Field Notes

Notes on security, risk, and decision-making to promote a stronger, more informed security community.

Field Notes is a collection of short essays on cybersecurity, risk, and decision-making to promote a stronger, more informed security community.

These notes come from more than two decades of working in IT and security, teaching, mentoring, and learning from real failures. They focus less on tools and more on how people think about security, how risk is misunderstood, and why many well-intentioned efforts fall short.

This writing is intentionally practical and accessible. There are no vendor pitches, no gated content, and no proprietary examples. The goal is to share knowledge that helps people make better security decisions in the real world.

What to Expect

  • Essays on security as a decision-making problem
  • Practical thinking on threat modeling and risk
  • Lessons from teaching, mentoring, and real-world work
  • No vendor pitches, no paywalls, no proprietary material

Essays

Availability Is Not Optional

Posted

January 2026

The SurvivalTrait Manifesto

Posted

January 2026

Before the First Move is Made

Posted

January 2026

The First Move is Data Collection

Posted

January 2026

The New Insider Threat Is Authorized

Posted

February 2026

Forged by Fire

Posted

February 2026

Forged by Fire, Part 2: The Field Manual

Coming Soon

February 2026

Forged by Fire, Part 3: Command and Control

Coming Soon

March 2026

Urgency As an Exploit

Posted

February 2026

Threat Modeling Before Frameworks

Coming soon.

March 2026