Practice, at length.
A Speak to It™ term tells you what something is. This is where the same subject is worked through properly: what good looks like, what to require, how to evidence it, and where most teams get it wrong.
289 written, 1405 more commissioned. Free to read, because a common professional vocabulary should not depend on ability to pay.
AI API Key Exposure
Developer Portal. Jupyter Notebook. GitHub. Public Repository. Bot. Six Weeks.
6 min read · 15 Sep 2026
Assurance vs Validation
SOC 2 Provides Assurance. Your Specific Risk Requires Validation.
6 min read · 15 Sep 2026
API Identity Misuse
The Application Is Decommissioned. The API Key Still Works. Somebody Else Is Using It.
7 min read · 14 Sep 2026
Cross-Border Data Flow Risks
The DPA Covers the Transfer. Nobody Covers Where the Data Goes After That.
9 min read · 14 Sep 2026
AI Adversarial Attacks
97% Benchmark Accuracy. Adversarial Perturbation: Invisible to Humans. Model Confidence on Wrong Classification: 97.3%.
4 min read · 13 Sep 2026
Build Pipeline Integrity
Production Environment: Secured. CI/CD Pipeline: 12 Third-Party Integrations. 7 Running on Production Credentials. 1 With Authentication Bypass.
4 min read · 13 Sep 2026
Audit Evidence Quality
Screenshot of MFA Enabled. One Role. Test Environment. Eleven Months Ago.
6 min read · 12 Sep 2026
Data Access Logging Gaps
The Access Controls Are Strong. Nobody Is Watching What They Access.
9 min read · 12 Sep 2026
Access Certification Effectiveness
100% Completion Rate. 11.7 Seconds Per Account. The Review Was a Checkbox.
6 min read · 11 Sep 2026
Vendor Patch Cadence Reality
Patch Policy: 30 Days. Average Actual Patch Time: 73 Days. Unpatched Critical Vulnerabilities: 4 of 14. Policy: Confirmed. Adherence: Not Measured.
4 min read · 11 Sep 2026
AI Attack Surface Expansion
Three AI Vendors. Each Assessed Independently. Aggregate Data Access: Complete Customer Profile. Aggregate Assessment: Not Conducted.
5 min read · 10 Sep 2026
Audit Scope Limitations
Three Samples Passed. Forty-Five Were Not Tested. The Conclusion Was Effective.
7 min read · 10 Sep 2026
Access Policy Misconfigurations
The Policy Was Correct at Deployment. The System It Governs Changed. The Policy Did Not.
6 min read · 9 Sep 2026
Data Access Privilege Creep
Each Grant Was Reasonable. The Accumulation Is Not.
6 min read · 9 Sep 2026
AI Bias in Risk Decisions
Objective Risk Score. Training Data: Historical Assessments. More Intensive Assessment: More Findings. Score: Circular.
6 min read · 8 Sep 2026
Artifact Registry Security
Artifact: Signed. Registry: Mutable. Write Access: 17 Accounts. Former Employee Accounts: 3 Still Active.
4 min read · 8 Sep 2026
Compliance Automation Gaps
Compliance Dashboard: Green. New Cloud Region Not Connected. New Auth System Not Integrated.
6 min read · 7 Sep 2026
Data Access via APIs
The Database Controls Are Strong. The API Returns Everything to Everyone.
8 min read · 7 Sep 2026
Alert Fatigue Across Ecosystems
Twelve Hundred Alerts. Forty-Five Seconds Each. Critical Indicator: Alert 1173.
5 min read · 6 Sep 2026
Supply Chain Attack Detection
SOC Coverage: Excellent. Detection Infrastructure: Production-Focused. Build Pipeline: Not Monitored. Compromise: 8 Months Undetected.
5 min read · 6 Sep 2026
AI Compliance Enforcement
AI Policy: Eighteen Months Active. Reviewed Systems: Seven. Unreviewed Production Systems: Four. Enforcement: Absent.
5 min read · 5 Sep 2026
Compliance vs Security Gap
PCI-DSS Compliant. Breached Through an Out-of-Scope System. Both True.
6 min read · 5 Sep 2026
Alert Prioritisation Gaps
Static Medium Priority. Current Context: Primary TTP of Active Threat Actor. Four-Hour Review Queue.
6 min read · 4 Sep 2026
Data Anonymization Myths
The Dataset Was Anonymized. 87% of Records Were Re-Identified in Two Weeks.
9 min read · 4 Sep 2026
AI Compliance vs Security Gap
GDPR: Confirmed. SOC 2: Confirmed. Article 22 Right to Explanation: Model Cannot Provide It.
6 min read · 3 Sep 2026
Branch Protection and Code Review Bypasses
Branch Protection: Configured. Admin Access: Never Revoked from Incident Response. Bypass: Direct Push to Main. Code Review: None. Hardcoded Key and Path Traversal: Introduced.
5 min read · 3 Sep 2026
Continuous Compliance Reality
All Controls Green. Friday Misconfiguration Detected Monday. Sixty-Three Hours.
6 min read · 2 Sep 2026
Data Auditability Challenges
They Are Compliant. They Cannot Prove It. Both Are True.
7 min read · 2 Sep 2026
Attack Dwell Time via Vendors
Forty-Eight Days Across Three Organisations. Customer Data Was the Final Target.
5 min read · 1 Sep 2026
Code Signing and Its Limits
Signature: Valid. Certificate: From Recognised CA. Key: Compromised 11 Months Prior. All Releases Since: Potentially Attacker-Signed.
5 min read · 1 Sep 2026
AI Continuity and Exit Planning
Model Sunset: 90 Days. Training Data: Not Maintained. Feature Engineering: Undocumented. Alternatives: Not Evaluated. Continuity Plan: None.
5 min read · 31 Aug 2026
Continuous Monitoring Gaps
Assessed Twelve Months Ago. Forty-Three Point Rating Drop Since. Nobody Noticed.
6 min read · 31 Aug 2026
Authentication vs Authorization Confusion
Authentication Confirmed Identity. Authorization Determines What They Can Do.
6 min read · 30 Aug 2026
Data Breach Notification Gaps
The Vendor's 72-Hour Clock Is Also Your 72-Hour Clock.
9 min read · 30 Aug 2026
AI Data Lineage Issues
AI Detected at 2:17am. Response Started 9:15am. Seven Hours. Attacker: Still Present.
6 min read · 29 Aug 2026
Container Image Supply Chain
Application Code: Reviewed. Container Base Image: 4 Months Outdated. System Library CVEs: 17. Critical RCEs: 2.
4 min read · 29 Aug 2026
Contractual vs Actual Controls
The Contract Requires MFA. Nobody Has Verified It Is Enforced.
6 min read · 28 Aug 2026
Data Deletion Validation
The Deletion Was Confirmed. The Evidence Was a Screenshot of the Wrong Table.
9 min read · 28 Aug 2026
Dependency Confusion Attacks
Internal Package: acme-internal-utils. Job Posting: Mentioned Internal Tooling. Public Registry: Attacker Published Same Name, Higher Version. 23 Applications: Compromised.
4 min read · 27 Aug 2026
Vendor Backup Storage Exposure
The Copy of Your Data That Nobody Assessed
10 min read · 27 Aug 2026
AI Data Retention Risks
M&A Targets Uploaded for Summarisation. Retained Thirty Days. Zero Retention: Not Configured.
6 min read · 26 Aug 2026
Control Duplication
Three Teams. Three Controls. All Doing the Same Thing. None Knowing About the Others.
6 min read · 26 Aug 2026
Breach Attribution Challenges
Three Hypotheses. All Consistent With Evidence. Attribution May Never Be Definitive.
5 min read · 25 Aug 2026
Data Exfiltration Paths
The Sophisticated Attack Vector Is a Spreadsheet Attached to a Gmail.
9 min read · 25 Aug 2026
AI-Driven Automation Risks
847 Renewal Offers. 312 Sent to Customers Who Had Cancelled. Automation: Correct. Integration: Missing.
5 min read · 24 Aug 2026
Dependency Pinning vs Floating Versions
Version Spec: >=2.0.0. New Version Published Thursday: 2.4.0. Tests: Passed Thursday. Production: Deployed Different Software Friday.
4 min read · 24 Aug 2026
Control Inheritance Misunderstandings
ISO 27001 Certified. The Certification Scope Does Not Cover Your Service.
6 min read · 23 Aug 2026
Data Governance Tooling Gaps
The Policies Are Excellent. The Tools That Would Enforce Them Were Never Bought.
6 min read · 23 Aug 2026
Breach Simulation Gaps
Simulation: Scripted Scenario. Real Breach: Unknown Scenario, Uncooperating Attacker, Uncertain Detection.
5 min read · 22 Aug 2026
Vendor Development Environment Security
Production: Secured. Developer Workstations: Local Admin. Credentials in Dotfiles. Personal GitHub Accounts for Work. Malicious VSCode Extensions Installed.
4 min read · 22 Aug 2026
AI Explainability Challenges
SHAP Values: What the Model Used. Why Those Features Are Valid Credit Risk Indicators: Not Answerable from Outputs.
4 min read · 21 Aug 2026
Control Mapping Inconsistencies
One Control Mapped to Five Frameworks. The Mapping Accuracy Varies by Framework.
6 min read · 21 Aug 2026
Cloud Security
Vendor Access, Misconfigurations, and the Risk You Invited In
7 min read · 20 Aug 2026
Data Governance vs Enforcement
The Policy Was Approved Three Years Ago. Nobody Has Checked Compliance Since.
8 min read · 20 Aug 2026
AI Governance Frameworks
AI Ethics Policy: Confirmed. Model Review Process: Described. Implementation Evidence: Not Requested.
5 min read · 19 Aug 2026
Vendor Security Disclosure Programmes
Disclosure Programme: Published. Report: Submitted. Acknowledged: Yes. Patched Within 7 Months: No. Advance Notice to Customers: Zero.
4 min read · 19 Aug 2026
Control Testing Depth
No Critical Vulnerabilities Found. Internal Network Not in Scope. Neither Was the Cloud.
6 min read · 18 Aug 2026
Data Inventory Completeness
The Inventory Has Seven Systems. The Environment Has Twenty-Three.
8 min read · 18 Aug 2026
Conditional Access Gaps
Strong Authentication. Unmanaged Device. Untrusted Network. Sensitive Data Downloaded.
6 min read · 17 Aug 2026
The Future of Software Supply Chain Security
Current Programme: Current for Today. AI-Generated Code: In Vendor Pipelines Now. Post-Quantum: On the Timeline. Regulatory Acceleration: Already Landed.
4 min read · 17 Aug 2026
AI Governance Gaps
AI Ethics Committee: Reviewed and Approved. EU AI Act High-Risk Classification: Not Assessed.
7 min read · 16 Aug 2026
Control vs Implementation Gap
The Penetration Test Programme Exists. The Last Test Was Fourteen Months Ago.
6 min read · 16 Aug 2026
Coordinated Response Failures
Vendor Plan: Preserve Everything. Customer Plan: Service Restored in Twenty-Four Hours. Both Correct. Both Impossible.
5 min read · 15 Aug 2026
Data Lifecycle Mismanagement
Creation Is Governed. Retention Is Optional. Deletion Is Nobody's Job.
9 min read · 15 Aug 2026
AI Hallucination Risk in Decisions
Credit Denied. Reason: Fourteen Features. Dominant Feature: Payment Timing Meets Geographic Mobility. Appeal: Dismissed.
6 min read · 14 Aug 2026
Infrastructure-as-Code Supply Chain Risk
IaC: Reviewed. Third-Party Terraform Modules: 14 Months Stale. Security Group: Management Ports Open to 0.0.0.0/0. Module Review: Not Conducted.
4 min read · 14 Aug 2026
Data Lineage Across Third Parties
You Approved the First Hop. Where Did the Data Go After That?
10 min read · 13 Aug 2026
Evidence vs Attestation
The Attestation Was Accurate for Two of Three Databases. One Was Different.
6 min read · 13 Aug 2026
Cross-Org Response Timelines
Same Threat. Two IR Teams. Seven IOCs and Four IOCs. No Sharing. Ten Total Missed.
5 min read · 12 Aug 2026
Supply Chain Incident Response
IR Programme: Mature for Production Incidents. Supply Chain Playbook: None. Affected Release Identification: No Process. Customer Deployment Inventory: Not Maintained.
4 min read · 12 Aug 2026
AI Incident Response Gaps
AI Decision Incident. IR Playbook: Data Breach, Ransomware, Outage. AI Incident: Not Covered.
5 min read · 11 Aug 2026
Exception Management Abuse
Forty-One Exceptions. Thirty-Seven Are Engineering Deferrals. Four Over a Year Old.
6 min read · 11 Aug 2026
Cross-Platform Visibility
Vendor Monitors AWS. DevOps Provider Monitors the Cluster. Both Assume. Neither Confirms.
5 min read · 10 Aug 2026
Data Minimization Failures
You Sent Everything. The Vendor Needed Some of It. The Breach Exposed All of It.
9 min read · 10 Aug 2026
AI Inference Data Leakage
Zero Retention Configured. In-Session Context Window: Customer Data Accessible to Crafted Prompts.
6 min read · 9 Aug 2026
Open Source License Risk
Platform Deployed: 18 Months. AGPL Component: Discovered by Legal. Disclosure Requirement: Potentially Applies to Vendor's Proprietary Code. Legal Review: 6 Months.
4 min read · 9 Aug 2026
Data Ownership Ambiguity
Your Data Trained the Model. The Vendor Owns the Model.
8 min read · 8 Aug 2026
GRC Tooling Limitations
The GRC Platform Manages What You Put Into It. It Does Not Know What You Left Out.
7 min read · 8 Aug 2026
Cross-System Identity Propagation
Deprovisioned in Azure AD. Active in the Jira Instance Nobody Added to the Connector.
6 min read · 7 Aug 2026
Supply Chain Risk in Mergers and Acquisitions
Platform Acquired. Open-Source Dependencies: 1,247. Critical Vulnerabilities: 73. Unresolvable Due to EOL: 14. Runtime: 3 Major Versions Behind. Due Diligence: No Supply Chain Assessment.
4 min read · 7 Aug 2026
AI Logging and Traceability
Audit Log: API Called. Decision Returned. Model Version: Not Captured. Input Features: Not Captured. Decision: Unreconstructable.
6 min read · 6 Aug 2026
Governance Accountability Gaps
RACI Matrix Exists. Nobody Made the 11pm Call. Nobody Read the Contract.
6 min read · 6 Aug 2026
Cross-Tenant Access Risks
When Your Vendor Serves Other Customers , and Their Risk Becomes Yours
8 min read · 5 Aug 2026
Data Replication Risks
The Primary Database Has Eleven Copies. How Many Are Governed?
9 min read · 5 Aug 2026
AI Misuse by Vendors
Support AI. Historical Training Labels. Historical Bias Encoded as Normal. Production Outage: Low Priority.
5 min read · 4 Aug 2026
Supply Chain Security Maturity Assessment
SBOM: Level 3. SCA: Level 3. SLSA: Level 0 (Unaware). Build Pipeline Security: Level 1. Supply Chain Monitoring: Level 0.
4 min read · 4 Aug 2026
Data Residency vs Access
The Data Lives in Germany. The Support Team Is in Manila. Both Are True.
9 min read · 3 Aug 2026
Governance Ownership Ambiguity
Three Teams Own the Vendor. None of Them Owned the Incident Response.
6 min read · 3 Aug 2026
Cross-Tenant Attack Detection
Customer A Breached. Investigation: Did Not Spread. Customer B Notified Three Weeks Later.
5 min read · 2 Aug 2026
NIST SP 800-161 for Practitioners
NIST 800-161: Reviewed and Considered Aligned. Implementation Tier: Not Assessed. Controls Implemented: Not Verified.
4 min read · 2 Aug 2026
AI Misuse Scenarios
AI Sales Tool: Approved. Personalised Outreach: Generated. Prospect Research: Autonomous, Undisclosed, Unconsented.
5 min read · 1 Aug 2026
Policy vs Enforcement
Twelve-Character Policy. Eight-Character Configuration. Both Active Simultaneously.
6 min read · 1 Aug 2026
Data Exfil Detection Gaps
Twelve Transfers. Eleven Gigabytes. All Below the DLP Threshold. No Alerts.
6 min read · 31 Jul 2026
Data Segregation Failures
The Tenant Isolation Is a WHERE Clause. One Bug and It Is Gone.
8 min read · 31 Jul 2026
AI Model Supply Chain Risk
The Model Works Perfectly. The Risk Is in What It Was Trained On and Who Has Access to It.
8 min read · 30 Jul 2026
Vendor Open Source Contribution Risk
Engineer: 3 Years Trusted Contributions. Employee Status: Departed. PR: Backdoor. Merge: Approved Based on Reputation. Affected Vendors: 14.
4 min read · 30 Jul 2026
Data Sovereignty Enforcement
The Data Is Sovereign. The Parent Company Is Not.
7 min read · 29 Jul 2026
Questionnaire Fatigue vs Real Risk
400 Questions. Three Weeks. The Specific Risk Was Never Asked About.
5 min read · 29 Jul 2026
Delegated Admin Risks
Delegated Admin Granted at Onboarding. Configuration Ended. Access Remains.
7 min read · 28 Jul 2026
Package Registry Trust Model
Package: Legitimate. Maintainer: Compromised via Social Engineering. Version Update: Bug Fix + Credential Harvesting. Downloads: 14,000 Weekly.
4 min read · 28 Jul 2026
AI Model Version Control
Foundation Model: Eleven Months Outdated. Security Patches: Three. Privilege Escalation: Unpatched. Validation Cycle: Three to Four Months.
6 min read · 27 Jul 2026
Regulatory Blind Spots
US Customer. US Vendor. Irish Data Storage. GDPR Applies. Was Never Assessed.
6 min read · 27 Jul 2026
Data Tagging Inconsistencies
Confidential in the Source System. Public in the Analytics Platform. Same Data.
6 min read · 26 Jul 2026
Detection Blind Spots
Platform Sees Everything Configured. Configuration Set at Deployment. New Services: Not Configured.
7 min read · 26 Jul 2026
AI Operational Risks
94% Accuracy. 6% Missed. Missed Records: Systematically the Most Complex. Human Review: Assumed Comprehensive.
5 min read · 25 Jul 2026
Supply Chain Security in Regulated Industries
FDA SBOM Requirement: Met. Critical CVEs in SBOM: 17. VEX Documentation: Not Provided. Regulatory Review Delay: 4 Months.
4 min read · 25 Jul 2026
Data Usage Monitoring
You Know What You Sent. You Have No Idea What They Do With It.
7 min read · 24 Jul 2026
Regulatory Interpretation Gaps
Five Years From Collection. Five Years From Last Transaction. Both Claim Compliance.
5 min read · 24 Jul 2026
Detection Engineering Gaps
Default Rules. Platform Inherited. No Customisation. Attacker Uses Industry-Specific Techniques.
6 min read · 23 Jul 2026
Reproducible Builds in Practice
500 Packages Analysed. 312: Reproducible. 188: Not Reproducible. The 188: Source Code Does Not Uniquely Determine Binary.
4 min read · 23 Jul 2026
AI Output Data Leakage
AI Draft. Confident Statements. Factually Incorrect. Published as Analysis.
6 min read · 22 Jul 2026
Regulatory Overlap Confusion
HIPAA or PCI-DSS? Both. The More Stringent Requirement Applies.
6 min read · 22 Jul 2026
Detection vs Prevention Balance
Zero Breaches. Three Near-Misses. Prevention Working. Breach Record Not Telling the Story.
5 min read · 21 Jul 2026
Encryption at Rest vs In Use
AES-256 Confirmed. The DBA Reads It in Plaintext. Both Are True.
8 min read · 21 Jul 2026
AI Plugin Vulnerabilities
94% Detection Rate. 56 Hours of False Positive Investigation. 23 Missed Anomalies. None of It in the Dashboard.
7 min read · 20 Jul 2026
Supply Chain Risk Quantification
Risk Ratings: High, Medium, High. Financial Exposure: Not Calculated. Board Communication: Not Possible. Investment Justification: Not Available.
4 min read · 20 Jul 2026
Insider Access at Vendors
The Threat That Has Valid Credentials, Authorized Access, and Four Months of Patience.
9 min read · 19 Jul 2026
Reporting vs Insight
Four Consistent Numbers. Six Months of Reports. Zero Decisions Informed.
6 min read · 19 Jul 2026
Device Trust for Vendor Access
Perfect Authentication. Unmanaged Device. Customer Data on a Personal Laptop.
6 min read · 18 Jul 2026
Programming Language Runtime Security
Platform: Well-Patched Application Code. Runtime: Python 3.9, EOL October 2025. Critical Runtime CVEs: 3. Future Patches: None.
4 min read · 18 Jul 2026
AI Risk Scoring Reliability
Risk Score: 73. Historical Accuracy at This Range: Unknown. Confidence Interval: None. Trend: Not Available.
6 min read · 17 Jul 2026
Risk Acceptance Misuse
Accepted Three Years Ago. Still Accepted. Nobody Has Reviewed It.
6 min read · 17 Jul 2026
Forensics Access Challenges
Forensic Access Requested. Legal Hold In Place. Investigation Blocked for Three Weeks.
6 min read · 16 Jul 2026
Metadata Exposure Risks
The Data Was Protected. The Metadata Told Them Everything They Needed.
9 min read · 16 Jul 2026
AI Security Monitoring
Weekly Reports: Alert Volumes, Resolution Rates, Coverage Statistics. Gaps, Limitations, Human Supplement Needed: Not Shown.
6 min read · 15 Jul 2026
Software Bill of Materials Automation
847 SBOM Documents. 7 Formats. 93% Never Parsed. 41% Over 12 Months Old. Supply Chain Visibility: None.
4 min read · 15 Jul 2026
Risk Appetite Misalignment
Risk Appetite: No Vendor Over Fifteen Percent. One Vendor at Forty-Two. Predates the Policy.
6 min read · 14 Jul 2026
Sensitive Data Discovery Gaps
The Vendor Does Not Know They Have Your Sensitive Data. Neither Do You.
8 min read · 14 Jul 2026
Identity Anomaly Detection Gaps
2am. Lagos. Seventeen Apps. Six Hundred Files. No Alert.
7 min read · 13 Jul 2026
Software Bill of Materials , Beyond the Mandate
SBOM: Provided. Critical Vulnerabilities Listed: 14. SBOM Age: 6 Months. Vulnerability Status: Not Included. Regulator: Not Satisfied.
4 min read · 13 Jul 2026
AI Security Testing Gaps
SOC 2: Infrastructure Covered. Pentest: Web App Covered. Code Review: Application Covered. AI Model: Not Tested.
6 min read · 12 Jul 2026
Risk Communication Gaps
The Risk Was Identified. It Was Documented. It Was Never Communicated to the People Who Could Have Done Something About It.
7 min read · 12 Jul 2026
Identity Attack Surface Expansion
One IdP Three Years Ago. Seven Authentication Systems Today. Who Is Mapping Them?
6 min read · 11 Jul 2026
Structured vs Unstructured Data Risk
The Database Is Governed. The Shared Drive Is Not. Both Hold Your Data.
9 min read · 11 Jul 2026
AI Supply Chain Dependencies
Four AI Pipeline Libraries. Three Well-Audited. One: Single Maintainer, Eight Months Inactive, Arbitrary Code Execution.
6 min read · 10 Jul 2026
Software Composition Analysis Gaps
SCA Configured: Main Branch, Python Only, CVE IDs Only. Uncovered: 7 Repositories, Go and Java Services, Non-CVE Issues.
4 min read · 10 Jul 2026
Risk Prioritisation Failures
Twelve High-Priority Items. One Matters Most. None Are Being Treated Differently.
6 min read · 9 Jul 2026
Tokenization vs Masking Confusion
The Token Is Safe. The Token Vault Is the Database. Who Can Query the Vault?
9 min read · 9 Jul 2026
Identity Compromise Blast Radius
The Compromise Will Happen. The Blast Radius Is What You Govern Now.
6 min read · 8 Jul 2026
Third-Party SDK Risk
SDK Evaluated at Integration. Vendor Acquired 18 Months Later. SDK Updated: New Data Collection. Enterprise Privacy Policy: Not Reflecting New Collection.
4 min read · 8 Jul 2026
AI Threat Detection Gaps
Detection Dashboard: All Green. Novel Technique Category: Not on the Dashboard. Attacker: Undetected.
6 min read · 7 Jul 2026
Risk Quantification Challenges
Score of 47. Probability of Breach: Unknown. Financial Impact: Unknown.
6 min read · 7 Jul 2026
Identity Federation Trust Risks
You Federated with Their IdP. Their Security Posture Is Now Part of Your Perimeter.
7 min read · 6 Jul 2026
Vendor Analytics Access Risks
Read Access to Everything Is Still Access to Everything.
9 min read · 6 Jul 2026
Supply Chain AI Trust Boundaries
Finance AI Trusted to Answer Policy Questions. Attacker with Compromised Credentials: Also Trusted. AI Cannot Tell the Difference.
5 min read · 5 Jul 2026
What Is SLSA and Why Your Vendors Should Care
SLSA Compliant: Confirmed. SLSA Level: 1. What Level 1 Means: Build Process is Documented. What It Doesn't Mean: Build Is Tamper-Resistant.
6 min read · 5 Jul 2026
Risk Register Accuracy
Ninety-Three Entries. Zero Closed in Eighteen Months. Not a Risk Picture. An Archive.
6 min read · 4 Jul 2026
Vendor Backup Data Risk
The Backup Is Your Production Data. It Just Lives Somewhere Nobody Governs.
9 min read · 4 Jul 2026
Identity Governance Gaps
The IGA Covers Joiners, Movers, and Leavers. Vendor Identities Are in a Spreadsheet.
7 min read · 3 Jul 2026
Software Supply Chain for SaaS Products
Installed Software: SBOM, SCA, Provenance Verification. SaaS Platform: Same Supply Chain Risk. Visibility: None.
4 min read · 3 Jul 2026
AI Vendor Lock-In Risks
API Deprecation Notice: 30 Days. Migration Plan: None. Alternative Evaluated: None. Calibration Reproducible: No.
5 min read · 2 Jul 2026
Risk Scoring Subjectivity
Same Evidence. Same Vendor. Score of 34. Score of 67. Both From Your Team.
6 min read · 2 Jul 2026
Identity-Based Lateral Movement
One Developer Credential. Four Identity Hops. Production Database.
6 min read · 1 Jul 2026
Vendor Data Access Reviews
The Review Was Completed. Every Account Was Approved. Half of Them Should Not Exist.
9 min read · 1 Jul 2026
API-Based AI Exposure
Vendor Confirmed Data Security. Data Was Flowing to OpenAI. Enterprise Had Never Assessed OpenAI.
6 min read · 30 Jun 2026
Secrets in Source Code
Policy: No Hardcoded Credentials. Git History: AWS Key, Database Credentials, RSA Key , 31 Months. Status: Technically Still There.
4 min read · 30 Jun 2026
SLA vs Enforcement
Four SLA Breaches in Eighteen Months. Four Service Credits Issued. Behaviour Unchanged.
6 min read · 29 Jun 2026
Vendor Data Aggregation Risks
Your Dataset Is Fine. Forty of Them Combined Is a Competitive Intelligence Weapon.
8 min read · 29 Jun 2026
Identity Logging Gaps
Authentication Succeeded. The Sixty-Eight Failed Attempts Before It Are Nowhere in the Log.
7 min read · 28 Jun 2026
Sigstore and the Transparency Log Revolution
Signing Key: File on Build Server, 3 Years Unrotated. Sigstore: Free, Short-Lived Certificates, Public Audit Log. Vendor Awareness: None.
4 min read · 28 Jun 2026
LLM Integration Risks
LLM Connected to 140,000 Documents. Service Account Access Broader Than User Permissions. Context Window: Exfiltration Channel.
6 min read · 27 Jun 2026
Third-Party Audit Reliance
Big Four SOC 2. Clean Report. The Auditor's Mandate Was Not Your Risk.
6 min read · 27 Jun 2026
Identity Proofing of Vendors
The Credential Belongs to Alex Chen. Who Is Alex Chen?
7 min read · 26 Jun 2026
Vendor Data Enrichment Risks
You Sent Names and Emails. The Platform Added Thirty-Seven Data Points.
9 min read · 26 Jun 2026
Model Access Control
Authenticated API. Rate Limiting: None. Query Volume: 500,000. Model: Reconstructed by Competitor.
6 min read · 25 Jun 2026
Software Provenance Verification
Signature: Valid. Delivery: HTTPS. Download URL: Legitimate. Distribution Infrastructure: Compromised 3 Weeks Prior. Software: Attacker's.
5 min read · 25 Jun 2026
Third-Party vs Fourth-Party Risk
Your Vendor Is Assessed. Their Subprocessor Processes Half Your Data. Unassessed.
6 min read · 24 Jun 2026
Vendor Data Lake Exposure
Designed for Maximum Accessibility. Filled with Maximum Sensitivity.
9 min read · 24 Jun 2026
Identity Trust Assumptions
Trust Was Established at Onboarding. It Has Been Assumed Ever Since.
6 min read · 23 Jun 2026
The SolarWinds Lessons Still Unlearned
SolarWinds: 2020. Assessment Checklist: Same Questions as 2019. Build Pipeline: Not Asked About.
4 min read · 23 Jun 2026
Model Drift Risks
Metrics: Stable. Detection Rate: Good. Behaviour: Quietly Changed Over Eight Months.
6 min read · 22 Jun 2026
Vendor Audit Rights Enforcement
Right-to-Audit: Three Years in the Contract. Three Years Never Exercised.
6 min read · 22 Jun 2026
Incident Communication Breakdowns
Seven Emails. Three Weeks. No Technical Detail. Exposure Assessment Incomplete.
6 min read · 21 Jun 2026
Vendor Data Retention Practices
The Contract Ended. The Data Did Not.
8 min read · 21 Jun 2026
Model Theft Risks
Model Secured. Vendor API Secured. Enterprise Customer Application: Not Secured. Model: Accessed Through the Customer.
6 min read · 20 Jun 2026
Threat Intelligence for Supply Chain Attacks
Threat Intel Report: Received. CI/CD and SDK Targeting: Described. Vendor Assessments Updated: No. Two Vendors Targeted: 6 Months Later.
4 min read · 20 Jun 2026
Vendor Control Drift
Assessed Two Years Ago. Sixty Percent Security Turnover Since. Drifting.
6 min read · 19 Jun 2026
Vendor Data Transformation Risks
You Sent Customer Records. The Vendor Made Something New From Them.
6 min read · 19 Jun 2026
Incident Escalation Across Vendors
Vendor Classifies P2. Customer Regulatory Clock Starts at Hour Zero. Customer Learns at Hour Thirty-Six.
6 min read · 18 Jun 2026
Transitive Dependency Risk
Direct Dependencies: Zero Critical Vulnerabilities. Transitive Dependency Depth 4: Critical Vulnerability. SCA Scope: Direct Dependencies. Depth 4: Out of Scope.
4 min read · 18 Jun 2026
Prompt Injection via Vendors
Customer Service Chatbot. Attacker Sends an Inquiry. LLM Follows the Attacker's Instructions.
7 min read · 17 Jun 2026
Vendor Reassessment Frequency
Assessed Eighteen Months Ago. Three Hundred Million More Records Since. Still Tier 2.
6 min read · 17 Jun 2026
Incident Ownership Confusion
Legal Says Business Owns It. Business Says IR Owns It. IR Says Legal Owns It. Clock Running.
5 min read · 16 Jun 2026
Vendor Reporting Data Leaks
The Dashboard Is Beautiful. The Export Behind It Is Unprotected Customer Data.
6 min read · 16 Jun 2026
Third-Party AI Integrations
Salesforce Einstein. HubSpot AI. Workday AI. Enabled by Default. Assessed as SaaS. Never as AI.
6 min read · 15 Jun 2026
Typosquatting in Package Registries
Legitimate Package: lodash. Typosquatted: lodash-utils. Downloads: 43,000. Production Deployments: 312. CVE: None. SCA Alert: None.
4 min read · 15 Jun 2026
Incident Playbook Gaps
Step Four: Isolate Per Appendix C. Weekend. Nobody Has Appendix C. Forty Minutes Lost.
6 min read · 14 Jun 2026
Vendor Risk Aggregation
Three Low-Risk Vendors. Same Cloud Provider. Same Dataset. Same Production Access. Not Low Risk.
6 min read · 14 Jun 2026
Software Update Mechanism Security
Auto-Update: Enabled by Default. Certificate: Compromised 3 Months Prior. Updates Applied: Potentially Compromised. Enterprise Aware: No.
4 min read · 13 Jun 2026
Training Data Poisoning
The Model Learned from Three Years of Data. One Year Was Labelled Wrong. The Model Learned That Too.
7 min read · 13 Jun 2026
Incident Response SLAs
Forty-Seven Hours Fifty-Nine Minutes. SLA Met. Scope Unknown. Customer Cannot Respond.
5 min read · 12 Jun 2026
Vendor Tiering Inaccuracies
Tier 3: Office Supplies. Also: Real-Time Warehouse System Integration. Both True.
6 min read · 12 Jun 2026
VEX , Vulnerability Exploitability eXchange
SCA Findings: 312. Actually Exploitable: 23. VEX Available: No. Triage Time: 3 Weeks.
4 min read · 11 Jun 2026
Vendor AI Usage Transparency
AI Features: Disclosed. AI Used to Score, Classify, and Route the Enterprise: Not Disclosed.
6 min read · 11 Jun 2026
Insider Threats at Vendors
Legitimate Access. Personal Cloud Account. Seventeen Thousand Records. Three Months.
6 min read · 10 Jun 2026
Zero Trust for Software Supply Chains
Network: Zero Trust. Dependencies: Pulled Without Publisher Verification. Build Agents: Broad Credentials. Software Updates: Server Identity from HTTPS Certificate Only.
5 min read · 10 Jun 2026
Just-in-Time Access vs Standing Access
Standing Access Runs 720 Hours a Month. It Is Needed for Four.
7 min read · 9 Jun 2026
Software Supply Chain Security
SLSA, SBOM, and the Hidden Risk in Every Line of Code You Trust
6 min read · 9 Jun 2026
Least Privilege in Vendor Access
You Gave Them Admin Because It Was Easier. It Was Never Revoked.
8 min read · 8 Jun 2026
Vendor Access Creep Over Time
Original Access: Read-Only Names and Emails. Three Years Later: Five Data Categories. Four Expansions: Zero TPRM Reviews.
4 min read · 8 Jun 2026