<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Posts on Security Blueprints</title>
    <link>https://securityblueprints.io/categories/posts/</link>
    <description>Recent content in Posts on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/categories/posts/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The Agent Perimeter Fallacy</title>
      <link>https://securityblueprints.io/posts/agent-perimeter-fallacy/</link>
      <pubDate>Tue, 03 Mar 2026 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/posts/agent-perimeter-fallacy/</guid>
      <description>Security practitioners who treat security as an engineering problem start by asking what they can make structurally impossible. Mandatory hardware second factors, positive execution control, egress restrictions: these are invariants, machine-enforced constraints that eliminate attack surface without requiring ongoing human judgment. Detection layers come after, augmenting a foundation that does not depend on them.&#xA;Not everyone works this way. There is a recurring pattern, more common than it should be, of reaching for detection as a first-line preventative control rather than as a complement to structural prevention.</description>
    </item>
    <item>
      <title>Three Security Invariants Could Prevent 65% of Breaches: Analyzing 70 Incidents and Building CISO Challenge</title>
      <link>https://securityblueprints.io/posts/three-security-invariants-ciso-challenge/</link>
      <pubDate>Thu, 09 Oct 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/posts/three-security-invariants-ciso-challenge/</guid>
      <description>Project update — August 2026: The game now has a dedicated development site. Visit game.securityblueprints.io for the current direction and private playtest updates.&#xA;I&amp;rsquo;ve spent 25 years in security, and watching the news cycle of breaches never gets less frustrating. Another company compromised. Another million records stolen. Another ransomware payment. What makes it worse is that most of these incidents didn&amp;rsquo;t have to happen.&#xA;While working at Google and Stripe, I helped develop security invariants which are technical controls that categorically eliminate entire attack surfaces.</description>
    </item>
    <item>
      <title>What are Security Invariants? Why do they matter?</title>
      <link>https://securityblueprints.io/posts/security-invariants/</link>
      <pubDate>Wed, 23 Oct 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/posts/security-invariants/</guid>
      <description>As shown by the numerous data breaches documented on Security Blueprints, many companies struggle to establish an effective security posture that prevents breaches or significantly reduces their impact.&#xA;Fortunately, there’s a powerful approach to substantially improve your security stance: Security Invariants . A security invariant is one of several types of constraints that once consistently enforced across a computing infrastructure, systematically reduces the attack surface without requiring the organization&amp;rsquo;s team members to make security decisions.</description>
    </item>
  </channel>
</rss>
