<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Roman Romanenco — Writing</title><description>Articles on product strategy, enterprise security, and the messy place between them.</description><link>https://romanromanenco.com/</link><language>en-us</language><item><title>Security Has a Product Problem</title><link>https://romanromanenco.com/blog/security-product-problem/</link><guid isPermaLink="true">https://romanromanenco.com/blog/security-product-problem/</guid><description>I spent years finding critical vulnerabilities. Then I realized finding them wasn&apos;t the hard part.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>Career</category></item><item><title>A Roadmap Is Not a Product Strategy</title><link>https://romanromanenco.com/blog/product-strategy-blueprint/</link><guid isPermaLink="true">https://romanromanenco.com/blog/product-strategy-blueprint/</guid><description>Most teams confuse a list of features with a strategy. Here&apos;s the 6-step framework I use to build product strategies that actually hold up under pressure.</description><pubDate>Wed, 06 Sep 2023 00:00:00 GMT</pubDate><category>Product Strategy</category></item><item><title>5 Insider Threats Your Company is Overlooking</title><link>https://romanromanenco.com/blog/insider-threats/</link><guid isPermaLink="true">https://romanromanenco.com/blog/insider-threats/</guid><description>The breach your security team is least prepared for isn&apos;t coming from outside. Here are the five insider threat vectors most organizations aren&apos;t watching closely enough.</description><pubDate>Tue, 05 Sep 2023 00:00:00 GMT</pubDate><category>Security</category></item><item><title>How I Automate Authenticated API Security Testing</title><link>https://romanromanenco.com/blog/automated-api-security-testing/</link><guid isPermaLink="true">https://romanromanenco.com/blog/automated-api-security-testing/</guid><description>Automating dynamic application security testing (DAST) for service APIs as part of a security testing pipeline, using OWASP ZAP and an OpenAPI spec.</description><pubDate>Wed, 26 Oct 2022 00:00:00 GMT</pubDate><category>Technical</category></item><item><title>Ransomware Defense Doesn&apos;t Have to Be Expensive</title><link>https://romanromanenco.com/blog/ransomware-proactive-defense/</link><guid isPermaLink="true">https://romanromanenco.com/blog/ransomware-proactive-defense/</guid><description>Good cyber hygiene and well-tuned security controls go a long way in defending against ransomware, even without a &apos;next-gen&apos; product. A breakdown of common delivery techniques and the cost-effective countermeasures that block them.</description><pubDate>Wed, 27 Apr 2022 00:00:00 GMT</pubDate><category>Security</category></item><item><title>Deconstructing the Ransomware Kill Chain</title><link>https://romanromanenco.com/blog/ransomware-kill-chain/</link><guid isPermaLink="true">https://romanromanenco.com/blog/ransomware-kill-chain/</guid><description>Ransomware is a relatively noisy form of malware, and its kill chain presents multiple opportunities for network defenders to detect and mitigate the threat. A stage-by-stage breakdown.</description><pubDate>Wed, 06 Apr 2022 00:00:00 GMT</pubDate><category>Security</category></item><item><title>Pass the CISSP on First Try With This Guide</title><link>https://romanromanenco.com/blog/cissp-review/</link><guid isPermaLink="true">https://romanromanenco.com/blog/cissp-review/</guid><description>Reflections on passing the CISSP on the first try, and the condensed study guide that got me there. Includes a preview of the Cryptography module.</description><pubDate>Thu, 24 Mar 2022 00:00:00 GMT</pubDate><category>Career</category></item><item><title>How a Malicious Chrome Extension Steals Your Session</title><link>https://romanromanenco.com/blog/how-a-malicious-chrome-extension-steals-your-session/</link><guid isPermaLink="true">https://romanromanenco.com/blog/how-a-malicious-chrome-extension-steals-your-session/</guid><description>Browser extensions are a blindspot most organizations aren&apos;t accounting for. Here&apos;s how session theft via a malicious extension works, and why it&apos;s more accessible than people think.</description><pubDate>Fri, 28 Aug 2020 00:00:00 GMT</pubDate><category>Technical</category></item></channel></rss>