increasing vulnerabilities will in fact result in an increase in the lagging indicator of...

8/8/2026
Read more

Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls

Security breaches are often not the result of awesome attacker capabilities or the sudden emergence of sophisticated zero-day exploits. Instead, what we usually find are the controls designed to stop the attack were believed to be operational but were actually broken or misconfigured at the moment when they were needed. Sometimes they were never fully in place to meet the security team's original intent. So, continuous control monitoring is needed to counter the natural decay that occurs to...

7/25/2026
Read more

Technology Waves and Security - Is This Time Really Different?

Most people have been through at least one wave of technology transformation. Some of us have been through a few and all carry the wisdom and scars from these. When you’ve experienced these changes you learn to appreciate, as the adage goes, that history might not repeat but it certainly does rhyme. In my working lifetime I caught the tail end of the mainframe to PC transition, the proliferation of client/server and distributed system architectures, wide-spread Internet adoption, mobile...

7/11/2026
Read more

Sorry, Cyber: You Aren't the Only Ones Saving the Company from Itself

There’s still a bit of a tone in some security circles that we’re somehow unique in constantly having to push back against ill-advised moves, or even outright craziness, from our business, operations, or technology colleagues. But, when you pause and think about all the many functions in your or other organizations you realize this is not so. You quickly see that while great security teams are true enablers of business and reducers of friction, most teams still have to (and are expected to...

6/27/2026
Read more

CISO Version 2.0 

Everyone, no doubt, has an opinion on how many versions of the CISO role we have gone through since its inception. There has been a constant evolution from what was essentially an IT security manager, to cyber-defense leader, compliance director, technology risk manager, and beyond. However, I would argue the incarnation of the CISO role up until recently has been CISO Version 1.0 albeit with some “point releases” on the way. This is simply because version 1 of the role is a mode where most...

6/12/2026
Read more

The Power of Community: 7 Steps to Fast-Track Your Security Career - Update

Since I wrote the first version of this post some years ago much has changed. Technology changes, market changes, specific industry changes, compounded by more aggressive and numerous threats that continue to reshape and challenge security teams and roles. The way we advance our careers and the way we use communities inside and outside our organization is changing. But there are also constants we can rely on. As we start out, or even when entering a new stage of our careers, we realize the...

5/29/2026
Read more

Do You Really Know What’s Going On?

At some point every leader needs to ask themselves: Do I really know what is going on in my company? Do I even know what is really going on in my own organization? Most leaders do not know the actual truth of what is happening. This is not because people are overtly hiding things or that leaders are ineffective, although sometimes it is both of those, but rather this is because of the “thermocline of truth” that I covered in this post. Organizations are full of cultural, structural, process,...

5/16/2026
Read more

High Frequency Trading and Lessons for Agentic AI

I suspect I’m not the only former or current financial markets technologist that sees parallels between the world of high frequency / algorithmic trading controls and what is needed for appropriate deterministic guardrails around our, mostly, non-deterministic agentic AI systems. As we transition from chatbots to systems of agents, that don't just talk but act, we are entering a regime of automated risk that the financial markets have navigated, mostly successfully, for decades....

5/2/2026
Read more

Maintenance of Everything : A Review

I haven’t done a book review for a while and there’s no better way to get back to this than a look at Stewart Brand’s Maintenance of Everything . Stewart developed a lot of this book in an open editing process and so the final delivery of what is Part 1 of a forthcoming series was all the more anticipated. I’ve long been obsessed with the need for maintenance in the context of technology risk management, security and reliability. A big part of technical debt build up and the security...

4/18/2026
Read more

Recommended Feeds