The whole garden
All Ideas
9 notes growing here โ sort and filter to find a path through them.
- Software Supply Chain as an Adversary Playbook
Modern breaches increasingly enter through dependencies and build pipelines rather than production apps.
- Zero Trust as Verify-Everywhere, Not VPN Replacement
Zero trust means every request is authenticated and authorized regardless of network location.
- Attack Trees for Structured Threat Modeling
Attack trees turn vague security worries into a hierarchy of concrete, testable adversary goals.
- Security Review Cadence as Operational Memory
A recurring review rhythm turns isolated security observations into durable operational memory.
- Detection Engineering as a Feedback Loop
Detection rules improve fastest when every alert is treated as feedback on assumptions.
- Access Review Patterns That Catch Drift
Access reviews catch more risk when they focus on entitlement drift and business context.
- Incident Debriefs Without Blame Drift
Good debrief notes preserve causes, decisions, and repairs without turning into blame records.
- Vendor Risk Triage for Small Teams
Small teams need a vendor risk process that quickly separates critical dependencies from routine suppliers.
- Secure Defaults Reduce Review Load
Strong defaults make weekly review easier by shrinking the number of exceptional decisions.