Skip to content

Writing

All writing

Long-form essays on identity, AI security, CIAM, Generative Engine Optimization, and the practice of building software. 728 pieces, newest first.

Latest essay

CISO

The CISO's 2027 Budget Memo: What to Fund, What to Cut, What to Defend When AI Agents Hit Production

AI agents are reaching production while security budgets grow 4%. How to use The CISO Desk benchmark cards, tool overlap analyzer and templates to write a 2027 memo that funds agent security by reallocation, with a copyable template.

Read the article
Podcasts

The Podcasts That Explained the Biggest Breaches Best

One first listen and one deeper episode for six major breaches: SolarWinds, NotPetya, Log4Shell, MOVEit, Scattered Spider and XZ Utils. Each verified against the show's feed, linked to a primary source, with the identity lessons pulled out.

GEO

llms.txt Is the Meta Keywords of 2026

Google says llms.txt neither helps nor harms. John Mueller compared it to the meta keywords tag. Adoption sits near 10% of domains and correlation studies find no citation effect. Here is the honest version, including the one use case where the file genuinely earns its place.

GEO

You Can Do Everything Right and Still Be Invisible

Every GEO playbook assumes AI engines can read your site. Cloudflare flipped the default to blocked on new domains and serves roughly a fifth of the web. I look at the access layer nobody optimizes, why it usually sits with infrastructure teams, and how to audit yours.

SaaS

AI Didn't Kill SaaS. It Killed the Seat.

SaaS prices just hit record inflation while a third of companies now build instead of buy. Software is not dying. The seat is, and so is every vendor that charges for access instead of outcomes.

Podcasts

Cybersecurity Podcasts for Students: A 12-Week Listening Plan

A week-by-week security podcast plan for university, bootcamp and self-taught students: one short daily news show, two or three named episodes a week, and a phase on identity, MFA and passkeys. Mapped to Security+, CySA+ and the CISSP.

Agentic AI

Agentic Commerce: How AI Agents Will Find, Compare, and Buy for You

On September 20, Amazon blocked Meta's new Muse AI agent from its store. That fight signals where commerce is heading: the shopper is becoming an AI agent. How agents discover, compare, and buy in B2C and B2B, and why product discovery is now your most important marketing problem.

AI

AGI Has Not Arrived. Here Is What 2026 Actually Proved

Jensen Huang declared AGI had arrived in a post that ended with "400K GPUs coming online next." That is not a scientific claim. It is a capital request with a headline attached. 2026 was remarkable. It was not the year general intelligence arrived.

CIAM

CIAM Observability: The Metrics Nobody Tracks

Vendor log retention ends months before the average breach is discovered. The funnel, security, and silent-failure metrics every CIAM deployment should have, and the seven-panel dashboard to start with.

AI Security

Your AI Agent Has No Idea Who Authorized It

Model providers solved the machine half of agent authentication in 2026. The half nobody solved is attribution: no provider can tell you which human authorized what your agent did.

Citation Tracking

We Tracked 180,000 AI Answers. Here Is What We Found

Most teams treat LLM output as deterministic. We measured 180,000 responses across four AI engines for 18 months and found the opposite: visibility drops 30% overnight, and the engines agree on 11%.