Insights Beyond the Project
Business lessons, leadership perspectives, and real-life experiences about building better organizations, and becoming better along the way.
Sometimes we begin something believing we are building it, only to discover it is building us.
Incident Response for a Business Without a Security Team
The version that helps fits on two pages. It removes the first hour of confusion, which is where most of the damage happens.
How to Prepare for a Client Security Questionnaire
Forty questions with a deadline, landing on whoever opened the email. What these documents are really asking, and how to answer once rather than every time.
Shared Logins and the Accounts Nobody Owns
Every growing business accumulates them for sensible reasons. How to find shared accounts, fix them in order of consequence and keep the list current.
Backups You Have Actually Tested
Almost every business says it has backups. Far fewer can say when somebody last restored one. Four questions and a quarterly habit that close the gap.
Who Owns Risk When There Is No Security Team
Your IT provider owns their scope, not your risk. What the ownership role actually involves in a business that has no specialists.
Phishing Is a Process Problem, Not a Technology Problem
The messages that cost money are the ones filters cannot judge. The control that works is a documented rule about who can change what, and how you verify.
What a Business Continuity Plan Looks Like for a Small Company
The useful version is a few pages, not a binder. It answers one question: if something we depend on stops working, what do we do in the first day.
Vendor Risk: The Questions to Ask Before You Sign
Your business runs on other people's software. The questions worth asking before you sign, because almost none of them can be asked usefully afterwards.
The Offboarding Checklist Most Businesses Get Wrong
When someone leaves, the laptop comes back but the accounts often stay open. How to build an offboarding list that actually closes the gaps.
Cyber Awareness Training That People Actually Remember
Annual security modules get completed and forgotten. A lighter approach that ties awareness to the work your team actually does.
Cybersecurity Is a Business Risk, Not Just an IT Problem
Cyber risk gets decided in operating meetings, not server rooms. What leadership actually owns, three questions worth asking, and a practical place to start.