5 October 2026 · AI Governance · Security Architecture · 6 min read
ISO 42001 creates the management system for responsible AI. It does not decide gateway design, machine identity, data boundaries, tool permissions or how technical failures will be contained.
3 October 2026 · Security Architecture · Operational Resilience · 6 min read
Prevention matters, but containment decides the outcome. The strongest architecture keeps failures local by constraining identity, trust, connectivity, authority and concentration risk.
28 September 2026 · AI Security · Security Architecture · 6 min read
Part 2 turns AI security design principles into an operating model for production monitoring, prompt-injection boundaries, approval, survivable failure, supply-chain control and lifecycle governance.
27 September 2026 · Security Architecture · Digital Trust · 6 min read
Connectivity diagrams show where systems communicate. Security architecture must expose the identity, authority, lifecycle and blast radius hidden inside every trusted connection.
26 September 2026 · Software Supply Chain · Digital Trust · 6 min read
If malicious code enters before signing, the signature may validate perfectly. Software trust needs verifiable provenance, isolated builds, protected keys, separation of duties and defence after installation.
25 September 2026 · AI Security · Security Architecture · 7 min read
A real AI sandbox uses default-deny egress, controlled DNS, allowlisted targets, synthetic credentials, independent kill controls and audit evidence—not behavioural instructions alone.
23 September 2026 · AI Security · Security Architecture · 6 min read
A practical framework for governing enterprise AI through explicit trust relationships, scoped machine identities, controlled data access, AI gateways, tool permissions and enforceable boundaries.
20 September 2026 · Security Operations · Security Architecture · 5 min read
A perfect alert can still lose the attack. Product testing should measure interruption, containment, analyst context and how far an attacker progresses toward business impact.
19 September 2026 · Identity Security · Governance · 5 min read
Disabling Active Directory is no longer enough. Effective offboarding must revoke distributed human access, long-lived secrets and machine credentials before they become orphaned trust.
16 September 2026 · AI Governance · Security Architecture · 6 min read
The enterprise AI gateway should enforce explicit trust, selective tool access, context-aware caching, token efficiency and resilient policy controls across models, agents, MCP servers and data.
14 September 2026 · Identity Security · Security Architecture · 6 min read
API authentication should match the trust scenario: delegated user access, managed workload identity, mutual TLS, short-lived pipeline tokens and tightly scoped third-party credentials are not interchangeable.
13 September 2026 · Governance · Cybersecurity · 5 min read
A decade-old Shellshock finding should trigger questions about asset ownership, deferred remediation, compensating controls, exception expiry and the business dependency keeping vulnerable technology alive.
11 September 2026 · AI Governance · Security Architecture · 7 min read
The real test of AI governance arrives when safety conflicts with speed. Defined boundaries, least privilege, independent challenge and recovery must survive that pressure.
9 September 2026 · Identity Security · Cybersecurity · 6 min read
MFA remains essential, but session tokens, recovery processes, help-desk verification, device trust and step-up controls determine whether authenticated access should remain trusted.
8 September 2026 · Operational Resilience · Cybersecurity · 7 min read
Moving a scan to midnight can protect immediate operations without fixing the underlying weakness. Mature organisations use controlled realism to test detection, containment, continuity and recovery.
7 September 2026 · Cybersecurity · Leadership · 6 min read
As technical knowledge becomes more accessible, Malaysia’s everyday ability to translate across cultures, align different perspectives and build trust can become a distinctive cybersecurity capability.
3 September 2026 · Critical Infrastructure · Artificial Intelligence · 8 min read
AI may not autonomously hack industrial systems, but it can multiply scarce reverse-engineering expertise, accelerate exploit adaptation and weaken the technical difficulty that once narrowed the threat population.
2 September 2026 · Security Operations · Security Architecture · 7 min read
Detection and ticket closure are not security outcomes. Effective defence requires shared context, architecture-wide containment and authority to remove the attacker’s options before critical systems are reached.
1 September 2026 · Careers · Leadership · 7 min read
The cybersecurity industry says it needs experience, yet many Gen X professionals find that seniority, salary history and age become barriers precisely when their judgement is most valuable.
30 August 2026 · AI Security · Governance · 7 min read
AI agents cannot accept risk or legal accountability. High-risk evaluations need enforceable isolation, real-time monitoring, independent shutdown controls and named incident owners before testing begins.
29 August 2026 · Software Supply Chain · Governance · 7 min read
Third-party assessments capture a moment. Strong vendor security limits connected trust, monitors critical access throughout the lifecycle and prepares the business to contain supplier failure.
25 August 2026 · Careers · Leadership · 5 min read
Salary reviews affect one year; deliberate decisions about staying, moving and building market value shape a cybersecurity career over decades.
23 August 2026 · Software Supply Chain · Security Architecture · 5 min read
The tools that scan, build and secure every application can become a privileged path across the software supply chain if their concentrated trust is compromised.
22 August 2026 · Critical Infrastructure · Security Architecture · 7 min read
Critical infrastructure must combine reliability with enforceable segmentation, governed identities, independent controls and tested recovery against increasingly automated attacks.
19 August 2026 · Security Architecture · Emerging Technology · 5 min read
Future technology cannot be governed by static perimeter-era architecture; protection must become identity-driven, policy-based and capable of continuous adaptation.
16 August 2026 · Cybersecurity · Threat Detection · 5 min read
Fast attackers trigger alarms. Patient attackers can quietly learn the environment, preserve access and wait until their position becomes most valuable.
15 August 2026 · Artificial Intelligence · Cybersecurity · 6 min read
AI may not create a new attack chain; it can remove the delays between familiar stages and force defence, identity and architecture to operate faster.
13 August 2026 · Cybersecurity · Security Architecture · 5 min read
Security maturity is not measured by how many products remain in the stack, but by whether every retained tool still has a defined purpose and measurable value.
12 August 2026 · Digital Trust · Cybersecurity · 5 min read
More accounts, content and engagement can conceal a quieter decline in authentic participation as people discover publicly but increasingly engage in private.
10 August 2026 · Cybersecurity · Leadership · 5 min read
Security is shaped by thousands of choices across architecture, operations, governance and leadership—not by technology alone.
7 August 2026 · Cybersecurity · Security Architecture · 5 min read
The real attack surface includes dormant packages, services, drivers and kernel modules that attackers can reach even when organisations never intended to use them.
7 August 2026 · AI Security · Security Architecture · 5 min read
Safety guardrails tell an AI agent what it should do. Security boundaries determine what it can reach, access and execute when those guardrails fail.
6 August 2026 · Cybersecurity · Leadership · 4 min read
Technical skills may secure the opportunity. Judgement determines whether others trust you with greater responsibility.
5 August 2026 · Cybersecurity · Leadership · 6 min read
The best cybersecurity leaders distribute judgement, create career paths and prepare successors instead of making the organisation dependent on them.
4 August 2026 · Cybersecurity · Security Architecture · 4 min read
Every control can fail. Resilient security architecture uses independent layers to contain failure before it becomes business disruption.
3 August 2026 · Cybersecurity · Governance · 4 min read
Shadow IT is driven by productivity. The real security problem begins when technology use and information movement become invisible and ungoverned.
2 August 2026 · Cybersecurity · Governance · 4 min read
A signed risk acceptance records a conscious decision to proceed. The exposure and accountability still remain with the organisation.
31 July 2026 · Data Security · Security Architecture · 7 min read
DSPM, DLP and CASB can complement one another, but overlapping features justify investment only when they close a measurable data-security gap.
29 July 2026 · Cybersecurity · Careers · 4 min read
Certifications should support a deliberate cybersecurity career strategy built on direction, practical experience, reputation and curiosity.
27 July 2026 · Cybersecurity · Leadership · 5 min read
Cybersecurity leadership is expanding from managing people and technology to governing humans, machines and AI agents under one framework of trust.
25 July 2026 · Cybersecurity · Security Operations · 7 min read
A practical checklist for preserving detection coverage, historical evidence and monitoring readiness throughout a SIEM migration.
25 July 2026 · AI Security · Identity Security · 3 min read
AI agents are becoming non-human privileged identities. Their authority must be governed as carefully as any privileged user.
24 July 2026 · Cybersecurity · Security Architecture · 3 min read
Good security architecture begins by challenging assumptions behind trust, access, data flows, controls and recovery.
23 July 2026 · Cybersecurity · Security Architecture · 5 min read
Security architecture brings trust, controls and resilience together so the business can operate confidently.
23 July 2026 · Cybersecurity · Security Operations · 3 min read
A SIEM migration changes how an organisation sees threats and must be governed as a period of elevated security risk.
22 July 2026 · Cybersecurity · Security Architecture · 2 min read
Security controls protect technology. Security architecture protects the business by designing trust, resilience and outcomes.
21 July 2026 · Cybersecurity · Security Architecture · 2 min read
Great security architects understand how attackers think, so they can design systems that remain resilient when trust fails.
20 July 2026 · Cybersecurity · Leadership · 7 min read
The future cyber community must combine offensive curiosity with trust, resilience, responsibility and the ability to protect organisations.
19 July 2026 · Cybersecurity · Digital Trust · 4 min read
Cybersecurity is evolving from protecting systems to engineering the trust relationships that allow organisations to innovate safely.
18 July 2026 · AI Security · Deception Technology · 4 min read
As attackers automate reconnaissance and campaigns with AI, deception must evolve into high-confidence trust validation.
17 July 2026 · Cybersecurity · Identity Security · 5 min read
The security perimeter has moved from network location to identity, permissions and continuously evaluated trust.
17 July 2026 · AI Security · Governance · 4 min read
Shadow AI is spreading through everyday work faster than governance can keep up. Visibility must come before control.
17 July 2026 · AI Security · Governance · 5 min read
AI adoption is moving at employee speed while governance moves at organisational speed. The first challenge is visibility.
16 July 2026 · Cybersecurity · Security Architecture · 5 min read
Connectivity is not trust. Explore why security architecture must make trust boundaries and controls visible, not merely data flows.
15 July 2026 · Cybersecurity · Security Architecture · 5 min read
Security should enable organisations to create value safely—not become the bottleneck that drives risk outside governance.
14 July 2026 · Cybersecurity · Security Architecture · 6 min read
Best practices are valuable, but strong security architecture begins with the risk and required outcome—not the same prescribed control for every environment.
10 July 2026 · AI Security · Cybersecurity · 9 min read
AI coding agents are rapidly becoming part of developer workflows. The key security question is not how intelligent they are, but what they are allowed to access, execute, and change.
10 July 2026 · Data Governance · Privacy · Security Architecture · 6 min read
Not every personal-data use case can be anonymised. The discipline is to ensure data remains identifiable only where there is a valid reason—and to reduce exposure everywhere else.
9 July 2026 · Cybersecurity · Security Architecture · 3 min read
AirDrop and Quick Share highlight a difficult security trade-off: frictionless experiences often require systems to process information before trust is fully established.
7 July 2026 · Cybersecurity · Active Directory · Security Architecture · 4 min read
A working Active Directory is not necessarily a resilient one. Explore six architectural principles that distinguish operational health from true cyber resilience.
4 July 2026 · Zero Trust · Cybersecurity · 4 min read
Zero Trust is often misunderstood as “trust nobody” or simply another security product. Its true purpose is limiting the consequences when trust decisions prove wrong.
29 June 2026 · Cybersecurity · Operational Resilience · 3 min read
Major incidents often begin as ordinary work. Explore why familiarity, routine exceptions, and ignored near misses create the conditions for failure.
25 June 2026 · Cybersecurity · 4 min read
Is the absence of a cyberattack really evidence of strong security? Only one of the three possible explanations should inspire confidence.
19 June 2026 · Cybersecurity · Leadership · 3 min read
A reflection on independence, incentives, vendor dependency, and the need for stronger internal cyber judgment.
16 June 2026 · Cybersecurity · Leadership · Digital Trust · 4 min read
Explore the difference between imagined, borrowed, and earned confidence, and why it matters to security leaders.
7 June 2026 · Cybersecurity · Leadership · 3 min read
Why cybersecurity fails when certainty replaces curiosity, and why challenging assumptions is a vital security control.
19 September 2025 · Data Governance · Privacy · 3 min read
Data breach notification begins with visibility: data inventory, meaningful monitoring, clear ownership and tested response readiness.
31 August 2025 · Cybersecurity · Leadership · 4 min read
Certification is valuable evidence, but cybersecurity hiring must assess demonstrated capability, judgment, experience and potential.
12 April 2025 · Cybersecurity · Security Operations · 4 min read
More security telemetry does not always mean better security. Explore why the modern SOC must optimise for signal, not alert volume.
19 March 2025 · Cybersecurity · Leadership · 4 min read
Behind every security control is a person. Explore why collaboration, culture, ownership, and human sustainability are essential to cyber resilience.
18 February 2025 · Cybersecurity · Leadership · 6 min read
A CISO’s experience becomes most valuable when it is adapted to the organisation’s actual authority, accountability and operating model.
23 May 2024 · Cybersecurity · Threat Intelligence · 4 min read
Not every breach claim is a real compromise. Explore how honeypots and deception technology can turn attacker activity into defensive intelligence.