What we're seeing
in the field.
Operator perspective on cybersecurity, M&A diligence, AI governance, and the decisions our clients actually face. Short, opinionated, and written by the people doing the work.
Risk doesn't die inside the tool. It dies at the handoff.
Security work fails in the handoffs between programs, not inside the tools. Three seams that leak, why nobody owns them, what the re-entry tax costs, and why integration is not the same as one record.
Read note →A vCISO does not have a security problem. They have a memory problem.
The bottleneck in a fractional practice is not security expertise. That part is instant. It is state. Running a dozen clients means re-deriving each program from scattered spreadsheets every time you switch. Where the memory leaks, what it costs, and what a practice that remembers looks like.
Read note →Document the program, or run it.
Twenty years of opening GRC tools to do something a GRC tool was not built to do. The category serves the audit. The operator runs the program. The tools you choose tell you which one you are really trying to do.
Read note →The hidden tax of TPRM done badly.
Four CISO and CIO seats, four board meetings that opened with a TPRM completion percentage. The percentage was always high. The risk was never measured. Three taxes the audit committee never sees, and the fourth one that has a Tuesday.
Read note →The 12-month security program is a lie.
Security advisor and fractional CISO engagements are sized to 12 months because that is how procurement buys. Programs mature on a 24 to 36 month curve. The gap is where security work goes to die.
Read note →The AI vendor risk your TPRM program can't see.
SIG and CAIQ were built for a SaaS world where vendor behavior was deterministic. AI vendors aren't. Here's the gap, the four questions to add now, and why even those won't keep up.
Read note →Pre-LOI is the new M&A cybersecurity diligence.
The traditional M&A cybersecurity diligence model assumes you have time to walk. You don't. Why pre-LOI screening is becoming table stakes for serious acquirers in 2026.
Read note →The four cybersecurity questions your board should be asking in 2026.
Most boards still ask cyber questions designed for a 2015 risk landscape. Here are the four that actually matter now: SEC disclosure readiness, third-party concentration risk, AI ownership, and CISO key-person risk.
Read note →If a note described your week,
we should talk.
Every note here came out of a real engagement. If one of them reads like your program, that is the conversation to start.