Fergus On:

Information Security. Drawing on experience in a variety of sectors, I prefer to write about pragmatic approaches grounded in real-world usage rather than rigid adherence to specific frameworks. Specialist topics include threat modelling, secure development, and shifting-left.

Feature The Three Theatres: Why security objectives fail before they start

Defining security-related objectives can be hard, but they can prove to be a valuable tool in signaling both strategic intent and an understanding of a team's role in delivering it. What about those objectives that ultimately signal little else than organisational dysfunction though?