Skip to content
Paul Marinos
Menu

Paul Marinos

Ten pillars of security work, and the connective tissue between them.

Security is usually written about one discipline at a time. That’s how it’s staffed, how it’s tooled, and how it’s sold — and it’s also why the same root cause gets rediscovered independently by five teams who never compare notes.

The interesting material lives at the seams. An overpermissioned role is a pentest finding, an IAM design failure, a control gap an auditor will flag, a detection opportunity nobody built, and a risk somebody has to prioritize against forty others. Same fact, five vocabularies, five audiences.

This site covers ten pillars in depth, but the argument it’s making is about how they compose.

Every article links to at least one article in a different pillar — that rule is enforced at build time, so this graph can’t quietly drift out of date. Drag it around; click through to any node.

The pieces that only make sense because all ten pillars are here:

  • One finding, five lenses. A single IAM misconfiguration traced through pentest, AppSec, GRC, detection, and intel — and reported five different ways.
  • The purple team loop. Adversary emulation → detection validation → backlog → prioritization. The full circuit from technique to tested detection.
  • Agentic AI identity. Zero Knowledge Trust, agent orchestration, and tool-use authorization are one problem: scoped, revocable, auditable authority for a non-human actor.
  • Risk prioritization as the universal problem. The same methods applied to AppSec backlogs, GRC findings, and pentest reports.
  • The substrate trace. One misconfigured network path as an architecture flaw, a pentest pivot, a detection blind spot, and a control gap.
  • Alert to answer. A detection fires, response contains it, forensics reconstructs it, malware analysis says what it could do — and the lesson returns as a tested rule.
  • Deletion nobody can prove. Defensible deletion against audit evidence and forensics, where the data an organization swore was gone is what the investigation recovers.
  • The telemetry gap. Log coverage analysis as the shared prerequisite for detection, IR, hunting, and audit evidence.
  • Communication as a technical skill. The same discipline behind a good intel product, a good pentest report, and a good audit narrative.