Insights

Notes from the practice.

Long-form writing on the questions buyers ask us before they hire us — Zero Trust without a CISO, what an AI security audit actually covers, executive identity hardening, and when to build custom software instead of stitching SaaS together. Cornerstones first; cadence after.

Latest

Cornerstone #1

Security · Zero Trust 2026-05-25 ~14 min read

A Zero Trust rollout plan for organizations with no CISO.

A practitioner walk-through of what a real Zero Trust rollout looks like for a 25–250 person organization without a dedicated security leader. What to ship in the first 30 days, the seven control moves that compound, the mistakes that delay it — and how to know it actually worked.

Read the cornerstone
You’ll come away with
  • A 90-day rollout shape, week by week
  • The 7 control moves to ship first
  • 4 mistakes that quietly add months
  • How to measure that it worked
Coming next

The next three cornerstones.

Drafting order, not necessarily publishing order. Each is written for the buyer who is researching the decision — not the buyer who is shopping a vendor.

Coming soon

What an AI security audit actually covers (and what it doesn’t)

Prompt-injection scope, jailbreak resistance, agent-to-tool privilege boundaries, training-data exposure, supply-chain review, and the line between “AI red-team” and “pen test.”

Coming soon

Executive identity hardening: a 30-day program for principals

Identity audit, data-broker removal, account hardening, household OPSEC, and the monitoring discipline that actually catches the next intrusion attempt.

Coming soon

Custom POS vs. Square vs. Shopify POS: when to build your own

The honest version of the build-vs-buy decision for retail and hospitality operators — with the per-transaction math that flips it.

Not the writing you came for?

If there’s a question you’d want us to write about, send it. Buyer questions drive the publishing queue.