Writing
Research and field notes.
Deep dives, threat analysis, and notes from the work - mostly on AI and agent security, sometimes on whatever is breaking this week.
Latest
Zero Trust Without The Vendor Fog
A practical reading of NIST SP 800-207 and the parts of Zero Trust that matter during implementation.
January 17, 20253 min readCybersecurity
Read note
July 2, 202110 min read
TOGAF And Zachman For Security Architecture
A practical comparison of TOGAF and Zachman for security teams that need structure without drowning in framework ceremony.
TOGAFZachman FrameworkEnterprise Architecture
June 15, 20218 min read
Using C4 Diagrams In Security Work
A practical way to use C4 diagrams for trust boundaries, data flows, and incident response.
C4 ModelArchitecture DiagramsCybersecurity
May 20, 20219 min read
4+1 Architecture Views For Security Reviews
How the 4+1 view model can keep security architecture from collapsing into one overloaded diagram.
4+1 ArchitectureKruchtenSystem Architecture