<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Field Notes</title><description>A personal knowledge wiki — ideas distilled from books, papers, conversations, and courses.</description><link>https://example.com/</link><item><title>Software Supply Chain as an Adversary Playbook</title><link>https://example.com/ideas/supply-chain-security/</link><guid isPermaLink="true">https://example.com/ideas/supply-chain-security/</guid><description>Modern breaches increasingly enter through dependencies and build pipelines rather than production apps.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Zero Trust as Verify-Everywhere, Not VPN Replacement</title><link>https://example.com/ideas/zero-trust-principles/</link><guid isPermaLink="true">https://example.com/ideas/zero-trust-principles/</guid><description>Zero trust means every request is authenticated and authorized regardless of network location.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Attack Trees for Structured Threat Modeling</title><link>https://example.com/ideas/attack-tree-analysis/</link><guid isPermaLink="true">https://example.com/ideas/attack-tree-analysis/</guid><description>Attack trees turn vague security worries into a hierarchy of concrete, testable adversary goals.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate></item><item><title>Security Review Cadence as Operational Memory</title><link>https://example.com/ideas/security-review-cadence/</link><guid isPermaLink="true">https://example.com/ideas/security-review-cadence/</guid><description>A recurring review rhythm turns isolated security observations into durable operational memory.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate></item><item><title>Detection Engineering as a Feedback Loop</title><link>https://example.com/ideas/detection-engineering-loop/</link><guid isPermaLink="true">https://example.com/ideas/detection-engineering-loop/</guid><description>Detection rules improve fastest when every alert is treated as feedback on assumptions.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Access Review Patterns That Catch Drift</title><link>https://example.com/ideas/access-review-patterns/</link><guid isPermaLink="true">https://example.com/ideas/access-review-patterns/</guid><description>Access reviews catch more risk when they focus on entitlement drift and business context.</description><pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Incident Debriefs Without Blame Drift</title><link>https://example.com/ideas/incident-debrief-notes/</link><guid isPermaLink="true">https://example.com/ideas/incident-debrief-notes/</guid><description>Good debrief notes preserve causes, decisions, and repairs without turning into blame records.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Vendor Risk Triage for Small Teams</title><link>https://example.com/ideas/vendor-risk-triage/</link><guid isPermaLink="true">https://example.com/ideas/vendor-risk-triage/</guid><description>Small teams need a vendor risk process that quickly separates critical dependencies from routine suppliers.</description><pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Secure Defaults Reduce Review Load</title><link>https://example.com/ideas/secure-defaults/</link><guid isPermaLink="true">https://example.com/ideas/secure-defaults/</guid><description>Strong defaults make weekly review easier by shrinking the number of exceptional decisions.</description><pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate></item></channel></rss>