Writing & thinking
Long-form thinking on cybersecurity, risk, consulting, and the things that connect them.
- What most organisations get wrong about threat intelligence — Most companies treat threat intelligence as a feed they subscribe to and forget about. The real value comes from understanding how threats specifically apply to your environment.
- Why the human layer is the hardest security problem to solve — Most security budgets invest heavily in technical controls. The human layer sits near the bottom of the list. That's the wrong order of priorities.
- Why your biggest security risk is probably someone you trust — 83% of organisations reported at least one insider attack in the last year. The breach that actually hurts tends to start much closer to home.
- The Gulf has mandated cybersecurity awareness training. Nobody told the training to speak Arabic. — Every enterprise in the GCC is now legally required to train its people on cybersecurity. The platforms doing that training were built for someone else entirely.
- We keep asking the wrong question about AI — AI doesn't have to be correct to be persuasive. Every AI failure I've studied reaches the same moment: a person looks at an output, accepts it as credible, and acts on it.
- Zero Trust can't tell whether you're being manipulated — Zero Trust verifies who you are and what you're allowed to do. It can't tell you whether an authorised person is being quietly persuaded by a confident AI to make a bad decision — that's a judgment problem, not an identity one.
- Auditable by design: what open source teaches about securing agentic AI — As enterprises hand real authority to AI agents, the security question is the same one open source answered decades ago: can you inspect what you are trusting?
- Securing borderless money: the cyber risk behind the stablecoin super bank — When onboarding takes a minute and money is self-custodial, human risk becomes the primary attack vector, not the rails. What regional fintechs should harden first.
- Choose the partner who completes you: a cross-interview read on co-founder fit — Two very different builders land on the same rule: complementary partners beat mirror-image partners, and healthy friction is a feature. The same logic builds resilient security teams.
- Breaking the standard: human-centric thinking from architecture to security — Nouf Al-Khubaizi's rule that standards are written by people, meant to be broken for the human, is not anti-rigor. It is a diagnosis of why security awareness fails.