Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
SSO and SaaS sprawl: why identity architecture matters before the breach
How the accumulation of SaaS tools creates an identity problem that security tools alone cannot fix - and what to do about it before something goes wrong.
Ransomware in 2022: operational continuity matters more than antivirus
What the LockBit wave says about how companies should think about protection - not as a technical task but as an operational one.
The Okta breach: what it means when an identity provider is compromised
In March 2022 Okta confirmed a breach. A look at the lesson a director should take from this, not just a security specialist.
Log4Shell: the management lessons from the incident
Breaking down the Log4Shell vulnerability as a management lesson - about hidden dependencies, response speed, and invisible risk.
Log4Shell: if you do not know your dependencies, you do not know your attack surface
The Log4Shell vulnerability showed that most companies have no idea which libraries are running inside their systems.
Zero trust: what it actually means and when it is worth the investment
Zero trust has become one of the biggest buzzwords in security. I break down what is behind it and who it is actually relevant for.
Colonial Pipeline: when a cyberattack stops physical infrastructure
The May 2021 Colonial Pipeline attack showed that the boundary between IT security and operational security has disappeared.
Colonial Pipeline: when cybersecurity becomes physical resilience
A breakdown of the Colonial Pipeline attack for managers: why the incident changes the security conversation for companies with physical infrastructure.
Hafnium and Exchange: the patch that waited too long
The March 2021 Microsoft Exchange mass exploitation showed that patch management is not a technical task - it is an organisational one.
SolarWinds: a supply chain attack explained for managers
What happened with SolarWinds, and why this incident changes the security conversation for companies that do not think of themselves as targets.
SolarWinds: supply chain risk now belongs in the risk model
The SolarWinds attack in December 2020 showed that trusted software can be an attack vector. What this means for how companies must think about their software suppliers.
Ransomware hits hospitals in a pandemic: a lesson for every security leader
In autumn 2020, several European hospitals were hit by ransomware attacks during the second wave of COVID-19. What this pattern tells us about operational risk.