SolarWinds and the Software Supply Chain Wake-Up Call
SolarWinds exposed a hard truth: trusted software channels can become attack channels. Here's what security leaders should do next.
SolarWinds exposed a hard truth: trusted software channels can become attack channels. Here's what security leaders should do next.
Most incident response plans look good on paper and fail under pressure. Here are the lessons that hold up in real breach scenarios.
Fast pipelines can quietly become high-risk pipelines. Here are the security gaps I see most often — and how to close them without slowing delivery.
Cloud migration doesn't fail because of technology. It fails because architecture and security decisions are made in the wrong order.
Threat modeling isn't just for security specialists. Here's a practical framework product and engineering teams can use without slowing delivery.
Passing an audit is not the same as reducing risk. Here's how to build a program where compliance supports security instead of replacing it.
'Shift left' was a good start, but it's no longer enough. Modern DevSecOps demands security controls across the entire software factory.
Remote work made one thing clear: perimeter controls are no longer enough. Identity has become the control plane for enterprise security.
Most Zero Trust programs fail because they start with tools instead of outcomes. Here's a practical roadmap that works in real enterprises.
The shift to remote work exposed security gaps most enterprises didn't know they had. Here are the mistakes I'm seeing — and how to fix them fast.
Most enterprises don't know what's inside the software they ship. Software Composition Analysis isn't optional anymore — here's what ignoring it actually costs.
The traditional firewall-centric security model is showing its age. Here's what enterprise security architects should be rethinking heading into 2020.