// BLOG
All posts.
Field notes from 20+ years in security. Plus the occasional detour into life, work, and whatever else is on my mind.
Threat Modeling for the Bank That Doesn't Have a Threat Intel Team
The standard threat modeling playbook assumes staff and budget many institutions don't have. Here's a working method for a security team of one to three people: four questions, free intelligence sources, and a defensible answer for the examiner.
Stop Trying to Spot the Deepfake
Cybersecurity Awareness Month is about to flood your inbox with tips for spotting deepfakes. Weird blinking, bad lip sync, extra fingers. That advice has already expired. Here's what to teach instead.
Whose No Counts
Everybody wants AI. Nobody wants the data center next door. 'Not in my backyard' works fine, as long as you have the power to make it stick.
I'm Speaking at ISC2 Security Congress 2026. Twice.
Two sessions at ISC2 Security Congress in Aurora, Colorado this October: one on making career decisions with the MOVE framework, one on threat modeling when your resources don't match your threat. Here's where to find me.
Your Security Rating Is a Credit Score From a Company That's Never Met You
Security ratings platforms grade your vendors from the parking lot, bill somebody for the number, and hand your board a red dot to ask you about. Here's what the score actually measures and what deserves your diligence hours instead.
The Vendor of My Vendor Is My Vendor
Jack Henry, IDScan.net, and LexisNexis. Three companies that aren't banks, all of them a community bank's problem, and not one of them chosen by the bank. Why the failures keep landing a tier or two below the line where your vendor program stops looking.
The Reporting Line Debate Is a Distraction
Everyone argues about where the CISO should report. That's the wrong argument. The real fix is a written mandate around the budget you'll have to challenge, and it doesn't require a new box on the chart.
My Brain Is Built for Incidents. It's the Other 320 Days That Need a System.
The wiring that makes me lose my keys is the same wiring that goes calm and fast when everything is on fire. What twenty years in security taught me about working with my brain instead of against it.
The Most Expensive Attack on Your Bank Won't Use Malware
Business email compromise still outearns ransomware every year, and it beats banks that have EDR, MFA, and a clean exam. The control that stops it is a process, not a product, and most institutions never test it.
The Authority Gap Is a Conflict of Interest Problem
Everyone agrees the CISO role is accountable for more than it controls. Almost nobody names the mechanism. Here's what actually has to change.