IT Risk & Controls

Things that are invisible until they're not.

Thought leadership on identity governance, cybersecurity controls, and IT audit — from someone who has spent 25 years watching the invisible become very visible.

Start Reading

Featured

Featured

The Clock Is Ticking: Why Versionless Identity Security Is No Longer Optional

AI is collapsing the window to patch from five days to five minutes. In an era of AI-powered zero-days and supply chain attacks, your identity security vendor's update cadence is no longer a product detail — it's a risk decision.

identity securityversionlesszero-daySaaScybersecurityAISailPoint
Featured

Things That Are Invisible Until They're Not

An introduction to why identity, access, and controls are the silent load-bearing walls of every organization — and what happens when they crack.

identity governanceIT riskcontrols

Recent Writing

All posts →

Things That Are Invisible Until They're Not

An introduction to why identity, access, and controls are the silent load-bearing walls of every organization — and what happens when they crack.

identity governanceIT riskcontrols

About this site

Identity and access are the invisible load-bearing walls of every organization. This site exists to make them legible — through rigorous analysis, practitioner perspectives, and the occasional uncomfortable truth.

Written by an Identity Strategist with over 25 years in IT audit, cybersecurity controls, and identity governance.

About the author →