Content
Strategic insights on blockchain, AI, security, leadership, and career in an age of disruption.

AI Voice Phishing: Why Your Defenses Face the Wrong Direction
AI voice-cloning has fundamentally reversed phishing attacks—now criminals call employees impersonating trusted leaders, exploiting help desk processes instead of technical vulnerabilities.
Recent Essays

AI Homogenization: Why Differentiation Matters Now
As AI tools commoditize professional work, differentiation shifts from speed to unique perspective. Discover how to stand out when everyone has access to the same models.

Crypto Security Failures: It's Always the People
40% of crypto hacks exploit stolen private keys, not broken cryptography. The real security gap isn't the math—it's the humans and processes protecting it.

AI Agents & Hidden Web Instructions: Security Risk
Autonomous AI agents can be manipulated by hidden webpage instructions to make unauthorized payments. Learn how indirect prompt injection threatens enterprise automation.

Who Keeps the Interest? The Real Stablecoin Battle
Stablecoin competition isn't about technology—it's about who controls float income. Learn why Open USD's consortium model threatens Circle's $653M quarterly advantage.
#security
142 posts

How Can I Help You?
Explore insights from the "How Can I Help You?" survey, revealing trends in security careers and reader demographics. Discover how a revamped assessment now tailors learning paths for aspiring professionals.

How To Move From Development to Security
Discover how developers can transition into the thriving field of application security with this guide. Learn essential skills, explore the OWASP Top 10, and find resources to enhance your security mindset.

Why We Will Never Secure The Internet of Things
Explore why securing the Internet of Things (IoT) remains elusive, as most devices, made by unknown manufacturers, lack security measures. Discover the need for universal security standards.

ISO 27017: A New Standard to Learn
Explore ISO 27017, a cloud-specific security standard that Amazon Web Services recently adopted. Learn how it complements existing ISO standards and its implications for cloud security practices.

InfoSec Does Time Management Wrong
Discover why traditional time management in IT and InfoSec falls short and learn how the "multiplier effect" can transform your workflow, boost productivity, and empower your team for long-term success.

Reader Mailbag: Join a Big Consulting Firm?
Explore the dilemma of joining a big consulting firm versus staying independent in infosec. Weigh the benefits of specialization and exposure at giants like KPMG against the freedom of solo consulting.

Now Secured By Let’s Encrypt
Discover how Let's Encrypt is revolutionizing web security by offering free SSL certificates, removing financial barriers and ensuring accessible encryption for everyone.

Project: Intrusion Detection
This starts the first in a series of projects you can use to improve your security skills. The ideas of these projects is something…

Passwords is Everything That is Wrong with Security
Explore why the outdated concept of passwords is failing modern security needs and discover innovative alternatives like token-based authentication that promise a more secure future.

On Third Party Security Breaches
Explore the aftermath of the T-Mobile/Experian breach, examining blame dynamics, brand impact, and strategies for mitigating third-party risk. Learn how to protect your company from similar incidents.

What InfoSec Pros Can Learn From Agile
Explore how InfoSec professionals can learn from Agile methodologies to improve security integration in software development, transforming security practices into a more proactive and disciplined approach.

Top 5 Security Career Struggles
Explore the top 5 struggles in security careers, from being a "one trick pony" to misdirected anger, and discover actionable solutions to overcome these hurdles for growth and success.