# [ security.voyage ] > Exploring the edge of cybersecurity. Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### About URL: https://security.voyage/about/ Last updated: 2026-03-28T23:25:46.000Z ## Hi, I'm Dominic I work in cybersecurity and write about designing security practices that hold up under real-world constraints. ![](https://storage.ghost.io/c/f9/b3/f9b3c20e-9de8-4f31-bb8a-5314ab6e62c7/content/images/2026/03/Dominic.jpg) Security.Voyage is meant to serve as a resource for practitioners and executives who care about clarity, depth, and the long-term direction of the cybersecurity field. The site explores how security systems evolve in both technical and human terms. Each piece aims to capture the “why” behind the “what,” examining the decisions, trade-offs, and mindset shifts that shape modern security work. Although written by one person, the intent is collective. The goal is to build a space where engineers, researchers, builders, and leaders can engage with thoughtful perspectives on security’s ongoing evolution. My qualifications include Education: - MS in Information Security - BS in Information Technology Certifications: - Certified Information Systems Security Professional (CISSP) - Certified Information Security Manager (CISM) - Certified Information Systems Auditor (CISA) - Certified in Risk and Information Systems Control (CRISC) - Certified Information Privacy Professional / Europe (CIPP/E) - AWS Certified Solutions Architect - Associate - CompTIA Linux+ - CompTIA Network+ - CompTIA Security+ - CompTIA A+ - Amateur Radio License - General Class Affilations: - FBI Infragard - Information Systems Security Association (ISSA) - Information Systems Audit and Control Association (ISACA) - International Information System Security Certification Consortium (ISC)2 - International Association of Privacy Professionals (IAPP) - Center for Internet security (CIS) ### Contact URL: https://security.voyage/contact/ Last updated: 2026-03-28T23:32:00.000Z This blog exists to share ideas and practical resources with the cybersecurity community. If you have questions, insights, or feedback about my posts or the materials I’ve shared, I’d like to hear from you. I welcome thoughtful discussions, corrections, and new perspectives that move the field forward. If you’d like to interview me, have me on your podcast, or invite me to speak at an event, please include a short description of your audience and topic. If you'd prefer you can email me at dominic@security.voyage Your Name Email Address Message ### Blog URL: https://security.voyage/blog/ Last updated: 2025-11-10T05:57:13.000Z _No content available._ ### Consulting URL: https://security.voyage/consulting/ Last updated: 2025-11-10T05:48:47.000Z _No content available._ ### Privacy Policy URL: https://security.voyage/privacy-policy/ Last updated: 2025-11-10T05:49:08.000Z _No content available._ ### Featured Posts URL: https://security.voyage/featured-posts/ Last updated: 2025-11-10T05:56:25.000Z _No content available._ ### Welcome to Security.Voyage URL: https://security.voyage/hero/ Last updated: 2026-03-29T02:24:43.000Z _No content available._ ### Qualifications URL: https://security.voyage/qualifications/ Last updated: 2026-01-25T23:50:51.000Z _No content available._ ### CISSP URL: https://security.voyage/cissp/ Last updated: 2026-01-26T04:02:07.000Z _No content available._ ## Posts ### AI changes the question, not the answer URL: https://security.voyage/cheap-intelligence-changes-the-question-not-the-answer/ Last updated: 2026-03-29T02:36:19.000Z What your company built before may not matter anymore. When a technological shift is big enough, past product-market fit stops being a roadmap. It becomes history. The shift from candle to lightbulb wasn't about making a better flame. Yet a lot of companies are treating AI that way. They're trying to make existing processes faster: AI that writes emails. AI that summarizes meetings. AI that fills out CRM fields. That's optimization. It's the electric candle. Real shifts change the question entirely. If teleportation was invented today, would we be reinventing how we travel, or wasting time building a teleporting car? AI might be closer to that kind of change. Which means the real question isn't: "How do we add AI to what we already do?" It's "What becomes possible now that intelligence is cheap?" ### Test Post 2 URL: https://security.voyage/test-post-2/ Last updated: 2025-11-17T04:39:03.000Z This is a second test post ### Political pressure is starting to affect cybersecurity vendors URL: https://security.voyage/political-pressure-is-starting-to-affect-cybersecurity-tools/ Last updated: 2025-11-17T04:37:56.000Z Are you confident that the cybersecurity solutions you rely on are free from political influence? In recent developments, the US government’s decision to tie security clearances to specific political positions has raised concerns in the cybersecurity community. As a seasoned security expert, I see a significant risk here. Many American cybersecurity firms, essential for reliable threat intelligence, could be pressured into taking political positions to secure their clearances. This could mean a loss of trust for many enterprise CISOs who depend on these vendors for unbiased, accurate information. Over time, the business impact may be severe if key threat intelligence providers are viewed as subject to political agendas, leading to potential shifts in vendor trust and relationship disruptions. In my view, executives should be aware of this evolving landscape. Conducting robust assessments of vendor independence will help protect enterprise risk and maintain operational confidence. ### The ultimate failure of risk management URL: https://security.voyage/the-ultimate-failure-of-risk-management/ Last updated: 2025-11-17T04:37:14.000Z Today Vox published a video called “Why the Titanic didn't have enough lifeboats” and I encourage everyone to watch it! The video can be found here ([https://www.youtube.com/watch?v=K64wRD8eaus](https://www.youtube.com/watch?v=K64wRD8eaus&ref=security.voyage)). In the video, Vox highlights how outdated British regulations allowed the Titanic to leave port with an insufficient number of lifeboats. There are two very important takeaways from the sinking of the Titanic that all business leaders need to recognize. The first takeaway; risk management is not optional or notional. Done right, it is a defined process based on quantitative (or semi-quantitative) metrics. Calculating risk can be done in many ways but the most common is “Risk = Severity x Likelihood”. The Titanic serves as the ultimate failure of risk management. The builders of the Titanic (Harland & Wolff) properly calculated that the likelihood of the ship sinking was low, given many of the mitigations in place. Even if the ship did start sinking, they assumed the telegraph could be used to call for rescue before lives were put in danger. However, they failed to properly calculate the severity. Since the ultimate cost of a sinking ship needs to be measured in human lives, the severity metric should have been of the highest magnitude. If Harland & Wolff had properly assessed the risk, they would have ended up realizing that despite the low likelihood of the ship sinking, the very high severity would have resulted in a High risk (High = Low x Very High). Once they realized the risk was still high, they would have implemented additional mitigating controls…like adding more lifeboats, which they did to the Titanic’s sister ship, right after the Titanic sank. For clarification, different groups use different risk calculation tables but when lives are at play, the calculation tables tend to assign greater risk values. For example, the US Army’s Deliberate Risk Management (DRM) process uses the risk calculation table above. Please note I’ve oversimplified this whole process, and this should not be used as an example of effective risk management but rather a primer. I encourage you to learn more at https://www.fairinstitute.org/ ![](https://storage.ghost.io/c/f9/b3/f9b3c20e-9de8-4f31-bb8a-5314ab6e62c7/content/images/2025/11/image.png) US Army’s Deliberate Risk Management (DRM) Matrix The second takeaway is that being compliant does not mean you are secure or safe. Speaking in terms of cybersecurity, compliance can often represent a subset of security and risk mitigation, but regulations often fail to account for all scenarios or stay up-to-date. While some compliance frameworks mandate risk management programs, these requirements are often overlooked or underdeveloped. Compliance should be seen as an additional requirement on top of minimal viable security and risk management, and not an alternative. Next time someone tells you their product is HIPAA or PCI compliant, ask them if they know how well being compliant worked out for the passengers of the Titanic. To summarize, a good risk management program would have likely saved the lives of many on that ship. It's too late to fix the Titanic but it's not too late to fix your organization. ### Test Post URL: https://security.voyage/test-post/ Last updated: 2025-11-17T04:38:24.000Z This is a test post