When we picture an attack we still imagine someone breaking into a central server. It almost never happens that way. It comes through the weakest link: a colleague's laptop, a supplier's cloud account, an email to an assistant, a document uploaded to an AI tool. Ordinary acts, by trusted people, done the wrong way.
I worked that out early, and by an unorthodox route. I was a programmer first: my first security program dates from 1995 and shipped on the cover disc of a magazine. Then cryptography for military bodies and public institutions, data protection technologies adopted by the European Commission and the European Defence Agency among others, and from 2022, CyberGrant in California. Thirty years of work, one conviction, and a patent that certifies it.
But nobody calls me at night about software.
A familiar face from television. A member of parliament. An entrepreneur. A chief executive on the eve of a decision they cannot get wrong. None of them cares for the technical lecture, and they are quite right. What they want to know is whether the person on the other end of the line will know what to do when something goes wrong. Because sooner or later something always does.
How it actually began was told by Andrea Bettini in Il Sole 24 Ore: Beyond the password.
I was a self-taught programmer with a burning enthusiasm and an idea larger than I was: to write security software at a time when hardly anyone discussed security. That is how Windows Limits came about, my first endpoint protection program.
It did one thing, and did it well: decide what a user could and could not do on a machine.
Today that has a name: it is called endpoint hardening, and it is one of the pillars of corporate security. In 1995 I was a seventeen-year-old who had grasped something early: that if you cannot stop someone sitting down at a computer, you can decide what that computer lets them do.
When PC Magazine published it, it felt enormous. Not for the recognition, but for the feeling of having made something useful.
That is where I learned the rule I still follow: simplicity and power are not opposites. A system nobody can operate protects nobody.
I work alongside people coming into information security today: professionals changing direction, younger managers, technical leads facing a board for the first time.
It is the part of the work that gives me the most back, and the reason I teach courses in person.