Skip to content

An independent trade publication

Enterprise Cybersecurity

Guides

Working reference for security architects and engineering leaders — reverse chronological, filterable by category.

Threat Modeling

STRIDE vs PASTA vs LINDDUN: Which Framework for Which System

Most framework comparisons read like feature checklists. This one gives working advice: when STRIDE, PASTA, and LINDDUN each earn their place, when they don't, and how to decide without over-thinking it.

July 29, 2026 · 10 min read

Security Architecture

How to Run an Architecture Review Board That Actually Works

Most architecture review boards become approval bottlenecks that ship rubber stamps. A working ARB is a lightweight decision-forcing function. Here's the difference, and how to run the second kind.

July 27, 2026 · 8 min read

Compliance & Governance

CMMC 2.0 Readiness: What Defense Contractors Need to Do Now

CMMC certification is moving from theory to contract requirement, and most of the defense industrial base is not ready. A working readiness plan, the scoping decisions that decide the cost, and the mistakes that stall a certification.

July 23, 2026 · 12 min read

Compliance & Governance

Third-Party Risk Management for SaaS-Heavy Organizations

The annual security questionnaire was built for a world with a dozen vendors. Modern organizations run on hundreds of SaaS tools, and the old model quietly stopped working. A realistic approach to third-party risk when the vendor list never stops growing.

July 16, 2026 · 10 min read

Security Architecture

Zero Trust Architecture for Mid-Market Companies: A Realistic Guide

Zero trust is the most oversold term in security, and the vendor version — buy a product, become zero trust — is a myth. What the model actually is, why mid-market companies get it wrong, and a realistic sequence that starts with the one thing that matters most.

July 13, 2026 · 11 min read

Detection & Response

Tabletop Exercises That Don't Suck: A CISO's Playbook

Most incident tabletops are theater — a scripted meeting everyone survives, followed by false confidence. A working exercise surfaces the decisions your organization can't yet make under pressure. How to run one that actually finds the gaps.

July 9, 2026 · 8 min read

Threat Modeling

The State of Threat Modeling in 2026

A working architect's view of threat modeling in 2026 — what's changed, what hasn't, which frameworks still earn their keep, and where AI tooling actually helps versus where it's noise.

April 24, 2026 · 11 min read