Sean D. Mack

Sean D. Mack

Creator
0 followers

CIO/CISO and author (Enterprise Security: A Data‑Centric Approach) who discusses real‑world cybersecurity leadership conversations and enterprise risk focus areas.

Fractional CISO: Full Accountability, 24/7 Availability
SocialFeb 19, 2026

Fractional CISO: Full Accountability, 24/7 Availability

Fractional CISO does not mean fractional accountability. Every client I work with has my cell phone. Security incidents do not respect office hours, and advisory only works if there is shared ownership.

By Sean D. Mack
GRC Tools Need Business‑focused Risk, Not Spreadsheet Tickets
SocialFeb 18, 2026

GRC Tools Need Business‑focused Risk, Not Spreadsheet Tickets

There are a lot of new entrants coming into the GRC market right now, which tells you something interesting is happening. But most of what I see still feels like workflow layered on top of spreadsheets. Executives do not need more...

By Sean D. Mack
Seeing Bugs in IDE Boosts Fixes From 0% to 70%
SocialFeb 18, 2026

Seeing Bugs in IDE Boosts Fixes From 0% to 70%

“At Facebook, they found that when security vulnerabilities were reported as issues, nearly 0% got fixed. But when these same problems appeared directly in the developer’s IDE, where the red squiggles were difficult to ignore, fix rates jumped to around...

By Sean D. Mack
Boards Pivot to Recovery as Breach Assumption Grows
SocialFeb 17, 2026

Boards Pivot to Recovery as Breach Assumption Grows

As more companies “assume breach,” I am seeing a shift from prevention to recovery. Boards are starting to ask different questions.

By Sean D. Mack
Recovery Plans Must Assume Active Directory Can Fail
SocialFeb 16, 2026

Recovery Plans Must Assume Active Directory Can Fail

If Active Directory is down, can you even log in to start restoring backups? A lot of recovery plans assume core services are intact but that's not always a safe bet.

By Sean D. Mack
AI Threats Demand Distinct Policy Beyond Existing Security Frameworks
SocialFeb 16, 2026

AI Threats Demand Distinct Policy Beyond Existing Security Frameworks

Thinking a lot about AI security vs traditional security. Do we actually need a separate AI policy, or should this live inside the security and governance structures we already have? To answer this we need to consider how AI and...

By Sean D. Mack