top of page
All Posts


Cyber Strategy Development
Excited to be in Tallin for CyCon! Doing a workshop on how we developed the Biden Administration's National Cybersecurity Strategy. Using this blogpost to collect the resources I cite in my talk: US Cyber Strategy Documents PPD 63 (Clinton 1998) 2000 Clinton Plan 2003 Bush Strategy 2009 Obama Cyberspace Policy Review 2018 Trump Strategy 2023 Biden Strategy 2024 Implementation Plan 2026 Trump Strategy Sample One Page Strategies Biden Strategy One-Pager (GAO) General Montgomere
Rob Knake
May 251 min read


TPO Group Announces Partnership with Legato Security
We’re proud to announce a strategic partnership between TPO Group and Legato Security - bringing together two organizations with deep roots in national security and defense to deliver truly end-to-end, mission-ready cybersecurity. This collaboration combines TPO Group’s expertise in cyber defense strategy, incident response, supply chain risk management, and executive advisory with Legato Security’s 24×7 managed detection and response, SOC excellence, and CMMC Level 2–aligned
TPO Group
Apr 211 min read


Hardware Risks Expose Deeper Supply Chain Gaps
TPO Group's Rob Knake and Edna Conway sit down with Data Breach Today's Tom Field Expanding digital dependence and geopolitical strain had exposed a critical imbalance in cybersecurity priorities. Organizations had over-focused on software while underinvesting in hardware assurance, leaving critical infrastructure exposed to threats embedded in global supply chains according to TPO Group's Rob Knake and Edna Conway. Read more...
TPO Group
Mar 301 min read


Beyond CVSS: OT Security Looks for Its Risk Methodology
As operational technology (OT) environments outgrow IT-centric risk models, industry leaders are rethinking whether traditional tools like CVSS can meaningfully guide decision-making. In a recent article in OT.Today , TPO Group’s Allan Friedman highlights the core limitation: translating real-world operational context into vulnerability scoring is not just difficult—it’s often impractical. As he notes, the data required to reflect true risk “lives deep within operational en
TPO Group
Mar 161 min read
bottom of page