Compliance Reporting Is Easy - Validation Is The Hard Part
Why most compliance automation fails at the engineering reality check, and how to build validation that actually works using unit and function tests.
Author and Cybersecurity Practitioner
Why most compliance automation fails at the engineering reality check, and how to build validation that actually works using unit and function tests.
How Open Policy Agent (OPA) transforms compliance from a cost center into a competitive advantage for cloud service providers.
Discover how Software Bills of Materials (SBOMs) are a key part of the transformation of cloud security and compliance practices.
Exploring why hardened components in your CI/CD pipeline are essential for security, from DIY approaches to vendor solutions.
Exploring how complexity itself has emerged as a meta-risk that overshadows conventional cybersecurity threats.
Learn how organizations can define and track ephemeral technology components in containerized environments.
Learn how to ethically assess the thoroughness of public asset inventory practices using free, open-source tools like Nmap, Masscan, Amass, and Shodan.
Learn how to unlock the power of AI on your ordinary laptop - no subscriptions, no privacy concerns, and no fancy hardware required.
How to implement a comprehensive vulnerability management workflow in AWS for under $50,000
How to implement compliance-as-code in AWS using GitOps and automated security control validation
Going down the rabbit hole while attempting to uninstall ProtonVPN - persistence mechanisms and security implications