Insights
Useful takes on owning security
The thinking behind the work we do for boards, CFOs, and regulated institutions, in plain words with no fear-mongering and no fluff. If something here rings true, we're happy to talk it through, and no pitch is required.
Blog
Latest insights
No fear-mongering and no fluff. If something here rings true, we're happy to talk it through, and no pitch is required.
The Breach That Never Touched the Network
A credit union's EDR was clean. Its identity logs were clean. And members could still have been phished at the real online-banking URL. The attack lived somewhere else entirely.
Read moreYour Transfer Lock Doesn't Do What You Think It Does
clientTransferProhibited looks reassuring in a WHOIS record. It didn't stop an attacker from redirecting a credit union's domain, and then it didn't stop them from transferring it to another country.
Read moreTwo DNS Records That Would Have Stopped a Credit Union Hijack
Within hours of taking over a credit union's DNS, an attacker held valid certificates for the whole domain, including a wildcard. No CA did anything wrong. Two missing records made it legal.
Read moreThe MX Record Nobody Watches
Everyone watched the hijacked website. The quieter, more dangerous move was in the mail: an MX record pointed at a server built to receive password resets, MFA codes, and vendor notices.
Read moreHow to Get a Hijacked Domain Back
Every incident playbook assumes you still control your domain. Here is the escalation ladder for the day you don't: hosting abuse desks, registrars, registries, and the five-day window most teams miss.
Read moreMost vCISOs Are Glorified Auditors. A Real One Operates a P&L.
An auditor tells you whether a control is present. A real vCISO tells you whether a control is worth it. The difference shows up on a P&L, not a compliance report.
Read moreInside the FAIR Monte Carlo: How 10,000 Simulations Turn Security Judgment Into a Risk Number
The Monte Carlo is where FAIR stops being a diagram and becomes a number. Here's how the simulation actually works, what the distributions mean, and how to read what it spits out.
Read moreThe Loss Exceedance Curve: The One Chart That Makes Cyber Risk a Board Conversation
Executives glaze over at heatmaps but sit up at one curve. Here's how to build, read, and present the FAIR Loss Exceedance Curve.
Read moreCalibrating Judgment: The Real Hard Part of FAIR Isn't Math, It's Honest Ranges
Every FAIR analysis stands or falls on the ranges people give you. Here's how to elicit honest, well-calibrated estimates instead of confident wrong ones.
Read moreYour Vendors Are One Portfolio: Using FAIR to Quantify Aggregate Third-Party Risk
One vendor's breach is an incident. Ten vendors with correlated exposure is a portfolio risk. Here's how FAIR turns your vendor list into a quantified number.
Read moreThe 30-Day Security Road-Mapping Sprint
Most security roadmaps are assembled backwards: start with the tools you own, then justify them. Here is a four-week sprint that ends with a one-pager the board can read in two minutes.
Read moreSecurity Shows Value by Making Spend Defensible
The fear argument for security budgets stops working after a few cycles. 'Best practice' gets cut because it can't be defended. The winning move is to answer in the CFO's currency.
Read moreNIST AI RMF and CSF 2.0: How They Fit Together
You don't need a second security program for AI. You need to know where the AI RMF plugs into the CSF program you already run.
Read moreShadow AI: Your Employees Already Deployed It
You don't have an AI adoption decision to make; adoption already happened without you. The decision is whether it stays invisible.
Read moreThe AI Vendor Questions Your Board Should Be Asking
Your vendors added AI to everything you buy. Here are the questions that separate governed AI from liability wearing a product label.
Read moreThe FAIR Risk Model: Quantifying Cybersecurity Risk in Financial Terms
Most organizations rate cyber risk as High, Medium, or Low, labels that mean nothing to a CFO or board. The FAIR risk model changes that by quantifying cybersecurity risk in financial terms. Here is how it works and whether it is right for your organization.
Read moreFrom “We Have Security” to “Prove It”: How a Mid-Market Manufacturer Secured a $600K Contract in 90 Days
A mid-market manufacturer had security controls but no documentation. A Fortune 500 prospect’s questionnaire and a 90-day vCISO engagement changed everything, including their revenue.
Read moreWhat Is a vCISO? And Why Growing Companies Are Hiring Them
You don't need a $300K executive to build a real security program. You need the right one, on your terms.
Read moreThe True Cost of a CISO — And Why a vCISO Makes More Financial Sense
A full-time CISO costs $430K+ when you count everything. A vCISO engagement delivers the same strategic leadership, plus a full specialist team, for a fraction of that. Here's the math.
Read moreWhat a Mature Security Program Actually Looks Like, and Why Most Don’t Get There
Security maturity isn’t about tools or audits; it’s about repeatable, measurable risk reduction.
Read moreWhy Vulnerability Scanning Alone Isn’t Enough
Tracking vulnerabilities is just the start. Data without a plan and process is wasted energy. An organization must know what's valuable before it can prioritize and act.
Read moreFrom Chaos to Clarity: Why GRC and Security Frameworks Are Essential
Stop chasing shadows; use a structured framework and a GRC platform to focus your cybersecurity program on what actually matters.
Read moreThe Future of Risk Management: Quantifying Cyber Risk with the FAIR Model
Why guessing isn’t a strategy; here’s how FAIR helps you move from fuzzy risk language to boardroom-ready numbers.
Read moreBuilding a Cybersecurity Roadmap: Where to Start From zero to strategy, what to prioritize and why.
Don't start security with a strategy; start with the problems. Turn scattered quick fixes into a cohesive roadmap that balances risk, cost, and what to prioritize.
Read moreWhat’s Your Risk in Dollars? Why You Need FAIR or Equivalent Models
Stop guessing. Start quantifying. Because “high risk” doesn’t mean anything until it has a price tag.
Read moreTabletop Exercises: Are You Ready or Just Hoping?
Cyber incidents aren’t hypothetical. If your plan only lives on paper, it’s not a plan; it’s a liability.
Read moreThe Post-Breach Checklist: What to Do in the First 72 Hours
The breach already happened. Now it’s about limiting damage, restoring trust, and protecting your business from round two.
Read moreWhy Every Mid-Sized Business Needs a vCISO
You don’t need a full-time CISO, but you do need someone who thinks like one. Here’s how a vCISO delivers security leadership without the executive overhead.
Read moreWant this kind of thinking doing the work on your team?
No pitch deck or obligation, just a straight conversation about what's keeping you up at night. If that's not us, that's fine.