About

“I have no special talent. I am only passionately curious.” Albert Einstein

I work in security because I wanted to understand how things work.

I have always wanted to know how something actually works rather than how it is described. Most of what I do comes from that: taking a system apart, finding where its real behaviour and its documented behaviour have drifted, and closing the distance between them.

That turned into a career in security. I own the management systems, policy and assurance an organisation is held to, and I stay close enough to the engineering to know whether the controls underneath them are real. I am comfortable answering for that in an audit, in a board paper, or in a code review. I hold the CISSP.

Right now that means leading security and compliance at BLP Digital. The full list of roles is on the work page.

How I work

Most security problems I meet are a gap between what an organisation believes is true and what its systems actually do. Closing that gap is the job. In practice it means less new policy and more verification, and where something has to be built before a control is real, I would rather build it than write another paragraph about it.

The rest is judgement about what matters. Not every risk deserves the same attention, and a security function that treats them as though they do will lose the room. I would rather be specific about the few things that could genuinely hurt, and honest about what I do not yet know.

What has my attention

Systems that make decisions, and the problem of governing something that behaves differently each time it runs. Regulation arriving faster than the engineering built to meet it. The distance between a control that satisfies an auditor and one that would hold against somebody who is actually trying. I write most of it down as I go, in essays and notes, and the occasional deck or tool other teams are welcome to take.

Elsewhere