Recent Posts & Research

Defining Security Invariants
Defining Security Invariants

Defining Security Invariants - 2025 revision to include SCP, RCP, Declarative Policies

Implementing Security Invariants in an AWS Management Account
Implementing Security Invariants in an AWS Management Account

How do you deploy security invariants in an AWS org management account? With Permission Boundaries tied to every principal.

Introducing the Universal Cloud Threat Model
Introducing the Universal Cloud Threat Model

Introducing the Universal Cloud Threat Model - a model anyone can use to cover 90% of the cloud attacks they may experience.

Minimally Viable Cloud Governance
Minimally Viable Cloud Governance

Everyone has a preferred cloud provider and you probably govern that one pretty well. But like it or not, your organization is using the other providers and you need to govern them too. This blog post covers the minimum things to do in your non-preferred providers.

All Posts >