# risk-management

Published articles for risk-management.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## NFR Brain: challenging the status quo of risk management with data

DevFeed: [NFR Brain: challenging the status quo of risk management with data](<https://devfeed.tech/articles/nfr-brain-challenging-the-status-quo-of-risk-management-with-data-41436.md>)

Original publisher: [Read original article](<https://building.nu.com/nfr-brain-challenging-the-status-quo-of-risk-management-with-data/>)

Author: Nubank Editorial

Published: 2026-09-04T14:18:41Z

Content type: opinion

Language: en

Sources: [Nubank](<https://devfeed.tech/sources/nubank.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [data](<https://devfeed.tech/topics/data.md>), [Risk](<https://devfeed.tech/topics/risk.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>)

Tags: [critical](<https://devfeed.tech/tags/critical.md>), [data](<https://devfeed.tech/tags/data.md>), [data-analytics](<https://devfeed.tech/tags/data-analytics.md>), [data-modelling](<https://devfeed.tech/tags/data-modelling.md>), [data-science-machine-learning](<https://devfeed.tech/tags/data-science-machine-learning.md>), [governance](<https://devfeed.tech/tags/governance.md>), [models](<https://devfeed.tech/tags/models.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

Nubank describes NFR Brain, a platform for combining data, modelling, and expert judgement to make non-financial risk signals comparable and actionable. The article presents it as a way to support more consistent, transparent risk prioritization in business decisions without automating judgement.

### Source excerpt

Author : Mayara Zenati At Nubank, we believe the most meaningful problems for customers and for the business rarely come with ready-made answers. That is why we challenge the status quo: not to innovate for innovation's sake, but to remove complexity and build solutions that make important decisions simpler, faster and better. This mindset also [...] The post NFR Brain: challenging the status quo of risk management with data appeared first on Building Nubank.

## NFR Brain: challenging the status quo of risk management with data

DevFeed: [NFR Brain: challenging the status quo of risk management with data](<https://devfeed.tech/articles/nfr-brain-challenging-the-status-quo-of-risk-management-with-data-38852.md>)

Original publisher: [Read original article](<https://building.nubank.com/nfr-brain-challenging-the-status-quo-of-risk-management-with-data/>)

Author: Nubank Editorial

Published: 2026-09-04T14:18:41Z

Content type: article

Language: en

Sources: [Nubank](<https://devfeed.tech/sources/nubank.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [data](<https://devfeed.tech/topics/data.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [data](<https://devfeed.tech/tags/data.md>), [data-analytics](<https://devfeed.tech/tags/data-analytics.md>), [data-science-machine-learning](<https://devfeed.tech/tags/data-science-machine-learning.md>), [management](<https://devfeed.tech/tags/management.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [service](<https://devfeed.tech/tags/service.md>)

### AI overview

Nubank is building NFR Brain, a platform that combines data, modelling and expert judgement to create a comparable and actionable view of non-financial risk. The article explains how the platform is intended to support clearer, more consistent prioritization across operational failures, customer complaints, third-party dependencies and other risk signals.

### Source excerpt

Author : Mayara Zenati At Nubank, we believe the most meaningful problems for customers and for the business rarely come with ready-made answers. That is why we challenge the status quo: not to innovate for innovation's sake, but to remove complexity and build solutions that make important decisions simpler, faster and better. This mindset also [...] The post NFR Brain: challenging the status quo of risk management with data appeared first on Building Nubank.

## Why agentic AI starts with legacy modernisation

DevFeed: [Why agentic AI starts with legacy modernisation](<https://devfeed.tech/articles/why-agentic-ai-starts-with-legacy-modernisation-33597.md>)

Original publisher: [Read original article](<https://blog.scottlogic.com/2026/08/21/why-agentic-ai-starts-with-legacy-modernisation.html>)

Author: Suzanne Angell

Published: 2026-08-21T09:33:00Z

Content type: opinion

Language: en

Sources: [Scott Logic](<https://devfeed.tech/sources/scott-logic.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [legacy](<https://devfeed.tech/topics/legacy.md>), [legacy systems](<https://devfeed.tech/topics/legacy-systems.md>), [data](<https://devfeed.tech/topics/data.md>), [Processes](<https://devfeed.tech/topics/processes.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [data](<https://devfeed.tech/tags/data.md>), [governance](<https://devfeed.tech/tags/governance.md>), [integration](<https://devfeed.tech/tags/integration.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [legacy-modernisation](<https://devfeed.tech/tags/legacy-modernisation.md>), [operational-risk](<https://devfeed.tech/tags/operational-risk.md>), [processes](<https://devfeed.tech/tags/processes.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

The article argues that organisations must address fragmented data, brittle processes, and outdated architectures before they can realise the full value of agentic AI. It explains that legacy systems may remain operationally critical, while accumulated technical, process, and organisational debt can prevent agents from accessing reliable information and executing workflows consistently.

### Source excerpt

Organisations are increasingly excited by the potential of agentic AI, but many overlook the legacy obstacles that stand in the way. In this post, I explore why successful AI adoption depends on tackling fragmented data, brittle processes and outdated architectures, and why modernisation is often the most important step towards unlocking value from intelligent agents.

## Want to use AI agents safely? Start with design

DevFeed: [Want to use AI agents safely? Start with design](<https://devfeed.tech/articles/want-to-use-ai-agents-safely-start-with-design-33596.md>)

Original publisher: [Read original article](<https://blog.scottlogic.com/2026/08/18/want-to-use-ai-agents-safely-start-with-design.html>)

Author: Colin Eberhardt

Published: 2026-08-18T13:12:00Z

Content type: opinion

Language: en

Sources: [Scott Logic](<https://devfeed.tech/sources/scott-logic.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [Security](<https://devfeed.tech/topics/security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [auditability](<https://devfeed.tech/tags/auditability.md>), [design](<https://devfeed.tech/tags/design.md>), [end-to-end-process](<https://devfeed.tech/tags/end-to-end-process.md>), [featured](<https://devfeed.tech/tags/featured.md>), [governance](<https://devfeed.tech/tags/governance.md>), [guardrails](<https://devfeed.tech/tags/guardrails.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [operational-resilience](<https://devfeed.tech/tags/operational-resilience.md>), [quality](<https://devfeed.tech/tags/quality.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [service-design](<https://devfeed.tech/tags/service-design.md>), [systems](<https://devfeed.tech/tags/systems.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

This article argues that organisations adopting AI agents should begin with process and system design rather than controls alone. It explains that design should account for human and machine strengths, establish proportionate guardrails, and define how observability and monitoring evolve as the system matures.

### Source excerpt

Concerns about control are one of the biggest barriers to adopting agentic AI, particularly in regulated environments. In this post, we discuss how organisations can harness AI safely by designing processes around the strengths of both humans and machines, then applying the right controls, guardrails and monitoring.

## AI governance gaps leave developer and agent access to AI tools insufficiently controlled

DevFeed: [AI governance gaps leave developer and agent access to AI tools insufficiently controlled](<https://devfeed.tech/articles/the-ai-innovation-security-paradox-17653.md>)

Original publisher: [Read original article](<https://nirmata.com/2026/08/04/ai-innovation-security-paradox/>)

Author: Anubhav Sharma

Published: 2026-08-05T01:56:41Z

Content type: opinion

Language: en

Sources: [Nirmata](<https://devfeed.tech/sources/nirmata.md>)

Topics: [ai-governance](<https://devfeed.tech/topics/ai-governance.md>), [Security](<https://devfeed.tech/topics/security.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [developer-productivity](<https://devfeed.tech/topics/developer-productivity.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [llms](<https://devfeed.tech/tags/llms.md>), [policy-management](<https://devfeed.tech/tags/policy-management.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [visibility](<https://devfeed.tech/tags/visibility.md>)

### AI overview

The article presents aggregated responses from security leaders about AI governance in fast-moving engineering organizations. It identifies gaps in centralized access control, policy enforcement, session auditing, real-time visibility, and protection against exposing permissions or environment variables to LLMs.

### Source excerpt

Three Questions We Asked About AI Governance -- And What the Answers Reveal Over the past few months, we've been having the same conversation on repeat with security leaders about AI at fast-moving engineering organizations. Different companies, different tech stacks, same three questions -- and,... The post The AI Innovation-Security Paradox first appeared on Nirmata.

## Canon 3X: Explore/Expand/Extract

DevFeed: [Canon 3X: Explore/Expand/Extract](<https://devfeed.tech/articles/canon-3x-explore-expand-extract-39973.md>)

Original publisher: [Read original article](<https://newsletter.kentbeck.com/p/canon-3x-exploreexpandextract>)

Author: Kent Beck

Published: 2026-07-30T13:04:07Z

Content type: opinion

Language: en

Sources: [Software Design: Tidy First?](<https://devfeed.tech/sources/software-design-tidy-first.md>)

Topics: [implementation](<https://devfeed.tech/topics/implementation.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Finance](<https://devfeed.tech/topics/finance.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [implementation](<https://devfeed.tech/tags/implementation.md>), [management](<https://devfeed.tech/tags/management.md>), [project-management](<https://devfeed.tech/tags/project-management.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

Kent Beck explains the 3X framework of Explore, Expand, and Extract, arguing that each phase of a product or company's growth requires different approaches to finance, teams, project management, technology, risk management, implementation, marketing, and sales.

### Source excerpt

I've started a series of Canon articles where I explain my ideas as plainly & unambiguously as possible--no analogies, no persuasion, just the facts.

## From Unplanned Risk to Lasting Resilience: The Role of Immediate Risk Reduction

DevFeed: [From Unplanned Risk to Lasting Resilience: The Role of Immediate Risk Reduction](<https://devfeed.tech/articles/from-unplanned-risk-to-lasting-resilience-the-role-of-immediate-risk-reduction-23979.md>)

Original publisher: [Read original article](<https://medium.com/mcdonalds-technical-blog/from-unplanned-risk-to-lasting-resilience-the-role-of-immediate-risk-reduction-16b1c0d9c2b8?source=rss----3bac42476d27---4>)

Author: Global Technology

Published: 2026-06-30T14:14:45Z

Content type: article

Language: en

Sources: [McDonald's Technical Blog - Medium](<https://devfeed.tech/sources/mcdonald-s-technical-blog-medium.md>)

Topics: [Resilience](<https://devfeed.tech/topics/resilience.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [audit](<https://devfeed.tech/topics/audit.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [governance](<https://devfeed.tech/tags/governance.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

This article explains how McDonald's Immediate Risk Reduction (IRR) team addresses urgent, unplanned security risks through coordinated, cross-functional action. It argues that a repeatable response process can reduce exposure and business impact while strengthening long-term cybersecurity resilience.

### Source excerpt

How Immediate Risk Reduction (IRR) brings teams together to tackle urgent risks quickly while strengthening the foundations for long-term resilience. by: Ebony Love, Director, Immediate Risk Reduction Quick Bytes IRR focuses on resolving meaningful, unplanned security issues quickly, without slowing down the business It's a deliberately cross functional effort, bridging across McDonald's to break down silos and drive coordinated action By standardizing the way urgent risks are handled, IRR helps embed resilience directly into McDonald's cybersecurity DNA In a global, fast-moving organization like McDonald's, unplanned risks aren't an exception; they're an expectation. As our technologies evolve, infrastructure modernizes, and platforms innovate, risks are continuously identified, ranging from foundational hygiene issues to more complex security challenges. These rarely arrive neatly scoped or conveniently timed. When they do show up, even manageable ones can stall, escalate, or compete with day-to-day priorities if there isn't a clear way to bring the right people together and address them. The Immediate Risk Reduction (IRR) team exists to close that gap. These risks can take many forms; it could be a market escalation, an internal audit finding, simple hygiene tasks, or a software update that introduces an unexpected risk. Regardless, by providing a clear, repeatable way to respond to urgent risks, we make sure they're addressed before they impact the business. To put it simply: IRR has changed how McDonald's handles unplanned risks, reducing exposure faster, limiting business impact, and making us better at cybersecurity over time. The result is a quicker resolution today, and stronger resilience for whatever comes next. Building a bridge across McDonald's IRR exists for one simple reason: real cybersecurity risks don't fit neatly in a box, aligning only to one team or function. On paper, we're part of Global Cyber Security, but in practice our team bridges across

## Maintenance of Everything : A Review

DevFeed: [Maintenance of Everything : A Review](<https://devfeed.tech/articles/maintenance-of-everything-a-review-39491.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/maintenance-of-everything-a-review>)

Author: Phil Venables

Published: 2026-04-18T10:45:19Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [maintenance](<https://devfeed.tech/topics/maintenance.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [reliability](<https://devfeed.tech/topics/reliability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [review](<https://devfeed.tech/tags/review.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

A review of Stewart Brand's book Maintenance of Everything, discussing the importance of maintenance in technology risk management, security, and reliability. It also questions cybersecurity benchmarking that focuses on inputs such as budgets instead of outcomes such as control effectiveness.

### Source excerpt

I haven't done a book review for a while and there's no better way to get back to this than a look at Stewart Brand's Maintenance of Everything . Stewart developed a lot of this book in an open editing process and so the final delivery of what is Part 1 of a forthcoming series was all the more anticipated. I've long been obsessed with the need for maintenance in the context of technology risk management, security and reliability. A big part of technical debt build up and the security...

## Beyond Compliance: Building Security That Protects Patients and Innovation

DevFeed: [Beyond Compliance: Building Security That Protects Patients and Innovation](<https://devfeed.tech/articles/beyond-compliance-building-security-that-protects-patients-and-innovation-4479.md>)

Original publisher: [Read original article](<https://www.toptal.com/executive-guidance/podcasts/building-security-that-protects-patients-and-innovation>)

Author: ZOHRA IBRAHIMI, INFORMATION SECURITY PRACTICE LEAD @ TOPTAL

Published: 2026-04-12T22:00:00Z

Content type: article

Language: en

Sources: [Toptal Blog](<https://devfeed.tech/sources/toptal-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [shadow AI](<https://devfeed.tech/topics/shadow-ai.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [governance](<https://devfeed.tech/tags/governance.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [shadow-ai](<https://devfeed.tech/tags/shadow-ai.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

A podcast discussion about healthcare cybersecurity with Orus Dearman of iRhythm Technologies and Zohra Ibrahimi of Toptal. They examine how security leaders balance compliance, innovation, reliability, and patient trust, including governance for AI adoption, shadow AI risk, vendor ecosystems, and supply-chain security.

### Source excerpt

As healthcare systems become more digital and interconnected, cybersecurity leaders must protect sensitive patient data while ensuring critical technology remains reliable and accessible. In this episode of the Executive Guidance podcast, Orus Dearman, Chief Information Security Officer at iRhythm Technologies, joins Zohra Ibrahimi, Toptal's Cyber and Information Security Practice Lead, to discuss how healthcare security leaders balance compliance, innovation, and trust.

## Preparing for the Cyber Security and Resilience Bill (CSRB): Compliance Insights from the Field

DevFeed: [Preparing for the Cyber Security and Resilience Bill (CSRB): Compliance Insights from the Field](<https://devfeed.tech/articles/preparing-for-the-cyber-security-and-resilience-bill-csrb-compliance-insights-from-the-field-29617.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/cyber-security-and-resilience-bill-compliance/>)

Author: sami.ali@goteleport.com (Sami Ali)

Published: 2025-10-22T00:00:00Z

Content type: opinion

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [policy](<https://devfeed.tech/tags/policy.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

This commentary draws on conversations with partners and prospects across EMEA to explain how organisations are preparing for the proposed UK Cyber Security and Resilience Bill. It focuses on supply-chain access, incident response, continuous risk assessment, and detailed reporting, arguing that compliance requires organisations to reassess infrastructure access and their ability to reconstruct incidents.

### Source excerpt

Explore insights from real customer conversations on how they're addressing the Cyber Security and Resilience Bill -- and how to start translating policy into action.

## Engineering Audits for ISO 13485 Medical Device Software Quality Management Systems

DevFeed: [Engineering Audits for ISO 13485 Medical Device Software Quality Management Systems](<https://devfeed.tech/articles/what-is-an-engineering-audit-like-26536.md>)

Original publisher: [Read original article](<https://annajmcdougall.medium.com/what-is-an-engineering-audit-like-dc2e09719efd?source=rss-51f15275ef3a------2>)

Author: Anna J McDougall

Published: 2025-08-18T20:21:35Z

Content type: article

Language: en

Sources: [Anna J McDougall](<https://devfeed.tech/sources/anna-j-mcdougall.md>)

Topics: [audit](<https://devfeed.tech/topics/audit.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Development](<https://devfeed.tech/topics/development.md>), [Software](<https://devfeed.tech/topics/software.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [coding-style](<https://devfeed.tech/tags/coding-style.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [engineering-management](<https://devfeed.tech/tags/engineering-management.md>), [iso](<https://devfeed.tech/tags/iso.md>), [iso-13485-standard](<https://devfeed.tech/tags/iso-13485-standard.md>), [lifecycle](<https://devfeed.tech/tags/lifecycle.md>), [management](<https://devfeed.tech/tags/management.md>), [medical-devices](<https://devfeed.tech/tags/medical-devices.md>), [processes](<https://devfeed.tech/tags/processes.md>), [quality](<https://devfeed.tech/tags/quality.md>), [regulatory](<https://devfeed.tech/tags/regulatory.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [review](<https://devfeed.tech/tags/review.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [safety](<https://devfeed.tech/tags/safety.md>), [software](<https://devfeed.tech/tags/software.md>), [software-engineering](<https://devfeed.tech/tags/software-engineering.md>), [systems](<https://devfeed.tech/tags/systems.md>)

### AI overview

This case study explains what an engineering audit involves under ISO 13485 for medical device software. It covers Quality Management System documentation, lifecycle management, patient safety, risk management, regulatory requirements, and the author's experience updating engineering compliance documents.

### Source excerpt

What is an Engineering Audit Like? An ISO 13485 Medical Device Engineering QMS Case StudyI think I found my new look. If there's one thing that gets me fired up, it's a good ol'-fashioned audit! ... Said nobody ever. Sadly, audits are a part of the business world that tend not to be fun. However, they also serve an important purpose, and are part of the transition from the "fun team lead" style of management into the "business leader" role is coming to grips with the unsexy stuff. As part of my role at HelloBetter, I was tasked with leading engineering compliance and reporting for ISO 13485, an internationally recognised standard for Quality Management Systems (QMS) specifically for medical device manufacturers, within the broader context of the EU Medical Device Regulation (MDR). For those who aren't familiar with what an audit of this kind involves, the simple version is this: Certain requirements exist as part of the standard, not just about how to effectively create and maintain software, but also how to document that compliance. This documentation is referred to as the Quality Management System (QMS), which as the name implies serves as documentation for how you maintain quality as per the ISO. The ISO isn't only about software, but software is part of "Lifecycle Management", tracking how a medical device (in this case) goes from design and development to distribution and surveillance. A company required to meet the ISO should therefore create and follow a system that ticks all the boxes for things like patient safety, risk management, and any additional regulatory hurdles. Typically once a year, an auditor is hired to enter the company and review the documentation alongside representatives from the company who guide them through the QMS. Additionally, individuals (like me!) are pulled from different parts of the company to talk through their processes and documentation, and to show any examples that may be relevant. My Experience with Engineering Compliance for

## Why AI Trust Will Shape Your Next Decade of Software Development

DevFeed: [Why AI Trust Will Shape Your Next Decade of Software Development](<https://devfeed.tech/articles/why-ai-trust-will-shape-your-next-decade-of-software-development-8248.md>)

Original publisher: [Read original article](<https://snyk.io/blog/why-ai-trust-will-shape-your-next-decade-of-software-development/>)

Author: Brendan Hann

Published: 2025-06-24T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Development](<https://devfeed.tech/topics/ai-development.md>), [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [snyk](<https://devfeed.tech/topics/snyk.md>), [Security](<https://devfeed.tech/topics/security.md>), [sdlc](<https://devfeed.tech/topics/sdlc.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [prompt injection](<https://devfeed.tech/topics/prompt-injection.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [ai-transparency](<https://devfeed.tech/tags/ai-transparency.md>), [automation](<https://devfeed.tech/tags/automation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [developer](<https://devfeed.tech/tags/developer.md>), [development](<https://devfeed.tech/tags/development.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [governance](<https://devfeed.tech/tags/governance.md>), [interest](<https://devfeed.tech/tags/interest.md>), [llm](<https://devfeed.tech/tags/llm.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [sdlc](<https://devfeed.tech/tags/sdlc.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [speed](<https://devfeed.tech/tags/speed.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

The article argues that AI trust is foundational for safe, scalable software development as organizations adopt AI and agentic workflows. It describes AI trust as maintaining control, visibility, security, governance, and continuous risk management while benefiting from faster delivery, greater productivity, and automation. It highlights risks including insecure AI-generated code, prompt injection, data exfiltration, model manipulation, and misconfiguration, and presents Snyk's AI Security Platform as a way to embed risk management and security into the SDLC.

### Source excerpt

Discover why AI Trust is crucial for secure, scalable software development in the AI era. Learn how Snyk's AI Security Platform helps you manage risk, enforce policies, and ensure continuous compliance.

## NIS2: Understanding key software security requirements

DevFeed: [NIS2: Understanding key software security requirements](<https://devfeed.tech/articles/nis2-understanding-key-software-security-requirements-13185.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/nis2-understanding-key-software-security-requirements>)

Published: 2025-02-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [cve-reporting](<https://devfeed.tech/tags/cve-reporting.md>), [energy](<https://devfeed.tech/tags/energy.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [manufacturing](<https://devfeed.tech/tags/manufacturing.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [transportation](<https://devfeed.tech/tags/transportation.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article explains how the European Union's NIS2 directive expands software security and vulnerability management requirements, shifts accountability to management and boards, and affects organizations operating in the EU. It discusses software supply chain security, open source development, SBOMs, CVE reporting, risk management, and the workload these requirements may create for security and developer teams.

### Source excerpt

The European Union's Network and Information Systems 2 is a compliance framework with strict requirements around vulnerability management.

## Reinventing Risk at Revolut

DevFeed: [Reinventing Risk at Revolut](<https://devfeed.tech/articles/reinventing-risk-at-revolut-26346.md>)

Original publisher: [Read original article](<https://medium.com/revolut/reinventing-risk-at-revolut-77e63c552503?source=rss----44c5ac415e14---4>)

Author: Konstantin Vasilev

Published: 2024-12-10T07:46:23Z

Content type: opinion

Language: en

Sources: [Revolut Engineering](<https://devfeed.tech/sources/revolut-engineering.md>)

Topics: [Finance](<https://devfeed.tech/topics/finance.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [banking](<https://devfeed.tech/tags/banking.md>), [fake-accounts](<https://devfeed.tech/tags/fake-accounts.md>), [finance](<https://devfeed.tech/tags/finance.md>), [financial](<https://devfeed.tech/tags/financial.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [knowledge-graph](<https://devfeed.tech/tags/knowledge-graph.md>), [operations](<https://devfeed.tech/tags/operations.md>), [outage](<https://devfeed.tech/tags/outage.md>), [revolut](<https://devfeed.tech/tags/revolut.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [services](<https://devfeed.tech/tags/services.md>)

### AI overview

Revolut describes how its Risk function approaches financial and operational risk in a financial-services business. The article explains that risks can overlap, such as fraud involving fake accounts leading to unpaid loans, and discusses the limitations of segregating risks into separate departments.

### Source excerpt

Using probability, reasoning and AI Revolut is known for its innovation in delivering "super-app" financial services to its customers. The success is evident not only through the rocketing user growth, but also via the ripple effects caused across the banking industry -- traditional finance has to reinvent and evolve, or remain part of history, just like the internet search replaced the paper phonebook. Behind this success stands a complex and impressive machinery, which is still piloted by the same founders, who also engineered the very first components and set the Revolut rocketship in motion. This machine is mostly known for its software excellence, however, with any financial services comes the responsibility of navigating a complex net of regulations and risks. True to the company values, the Risk function at Revolut also innovates, leveraging the decades of banking experience of its leadership and adding the challenger way of thinking with the latest technology. What is Risk? One can find many definitions of risk, ranging from explanations suitable for children, "The possibility of something bad happening", to advanced statistical definitions used in finance: Uncertainty of the return on investment, characterised by standard deviation, asymmetry and tails of the return distribution and the generic ISO 31000 definition: "The effect of uncertainty on objectives" In addition, both graduate textbooks and banking regulations define two general types of risk: Financial: related to financial positions, such as: user deposits, lending, and investments in market instruments. Operational: related to failure of operations, such as: system outage, fraud and natural disasters. Some of you might already sense the inevitable challenges in distinguishing the above definitions and risks. Events seldom happen in isolation and independently: a natural disaster can lead to system outages and market crashes, similarly fraudsters might use fake accounts to withdraw loans which would

## Where Do I Start With SASE Evaluations? Gartner® Report

DevFeed: [Where Do I Start With SASE Evaluations? Gartner® Report](<https://devfeed.tech/articles/where-do-i-start-with-sase-evaluations-gartner-report-20381.md>)

Original publisher: [Read original article](<https://umbrella.cisco.com/blog/where-do-i-start-with-sase-evaluations-gartner-report>)

Author: Yuval Yatskan

Published: 2024-09-10T08:00:00Z

Content type: article

Language: en

Sources: [OpenDNS](<https://devfeed.tech/sources/opendns.md>)

Topics: [SASE](<https://devfeed.tech/topics/sase.md>), [Security](<https://devfeed.tech/topics/security.md>), [SD-WAN](<https://devfeed.tech/topics/sd-wan.md>)

Tags: [cisco-sase](<https://devfeed.tech/tags/cisco-sase.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [sase](<https://devfeed.tech/tags/sase.md>), [sd-wan](<https://devfeed.tech/tags/sd-wan.md>), [secure-access-service-edge](<https://devfeed.tech/tags/secure-access-service-edge.md>), [secure-access-service-edge-sase](<https://devfeed.tech/tags/secure-access-service-edge-sase.md>), [security-service-edge-sse](<https://devfeed.tech/tags/security-service-edge-sse.md>), [spotlight](<https://devfeed.tech/tags/spotlight.md>), [strategy](<https://devfeed.tech/tags/strategy.md>)

### AI overview

This Cisco Umbrella article explains how SASE combines cloud-delivered networking and security for distributed workplaces, with SSE as its security-focused subset. It highlights a Gartner report that offers guidance for beginning SASE evaluations, including strategy and requirements considerations.

### Source excerpt

Ransomware makes up 154 million of the threats Cisco blocks monthly; information stealers make up 246 million more. However, the continued evolution of online threats from ransomware and persistent bad actors is only one small piece of the risk management puzzle. Security leaders are not only responding to more sophisticated and expanding threats, but they're [...] The post Where Do I Start With SASE Evaluations? Gartner® Report appeared first on Cisco Umbrella.

## How NIST is changing standards to safeguard AI

DevFeed: [How NIST is changing standards to safeguard AI](<https://devfeed.tech/articles/how-nist-is-changing-standards-to-safeguard-ai-13092.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-nist-is-changing-standards-to-safeguard-ai>)

Published: 2024-08-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Responsibility & Safety](<https://devfeed.tech/topics/responsibility-safety.md>), [ai safety](<https://devfeed.tech/topics/ai-safety.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>)

Tags: [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [gemini](<https://devfeed.tech/tags/gemini.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [nist](<https://devfeed.tech/tags/nist.md>), [responsible-ai](<https://devfeed.tech/tags/responsible-ai.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [standards](<https://devfeed.tech/tags/standards.md>)

### AI overview

The article explains how NIST is developing AI safety and security guidelines in response to the White House's October 2023 Executive Order. It highlights generative AI risks such as disinformation, phishing, malware development, and sensitive-data leaks, and describes planned companion resources for the AI Risk Management Framework and Secure Software Development Framework.

### Source excerpt

New NIST AI standards address generative AI risks with a focus on risk management, security practices, and recognizing synthetic content.

## The Swedbank Outage shows that Change Controls don't work

DevFeed: [The Swedbank Outage shows that Change Controls don't work](<https://devfeed.tech/articles/the-swedbank-outage-shows-that-change-controls-don-t-work-27908.md>)

Original publisher: [Read original article](<http://highscalability.com/blog/2023/8/16/the-swedbank-outage-shows-that-change-controls-dont-work.html>)

Author: Bruce Johnston

Published: 2023-08-16T17:05:12Z

Content type: opinion

Language: en

Sources: [High Scalability](<https://devfeed.tech/sources/high-scalability.md>), [High Scalability](<https://devfeed.tech/sources/high-scalability-2.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [banking](<https://devfeed.tech/tags/banking.md>), [change](<https://devfeed.tech/tags/change.md>), [incident](<https://devfeed.tech/tags/incident.md>), [management](<https://devfeed.tech/tags/management.md>), [outage](<https://devfeed.tech/tags/outage.md>), [payments](<https://devfeed.tech/tags/payments.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

The article examines the Swedbank outage caused by an unapproved IT change and the Swedish FSA's findings that the bank's internal controls and change management process failed. It argues that manual approvals and change meetings do not by themselves mitigate risk in modern technology organizations.

### Source excerpt

This week I've been reading through the recent judgment from the Swedish FSA on the Swedbank outage. If you're unfamiliar with this story, Swedbank had a major outage in April 2022 that was caused by an unapproved change to their IT systems. It temporarily left nearly a million customers with incorrect balances, many of whom were unable to meet payments. After investigation, the regulator found that Swedbank had not followed their change management process and issued a SEK850M (~85M USD) fine. That's a lot of money to you and me, but probably didn't impact their bottom line very much. Either way I'm sure the whole episode will have been a big wake up call for the people at the bank whose job it is to ensure adequate risk and change controls. So, what went wrong and how could it have been avoided? How did the Swedbank incident happen? The judgment doesn't describe the technical details behind the incident, but it does provide glimpses into how they assessed what went wrong: "The deficiencies that were present in Swedbank's internal control made it possible to make changes to one of the bank's most central IT systems without following the process in place at the bank to ensure continuity and reliable operations. This violation is therefore neither minor nor excusable." "none of the bank's control mechanisms were able to capture the deviation and ensure that the process was followed" "one of the main causes underlying the IT incident was non-compliance with the change management process and that it is probable that this also resulted in a slower analysis of the incident and a greater impact on the operations." "good internal control is a prerequisite for a bank to be able to fulfill the requirements on risk management" Even if you think $85M isn't much of a fine - simply the cost of doing business - the full range of options open to the regulator included removing Swedbank's banking license: "It is therefore not relevant to withdraw Swedbank's authorisation or issue th

## What the Swedbank outage reveals about the limits of traditional change management

DevFeed: [What the Swedbank outage reveals about the limits of traditional change management](<https://devfeed.tech/articles/the-swedbank-outage-shows-that-change-controls-don-t-work-33611.md>)

Original publisher: [Read original article](<https://highscalability.com/the-swedbank-outage-shows-that-change-controls-dont-work/>)

Author: Bruce Johnston

Published: 2023-08-16T16:05:12Z

Content type: opinion

Language: en

Sources: [High Scalability](<https://devfeed.tech/sources/high-scalability-3.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>)

Tags: [banking](<https://devfeed.tech/tags/banking.md>), [incident](<https://devfeed.tech/tags/incident.md>), [management](<https://devfeed.tech/tags/management.md>), [outage](<https://devfeed.tech/tags/outage.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

The article examines the Swedish FSA's judgment on Swedbank's April 2022 outage, which followed an unapproved IT change and affected customer balances and payments. It argues that traditional change-management controls, including manual approvals and change meetings, do not by themselves guarantee safe and secure changes.

### Source excerpt

This week I've been reading through the recent judgment from the Swedish FSA on the Swedbank outage. If you're unfamiliar with this story, Swedbank had a major outage in April 2022 that was caused by an unapproved change to their IT systems. It temporarily left nearly

## Worthwhile Books Q4 2022

DevFeed: [Worthwhile Books Q4 2022](<https://devfeed.tech/articles/worthwhile-books-q4-2022-37134.md>)

Original publisher: [Read original article](<https://shostack.org/blog/worthwhile-books-q4/>)

Author: Adam

Published: 2022-12-19T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>)

Tags: [books](<https://devfeed.tech/tags/books.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [safety](<https://devfeed.tech/tags/safety.md>)

### AI overview

A personal roundup of books read in late 2022, highlighting works about safety, maritime disaster, engineering, risk management, science, fiction, and astrobiology. The author emphasizes lessons that transfer from safety to cybersecurity.

### Source excerpt

Books that I read in the fourth quater that are worth your time include several about safety with lessons for cybersecurity

## Application Security Roundup - June

DevFeed: [Application Security Roundup - June](<https://devfeed.tech/articles/application-security-roundup-june-36680.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-june/>)

Author: Adam

Published: 2022-06-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [medical-devices](<https://devfeed.tech/tags/medical-devices.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

A June application security roundup highlights articles about requirements for medical-device cybersecurity, policy and implementation, and the importance of appropriate risk management and investigation despite concerns about cost and delay.

### Source excerpt

Interesting appsec posts: from medical devices to bridges.

## What are we going to do: CO2 edition

DevFeed: [What are we going to do: CO2 edition](<https://devfeed.tech/articles/what-are-we-going-to-do-co2-edition-37116.md>)

Original publisher: [Read original article](<https://shostack.org/blog/what-are-we-going-to-do-co2-edition/>)

Author: Adam

Published: 2021-10-05T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [bypass](<https://devfeed.tech/tags/bypass.md>), [carbon](<https://devfeed.tech/tags/carbon.md>), [climate](<https://devfeed.tech/tags/climate.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [ease](<https://devfeed.tech/tags/ease.md>), [emissions](<https://devfeed.tech/tags/emissions.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [usability](<https://devfeed.tech/tags/usability.md>)

### AI overview

The article uses Microsoft's evaluation of carbon-removal proposals to discuss how explicit criteria can improve mitigation and risk-management decisions. It applies this idea to cybersecurity threat modeling, including cost, bypass resistance, usability, and unusual circumstances.

### Source excerpt

What happened when Microsoft tried to buy climate abatements

## Zen and the art of not quantifying risk

DevFeed: [Zen and the art of not quantifying risk](<https://devfeed.tech/articles/zen-and-the-art-of-not-quantifying-risk-37136.md>)

Original publisher: [Read original article](<https://shostack.org/blog/zen-and-the-art-of-not-quantifying-risk/>)

Author: Adam

Published: 2021-07-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Development](<https://devfeed.tech/topics/development.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [development](<https://devfeed.tech/tags/development.md>), [dialog](<https://devfeed.tech/tags/dialog.md>), [meetings](<https://devfeed.tech/tags/meetings.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that threat modeling should not focus on producing precise risk numbers. Instead, security teams should work with development and operations on prioritization, using simpler relative sizing when appropriate. This approach can reduce conflict and help address easily fixed lower-priority issues alongside larger changes.

### Source excerpt

Many people want their threat modeling work to produce risk numbers, and in this post you'll learn why that's a mistake.

## Review: Practical Cybersecurity Architecture

DevFeed: [Review: Practical Cybersecurity Architecture](<https://devfeed.tech/articles/review-practical-cybersecurity-architecture-36957.md>)

Original publisher: [Read original article](<https://shostack.org/blog/review-practical-cybersecurity-architecture/>)

Author: Adam

Published: 2021-05-26T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [practical](<https://devfeed.tech/tags/practical.md>), [review](<https://devfeed.tech/tags/review.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>)

### AI overview

Adam Shostack reviews Practical Security Architecture by Diana Kelley and Ed Moyle, praising its concise, practical, customer-focused approach to security architecture. He also discusses its treatment of application security, risk management, and threat modeling, including his view that likelihood can often be simplified when analyzing public-facing applications.

### Source excerpt

Adam Shostack's review of the book Practical Cybersecurity Architecture

## Includes No Dirt: Healthcare Threat Modeling (Thursday)

DevFeed: [Includes No Dirt: Healthcare Threat Modeling (Thursday)](<https://devfeed.tech/articles/includes-no-dirt-healthcare-threat-modeling-thursday-36838.md>)

Original publisher: [Read original article](<https://shostack.org/blog/includes-no-dirt-healthcare-threat-modeling-thursday/>)

Author: Adam

Published: 2019-10-31T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [development-process](<https://devfeed.tech/tags/development-process.md>), [healthcare](<https://devfeed.tech/tags/healthcare.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>)

### AI overview

A commentary on the "Includes No Dirt" threat modeling approach by William Dogherty and Patrick Curry of Omada Health. The article describes its focus on security, privacy, and compliance, outlines the NO DIRT model and supporting worksheets, and discusses its potential use in development and vendor risk management.

### Source excerpt

"Includes No Dirt" is a threat modeling approach by William Dogherty and Patrick Curry of Omada Health, and I've been meaning to write about it since it came out.

[Next page](<https://devfeed.tech/tags/risk-management.md?cursor=WyIyMDE5LTEwLTMxVDAwOjAwOjAwKzAwOjAwIiwgIjk5ZmFlNTYxLWY3NmEtNDE5Ny1iOGNlLWM3OThiYzM4YWViYyJd>)