Content grid with edge-lit article cards floating in dark space — Amelia S. Gagne's writing on strategy, psychology, AI adoption, and cybersecurity

Pillar

Cybersecurity

Engineering-framed topics; secure-by-construction

26 articles  • Page 1 of 3

Cybersecurity Sep 19, 2026 • 8 min

Cyber Resilience Tools Cost vs Breach Recovery and Fines

Cyber resilience tools cost versus breach recovery and fines is a recurring number you choose against a one-time number you do not. IBM's 2026 average breach is $4.99 million globally and $11.5 million in the US. The fine is rarely the largest line.

Cybersecurity Sep 15, 2026 • 7 min

Vendor Security Questions for Mixed Data Environments

Vendor security protocol questions for mixed data environments come down to who owns each control across your estate and theirs. CSA added Shared Security Responsibility Model columns to CAIQ v4 because unassigned controls are a leading source of cloud risk.

Cybersecurity Aug 17, 2026 • 8 min

CISA Secure by Demand: Questions for Software Vendors

CISA Secure by Demand (August 2024) is the buyer list: is MFA extra, do default passwords still exist, how do patches install, is there a public VDP. Design is the maker pledge. Demand is what you ask before you sign.

Cybersecurity Aug 6, 2026 • 8 min

Five Eyes Agentic AI Guidance for a Small Business

On 1 May 2026 CISA and allies published agentic AI guidance. For a small business: one low-risk job, its own login, tiny permissions, a person on pay and deletes, and a kill switch.

Cybersecurity Aug 3, 2026 • 7 min

Questions to Ask Business Internet Providers About Cybersecurity

Questions to ask business internet providers about cybersecurity: who can change routing, which logs you can export, the incident clock, MFA on the portal, and credits that land on the invoice. CISA's Demand guide is the shopping list. Get it in writing.

Cybersecurity Jul 8, 2026 • 5 min

The Attack Baseline Every Small Website Already Faces

A newly exposed cloud server gets its first probe in about 52 seconds. Small website attacks are automated and constant, not a big-company problem. Secure-by-construction absorbs the baseline.

Cybersecurity Jun 25, 2026 • 6 min

Software Supply Chain Risk Is a People Problem Now

In 2025 Sonatype counted 454,600 new malicious packages, and the easiest way in was phishing a trusted maintainer. Software supply chain risk is now a people problem, and the fix is verification cheap enough to actually use.