IT Risk & Controls

Things that are invisible until they're not.

Thought leadership on identity governance, cybersecurity controls, and IT audit — from someone who has spent 25 years watching the invisible become very visible.

Start Reading

Featured

Featured

Who Authorized That Agent to Touch the Grid?

AI agents are already operating against enterprise and OT systems — holding credentials nobody issued deliberately, crossing boundaries that were supposed to be controls. A practitioner framework for governing non-human identity before the regulator asks.

identity securityAI agentsnon-human identityidentity governanceOT securitySailPointcybersecurity
Featured

The Clock Is Ticking: Why Versionless Identity Security Is No Longer Optional

AI is collapsing the window to patch from five days to five minutes. In an era of AI-powered zero-days and supply chain attacks, your identity security vendor's update cadence is no longer a product detail — it's a risk decision.

identity securityversionlesszero-daySaaScybersecurityAISailPoint

Recent Writing

All posts →

Who Authorized That Agent to Touch the Grid?

AI agents are already operating against enterprise and OT systems — holding credentials nobody issued deliberately, crossing boundaries that were supposed to be controls. A practitioner framework for governing non-human identity before the regulator asks.

identity securityAI agentsnon-human identityidentity governanceOT securitySailPointcybersecurity