Primary research papers from Securosis, released under Creative Commons licensing.
Securosis Research is developed under the Totally Transparent Research Process.
Primary research papers from Securosis, released under Creative Commons licensing.
The Universal Cloud Threat Model is a collaboration between PrimeHarbor Technologies and Securosis. It is a cloud-centric threat model to help organizations focus security efforts on the most-common attacks most organizations will experience. The UCTM is designed as an adjunct to other threat models. From the introduction:
Security Operations, SecOps for short, has been one of the more difficult security domains to modernize for cloud. It requires a combination of new subject matter expertise, new technologies, process updates, and even a slightly different mindset. Cloud impacts SecOps in ways both obvious and subtle, and because most organizations still have datacenters and offices, teams need to add new skills and update operations while still supporting everything already on their plates. It’s a daunting…
Data security remains elusive. You can think of it as something of a holy grail. We’ve been espousing the idea of data-centric security for years, focusing on protecting the data, so you can worry less about securing devices, networks, and associated infrastructure. As with most big ideas, it seemed like a good idea at the time.
The way applications are built, deployed, and maintained in most organizations is being disrupted. Macro changes include the ongoing cloud migration disrupting the tech stack, new application design patterns bringing microservices to the forefront, and DevOps changing dev/release practices. As we’ve been slowly navigating this sea change, the common thread across these changes is increasing reliance on Application Programming Interfaces (APIs).
After many decades as security professionals, it’s depressing to keep seeing the same issues and mistakes. It feels like we’re stuck in hacker Groundhog Day. Get up, clean up the mistakes made by users or administrators, handle a new attack, and fill out compliance reports, only to have to do it all over again the next day.
Presentations from Securosis analysts at conferences and events.
Chris & Rich’s session at RSAC 2025 The Coming Cloudpocolypse: Disrupting the Cloud Shared Responsibility Model.
You can also find the Slides here
Rich and Chris’s session at re:Invent 2024 on Security invariants: From enterprise chaos to cloud order
Slides and an accompanying Blog Post that included the re:Invent releases that didn’t make it into our talk.
Chris & Rich’s session at RSAC 2024 CloudSec Hero to Zero: Self-Obsolescing Through Prolific Efficiency.
You can also find the Slides here. Read more about the Universal Cloud Threat Model in the research library.
Chris’s presentation to BSides Augusta in 2021 - The Cloud is Dark and Full of Terrors
Slides and Blog Post are available.
Our discussion of the PCI Council’s Tokenization Information Supplement.
Tokenization Guidance (PDF)