Articles from the team
- Cloud Security8 min read
Most risk registers are a spreadsheet updated the week before an audit
A register nobody opens is not a control, it is an artefact. What makes one get read: owners, expiry dates, and covering cost and operations rather than security alone.
- DevSecOps8 min read
Branch protection is a setting. At five hundred repositories it is a governance problem
Per-repository controls drift the moment you stop watching them, and every new repository starts ungoverned. What to centralise, what to leave alone, and the one number worth reporting.
- DevSecOps9 min read
Your build system holds credentials to everything and is governed like a dev tool
CI can reach your cloud, your registries and your production deploy path. It is almost never in scope for the controls that protect any of them. What to change, in order.
- Application Security9 min read
The OWASP Top 10 has been rewritten. Your AppSec backlog is now out of date
Misconfiguration jumped to #2, supply chain is new at #3, SSRF disappeared and there is a category that did not exist before. What the 2025 list changes about where you spend your next quarter.
- AI Security9 min read
The AI security checklist we actually use, and how to verify each control
Seven sections, each with the check that tells you whether the control exists. Inventory first, because the other six assume you know what is running.
- AI Security8 min read
Getting an AI coding assistant approved instead of blocked
Security says no, the business rolls it out anyway, and now nobody is watching it. The control set that gets a coding assistant approved on purpose.
- Application Security8 min read
Turning a scanner dump into a list developers will actually action
SAST, DAST and SCA will hand you thousands of findings sorted by a severity that knows nothing about your environment. Ranking them is the work.
- AI Security10 min read
OWASP's LLM Top 10 for 2026 is the first one backed by incident data. Three entries moved because of it
The 2026 list weighs practitioner consensus against what has actually gone wrong in the field. Where those two disagree is where your roadmap is probably wrong.
- AI Security11 min read
OWASP has published a Top 10 for agentic AI. If you are running agents, here is what it means for you.
We read all ten entries of OWASP's new Top 10 for Agentic Applications and mapped them to the controls you should already be building — in the order that removes the most risk.
- Cloud Security9 min read
You rolled out MFA and conditional access. Your workloads still trust each other completely
Most zero-trust programmes finish the human half and stop. The identities that actually move laterally in a cloud breach are the non-human ones, and almost nobody has inventoried them.
Have a question we have not written about?
Ask us directly. We reply within one business day.