Insights

Practical perspectives on cloud and infrastructure security.

Notes on the technical work that follows a security finding, written for engineering and security teams.

Resilience

A Backup Is Not a Disaster Recovery Plan

Why backup coverage and recovery capability are different things, and what validating recovery actually involves.

Coming soon

Identity

Why IAM Problems Surface During Enterprise Security Reviews

Access tends to accumulate quietly. Enterprise due diligence is often the point at which that becomes visible.

Coming soon

Remediation

From Pentest Finding to Remediation

What happens after the report is delivered, and how infrastructure findings differ from application findings.

Coming soon

Enterprise readiness

What Enterprise Buyers Actually Want to See From Cloud Security

The questions behind the questionnaire, and the technical detail buyers increasingly expect.

Coming soon

Assurance

Why Security Evidence Matters

Implementing a control and being able to demonstrate it are separate pieces of work.

Coming soon

AI infrastructure

AI Agents Are Creating a New Privileged Identity Problem

Automation introduces identities and permissions that traditional access review processes were not designed for.

Coming soon

Articles are published as they are written. Titles listed above are planned topics.

Prefer to discuss it directly?

If one of these topics reflects a live requirement in your environment, a short conversation is usually more useful than an article.

Start a Conversation