Continuous improvement
Lessons should change the next decision.
Every lesson begins with evidence from a published article. Browse the latest changes in understanding and practice across the four decision domains.
Explore the decision domainsAccountability and capital
Govern & Invest
What matters, who owns it, and where should we invest?
Strategy, risk appetite, accountability, operating models, assurance, metrics, budgets, talent, and third-party governance.
- Govern & Invest
A seamless model update can still be a material governance event. Test the decision impact before allowing new scores to rewrite priorities, capacity, and risk reporting.
From: EPSS v5 Changed the Queue Without Changing the Integration - Govern & Invest
Executives should demand a prioritization process that explains material exposure, accountable ownership, uncertainty, response constraints, and verified risk reduction.
From: What Executives Should Demand from Vulnerability Prioritization - Govern & Invest
A material model change is a governance event: thresholds, workflows, capacity assumptions, and executive reporting must be revalidated before adoption.
From: EPSS v4 Changed the Scores. The Leadership Lesson Was Model Governance - Govern & Invest
Vulnerability management becomes defensible when scores inform a transparent decision system built around exposure, consequence, ownership, capacity, and verified outcomes.
From: Vulnerability Management Is a Decision System, Not a Patch Queue
Secure transformation
Architect & Build
How do we build and adopt technology without hidden exposure?
Cloud and platform architecture, product security, data, identity architecture, trust boundaries, and secure-by-design engineering.
- Architect & Build
Local AI increases operator control and responsibility together; privacy, isolation, recoverability, and cost must be explicit architectural decisions.
From: Local AI on Proxmox: The Security Tradeoffs Behind GPU-Enabled LXC - Architect & Build
Orchestration concentrates authority; even a small automation platform needs deliberate state protection, access boundaries, upgrades, and recovery.
From: Running AWX on MicroK8s: What a Small Automation Platform Still Requires - Architect & Build
Strong randomness does not make a secret securely managed; the full credential lifecycle needs protected storage, controlled delivery, rotation, and recovery.
From: Random Passwords from the Shell: A Small Tool with Security Boundaries
Operational exposure
Defend & Detect
Where are we exposed, and which controls demonstrably change it?
Threats, vulnerability and exposure management, detection, response readiness, and operational control validation.
- Defend & Detect
EPSS improves prioritization when probability informs policy alongside known exploitation, reachability, business consequence, control strength, and remediation capacity.
From: Operationalizing EPSS Without Turning Probability into Policy by Accident - Defend & Detect
Shell history is both operational memory and potentially sensitive evidence, so retention, exclusion, access, and deletion must be designed together.
From: Bash History Is Operational Memory—and Sometimes Sensitive Data
Continuity under pressure
Resilience & Recovery
Can the organization withstand disruption and recover reliably?
Disruption, concentration risk, crisis leadership, continuity, recoverability, and verified restoration.
- Resilience & Recovery
A backup inside the same failure domain is not an independent control; recovery evidence requires separated artifacts, protected secrets, and repeated restore tests.
From: A Backup That Depends on n8n Is Not an Independent Control - Resilience & Recovery
An operator can automate deployment mechanics, but it cannot replace accountable ownership, verified backups, explicit decision points, or a tested rollback path.
From: Upgrading AWX on MicroK8s Without Treating the Operator as a Rollback Plan - Resilience & Recovery
A patch is successful only when compatibility, rollback, service restoration, and the resulting security state have all been verified.
From: Patching Standalone ESXi: A Lab Runbook Built Around Recovery - Resilience & Recovery
Recovering disk space safely means preserving a known-good boot path, previewing dependency changes, and verifying the host after reboot.
From: Recovering Ubuntu Boot Space Without Removing Your Recovery Path