Writing
Research and field notes
Deep dives, threat analysis, and notes from the work - mostly on AI and agent security, sometimes on whatever is breaking this week.
Latest
How to Evaluate Tools for Securing Production AI Agents
An evaluation method that follows identity, authority, approval, and failure behavior through a real agent workflow.
September 9, 20265 min readAI Security
Read article
July 2, 202110 min read
TOGAF And Zachman For Security Architecture
A practical comparison of TOGAF and Zachman for security teams that need structure without drowning in framework ceremony.
TOGAFZachman FrameworkEnterprise Architecture
June 15, 20218 min read
Using C4 Diagrams In Security Work
A practical way to use C4 diagrams for trust boundaries, data flows, and incident response.
C4 ModelArchitecture DiagramsCybersecurity
May 20, 20219 min read
4+1 Architecture Views For Security Reviews
How the 4+1 view model can keep security architecture from collapsing into one overloaded diagram.
4+1 ArchitectureKruchtenSystem Architecture