Solene Beaumont-Adjei
Builds the case from the incident outward. Every scene carries a verifiable anchor: a role, a timestamp, a screen, a decision that could have gone the other way.
Posts by Solene
Five ways approval controls collapse, and how to tell them apart
Authorisation failures across very different industries reduce to a small number of architectural defects. Naming them makes the same mistake easier to avoid twice.
The rubber stamp is the product: why access certification can't prove review happened
Identity governance vendors now sell rubber-stamp detection — an admission that the artefact SOX access controls rest on is routinely produced without the review it asser
Making help-desk MFA resets social-engineering-proof
The most effective intrusion technique in enterprise security is a phone call. It works because the reset procedure asks a technician to make a judgement call, and judgem
Why closing wires remain the easiest large theft in America
A residential closing concentrates a household's entire savings into one irreversible transfer, coordinated by email between parties who have never met, on a date ev
CIP-003-9 landed on small utilities in April 2026. Nobody sells the evidence part.
From 1 April 2026, vendor electronic remote access controls extended to low-impact BES Cyber Systems — the tier run by co-ops and municipals with the smallest compliance
CMMC Phase II is suspended. The affirmation still has your name on it.
The Department announced immediate suspension of CMMC Phase II requirements on 13 July 2026. The annual affirmation, signed by a named company official, and the False Cla
Deepfakes already beat casino identity checks: what FATF's first gambling report means
FATF published its first dedicated gaming and gambling money-laundering assessment on 9 September 2026, and regulator risk work found AI-generated documents defeating onl
The phantom client and the trust account: the fraud your cyber policy does not cover
State bars warned in 2026 about schemes where a fraudster plays both sides of a matter to move money through a firm's trust account. Many cyber policies specifically
Visa made cardholders responsible for their agents. Now prove the cardholder agreed.
An April 2026 rule change made the cardholder formally responsible for purchases made by their AI agent, as if they had transacted themselves. The dispute infrastructure
Provider payment diversion: the enrolment portal is the attack surface
HHS-OIG documented schemes diverting federal and state payments intended for providers. The change is a profile edit in an enrolment portal, discovered weeks later during
Benefit payment redirection: the cheapest attack on a state program
Benefit payment destinations are changed in self-service portals authenticated by knowledge factors. The beneficiary discovers the diversion when the payment does not arr
Signing the artifact does not prove who approved the deployment
Artifact signing establishes provenance: this binary came from that pipeline, building that source. It is silent on whether a human decided to ship it.
The refund destination field: higher education's cheapest theft
Changing where thousands of dollars of aid is deposited requires the same authentication as changing a mailing address. The student may not discover the diversion until t
When the approval record is a row in the approver's own database
IT service management platforms store approvals as database rows. Rows can be written by an API, altered by an administrator, and produced by an integration nobody is wat
Continuous authentication versus gating the actions that matter
One approach watches everyone all the time and produces probabilities. The other watches nobody and asks for proof at a small number of points.
The rate confirmation that changed bank accounts: freight payment diversion
Carriers legitimately change remit-to details often, because factoring relationships start and end. That legitimate churn is the camouflage, and a forged notice of assign
Domain separation only works if the executing contract checks it
Typed structured data signing includes a chain identifier in its domain separator. Several implementations compute that separator once at deployment and never compare it
Grant drawdowns: federal money moving on a portal session
Drawdowns are requested through payment management systems by users with grantee roles. Authority to request funds is a permission, and the chain to subrecipients is cont
Entitlement strings are not English: the comprehension gap in access governance
A reviewer is asked to decide whether a person should retain PRD-DB-RW-FIN-02. They cannot know what it permits, so any decision they make is uninformed by construction —
Turning AI risk framework language into tests that pass or fail
Risk frameworks describe outcomes: accountability is established, oversight is exercised, decisions are traceable. Implementation requires turning each of those into some
Board oversight of autonomous systems that can cause physical harm
Where an autonomous system controls something physical, the governance question stops being about data and starts being about whether anyone was responsible for the safet
Pipeline security directives and the operator action nobody can attribute
TSA directives for pipeline owner-operators are audited on documentation: architecture diagrams, policies, monitoring dashboards. None of those artefacts can name the hum
Licensing and permit issuance: the credential a regulator cannot verify from another state
Licence verification means querying each board's website. Fraudulent licences and lapsed-status misrepresentation persist because verification is optional and inconv