April 27, 2026
If you run local agents, you need to make tough choices between autonomy and safety. Setting dangerously-skip-permissions while sword fighting on desk chairs and letting the tokens burn bright is...
Read →
March 23, 2026
Running security for AWS-centric companies means getting down and dirty with CloudTrail. Not only will you crawl the logs with SIEMs to “find the baddies” via IoCs; as a proactive...
Read →
January 13, 2026
Commercial GRC tools can cost $12K+/year and lock your compliance docs in proprietary systems. GraphGRC v2 gives you SOC 2 documentation in GitHub - pre-written controls, policies, and processes in...
Read →
January 10, 2026
Dependabot throws security alerts but sometimes can't create pull requests. Here's a GitHub Action that automatically sends failed alerts to Copilot for resolution.
Read →
November 7, 2025
Raccoons are both advanced and persistent threats. After one attacked my chihuahua Jolene, I declared war on my backyard invaders. Through ultrasonic deterrents, motion-activated sprinklers, and wacky inflatable air dancers,...
Read →
October 23, 2025
Data retention covers two different problems - preservation (minimum time you must keep archival data) and deletion (maximum time you can keep personal data). They require opposite technical approaches -...
Read →
October 14, 2025
Your new hire sits through generic security training, clicks through a 47-page policy, and gets random access over time. Three months later they ping for production access. The policies? Nobody's...
Read →
October 1, 2025
Modern software companies use a lot of software services. Traditional security teams address third-party risk through certifications and questionnaires, but there's an opportunity to actually reduce risk by collaborating with...
Read →
June 3, 2025
A framework for helping security engineers choose high-impact work using three criteria - business goals, implicit interest, and personal growth.
Read →
March 6, 2025
Running EKS in FedRAMP environments requires careful implementation across multiple security domains
Read →
March 1, 2025
Learn how software vendors can serve FedRAMP-authorized cloud service providers without going through the full authorization process.
Read →
February 23, 2025
Learn how to leverage AWS Bedrock to create a FedRAMP-compliant AI assistant for your System Security Plan without exposing sensitive information.
Read →