Updated 15 August 2026

Field notes for people responsible for risk.

Short, practical guidance for security leaders, engineers and operators. Where a note relies on external research, the primary source is linked inside the article.

New: Security Architecture Series

30 practical guides covering AI security, cloud and network architecture, security operations, CTO governance and cybersecurity careers.

Editorial cover for AI security framework: a practical operating model

AI security framework: a practical operating model

Build an AI security framework that connects governance, model and data risk, application controls, monitoring and accountable decisions.

Read the guide →
Editorial cover for How to implement the NIST AI RMF without creating shelfware

How to implement the NIST AI RMF without creating shelfware

Turn the NIST AI RMF functions—Govern, Map, Measure and Manage—into an operating rhythm for product and security teams.

Read the guide →
Editorial cover for A secure AI development lifecycle from idea to retirement

A secure AI development lifecycle from idea to retirement

Embed AI threat modelling, data controls, evaluations, release evidence, runtime monitoring and retirement into the product lifecycle.

Read the guide →
Editorial cover for Threat modelling an LLM application: the complete system view

Threat modelling an LLM application: the complete system view

Threat model an LLM application across users, prompts, retrieval, model providers, tools, output handling and operational controls.

Read the guide →
Editorial cover for Access control architecture for AI agents

Access control architecture for AI agents

Design identity, permissions, approval gates, tool boundaries and audit evidence for AI agents that can take actions.

Read the guide →
Editorial cover for Secure cloud architecture: a practical blueprint

Secure cloud architecture: a practical blueprint

Design a secure cloud architecture around identity, accounts, network zones, workloads, data, logging, resilience and shared responsibility.

Read the guide →
Editorial cover for Designing a secure cloud landing zone

Designing a secure cloud landing zone

Create a cloud landing zone with account separation, federated identity, policy guardrails, network services, logging and an operating model.

Read the guide →
Editorial cover for Identity architecture for hybrid and multi-cloud environments

Identity architecture for hybrid and multi-cloud environments

Unify workforce, workload and privileged identity across on-premises and multiple clouds without creating a universal administrator.

Read the guide →
Editorial cover for Cloud security logging architecture that responders can use

Cloud security logging architecture that responders can use

Design cloud logging around investigation questions, protected collection, normalised context, detection ownership and sustainable retention.

Read the guide →
Editorial cover for Design cloud backup and recovery for a real cyber incident

Design cloud backup and recovery for a real cyber incident

Build isolated backups, recovery identities, clean restore procedures and business-tested recovery evidence for cloud services.

Read the guide →
Editorial cover for Types of cybersecurity: a complete practical guide

Types of cybersecurity: a complete practical guide

Understand the major types of cybersecurity, what each protects, the controls it uses and how the disciplines work together.

Read the guide →
Editorial cover for Network security types and controls: what each one actually does

Network security types and controls: what each one actually does

A clear guide to perimeter, segmentation, access, DNS, email, wireless, cloud network, monitoring and zero trust controls.

Read the guide →
Editorial cover for An enterprise network segmentation blueprint

An enterprise network segmentation blueprint

Plan network zones, conduits, management access, cloud connections, third parties and validation without breaking the business.

Read the guide →
Editorial cover for A zero trust implementation roadmap that starts with real services

A zero trust implementation roadmap that starts with real services

Move from zero trust principles to service inventory, identity, device, policy, segmentation, telemetry and measured rollout.

Read the guide →
Editorial cover for API security architecture from edge to data

API security architecture from edge to data

Design API discovery, authentication, authorization, validation, rate limits, service identity, logging and lifecycle controls.

Read the guide →
Editorial cover for How to build a cybersecurity team: a practical hiring plan

How to build a cybersecurity team: a practical hiring plan

Plan cybersecurity recruitment around business outcomes, operating responsibilities, role combinations, seniority and provider support.

Read the guide →
Editorial cover for Cybersecurity organisation chart: teams, ownership and handoffs

Cybersecurity organisation chart: teams, ownership and handoffs

Design a cybersecurity organisation across leadership, governance, architecture, engineering, operations, identity, resilience and assurance.

Read the guide →
Editorial cover for The CTO security operating model: turning accountability into practice

The CTO security operating model: turning accountability into practice

A practical security operating model for CTOs covering ownership, engineering standards, risk decisions, resilience and executive reporting.

Read the guide →
Editorial cover for The first ten cybersecurity hires: roles and sequence

The first ten cybersecurity hires: roles and sequence

A flexible sequence for the first ten security hires across leadership, product, cloud, operations, GRC, identity and detection.

Read the guide →
Editorial cover for Build a cybersecurity skills matrix people will actually use

Build a cybersecurity skills matrix people will actually use

Create a cybersecurity skills matrix based on real work, proficiency evidence, career paths and team resilience rather than certificates alone.

Read the guide →
Editorial cover for Security operations: an operating model beyond alert queues

Security operations: an operating model beyond alert queues

Build security operations around detection, triage, investigation, containment, engineering, threat context and measurable service outcomes.

Read the guide →
Editorial cover for How to design a modern SOC: people, process and technology

How to design a modern SOC: people, process and technology

Design an internal, outsourced or co-managed SOC with clear scope, roles, telemetry, case flow, response authority and quality measures.

Read the guide →
Editorial cover for Incident response command structure for technical and business teams

Incident response command structure for technical and business teams

Define incident command, technical leads, communications, legal support, business decisions and recovery ownership before a crisis.

Read the guide →
Editorial cover for The detection engineering lifecycle: from threat idea to trusted signal

The detection engineering lifecycle: from threat idea to trusted signal

Create, test, deploy, tune and retire security detections with threat hypotheses, data contracts, runbooks and measurable quality.

Read the guide →
Editorial cover for Security metrics a CTO and board can actually use

Security metrics a CTO and board can actually use

Report cyber risk through service exposure, control evidence, detection, response, recovery and accountable decisions—not vanity counts.

Read the guide →
Editorial cover for Security governance with NIST CSF 2.0: making Govern operational

Security governance with NIST CSF 2.0: making Govern operational

Use the NIST CSF 2.0 Govern function to align risk appetite, roles, policy, supply chain and oversight with security operations.

Read the guide →
Editorial cover for A security architecture review process engineers will use

A security architecture review process engineers will use

Create tiered security architecture reviews with early engagement, threat modelling, clear decisions, evidence and reusable patterns.

Read the guide →
Editorial cover for Third-party security: an operating model from selection to exit

Third-party security: an operating model from selection to exit

Manage supplier security through service criticality, due diligence, contract controls, access, monitoring, incidents and exit planning.

Read the guide →
Editorial cover for Run a cybersecurity risk assessment workshop that produces decisions

Run a cybersecurity risk assessment workshop that produces decisions

Facilitate a focused cyber risk workshop using business services, threat scenarios, control evidence, ownership and treatment decisions.

Read the guide →
Editorial cover for How to run a cybersecurity tabletop exercise that changes readiness

How to run a cybersecurity tabletop exercise that changes readiness

Design and facilitate cyber tabletop exercises with realistic injects, decision pressure, clear objectives and accountable improvements.

Read the guide →
Editorial cover for What the 2026 breach data changes about vulnerability priorities

What the 2026 breach data changes about vulnerability priorities

Why exploit-driven access, ransomware and third-party exposure deserve a different operating rhythm.

Read the field note →
Editorial cover for OWASP Top 10:2025—what engineering leaders should do next

OWASP Top 10:2025—what engineering leaders should do next

Translate the updated awareness list into backlog, design and supply-chain decisions.

Read the field note →
Editorial cover for A practical control map for agentic AI systems

A practical control map for agentic AI systems

Identity boundaries, tool permissions, evidence, monitoring and human approval.

Read the field note →
Editorial cover for Ransomware protection: five controls to verify this quarter

Ransomware protection: five controls to verify this quarter

A focused check across exposure, identity, recovery and response.

Read the guide →
Editorial cover for Build a vulnerability lifecycle people will actually follow

Build a vulnerability lifecycle people will actually follow

From discovery and validation to ownership, remediation and closure.

Read the guide →
Editorial cover for Cloud security fundamentals across AWS, Azure and GCP

Cloud security fundamentals across AWS, Azure and GCP

Identity, visibility, configuration, data boundaries and response readiness.

Read the guide →
Editorial cover for Privileged access management without operational gridlock

Privileged access management without operational gridlock

Control high-impact accounts while preserving usable workflows.

Read the guide →
Editorial cover for What a modern penetration test should include

What a modern penetration test should include

Scope, rules of engagement, evidence and outcomes beyond a scanner report.

Read the guide →
Editorial cover for Zero trust as an operating model—not a product category

Zero trust as an operating model—not a product category

A phased implementation path built around identity and verification.

Read the guide →
Editorial cover for Endpoint security: the controls behind the console

Endpoint security: the controls behind the console

Coverage, tamper resistance, telemetry and response capability.

Read the guide →
Editorial cover for A practical PCI DSS readiness checklist

A practical PCI DSS readiness checklist

Evidence, scoping and control ownership for technology teams.

Read the checklist →
Editorial cover for HIPAA security questions for technology suppliers

HIPAA security questions for technology suppliers

Where product, cloud and operational responsibilities meet.

Read the guide →
Editorial cover for Cloud-native security, explained without the buzzwords

Cloud-native security, explained without the buzzwords

A direct guide to workloads, identities, pipelines and runtime risk.

Read the guide →
Editorial cover for Network segmentation patterns that reduce blast radius

Network segmentation patterns that reduce blast radius

Practical boundaries, validation and exception management.

Read the guide →
Editorial cover for Adversarial machine learning: a usable starting point

Adversarial machine learning: a usable starting point

Threats to models, data, interfaces and the systems around them.

Read the analysis →
Editorial cover for Security awareness that respects the workforce

Security awareness that respects the workforce

Train for realistic decisions instead of measuring blame.

Read the guide →
Editorial cover for What 24/7 monitoring should deliver to the business

What 24/7 monitoring should deliver to the business

Coverage, escalation, evidence and outcomes for managed security.

Read the guide →
Editorial cover for Connect data security, compliance and operational risk

Connect data security, compliance and operational risk

A governance model that keeps evidence close to the work.

Read the guide →

Need an answer for your environment?

Send the context. We will help you turn broad guidance into a focused next step.

Ask a security question →