Northwoods Security Notes

Latest thoughts on startup security, vCISO leadership, and risk.

Why Your Incident Response Plan Doesn't Work (Yet)

Tabletop exercises cut breach timelines by 76 days. Here's how to run one that actually changes your security posture.

The Plan You Hope You Never Use

Most startup IR plans are compliance artifacts, not decision-making tools. Five pre-made decisions matter more than forty pages of procedures.

The SOC 2 Survival Guide: What Founders Get Wrong

SOC 2 engagements grew 49% in three years - but most startup guidance skips the hard parts. Five mistakes from the CISO side of the table.

What Enterprise Customers Actually Check in Security Reviews

Most startups treat the 300-question security questionnaire as a compliance exam. It's a risk triage -- and only 20% of those questions decide the deal.

When to Hire Your First Full-Time Security Person

In 2019, security was a cost center. In 2026, it's a revenue gate. Five business triggers that tell you when to hire — none involve headcount.

Security Debt: Why Seed-Stage Shortcuts Cost 10x

82% of organizations carry security debt. For startups, every shortcut compounds — and the bill arrives at the worst possible moment.

The Amnesiac Intern

Why AI Agents Need External Memory

The AI Paradox: Why Hyper-Efficiency Could Mean More Human Work

How a 19th-century economic theory can inform our thinking about AI and the future of work.

When AI Became the Weapon

Lessons from the First Major AI-Powered Cyberattack

You already hired your first security leader.

Surprise: they think they’re your DevOps engineer. 🛡️

DeepSeek: A cautionary tale

How to separate the hype from the risk around DeepSeek AI

The First 10 Security Controls for a Seed-Stage Team

Ten controls you can ship in weeks—not quarters—with clear owners and first steps.

Welcome to Northwoods Security Notes

Plain-English security for Seed–Series B teams. Short, pragmatic posts you can act on this week.