image
September 9, 2026

Your Compliance Evidence Is Getting Better. Your Controls Aren't.

AI can now collect compliance evidence, map it to controls, identify gaps, draft policies, and write the narrative explaining how a company meets a requirement. AI didn't create the problem I want to talk about. It just makes the evidence cleaner, faster, and easier to produce.I've spent a large part of my career assessing security programs, working through compliance requirements, and helping companies fix what happens after the assessment is over. Long before AI entered the conversation, I saw the same issue over and over again. A company could show evidence that a control existed without necessarily proving that the control worked the way everyone thought it did.I don't think better evidence is a bad thing. I think we're going to see a lot more of it. The problem is what happens when we start confusing better evidence with better security.And that changes what we should be asking.What did compliance automation actually change?Tools like Vanta and Drata have improved a part of compliance that needed to improve.Anyone who has been through enough audits remembers the old process. Someone creates an evidence request list. Teams start taking screenshots. People chase control owners. Evidence gets dropped into folders. Spreadsheets track what is missing. Then everyone does it again during the next audit cycle.

image
August 11, 2026

Security Theater vs. Real Security: Why Passing a Compliance Audit Doesn't Mean You're Secure

Passing a compliance audit is important, but it doesn't necessarily mean you're secure. One of the most common things I see when assessing companies is that the issue isn't a lack of security investment. In many cases, they've bought the right tools, written the policies, implemented MFA, deployed endpoint security, configured backups, and completed the audit. On paper, the program looks good. The problem starts when you look at how those controls are actually being operated day to day.

image
August 3, 2026

Who Owns AI Governance at Your Company?

AI governance isn't a technology problem. It's an ownership problem. Only 2% of small firms have a comprehensive AI governance framework, yet 88% of organizations are already using AI in at least one business function. Meanwhile, one in five data breaches now involves shadow AI , and in 97% of those cases, the breached organization had no AI access controls in place.

image
July 23, 2026

What to Do After a Data Breach: The Real Work Starts Now

The breach is over.The systems are back online. Business is operating again. The incident response team has wrapped up. The cyber insurance claim is underway. Everyone wants to move on.That's exactly when I tell clients to slow down.After being involved in enough incident response engagements, I've learned that the recovery phase is where organizations either become significantly stronger or quietly set themselves up for the next incident.The attack is over, but the work isn't.

image
July 23, 2026

Data Breach Response: What the First 24 Hours Actually Look Like

A few years ago, I was pulled into an incident that started with a single customer call. The customer had logged into the platform that morning and noticed files were missing. At first, everyone assumed it was a support issue. Then a second customer reported something similar. Then a third. Within an hour, leadership was pulled into the conversation. At that point, nobody knew whether the issue was operational, accidental, or security related. The investigation was just getting started.

image
June 16, 2026

Before the Breach: The Warning Signs Were Already There

Every organization worries about a breach. Almost none understand what one actually looks like until they live through it. This is the first post in a series on what actually happens before, during, and after a breach. This one is about what comes before: the conditions that were already there, long before anyone knew there was a problem.Every organization worries about a breach. Almost none understand what one actually looks like until they live through it.

image
August 3, 2026

Third-Party Vendor Risk Management for Small Businesses: Start With Visibility

Most companies no longer operate entirely inside systems they own or directly control. Business operations now depend on SaaS platforms, MSPs, cloud providers, contractors, outsourced IT teams, payroll systems, AI tools, marketing platforms, and dozens of connected applications working together behind the scenes.The attack surface has changed significantly over the last five years, especially for fast-growing companies that depend heavily on third-party technology to operate. And in a lot of environments, visibility has not kept pace.

image
August 3, 2026

Startup Security Roadmap: Seed to Series C

A stage-by-stage guide to building a security program that scales with your business, supports enterprise revenue, and holds up under investor scrutiny. Security in SaaS companies is often misunderstood, especially in early and growth-stage startups. These businesses deliver cloud-based software and are responsible for storing, processing, and protecting customer data, particularly as they begin targeting enterprise clients where security and compliance directly impact revenue.

image
August 3, 2026

The Cybersecurity Maturity Path: From Startup to Enterprise

Security is not one size fits all. A 10-person startup with an MVP and a short runway should not be investing like a 5,000-person global SaaS company preparing for IPO. But too often, companies either underinvest early or throw money at tools without a plan later.

What topics would you like us to cover next? Share your ideas