Designing an email protection capability against phishing, fraud, and critical-process compromise

Structuring an email protection capability focused on detecting phishing, fraud, impersonation, and other interactions capable of compromising critical business processes.

August 7, 2026 · 7 min read

From vulnerabilities to priorities: designing a context-based RBVM approach

An RBVM approach connecting data quality, asset criticality, exposure, severity, threat, controls, remediation constraints, ownership, and residual risk.

August 7, 2026 · 8 min read

From tools to capabilities: designing a cybersecurity decision model

An approach for moving away from isolated product-centered cybersecurity decisions and toward capabilities the organization needs to execute.

August 7, 2026 · 8 min read

More security tools do not mean more security capability

Technology can enable a capability, but the capability exists only when people, processes, decisions, controls, and evidence work together.

August 7, 2026 · 5 min read

A technically correct architecture can be a bad business decision

Architecture quality depends on more than technology: operability, cost, skills, dependency, recovery, governance, and the real ability to sustain it also matter.

August 7, 2026 · 5 min read

Having 10,000 vulnerabilities does not mean having 10,000 priorities

Vulnerability management creates value when it turns thousands of findings into a manageable number of decisions that can be executed, validated, and explained.

August 7, 2026 · 5 min read

What information is missing when a vulnerability only has a CVSS score

A CVSS score can tell us a great deal about a vulnerability and very little about what an organization should do first.

August 7, 2026 · 5 min read

Email is not just a channel: it is an attack surface against critical business processes

A convincing email can alter a decision, capture credentials, or redirect a critical process without looking like a traditional attack.

August 7, 2026 · 5 min read

Prioritizing risk is not sorting vulnerabilities

Good prioritization connects exposure, impact, context, and execution capacity; it is not just a technical ranking exercise.

August 7, 2026 · 4 min read

Resilience starts before the incident

Responding well matters, but resilience depends on earlier decisions about capabilities, dependencies, recovery, and learning.

August 7, 2026 · 4 min read