About this site
I've spent a long time in technology, and the path matters more than any title: I started writing software, moved into running projects, and ended up responsible for security, compliance, and IT operations — usually all three at once, usually somewhere the security "team" was a column on my own calendar. Along the way that work has included quality and process frameworks (the ISO 9001 and CMMI side of the house) as much as the security ones, which turns out to shape how I see both.
I want to be straightforward about what this site is. It's not the work of someone who has seen everything and got it all right. It's the working notes of someone still doing the job — including the parts I'm still not good at, which I try to say out loud when they're relevant. Plenty of what's here was learned by getting it wrong first.
How the thinking works
A few convictions sit underneath everything on this site, and you'll see them repeat:
A bad system beats a good person, every time. When something keeps failing, I've learned to stop asking "who slipped?" and start asking "what made slipping the path of least resistance?" Most security failures at small organizations are process failures wearing a person costume.
You can't fix what you can't see. Invisible work, invisible spend, invisible risk — the dangerous things are dangerous mostly because nothing in the weekly routine ever surfaces them. Half of what I recommend, from risk registers to license audits to evidence-as-byproduct, is really just machinery for making invisible things visible before they choose their own moment.
Everything has a constraint, and effort spent elsewhere mostly feels like progress. Budget, attention, assessor queues, leadership patience — finding what actually limits the system, and being honest that it's rarely the thing you'd prefer to work on, decides whether effort compounds or evaporates.
Decisions belong to people, in writing, with dates. Risk acceptance, scope choices, deferrals — the discipline isn't bureaucracy. People defend decisions they helped make, and organizations only remember what someone wrote down.
What you'll find here
The notes I'd want handed to me on day one of a small-organization security role: how to navigate the framework maze without buying it dinner, how to talk to leadership so decisions actually get made, how to fund security out of waste before asking for budget, and templates that have survived contact with real audits and real operations. Written to the point — if a sentence doesn't earn its place, it goes.
Where tooling specifics are unavoidable, I write for Windows and Microsoft 365, because that's what most small and mid-sized organizations actually run. Everything else stays tools-agnostic on purpose: principles outlive products. And because demands differ by situation, there are dedicated pages for startups, US government work, India, and ISO and management systems.
What this site will never be
There's nothing for sale here. No email walls in front of the templates, no affiliate links, no "book a call." This site is a personal project, kept on my own time. If something here saves you a bad afternoon, that's the transaction, completed.
A note on judgment
Everything here is strictly personal: this site is a personal project, written on my own time, and nothing on it represents the views, practices, or environment of any employer, client, or organization I work with — past or present. Beyond that, everything here is practitioner opinion — tested in the environments I've worked in, which are not yours. Frameworks update, portals get rearranged, regulations move. Take the reasoning, verify the specifics, and adapt to your own context; that habit will serve you better than any checklist on this site, including mine.
Get in touch: corrections, disagreements, and war stories are all welcome at hello@allaboutrisk.info. The disagreements are usually the most useful.