Glossary

Every framework on this list showed up first inside a real breach, not a textbook. Each entry gives you the plain-language definition, then points to the specific incident that proves why it matters. If a term isn’t here yet, it hasn’t earned a place in the newsletter, that’s the bar for inclusion, not an oversight.

AI & Agentic Security Frameworks

MAESTRO
The Cloud Security Alliance’s threat-modeling framework for multi-agent AI systems, built for goal misalignment, not exploits. Read the full entry →

MITRE ATLAS
The AI-specific counterpart to MITRE ATT&CK, covering adversary techniques against machine learning systems, prompt injection, jailbreaking, model extraction. Read the full entry →

OWASP LLM07:2023-24 (Insecure Plugin Design)
The risk of an AI agent trusting a tool or plugin that has changed since it was first authorised. Edition matters, LLM07 means something different in 2025. Read the full entry →

NIST AI RMF (Agentic Profile)
NIST’s voluntary AI risk framework, extended to cover AI systems that take autonomous action, not just generate output. Read the full entry →

EU AI Act Article 14 (Human Oversight)
The legal requirement that high-risk AI systems be built so a human can actually intervene and stop them, not just watch them. Read the full entry →

Core Security Architecture

Non-Human Identity (NHI)
Any credential, API key, or service account that authenticates without a human behind it, the least governed access category in most enterprises. Read the full entry →

Zero Trust Architecture
An architectural principle, not a product: nothing is trusted by default, every access request is verified explicitly. Read the full entry →

CIS Controls v8.1
18 prioritised, vendor-neutral security safeguards, scaled to organisational maturity through three Implementation Groups. Read the full entry →

MITRE ATT&CK
The public knowledge base mapping real adversary behaviour to specific, named technique IDs, the standard defenders use to name what actually happened. Read the full entry →

SABSA
A risk-driven framework for designing security architecture from business requirements downward, not from a checklist upward. Read the full entry →

New terms are added as new episodes and breach analyses publish. Subscribe on Substack to get each one as it’s covered.