For CTOs
Security for CTOs and engineering leaders: security questionnaires, SOC 2 without derailing the roadmap, shadow IT, and pipeline risk.
Guides
-
· Jon Rose · 4 min read
Every Startup Says 'Security Is a Priority.' Here's What That Actually Means at the Infrastructure Level
Enterprise buyers ignore "we take security seriously." Learn the infrastructure decisions that close deals, from encryption to audit logs.
-
· Jon Rose · 4 min read
Your Next Enterprise Deal Will Die in the Security Questionnaire
Learn how CTOs at growth-stage software companies can build a security questionnaire process that wins enterprise deals without a dedicated security team.
-
· Jon Rose · 4 min read
The AWS Bill Has a Security Problem Nobody's Looking At
Your AWS bill hides security risks. Learn why cloud cost optimization and cloud security are the same conversation for software company CTOs.
-
· Jon Rose · 4 min read
What Your Engineers Won't Tell You About Shadow IT
Engineering teams adopt tools faster than security can review them. Learn how to manage shadow IT risk without slowing your developers down.
-
· Jon Rose · 4 min read
SOC 2 Is Engineering's Problem Now
How CTOs at mid-market software companies can implement SOC 2 controls without derailing the product roadmap. Automate evidence, pick the right controls.
-
· Jon Rose · 4 min read
The Security Debt Hiding in Your CI/CD Pipeline
CI/CD security risks accumulate silently. Learn how to audit pipeline debt before it blocks a deal or causes an incident.
-
· Jon Rose · 6 min read
CTO Security Responsibilities: You're the CISO Until You Hire One
Most CTOs own security by default, and focus on the wrong parts. Learn when to hand off and what happens if you wait too long.
-
· Jon Rose · 1 min read
We Use That?!
Every company uses third-party software. You don't have to review the code of everything, but you do have to know the risks to prioritize and manage them.
-
· Jon Rose · 4 min read
Why Do Software Engineers Ignore Security Issues?
Why is it, even in innovative companies, that development teams tend to ignore information security issues?
Practical security guidance for growing companies: building security programs, passing customer security reviews, and making smart security decisions.