Insights
Security notes, writeups and things worth thinking about.
Technical when it needs to be. Human when it can be.
Application Security
Why access control is a business risk, not just a technical one
A simple way to think about authorization problems before they turn into customer or operational problems.
Read it
API Security
Three things I would check before opening an API to customers
A small pre-launch security pass that catches issues teams often discover later.
Read it
Cyber Risk
Security before the audit
Why waiting for a questionnaire or compliance deadline can make security work more expensive than it needs to be.
Read it