Back to Home
Writing

An overview of the essays, notes, and field observations I’ve published so far.

Writing on cyber risk, third-party security, supply chain resilience, and the practical realities of making security work outside the slide deck.

TPRM Operating Model September 2026

The Minimum Viable TPRM Program for Mid-Sized Companies

A practical minimum viable third-party risk management program for mid-sized companies that need discipline without enterprise bureaucracy.

Board Governance September 2026

What Boards Actually Need to Know About Third-Party Cyber Risk

A board-level view of third-party cyber risk: critical dependencies, evidence, decisions, escalation, and resilience.

Risk Data September 2026

Why Supplier Risk Is a Data Problem Before It Is a Compliance Problem

Supplier risk programs fail when supplier, service, evidence, ownership, and dependency data are fragmented across tools and spreadsheets.

Third-Party Risk September 2026

The Hidden Cost of Vendor Questionnaires

Why vendor questionnaires consume so much effort and how to redesign them around risk decisions rather than document collection.

NIS2 & Supply Chain August 2026

NIS2 and the Extended Supply Chain: When Your Small Supplier Becomes Your Biggest Risk

How NIS2 expectations cascade through supplier ecosystems and why small suppliers can create large cyber risk.

Third-Party Risk August 2026

From Checkbox to Culture: Building a Third-Party Risk Program That Actually Works

A practical guide to building a third-party risk program that moves beyond questionnaires and creates real supplier risk governance.

Governance August 2026

Cybersecurity Is Now a Board Problem — Personal Liability Under NIS2 and DORA

NIS2 and DORA move cybersecurity governance into the boardroom. Management teams need evidence that they understand cyber risk, supplier dependencies, resilience, and incident response.

AI Supply Chain May 2026

AI Is Now a Supply Chain Risk — and Most Boards Can't Answer Basic Questions About It

AI has quietly become one of the most concentrated, least-governed supply chains in the enterprise — and many organizations still cannot explain which models, providers, agents, and data flows they depend on.

Supply Chain April 2026

The Supply Chain is Now The Biggest Cyber Threat - Here's What The Numbers Say

The supply chain is now the primary way enterprise cyber risk materializes - here's what the numbers, the incidents, and the attackers themselves tell us about it.

Supply Chain April 2026

What Regulators Now Require for Supply Chain Security

Regulators, critical suppliers, and the uncomfortable truth that third-party risk is no longer procurement paperwork but a core security and resilience obligation.

Back to Writing