I break into things for a living.
More specifically, I’ve spent the last decade finding out how organizations fail at security and helping them do something about it. The technical work is interesting, but it’s the harder questions underneath that keep me here: how people build trust in systems, where that trust breaks down, and what it costs when it does.
I run Empiric Security (opens in new tab), my independent offensive security consultancy. My CV has all the details: experience, credentials, speaking history, etc.
Outside of work I shoot film (opens in new tab) and ride motorcycles.
Recent Writing
- A Song of Heists and Drive-Bys Why any organization with a public IP has to plan for un-patchable zero-day exploitation, not just targeted attacks.
- You Can’t Just Publish Partial Exploits Anymore Taking a ‘safely’ disclosed WordPress RCE most of the way to a full unauthenticated exploit chain with public research, a patch diff, and an LLM, and the rest with a public PoC.
- One Home for Everything I Write Consolidating my scattered writing under one roof, without giving up digital ownership.
I post new writing here first. Follow a feed to catch it as it goes up.