I write to develop and test ideas about Enterprise Security, business enablement, organizational design, and the relationships between them.

Much of my writing is organized around three questions I continue to explore:

Designing Enterprise Security Organizations

How should Enterprise Security organize around the business it supports? I’m interested in operating models, engagement structures, and other mechanisms that help security organizations move beyond delivering individual security services toward enabling better business decisions.

Building Trusted Relationships

What creates trusted and productive security advisory relationships? I explore how communication, understanding, credibility, and relationships affect Security’s ability to influence decisions and manage risk.

Creating Learning Systems

How can security organizations learn systematically from their interactions with the business? I’m interested in turning conversations, friction, observations, and outcomes into signals that improve how Security operates.