Latest Articles
The Open Secret About How Cyber Practitioners Handle Secrets
Credentials are still scattered across developer machines, build pipelines, configuration files, and AI agent directories. Unaudited, unrotated, and unprotected. This article reflects my first-hand experience. Root cause, real exposure, and a practical path forward, for both leadership and engineering teams. And it makes the case for a board-and-management mandate on credential security management even more urgent.
Year 2029: How Google’s Quantum Warning (Q-Day) Came True, Triggering a Confidence Crisis and Costing One Bank Millions in just two weeks!
A fictional 2029, a real Q-Day. Not a single account hacked. Not one key cracked. Sinasia Financial Group was asked a question it could not answer. The suspension cost millions. The memo had warned them three years earlier. The board deferred. Q-Day is not a technical event. It is a trust event. With thanks to Marin Ivezic, whose framing reshaped how I see this threat.