Articles

Identity-to-data security thinking.

Notes on Identity Progression Attacks, lateral movement, and why cloud security needs to model movement toward sensitive data.

Unknown vulnerabilities make early progression detection essential

Why faster discovery of previously unknown flaws makes it vital to detect the movement from initial access toward sensitive data.

Insider threats: when legitimate access becomes a path to sensitive data

Why insider risk is not only about intent, but about what trusted identities can reach and how their access changes over time.

What is our identity-to-data breach exposure right now?

Why security leaders need a defensible point-in-time view of the paths from compromised identities to sensitive data.

How data breaches happen in cloud environments

A plain-English guide to how attackers move from initial access to sensitive data in cloud environments.

Machine-speed attacks need path-speed detection

Why cloud and AI-driven identity progression require detection that evaluates paths to sensitive data continuously.

Assume credentials will leak. Detect movement toward data

Why the CISA credential exposure is a reminder to monitor valid identity activity as it moves toward sensitive data.

What APRA's AI letter means for Australian security leaders

Why APRA's AI letter makes AI security an operational-resilience question for regulated Australian organisations.

What the Canvas breach says about SaaS blast radius

Why SaaS breach response needs to answer what an attacker could reach before the final scope is confirmed.

The real breach starts before attackers exfiltrate data

Why security teams need to detect attacker progression before confirmed data loss.

What are Identity Progression Attacks?

A practical definition of Identity Progression Attacks and why defenders need to detect movement from foothold to high-value target.

Supply chain attacks are a credential theft problem

Why software supply chain compromises often become fast-moving identity-to-data attacks once credentials are stolen.

Why we're building vec0

Why vec0 models attacker progression through identities, permissions, and systems as paths toward sensitive data.