<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Ilyas Hamdi</title><link>https://ilyashamdi.com/categories/security/</link><description>Recent content in Security on Ilyas Hamdi</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Mon, 19 Aug 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://ilyashamdi.com/categories/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Infrastructure security architecture patterns</title><link>https://ilyashamdi.com/writing/infrastructure-security-architecture-patterns/</link><pubDate>Mon, 19 Aug 2024 00:00:00 +0000</pubDate><guid>https://ilyashamdi.com/writing/infrastructure-security-architecture-patterns/</guid><description>A security pattern adopted without a threat model is a control with no clear job. The patterns aren't the problem. The application is.</description></item><item><title>Zero trust network architecture</title><link>https://ilyashamdi.com/writing/zero-trust-network-architecture/</link><pubDate>Tue, 23 Jul 2024 00:00:00 +0000</pubDate><guid>https://ilyashamdi.com/writing/zero-trust-network-architecture/</guid><description>Zero trust is one of the most successfully marketed architectural concepts of the decade. Most projects deliver better-than-perimeter, not actual zero trust.</description></item><item><title>The security posture question most organizations ask too late</title><link>https://ilyashamdi.com/writing/security-posture-too-late/</link><pubDate>Mon, 14 Aug 2023 00:00:00 +0000</pubDate><guid>https://ilyashamdi.com/writing/security-posture-too-late/</guid><description>Four triggers force the question 'what's our security posture, actually?' Three are expensive. The fourth is the one to engineer for yourself.</description></item><item><title>When compliance becomes a substitute for security thinking</title><link>https://ilyashamdi.com/writing/compliance-vs-security-substitute/</link><pubDate>Tue, 23 May 2023 00:00:00 +0000</pubDate><guid>https://ilyashamdi.com/writing/compliance-vs-security-substitute/</guid><description>Compliance frameworks set a floor, not a ceiling. Treating them as the security strategy is how organizations end up audited and exploitable.</description></item><item><title>IAM sprawl is access debt</title><link>https://ilyashamdi.com/writing/iam-sprawl-access-debt/</link><pubDate>Tue, 15 Nov 2022 00:00:00 +0000</pubDate><guid>https://ilyashamdi.com/writing/iam-sprawl-access-debt/</guid><description>IAM is the part of your cloud footprint that grows fastest and gets cleaned up the slowest. The result looks like a control and behaves like a liability.</description></item></channel></rss>