Back to the site Free resource · PDF · 124 slides

Security Architect:
the survival kit

Role, expectations and journey within the Digital Governance Framework (DGF): from the contract to the committee, from reading the file to the risk matrix.

Free, no sign-up. The link opens or saves the PDF directly.

First slide of the survival kit: Security Architect, role, expectations and journey within the DGF
Slide 1 of 124 · click to download
The finding

Why this kit?

Companies do not always understand where the security architect belongs: too early, too late, or outside the process. Summoned at the gate once the contract is already signed, they discover the requirements instead of confirming them. Called in without any criticality or RTO expressed by the business, they invent requirements, and get them wrong.

This kit gives concrete reference points to be in the right place at the right time, in particular within the Digital Governance Framework (DGF): the sequence of gates that governs every significant change to the information system, from buying a SaaS platform to integrating an acquired entity.

It is written from the field: more than ten years of AWS and Azure security architecture in large enterprises, across finance, banking, insurance, defense, pharma and retail, in France, Belgium, Switzerland and the Middle East.

30%

of companies have a real DGF in place, with a dedicated application to track a project's life cycle. For the others, the gates live in emails and spreadsheets.

Personal finding, based on the organizations I have worked with: not a formal study.
90%

of the people who review a file do not properly assess the identity and access part (IAM). We check SSO and MFA, and stop there.

Personal finding, based on the files I have reviewed or re-read.
A gate is prepared, not endured. Involving security from the business need costs one hour of scoping; discovering it at the gate costs weeks of renegotiation.
How to use

Three ways to read it, depending on your role

The document is designed to be skimmed in ten minutes or read end to end. Each profile has its own path.

Executive

10 minutes
  • Finding: a real DGF is still rare
  • DGF gates
  • Business as risk owner
  • Four statuses of a file
  • Ten pitfalls
  • Setting up a DGF in 90 days

Project manager

30 minutes
  • Three paths and checklist per gate
  • Access the contract from day one
  • Initial assessment form
  • Complete checklist
  • Matrix and risk card
  • Case studies

Security architect

Everything, in order
  • CIA+TN compass and its sub-criteria
  • Thirty-six technical categories
  • IAM, Azure and AWS: permissions
  • AI project security
  • Convincing and steering
  • Patterns, pitfalls, toolbox, glossary
Agenda

Twelve parts, from the role to the glossary

  1. 01
    Who am I, and why this kit?Background, certifications, industries and intent
  2. 02
    The security architect rolePositioning, six missions, expectations, deliverables, the 8 essentials
  3. 03
    The DGFGates, three paths, checklist per gate, and a DGF in 90 days
  4. 04
    Surviving the gatesThe Security & Architecture gate and the six right reflexes
  5. 05
    DGF maturity by country and by industryPersonal rankings, based on field experience
  6. 06
    Procurement, IT, Business & SecurityThe contract, the IT department's existing framework, the business as risk owner
  7. 07
    Reviewing a file: the readingCIA+TN compass, reading grid, sub-criteria, warning signs
  8. 08
    Technical assessmentDGF questionnaire, thirty-six categories, Azure and AWS, ISO and NIST
  9. 09
    Risk matrixAssess, decide, record: statuses, risk card, opinion, three case studies
  10. 10
    AI projectsAgent architecture, identities, risks, assessment
  11. 11
    Convincing and steeringCommunication, classic remarks, indicators
  12. 12
    Patterns, pitfalls, tools and glossaryEight patterns, ten pitfalls, eight templates, the vocabulary
Excerpts

What you will find inside

Seven ideas that structure the kit, illustrated by the matching slides. Click an image to enlarge it.

Slide: three DGF paths, one constant, the Security and Architecture gate
Part 3 · Three paths, one constant
The DGF

An unavoidable gate, whatever the path

New platform, merger and acquisition or new project: the trigger changes, the order of the gates changes, but the Security & Architecture gate is always there. For a vendor platform it even comes before IT: security qualifies the solution and the contract before the commitment.

  • What each gate checks, who holds it, and the opinion it gives: green, yellow or red light
  • The checklist of what you need before each gate
  • Six reflexes to survive the gates, and a plan to set up a DGF in 90 days
Slide: the CIA+TN compass, confidentiality, integrity, availability, traceability, non-repudiation
Part 7 · The CIA+TN compass
Reading a file

Five criteria, three questions per criterion

Confidentiality, integrity, availability, traceability, non-repudiation: everything is assessed through these five criteria. Every section of the architecture file, every question asked and every opinion given maps to one of them.

  • The anatomy of an architecture file in nine sections, with the criteria each one must address
  • For each criterion, "what we expect" and "what does not pass", drawn from real cases
  • Eight warning signs: flows "to be defined later", shared service accounts, exceptions without a due date…
Slide: IAM, the point that 90% assess badly, the seven points to assess
Part 8 · IAM, the seven points to assess
Identity and access

IAM: the point that 90% assess badly

"Who has access to what" hides in seven different places: Azure RBAC and Entra ID roles, managed identities, delegated permissions, Graph application permissions, AI agent identity, Conditional Access, break-glass account. The kit walks through each of them for Azure and for AWS, with the classic mistake of each.

  • The classic omission: the break-glass account, its rules, and the question to ask the file
  • Sixteen findings from a real 2026 Entra ID audit, anonymized and ranked by criticality
  • Hybrid AD and Entra directory, guests and external identities, administrator access
Slide: the complete checklist, thirty-six technical categories in six families
Part 8 · The complete checklist
Technical assessment

Thirty-six categories, each with real-life examples

Secrets, infrastructure as code, containers, penetration tests, licenses, network, PaaS, APIs, mobile, PKI, email, encryption, GDPR, backups, SOC, incident response, awareness, AI… One slide per category: what we expect, and what does not pass.

  • The initial assessment form in ten blocks, filled in at scoping with the requester
  • The Architecture block of the form: twelve questions, and the expected answer
  • The mapping to ISO 27001:2022 (Annex A) and NIST CSF 2.0
Slide: impact times probability risk matrix, applied to the SaaS CRM case study
Part 9 · Matrix applied to the case study
Decide and record

From finding to risk, from risk to opinion

A finding without a scenario is not a risk; a risk without an owner is not managed; a risk without an exit is not tracked. The kit runs through the full chain: impact × probability score from 1 to 16, thresholds, four statuses of a file, risk card, opinion template.

  • Three case studies reviewed end to end: a SaaS CRM, a merger and acquisition, an internal AI support agent
  • The complete risk card, always signed by the business
  • The opinion in five blocks: summary, one light per criterion, dated conditions, alternative, decision
Slide: an enterprise AI agent, more than a call to the model, the production platform
Part 10 · An enterprise AI agent
AI projects

An AI agent is more than a call to the model

AI gateway, orchestrator, agents, tools, data and models, and five cross-cutting controls around the chain. The reference architecture layer by layer, and what we check at each level.

  • Agent identities and Conditional Access: the trap of "All users" policies that do not include agents
  • The specific risks: prompt injection, leakage through memory or the RAG index, over-privileged tools, third-party MCP servers
  • Twelve questions to assess an AI file
Slide: the ten pitfalls of the security architect, and their antidote
Part 12 · The ten pitfalls
Patterns and pitfalls

Eight secure patterns, ten pitfalls and their antidote

Web exposure, SaaS integration, cloud landing zone, partner access, sensitive data, Zero Trust remote access, deployment pipeline, AI agent: eight ready-to-reuse architecture patterns, with their rules.

  • The ten pitfalls: arriving at the gate, the "no" without an alternative, the eternal exception, zero risk, the contract discovered after signature…
  • The classic remarks ("it's SaaS, the vendor handles security") and how to answer them
  • Eight indicators to steer the role, and a glossary of about fifty terms
Toolbox

Eight templates to take away

Ready-to-use templates, reusable as they are in your own files.

Key takeaways

Four ideas to take away

  1. 1Design, don't endure

    Security is built from the design stage; the security architect is its guarantor.

  2. 2Three dimensions

    Knowledge, know-how, attitude: posture matters as much as technique.

  3. 3An unavoidable gate

    Whatever the DGF path, the Security & Architecture gate is always there; only its position changes.

  4. 4Documented pragmatism

    Yellow light, recorded exceptions, tracked action plans: secure without blocking.

Download the survival kit

124 slides, free, no sign-up. Share them with your CISO, your project managers, your procurement team: that is what they are for.

Jeremy Canale AWS / Azure Security Architect · Agentic security

More than ten years of cloud security architecture, one of the first cloud consultants in Europe in 2013. Twenty-six certifications and trainings (Microsoft, AWS, ISACA, NVIDIA, Anthropic, Palo Alto). Large enterprises only, in finance, banking, insurance, defense, pharma and retail. Available in France, Belgium and Switzerland.