Skip to content
Paul Marinos
Menu

Paul Marinos

Ten pillars of security work, and the connective tissue between them.

Security is usually written about one discipline at a time. That’s how it’s staffed, how it’s taught, and how it’s sold. It’s also why the same root cause gets rediscovered independently by five teams who never compare notes.

The interesting material lives at the seams. An overpermissioned role is a pentest finding, an IAM design failure, a control gap an auditor will flag, a detection opportunity nobody built, and a risk somebody has to prioritize against forty others.

This site covers ten security pillars in depth, but what it aims to emphasize the most is the space between them: how these disciplines interrelate, and how work in one can be meaningfully communicated to the next. These are my public working notes on both.

Every article links to at least one article in a different pillar, and the map below is those connections made visible. It visualizes how the disciplines interrelate, and it’s drawn from the articles themselves, highlighting the natural overlap that should lead to cross-team collaboration. Drag it around; click through to any node.

The pieces that only make sense because all ten pillars are here. Each is its own page, a walk through the same fact as it crosses discipline lines:

  • One finding, five lenses: a single IAM misconfiguration traced through pentest, AppSec, GRC, detection, and intel, then reported five different ways.
  • The purple team loop: adversary emulation → detection validation → backlog → prioritization. The full circuit from technique to tested detection.
  • Agentic AI identity: zero Knowledge Trust, agent orchestration, and tool-use authorization are one problem: scoped, revocable, auditable authority for a non-human actor.
  • Risk prioritization as the universal problem: the same methods applied to AppSec backlogs, GRC findings, and pentest reports.
  • The substrate trace: one misconfigured network path as an architecture flaw, a pentest pivot, a detection blind spot, and a control gap.
  • Alert to answer: a detection fires, response contains it, forensics reconstructs it, malware analysis says what it could do, and the lesson returns as a tested rule.
  • Deletion nobody can prove: defensible deletion against audit evidence and forensics, where the data an organization swore was gone is what the investigation recovers.
  • The telemetry gap: log coverage analysis as the shared prerequisite for detection, IR, hunting, and audit evidence.
  • Communication as a technical skill: the same discipline behind a good intel product, a good pentest report, and a good audit narrative.
  • The contract is the control: for everything you don’t operate (SaaS, feeds, managed services), the security leverage lives at signature time, and five disciplines keep discovering it independently.
  • The namespace nobody shares: threat-actor aliases, event schemas, control crosswalks, asset inventory, and the business ontology: five disciplines paying the same no-shared-vocabulary tax.
  • Every copy flattens permissions: the RAG index, the SIEM, the data lake, and the backup all shed their sources’ access control at copy time, unless someone re-derives it on purpose.

Pieces in my own voice that don’t belong to any one pillar: arguments, ideas, and reflections. More contemplative and less technically focused compared to the above knowledge base of technical notes, these essays should be higher level or more ‘zoomed out’, and might offer some more creative and opinionated insight.

I keep an about page with who I am, the focus I’m building, and the method behind the site: identity as the terrain, techniques as the steps, the graph as the map.