Field notes &
playbooks.
Plain-language guides, real-world case studies, and a glossary that actually explains what the acronyms mean — written by certified practitioners who do this work every day.
Recent writing.
View all articles →The IAM rollout order for a 50-person SaaS.
Access control is the first real wall a growing SaaS hits. Here's the order to roll it out, what a SOC 2 review actually asks for, and where a spreadsheet is still genuinely fine.
A vCISO's first 90 days.
Ninety days with a vCISO does not fix security, it buys you a clear-eyed risk map, a plan you can afford, and a few real wins. Here is what those first months should actually look like, and what really happens in them.
Zero Trust without buying anything.
You got told you need Zero Trust and priced it like a product. For most small companies it's a configuration project, not a purchase, and you already own most of the parts.
PIPEDA vs Law 25: what Canadian small businesses actually have to do.
Someone said the words "Law 25" and now there's a knot in your stomach. What PIPEDA and Quebec's Law 25 actually require about moving your data, in plain English, minus the legalese and the panic.
Software we’re building.
Plain language. No jargon tax.
A reference for the acronyms and frameworks that come up most often in compliance and security work. Bookmark it — we update as new frameworks emerge.
SOC 2
Service Organization Control 2A security framework developed by the AICPA that defines how service organizations should handle customer data based on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. Most enterprise buyers require vendors to be SOC 2 compliant.
SOC 2 Type I vs Type II
Point-in-time vs. ongoing assessmentType I assesses security controls at a single moment — a snapshot. Type II evaluates controls over a period (typically 3–12 months) to verify they operate consistently. Most companies start with Type I and progress to Type II.
ISO 27001:2022
International information security standardThe 2022 revision of ISO’s information security management system (ISMS) standard. Widely used outside North America and increasingly required by European and Asian enterprise buyers. Includes 93 controls across 4 themes.
NIST CSF 2.0
NIST Cybersecurity Framework 2.0Released in 2024, NIST CSF 2.0 is the updated U.S. National Institute of Standards and Technology cybersecurity framework. Adds the Govern function to the original five (Identify, Protect, Detect, Respond, Recover) and covers 106 subcategories.
PIPEDA
Personal Information Protection and Electronic Documents ActCanada’s federal privacy law governing how private-sector organizations collect, use, and disclose personal information during commercial activities. Applies to every business operating in Canada. Requires consent, safeguards, and breach notification.
Zero Trust
Zero-trust security architectureA security model that assumes no user or device is trusted by default, regardless of whether they’re inside the network perimeter. Every access request is verified, authenticated, and authorized. Often summarized as "never trust, always verify."
Data sovereignty
Data residency and jurisdictional controlThe principle that data is subject to the laws of the country where it’s physically stored. Critical for Canadian federal, provincial, and regulated-industry organizations that must keep data inside Canadian borders and out of US CLOUD Act reach.
IAM
Identity and Access ManagementThe discipline of managing digital identities — users, service accounts, machine identities — and controlling their access to systems and data. Core practices include SSO, MFA, RBAC, PAM, and periodic access reviews.
MFA
Multi-factor authenticationA security mechanism requiring two or more verification factors to access a resource. Factors fall into three categories: something you know (password), something you have (phone, token), something you are (biometric). MFA is the single highest-ROI control for most organizations.
Pen test vs VA
Penetration test vs vulnerability assessmentA vulnerability assessment scans for known weaknesses and produces a prioritized list. A penetration test attempts to actively exploit weaknesses to determine real-world impact. Pen tests are slower and more expensive but reveal chained attack paths that VAs miss.
One email. A month.
Field notes, playbooks, and the occasional war story. Written for security teams who’d rather read 800 useful words than skim a 4,000-word listicle.