Skip to content

Reference

How security leaders decide, and how they defend the decision afterward.

Every other reference tells you what to build or which product to shortlist. This one covers the part in between: the committee that has to agree, the budget line that has to exist, and the answer you will owe someone in six months when they ask why you chose this.

Written from both sides of the security purchase. Free, ungated, and sourced line by line, because a decision brief with an unverifiable number in it is worth less than no brief.

The desks

Buying & Evaluation

8

Security software has the largest buying committee in enterprise technology, and almost nobody writes about it from inside the room. This desk covers the mechanics: who is really in the committee, what triggers a budget line, whether a POC earns its cost, how questionnaires get used as a weapon, and how to retire a tool without leaving a hole.

Identity & Access Leadership

6

Identity is usually the largest line in a security budget and the hardest one to explain upward. This desk covers the leadership decisions: sequencing IGA, PAM, and ITDR; owning non-human identity before it is a tooling problem; what identity debt costs at scale; and what an auditor will actually open when they test access control.

Security Leadership in SaaS

5

A software company carries two security programs that get confused for one: the one protecting the product customers buy, and the one protecting the company that builds it. This desk covers the decisions a founder or first head of security has to make about both, plus the point at which enterprise readiness stops being a compliance exercise and starts blocking revenue.

Budget & Board

In progress

Budget construction, prioritization, board reporting, and materiality. Written from the vantage of someone who has had to justify security spend to a board that was measuring something else.

AI Governance

In progress

Shadow AI, agent authorization, model inventory, and the regulatory obligations landing now. Governance decisions, not model architecture.

Benchmarks

All 10

One number per page, with its source, its sample, its methodology, and a written statement of what it does not mean. Re-verified quarterly.

Latest

Field NoteSaaSAugust 28, 2026

Your First Security Hire Is Not an Engineer

Founders hire a strong application security engineer into the first security role and get an unhappy engineer doing spreadsheet work while the queue keeps growing. The job is program work.

Decision BriefIdentityAugust 28, 2026

IGA, PAM, or ITDR First?

Three identity categories compete for the same budget line and vendors in each will tell you theirs comes first. The sequence is decided by which failure you can already evidence.

Everything on the buying desk

Tools

No signup, no server, nothing leaves your browser. Every benchmark inside a tool links to the card it came from, so you can check the arithmetic and the source.

Who writes this

Deepak Gupta co-founded LoginRadius and scaled it to over a billion user identities, which meant answering several hundred enterprise security evaluations from the vendor's chair and watching how those decisions really got made. On the other side of the same job, he ran the SOC 2, ISO 27001, GDPR, and CCPA programs that had to buy their own tooling out of a budget somebody else controlled.

That is a narrow claim, and it is the one this desk stays inside. There is no Fortune 500 CISO career advice here, no compensation benchmarking, and no leadership curriculum. What is here is the mechanics of buying, the identity chapter of a program, and what security leadership actually looks like inside a software company.

More about this desk and its boundaries·How the sourcing works

Common questions

What is The CISO Desk?
A free, ungated reference for security leaders published at guptadeepak.com/ciso. It covers how security purchases actually happen, how identity programs get funded and sequenced, and how a software company builds a security function. Every external statistic carries a named source, a sample size, and a verification date.
Who writes The CISO Desk?
Deepak Gupta, who co-founded LoginRadius and scaled it to over a billion user identities before founding GrackerAI. That background means several hundred enterprise security evaluations answered from the vendor's chair, plus running the SOC 2, ISO 27001, GDPR, and CCPA programs that had to buy their own tooling.
How is this different from a vendor comparison site?
It does not compare vendors. Product shortlists live in the CIAM Compass and GRC Compass directories, and implementation guidance lives in Guides. This desk covers the decision itself: who decides, on what information, and how the choice gets defended afterward.
Is any of it gated?
No. There is no signup, no email wall, and no lead form on any page. The interactive tools run entirely in the browser, make no network calls, and store nothing, so nothing a reader types about their security stack ever leaves their device.
How current is the data?
Every page carries an as-of date, and every external figure carries a separate verification date. Benchmark cards are re-checked quarterly, and the build fails if a cited figure has not been verified within ninety days, so a stale number cannot ship silently.