Environment Separation Is a Claim Until Someone Reads the Config
A production service that answered every check was reading development tables and publishing an index with no version history in it at all.
Exposure reduction, attack surface, metrics that change decisions, and control assurance.
19 articles
A production service that answered every check was reading development tables and publishing an index with no version history in it at all.
A chat integration appeared to require a public webhook endpoint into a machine I own, and the transport that removed the endpoint entirely cost less than any control I would have put in front of it.
Nine findings came out of one adversarial audit. Two were exploitable defects and five were divergence between what the documentation claimed and what the code did.
A security finding about swallowed email errors was fixed correctly, and the same commit is why the notification emails stopped arriving for four days.
Five review passes over one backend in seven days. The finding count fell every time, the top severity band did not move until the last pass, and two of those top findings were defects the pass before had introduced.
A batch of twenty-seven security fixes closed cleanly and produced a critical regression plus fifteen new findings inside the hour, because the firewall at the heart of it had been added to the template and attached to nothing.
A Next.js downgrade that fixed a broken static export also put five open security advisories back into the lockfile for fifteen hours, and nothing recorded that as a decision.
Writing a maturity score down as a function forces you to answer the scoring questions a consultant never has to say out loud, starting with what an unanswered question is worth.
Control claims are cheap. Assurance improves when teams can produce timely evidence that controls are operating as designed.
Effective security metrics should change decisions, not just decorate dashboards.
Counting vulnerabilities is easy. Reducing real risk requires better prioritization, ownership, and remediation execution.
Cloud IAM debt accumulates quietly until attackers exploit it. Here is a practical model for reducing permission sprawl safely.
Boards do not need more dashboard noise. They need metrics tied to business decisions, material risk, and response readiness.
Periodic vulnerability scans miss the assets attackers find first. Continuous attack surface management closes that gap.
Boards don't need more security data. They need decision-grade metrics that connect controls, risk movement, and business impact.
Log4Shell exposed what many teams already suspected: you can't defend what you can't inventory. SCA is now foundational, not optional.
Managing open source risk at enterprise scale requires process discipline, ownership, and signal-focused prioritization — not endless alert volume.
The OWASP Top 10 is useful, but only if teams translate it into real engineering decisions and risk priorities.
Most enterprises don't know what's inside the software they ship. Software Composition Analysis isn't optional anymore — here's what ignoring it actually costs.