
The risk was documented. It had a score.It had a description.It even had recommended controls. But no one owned it....
This site documents my progression from learner to human-centered cybersecurity

The risk was documented. It had a score.It had a description.It even had recommended controls. But no one owned it....

Spreadsheets are powerful. But they are also fragile. When I first worked on an ISO 27001-aligned risk register, it looked...

Amara stared at the spreadsheet longer than she expected. Rows of risks.Columns for likelihood, impact, controls, ownership.Numbers that looked simple...

Amara followed the procedure. At least, she tried to. The manual said one thing.The situation in front of her was...

Amara didn’t miss a step because she didn’t care. She missed it because it was early, she was tired, and...

One of the biggest lessons I am learning as I explore cloud security through a GRC lens is this: Cloud...