Insights
Writing from the field.
Practitioner-researcher essays on cybersecurity at scale, quantitative risk, AI in operations, and the structural problems no one wants to name.
More writing
Risk Quantification
The Last Mile of Risk Quantification
Running a Monte Carlo simulation is the easy part. Getting executives to act on the results is where most risk programs quietly fail.
Public-Sector CISO
The Tool Isn't the Problem. The Workflow Is.
Facial recognition wrongful arrests aren't a technology failure. They're a process failure. Here's what government needs to fix.
Risk Quantification
You Can't Govern What You Can't See: AI Risk in the Enterprise
AI risk isn't a technology problem. It's a visibility problem. Here's what that means for every CISO managing enterprise AI at scale.
Risk Quantification
The Inventory Trap: Why Knowing What You Have Is Not the Same as Managing Risk
Most security programs stop at asset discovery. Here's why visibility without quantification is just expensive awareness.
AI in Operations
The Shared Antenna Problem
When federal funding cuts killed MS-ISAC support, state CISOs lost more than a budget line. They lost the antenna that let them hear what was coming.
Risk Quantification
The Agent Has the Keys. Do You Know Which Doors It Can Open?
AI agents aren't scary because they're smart. They're scary because nobody quantified what they can reach. Here's how to fix that.
Risk Quantification
The Compliance Costume Is Coming Off
Cyber risk is finally being treated as a business problem. Here's why that shift is harder than it looks and what it actually demands from leaders.
Public-Sector CISO
The Security Theater You Built and Can't Stop Performing
Most security programs don't fail during attacks. They fail during audits they pass. Here's why looking secure is more dangerous than being vulnerable.
AI in Operations
Your Organization Just Got a Code Cannon. Who Controls the Trigger?
AI lets every employee generate production-grade risk at machine speed. Here's what that means for enterprise security leaders.
AI in Operations
The Accountability Vacuum at the Center of AI-Driven Security
AI agents are making security decisions at machine speed. Nobody owns those decisions. That gap is the real crisis in cloud security right now.
Public-Sector CISO
The Day Your Team Stops Waiting for You
A State CISO on why the hardest leadership skill isn't decision-making. It's making yourself unnecessary in the right moments.
Public-Sector CISO
The Safe Choice Is the Riskiest Choice You Can Make
Enterprise vendor selection feels like risk management. It isn't. Here's what most CISOs get wrong before the contract is even signed.

Public-Sector CISO
The Audit Report Is a Photograph of a Fire
Point-in-time compliance audits tell you where the fire was, not where it is. Here's why that distinction costs organizations everything.

AI in Operations
Page count is not a design constraint
AI assistance imports invisible defaults and optimizes against them as if they were user requirements. The fix is to surface the default before acting on it.
AI in Operations
Parallel Agents Are a Voice Problem, Not a Research Pattern
Five agents, fifty five posts, three minutes. The job worked because the prompt encoded the author's taste, not because parallelism is magic.

AI in Operations
When the ledger becomes the inbox
If your review-counter accumulates instead of clearing, it has stopped being a gate and started being a guilt counter. Redesign it.
Method
When the Watchdog Doesn't Bark
Silence in a monitoring system is indistinguishable from health, and the system is structured so that you only test the alert path during the exact event you are trying to detect.
Public-Sector CISO
AI Governance Is a Security Problem, Not a Policy Exercise
Most states treat AI governance as a compliance checkbox. Here's why that framing guarantees failure - and what the security-first approach looks like.
AI in Operations
Prepare to Lead, Not Present
A status report is for someone reading alone. A chair is leading a room. The two artifacts have different jobs and should have different shapes.
Method
When Iterative Review Saturates, Expand Scope Rather Than Terminate
Convergence within a review scope does not mean ready. It means the scope is exhausted. The next move is to expand scope, not to declare done.
AI in Operations
Four Hallucinations in One Session: Grep-Verify Is the Cheap Counter
When parallel sub-agents touch many similar files, plausible-sounding but wrong quotes are the dominant failure mode. The cheapest counter is a discipline rule, not a model upgrade.
Risk Quantification
Measuring the Multiplier: What an AI-Augmented Strategic Plan Actually Costs
Three to seven cents on the consulting dollar is the headline. The real story is what makes the multiplier work, and what makes it collapse.
Public-Sector CISO
Risk Measurement Is Not Risk Management
Most cyber risk programs are built to produce reports, not decisions. Here's why that distinction matters more now than ever.
AI in Operations
When Benchmarks Describe Rather Than Aspire
Survey instruments that sequence descriptive and normative questions produce answers that echo current state, not strategic intent. Here is what to do about it.
Risk Quantification
Comfort Equals Depth Deficit
I declared a high-stakes briefing 'done' four times. Each push for another pass found a new load-bearing error. The fix isn't more passes; it's different lenses.
Public-Sector CISO
The Confidence Trap: Why AI Sounds Right Even When It's Wrong
AI confidence isn't a feature. It's a design choice that security leaders need to understand before they trust the output.
Public-Sector CISO
The Transformation Trap: Why 'Chief' Titles Without Mandate Are Theater
State governments keep creating transformation roles that sound powerful. Here is why most of them fail before the first budget cycle ends.
AI in Operations
Automated Systems Encode Their Author's Default Posture
When you automate a report, you don't automate intelligence. You automate the author's judgment, frozen at the moment the template was written.
AI in Operations
Map Before You Adopt
Most people respond to a 'new pattern' the wrong way twice: they dismiss it, or they adopt the whole thing. There is a third move that beats both.
Public-Sector CISO
Pilots That Only Prove What You Already Believe
Government AI pilots are designed to succeed, not to learn. Here's why that's the wrong architecture and what a real test looks like.