The four phases
Review
Measure, test, audit, feed back
Assess protective effectiveness and gaps. Test controls and detection capabilities. Measure detection time, response time, and mitigation effectiveness. Audit compliance with protective standards and protocols. Feed findings into threat intelligence and capability planning. Refine threat models and protective measures based on what the environment teaches you.
What this phase produces
- Detection time
- Response time
- Mitigation effectiveness
- Compliance with protective standards
- Findings fed back into Learn
Writing
8 articles on Review
Post Coverage Is a Protective Audit, Not a Finance Task
An unfilled post is an unprotected site, and the record that proves the post was filled is the same record that bills the client. Redesigning timekeeping controls, billing reconciliation, contract compliance, post coverage validation, and exception review cut revenue leakage by 95% at a 127-account security enterprise. The finance result was real. The protective result was larger, and it is the one most security leaders never claim.
5 min readThe After-Action Review Is Where Review Happens
Exercises produce findings. After-action reviews produce change, and only when the corrective action has an owner, a date, and a place in the next plan. Four conflict-affected operating environments, two country evacuations, and a post-earthquake recovery taught what a rigorous after-action review looks like, who has to own what comes out of it, and how findings feed threat intelligence rather than a filing cabinet.
5 min readThree Numbers a Protective Program Must Report
Activity counts are not measures. A protective program that reports patrols completed and alerts reviewed is describing effort, and effort is not what leadership is paying for. Three numbers describe effectiveness: detection time, response time, and mitigation effectiveness. Each needs a defined clock and a defined denominator, or the number is theatre. This article sets out how each was defined and moved in practice.
5 min readThe Internal Audit Is a Protective Control
Operations cannot see its own gaps from inside. An internal audit against a standard and the organization's own documented practice finds what daily work hides, and the closing meeting is where leadership decides what to do about it. Six ISO/IEC 27001 Clause 9.2 audits delivered for client organizations show how the method works, and why protective programs, which are almost never audited this way, need it most.
5 min readHow Humans Break Terraform Deployments: A Cautionary Tale
Infrastructure as Code has changed how organizations provision cloud resources. Terraform enables repeatable, auditable deployments. But human operators break it in predictable ways. This article maps ten common failure patterns to GRC control gaps, providing both practitioners and governance professionals a shared framework for closing them.
10 min read· part 3
Building a Security Knowledge Base for the Energy Sector: From Lessons Learned to Better Decisions
Critical infrastructure security teams in the energy sector need more than scattered documents and compliance files. They need a structured Book of Knowledge that consolidates operational experience, regulatory requirements, threat intelligence, and lessons learned into a reasoning-capable resource that supports action under pressure.
9 min readShould Security Investigators Play a Larger Role in Risk Management Audits in Global MedTech?
A mature security function should not be judged only by how well it prevents theft, violence, or data loss. In a global medical device company, the stronger test is whether it facilitates the mission. This article makes the case for the Office of Security Risk Management as an enterprise capability that strengthens ISO 14971 compliance and audit follow-through.
9 min read· part 8
Proving the Value: Metrics, KPIs, and Board-Level Reporting for Security Programs
Executive protection and Protective Intelligence programs are among the most closely scrutinized areas of any corporate security budget. When these programs operate at their best, nothing happens. That quiet success creates a persistent perception problem. Programs that cannot articulate their value in the language of the business are the first to face reduction.
10 min readServices that deliver Review
How the Trusted Advisor delivers this phase
The Trusted Advisor delivers Review through audits and measurement: ISO/IEC 27001 internal audits, security program audits, and the metrics and board reporting that show what detection, response, and mitigation actually achieved.
Talk to the Trusted AdvisorRisk posture
Security audits, assessments, and surveys
Structured reviews of facilities, events, teams, and programs to identify practical gaps and strengthen protective posture.
Portfolio evidence