Skip to content

For

New CISO

You have taken a security leadership seat and inherited a stack, a budget, and a set of commitments you did not make. The first decisions are about what to keep, what to fund, and what to stop.

These pieces are the decision mechanics rather than a maturity model: how evaluations reach a conclusion, what actually creates a budget line, how to sequence identity spend, and how to retire something without leaving a hole.

11 pieces

Decision BriefIdentityAugust 28, 2026

IGA, PAM, or ITDR First?

Three identity categories compete for the same budget line and vendors in each will tell you theirs comes first. The sequence is decided by which failure you can already evidence.

PlaybookBuyingAugust 28, 2026

Killing a Tool: The Murder Board Nobody Runs

Security teams buy well and retire badly, which is how a stack reaches thirty tools. A murder board is the two-hour structure that makes a retirement decision defensible before it happens.

Decision BriefBuyingAugust 28, 2026

Should You Run a POC or Trust the Reference Call?

A proof of concept costs weeks of engineering time you are not accounting for. Two good reference calls cost ninety minutes. The choice turns on one question: is the failure you care about visible from outside?

Field NoteIdentityAugust 28, 2026

The Cost of Identity Debt at Scale

Identity debt never arrives as a security incident. It arrives as onboarding that takes nine days, an audit finding that recurs, and a migration estimated at one quarter that takes three.

Field NoteIdentityAugust 28, 2026

What Auditors Actually Test in Identity

Auditors do not evaluate your identity architecture. They pick names off a list and ask you to prove what happened. Elegant design earns nothing if the record is missing.