Threat Modelling Under APRA CPS 234: Evidence for the Design-Time Obligations
How threat modelling gives APRA-regulated entities defensible evidence for CPS 234's design-time control obligations, and a process that fits alongside CPS 230.
Blog
Perspectives on security, compliance, and building resilient organisations from the Alvor team.
Latest Articles
How threat modelling gives APRA-regulated entities defensible evidence for CPS 234's design-time control obligations, and a process that fits alongside CPS 230.
How to threat model AI systems: STRIDE extended for LLM applications, the OWASP LLM Top 10 mapped to design-time decisions, and a worked RAG example.
A step-by-step threat modeling guide: scope the system, draw the data flow diagram, mark trust boundaries, enumerate threats with STRIDE, map controls, and decide.
STRIDE threat modeling explained: what each of the six categories means, eighteen concrete example threats, how to run STRIDE against a data flow diagram, and a template.
Eight tools for threat modeling and security design review, compared honestly by a vendor that competes with most of them: who each one is actually for, what changed after the ThreatModeler-IriusRisk deal, and how AI reshuffled the category.
What each of the CISA Secure by Design pledge's seven goals asks of an engineering organization, which practice owns it, and how to tell commitment from a logo.
STRIDE, PASTA, and LINDDUN answer different questions. A side-by-side comparison of what each finds, what it costs to run, and how to choose for your team.
A walkthrough of one representative afternoon: a whiteboard photo becomes an editable architecture diagram, a written design explanation, a STRIDE threat model with mapped controls, and a signed design record before the end of the day.
The workshop is the scaling bottleneck of threat modeling, not the analysis. How an async-first process covers more systems with less calendar: structured intake, diagrams from what exists, proposed threats, and one short conversation where judgment actually matters.
Why security decisions decay faster than the systems they govern, and how a six-heading ADR turns risk acceptances, exceptions, and design calls into precedent instead of folklore.
A 45-item security architecture review checklist across seven sections, from scope to named sign-offs, with the reasoning behind each section and a free printable version.
A practical guide to security design reviews: the six-step process, who needs to be in the room, what a finished review actually contains, and the anti-patterns that turn reviews into theater.

Most agent security guidance assumes a foundation you may never have finished building. This is the tier nobody wrote down.
AI now finds vulnerabilities faster than teams can verify, disclose, and patch them, and attackers hold the same tools. The monthly patch cycle has quietly stopped being enough. Here is what belongs on a 2026 vulnerability management roadmap.
Most guides tell you what a security program should look like. This one tells you how to actually build one - from your first risk register to your first audit - without a dedicated security team.
The 5x5 risk matrix is the most widely used tool in security risk management. It is also one of the least effective. Here is how to build a risk practice that actually drives decisions.
Your first SOC 2 audit does not have to be a three-month panic. Here is a structured, low-drama approach to getting your Type II report - from scoping to the final deliverable.
Security culture is not built through compliance training modules. It is built through systems, incentives, and the small decisions that happen every day in engineering teams.
Most vendor risk programs are a spreadsheet of questionnaires that nobody reads after they're collected. Here is how to build a program that genuinely reduces third-party risk.