Insights

Practical writing on security governance and risk.

Notes from the operational side of security work: how findings actually get fixed, and how risk stays visible and owned instead of drifting.

Vulnerability metrics leaders can act on

Raw vulnerability counts tell a leader nothing they can act on. The handful of measures that do, why SLA compliance, aging, exceptions, coverage, and recurrence work as a set, and why a dashboard makes the case for the work without doing the work itself.

Read the full post