惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
Vercel News
Vercel News
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
量子位
Engineering at Meta
Engineering at Meta
B
Blog RSS Feed
博客园 - 【当耐特】
Recent Announcements
Recent Announcements
Google DeepMind News
Google DeepMind News
D
DataBreaches.Net
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
人人都是产品经理
人人都是产品经理
IT之家
IT之家
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Jina AI
Jina AI
博客园 - 三生石上(FineUI控件)

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Modern Defensible Architecture: Resilience for the Austra...
Rodman Ramezanian · 2026-04-29 · via Wiz Blog | RSS feed

The Australian Signals Directorate (ASD)’s message to government Departments is clear: the question is no longer if a cyber security incident will occur, but when. Although authored by Australia, the Australian Cyber Security Centre (ACSC)’s Modern Defensible Architecture (MDA) reflects joint guidance developed alongside international partners. These include South Korea, Germany, Canada, the Czech Republic, Japan, and New Zealand, underscoring the MDA's relevance to both public and private sector organisations across multiple jurisdictions.

As Departments adopt MDA guidance, they face a common reality: defending increasingly complex, cloud-enabled environments with tools designed for a different era. This is where Wiz plays a critical enabling role.

Reinforcing Layered Architecture (Foundations 1, 5, 6)

Layered architecture recognises that no single control can fully prevent compromise. Departments must implement overlapping defences across identity, workloads, networks, applications, and data to ensure resilience even if one layer fails. Resources are ephemeral, identities and permissions sprawl across environments, and data moves dynamically between services. Most breaches exploit combinations rather than isolated flaws, and traditional security tools struggle to maintain visibility and context.

Regardless of whether Departments adopt a single-cloud, multi-cloud, or hybrid approach, Wiz reduces operational friction. Wiz provides agentless-first, API-driven visibility across cloud environments without performance overhead.

It maintains an always-current view of assets and identities across VMware, AWS, Azure, Google Cloud, and other hybrid and multi-cloud environments. Wiz then connects the dots between exposures and permissions to identify true attack paths, helping teams focus on the highest-impact risks and drive measurable reduction in exposure.

Operationalising Zero Trust (Foundations 2, 3, 6)

MDA is essentially the ACSC’s way of saying security can’t sit at the edge anymore; it must be built into the architecture itself. Zero Trust fails when it’s treated as a philosophy instead of an operational model. This is a challenge that scales exponentially with cloud and AI. While Zero Trust is often narrowly viewed as an end-user access tool, the MDA framework demands these principles be applied deeply within cloud infrastructure.

In this model, Zero Trust succeeds only when enforcement points (like Cloud IAM and network controls) are informed by real-time context rather than static policy. 

Wiz serves as this critical Policy Information Point (PIP), providing the deep visibility into identities and entitlements required to govern access effectively. By continuously analyzing IAM policies to identify excessive permissions, risky trust relationships, and privilege escalation paths, Wiz transforms Zero Trust from a concept into a defensible reality. By generating least-privilege recommendations and highlighting "toxic combinations" across identity-driven attack paths, Wiz enables Departments to align their architecture with MDA’s core intent: adaptive, risk-informed, and truly defensible security.

Ultimately, Wiz provides the governance and continuous verification required to keep Zero Trust from becoming 'set and forget.'

Embedding Secure-by-Design Practices (Foundations 4, 7, 8)

MDA reframes secure-by-design as an architectural outcome that spans the entire lifecycle, including the software supply chain. Wiz supports this by identifying exploitable weaknesses early in code and configuration, tracing runtime risk back to its source, and enabling remediation before insecurity becomes operational debt.

As Australian Government departments increasingly look to leverage AI-driven capability, the rapid instantiation and interconnection of AI and ML-enabled cloud resources materially increases the complexity of supply chain risk, introducing layered dependencies and abstracted control planes that are not governed in the same deterministic manner as traditional IaaS. Wiz responds to this challenge by providing consolidated, context-aware visibility across AI assets, models, identities, and data flows. Wiz delivers a whole-of-system view of the attack surface to support effective governance and risk-informed decision-making.

Compromise can occur at any point in the lifecycle, including via third-party and open-source software, challenging Departments to build systems that remain defensible even when trusted components fail. 

Wiz helps Departments build security into delivery, not bolt it on after deployment. The platform extends protection from code to runtime, identifying risks early in infrastructure-as-code templates, CI/CD pipelines, and live environments. It traces these risks to their source, even down to the specific parameter in a single line of code. This enables remediation at the root cause, reduces downstream exposure, and embeds security into everyday delivery processes.

Continuous Assurance and Informed Decision-Making (Foundations 9, 10)

A modern defensible architecture requires continuous, actionable monitoring rather than periodic assessments against static compliance models. In other words, adopting a continuous Authority To Operate (cATO) regime that keeps pace with dynamic cloud environments. But what executives need isn’t more flashy dashboards and reports. It’s confidence that risk is understood and controlled. Monitoring without context is just data collection. 

Wiz delivers high-fidelity signals with full architectural context, showing what’s at risk, why it matters, and how to remediate efficiently. This reduces Mean Time To Respond (MTTR) and supports confident, timely decision-making. Wiz also provides executive-level insight into risk posture and alignment with ACSC guidance (including ISM and Essential Eight), supporting governance, accountability, and assurance.

Government-Ready Confidence

For Commonwealth Departments, assurance is the bedrock of digital transformation. The Information Security Registered Assessors Program (IRAP) provides a framework for assessing the implementation and effectiveness of an organization’s security controls against the Australian government’s security requirements, as outlined in the Information Security Manual (ISM) and Protective Security Policy Framework (PSPF). Wiz’s commercial product has been evaluated against the PROTECTED ISM controls, effectively removing the friction of protracted custom assessments.

By championing a multi-cloud security strategy, we empower Departments to maintain a consistent security posture across diverse and expanding cloud estates. This unified approach directly supports the Modern Defensible Architecture (MDA) goals of visibility and interoperability, ensuring that even the most sensitive workloads remain secure from code to runtime. Wiz provides the technical foundations necessary for agencies to scale their multi-cloud workloads with absolute confidence.

From Guidance to Resilient Outcomes

Modern Defensible Architecture is a continuous journey. Wiz doesn’t just support MDA; it makes it achievable. As a unified, cloud-native platform, it breaks down silos between development, security, and operations, enabling shared visibility and prioritisation. 

The ACSC’s Modern Defensible Architecture recognises that cyber resilience is no longer achieved through compliance alone, but through architecture that continuously adapts to risk. Wiz welcomes this guidance and looks forward to working with Australian public sector and enterprise organisations to translate architectural intent into sustained, measurable resilience.