Writing & analysis

Useful ideas deserve more than a slide bullet.

This is where I explain cybersecurity governance, program design, human risk, and AI governance in a way that respects both the complexity of the subject and the reader’s time.

Featured paperGraduate research · 17 pages · 12 cited sources

An Integrated Approach to Cybersecurity Governance for Organizations with Established Cybersecurity Programs

A practical modernization argument built around GRC, human-centered training, executive risk communication, responsible AI integration, and continuous reevaluation.

NIST CSF 2.0NIST RMFAI RMFHuman riskIncident response

Research directions

Questions I keep pulling apart.

These are active professional interests—not empty article slots. New pieces will appear only when the research and argument are ready.

AI governance without theater

How organizations can distinguish responsible oversight from policy language that creates no usable decision process.

Human risk as system design

Why blaming the user obscures the organizational conditions that allow ordinary mistakes to become serious incidents.

Incident readiness beyond the plan

What communication, ownership, evidence preservation, and rehearsal reveal about whether a response program can actually operate.

Writing standard

Trace the source. Explain the consequence. Leave something usable.

My goal is not to produce more cybersecurity content. It is to produce clearer professional judgment.