Security Guides
Deep-dive playbooks, startup fundamentals, enterprise hardening.
SBOM Operations at Enterprise Scale: CycloneDX, SPDX, and SLSA Provenance
Moving from SBOM generation to SBOM operations. Dependency-Track, reachability, VEX, SLSA Build L3, vendor SBOM intake, and a maturity model for grading…
Security GuidesAPI Security in 2026: BOLA, Mass Assignment, and Authorization Patterns
The OWASP API Top 10 in operational terms. BOLA prevention patterns, RBAC vs ABAC vs ReBAC, OPA Rego policies, OpenFGA, and a…
Cloud SecurityKubernetes Pod Security in Production: PSA, Kyverno, and OPA Gatekeeper Compared
Comparative analysis of the three dominant Kubernetes policy engines. When to use which, how to compose them, and a defensible migration from…
Incident ResponseScenario Brief: Anatomy of a High-Risk Patch Tuesday for Windows Estate Defenders
Tabletop-ready scenario: a hypothetical Patch Tuesday with twin Print Spooler bugs echoing PrintNightmare. Domain-controller priority and SOC detection workflow.
ComplianceScenario Brief: Tracking SBOM Readiness Among SEBI-Regulated Intermediaries
Tabletop-ready compliance scenario: where stockbrokers and depository participants stand against the SEBI CSCRF Phase 2 SBOM requirement and the 30-day sprint plan.
AcademyModule 7 · Cloud-Native Security Architecture — Kubernetes, Service Mesh, Serverless
Why this module exists. Cloud-native architecture moves so much of the trust boundary into automation that the security architecture must shift correspondingly.…
AcademyModule 6 · Threat Modelling at the Architecture Stage
Why this module exists. Threat modelling is referenced in every security architecture guide and practised by few engineering teams. The reason: it…
AcademyModule 5 · Reference Architecture for Indian Regulated Workloads
Why this module exists. Architects designing for Indian regulated workloads navigate four to six overlapping regulator expectations. The cost of architecting for…
AcademyModule 4 · Service Mesh Security — Istio, Linkerd, mTLS-Everywhere
Why this module exists. Microservices security cannot be solved at the firewall — there are too many internal calls, the topology changes…
AcademyModule 3 · Zero Trust Architecture — From Principle to Production
Why this module exists. “We’re doing Zero Trust” is said by Indian enterprises that have simply renamed their VPN. This module covers…