uptime: 20+ years · role: security leadership · status: allergic to security theater
Security programs that work, not ones that just pass the audit.
I'm Jim Guckin. I've spent two decades leading security teams, and I write about the gap between what looks good on a dashboard and what actually protects an organization. I've been in the room when things went wrong…which is where most of the useful lessons come from.
what i do
Four hats, one job
Security Leadership
My primary focus is protecting the organization's data and systems from external and internal threats. I work closely with IT and other departments to implement and maintain strong security measures, and to educate and train employees on practices that actually stick.
Technology Mentor
I help others develop and improve their skills in the field. Whether it's answering questions, providing resources, or collaborating on projects, I try to be a useful resource for people growing their knowledge in technology.
Technology Educator
I design and deliver engaging lessons and hands-on activities that help people understand and apply key concepts in technology. In a classroom or online, the goal is the same: make it click.
Speaker & Writer
I share what I've learned through talks, writing, and my podcast. The goal is to spark honest conversations about what works in security…and to name the things that only look like they work.
latest from the blog
Recent posts
-
2026-06-24 · it-strategy
Security Awareness Training That Doesn’t Embarrass Anyone
Can I tell you about a phishing simulation I ran early in my career that I am not particularly proud of (I wasn’t perfect, nor am I now). We had just rolled out a new security awareness training program. The vendor was enthusiastic, the platform had dashboards and the dashboards had charts. The charts went …
-
2026-05-14 · career-leadership
Why AI-Driven Exploitation Changes Everything
I’ve been doing this long enough to remember when a zero-day was something whispered about in conference hallways (I know I’m old). A rare, expensive, almost mythological artifact, the kind of thing nation-states hoarded, and intelligence agencies paid seven figures to acquire. The barrier to weaponizing a zero-day used to be something…you needed time, expertise, …
-
2026-04-29 · it-management
What Zero Trust Actually Requires That Nobody Wants to Talk About
Am I the only one who has experienced this…usually after a board meeting or a vendor briefing, where someone announces that the company is going to implement zero trust. The room nods, a working group gets formed, budget line appears and within a few weeks, the initiative is underway… with everyone quietly assuming that what …
-
2026-03-19 · disaster-recovery
When Security Architecture Depends on Tribal Knowledge
There is a moment in almost every organization when someone says a phrase that sounds reassuring on the surface but I hope should make security leaders just a little uncomfortable: “Don’t worry, Mike knows how that works.” (no real Mike’s are used in today’s example). Mike I’m sure is a great guy, he’s been with …
testimonials --source verified-humans
What colleagues say
"I work with a lot of IT professionals and Jim ranks at the top. His ability to get to the bottom of issues and manage them until they are complete is incomparable. Jim is also a savvy negotiator who understands the value of vendor relationships, while at the same time knows what's best for his company."
"Jim is extremely knowledgeable about his field of expertise. Under his helm as Helpdesk Manager this department was run efficiently and effectively. Jim always took time to communicate to the end user and made sure he was available at all times."
"Jim made me advance my career and learn stuff on the fly, and for that I'm highly grateful. He shaped me into what I am today. Jim is a great asset to a company's IT department."
industries worked with