How security failures learned to sound reasonable

The most useful phrases in a modern security programme are the ones that cannot be argued with. “The platform gives us coverage.”, “We have visibility.”, “The tool supports MFA.” Each one is calm, professional, and technically defensible. Each one can also be doing something quietly different from what the room hears. …

May 3, 2026 · 4 min
A boardroom with no walls, floating in calm white space. Six figures in identical grey suits sit around a long polished table, each with a smooth mirrored orb where their head should be, nodding politely at a single document hovering above the table

How some ideas outlast their own evidence

Across many mature organisations, the same phrases seem to keep coming back, like “Aligned with best practice”, “The control is in place”, and “We followed the framework”. They survive failure. They survive scandal. They survive the people who used them last time. The question worth asking is perhaps not whether they a…

May 3, 2026 · 5 min

Mapping trust

Organisations invest heavily in procedures, certifications, and standards. Yet whether those investments deliver results depends on something far less tangible: human relationships. As organisations become more distributed and interdependent, seeing and strengthening these connections becomes critical to resilience. Th…

October 30, 2025 · 4 min

The relational firewall

A developer pushes a feature. Security flags a missing TLS configuration. Operations scrambles to patch the database. Alerts multiply while emails ping insistently and no one knows who owns what. Technical pipelines are fine. The human side stutters. Miscommunication, conflicting priorities, and unspoken assumptions sl…

October 21, 2025 · 4 min

Muscle memory for incident stress

Introduction A SOC alert does not knock politely. It arrives like a crowd of people shouting different instructions in a language only half understood. One alert maybe says “ransomware detected,” another could flag “unusual login,” and the logs you trust most are blank. Analysts glance at dashboards, shrug, and whisper…

October 21, 2025 · 4 min

The audit as x-ray

There is a certain bleak poetry in a security audit. The word audit evokes clipboards, compliance spreadsheets, and the faint smell of burnt patience. But beneath the bureaucracy lies something far more interesting: an act of seeing. A real audit, not compliance theatre, but the kind that leaves everyone quietly re-eva…

October 20, 2025 · 6 min
Satir Change Model

How to survive your first incident response

If you have ever tried to set up a Security Incident Response Team (SIRT) function in a small organisation, you will know that it is not about security, incidents, or even teams. It is about humans behaving badly under stress. Enter the Satir Change Model, a tool from family therapy that has no right working in cyberse…

October 16, 2025 · 6 min