- Posted by Alex Harding
- on
Most teams still bolt security on at the end, then act surprised when the audit goes badly. Alex Harding makes the case for Security Stories, negative “what if” scenarios written from the attacker’s viewpoint and dropped straight into the backlog, so security gets designed in rather than retrofitted. A practical look at how the technique maps onto ITIL (Version 5) and where it earns its keep in the design stage.