Evolve
Feb 2026

Security... If it stands still, dies.
In 2009, when I launched the original blog, the logo reflected exactly where I was at the time. It was sharp, aggressive, adversarial. Red teaming drove everything, and thinking like an attacker was the point. If you could understand how an adversary moved, how they thought, how they exploited assumptions, you could build something better. The logo carried that mindset, built around friction and tension, and it assumed that offense was the truest teacher.
By 2017, I had changed. Years of building teams, running programs, and watching organizations struggle under the weight of their own "security" forced a shift. Offense without defense was incomplete, and defense without offense was blind. The logo evolved because I did. It became simpler, lighter, with less ornament and more intent. The focus moved toward integration, making security understandable and efficient while reducing drag. Build programs where red and blue informed each other instead of competing for relevance. This new blog followed that same path, with fewer theatrics and more clarity, stripped down to what was useful.
And now, since 2025, another shift has taken hold, one I call Security Brutalism.
Just fundamentals, without complexity or frameworks layered on frameworks, and without theater. Strong baselines. Controls that are simple, direct, hardened, and that work whether you are defending or probing. Resilience over elegance, density over decoration. The current logo reflects that idea, simpler, heavy, intentional. It feels compressed, almost austere, hardened for security rather than designed for applause.
Security should work this way because it is survival, and security decays on contact. The moment a control meets reality, entropy begins. Adversaries adapt, technology shifts, organizations sprawl, and what worked last year becomes brittle this year. What felt advanced becomes legacy overnight. If security does not move forward, it moves backward, and there is no neutral position to hold.
Too many programs calcify. They protect last year's architecture against yesterday's threat model, using controls that passed an audit once. They confuse documentation with defense and mistake motion for progress. Slowly and quietly, the baseline erodes, gaps widen, response times stretch, and assumptions go unchallenged.
Security has to remain nimble. It has to look forward more than it looks inward, and it has to adapt as a habit rather than a reaction. Offense and defense have to inform each other continuously. Baselines have to be tested, simplified, and reinforced. Controls must be built to survive contact, not just compliance.
My evolution reflects that reality. The logos changed because the thinking changed, and the thinking changed because the environment demanded it. It will demand it again.
There will be another evolution at some point. There has to be. Security that refuses to evolve eventually becomes unable to protect anything, including its own baseline.