// field notes

All advisories

Every post, newest first.

Threat Modeling Mastery

STRIDE Methodology Explained: The Threat Modeling Framework Every Engineering Team Should Know

Learn how the STRIDE threat modeling framework works, with real examples, common mistakes, and best practices for catching security threats before you build.

2026-07-284 MINUTES
Security Architecture & Secure by Design

Secure by Design vs. Bolt-On Security

Security bolted on at the end isn't security — it's a patch job with a deadline. The cost difference isn't the fix, it's when you found the problem.

2026-07-282 MINUTES
Threat Modeling Mastery

STRIDE Explained Simply, With a Real Example

Six categories, applied to one component at a time. Here's STRIDE walked through a login form, end to end — no textbook theory.

2026-07-212 MINUTES
AI Security & Governance

What AAISM Actually Covers, and Why I'm Pursuing It

ISACA's new AI-specific security management certification, broken down into its three real domains — and why it's the credential that most directly signals AI Security Architect readiness.

2026-07-14~1 MINUTE
Privacy Engineering & Compliance

What CIPT Actually Covers, and Why Security Folks Should Care

CIPT isn't a legal certification — it's the technical privacy credential security folks are sleeping on. Here's the difference between CIPT and CIPP, and why it complements ISO 27701 and DPDPA work.

2026-07-07~1 MINUTE
GRC & ISO Standards

ISO 27001: What an Audit Actually Looks Like, From the Inside

Most people preparing for their first ISO 27001 audit have no idea what the actual day looks like. It's mostly conversation and evidence review — and the teams that struggle aren't the ones with imperfect controls.

2026-06-30~1 MINUTE
Certification & Career Growth Journey

Why I'm Pursuing CISSP Now, After Years in Offensive Security

Five years in offensive security gave deep technical fluency. Here's honestly why CISSP came after that experience, not before it — and why the sequencing changed how the material lands.

2026-06-23~1 MINUTE
Offensive-to-Defensive Lessons

What 5 Years of Offensive Security Taught Me About Defense

The biggest shift: attackers don't need to be clever if a system gives them an easy path. Most real findings weren't exotic zero-days — they were a missed access check or an overly trusted assumption.

2026-06-16~1 MINUTE
Leadership & Mentorship in Security

What I Look For When Mentoring Someone New to Security

Not raw technical knowledge — that's teachable. Three things predict long-term growth far better than how much someone already knows on day one.

2026-06-09~1 MINUTE