Field NotesWritten from the seat, not the sideline Advisory & software · Led by a practicing CISO and CIO
Field NotesThe Pylon GroupWritten from the seat, not the sideline

What we're seeing
in the field.

Operator perspective on cybersecurity, M&A diligence, AI governance, and the decisions our clients actually face. Short, opinionated, and written by the people doing the work.

Eight notesPublished to date
MonthlyCadence, roughly
Dan CostantinoFounder · practicing CISO
No. 08

Risk doesn't die inside the tool. It dies at the handoff.

Security work fails in the handoffs between programs, not inside the tools. Three seams that leak, why nobody owns them, what the re-entry tax costs, and why integration is not the same as one record.

Read note
August 17, 20266 min readSecurity programs
No. 07

A vCISO does not have a security problem. They have a memory problem.

The bottleneck in a fractional practice is not security expertise. That part is instant. It is state. Running a dozen clients means re-deriving each program from scattered spreadsheets every time you switch. Where the memory leaks, what it costs, and what a practice that remembers looks like.

Read note
July 1, 20266 min readvCISO practice
No. 06

Document the program, or run it.

Twenty years of opening GRC tools to do something a GRC tool was not built to do. The category serves the audit. The operator runs the program. The tools you choose tell you which one you are really trying to do.

Read note
June 1, 20266 min readSecurity programs
No. 05

The hidden tax of TPRM done badly.

Four CISO and CIO seats, four board meetings that opened with a TPRM completion percentage. The percentage was always high. The risk was never measured. Three taxes the audit committee never sees, and the fourth one that has a Tuesday.

Read note
May 26, 20265 min readThird-party risk
No. 04

The 12-month security program is a lie.

Security advisor and fractional CISO engagements are sized to 12 months because that is how procurement buys. Programs mature on a 24 to 36 month curve. The gap is where security work goes to die.

Read note
May 4, 20266 min readSecurity leadership
No. 03

The AI vendor risk your TPRM program can't see.

SIG and CAIQ were built for a SaaS world where vendor behavior was deterministic. AI vendors aren't. Here's the gap, the four questions to add now, and why even those won't keep up.

Read note
May 2, 20266 min readThird-party risk
No. 02

Pre-LOI is the new M&A cybersecurity diligence.

The traditional M&A cybersecurity diligence model assumes you have time to walk. You don't. Why pre-LOI screening is becoming table stakes for serious acquirers in 2026.

Read note
April 19, 20264 min readM&A diligence
No. 01

The four cybersecurity questions your board should be asking in 2026.

Most boards still ask cyber questions designed for a 2015 risk landscape. Here are the four that actually matter now: SEC disclosure readiness, third-party concentration risk, AI ownership, and CISO key-person risk.

Read note
April 19, 20265 min readBoard governance
NextTalk to an operator

If a note described your week,
we should talk.

Every note here came out of a real engagement. If one of them reads like your program, that is the conversation to start.

See how we work