[Writing]

Blog

Notes from the field — cybersecurity, defensive engineering, and the craft of keeping systems safe.

·5 min

Zero Trust isn't a product. It's a roadmap

81% of organizations say they're 'implementing Zero Trust' in 2026. Most are buying a product and calling it done. NIST 800-207's actual definition, CISA's Maturity Model, and the phased adoption pattern that works.

#zero-trust#nist#architecture
·4 min

Supply chain attacks: when your vendor is the attacker's toehold

2026 has been a watershed year for third-party compromise. Korean Air via a catering vendor, Trust Wallet's $8.5M Chrome extension, the Marquis SonicWall incident hitting US banks. Patterns and what to demand of vendors.

#supply-chain#third-party#incident-response
·4 min

Passkeys have won. Here's why you should move your logins

Apple, Google, and Microsoft all default. 800M Google accounts, 175M Amazon. A 99.9% lower compromise rate than passwords. What passkeys actually are, and why phishing stops working against them.

#authentication#passkeys#fido2
·4 min

Prompt injection is the LLM-era SQL injection, and harder to fix

OWASP's #1 LLM risk, two years running. 73% of production AI deployments are vulnerable. The 2026 defense stack, and the architectural problem nobody has solved yet.

#ai-security#llm#prompt-injection
·4 min

Most cloud breaches aren't sophisticated, they're misconfigurations

Roughly 99% of cloud security incidents in 2026 trace back to preventable mistakes, not zero-days. The five patterns that show up in audits, and the AWS and Azure tooling that catches each one.

#cloud-security#aws#azure