Day One The Pylon Dispatch Vol. I · No. 01 · 05.18.2026
Services Platform Scout Anvil Command All software → Field Notes Company About Dispatch Process
Field Notes

What we're seeing in the field.

Operator perspective on cybersecurity, M&A diligence, AI governance, and the decisions our clients face. Short, opinionated, written by the people doing the work.

No. 05 · July 1, 2026 · 6 min read

A vCISO does not have a security problem. They have a memory problem.

The bottleneck in a fractional practice is not security expertise. That part is instant. It is state. Running a dozen clients means re-deriving each program from scattered spreadsheets every time you switch. Where the memory leaks, what it costs, and what a practice that remembers looks like.

Read note
No. 04 · June 1, 2026 · 6 min read

Document the program, or run it.

Twenty years of opening GRC tools to do something a GRC tool was not built to do. The category serves the audit. The operator runs the program. The tools you choose tell you which one you are really trying to do.

Read note
No. 03 · May 26, 2026 · 5 min read

The hidden tax of TPRM done badly.

Four CISO and CIO seats, four board meetings that opened with a TPRM completion percentage. The percentage was always high. The risk was never measured. Three taxes the audit committee never sees, and the fourth one that has a Tuesday.

Read note
No. 02 · May 4, 2026 · 6 min read

The 12-month security program is a lie.

Security advisor and fractional CISO engagements are sized to 12 months because that is how procurement buys. Programs mature on a 24 to 36 month curve. The gap is where security work goes to die.

Read note
No. 01 · April 19, 2026 · 5 min read

The four cybersecurity questions your board should be asking in 2026.

Most boards still ask cyber questions designed for a 2015 risk landscape. Here are the four that actually matter now: SEC disclosure readiness, third-party concentration risk, AI ownership, and CISO key-person risk.

Read note