Writing

Field notes for security leaders, executives, and risk owners.

50 articles across the four phases of GRC, applied to converged security. Drawn from field experience and professional practice.

Above the phases · Principled Performance

Praestantia Principiata: A Philosophy for Work and Life

A personal essay on the Latin motto J Damien Scott has built his career around: Praestantia Principiata, or principled excellence. Drawing on the OCEG GRC framework, the essay traces a through-line from Marine Corps service, law enforcement, commercial diving, and private aviation to converged security consulting — arguing that governance, risk, and compliance is not a compliance function but a discipline for living and working with integrity under pressure.

Principled excellence is not a credential. It is a discipline I choose to practice every day, and I intend to keep choosing it.

50 of 50 articles, newest first

  1. ReviewPost Coverage Is a Protective Audit, Not a Finance TaskAn unfilled post is an unprotected site, and the record that proves the post was filled is the same record that bills the client. Redesigning timekeeping controls, billing reconciliation, contract compliance, post coverage validation, and exception review cut revenue leakage by 95% at a 127-account security enterprise. The finance result was real. The protective result was larger, and it is the one most security leaders never claim.5 min read
  2. ReviewThe After-Action Review Is Where Review HappensExercises produce findings. After-action reviews produce change, and only when the corrective action has an owner, a date, and a place in the next plan. Four conflict-affected operating environments, two country evacuations, and a post-earthquake recovery taught what a rigorous after-action review looks like, who has to own what comes out of it, and how findings feed threat intelligence rather than a filing cabinet.5 min read
  3. ReviewThree Numbers a Protective Program Must ReportActivity counts are not measures. A protective program that reports patrols completed and alerts reviewed is describing effort, and effort is not what leadership is paying for. Three numbers describe effectiveness: detection time, response time, and mitigation effectiveness. Each needs a defined clock and a defined denominator, or the number is theatre. This article sets out how each was defined and moved in practice.5 min read
  4. ReviewThe Internal Audit Is a Protective ControlOperations cannot see its own gaps from inside. An internal audit against a standard and the organization's own documented practice finds what daily work hides, and the closing meeting is where leadership decides what to do about it. Six ISO/IEC 27001 Clause 9.2 audits delivered for client organizations show how the method works, and why protective programs, which are almost never audited this way, need it most.5 min read
  5. LearnThe Books Being Destroyed Are Not Rare. They Are Out of Print.A viral story claimed AI companies are destroying rare books to train their models. Most of that story is true. One word in it is not, and it happens to be the word carrying the emotional weight. The books are not rare. They are out of print. That distinction decides almost everything: what was actually destroyed, whether anything irreplaceable was lost, and whether the governance concern survives scrutiny.8 min read
  6. PerformThe Badge Swipe and the Log Entry Belong to the Same InvestigationA badge log and a data loss alert can describe the same person on the same afternoon and still end up in two different case files. Convergence gets endorsed in a mission statement and then quietly reverts to two departments that report through different chains, hold different budgets, and keep different records.7 min read
  7. PerformThe Warning Was Reported. No One Owned It.Financial institutions already know how to govern a risk they cannot predict. Most have not pointed that machinery at people. Detection is rarely the failure point. Routing is. And routing is a design problem, which means it is ours to fix.7 min read
  8. LearnTSI/EN 50600: The European Standard Quietly Reshaping How Data Centres Are Built, Secured, and JudgedEN 50600 and TÜViT's Trusted Site Infrastructure (TSI) have become the de facto benchmark for data centre quality in Europe. This article explains what they actually require, how the classification system works, and why the standard now sits at the intersection of physical security, NIS2, and the CER Directive.14 min read
  9. AlignWhen the Lights Go Out: What ISO 22301 Actually Does for Your BusinessISO 22301 is the international standard for business continuity management. This article explains what it actually requires, why it belongs in the boardroom rather than the risk register, and how to start applying its thinking before you pursue certification.9 min read
  10. LearnAI Just Took the Front Desk: What the Tier-1 Support Takeover Actually MeansTier-1 customer support — password resets, order status, refunds — is being absorbed by AI agents at scale. Gartner predicts 80% autonomous resolution of common service issues by 2029. But the Klarna reversal and the Air Canada chatbot liability ruling show that speed without accuracy just moves the failure point. This article examines the evidence, its limits, and what the shift means for organizations of every size.7 min read
  11. LearnPhysical AI Is the Next Platform Shift, and Physical Security Should Pay AttentionNVIDIA CEO Jensen Huang's bet on physical AI points to a genuine shift in what artificial intelligence is for: not generating text, but acting in the physical world. For security professionals, this means video analytics that detects threats in real time, autonomous patrol robots covering ground that human officers cannot, and a new category of technical and organizational risk that demands informed vendor scrutiny.7 min read
  12. Principled PerformancePraestantia Principiata: A Philosophy for Work and LifeA personal essay on the Latin motto J Damien Scott has built his career around: Praestantia Principiata, or principled excellence. Drawing on the OCEG GRC framework, the essay traces a through-line from Marine Corps service, law enforcement, commercial diving, and private aviation to converged security consulting — arguing that governance, risk, and compliance is not a compliance function but a discipline for living and working with integrity under pressure.9 min read
  13. AlignA GRC Blueprint for Directing 24/7 Security Operations at ScaleA large, multi-site security operation running around the clock is a live risk management system. Every shift, every post assignment, and every client contract carries obligations that can slip in small ways. This article applies the OCEG Principled Performance framework to a 24/7 security operations context, with a four-step implementation timeline.9 min read
  14. ReviewHow Humans Break Terraform Deployments: A Cautionary TaleInfrastructure as Code has changed how organizations provision cloud resources. Terraform enables repeatable, auditable deployments. But human operators break it in predictable ways. This article maps ten common failure patterns to GRC control gaps, providing both practitioners and governance professionals a shared framework for closing them.10 min read
  15. AlignGRC Beyond the Firewall, part 1Beyond IT: GRC as an Enterprise DisciplineMany people first encounter GRC through cybersecurity, audit, privacy, or IT control work. But GRC is not an IT function. It is an enterprise discipline that helps organizations govern decisions, manage uncertainty, meet obligations, and act with integrity wherever decisions create consequences.9 min read
  16. AlignGRC Beyond the Firewall, part 2GRC in Physical Security: Governing Protection, Duty of Care, and ResilienceIn physical security, risk is not abstract. It has weight, movement, timing, location, and consequence. A guard standing post is not the same thing as a controlled security operation. A protective detail is not the same thing as an executive protection program. The difference is GRC.12 min read
  17. AlignGRC Beyond the Firewall, part 3GRC in Mission-Driven Organizations: Turning Ethical Purpose into Accountable ActionA good mission does not eliminate the need for governance, risk management, and compliance. It increases it. This article applies GRC to a fictional nonprofit to show how mission-driven organizations convert ethical purpose into accountable action through board oversight, donor stewardship, campaign governance, and credible impact reporting.14 min read
  18. LearnAI Can't "Read the Room" Today. But in 2030, It May Know How You Feel Before You Do.Today's AI cannot read a room. But the convergence of neuromorphic computing, quantum biological sensing, and multimodal foundation models suggests that by 2030, AI may be able to detect your emotional state before you consciously register it yourself. The security implications are significant.7 min read
  19. AlignThe Executive Protection Standard: What It Changes, and What It RequiresFor decades, executive protection operated without a recognized national standard. The new ANSI-recognized standard changes that. This article examines what it changes, what it requires, and what the industry must do now to meet the floor it establishes.8 min read
  20. PerformFrom Veteran to Project Manager: Why Military Leadership Fits the Business SectorWhen examining the leadership principles learned through military service, the alignment with project management discipline is unmistakable. This article demonstrates how Marine Corps leadership principles directly strengthen the functional responsibilities of project management as defined by the PMBOK Guide and GAO best practices.15 min read
  21. LearnCritical Infrastructure, part 2What Every Power Company Security Team Should Know About Critical Infrastructure ThreatsEvery security professional understands that threats change. What deserves closer attention is how the threat landscape for energy sector critical infrastructure has evolved from isolated criminal acts into coordinated, ideologically motivated campaigns targeting the physical and cyber systems that sustain national power generation and distribution.8 min read
  22. AlignCritical Infrastructure, part 1From Guard Gates to Grid Resilience: Why Physical Security Is Now Critical Infrastructure Risk ManagementPower-company security has always been about gates, badges, cameras, patrols, and response. But the threat landscape has evolved so fundamentally that physical security must now be understood as critical infrastructure risk management. This article argues that security teams in the electric sector must think in terms of function, consequence, and resilience rather than perimeter alone.10 min read
  23. ReviewCritical Infrastructure, part 3Building a Security Knowledge Base for the Energy Sector: From Lessons Learned to Better DecisionsCritical infrastructure security teams in the energy sector need more than scattered documents and compliance files. They need a structured Book of Knowledge that consolidates operational experience, regulatory requirements, threat intelligence, and lessons learned into a reasoning-capable resource that supports action under pressure.9 min read
  24. LearnComprehensive Regulatory Reference: CFATS, MTSA, and NERC-CIP Physical SecurityA detailed, postgraduate-level analysis of three critical regulatory frameworks governing the physical security of U.S. critical infrastructure: the Chemical Facility Anti-Terrorism Standards, the Maritime Transportation Security Act, and the North American Electric Reliability Corporation Critical Infrastructure Protection standards.14 min read
  25. LearnCFATS After the Sunset: Why Chemical Security Still MattersThe Chemical Facility Anti-Terrorism Standards program has legally lapsed after Congress allowed its statutory authority to expire. This article examines why CFATS-style security remains essential for antiterrorism, what organizations should do during the regulatory gap, and how to maintain chemical security discipline without enforceable federal mandates.12 min read
  26. AlignFrom Stewardship to Enterprise: Why the Modern Family Office Requires Institutional-Grade Risk ManagementThe global wealth landscape is witnessing the rapid institutionalization of private capital. Family offices are evolving from discreet wealth preservation vehicles into sophisticated investment platforms, yet their security and risk management frameworks have not matured concurrently. This article examines the expanding threat landscape and the imperative to adopt enterprise-grade risk management.8 min read
  27. AlignThe Architecture of Trust: Risk Management in the New Era of Branded and Wellness-Centric LivingThe global pipeline for branded residences is projected to exceed 1,000 schemes by 2030. As the value proposition shifts toward wellness, community, and curated lifestyle, the security and risk management implications are significant and largely unaddressed.7 min read
  28. LearnBorderless Capital, Borderless Threats: Evolving Security Strategies for the Ultra-Mobile ExecutiveThe global population of Ultra-High-Net-Worth Individuals has reached 713,626, expanding at an extraordinary rate. As capital and its owners become increasingly mobile, the threat landscape follows. This article examines the security implications of ultra-mobility and what it requires of the protection function.8 min read
  29. LearnDrones in Corporate Security, part 1Article 1 — Why Drones Now Matter to Corporate Executive Protection in Conflict-Affected MarketsDrone technology has moved from a military novelty to a standard operational tool in conflict-affected environments. For corporate executive protection programs operating in fragile markets, this shift changes the geometry of exposure in ways that traditional ground-focused security architectures were not designed to address.8 min read
  30. PerformDrones in Corporate Security, part 2Article 2 — Aerial Advance Work: Using Drones for Route Reconnaissance, Venue Assessment, and Movement OverwatchAerial advance work is not a replacement for ground-level advance work. It is a complement that addresses the specific limitations of ground-based reconnaissance: the inability to see over obstacles, the time required to physically check extended routes, and the difficulty of maintaining continuous situational awareness during a movement.9 min read
  31. LearnDrones in Corporate Security, part 3Article 3 — Drones as a Protective Intelligence Layer: Pattern-of-Life, Anomaly Detection, and Threat MappingThe most durable value of drone integration in corporate security is not the dramatic intervention. It is the quiet, systematic collection of pattern-of-life data that makes the operating environment legible. This article examines how drones function as a protective intelligence layer when integrated with disciplined analytic processes.9 min read
  32. PerformDrones in Corporate Security, part 4Article 4 — Beyond the Compound Wall: Drone Security for Camps, Compounds, and Temporary Operating SitesSemi-static sites present a distinct security challenge. Their perimeters are fixed but their threat environments are dynamic. Traditional perimeter-focused security architectures leave significant gaps in the overhead dimension. This article examines how drone integration addresses those gaps.8 min read
  33. LearnDrones in Corporate Security, part 5Article 5 — The Adversary Has Drones Too: What Hostile Aerial Threats Mean for Executive ProtectionThe same technology that enhances corporate security programs can be turned against them. Hostile drone use against corporate targets is no longer a theoretical risk. This article examines the kinetic and non-kinetic threat pathways, why hostile drones are difficult to defend against, and what this means for executive protection planning.8 min read
  34. PerformDrones in Corporate Security, part 6Article 6 — Counter UAS for the Private Sector: What Is Useful, Lawful, and Realistic in High-Risk EnvironmentsCounter-UAS is a rapidly evolving field that has generated significant vendor activity and considerable confusion about what private-sector actors can lawfully and practically deploy. This article examines what is actually useful, what is legally permissible, and what realistic success looks like for corporate security programs.9 min read
  35. ReviewShould Security Investigators Play a Larger Role in Risk Management Audits in Global MedTech?A mature security function should not be judged only by how well it prevents theft, violence, or data loss. In a global medical device company, the stronger test is whether it facilitates the mission. This article makes the case for the Office of Security Risk Management as an enterprise capability that strengthens ISO 14971 compliance and audit follow-through.9 min read
  36. AlignIntelligence Operations, part 9Bridging the Silos: Protective Intelligence as the Core of Insider Threat ProgramsOrganizations with a formal, cross-functional insider risk management program avoid an average of seven major insider incidents per year, resulting in approximately $8.2 million in avoided breach costs. Yet only 63% of organizations currently operate such a program. The structural failure is not a lack of data. It is a failure to connect the data that already exists across organizational silos.8 min read
  37. AlignApplying ISO 31000 Under PressureWhat a risk management standard actually looks like when the country is on fire. Drawing from seven years of experience in Haiti, this article demonstrates how ISO 31000's framework for managing uncertainty translates into life-or-death operational decisions in one of the world's most complex security environments.14 min read
  38. LearnNavigating the Global Maze: Key Challenges for Country Managers on International Security AssignmentsAs organizations expand their operations across borders, the role of a Country Manager in overseeing international security and intelligence assignments has never been more critical. Success hinges on mastering six foundational factors: legal and political realities, economic stability, security threats, geographic considerations, cultural competence, and infrastructure.7 min read
  39. LearnHavana Syndrome (AHI): Comprehensive Intelligence BriefingA comprehensive intelligence briefing for executive protection professionals on Havana Syndrome, officially designated Anomalous Health Incidents. Covers the evidence for directed-energy weapons, the DHS acquisition of a Russian-component pulsed-RF device, protective measures, and incident response protocols for security teams.12 min read
  40. AlignFrom Protective Detail to Enterprise Risk Program: Applying GRC to Executive ProtectionExecutive Protection should be governed as an enterprise risk function, not treated as a standalone protective service. When Governance, Risk, and Compliance is applied to an integrated EP program, it gives leaders a disciplined way to define authority, align protective decisions with enterprise risk appetite, meet duty-of-care and compliance obligations, and create accountable, auditable protection outcomes.12 min read
  41. LearnIntelligence Operations, part 1Moving "Left of Boom": The Strategic Value of Protective IntelligenceExecutive targeting incidents doubled in 2025. A corporate security program that relies solely on gates, guards, and guns is not just outdated. It is a critical vulnerability. Protective intelligence moves the organization left of boom by identifying, assessing, and dismantling threats before they cross the threshold of the enterprise.7 min read
  42. AlignIntelligence Operations, part 2The Intelligence-Led Executive Protection DetailThe era of the visible deterrent is over. The modern executive protection detail must evolve from a logistics-heavy guarding function into a dynamic, intelligence-driven operation. It is no longer about how close you stand to the principal. It is about how far ahead you can see.8 min read
  43. LearnIntelligence Operations, part 3Decoding the Pathway to Violence: Behavioral Threat Assessment in Corporate SettingsTargeted violence is rarely spontaneous. It is the result of an understandable, evolving, and often discernible process of thinking, behavior, and preparation. Understanding the Pathway to Violence allows corporate security programs to identify warning behaviors and intervene before an attack occurs.9 min read
  44. LearnIntelligence Operations, part 4Mastering the Digital Footprint: OSINT Tradecraft for Executive ProtectionNinety-eight percent of executives have their property addresses or sensitive personal information available online. If corporate security teams are not conducting their own digital reconnaissance, they are operating blind against an adversary who is not. OSINT is the earliest possible warning system in the modern protective intelligence arsenal.8 min read
  45. PerformA Linchpin of Executive Security: Securing the Principal Mobile NumberA principal’s primary mobile number frequently serves as the linchpin for both physical and cyber security. It controls residential alarm authentication, smart home access, emergency notifications, and real-time location services. Because much of this infrastructure relies on SMS-based multi-factor authentication, it remains highly susceptible to SIM swapping and social engineering.9 min read
  46. PerformIntelligence Operations, part 5The Adversary Within: Insider Threat Detection and MitigationThe most dangerous adversary is often already inside the perimeter. Insider threats account for an average of $19.5 million in annual losses per organization, yet most corporate security programs remain structurally oriented toward external threats. Protective Intelligence provides the connective tissue that links behavioral indicators across HR, cybersecurity, and physical security into a unified detection and mitigation framework.9 min read
  47. LearnIntelligence Operations, part 6The AI Force Multiplier: Technology's Role in Modern Threat IntelligenceThe modern corporate security apparatus is drowning in data. GSOCs monitor thousands of cameras, access control logs, travel itineraries, and open-source intelligence feeds simultaneously. Alert fatigue is a structural crisis, not a personnel problem. AI is not a replacement for human judgment; it is an analytic force multiplier that automates collection, triages the noise, and surfaces the signal.10 min read
  48. AlignIntelligence Operations, part 7Navigating the Gray Areas: Ethics, Privacy, and Legal Compliance in IntelligenceThe difference between effective intelligence gathering and an unlawful invasion of privacy often hinges on how data is collected and subsequently used, not merely what data is collected. A Protective Intelligence program that operates without strict ethical and legal guardrails is not a security asset; it is a liability.8 min read
  49. ReviewIntelligence Operations, part 8Proving the Value: Metrics, KPIs, and Board-Level Reporting for Security ProgramsExecutive protection and Protective Intelligence programs are among the most closely scrutinized areas of any corporate security budget. When these programs operate at their best, nothing happens. That quiet success creates a persistent perception problem. Programs that cannot articulate their value in the language of the business are the first to face reduction.10 min read
  50. PerformSurveillance: Powering Your OperationsA practical guide to portable power solutions for surveillance operations. Covers the evolution from heavy deep-cycle battery banks to modern lightweight lithium power stations that can power cameras, computers, drones, and accessories from a single transportable unit.3 min read

Field Notes · by email

One email when a new article publishes. Nothing else.

Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes