• Decision Velocity Begins with Trust

    In real incidents, the biggest delays usually don’t come from the tools or the playbooks. Your team can often figure out what needs to happen. What’s harder is gaining the trust across organizational boundaries to make decisions and act quickly when every second counts. The capacity of an organization to move from information to decision…

  • Trust Before Technology

    Let’s be honest—most organizations treat incident response like a purely technical exercise: alerts, logs, endpoints, playbooks, and containment steps. But when a real crisis hits, the hardest part usually isn’t figuring out what to do. It’s having the trust and authority to move fast enough to actually do it. Your team might already know which…

  • Detection Is Not Enough: Decision Velocity Is the Next Frontier

    As adversaries move laterally in seconds, detection alone isn’t enough. We must also optimize how fast we can decide. Recently, I wrote that IR must evolve from an episodic process to a continuous operating capability—because modern threats outpace traditional structures. Speed isn’t generated only in the SOC. It’s forged in governance. We’ve invested years in…

  • 27 Seconds: Why Incident Response Must Become Continuous

    27 seconds. That was the fastest observed breakout time for an intrusion in 2025. Not 27 minutes. Not 27 hours. 27 seconds.