Phishing at Scale: Watch the Playbook, Not Just the Websites
RMM phishing is not new. What makes this discovery notable is its scale: researchers connected hundreds of cases across 46 countries and found that the United States was the campaign’s leading target. At first glance, this looked like a phishing campaign built around fake Canadian tax documents. It was much bigger than that. Researchers at […]
You Don’t Have an IT Problem. You Have a Gap Problem.

A CFO told me last month that IT was handled. They had a guy. He’d been there nine years, knew everything, never complained. So I started asking questions. Who handles the cyber insurance questionnaire? “The broker fills that out.” Who runs the backups? “There’s a company that does that.” Who patches the laptops? “Our guy […]
Your Email Gateway Never Saw It Coming

How an innocent Google search can become tomorrow morning’s ransomware incident. Your security awareness program has spent years teaching employees to be suspicious of phishing emails. That’s still important. But what if there isn’t an email? Imagine one of your engineers needs a new developer tool. They open Google. Type the product name into the […]
The Most Important Person on My Flight Wasn’t on the Airplane

The Handoff I was alone in the cockpit, flying myself through a line of thunderstorms, when I realized I was trusting a complete stranger with something incredibly important. I’d never met them. I probably never will. Yet for the next twenty minutes, I trusted them completely. That realization changed the way I think about trust. […]
The Ransomware That Still Needed a Human

Every few months, cybersecurity gets a new “first.” The first AI worm. The first autonomous attack. The first fully AI-powered ransomware. Headlines move fast. Reality usually takes a little longer. That’s exactly what happened last week. Early reports suggested researchers had documented the first truly agentic ransomware—an AI system capable of compromising a network, moving […]
Why “HaveIBeenPwned” Belongs in Your Security Program
“There’s a website called Have I Been Pwned, maintained by Troy Hunt. You can enter your email address and see if it’s been involved in a breach. If your email has been around for a while, it’s probably been breached. That’s not catastrophic. What matters is whether you reused passwords.” Eric Brown Most security teams […]
Loop Prompting: A Technique for Getting More Out of LLMs

Most practitioners run one prompt, read the output, and move on. For drafting emails or summarizing a document, that is fine. For anything that requires actual analytical depth, it is the wrong approach. A single LLM pass gives you the first reasonable answer, not the best one. Loop prompting is how you fix that. What […]
The Numbers Behind the Curtain

A few weeks ago I flew myself down to Orlando for CoachCon 2026, a two day gathering of entrepreneurs built around a single idea: thinking about thinking. Dan Sullivan hosted. The keynotes came from Angus Fletcher, author of Primal Intelligence, and Alison Levine, team captain of the first American Women’s Everest Expedition. I planned to […]
The Vanishing Buffer

An hour over a Colorado pass, a sentence in a Google ballroom, and the disappearance of the one thing every previous technology revolution quietly handed us: time Pueblo, Colorado. Hours before sunrise. To the west, the mountains we would have to cross were still dark on dark, more shape than range. A slight breeze worked […]
Harmony, Abnormal, Proofpoint: What Matters In Email Security

Most email security products are about as effective as eating spaghetti with a spoon. I have used quite a few. Three stand out. That number may shrink or expand because security tools change and evolve constantly. A firewall product that led the market twenty years ago should not be anywhere near a data center today. […]