ZTNA vs VPN: why retire traditional remote access
VPN gives the user too much network. ZTNA grants only the specific application, verifying identity and device posture on every session.
Coming soonInsights
Notes and articles on technology that decides. Pillar content on Zero Trust, cloud migration (the 7 Rs) and AI architectures built on MCP.
Zero Trust Network
Replacing the traditional perimeter with continuous verification, segmentation and granular control.
VPN gives the user too much network. ZTNA grants only the specific application, verifying identity and device posture on every session.
Coming soonHow to apply data loss prevention policies across email, SaaS and endpoints without turning security into a bottleneck.
Coming soonDynamic categorisation, per-user and per-SaaS-tenant control, and exceptions driven by business process — not static lists.
Coming soonRemote browser isolation and visibility over unsanctioned SaaS to reduce shadow IT without blocking the user.
Coming soonReal-time inspection of prompts and files sent to ChatGPT, Copilot, Gemini and Claude. Block or redact sensitive data (PII, source code, contracts) before it leaves, with per-user and per-app audit trail.
Coming soonCloud migration — The 7 Rs
The framework AWS and Azure use to decide what to do with every application during a migration.
Rehost, Replatform, Repurchase, Refactor, Relocate, Retain and Retire. How to pick the right strategy per application — not by trend.
Coming soonWhen to move as-is and when to invest in small changes (managed databases, containers) to gain cost and operational efficiency.
Coming soonRewriting to microservices or serverless makes sense in few cases. Repurchasing as SaaS often delivers more value with less risk.
Coming soonA successful migration is also a cleanup. Criteria for retiring applications and for keeping workloads that shouldn't move yet.
Coming soonAI and MCP architectures
How modern agents connect to internal data and tools in a controlled, auditable way.
An open protocol that lets LLMs consume internal tools, data and actions through a common contract — not bespoke integrations.
Coming soonMCP servers per domain (HR, finance, tickets), role-based permissions and traceability for every call the agent executes.
Coming soonCombine embeddings-based retrieval with MCP tools to answer with your own context — without exposing the entire data lake.
Coming soonSpecialist agents delegating to each other, an orchestrator that decides the handoff, and a shared MCP layer as the tool surface.
Coming soon