Security audits are diagnostic, not therapeutic. By the time a finding lands in a report, the design decision that created it is usually months old and expensive to undo. The cheapest security work happens at the whiteboard.
Threat-model in the same room as the architecture
Make the security baseline visible alongside the system diagram: identity model, data classifications, default deny, audit boundaries, secret lifecycle. If a reviewer cannot find them in five minutes, they do not exist.
The four questions
- Who is the caller, and how do we know?
- What data crosses this boundary, and how is it classified?
- What is the blast radius if this component is fully compromised?
- How would we know — within minutes, not days?
“Most enterprise breaches I have read post-mortems for trace back to a forgotten trust assumption, not a novel exploit.”
Bake the answers into ADRs. Re-ask them every time the architecture changes. Security is not a phase; it is a property the team maintains on purpose.
Md Arifur Rahman is a Senior Software Engineer, Systems Architect, and Cyber Security professional with 8+ years building production-grade platforms across fintech, government, and enterprise SaaS.
