Essays and breakdowns for people who design and run security systems: Zero Trust and privileged access, workforce and endpoint guardrails, detection engineering, and frameworks like NIST CSF, CDM, and MITRE D3FEND. Recent work focuses on securing AI coding agents (skill and supply-chain risk, sandboxed runtimes) plus credential and software supply-chain failures. Earlier writing includes high-profile breach and architecture case studies (for example Change Healthcare ransomware and the Duolingo API exposure), cryptography, microsegmentation, and passwordless authentication.