Insights
Notes without the hype.
Plain-language notes on the things our clients are actually dealing with new rules, new tools, and how to handle both without the hype.
We're security engineers, not report-writers — why the report is the easy part
Most security consulting stops at a report full of red findings. Here's why the fix is the hard 80%, and the question that sorts real help from paperwork.
Read →What a decade of defense-grade security taught me about small-business risk
Defense-grade security isn't about eliminating risk. It's knowing which risks you can afford to take fast; the judgment a small business needs most.
Read →Using AI at work without doing something you'll regret
Is it safe to use AI at work? The real risks, calmly stated, the rules I follow about what I'll paste into a chatbot, and the one question to ask any AI vendor.
Read →A big customer sent you a security questionnaire. Here's what they're actually asking.
A security questionnaire from a big customer isn't a test of your paperwork. What each section is really asking, and the few controls that answer most of it.
Read →