All Writing

← Home

Threat Modeling for Cloud: Where Your Risk and Your Budget Actually Move

Cloud breaches are rarely exotic exploits. They are identity and configuration decisions. For a security leader, the cloud shifts where risk concentrates and where control spending pays off, and a threat model that ignores that shift protects the wrong things.

6 min read

Threat Modeling in Practice: Building a Program Your Teams Actually Run

The mechanics of threat modeling are well understood. The reason most programs fail is not technique; it is the operating model around it. What a security leader has to get right for threat modeling to survive contact with a delivery schedule.

6 min read

Threat Modeling Explained: A Security Leader's Guide to Catching Risk Before It Ships

Most expensive breaches trace back to a design decision nobody challenged in a meeting. Threat modeling is how leaders catch that class of risk early, and how to tell whether your organisation actually does it or just performs it.

5 min read

NVIDIA NemoClaw vs OpenClaw: A Security and Architecture Deep-Dive (Is the Move Worth It?)

NVIDIA announced NemoClaw at GTC 2026 as the security layer OpenClaw always needed. I evaluated both thoroughly; here is my honest verdict on the architecture, where NemoClaw genuinely improves the security posture, and where it still falls short.

15 min read

I Built a Team of AI Agents for Bug Bounty Hunting. Three Weeks of Iteration Taught Me More Than Three Years of Reading About AI.

I deployed 6 specialised AI agents for bug bounty hunting using OpenClaw. Here's the honest account: initial scores, what broke, the triage turning point, and what actually improved.

9 min read

I Asked Two AI Models to Cross an Ethical Line. One Refused. One Didn't. Here's What That Means for Security.

Same prompt, same context, two different LLMs, two completely different decisions. A real experiment that exposes why inconsistent AI guardrails are themselves a security vulnerability.

11 min read