KevinBytes

Writing

Research and field notes

Deep dives, threat analysis, and notes from the work - mostly on AI and agent security, sometimes on whatever is breaking this week.

Latest

Zero Trust Without The Vendor Fog

A practical reading of NIST SP 800-207 and the parts of Zero Trust that matter during implementation.

January 17, 20253 min readCybersecurity
July 2, 202110 min read

TOGAF And Zachman For Security Architecture

A practical comparison of TOGAF and Zachman for security teams that need structure without drowning in framework ceremony.

TOGAFZachman FrameworkEnterprise Architecture
June 15, 20218 min read

Using C4 Diagrams In Security Work

A practical way to use C4 diagrams for trust boundaries, data flows, and incident response.

C4 ModelArchitecture DiagramsCybersecurity
May 20, 20219 min read

4+1 Architecture Views For Security Reviews

How the 4+1 view model can keep security architecture from collapsing into one overloaded diagram.

4+1 ArchitectureKruchtenSystem Architecture