How security failures learned to sound reasonable

The most useful phrases in a modern security programme are the ones that cannot be argued with. “The platform gives us coverage.”, “We have visibility.”, “The tool supports MFA.” Each one is calm, professional, and technically defensible. Each one can also be doing something quietly different from what the room hears. …

May 3, 2026 · 4 min
A boardroom with no walls, floating in calm white space. Six figures in identical grey suits sit around a long polished table, each with a smooth mirrored orb where their head should be, nodding politely at a single document hovering above the table

How some ideas outlast their own evidence

Across many mature organisations, the same phrases seem to keep coming back, like “Aligned with best practice”, “The control is in place”, and “We followed the framework”. They survive failure. They survive scandal. They survive the people who used them last time. The question worth asking is perhaps not whether they a…

May 3, 2026 · 5 min

Is your threat model already behind?

Most organisations think they have a threat model. What they usually have is a historical artefact: a snapshot of how the environment looked on the day several people sat in a room with diagrams, coffee, and varying levels of optimism. The session happens. Assets are mapped. Threats are identified. Risks are scored. A …

May 2, 2026 · 5 min

Architecture reviews that approve instead of challenge

Architecture reviews exist to catch problems before they become expensive. In practice, most reviews catch a different set of problems from the ones they were designed to find, and miss a different set from the ones that will eventually cause trouble. This is not because the reviewers lack competence. It is because mos…

April 2, 2026 · 5 min
A massive, exhausted turtle trudging through a surreal European city, carrying a towering heap of audit checklists, sticky notes, and cybersecurity manuals on its shell. Tiny overworked auditors run around frantically.

NIS2 compliance: The Kafkaesque burden on Europe’s companies

Europe has suddenly declared that hundreds of thousands of companies must meet demanding NIS2 cybersecurity standards, yet the pool of qualified auditors is tiny in comparison. Critics note there’s a shortage of qualified auditors to perform the required assessments, the compensation for auditors is too low, and the au…

November 26, 2025 · 4 min