Advisory / retained / limited capacity

Advisory

I advise a small number of companies on security architecture through a dedicated monthly cadence. You bring the architecture, the roadmap, and whatever is on your mind. I tell you what I think.

Why this lens

Most security measures reduce risk. A few remove the attack surface altogether. The 76 analyses on this site argue that the difference between the two is measurable.

Of those, 76 are scored against the four invariants. The best three together would have prevented or significantly mitigated 47. That is the lens I bring to a conversation.

62%Best three together47 of 76 scored breaches prevented or mitigated.

Each invariant on its own

How the scoring works →

Who is advising

Niels Provos
Niels Provos has spent his career on one question: what can we make structurally impossible?

In 1999, Niels Provos drove to Canada to strip the encumbered cryptography out of OpenSSH, because United States export law would not let him do the work at home. OpenBSD could then release the code worldwide. He and David Mazières published bcrypt the same year; it still hashes passwords at companies founded two decades later. Honeyd and libevent followed.

Google hired him into its security organization in 2003, where he defended the company against denial-of-service attacks and helped start Safe Browsing in 2006. He ran the team for seven years, which is why Chrome, Firefox and Safari warn you before you open a malicious page. As a Distinguished Engineer, he spoke at Google I/O on how Google secures its infrastructure. In 2018, Stripe made him Head of Security; from 2022 to 2024, he led security efficacy at Lacework.

Anthropic’s Mythos agent found a signed-integer comparison in OpenBSD’s TCP SACK code that could panic the kernel. It had survived twenty-seven years of review. Provos wrote it in 1998, while finishing his doctorate at Michigan, and confirmed the mistake was his. He reproduced the result independently with IronCurtain, his open-source agent runtime, on models anyone can rent, for tens to low hundreds of dollars an audit. Patching faster will not keep up with that. The controls that put a whole class of bug out of reach will.

Security Blueprints puts that argument on the record. 76 breaches taken down to root cause, scored against structural controls, answer a question the industry mostly guesses at: which controls prevent breaches, and by how much. He wrote PlanAI to run the analysis and is building CISO Challenge, a simulation of the funding decisions that produce breaches. Running security engineering teams for fifteen years taught him the rest. The hardest part of an invariant is rarely technical; it is getting an organization to adopt one.

How it works

What it is not

  • Not an audit.
  • Not a compliance exercise.
  • Not a penetration test.
  • Not an extra pair of hands.
  • No report at the end.

You get grounded, deeply experienced technical feedback in real time. If your team needs formal deliverables or written reports, this is the wrong engagement.

The method, in public

Start a conversation

Six fields. The message is the one that matters; the more specific you are, the better a first conversation will be. You will get an email to confirm the address, then a reply from me within a few days.

Headcount or funding stage is enough.
Be specific.
Retained monthly.

Now playing Bandcamp