IT Leadership Training: How to Develop Real IT Leaders

Every organization I’ve watched promote a strong engineer into a leadership role makes the same silent bet: that leadership will just happen, the way it happened for whoever’s in charge now. It usually doesn’t. IT leadership training exists precisely because the skills that get someone promoted — technical mastery, fast problem-solving — are almost never […]

How to Protect Data on a Mobile Device (Complete Guide)

Your phone is almost certainly the least-protected device with the most sensitive access in your life — email, banking, work systems, photos, and the “forgot password” reset for nearly every account you own, all reachable from one small glass rectangle you’ve probably left on a restaurant table at least once. So let’s fix that properly. […]

How Does Ransomware Spread? Detection & the Pay Decision

Ransomware is the incident every leader quietly dreads, and most of the dread comes from not understanding the mechanics. So let’s fix that. How does ransomware spread, how do you catch it before the encryption starts, and — the question nobody wants to answer in the moment — should you ever pay? I’ll take those […]

Data Protection Strategy: A Business Leader’s Guide

Data protection strategy — proportional protection for the data that matters most — LeadingCyber

Here’s a pattern I’ve seen across every organization I’ve worked with: everyone agrees data is “the crown jewels,” and almost nobody can tell you where all of it lives, who can touch it, or when it was last backed up. A data protection strategy is the fix for that gap — not another tool purchase, […]

Network Security Assessment: The Complete Guide (2026)

Network security assessment — getting the full map of the network back — LeadingCyber

Every network I’ve ever assessed had at least one surprise in it — a forgotten remote-access path, a switch running default credentials, a “temporary” firewall rule from 2021. Not because the teams were careless, but because networks grow the way cities do: one reasonable decision at a time, until nobody holds the full map anymore. […]

How to Prepare for a Cyber Attack: A Leader’s Checklist

How to prepare for a cyber attack — readiness decided before the incident — LeadingCyber

I spent years in public-sector and utility IT, where emergency preparedness isn’t a slide deck — it’s a way of operating. Storms, outages, equipment failures: you plan for them because they’re coming whether you plan or not. Cyber attacks belong in exactly that category. So when people ask how to prepare for a cyber attack, […]

Information Security Policy: How to Write One (+ Template)

Every audit, every compliance framework, every cyber insurance application asks the same first question: do you have an information security policy? And here’s what two decades around IT organizations has taught me — most companies technically do. It’s forty pages long, written in 2019, and nobody below the IT director has ever read it. That’s […]

What Is a CISO? Role, Salary, and How to Become One

What is a CISO — the executive who owns security risk, strategy, and the 2 a.m. phone call — LeadingCyber

Ask five people what is a CISO and you’ll get five answers: “the security boss,” “the person who says no,” “the one who gets fired after the breach.” All three contain a grain of truth, and none of them capture the job. The CISO has become one of the most consequential — and most misunderstood […]

Virtual CISO (vCISO): What It Is and When to Hire One

Virtual CISO — executive security leadership without the executive salary — LeadingCyber

Somewhere between “our IT person handles security” and “we have a full executive security team” sits most of the business world — big enough to be a target, not big enough to justify a $250,000+ security executive. That gap is exactly what the virtual CISO model exists to fill. And in my years around mid-size […]

Risk-Based Vulnerability Management: A Practical Guide

Funnel infographic showing risk based vulnerability management filtering thousands of scan findings down to the few that pose real risk — LeadingCyber

Here’s an uncomfortable number: research has consistently found that only a small fraction of published vulnerabilities — mid-single digits, percent-wise — ever get exploited in the wild. Yet most security teams treat all 40,000 findings on the scan report as equally urgent, burn out chasing CVSS scores, and still miss the one flaw attackers actually […]