security-architecture
Latest
Moving Autonomous Agent Secrets Out of .env
For a long time, my autonomous agent found credentials the same way many applications do. Why I replaced a flat environment file with scoped Vaultwarden access, short-lived agent sessions, and a verified audit trail that now reaches Graylog and Wazuh.
The Map and the Floor
After years of working, teaching, writing in this field, the pattern I see most in newcomers is not lack of ability. It is freezing...
Practice at Home the Way You Preach at Work
I spend my working hours telling teams how to do security well. Segment the network. Write the change down. Model the threat before you build the control. Then I go home, and if I am honest with myself, the temptation is to cut every one of those corners because it is "just the lab."
The Moment AI Stops Being a Tool: Why Autonomy Is the Risk Multiplier
A tool's failure is advisory because a human still reviews the output before anything happens. An agent's failure is operational because the bad output is the action...