Field Notes
Independent research and operating judgment.
Writing, research, and tools for technical decisions with material consequences. Everything publishes here first, with honest labels. Nothing claims a ship date it has not met.
Notes
018
Independent Technical Judgment Is Most Valuable When Incentives Diverge
The internal team, the response firm, counsel, the insurer, and the board answer different questions from the same facts. Nobody has to be dishonest for conclusions to be shaped by position. Independence is structural, and it is testable before an engagement starts.
Institutional Security · August 21, 2026 · 6 min
NOTE
017
AI Can Accelerate Analysis Without Owning the Conclusion
A model produces fluent output whether or not it is grounded, and fluency carries no marker separating source evidence from generated interpretation. Human review is not a control unless the reviewer knows what to trace. Setting explicit validation boundaries.
Technical Notes · August 21, 2026 · 6 min
NOTE
016
Cloud Security Architecture Is an Identity Problem Before It Is a Network Problem
The cloud control plane is an authenticated API, not a network location, and control-plane authority includes rewriting the network controls themselves. Transitive role chains, workload identity, deployment authority, drift between declared and deployed state, and cluster authorization.
Security Architecture · August 21, 2026 · 7 min
NOTE
015
A Control Is Worth What It Changes About the Outcome
Coverage establishes that controls exist. It does not establish that anything worth reaching became unreachable. Attack paths run through legitimate function, so a control beside the path changes nothing however well configured. What objective-based testing can and cannot establish.
Security Architecture · August 21, 2026 · 7 min
NOTE
014
Air-Gapped Does Not Mean Governed
Isolation is a strong control against reachability from untrusted networks and answers no governance question. Identity inside the enclave, administrative access, artifact provenance, patch cadence, and available evidence are all unchanged by the gap, and several get harder.
Private AI · August 21, 2026 · 7 min
NOTE
013
Crisis Leadership Is the Conversion of Incomplete Technical Facts Into Decisions
A technical crisis runs two clocks: the evidence clock, governed by what can be established and how fast, and the decision clock, set by obligations and stakeholders. They do not wait for each other. Partition the facts, sequence by reversibility, and decide the rules before the crisis.
Incident Command · August 21, 2026 · 7 min
NOTE
012
Boards Need Decisions From Security, Not Telemetry
Measurement without consequence, ownership, or a request converts oversight into spectatorship, and leaves directors accountable for a posture they were never shown in actionable form. The four elements a board security report should carry, and a test that exposes a decorative metric.
Institutional Security · August 21, 2026 · 6 min
NOTE
011
Forensic Parsers Should Fail Closed
Evidence-processing software that silently skips what it cannot read manufactures a gap the analyst cannot see. How parsers should behave on truncation, dirty transactional state, integrity failures, and unsupported structures, and what to require of any tool whose output supports a conclusion.
Technical Notes · August 21, 2026 · 7 min
NOTE
010
Before You Buy the Architecture, Identify What Must Be True for It to Work
Proposals arrive as advocacy. Capital is protected by falsification: decompose the commitment into the assumptions that must hold, grade each by verifiability, rank by damage-if-false, buy evidence for the expensive ones before signing, and restructure around what cannot be known.
Infrastructure & Economics · August 21, 2026 · 5 min
NOTE
009
Private AI Is a Custody Model, Not a Hosting Model
Running AI on your own infrastructure buys custody: the opportunity to control data, weights, and telemetry, plus the obligation to exercise it. Privacy is a property of the operated system: serving layer, retrieval stores, prompt logs, identities, and dependencies. The questions to answer before approving a deployment.
Private AI · August 21, 2026 · 6 min
NOTE
008
A Technical Claim Is Not Evidence
Secure, scalable, private, zero trust, enterprise ready: propositions wearing the costume of facts. How to decompress each label into testable statements, an evidence hierarchy for vendor claims, and why the refusal to warrant a claim is itself information.
Technical Diligence · August 21, 2026 · 6 min
NOTE
007
Technical Due Diligence Should Test the Investment Thesis, Not Merely the Technology
A technology assessment answers whether the systems are good. A transaction needs to know whether the technical facts support the specific economic bet being priced. The method: decompose the thesis into technical assumptions, rank by valuation sensitivity, test the ones doing the most work.
Technical Diligence · August 21, 2026 · 5 min
NOTE
006
Evidence Gaps Are Findings
What an investigation could not examine is a result, not a footnote. Gaps in telemetry, retention, scope, and third-party visibility bound every conclusion, and the decisions built on those conclusions inherit the ceiling. How to read an incident report so the gaps stay visible.
Incident Command · August 21, 2026 · 6 min
NOTE
005
The Incident Is Contained. That Does Not Mean It Is Closed.
Containment is an operational state. Closure is a governance decision that requires different evidence: scope understood, access gone, unknowns stated and accepted. The five states that get collapsed into one announcement, and what a board should require before accepting that an incident is over.
Incident Command · August 21, 2026 · 6 min
NOTE
004
What the First 90 Days of Security Leadership Should Actually Produce
The first quarter should produce decision clarity: a defensible risk position, named ownership, a commitments inventory, a tested escalation path, and a short prioritized plan with reasoning attached. Not a maturity program, not a tool rollout. How to evaluate the leader at day 90.
Security Leadership · August 21, 2026 · 6 min
NOTE
003
The Security Program Changes When Enterprise Customers Start Asking Questions
The first serious enterprise security review turns security into a revenue dependency and a stream of contractual representations. Why answering each questionnaire ad hoc fails as it scales, and the five capabilities to build instead.
Security Leadership · August 21, 2026 · 6 min
NOTE
002
SOC 2 Is Not a Security Strategy
A SOC 2 report is an assurance artifact: defined controls, a boundary management chose, a defined period. Treating it as the security strategy substitutes a reporting instrument for judgment. What the report establishes, what it cannot, and the questions an accountable executive should ask.
Security Leadership · August 21, 2026 · 7 min
NOTE
001
When a Company Actually Needs a Fractional CISO, and When It Doesn't
Fractional security leadership solves a judgment and accountability deficit, not a labor deficit. The conditions that create the need, what the role should and should not own, and seven diagnostic questions to apply before buying anything.
Security Leadership · August 21, 2026 · 9 min
NOTE
Research & Tools
A
Sample: an Executive Decision Memorandum
What the deliverable of an Executive Decision Review looks like: question, evidence, assumptions, findings, unknowns, implications, and one conclusion. An illustrative composite, clearly labeled, containing no client information.
SAMPLE
B
The Local AI Hardening Checklist
40 checks across 6 domains for Ollama, vLLM, llama.cpp, and RAG stacks. Free, no email. Printable. Share it.
PUBLISHED
C
Tasia, an open-source private AI hardening tool
Reviews the configuration of a private AI stack (compose, env files, Dockerfiles), flags exposure patterns with file and line, and writes a hardening pack your team can act on. Go, Apache 2.0, prebuilt binaries for macOS and Linux.
OPEN SOURCE
D
The Private AI Exposure Index
Measuring how private AI systems are actually exposed, and whether they can be investigated when something goes wrong. The methodology is published before the results.
CURRENT RESEARCH
E
Windows Gaming Reference Configuration
A Windows 11 reference configuration for a purpose-built PC gaming machine, written to the discipline a production system would get. Audit before change, full policy backup and a restore path before anything mutates, desired state applied through Microsoft-native tooling, and verification that the deployed state matches what was declared. It declines the trade the genre is built on: Defender, Firewall, Secure Boot, TPM, and BitLocker stay on, and no unsupported registry folklore is used. Performance claims require published benchmarks and raw methodology, including results showing no change. PowerShell, LGPO, WinGet. MIT.
OPEN SOURCE
Field Notes, by email
New notes land here first and go out by email. Vendor claims tested, failure modes, infrastructure economics, lessons from incidents and live deployments. No news feed.