Who writes this, what it deliberately does not cover, and how it relates to the other references on guptadeepak.com.
What this is
A free, ungated reference for people who have to make a security decision and then live with it.
Most security writing addresses one of two jobs: how to build something, or which product to shortlist. Both are useful. Neither is the job a security leader spends most of their week doing, which is getting a group of people who report to different executives to agree on something, funding it out of a budget somebody else controls, and being able to explain the reasoning afterward to a board, an auditor, or a regulator.
That is the gap this desk works in.
What it deliberately is not
A CISO career curriculum. That territory is well covered by people who have run enterprise security organizations for decades. The claim here is narrower and different.
A vendor directory. There are two on this site already, and vendor listings belong in them.
A glossary. Guides holds one.
Career, compensation, burnout, or crisis leadership content. No defensible claim, so no content.
Where the authority comes from, and where it stops
Deepak Gupta founded LoginRadius in 2013 and scaled it to over a billion user identities. On the vendor side of that job, that meant several hundred enterprise security evaluations answered from the seller's chair, with a clear view of how those decisions actually got made and where they died. On the buyer side of the same company, it meant running the SOC 2, ISO 27001, GDPR, and CCPA programs and buying the tooling they needed.
That is an unusual position and it is a specific one. It supports strong claims about how security purchases work, about the identity chapter of a program, and about building a security function inside a software company.
It does not support claims about running security for a Fortune 500 bank, and this desk does not make them. Where a topic sits outside that experience, either it does not get written, or it gets written from the vantage that is actually available and says so on the page.
How it relates to the rest of the site
Each desk here states, on its own page, what is deliberately not covered and where that material lives instead. That is not politeness. Sub-properties on a shared domain compete with each other for the same query unless the boundary is written down, and writing it down on the page is the cheapest enforcement available.
Disclosure
Deepak founded and runs GrackerAI. Where its data or its market is relevant to something on this desk, that is disclosed inline on first mention. No content here is sponsored, and no vendor has paid for placement, review, or mention.
The desks and their boundaries
- Buying & Evaluation
- A security purchase crosses more internal boundaries than almost any other software buy, and almost nobody writes about it from inside the room. This desk covers the mechanics: who is really in the committee, what triggers a budget line, whether a POC earns its cost, how questionnaires get used as a weapon, and how to retire a tool without leaving a hole.
- Vendor shortlists are not here. If you already know the category and want to compare products, the Compass directories do that job properly, and the Guides library covers category-specific evaluation.
- Identity & Access Leadership
- Identity is usually the largest line in a security budget and the hardest one to explain upward. This desk covers the leadership decisions: sequencing IGA, PAM, and ITDR; owning non-human identity before it is a tooling problem; what identity debt costs at scale; and what an auditor will actually open when they test access control.
- Architecture and implementation are not here. Zero trust design, protocol choices, and how to wire a specific stack live in Research and Guides. Vendor comparison lives in the Identity Map and CIAM Compass.
- Security Leadership in SaaS
- A software company carries two security programs that get confused for one: the one protecting the product customers buy, and the one protecting the company that builds it. This desk covers the decisions a founder or first head of security has to make about both, plus the point at which enterprise readiness stops being a compliance exercise and starts blocking revenue.
- Stack recommendations are not here. What to actually deploy at seed stage, and how to pass an audit, live in Guides.
- Budget & Board
- Budget construction, prioritization, board reporting, and materiality. Written from the vantage of someone who has had to justify security spend to a board that was measuring something else.
- Market sizing and category landscape are not here. Research covers the enterprise security market itself.
- AI Governance
- Shadow AI, agent authorization, model inventory, and the regulatory obligations landing now. Governance decisions, not model architecture.
- The AI security stack itself is covered in Research. AI governance vendor selection is covered in GRC Compass.
- The Record
- A security decision is judged twice: once when you make it, and once afterward by someone reconstructing it from whatever record exists. This desk covers the second reading. What to escalate and to whom, how a risk acceptance is recorded so that a known risk reads as governance rather than concealment, and what a public security claim commits the person who signed it to.
- Legal advice is not here, and nothing on this desk is a substitute for counsel. Regulatory obligation mapping lives in GRC Compass, and incident response mechanics live in Guides.
How the sourcing and verification works