Latest Posts

Attack modeling a forgotten password system

Attack modeling a forgotten password system

This Attack Model maps potential attack vectors in a typical forgotten password system. The goal is to catalogue exploitable attack vectors along with the related security controls.

Post Thumbnail

Threat Modeling Is Dead

STRIDE has not aged well…

I’ve seen first-hand the thick PDFs and Excel files that my clients have had delivered …

Post Thumbnail

Security Requirements

A few years ago I was brought in to help with security for a project at a large retailer in the UK. They were building …

Post Thumbnail

There Is No Perimeter

Let me tell you a story…

A few years ago, I was working with a company that had a traditional approach to …

Post Thumbnail

2024: Year of the Supply Chain Attack?

The news of Hezbollah agents being targeted with exploding pagers and UHF radios was a shock to us all. Whilst this type …