Notes from my work in product cybersecurity and compliance, with practical reflections and questions worth asking.