All practices
Defense in depth, not defense in decks.05 / 06

Cybersecurity

Zero-trust that survives an audit, threat models tied to real architecture, and red teaming that produces fixes rather than findings.

ic-secops · posture / identity / egressSOC 2 type II · ISO 27001 · 1 critical open
TRUST BOUNDARIESPUBLICuntrustedbrowser clientspartner apiEDGEdmzcloudflare wafingress · tls 1.3rate limit 2k/sPRIVATEworkload identityapiworkeradmin (jit)DATAencrypted at restrds · kms cmks3 · sse-kmsvaulttls 1.3 · hstsmTLS · spiffe idiam role · 15m credsegress default-deny · 3 undeclared destinations blocked todayATT&CK DETECTION COVERAGE · 94%14 tactics × 5 technique groups · 4 uncoveredMTTR38mmedian, 90dCRITICAL1 openCVE-2026-3184 · transitiveTRUE POSITIVES0last 24hLAST AUDITcleanevidence bundle exported
Representative trust boundary · not a live system

Defense in depth, not defense in decks.

We build security into the substrate — identity, network, application, supply chain. Threat modeling, zero-trust architecture, incident response runbooks. Compliance as a side effect of good engineering, not a separate project.

01Zero-trust architecture
02Threat modeling & red teaming
03SOC2 / ISO 27001 readiness
04Secure SDLC & supply chain
05Incident response runbooks