Northwoods Security Notes

Latest thoughts on startup security, vCISO leadership, and risk.

Your Certificate Got You in the Room. Now They Start Asking.

About a third of breaches arrive through a vendor, so a SOC 2 or ISO 27001 badge only gets you in the room. Here is what buyers ask next.

Your Patch Window Is Now Your Attack Window

Exploits now hit in hours while the median fix still takes 43 days. A CISO's read for founders who can't out-patch the internet.

The Vendor Who Disappears

Anthropic's Fable lockout proved a closed AI model can be switched off by a government overnight - for who you are, not what you did. It's a sovereignty risk, not a vendor one.

Are You Writing Job Descriptions for People Who Don't Exist?

Startup security postings stack three careers into one role - then sit open for months. Staff the dominant third, buy or rent the rest.

You Have ISO 27001. Do You Still Need SOC 2?

Where ISO 27001 maps cleanly to SOC 2, where it doesn't, and how to bridge the gap without rebuilding your security program.

Resilience is Key to Startup Survival

So treat recovery measures like your business life depends on them - because it does.

The Credentials Nobody's Managing

Non-human identities outnumber employees 82-to-1, and 91% survive off-boarding. A four-step audit to find the ghost credentials in your stack.

The Biggest Breach Study of the Year Has a Startup Problem

Verizon's annual breach study analyzed 22,000 incidents. Three findings hit startups harder - and the commentary skips them.

Fractional CISO vs. Full-Time CISO: Which Does Your Startup Need?

Small/midmarket CISOs average $415K in total comp. Fractional runs $5K-$15K/month. But the real question isn't cost - it's stage.

Put Away Your Hammer - That AI Vendor is Not a Nail

Your SOC 2 checklist was built for something entirely different. If you don't want to wind up like the 97% of AI breach victims who lacked proper AI controls, here are the tools you need.

What Your Board Will Ask About AI Security

AI moved from pilot to board agenda faster than most founders expected. Three questions are coming - and the answers reveal more than you think.

Why Your Incident Response Plan Doesn't Work (Yet)

Tabletop exercises cut breach timelines by 76 days. Here's how to run one that actually changes your security posture.

The Plan You Hope You Never Use

Most startup IR plans are compliance artifacts, not decision-making tools. Five pre-made decisions matter more than forty pages of procedures.

The SOC 2 Survival Guide: What Founders Get Wrong

SOC 2 engagements grew 49% in three years - but most startup guidance skips the hard parts. Five mistakes from the CISO side of the table.

What Enterprise Customers Actually Check in Security Reviews

Most startups treat the 300-question security questionnaire as a compliance exam. It's a risk triage -- and only 20% of those questions decide the deal.

When to Hire Your First Full-Time Security Person

In 2019, security was a cost center. In 2026, it's a revenue gate. Five business triggers that tell you when to hire — none involve headcount.

Security Debt: Why Seed-Stage Shortcuts Cost 10x

82% of organizations carry security debt. For startups, every shortcut compounds — and the bill arrives at the worst possible moment.

The Amnesiac Intern

Why AI Agents Need External Memory

The AI Paradox: Why Hyper-Efficiency Could Mean More Human Work

How a 19th-century economic theory can inform our thinking about AI and the future of work.