Category: Field Guides
-

The Vendor Incident Playbook
The vendor incident playbook has become the playbook the security team has been quietly trying to write, the playbook the breach response the vendor will produce has been quietly mocking, the playbook the next third party breach will demand.
-

A Weekend Migration: Replacing One Cloud Service With a Self Hosted Alternative
We migrated a paid analytics service to a self hosted alternative and wrote down the actual time it took, the actual failures, and the actual cost. The Saturday afternoon is real. The Tuesday evening for DNS cutover is also real.
-

Network Segmentation: A Field Guide for 2026
A field guide to the network segmentation in 2026, with what the segmentation actually does, the three layers that matter, what to segment first, and what the operations team needs to keep the segmentation working.
-

A Field Guide to the Vendor Questionnaire
The vendor security questionnaire in 2026 amounts to the 500 question form the enterprise sends to every vendor, with the vendor filling out the form, with the enterprise reviewing the answers, with the enterprise approving the vendor. The form has not changed in 10 years. The vendors have. The threats have. The field guide covers…
-

A Field Guide to the Incident Postmortem
The postmortem runs as the document nobody wants to write and everybody wants to read. Done well, it pays for itself the next time the same incident shows up in a different costume. Done badly, it sits in the compliance folder, the next incident hits the same gap, and the postmortem gets cited in the…
-

A Field Guide to the Threat Model
The threat model sits as the document most security teams have written once, presented to the board, then shelved. Three years later the architecture has changed, the threat actors have changed, the controls have changed, and the threat model still says the same thing. The threat model that does not get updated serves as the…
-

A Field Guide to the SOC 2 Audit
A field guide to the SOC 2 audit in 2026, with what the audit is actually for, why most implementations fail, and the right way to make the model work in a modern security organisation.
-

How to Actually Allocate the Security Budget in 2026
Most security budgets in 2026 get allocated by historical precedent, by what got funded last year and the year before, with adjustments for headcount and inflation. The result runs as a budget that does not match the threat. The 2026 guide to allocating the security budget based on the actual risk, not the historical precedent.
-

A Field Guide to the CISO Board Deck
The CISO board deck in 2026 amounts to the document the CISO presents to the board 4 times per year, with the deck determining whether the CISO gets the budget, the headcount, the mandate. The deck that works is the deck that answers the 4 questions the board asks, with the 12 slides that fit…
-

A Field Guide to the CISO’s First 90 Days
The new CISO has 90 days to figure out what the security program actually does, what it does not, and what the board needs to know. Here is the playbook.