Back to Home
Writing

An overview of the essays, notes, and field observations I’ve published so far.

Writing on cyber risk, third-party security, supply chain resilience, and the practical realities of making security work outside the slide deck.

Supply Chain March 2025

Why Your Vendor Risk Program Misses the Point

Most TPRM programs are built to pass audits, not to manage actual risk. Here’s what changes when you treat vendor risk as an intelligence function instead.

Cyber January 2025

The Quiet Failure Mode: Inherited Trust in Software Supply Chains

Open-source dependencies, build pipelines, and the uncomfortable truth about software you didn’t write but fully own.

Back to Writing