Field notes on security

Plain-English writing on vulnerabilities, compliance, and the cost of doing nothing.

No "thought leadership" filler. Just real analysis on what is breaking, who is paying for it, and how teams without a security department can keep up.

All Vulnerabilities AI security Compliance Engineering
Threats
28,961

The compounding cost of one ignored vulnerability

28k new CVEs last year, 76% of breaches had a patch available, and the average mid-size company is carrying months of unpatched exposure. The economics of doing nothing have changed.

8 May 20269 min read
AI security
AI

Everyone is building with AI. Almost no one is protecting it.

Prompt injection, model theft, leaked API keys in inference layers, training-data poisoning, the attack surface around AI shipped to production is larger than the surface AI itself protects.

24 April 20267 min read
Compliance
€20M

GDPR is not a one-time exercise. Here is how to stop treating it as one.

Every new feature is a new processing activity. Every new vendor is a new sub-processor. SMBs cannot afford a full-time DPO and a quarterly external audit. We rebuilt the workflow.

12 March 20268 min read
Engineering
2.4d

Cutting mean time-to-patch from 11 days to 2.4: what changed

A field report on the workflow shifts that moved patch latency below industry baseline. Hint: it was not the tools, it was the framing.

21 February 20266 min read
Engineering
300k

Building a 300k-record vulnerability database that stays current

Inside the ingestion strategy, the source-by-source feed model, and the version-matching approach that keeps false positives below 4%.

14 January 202610 min read

One field-note email per month.

No newsletter spam, no "sponsored content", no roundups. One in-depth post on what changed in security and what to do about it. Unsubscribe any time.