Insights
Practical perspective, not panic
Cyber resilience, investigations and evidence, AI and cybercrime, executive leadership, and private-client security — written from practitioner experience.

Private Client Security
The Most Dangerous Network You'll Use This Month Is the One in Your Hotel Room
Researchers just documented a months-long campaign hijacking hotel and conference-center Wi-Fi to redirect guests into fake Microsoft 365 logins, and in some cases, to steal valid login sessions without ever touching a password. For anyone who travels and checks email from a hotel room, this isn't a hypothetical. It's the network you're on right now.

Investigations & Evidence
AI-Assisted Cybercrime Investigations: Why Law Enforcement Can't Afford to Fall Behind
Cybercrime losses reported to the FBI nearly tripled in four years. The tools to investigate at that scale exist today, built on Elasticsearch, sharpened by AI, but inside law enforcement, adoption is still the exception, not the rule. On what I've learned putting these tools to work myself, and why the gap is a public-safety problem, not a technology preference.

Executive Leadership
Beyond the Technology: What Defines an Effective Technology and Information Security Leader
Modern technology and security leadership isn't about protecting systems. It's about enabling the organization to pursue its objectives at a level of risk it can actually live with. On technical credibility, business enablement, and why translation is the real job.

AI & Cybercrime
The Anthropic Ruling Wasn't About the Pentagon. It Was About Who Controls the Guardrails.
A federal judge just ruled the Pentagon acted unlawfully when it punished Anthropic for refusing to remove the safety guardrails blocking its AI from autonomous weapons and mass surveillance. The headline is a government dispute. The lesson underneath it belongs to anyone relying on someone else's AI.

Cyber Resilience
Cyber Resilience: Preparing the Business to Withstand the Inevitable
The organizations that survive a cyberattack aren't necessarily the ones with the most technology. They're the ones that prepared to make sound decisions under pressure. On RTO, RPO, tabletop exercises, and the risk that even a strong program can't eliminate.

The Breach Debrief
Breach Debrief: The Ashley Madison Breach Nobody Was Ever Charged For
In July 2015, a group calling itself Impact Team dumped the personal data of more than 30 million Ashley Madison users online. I was working cybercrime investigations with Toronto Police Service at the time. More than a decade later, nobody has ever been charged.

Investigations & Evidence
The Future of Criminal Investigations Will Rise or Fall Around What We Do With the Data
AI can organize evidence, surface leads, and save investigators time they don't have. It can also manufacture false certainty and contaminate the record. Here's how I think about AI as an investigative assistant, not an evidence source, examiner, or attribution authority.

Private Client Security
Private Client Security Isn't One Discipline. It's Five, Working Together.
High-net-worth families and family offices carry a risk profile most cybersecurity advice was never built for. Here are the five areas actually driving harm right now, and where I'd start.

The Breach Debrief
Breach Debrief: The MyHeritage Breach Nobody Detected for Seven Months
A file sat on a server MyHeritage didn't control for seven months before a researcher found it, not them. The first entry in The Breach Debrief walks the chain of events and pulls out what it actually teaches.

AI & Cybercrime
AI Didn't Invent Cybercrime. It Just Got Better at the Job.
Every AI headline comes with the same panic: this changes everything. Having investigated cybercrime for years, I don't think that's the right way to frame it, or where the real risk actually sits.