curiousecurity

Enterprise architecture and security governance, from the board seat

  • Posts
  • About
  • Career
  • Education
  • Contact
  • LinkedIn
  • GitHub
  • Email

Architecture Governance Only Works When the Loop Closes

August 12, 2026 by The Architecture Desk

Governance programs don't usually fail from missing policy. Most boards I've sat on already have a principles document, a review process, an exception form, some kind of vendor questionnaire. What they don't have is a loop that closes, where each piece actually feeds the next one instead of sitting in its own binder. A decision gets made without an ADR. An exception gets approved without an expiration date anyone tracks. A vendor clears procurement before architecture ever sees the data flow. … [Read more...]

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture

AI Agent Sprawl Is SaaS Sprawl With Better PR

August 11, 2026 by The Architecture Desk

3D rendered ai text on dark digital background

Three million AI agents are now running inside corporate environments, according to Gravitee's State of AI Agent Security 2026 report, and the mean monitoring coverage across those estates sits at 52%. That's not a rounding error. That's an entire shadow estate of autonomous software making decisions, calling APIs, and touching data with almost no one watching. Put that next to Gartner's forecast that 40% of enterprise applications will ship with task-specific AI agents embedded by the end of … [Read more...]

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture

An Architecture Exception Without an Expiration Date Isn’t an Exception

August 9, 2026 by The Architecture Desk

text

A credential issued in 2022 for a limited pilot integration at Klue sat active for roughly four years after the pilot itself was quietly abandoned. Nobody owned it. Nobody reviewed it. Nobody put a date on the calendar for it to stop working, and that last part is the whole story. When the extortion group Icarus went looking for a way in, that single dormant token turned into the entry point for the Salesforce environments of close to 200 companies, according to TechCrunch's reporting on the … [Read more...]

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture

What Belongs in an ADR (and What Doesn’t)

August 9, 2026 by The Architecture Desk

What Belongs in an ADR (and What Doesn't)

Somebody on your team probably wrote an ADR last month titled something like "Adopt Prettier for the billing service," or "Standardize on camelCase for internal package names." Go read it back in six months and ask what it's actually protecting. Nothing. It's not wrong, exactly, it's just not architecture, and it's sitting in the same collection as the decision about who owns the customer identity record, as if the two carry the same weight. That's how ADR programs actually fail, and it took me … [Read more...]

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture

The Architecture Board Loves Approving New Systems. It Almost Never Retires the Old Ones.

August 7, 2026 by The Architecture Desk

white metal cabinets

Ask anyone on your architecture board to name the last system the board actually voted to retire, not deprecate in a slide, not flagged "legacy" in a spreadsheet somewhere, but formally decommissioned. Watch them pause. They'll rattle off every platform evaluation and integration exception from the last year without breaking a sweat, but retirement almost never shows up as its own agenda item. It shows up as a footnote buried in someone else's proposal, if it shows up at all. That's not because … [Read more...]

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture

Architecture Principles Don’t Score an RFP. Implications Do.

August 5, 2026 by The Architecture Desk

low angle photography of architecture building

Ten principles on a slide, a paragraph of rationale under each, reviewed by the board twice a year and opened by nobody else in between. That's how most architecture principles documents live out their existence. Then a $2M platform RFP goes out the door, gets scored on cost, feature checklist, and vendor references, and the principles document never enters the room. Nobody decided it didn't matter, and that's kind of the point, nobody did the work required to make it matter to an evaluator … [Read more...]

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture

Architecture Decision Records Are a Governance Control, Not a Documentation Habit

August 3, 2026 by The Architecture Desk

a black and white photo of a bridge over water

Someone challenges your team right now to produce the reasoning behind last quarter's biggest architecture call, not the decision itself, the actual reasoning, and I want you to be honest with yourself about how long that would take. For most EA boards, the honest answer is "we'd have to ask around and hope the right person still works here." That gap is where a familiar meeting keeps happening: someone proposes a change, a senior architect objects that "we already decided against this," and … [Read more...]

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture

Why I Standardized on LeanIX as the EAM System of Record

August 3, 2026 by The Architecture Desk

Why I Standardized on LeanIX as the EAM System of Record

A director on our ARB asked a simple question last quarter: how many identity providers are we running in production, right now, today. Three architects in the room gave three different numbers, and none of them matched the CMDB export somebody pulled up on the spot to settle it. The meeting stalled for ten minutes while people argued over whose spreadsheet was current (mine wasn't, for what it's worth). That's not a staffing problem, and it's not a communication problem either. That's what … [Read more...]

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture

The Architecture Review Board: Narrow Docket, Small Room, Hard Exceptions

July 31, 2026 by The Architecture Desk

A blueprint of a building with a bunch of windows

A board that reviews everything ends up governing nothing. I've sat through review meetings that burned a full hour on one team's API contract, argued clause by clause, while the actual risk in the portfolio sat three agenda items down, untouched, ticking. The fix isn't more rigor in the room. It's a shorter, sharper definition of what the room is actually for. I hold one of these seats myself, and I take the calendar invite seriously enough that it changes how I spend the rest of my week. The … [Read more...]

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture

Reuse, Buy, Build: The Order Most Companies Get Backwards

July 30, 2026 by The Architecture Desk

a person holding a black book with the word buy written on it

Thirty-five percent of enterprises have already replaced at least one SaaS tool with something built in-house, and sixty percent of those builds happened as shadow IT, outside procurement and outside architecture review, according to Retool's 2026 Build vs. Buy Report. That second number is the one that should keep an EA board up at night, not the first. A tool getting replaced is just the market doing its job. A tool getting replaced by something nobody on the architecture side ever laid eyes … [Read more...]

Filed Under: Architecture Tagged With: cybersecurity, enterprise-architecture

  • 1
  • 2
  • 3
  • …
  • 5
  • Next Page »