Threat Modelling: The Now of IT

Threat modelling was the subject of the latest Virtualization Security Podcast (which I am still trying to upload, so time for a new service). Threat modelling is what every security person does, but not necessarily formally. Threat modelling in many ways takes an architecture and looks for well-known threats. One such threat that could come …

Anti-Ransomware: All About Architecture

As I read the “we solve ransomware” emails in my inbox and saw comments on Twitter and Slack, I started to think about how to solve ransomware once and for all. It sounds like a difficult task, but I think it is all about an architecture: an architecture that uses modern ideas. A solution needs to combine …

In the Hybrid Cloud, Your Role Matters, but…

The title of this article is “In the Hybrid Cloud, Your Role Matters, but…,” and there is a big “but” there. How you use your role is what really matters. Whether you are a cloud, virtualization, or container administrator, evangelist, or architect, how you use your role makes or breaks the secure hybrid cloud. We …

Notes from the Field: The Difference between Architecture and Design

I’m going to diverge ever so briefly from my “Reversed Assumptions” posts to share some happenings in this current engagement I’m on and to tie in some of the previous posts on design and architecture. This post focuses on what architecture is and what it isn’t. As I have engaged with many different sizes of …