Environment Separation Is a Claim Until Someone Reads the Config
A production service that answered every check was reading development tables and publishing an index with no version history in it at all.
Reference architectures, zero trust, architecture reviews, and decision records that survive contact with delivery.
21 articles
A production service that answered every check was reading development tables and publishing an index with no version history in it at all.
Retiring a service is an ordered operation with a preservation gate that has to be verified before anything is destroyed, and a list of consumers that no inventory holds.
A scheduled worker was reading a Cloudflare bot challenge as a rate limit. Classifying it correctly was the right fix, and the first version of that fix doubled the traffic the worker sent.
Two commits a day apart set opposite failure defaults in the same backend, and what decided each one was not the sensitivity of the asset but who gets refused when the control is wrong.
A chat integration appeared to require a public webhook endpoint into a machine I own, and the transport that removed the endpoint entirely cost less than any control I would have put in front of it.
Adding Android to a backend built for iOS forced a choice between relaxing JWT audience validation and issuing a second client identity, and the cheaper-looking option was the one that destroyed information.
Writing a maturity score down as a function forces you to answer the scoring questions a consultant never has to say out loud, starting with what an unanswered question is worth.
Architecture reviews should reduce downstream risk, not become documentation theatre.
At enterprise scale, identity telemetry is often the fastest signal for active compromise. Operations need to be built around that reality.
Architecture quality improves when decisions are recorded with context, tradeoffs, and accountable ownership.
As AI capabilities accelerate, security architecture has to evolve from static reviews to faster, risk-informed design guardrails.
Tool sprawl raises cost and complexity without guaranteed risk reduction. Here's a practical model for consolidating controls without losing coverage.
Healthcare security decisions affect patient care in real time. A workable Zero Trust model must protect systems without disrupting clinical operations.
Security architecture reviews should drive decisions, not generate shelfware. Here's a practical playbook that works in enterprise environments.
IoT security doesn't fail because of devices alone. It fails when architecture, ownership, and operational controls don't scale with deployment speed.
Cloud migration doesn't fail because of technology. It fails because architecture and security decisions are made in the wrong order.
Threat modeling isn't just for security specialists. Here's a practical framework product and engineering teams can use without slowing delivery.
Remote work made one thing clear: perimeter controls are no longer enough. Identity has become the control plane for enterprise security.
Most Zero Trust programs fail because they start with tools instead of outcomes. Here's a practical roadmap that works in real enterprises.
The shift to remote work exposed security gaps most enterprises didn't know they had. Here are the mistakes I'm seeing — and how to fix them fast.
The traditional firewall-centric security model is showing its age. Here's what enterprise security architects should be rethinking heading into 2020.