Skip to content

An independent trade publication

Enterprise Cybersecurity

Independent · Since 2013 · No vendor noise

Security architecture and threat modeling for the people who own the blast radius.

Long-form guides and field notes for the architects and engineering leaders who have to model the threat before an attacker does. Read by practitioners, funded by no one.

The beat

Threat Modeling

STRIDE, attack trees, and the practice of finding weaknesses on paper before an adversary finds them in production.

Security Architecture

Trust boundaries, blast-radius containment, and the design decisions that decide how bad a breach gets.

Compliance & Governance

SOC 2, ISO 27001, and turning audit obligations into controls that actually reduce risk.

Detection & Response

Telemetry, detection engineering, and shrinking the gap between compromise and containment.

The lead

April 24, 2026 · 11 min read

The State of Threat Modeling in 2026

A working architect's view of threat modeling in 2026 — what's changed, what hasn't, which frameworks still earn their keep, and where AI tooling actually helps versus where it's noise.

Read the guide →

More from the desk

Threat Modeling

STRIDE vs PASTA vs LINDDUN: Which Framework for Which System

Most framework comparisons read like feature checklists. This one gives working advice: when STRIDE, PASTA, and LINDDUN each earn their place, when they don't, and how to decide without over-thinking it.

July 29, 2026 · 10 min read

Security Architecture

How to Run an Architecture Review Board That Actually Works

Most architecture review boards become approval bottlenecks that ship rubber stamps. A working ARB is a lightweight decision-forcing function. Here's the difference, and how to run the second kind.

July 27, 2026 · 8 min read

Compliance & Governance

CMMC 2.0 Readiness: What Defense Contractors Need to Do Now

CMMC certification is moving from theory to contract requirement, and most of the defense industrial base is not ready. A working readiness plan, the scoping decisions that decide the cost, and the mistakes that stall a certification.

July 23, 2026 · 12 min read

The network

Enterprise Cybersecurity sits between the research that informs it and the tools it points you toward.

The Enterprise Cybersecurity Brief

One email, occasionally. Threat modeling notes, security architecture reads, and what's actually working in enterprise programs — no vendor noise.

Newsletter signup is not configured yet.