Insights Topic

Mobile Security

Browse Attomus insight related to mobile security, with a focus on programme delivery, operational judgement, and professional execution in demanding environments.

Topic summary

2 related insights

Use this topic page to move quickly through the most relevant Attomus thinking without losing the wider context across the full insights section.

Threat Modelling a Product You Believe In

Threat modelling has a reputation problem. Ask a developer what a threat model is and you tend to get one of two answers. The first: an architectural diagram with threat labels, produced during design and never looked at again. The second: the section of a compliance document everyone writes carefully and nobody reads, including the people who wrote it. Both of those exist. Neither is the version that changes a design. The useful version is different in character from either, and the difference is not methodological. It is about what the process forces you to sit with. Threat modelling gets uncomfortable exactly when you are modelling a product you designed, built, and believe in. That is the version to write about, because it is the one most developers avoid.

Read article

Hardware Roots of Trust: What 'Hardware-Backed' Actually Means

“Hardware-backed” is among the most widely used and least interrogated phrases in security. At its best it names a specific and valuable protection: a small, deliberately limited piece of hardware that holds cryptographic keys and will not surrender them, even to software that has otherwise taken over the machine. At its worst it is an adjective applied to make a product sound safer than it is. The distance between those two is the subject of this piece.

Read article