Blog

Secure by Design & DevSecOps

Security is cheapest and most effective when it starts at design. These articles cover Secure by Design principles, shift-left practices and how to bring threat modeling into DevSecOps workflows without slowing delivery. Read perspectives from CISOs, security architects and engineering leaders on making secure design a repeatable habit.

Latest articles

Beyond the sandbox: Threat modeling the OpenAI and Hugging Face incident

Blog

Beyond the sandbox: Threat modeling the OpenAI and Hugging Face incident

We explored the initial sandbox escape in the OpenAI and Hugging Face incident. Here’s what it reveals about trust boundaries, connected services, and secure design in an agentic era.

Read More
Secure by Design: Proactive Resilience in the era of AI Supply Chain Risk and MCP

Blog

Secure by Design: Proactive Resilience in the era of AI Supply Chain Risk and MCP

After an MCP vulnerability reportedly impacting over 150 million downloads, see why AI supply chain risk demands architectural threat modeling, not just reactive scanning.

Read More
2026 Predictions: AI-Acceleration Will Shift Security Back to Design

Blog

2026 Predictions: AI-Acceleration Will Shift Security Back to Design

With global cybercrime costs projected to hit $11.3 trillion in 2026, our predictions show why secure-by-design is becoming a business requirement, not a buzzword.

Read More
Start Left At Design: Lessons From a CISO Panel

Blog

Start Left At Design: Lessons From a CISO Panel

A CISO panel reveals why most "shift left" efforts still fail — and why real progress starts with design review, not later-stage scanning.

Read More
The Threat Modeling Tools Market is Booming: Here’s What You Should Know

Blog

The Threat Modeling Tools Market is Booming: Here’s What You Should Know

The threat modeling tools market is projected to grow 14.2% annually — here's what's driving the shift toward proactive, built-in security.

Read More