1. Secrets Management intermediate

    A team stores credentials in a secrets manager and considers the problem solved. What is still wrong, and what does a genuinely good secrets posture look like?

    2 min answer secretsrotationworkload-identitycredentials
  2. Sector Cloud Rules intermediate

    Until 2025 a European firm's cloud exit plan priced the egress bill as the main barrier and assumed the migration window was negotiable. The EU Data Act has applied since 12 September 2025 and removes switching charges entirely from 12 January 2027 while capping the switching timetable. What changed for the architecture team and what did not?

    3 min answer eu-data-actcloud-exitfunctional-equivalenceconcentration-risk
  3. Secure API Design intermediate

    A developer platform's API is used by thousands of external integrators. What security properties must be defaults rather than options?

    2 min answer postmanapi-securitydefaultsscopes
  4. Security Design Review intermediate

    A security design review consistently produces findings that are expensive to act on. What is wrong with the process?

    2 min answer workosdesign-reviewtimingthreat-model
  5. Security Design Review intermediate

    Security reviews happen the week before launch. Findings are usually rejected as too late to fix. How do you change this?

    2 min answer securityprocessinfluence
  6. Security Design Review intermediate

    Your security design review template asks for data flows, trust boundaries, authentication and encryption. A team submits a support assistant that reads customer ticket text and calls three internal APIs with a service account, one of which issues refunds. The template produces no findings. What would you add to it, and what would you leave alone?

    3 min answer security-design-reviewprompt-injectionconfused-deputyagents
  7. Security Testing in the Pipeline intermediate

    A pipeline runs security scanning and produces hundreds of findings that nobody acts on. What should change?

    2 min answer marqetasecurity-testingtriagereachability
  8. Security Testing in the Pipeline intermediate

    Which security checks belong in the pipeline, and what makes them useful rather than noise?

    2 min answer security-testingpipelinesignal-to-noiseprioritisation
  9. Security vs Usability intermediate

    A B2B SaaS with 900 tenants makes SAML single sign-on mandatory for every enterprise-plan tenant after a security review, and local passwords are deleted. Six weeks later an identity provider outage locks about 40 tenants out for three hours and support has no way to help. What did the mandate buy, what did it pay, and what should have existed first?

    2 min answer ssoidentityavailabilitybreak-glass
  10. Security vs Usability intermediate

    A security control is being circumvented by most of the team. What do you conclude and what do you do?

    2 min answer securityusabilityworkaroundsfriction
  11. Segregation of Duties intermediate

    An audit finds 40 engineers with permanent production database read access. The team says they need it for support. Resolve it.

    2 min answer accesscontrolsinsider-risk
  12. Self-Service Provisioning intermediate

    A platform offers self-service provisioning and teams still file tickets. Why, and what would change it?

    2 min answer delhiveryself-serviceprovisioningfriction