Security Concepts

Understand the domain before you buy the product.

Vendor-agnostic breakdowns of critical security domains. No product pitches. No marketing language. Just the problem, how the technology works, where it fails, and the questions you should be asking.

08 Domains
32 Diagnostic questions
03 Perspectives
Threat flow
Attack Surface & Defense PointsThreat Flow
Outside Threats
Network Access
Web Apps
APIs & Microservices
Secure Data
Insider Threats
Internal risk vectors
Insider ThreatsInternal Risk Vectors
Privileged User AbuseEmployee Data TheftCredential Misuse (Compromised Accounts)Fraudulent Transactions by Internal UsersShadow IT & Unauthorized Cloud Access