How the pieces fit —
and what to do when they don't.
The hardest problems in security aren't technical. I think through what that means for the people building programs and the founders building the companies behind them.
Follow the thinkingWhat's coming
Six pieces in progress
These are the questions I'm working through — on how integrated security programs actually get built, and on the commercial decisions that determine whether security companies survive. Some are solo analysis. Several are co-authored with practitioners I've worked alongside.
When to Sell
The Hiring Fraud Nobody's Naming
AI Can Break Your Software. Now What?
When to Stay
Genuine Opportunity or Noise
Work with me
Advisory
If you're a security leader looking for a trusted advisor with skin in the game — introductions, strategy, or a second opinion on a decision — that's what Passarel is for.
connect@passarel.com →Staris AI
If your team is still relying on point-in-time pentesting, there's a better model. Staris delivers continuous attack path validation — built for security teams that want to stay ahead, not just catch up.
staris.tech/contact →Get it in your inbox
One thesis.
Every other Tuesday.
One problem, one framework, one implication for how you build or sell. Written for security leaders who already know the landscape and founders who are living inside it.
No spam. Unsubscribe any time.