Writing, speaking & open source
Where I've written down or said out loud the things I keep having to explain in person.
LinkedIn, 2026. Many business leaders think their CISO is underperforming. Usually it isn't a performance problem, it's a visibility one — the work that prevents incidents leaves no trace, and the decisions that matter most are the ones nobody sees being made. Written after watching good security leaders burn out while being told they weren't adding value.
BSides Melbourne 2024, career track. On neurodiversity in cyber security workplaces — the discrimination, the accommodations that actually help, and why so many neurodiverse people in this field have a thirst for learning, knowledge and complexity. Plus the career lessons that turned out to apply to everyone.
A free, game-based threat modelling workshop, originally developed with colleagues at MYOB and iterated on since. Ninety minutes, up to ten people: engineers walk through their architecture, participants roleplay threat actors and brainstorm attacks, then the group prioritises, risk-assesses and decides what to actually do. Includes printable threat actor cards.
It's designed to solve a specific problem: security assessments that happen to engineering teams don't change behaviour, but ones engineering teams run themselves do. Teams that ran it went on to raise more security improvements on their own initiative.