Articles
Short, opinionated, and written for organizations where one team — or one person — carries IT, security, and compliance at once.
Foundations: the 80/20 series
You're the security team now. Start here.
The Pareto principle applied to SMB security: a vital few controls eliminate most breach risk — and the breach data proves it.
Part 2 · The playbooksThe playbooks: deploying the five controls
Each control as a step-by-step playbook — owner, effort, pitfalls, an explicit "done means," and the evidence that proves it.
Part 3 · The planThe first 90 days: an execution plan for teams
Week-by-week phases, ownership, the weekly 25 minutes, three leadership decisions — and an interactive checklist that tracks it all.
Part 4 · The proofProving it works: five numbers and a quarterly review
Coverage metrics, not activity metrics: the five numbers that detect erosion, and the one-hour review that keeps them green.
Thinking Tools
Compliance
Leadership & Operations
Talking to leadership about risk: bring decisions, not dashboards
The three-sentence rule, calendar-language likelihood, and why documented risk acceptance is your best friend.
Operations & LeadershipWearing all the hats without dropping them
The three-bucket model, the calendar as a compliance control, what to outsource — and how to say no with a number.
Money & Microsoft 365
The license audit: the security budget you already have
Ghost licenses, duplicate tools, tier mismatches, and shelfware. The audit that funds your next security project.
Microsoft 365The M365 baseline: eight moves that actually matter
Defaults optimize for adoption, not protection. The ordered list that closes the gaps attackers actually use.