Researcher · Analyst · Myth-buster

Adrian Sanabria

Adrian SanabriaPragmatic Cybersecurity.

I dig for what's actually true in security, busting the industry myths that keep getting repeated, and helping practitioners get the fundamentals right instead of chasing whatever's on the conference floor this year.

Featured research

Destroyed by Breach

"One breach and you're out of business" is one of the most repeated claims in security. It's also mostly wrong. So I went looking for the receipts: every company that genuinely shut down because of a cybersecurity incident, documented and sourced.

The list is short, the causes are usually more complicated than "hackers," and the real lessons are far more useful than the fear.

Explore destroyedbybreach.com
Companies confirmed shut down by a breach
33verified, worldwide, all-time
Years across IR, pentesting, and analysis20+
Fortune 500s ended by a breach alone0

FEATURED WORK

The Defenders Initiative

Primary research on vulnerability management and breach analysis, published as reports, talks, and plain-language lessons learned from breaches we actually understand.

It's the home for the work that doesn't fit in a tweet: deep dives into what went wrong, why it keeps happening, and what defenders can do about it without buying another platform.

  • Breach reconstruction
  • Vulnerability management
  • Security fundamentals
  • Industry myth-busting
Read the research
Breach Lessons: the 2023 MGM Breach
Featured article

Breach Lessons: the 2023 MGM Breach

A help-desk call, not a zero-day, started ten days of chaos and a $100M hit. I reconstructed the incident from public filings and reporting to show what actually went wrong — and what defenders can learn from it.

Read the full analysis

Media & content

Shows I host, episodes I join, and the work I do helping other people say something worth hearing.

Illustration for Open Source Security Summit 2026

Upcoming speaking

Open Source Security Summit 2026

September 17, 2026 · 11 AM – 1 PM ET

Featured speaker at Bitwarden's seventh annual virtual summit. I'll be moderating a fireside chat with Joseph Menn on hackers, ethics, and the security community.

Register for free
Illustration for Identity security under pressure

Live webcast

Identity security under pressure

July 30, 2026 · 2:00 PM ET

Joining Timothy Youngblood (Onyx Security) and Shimrit Tzur-David (Secret Double Octopus) for an SC Media conversation on AI, compliance, and the identity gaps you can't afford to ignore.

Save your spot
Illustration for Enterprise Security Weekly

Podcasting

Enterprise Security Weekly

Main host since 2021. Every week we work through what's actually happening in the security market — funding, products, and the claims that don't survive a second look.

Watch the playlist
Illustration for Shared Everything: AI vs. enterprise security

Guest appearance

Shared Everything: AI vs. enterprise security

A July 2026 conversation with Nicole Hemsoth Prickett on why AI is accelerating vulnerability discovery faster than enterprises can prioritize it — plus prompt injection, retrieval poisoning, and the supply chain problem nobody has solved.

Listen to the episode
Illustration for ConversingLabs: Learning from security's failures

Live interview

ConversingLabs: Learning from security's failures

Paul F. Roberts and I talked about building a more secure software ecosystem — and what the security industry can learn from its failures instead of repeating them.

Watch on LinkedIn
Illustration for SquareX: Why ransomware still keeps winning

Guest appearance

SquareX: Why ransomware still keeps winning

A talk with the SquareX team on why ransomware keeps succeeding against well-funded defenses — the browser as the new attack surface, the identity and access gaps attackers keep reusing, and what actually moves the needle.

Watch the talk
Illustration for Wireless Threat Series by Bastille

Hosted show

Wireless Threat Series by Bastille

A show for Bastille about the wireless attack surface — from rogue access points and RF spoofing to the devices most security teams forget they own.

Watch the series
Illustration for SimplyCyber Fireside: AI Is Not Coming For Your Job

Guest appearance

SimplyCyber Fireside: AI Is Not Coming For Your Job

A conversation with Gerald Auger about what AI actually means for cybersecurity careers — separating real automation gains from the doomer narratives, and where human judgment still wins.

Watch the episode
Illustration for Alice in Supply Chains

Co-hosted show

Alice in Supply Chains

A monthly podcast for Tenchi Security, co-hosted with Alexandre Sieira. We dig into third-party cyber risk news, supply chain incidents, and what TPCRM practitioners should actually do about them.

Listen to the show

Advisory work

Advisory & consulting

Three ways to work together: structured faculty advisory through IANS, direct startup advisory, and production help for security vendors who want a show people actually want to hear.

IANS Faculty

Ask-an-Expert advisory calls, written guidance, and event content for enterprises of every size — carried over from eight years as an industry analyst. I help security leaders cut through vendor noise, validate strategy, and communicate risk in language the board actually understands.

View IANS faculty profile
Startup advisory

Solo advisory for security startups and founders: positioning, product strategy, go-to-market messaging, and the honest feedback investors won't give you. Book a session directly if you want a pragmatic outside perspective.

Book startup advisory
Services

I help security vendors build shows people actually want to hear — booking, editorial direction, and the discipline to keep the marketing out of the microphone.

Talk about a show

About Adrian

I've spent about two decades in security, and I've done most of the jobs people argue about online. Security architecture at a payments company, consulting and penetration testing, PCI work, incident response, and building an internal security program from the inside.

Then I spent four years as an industry analyst at 451 Research covering cloud, endpoint, and pretty much every category that got a booth at RSA. That's where the myth-busting habit started: once you've seen a few hundred vendor pitches, the gap between the claim and the reality gets hard to ignore.

I've also been on the other side — founding Savage Security, running product at startups like Tenchi and Valence, and starting BSides Knoxville, which has been running for twelve years. Building something is a good cure for cynicism. It's also why I'd rather help defenders fix the fundamentals than sell them the next acronym.