8 posts found
13 August 2026 · By P LarnerBlog post
End-of-life systems are a distinct risk class, because the normal remedy is gone for good. How to build an obsolescence register and plan the runway.
Security in Practice#Cyber Essentials#obsolescence#asset management#end of life#patching
Read more →11 August 2026 · By P LarnerBlog post
A practical walkthrough of threat modelling, from scoping and data flow diagrams through STRIDE and attack trees to keeping the model alive afterwards.
Security in Practice#secure design#attack trees#threat modelling#DREAD#STRIDE
Read more →7 August 2026 · By P LarnerBlog post
Frontier AI arrives twice, as capability in the hands of attackers and as a system you connect to your own data. The controls and the owners differ.
Security in Practice#deepfake#shadow IT#self-hosting#artificial intelligence#phishing
Read more →7 August 2026 · By P LarnerBlog post
Why the 300-question spreadsheet fails, and how to replace it with tiering and evidence so effort follows risk and Tier 1 suppliers get real scrutiny.
Security in Practice#supplier assurance#ISO 27001#third-party risk#due diligence
Read more →5 August 2026 · By P LarnerBlog post
What frontier AI actually means, the compute thresholds regulators wrote down in the UK, EU and US, and why your exposure runs through suppliers and attackers.
Security in Practice#frontier models#artificial intelligence#EU AI Act#AI Security Institute#regulation
Read more →29 July 2026 · By P LarnerBlog post
How to turn thousands of scanner findings into a handful of thematic, owned risks your register can actually carry.
Security in Practice#KEV#vulnerability management#CVSS#EPSS#risk register#remediation SLAs
Read more →28 July 2026 · By P LarnerBlog post
You cannot protect, patch or monitor what you do not know you have. Every security discipline quietly assumes an accurate list of systems exists, and in most organisations that assumption is wrong. This post explains why every serious framework puts asset management first and how to build a register that actually works.
Security in Practice#discovery#reconciliation#asset management#shadow IT#inventory#CIS Controls
Read more →25 July 2026 · By P LarnerBlog post
How to prepare for a compliance audit: evidence hygiene through the year, control narratives, common findings, and an internal dry run before the real thing.
Security in Practice#control narratives#findings#ISO 27001#evidence#audit preparation#SOC 2
Read more →