Ideas and field notes

Blog

Practical writing about cybersecurity, compliance, and sustainable security operations.

Follow the data

Documenting where sensitive data comes from, what it passes through, and where it rests determines both the scope of an obligation and the threats that actually apply.

The risk assessment that should come first

A risk assessment tells the organization which risks it actually has. Nearly every other governance activity, the policy review included, is guesswork without it.