From Block Everything to Risk-Based Enablement: Safely Deploying GenAI in Healthcare· coming soon
How a block-everything security posture breaks down when the business demands GenAI — and a framework for enabling it without putting PHI at risk.
SecretSquirrel.cloud
Field-tested perspectives on:
Anonymous by design. Practical by experience.
Browse
Practitioner-written intelligence across the domains that matter most.
Long-term
This publication documents something beyond individual posts.
How a block-everything security posture breaks down when the business demands GenAI — and a framework for enabling it without putting PHI at risk.
Moving from hands-on security work to security leadership faster than expected. The identity shift, the lessons, and what the path actually looks like.
CVE-2019-10768 prototype pollution enables authorization bypass — and a safe demonstration methodology for developer briefings.
Risk-scored phish-resistant identity verification with Temporary Access Passes, Teams live agent escalation, and a full RBAC admin panel.
The gap between a DLP policy document and a DLP policy that actually works in a clinical environment.
FortiBleed: What the June 2026 Campaign Tells Us About Internet-Facing Appliance Risk
Client-Side Auth Bypass in Legacy AngularJS Clinical Applications
HIPAA DLP in Practice: Configuring Netskope for PHI Protection at Scale
Planning for Executive Security Leadership
From Block Everything to Risk-Based GenAI Enablement
Template
A practical template for defining scope, mission, and governance structure for a new or evolving security program.
Reference
A curated set of metrics and visualizations designed for board-level security reporting without technical jargon.
An anonymous security practitioner documenting the journey toward executive security leadership. Field-tested perspectives, not vendor content.
Read more about this publication →