Author
Joe Donovan
About
Principal Security Consultant at PlatformSecurity specializing in platform, cloud, and API security. Mobile and IoT security assessor and a prolific bug bounty hunter.
Articles by Joe Donovan
9 results
- Platform Security
Platform Security vs AppSec vs Cloud Security: Who Owns What?
Confused about platform security vs AppSec and product security vs platform security? This guide explains ownership boundaries, responsibility matrices, and operating models for IAM, CI/CD, Kubernetes, secrets, and vulnerability management.
04/20/202610 min read - Platform Security
The Platform Security Team Charter (Copy/Paste Template)
Need a practical security team charter template? Use this platform security charter to define mission, scope, SLAs, intake, engagement model, metrics, and a realistic quarterly roadmap.
04/13/20266 min read - Platform Security
Platform Security’s First 90 Days: What to Ship (Not Just Assess)
Your first 90 days as a security engineer should ship controls that scale, not endless assessments. Here’s how to build a security program early with SSO/MFA, secrets, baseline logging, and CI guardrails, plus anti-patterns and how to avoid tool sprawl.
04/08/20269 min read - GRC
Vendor Security Questionnaires (SIG/CAIQ): How to Answer Without Lying or Writing a Novel
A direct playbook for GRC teams: answer customer security questionnaires fast without over-claiming, build an evidence pack once, and push back on low-signal questions without slowing deals.
04/06/20266 min read - Platform Security
Incident Response for Platform Teams: The “Platform Outage” Meets “Security Incident” Playbook
Need an incident response runbook template for platform teams? This detailed playbook covers security incident triage, severity, communications, evidence preservation, cloud and Kubernetes containment, and post-incident hardening.
04/01/20269 min read - GRC
HITRUST Security for AI Systems (ai2): Requirements, Threats, and Web App Testing
HITRUST’s Security for AI Systems add-on layers ai1 or ai2 onto your CSF assessment: up to dozens of tailored AI statements. Here’s what that means for deployed GenAI, what assessors look for, and how to test AI-enabled web apps beyond a normal pen test.
03/29/20269 min read - Platform Security
Guardrails, Not Gatekeepers: How Platform Security Scales with Engineering
Platform security scales when you ship security guardrails and paved roads—not approval queues. Here’s how a shift left security platform team uses self-service controls, policy-as-code, golden pipelines, and strong developer experience, plus what to automate first.
03/27/20268 min read - Platform Security
Cloud Security Checklist for CTOs
A practical cloud security checklist for technology leaders: what to fund first, how IAM, visibility, and blast-radius controls fit together, and how to avoid the usual multi-account and CI/CD traps—without pretending one afternoon of configuration fixes everything.
09/18/20247 min read - Platform Security
Cloud Security Trends and Challenges in 2026
Explore the emerging trends in cloud security for 2026. From AI driven attacks to the importance of specialized cloud security services in protecting complex environments.
02/12/20242 min read