Study the adversary, not only the alert
A threat is a party with capability and intent — not a finding in a scanner report. These essays are about the disciplines that take the adversary seriously: modelling systems before they are built, buying intelligence that someone will actually act on, tracking the infrastructure an operation cannot cheaply rebuild, and being honest about the difference between knowing who did it and knowing what to do next.
All essays
- Threat, Vulnerability, Risk — Three Words, Three Jobs
The three terms are used interchangeably and they describe different objects with different owners. The confusion is not pedantry; it shows up directly in how budgets get argued.
- A Tabletop That Fails Is Working
An exercise that everyone passes has told you nothing. The value is in the decisions nobody could make, the dependency nobody had mapped, and the question nobody could answer.
- The Adversary Has a Budget
Intrusions have a cost structure — access, tooling, infrastructure, labour, time and the risk of burning a capability. Controls work by moving one of those lines, and most programmes never ask which.
- Infrastructure Outlives the Payload
A file hash changes for free; a hosting arrangement does not. Tracking the machinery an operation has to keep standing is slower, harder to automate, and considerably more durable.
- Attribution Is Fascinating; Ask What It Changes
Naming the adversary satisfies something real, but most incident decisions are identical whoever is behind the keyboard. The useful question is which specific choice would differ.
- Why Purchased Threat Intelligence Sits Unread
Most intelligence feeds fail not because the data is bad but because nobody defined the decision the data was supposed to inform. Requirements first, subscriptions second.
- Threat Modelling Is Design Work, Not Review Work
A threat model produced after the architecture is fixed can only describe problems. Produced while the boxes and arrows are still soft, it changes them — which is the whole point.