Identity Security
A practitioner's perspective on identity as the modern control plane of cyber resilience.
Identity security, AI trust, cyber resilience, CISO development, incident response, cloud risk, third-party governance, and professional leadership.
A practitioner's perspective on identity as the modern control plane of cyber resilience.
How AI can outpace cyber threats by building adaptive, self-healing security architectures.
Frameworks for governing AI systems so trust is built deliberately, not assumed.
A blueprint for modernizing identity and access management at enterprise scale.
Practical governance for third-party risk, identity, and shared accountability.
Security best practices for the hybrid workforce, written during the pandemic shift.
How to translate cyber program investment into language boards and CFOs actually buy.
Why the modern CISO's most important skill is teaching — to boards, peers, and teams.
A practical framework for the measurements that matter in enterprise security programs.
A step-by-step plan to take ownership of your career as a cybersecurity professional.
What hiring committees actually look for, and how to prepare for the CISO interview cycle.
Planning the next phase of your career — preparing for, entering, and exiting CISO roles.
Why data science is foundational for an advanced enterprise cyber program.
Principles for mentoring cybersecurity professionals — adapted from a lifetime of practice.
Reducing open source risk through software bills of materials and supply chain hygiene.
An older piece — still painfully relevant — on the long arc away from passwords.
How to drive consensus on cyber risk through a disciplined TVA process.
A working perspective on building, exercising, and improving incident response programs.
A framework for handling incidents that span multi-cloud environments and shared responsibility.
A powerful tool for transformational leaders aligning teams around shared outcomes.
On hard problems, ownership, and how senior leaders develop the next generation.
Findings on password hygiene drawn from the BSIMM software security maturity model.
A short personal essay — quite the accident — on how Jim's cybersecurity career began.
All downloads are direct PDF or DOCX files. No form, no signup.