| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Original HTTPS Page] |
Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.
You must be logged in to block users.
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abuseSecurity Shouldn't Be Paywalled.
Most of what a company needs to be safer isn't secret and isn't hard. It's just locked up behind a consulting engagement or a form that wants your email before it'll show you a checklist.
So I'm putting the stuff I'd hand a client on day one out here. Free. No form. Licensed so you can use it commercially.
I'm a cyber risk and technology exec. 30 years across financial services, professional services, and critical infrastructure. Ran technology as CTO for a five-office firm. Most recently SVP in Kroll's Cyber Risk practice, sitting as vCISO for enterprise clients.
I work on the boring half of security. The policies, the controls, the habits. The stuff that turns a strategy deck into something somebody actually does on a Tuesday.
Right now a lot of that is AI. How do you govern GenAI and agents without banning them outright or letting them run loose? Most frameworks haven't caught up yet.
You don't have to outrun the bear. You have to not be the slowest.
But you can't sprint either. Go all out and you burn your team down in two quarters, and the program dies with your enthusiasm. The job is finding a pace you can hold for years.
That's one of eleven things I say a lot. The rest are in PRINCIPLES.md. Everything here comes out of them.
| Kroll | SVP, Cyber Risk Advisory Services |
| Roberts Markel Weinberg Butler Hailey PC | Chief Technology Officer |
| Alvarez & Marsal | Manager, Forensic Technology Services |
| Ernst & Young | Senior, Fraud Investigation & Dispute Services |
B.B.A. Management Information Systems, Texas Tech EnCE · RCA · Cellebrite CCLO and CCPA
Security Lessons is the big one. 727 security lessons from stories people already know. The Simpsons, Shakespeare, Star Wars, the KJV Bible, Breaking Bad, real heists, Greek myth, a century of actual incidents. Every one mapped to NIST CSF 2.0 and ISO 27001.
I talk in analogies because framework language doesn't move anybody. That repo is 727 of them.
The rest gets posted as I finish it. Control mappings, policy sets, tabletop scenarios, board briefing structures, assessment scaffolding.
All of it CC BY 4.0. Use it, change it, sell services on top of it. Just say where you got it.
Notes on a Cocktail Napkin in Sharpie Beat Nothing. Everything here is a napkin somebody already scribbled on. Take it and write over it.
Something you need that isn't here? Open an issue and tell me.
Opinions are mine. Not my employers', current or former, and not my clients'. Nothing here comes from a client engagement.
Board and executive briefing templates for cybersecurity. Slide structures, metrics, and language that non-technical directors actually understand.
AI governance sized for real companies: use policy, intake and review, a risk register, vendor questions, and the EU AI Act dates in plain English.
How to run security as a fractional CISO: the first 90 days, operating cadence, deliverables that matter, and leaving programs better than you found them.
A complete security program you can adopt in a week: 22 plain-English policies plus honest mappings for ISO 27001, NIST CSF 2.0, CIS, SOC 2, PCI, HIPAA, GDPR, CMMC and more.
Hundreds of short security lessons from the field. One idea at a time, plain English, every one says why.
Secure, repeatable IONOS infrastructure deployments for Coolify, including Ubuntu cloud-init, server hardening, deployment guidance, and configuration examples.
| Back | FazBrowse Home | New Git URL |