ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Blog

Insights & ideas

Perspectives on security, compliance, and building resilient organisations from the Alvor team.

Latest Articles

September 1, 2026·14 min read

The GPU Cluster Nobody Owns: Securing Enterprise AI Infrastructure

AI teams inside ordinary companies now run HPC-class machines holding models and training data. Why the enterprise security stack misses them, and how the NIST SP 800-223 zone architecture applies.

AISecurity ArchitectureHPC
Read →
September 1, 2026·12 min read

What Is a System Security Plan? The SSP, Explained Properly

What a System Security Plan is, what goes in one, who requires it (NIST 800-171 and CMMC, FedRAMP, FISMA, Australia's ISM and IRAP), how to write one, and why most SSPs are out of date the day they are signed.

Compliance
Read →
August 28, 2026·15 min read

CUI on a Shared HPC Cluster: Meeting NIST 800-171 Without Fencing the Whole Machine

How research computing centres meet NIST SP 800-171 and CMMC obligations for controlled unclassified information on shared clusters: the enclave pattern, scoping, and the SP 800-223 zones it builds on.

ComplianceHPC
Read →
August 25, 2026·15 min read

Why Your Enterprise Security Controls Break on an HPC Cluster (and What Replaces Them)

Ten enterprise controls, from EDR to change control, and what happens to each on a supercomputer: why it breaks, and the HPC-native control that replaces it, mapped to NIST SP 800-223 and SP 800-234.

Security ArchitectureHPC
Read →
August 12, 2026·12 min read

Threat Modelling Under APRA CPS 234: Evidence for the Design-Time Obligations

How threat modelling gives APRA-regulated entities defensible evidence for CPS 234's design-time control obligations, and a process that fits alongside CPS 230.

Threat ModelingSecurity Architecture
Read →
August 5, 2026·16 min read

Threat Modeling AI Systems: A Practical Guide for LLM and Agentic Applications

How to threat model AI systems: STRIDE extended for LLM applications, the OWASP LLM Top 10 mapped to design-time decisions, and a worked RAG example.

AIThreat ModelingSecurity Architecture
Read →
July 29, 2026·14 min read

How to Do Threat Modeling: A Step-by-Step Guide for Your First Real System

A step-by-step threat modeling guide: scope the system, draw the data flow diagram, mark trust boundaries, enumerate threats with STRIDE, map controls, and decide.

Threat ModelingEngineering
Read →
July 22, 2026·13 min read

STRIDE Threat Modeling Explained: Six Categories, Real Examples, and a Template

STRIDE threat modeling explained: what each of the six categories means, eighteen concrete example threats, how to run STRIDE against a data flow diagram, and a template.

Threat ModelingEngineering
Read →
July 15, 2026·10 min read

The Security Architecture Tool Landscape in 2026

Eight tools for threat modeling and security design review, compared honestly by a vendor that competes with most of them: who each one is actually for, what changed after the ThreatModeler-IriusRisk deal, and how AI reshuffled the category.

Threat ModelingSecurity ArchitectureEngineering
Read →
July 10, 2026·9 min read

CISA Secure by Design Pledge: Seven Goals, Operationalized

What each of the CISA Secure by Design pledge's seven goals asks of an engineering organization, which practice owns it, and how to tell commitment from a logo.

Secure by DesignSecurity ArchitectureEngineering
Read →
July 7, 2026·10 min read

STRIDE vs PASTA vs LINDDUN: Which Threat Modeling Method to Use

STRIDE, PASTA, and LINDDUN answer different questions. A side-by-side comparison of what each finds, what it costs to run, and how to choose for your team.

Threat ModelingEngineering
Read →
July 2, 2026·7 min read

From Whiteboard Photo to Threat Model in an Afternoon

A walkthrough of one representative afternoon: a whiteboard photo becomes an editable architecture diagram, a written design explanation, a STRIDE threat model with mapped controls, and a signed design record before the end of the day.

AIThreat ModelingSecurity Architecture
Read →
June 29, 2026·9 min read

Threat Modeling Without Workshops

The workshop is the scaling bottleneck of threat modeling, not the analysis. How an async-first process covers more systems with less calendar: structured intake, diagrams from what exists, proposed threats, and one short conversation where judgment actually matters.

Threat ModelingAIEngineering
Read →
June 23, 2026·8 min read

Architecture Decision Records for Security Teams

Why security decisions decay faster than the systems they govern, and how a six-heading ADR turns risk acceptances, exceptions, and design calls into precedent instead of folklore.

Security ArchitectureDesign ReviewEngineering
Read →
June 16, 2026·7 min read

The Security Architecture Review Checklist (One You Will Actually Use)

A 45-item security architecture review checklist across seven sections, from scope to named sign-offs, with the reasoning behind each section and a free printable version.

Security ArchitectureDesign ReviewEngineering
Read →
June 9, 2026·9 min read

What Is a Security Design Review? Process, Roles, and What Good Looks Like

A practical guide to security design reviews: the six-step process, who needs to be in the room, what a finished review actually contains, and the anti-patterns that turn reviews into theater.

Design ReviewSecurity ArchitectureEngineering
Read →
June 1, 2026·11 min read

Your AI Agents Will Inherit Every Gap You Haven't Closed

Most agent security guidance assumes a foundation you may never have finished building. This is the tier nobody wrote down.

AIZero Trustidentity
Read →
May 26, 2026·6 min read

Vulnerability Management in the AI Era: The Bar Has Moved

AI now finds vulnerabilities faster than teams can verify, disclose, and patch them, and attackers hold the same tools. The monthly patch cycle has quietly stopped being enough. Here is what belongs on a 2026 vulnerability management roadmap.

vulnerability managementAIDevSecOps
Read →
February 20, 2026·7 min read

Building a Security Program from Zero: A Practitioner's Playbook

Most guides tell you what a security program should look like. This one tells you how to actually build one - from your first risk register to your first audit - without a dedicated security team.

security programstartupsstrategy
Read →
February 10, 2026·8 min read

Risk Management Beyond the Heat Map: Why Most Risk Registers Fail

The 5x5 risk matrix is the most widely used tool in security risk management. It is also one of the least effective. Here is how to build a risk practice that actually drives decisions.

risk managementframeworksstrategy
Read →
January 28, 2026·10 min read

SOC 2 Without the Fire Drill: A Calm Guide to Your First Audit

Your first SOC 2 audit does not have to be a three-month panic. A structured, low-drama route to a Type II report: scoping, the control framework, a realistic timeline, evidence, exceptions, and what changes after the report.

SOC 2complianceaudits
Read →
January 15, 2026·8 min read

Security Culture in Engineering Organisations: Beyond the Annual Training

Security culture is not built through compliance training modules. It is built through systems, incentives, design reviews, and the small decisions that happen every day in engineering teams. Five mechanisms that work, and how to measure them.

cultureengineeringsecurity
Read →
January 2, 2026·9 min read

Third-Party Risk Management That Actually Works

Most third-party risk programs are a spreadsheet of questionnaires nobody reads after they are collected. How to build a tiered, continuously monitored program that genuinely reduces vendor risk, and what CPS 230 and DORA now expect of it.

vendor riskthird-party riskcompliance
Read →
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Secure by Design
  • Asset Management
  • Risk Management
  • Compliance
  • Policy
  • Security Management
  • Third-Party Risk Management
  • Business Continuity

Capabilities

  • Security Architecture
  • Security Design Review
  • Threat Modeling
  • Dependency Mapping
  • Data Governance
  • Components & SBOM
  • System Security Plan
  • Deployment models

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign
  • Australia

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • ISM
  • IRAP
  • Essential Eight
  • ASD Essentials
  • SABSA
  • PCI DSS
  • CMMC
  • FedRAMP
  • Control alignment

Advisory

  • Advisory overview
  • Assess
  • Architect
  • Build
  • Operate
  • All engagements

Company

  • About
  • Blog
  • Learn
  • Security
  • Pricing
  • Compare Alvor

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

PrivacyTermsCookie PolicyVulnerability Disclosure