ALVOR
Platform
PricingCompare
Advisory
AboutBlog
Get Demo
ALVOR
Platform
PricingCompare
Advisory
AboutBlog
Get Demo

Blog

Insights & ideas

Perspectives on security, compliance, and building resilient organisations from the Alvor team.

Latest Articles

August 12, 2026·11 min read

Threat Modelling Under APRA CPS 234: Evidence for the Design-Time Obligations

How threat modelling gives APRA-regulated entities defensible evidence for CPS 234's design-time control obligations, and a process that fits alongside CPS 230.

Threat ModelingSecurity Architecture
Read →
August 5, 2026·16 min read

Threat Modeling AI Systems: A Practical Guide for LLM and Agentic Applications

How to threat model AI systems: STRIDE extended for LLM applications, the OWASP LLM Top 10 mapped to design-time decisions, and a worked RAG example.

AIThreat ModelingSecurity Architecture
Read →
July 29, 2026·14 min read

How to Do Threat Modeling: A Step-by-Step Guide for Your First Real System

A step-by-step threat modeling guide: scope the system, draw the data flow diagram, mark trust boundaries, enumerate threats with STRIDE, map controls, and decide.

Threat ModelingEngineering
Read →
July 22, 2026·13 min read

STRIDE Threat Modeling Explained: Six Categories, Real Examples, and a Template

STRIDE threat modeling explained: what each of the six categories means, eighteen concrete example threats, how to run STRIDE against a data flow diagram, and a template.

Threat ModelingEngineering
Read →
July 15, 2026·10 min read

The Security Architecture Tool Landscape in 2026

Eight tools for threat modeling and security design review, compared honestly by a vendor that competes with most of them: who each one is actually for, what changed after the ThreatModeler-IriusRisk deal, and how AI reshuffled the category.

Threat ModelingSecurity ArchitectureEngineering
Read →
July 10, 2026·9 min read

CISA Secure by Design Pledge: Seven Goals, Operationalized

What each of the CISA Secure by Design pledge's seven goals asks of an engineering organization, which practice owns it, and how to tell commitment from a logo.

Secure by DesignSecurity ArchitectureEngineering
Read →
July 7, 2026·10 min read

STRIDE vs PASTA vs LINDDUN: Which Threat Modeling Method to Use

STRIDE, PASTA, and LINDDUN answer different questions. A side-by-side comparison of what each finds, what it costs to run, and how to choose for your team.

Threat ModelingEngineering
Read →
July 2, 2026·7 min read

From Whiteboard Photo to Threat Model in an Afternoon

A walkthrough of one representative afternoon: a whiteboard photo becomes an editable architecture diagram, a written design explanation, a STRIDE threat model with mapped controls, and a signed design record before the end of the day.

AIThreat ModelingSecurity Architecture
Read →
June 29, 2026·9 min read

Threat Modeling Without Workshops

The workshop is the scaling bottleneck of threat modeling, not the analysis. How an async-first process covers more systems with less calendar: structured intake, diagrams from what exists, proposed threats, and one short conversation where judgment actually matters.

Threat ModelingAIEngineering
Read →
June 23, 2026·8 min read

Architecture Decision Records for Security Teams

Why security decisions decay faster than the systems they govern, and how a six-heading ADR turns risk acceptances, exceptions, and design calls into precedent instead of folklore.

Security ArchitectureDesign ReviewEngineering
Read →
June 16, 2026·6 min read

The Security Architecture Review Checklist (One You Will Actually Use)

A 45-item security architecture review checklist across seven sections, from scope to named sign-offs, with the reasoning behind each section and a free printable version.

Security ArchitectureDesign ReviewEngineering
Read →
June 9, 2026·9 min read

What Is a Security Design Review? Process, Roles, and What Good Looks Like

A practical guide to security design reviews: the six-step process, who needs to be in the room, what a finished review actually contains, and the anti-patterns that turn reviews into theater.

Design ReviewSecurity ArchitectureEngineering
Read →
June 1, 2026·11 min read

Your AI Agents Will Inherit Every Gap You Haven't Closed

Most agent security guidance assumes a foundation you may never have finished building. This is the tier nobody wrote down.

AIZero Trustidentity
Read →
May 26, 2026·6 min read

Vulnerability Management in the AI Era: The Bar Has Moved

AI now finds vulnerabilities faster than teams can verify, disclose, and patch them, and attackers hold the same tools. The monthly patch cycle has quietly stopped being enough. Here is what belongs on a 2026 vulnerability management roadmap.

vulnerability managementAIDevSecOps
Read →
February 20, 2026·7 min read

Building a Security Program from Zero: A Practitioner's Playbook

Most guides tell you what a security program should look like. This one tells you how to actually build one - from your first risk register to your first audit - without a dedicated security team.

security programstartupsstrategy
Read →
February 10, 2026·8 min read

Risk Management Beyond the Heat Map: Why Most Risk Registers Fail

The 5x5 risk matrix is the most widely used tool in security risk management. It is also one of the least effective. Here is how to build a risk practice that actually drives decisions.

risk managementframeworksstrategy
Read →
January 28, 2026·8 min read

SOC 2 Without the Fire Drill: A Calm Guide to Your First Audit

Your first SOC 2 audit does not have to be a three-month panic. Here is a structured, low-drama approach to getting your Type II report - from scoping to the final deliverable.

SOC 2complianceaudits
Read →
January 15, 2026·7 min read

Security Culture in Engineering Organisations: Beyond the Annual Training

Security culture is not built through compliance training modules. It is built through systems, incentives, and the small decisions that happen every day in engineering teams.

cultureengineeringsecurity
Read →
January 2, 2026·8 min read

Vendor Risk Management That Actually Works

Most vendor risk programs are a spreadsheet of questionnaires that nobody reads after they're collected. Here is how to build a program that genuinely reduces third-party risk.

vendor riskthird-party riskcompliance
Read →
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Security Architecture
  • Assets
  • Components
  • Dependency Mapping
  • Data Governance
  • Secure by Design
  • Security Design Review
  • Threat Modeling
  • Risk
  • Compliance
  • Policy
  • Program
  • Business Continuity
  • TPRM

Solutions

  • Startups
  • Mid-Market
  • Enterprise

Company

  • About
  • Advisory
  • Compliance
  • Blog
  • Security
  • Pricing
  • Compare

Legal

  • Privacy
  • Cookie Policy
  • Terms
  • Disclosure

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

LinkedIn