Security Shouldn't Be Paywalled.
Most of what a company needs to be safer isn't secret and isn't hard. It's just locked up behind a consulting engagement or a form that wants your email before it'll show you a checklist.
So I'm putting the stuff I'd hand a client on day one out here. Free. No form. Licensed so you can use it commercially.
I'm a cyber risk and technology exec. 30 years across financial services, professional services, and critical infrastructure. Ran technology as CTO for a five-office firm. Most recently SVP in Kroll's Cyber Risk practice, sitting as vCISO for enterprise clients.
I work on the boring half of security. The policies, the controls, the habits. The stuff that turns a strategy deck into something somebody actually does on a Tuesday.
Right now a lot of that is AI. How do you govern GenAI and agents without banning them outright or letting them run loose? Most frameworks haven't caught up yet.
You don't have to outrun the bear. You have to not be the slowest.
But you can't sprint either. Go all out and you burn your team down in two quarters, and the program dies with your enthusiasm. The job is finding a pace you can hold for years.
That's one of eleven things I say a lot. The rest are in PRINCIPLES.md. Everything here comes out of them.
- Cyber Risk and Governance. Building programs, running maturity assessments, reporting to boards. NIST CSF, ISO 27001, CIS, CMMC, HIPAA, PCI, NIST 800-82.
- VCISO Work. Owning cyber strategy and the risk roadmap for enterprise clients, including regulated and critical infrastructure.
- AI Governance. Acceptable use, controls, oversight for GenAI and agentic systems. New risk model. Most frameworks are behind.
- Third-party Risk. TPRM and supply chain. Vendor tiering through remediation.
- Incident Readiness. 50 plus tabletops and IR readiness engagements.
- Enterprise Tech. Took a 175-person firm from all on-prem to cloud-first. Paid off in March 2020 when everyone went home overnight and nothing broke.
| Kroll | SVP, Cyber Risk Advisory Services |
| Roberts Markel Weinberg Butler Hailey PC | Chief Technology Officer |
| Alvarez & Marsal | Manager, Forensic Technology Services |
| Ernst & Young | Senior, Fraud Investigation & Dispute Services |
B.B.A. Management Information Systems, Texas Tech EnCE · RCA · Cellebrite CCLO and CCPA
Security Lessons is the big one. 727 security lessons from stories people already know. The Simpsons, Shakespeare, Star Wars, the KJV Bible, Breaking Bad, real heists, Greek myth, a century of actual incidents. Every one mapped to NIST CSF 2.0 and ISO 27001.
I talk in analogies because framework language doesn't move anybody. That repo is 727 of them.
The rest gets posted as I finish it. Control mappings, policy sets, tabletop scenarios, board briefing structures, assessment scaffolding.
All of it CC BY 4.0. Use it, change it, sell services on top of it. Just say where you got it.
Notes on a Cocktail Napkin in Sharpie Beat Nothing. Everything here is a napkin somebody already scribbled on. Take it and write over it.
Something you need that isn't here? Open an issue and tell me.
- Web: HarrisonWard.com
- LinkedIn: in/harrisonaward
- Security issues: the Security tab on any repo here
Opinions are mine. Not my employers', current or former, and not my clients'. Nothing here comes from a client engagement.


