Principle Security Principle Security.

Insights

Useful takes on owning security

The thinking behind the work we do for boards, CFOs, and regulated institutions, in plain words with no fear-mongering and no fluff. If something here rings true, we're happy to talk it through, and no pitch is required.

Blog

Latest insights

No fear-mongering and no fluff. If something here rings true, we're happy to talk it through, and no pitch is required.

The Breach That Never Touched the Network
Aug 30, 2026 · 7 min read

The Breach That Never Touched the Network

A credit union's EDR was clean. Its identity logs were clean. And members could still have been phished at the real online-banking URL. The attack lived somewhere else entirely.

Read more
Your Transfer Lock Doesn't Do What You Think It Does
Aug 30, 2026 · 6 min read

Your Transfer Lock Doesn't Do What You Think It Does

clientTransferProhibited looks reassuring in a WHOIS record. It didn't stop an attacker from redirecting a credit union's domain, and then it didn't stop them from transferring it to another country.

Read more
Two DNS Records That Would Have Stopped a Credit Union Hijack
Aug 30, 2026 · 6 min read

Two DNS Records That Would Have Stopped a Credit Union Hijack

Within hours of taking over a credit union's DNS, an attacker held valid certificates for the whole domain, including a wildcard. No CA did anything wrong. Two missing records made it legal.

Read more
The MX Record Nobody Watches
Aug 30, 2026 · 6 min read

The MX Record Nobody Watches

Everyone watched the hijacked website. The quieter, more dangerous move was in the mail: an MX record pointed at a server built to receive password resets, MFA codes, and vendor notices.

Read more
How to Get a Hijacked Domain Back
Aug 30, 2026 · 8 min read

How to Get a Hijacked Domain Back

Every incident playbook assumes you still control your domain. Here is the escalation ladder for the day you don't: hosting abuse desks, registrars, registries, and the five-day window most teams miss.

Read more
Most vCISOs Are Glorified Auditors. A Real One Operates a P&L.
Aug 11, 2026 · 6 min read

Most vCISOs Are Glorified Auditors. A Real One Operates a P&L.

An auditor tells you whether a control is present. A real vCISO tells you whether a control is worth it. The difference shows up on a P&L, not a compliance report.

Read more
Inside the FAIR Monte Carlo: How 10,000 Simulations Turn Security Judgment Into a Risk Number
Aug 10, 2026 · 8 min read

Inside the FAIR Monte Carlo: How 10,000 Simulations Turn Security Judgment Into a Risk Number

The Monte Carlo is where FAIR stops being a diagram and becomes a number. Here's how the simulation actually works, what the distributions mean, and how to read what it spits out.

Read more
The Loss Exceedance Curve: The One Chart That Makes Cyber Risk a Board Conversation
Aug 10, 2026 · 7 min read

The Loss Exceedance Curve: The One Chart That Makes Cyber Risk a Board Conversation

Executives glaze over at heatmaps but sit up at one curve. Here's how to build, read, and present the FAIR Loss Exceedance Curve.

Read more
Calibrating Judgment: The Real Hard Part of FAIR Isn't Math, It's Honest Ranges
Aug 10, 2026 · 7 min read

Calibrating Judgment: The Real Hard Part of FAIR Isn't Math, It's Honest Ranges

Every FAIR analysis stands or falls on the ranges people give you. Here's how to elicit honest, well-calibrated estimates instead of confident wrong ones.

Read more
Your Vendors Are One Portfolio: Using FAIR to Quantify Aggregate Third-Party Risk
Aug 10, 2026 · 8 min read

Your Vendors Are One Portfolio: Using FAIR to Quantify Aggregate Third-Party Risk

One vendor's breach is an incident. Ten vendors with correlated exposure is a portfolio risk. Here's how FAIR turns your vendor list into a quantified number.

Read more
The 30-Day Security Road-Mapping Sprint
Aug 8, 2026 · 7 min read

The 30-Day Security Road-Mapping Sprint

Most security roadmaps are assembled backwards: start with the tools you own, then justify them. Here is a four-week sprint that ends with a one-pager the board can read in two minutes.

Read more
Security Shows Value by Making Spend Defensible
Aug 5, 2026 · 7 min read

Security Shows Value by Making Spend Defensible

The fear argument for security budgets stops working after a few cycles. 'Best practice' gets cut because it can't be defended. The winning move is to answer in the CFO's currency.

Read more
NIST AI RMF and CSF 2.0: How They Fit Together
Jul 2, 2026 · 7 min read

NIST AI RMF and CSF 2.0: How They Fit Together

You don't need a second security program for AI. You need to know where the AI RMF plugs into the CSF program you already run.

Read more
Shadow AI: Your Employees Already Deployed It
Jul 1, 2026 · 6 min read

Shadow AI: Your Employees Already Deployed It

You don't have an AI adoption decision to make; adoption already happened without you. The decision is whether it stays invisible.

Read more
The AI Vendor Questions Your Board Should Be Asking
Jun 30, 2026 · 6 min read

The AI Vendor Questions Your Board Should Be Asking

Your vendors added AI to everything you buy. Here are the questions that separate governed AI from liability wearing a product label.

Read more
The FAIR Risk Model: Quantifying Cybersecurity Risk in Financial Terms
Jun 23, 2026 · 7 min read

The FAIR Risk Model: Quantifying Cybersecurity Risk in Financial Terms

Most organizations rate cyber risk as High, Medium, or Low, labels that mean nothing to a CFO or board. The FAIR risk model changes that by quantifying cybersecurity risk in financial terms. Here is how it works and whether it is right for your organization.

Read more
From “We Have Security” to “Prove It”: How a Mid-Market Manufacturer Secured a $600K Contract in 90 Days
Jun 11, 2026 · 5 min read

From “We Have Security” to “Prove It”: How a Mid-Market Manufacturer Secured a $600K Contract in 90 Days

A mid-market manufacturer had security controls but no documentation. A Fortune 500 prospect’s questionnaire and a 90-day vCISO engagement changed everything, including their revenue.

Read more
What Is a vCISO? And Why Growing Companies Are Hiring Them
Feb 13, 2026 · 9 min read

What Is a vCISO? And Why Growing Companies Are Hiring Them

You don't need a $300K executive to build a real security program. You need the right one, on your terms.

Read more
The True Cost of a CISO — And Why a vCISO Makes More Financial Sense
Feb 13, 2026 · 6 min read

The True Cost of a CISO — And Why a vCISO Makes More Financial Sense

A full-time CISO costs $430K+ when you count everything. A vCISO engagement delivers the same strategic leadership, plus a full specialist team, for a fraction of that. Here's the math.

Read more
What a Mature Security Program Actually Looks Like, and Why Most Don’t Get There
Dec 21, 2025 · 3 min read

What a Mature Security Program Actually Looks Like, and Why Most Don’t Get There

Security maturity isn’t about tools or audits; it’s about repeatable, measurable risk reduction.

Read more
Why Vulnerability Scanning Alone Isn’t Enough
Dec 2, 2025 · 3 min read

Why Vulnerability Scanning Alone Isn’t Enough

Tracking vulnerabilities is just the start. Data without a plan and process is wasted energy. An organization must know what's valuable before it can prioritize and act.

Read more
From Chaos to Clarity: Why GRC and Security Frameworks Are Essential
Jul 31, 2025 · 4 min read

From Chaos to Clarity: Why GRC and Security Frameworks Are Essential

Stop chasing shadows; use a structured framework and a GRC platform to focus your cybersecurity program on what actually matters.

Read more
The Future of Risk Management: Quantifying Cyber Risk with the FAIR Model
May 31, 2025 · 4 min read

The Future of Risk Management: Quantifying Cyber Risk with the FAIR Model

Why guessing isn’t a strategy; here’s how FAIR helps you move from fuzzy risk language to boardroom-ready numbers.

Read more
Building a Cybersecurity Roadmap: Where to Start From zero to strategy, what to prioritize and why.
Mar 15, 2025 · 4 min read

Building a Cybersecurity Roadmap: Where to Start From zero to strategy, what to prioritize and why.

Don't start security with a strategy; start with the problems. Turn scattered quick fixes into a cohesive roadmap that balances risk, cost, and what to prioritize.

Read more
What’s Your Risk in Dollars? Why You Need FAIR or Equivalent Models
Oct 1, 2024 · 4 min read

What’s Your Risk in Dollars? Why You Need FAIR or Equivalent Models

Stop guessing. Start quantifying. Because “high risk” doesn’t mean anything until it has a price tag.

Read more
Tabletop Exercises: Are You Ready or Just Hoping?
Feb 28, 2024 · 3 min read

Tabletop Exercises: Are You Ready or Just Hoping?

Cyber incidents aren’t hypothetical. If your plan only lives on paper, it’s not a plan; it’s a liability.

Read more
The Post-Breach Checklist: What to Do in the First 72 Hours
Sep 30, 2023 · 3 min read

The Post-Breach Checklist: What to Do in the First 72 Hours

The breach already happened. Now it’s about limiting damage, restoring trust, and protecting your business from round two.

Read more
Why Every Mid-Sized Business Needs a vCISO
Sep 30, 2023 · 3 min read

Why Every Mid-Sized Business Needs a vCISO

You don’t need a full-time CISO, but you do need someone who thinks like one. Here’s how a vCISO delivers security leadership without the executive overhead.

Read more

Want this kind of thinking doing the work on your team?

No pitch deck or obligation, just a straight conversation about what's keeping you up at night. If that's not us, that's fine.