Nick SilvestriRisk is a decision

I learned to lead on a retail floor. I learned security in the middle of incidents.

I've spent twelve years in cybersecurity, from hands-on incident response and forensics to leading security operations and programs.

Today I lead a security team that serves several regulated organizations at once, brief executives every month, and run incident response when something goes wrong. Along the way I've rebuilt teams, answered to regulators, and learned that most security problems are really decision problems. The technology usually isn't the hard part. Getting the right people to make an informed call, and then following through, is.

This site is where I write about that work, one real situation at a time.

2 min
to detect a rogue device during a blind physical penetration test, and 4 to get it off the network
60 to 6
monthly alerts after replacing a managed detection provider, and every one of the six was worth acting on
50%+
faster detection at one organization after rebuilding its detection content, triage, and analyst workflow
95%+
of critical vulnerabilities on business-critical systems fixed, sustained, under a risk-based program

At a glance

Role
Security operations and program leader across several regulated organizations at once
Focus
Incident response, security programs, governance, and executive risk decisions
Experience
12 years, from hands-on incident response and forensics to leading programs
Executives
Monthly briefings with CEOs, CFOs, and CTOs
Credentials
CISSP and five GIAC certifications (GCIH, GCFA, GCFE, GCED, GSEC)
Teaching
SANS instructor facilitator in 2017, 2019, and 2024
Recognition
1st place, SANS DFIR Championship (2019)
Contact
LinkedIn

I keep employers, clients, and colleagues out of my writing on purpose. The details are on my LinkedIn and in conversation.

How I lead

Building teams

I rebuilt an inherited security team using Situational Leadership II, with a development plan for each analyst, and coached people from doing tasks to owning processes.

Commanding incidents

I command incident response across business units, IT, security, HR, and executive leadership, and I coach outside responders on containment and escalation.

Advising executives

I brief CEOs, CFOs, and CTOs every month, turn technical risk into decisions they can make, and bring options with real costs rather than a single answer.

Governing programs and partners

I build governance that holds up with examiners and auditors, and I hold managed providers to the outcomes they're paid for.

Case files

A few situations from my career, with identifying details redacted. Field Notes tells the full stories.

Case 01Detection program

WannaCry, stopped at one workstation

Organization Year 2017

As security lead, I had put detection in place for exactly this kind of behavior. When WannaCry hit, it flagged a workstation mass-scanning SMB across the network.

Outcome. Stopped at that workstation before it spread.

Case 02Incident command

The ransomware that never ran

Organization Year 2024

An attacker flooded a user's inbox, called over Teams pretending to be IT support, and got a malware loader onto the network. I directed my team's response, which caught and contained the loader before any ransomware executed.

Outcome. Avoided an estimated ~$5M, the average cost of an incident from that ransomware group once it's established. That's an estimate, not measured savings.

Case 03Defense in depth

Two minutes on a blind test

Organization Year 2025

A penetration tester planted a rogue device on the internal network with no warning to my team. The layered defenses my team built and ran held it off, then flagged it within two minutes of getting on.

Outcome. Four minutes from connection to off the network.

Case 04Vendor governance

Sixty alerts a month, six that mattered

Organization

A managed detection provider was sending about 60 alerts a month, 55 of them false positives. I pushed for a standing meeting so they could learn the business and tune. When that didn't fix it, I brought leadership three options instead of one answer.

Outcome. The provider they chose brought it down to about six alerts a month, all of them actionable.

Career timeline

Newest first.

  1. Today
    • RoleLeading a security team and security programs for regulated organizations, with monthly briefings for CEOs, CFOs, and CTOs.
  2. 2025
    • IncidentBlind physical penetration test: the defenses my team ran detected a rogue device within two minutes and had it off the network in four.
  3. 2024
    • IncidentDirected my team's response to a ransomware intrusion, caught before it executed, avoiding an estimated ~$5M average incident cost.
    • TeachingInstructor facilitator for SANS SEC504 (the GCIH course), SANS DFIR Miami.
    • RecognitionInvited by a SANS DFIR instructor to guest lecture in their course.
  4. 2019
    • Recognition1st place, SANS DFIR Championship.
    • TeachingInstructor facilitator, SANS SEC555: SIEM with Tactical Analytics.
  5. 2018
    • Recognition1st place, DEF CON Hacking Village Python Challenge.
  6. 2017
    • IncidentDetection I put in place as security lead caught WannaCry mass-scanning SMB, and we stopped it at the workstation before it spread.
    • TeachingInstructor facilitator for the GCED course, SANS.
    • Recognition2nd place, SANS Pentest Austin Group Challenge.
  7. 2016
    • RoleJoined as security lead for one organization and grew the function to serve several regulated organizations.
  8. 2015
    • RoleSecurity engineering lead at a B2B technology company: drove the security program's maturity and served as the liaison between engineers, executives, and external auditors.
  9. 2014
    • RoleManaged services security: assessments, hardening, and incident response across many customer environments.
    • EducationB.S. Computer Science, Rowan University.
  10. 2012
    • RoleIT manager for an e-commerce business: ran operations and put the first security controls in place.
  11. 2008
    • RoleRetail store manager: owned the P&L and hired, trained, and developed a team of eight. It's where I learned to lead people.

Credentials

Each certification links to the issuer, so you can check it yourself.

Want the stories behind all this? Read Field Notes, or find me on LinkedIn.