Blog
Notes from the field — cybersecurity, defensive engineering, and the craft of keeping systems safe.
Zero Trust isn't a product. It's a roadmap
81% of organizations say they're 'implementing Zero Trust' in 2026. Most are buying a product and calling it done. NIST 800-207's actual definition, CISA's Maturity Model, and the phased adoption pattern that works.
Supply chain attacks: when your vendor is the attacker's toehold
2026 has been a watershed year for third-party compromise. Korean Air via a catering vendor, Trust Wallet's $8.5M Chrome extension, the Marquis SonicWall incident hitting US banks. Patterns and what to demand of vendors.
Passkeys have won. Here's why you should move your logins
Apple, Google, and Microsoft all default. 800M Google accounts, 175M Amazon. A 99.9% lower compromise rate than passwords. What passkeys actually are, and why phishing stops working against them.
Prompt injection is the LLM-era SQL injection, and harder to fix
OWASP's #1 LLM risk, two years running. 73% of production AI deployments are vulnerable. The 2026 defense stack, and the architectural problem nobody has solved yet.
Most cloud breaches aren't sophisticated, they're misconfigurations
Roughly 99% of cloud security incidents in 2026 trace back to preventable mistakes, not zero-days. The five patterns that show up in audits, and the AWS and Azure tooling that catches each one.