Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
Zero trust architecture: what it means in practice for a growing company
A clear explanation of zero trust as an operational security model - what changes, what stays the same, and how to approach adoption without a rewrite of everything.
NIS2: the directive starts living in practice, not just in PDFs
What NIS2 enforcement means for companies operating in the European market: who is covered, what is required, and where to start.
CrowdStrike: how one content update tears the global operational fabric
A breakdown of the July 2024 incident and what it reveals about business operational resilience.
Shadow AI tools: managing risk without banning everything
How companies can manage the risks from employees' unsanctioned use of AI tools - without making a blanket ban the only answer.
The xz backdoor: open source supply chain security is a topic for architects, not lawyers
A breakdown of the xz utils incident and why attacks on the open source supply chain change architectural requirements - not legal ones.
NIST Cybersecurity Framework 2.0: the framework gets broader and closer to business
What changed in the new version of NIST CSF and why the update matters not only to security teams but to executives who are responsible for risk management.
The Okta breach: what happens when your identity provider is compromised
A look at the Okta incident in October 2023 and practical conclusions for companies that rely on centralised authentication.
Zero trust networking: a practical starting point for non-security teams
Zero trust is talked about constantly but implemented rarely. Here is a grounded explanation of what it means in practice and where a company with limited security resources should actually start.
AI API keys are becoming the new security perimeter
Why connecting to language models through an API creates a new class of risks and what to do about it now, before the keys have spread across the entire infrastructure.
Software supply chain attacks: when the vulnerability arrives with an update
An attack delivered through a trusted software vendor is one of the hardest threat vectors to defend against. I look at how it works and what businesses can actually do.
LastPass and the lesson in secrets management: what happened and what it means
The 2022 LastPass breach became one of the most discussed incidents in credential management. I look at what happened and what conclusions matter for business.
Identity after the perimeter: what zero trust is and why founders need to understand it
The corporate perimeter has ceased to exist. A breakdown of what this means for security and what practical steps follow from this logic.