Design Review Sprint
STRIDE threat model, MITRE ATT&CK risk register, RiskScore findings and a mitigation roadmap for one system.
Obsidian Cloud threat-models, design-reviews and governs enterprise and AI systems for regulated organisations. The output is work your team can act on the same week.
Innovation without governance is an unquantified liability.
years across financial services, health, industrial, banking, consultancy and critical national infrastructure
Obsidian Cloud established as an independent security consultancy
fixed-scope engagements, from a one-system review to a retained seat on your governance forum
One sharp deliverable each. Most clients start with the Design Review Sprint. Engagements are sold under The Architecture Brief Advisory and invoiced through Obsidian Cloud.
STRIDE threat model, MITRE ATT&CK risk register, RiskScore findings and a mitigation roadmap for one system.
CIS Controls v8.1, SOC 2 or ISO 27001 control mapping against your actual estate, a prioritised remediation plan and an audit-readiness scorecard.
Fixed-scope review of one agentic or AI use case: MITRE ATLAS and STRIDE analysis, trust-boundary decomposition, risk register, prioritised mitigations and governance guardrails.
A standing seat on your AI and agentic governance forum: design review gate, quarterly risk register refresh and on-call architecture sign-off.
Obsidian Cloud delivers the consultancy work and runs The Architecture Brief, the security-architecture publication that builds the audience and the authority behind it.
Commercial work is contracted under the Obsidian Cloud name. The publication stays editorially independent.
A weekly security-architecture publication read by CFOs, CIOs and CISOs at regulated fintechs and enterprises. Each issue breaks down a real breach before the post-mortems are sanitised, and pairs it with the control or framework that would have closed it.
Twenty years of hands-on security architecture across financial services, health, industrial, banking, consultancy and critical national infrastructure. Specialisms: data, platform, network, infrastructure and application security, identity and access management, Zero Trust, and agentic AI security.
Name the breach, the AI use case or the control gap. We will reply with a scoped proposal. No form, no tracking: just email.