Latest Regulations·June 18, 2026

CRA — 24 hours to report a vulnerability. What changes on 11 September 2026

The Cyber Resilience Act introduces a duty to report actively exploited vulnerabilities within 24 hours. Who it applies to, the key dates, and what you need in your delivery process.

Read article →
17 articles
FundamentalsMay 27, 2026

Threat modeling with STRIDE — finding gaps before the code exists

Threat modeling is the cheapest way to catch security problems — at the design stage, not after a pentest. What STRIDE is and how to wire it into the delivery process.

10 min readRead →
ToolsMarch 18, 2026

Policy-as-Code — when security policy exists only on paper

Most organizations have security policies. Few have mechanisms that actually enforce them. The difference becomes apparent during an incident.

8 min readRead →
FundamentalsMarch 17, 2026

Zero Trust in the context of DevSecOps — a principle you cannot ignore

Zero Trust is a security architecture based on the assumption that no user, system or network should be trusted by default.

7 min readRead →
PracticeMarch 16, 2026

Why DevSecOps slows down teams — and when it doesn't have to

Most negative experiences with implementing security in pipelines stem from implementation errors, not from the DevSecOps idea itself.

9 min readRead →
BusinessMarch 15, 2026

Enterprise client security questionnaire — what they check and how to prepare

VRA blocks the contract. Analysts look for answer consistency, knowledge of your environment and evidence — not declarations.

8 min readRead →
SecurityMarch 14, 2026

Long-lived tokens in CI/CD — why they are a problem nobody sees

Static API keys and cloud access tokens in pipelines are one of the most common attack vectors. The problem is structural.

8 min readRead →
BusinessMarch 13, 2026

Cost of data breaches and CI/CD incidents — what the data says

IBM, Verizon, GitGuardian — what the data says about security incident costs and why companies selling to Enterprise pay double.

8 min readRead →
PracticeMarch 12, 2026

GitHub Actions — 10 configuration mistakes I see in every audit

GITHUB_TOKEN with write on everything, actions without SHA pinning, secrets in logs — 10 mistakes that co-occur and reinforce each other.

9 min readRead →
FundamentalsMarch 11, 2026

Evidence Pack — What It Is and Why Your Auditor Wants One

An Evidence Pack is the technical documentation that proves your pipeline security controls actually work — not just that you claim they do.

10 min readRead →
ToolsMarch 10, 2026

SBOM — why the software bill of materials is becoming a market requirement

Software Bill of Materials describes what software is built from. Regulations and Enterprise requirements mean its absence blocks sales.

8 min readRead →
RegulationsMarch 9, 2026

SOC 2 Type II and Your CI/CD Pipeline — What Auditors Actually Verify

SOC 2 auditors increasingly examine CI/CD pipelines. Here's what they look for and how to prepare.

10 min readRead →
SecurityMarch 8, 2026

Secret leaks in CI/CD pipelines — scale of the problem and mechanisms

Secrets in pipelines leak regularly — often not through attacks but through configuration errors that exist for years.

9 min readRead →
BusinessMarch 7, 2026

Vendor Risk Assessment — What Enterprise Buyers Actually Evaluate

VRA questionnaires are getting longer and more technical. Here's what security analysts look for and how to respond effectively.

10 min readRead →
SecurityMarch 6, 2026

Artifact integrity in DevOps — the gap most organizations ignore

Between build and production deployment an artifact can be replaced. Without integrity verification — there is no way to detect it.

8 min readRead →
RegulationsMarch 5, 2026

NIS2 and the software supply chain — new obligations for technology companies

NIS2 requires auditing software suppliers. If you deliver software to entities covered by the directive — you must prove supply chain security.

12 min readRead →
RegulationsMarch 4, 2026

DORA and CI/CD Pipeline Security — What the Regulation Actually Requires

DORA requires ICT security controls including CI/CD systems. If you sell software to financial institutions — your pipeline is in scope.

10 min readRead →
FundamentalsMarch 3, 2026

CI/CD Hardening — What It Is and Why Companies Ignore It

Your CI/CD pipeline holds production keys — but it's secured like a dev tool. What is hardening and why do companies ignore it?

12 min readRead →

No articles in this category.