<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Shihan Suhail · Writing</title><description>Field notes on risk, compliance, cloud security and AI.</description><link>https://www.shihansuhail.com/</link><language>en</language><item><title>Scanning Terraform Against Azure Policy at Build Time in Azure DevOps</title><link>https://www.shihansuhail.com/writing/scanning-terraform-against-azure-policy-at-build-time/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/scanning-terraform-against-azure-policy-at-build-time/</guid><description>Azure Policy stops noncompliant resources at deploy time. This shows how to catch the same violations earlier, in the Azure DevOps build, so a bad Terraform plan fails the pipeline instead of the deployment.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Security</category><category>GRC</category></item><item><title>Strengthening Your Cloud Security Posture with Microsoft Defender for Cloud</title><link>https://www.shihansuhail.com/writing/strengthening-your-cloud-security-posture-with-microsoft-defender-for-cloud/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/strengthening-your-cloud-security-posture-with-microsoft-defender-for-cloud/</guid><description>Knowing where your cloud environment is weak is half the battle. Microsoft Defender for Cloud gives you a continuous read on your posture and maps it straight to the standards you have to comply with.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Security</category><category>GRC</category></item><item><title>What the EU AI Act Means for Risk and Compliance Teams</title><link>https://www.shihansuhail.com/writing/what-the-eu-ai-act-means-for-risk-and-compliance-teams/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/what-the-eu-ai-act-means-for-risk-and-compliance-teams/</guid><description>The EU AI Act is the first comprehensive law to regulate AI by risk. For compliance teams the question is no longer whether it applies, but which of your AI systems fall into which tier, and what each tier demands.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>AI</category><category>GRC</category><category>Risk</category></item><item><title>Running Terraform in Azure DevOps Pipelines</title><link>https://www.shihansuhail.com/writing/running-terraform-in-azure-devops-pipelines/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/running-terraform-in-azure-devops-pipelines/</guid><description>A practical Azure DevOps pipeline for Terraform: remote state in Azure Storage, a plan you review before it runs, and an apply that only happens after someone approves it.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Automation</category></item><item><title>Enforcing Compliance Guardrails with Azure Policy</title><link>https://www.shihansuhail.com/writing/enforcing-compliance-guardrails-with-azure-policy/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/enforcing-compliance-guardrails-with-azure-policy/</guid><description>Most cloud governance problems are not technology problems, they are consistency problems. Azure Policy lets you turn your security and compliance rules into guardrails that apply automatically across every subscription.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>Azure</category><category>GRC</category><category>Security</category></item><item><title>SOC 2 vs ISO 27001: Choosing the Right Framework (or Running Both)</title><link>https://www.shihansuhail.com/writing/soc-2-vs-iso-27001-choosing-the-right-framework/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/soc-2-vs-iso-27001-choosing-the-right-framework/</guid><description>The question I get asked more than any other is whether a company should pursue SOC 2 or ISO 27001. They overlap heavily but they are not the same thing, and the right answer depends on who is asking you for it.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>SOC 2</category><category>GRC</category><category>Risk</category></item><item><title>Deploying Bicep from Azure DevOps Pipelines</title><link>https://www.shihansuhail.com/writing/deploying-bicep-from-azure-devops-pipelines/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/deploying-bicep-from-azure-devops-pipelines/</guid><description>Bicep gives you clean, typed infrastructure as code for Azure, and Azure DevOps gives you a place to validate and ship it safely. Here is a pipeline that previews every change before it touches production.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Automation</category></item><item><title>Eliminating Hardcoded Secrets with Azure Key Vault and Managed Identities</title><link>https://www.shihansuhail.com/writing/eliminating-hardcoded-secrets-with-azure-key-vault-and-managed-identities/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/eliminating-hardcoded-secrets-with-azure-key-vault-and-managed-identities/</guid><description>Connection strings and API keys sitting in config files are still one of the most common ways credentials leak. Here is how to get them out of your code for good using Key Vault and managed identities.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><category>Azure</category><category>Security</category><category>Automation</category></item><item><title>Preparing for DORA: Operational Resilience for the Financial Sector</title><link>https://www.shihansuhail.com/writing/preparing-for-dora-operational-resilience-for-the-financial-sector/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/preparing-for-dora-operational-resilience-for-the-financial-sector/</guid><description>DORA reframes ICT risk as an operational resilience problem the board is accountable for, not an IT problem buried in a basement. Here is how I read its five pillars and where firms should focus.</description><pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate><category>GRC</category><category>Risk</category><category>Security</category></item><item><title>Evaluating SOC 2 Type II Reports as a Cybersecurity Engineer</title><link>https://www.shihansuhail.com/writing/evaluating-soc-2-type-ii-reports-as-a-cybersecurity-engineer/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/evaluating-soc-2-type-ii-reports-as-a-cybersecurity-engineer/</guid><description>It is important to understand that data is a key element of modern society, the lifeblood of business data in the present era. As such, cybersecurity executives are required to…</description><pubDate>Wed, 09 Apr 2025 00:00:00 GMT</pubDate><category>SOC 2</category><category>Security</category></item><item><title>Will AI Agents Disrupt GRC Workflows? Yes - and Here&apos;s Why</title><link>https://www.shihansuhail.com/writing/will-ai-agents-disrupt-grc-workflows-yes-and-here-s-why/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/will-ai-agents-disrupt-grc-workflows-yes-and-here-s-why/</guid><description>Will AI Agents Disrupt GRC Workflows? In the ever evolving cybersecurity and compliance landscape, Governance, Risk, and Compliance GRC workflows have long been cumbersome, time intensive, and manual. But changing…</description><pubDate>Sat, 05 Apr 2025 00:00:00 GMT</pubDate><category>GRC</category><category>AI</category></item><item><title>Azure Landing Zone Review Assessment</title><link>https://www.shihansuhail.com/writing/azure-landing-zone-review-assessment/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/azure-landing-zone-review-assessment/</guid><description>Introduction Organizations are constantly searching for methods to harness the potential use of the cloud to operate their operational architecture and compete in today’s fast paced digital environment. As a…</description><pubDate>Sun, 23 Mar 2025 00:00:00 GMT</pubDate><category>Azure</category></item><item><title>Implementing SOC 2 Compliance Framework</title><link>https://www.shihansuhail.com/writing/implementing-soc-2-compliance-framework/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/implementing-soc-2-compliance-framework/</guid><description>Introduction I have implemented SOC 2 compliance and am aware of the challenges. SOC 2 ensures that customer information is secure. The framework provides guidelines for security, availability, processing integrity,…</description><pubDate>Sun, 23 Mar 2025 00:00:00 GMT</pubDate><category>SOC 2</category><category>GRC</category></item><item><title>Automating Azure Resource Graph Queries with Logic Apps</title><link>https://www.shihansuhail.com/writing/automating-azure-resource-graph-queries-with-logic-apps/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/automating-azure-resource-graph-queries-with-logic-apps/</guid><description>Overview Azure Resource Graph Explorer enables querying resources at scale across subscriptions, management groups, and entire tenants. If you need to execute queries periodically and take action on the results,…</description><pubDate>Wed, 12 Mar 2025 00:00:00 GMT</pubDate><category>Azure</category><category>Automation</category></item><item><title>Step by Step Guide to Connecting OpenAI with Azure Portal</title><link>https://www.shihansuhail.com/writing/step-by-step-guide-to-connecting-openai-with-azure-portal/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/step-by-step-guide-to-connecting-openai-with-azure-portal/</guid><description>The integration of the OpenAI model into the Azure ecosystem gives organizations an unprecedented opportunity to harness the power of AI for a variety of applications. Microsoft Azure makes this…</description><pubDate>Sat, 18 Jan 2025 00:00:00 GMT</pubDate><category>AI</category><category>Azure</category></item><item><title>How to Resolve VSS Writer Errors Without Rebooting</title><link>https://www.shihansuhail.com/writing/how-to-resolve-vss-writer-errors-without-rebooting/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/how-to-resolve-vss-writer-errors-without-rebooting/</guid><description>Resolve VSS Writer Errors Without Rebooting How to Resolve VSS Writer Errors Without Rebooting Scenarios Scenario 1: Failed VSS Writers Backups fail due to VSS writers in a failed state,…</description><pubDate>Sun, 17 Nov 2024 00:00:00 GMT</pubDate><category>Infrastructure</category></item><item><title>How to Import Azure Wiki Contents into a JSON File</title><link>https://www.shihansuhail.com/writing/how-to-import-azure-wiki-contents-into-a-json-file/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/how-to-import-azure-wiki-contents-into-a-json-file/</guid><description>In today&apos;s digital age, organizations often depend on collaborative tools like Azure Wiki to streamline knowledge sharing among team members. However, there are situations when you might need to export…</description><pubDate>Sun, 17 Nov 2024 00:00:00 GMT</pubDate><category>Azure</category><category>Automation</category></item><item><title>Veeam Known Issues: Network Failure and SSL Errors</title><link>https://www.shihansuhail.com/writing/veeam-known-issues-network-failure-and-ssl-errors/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/veeam-known-issues-network-failure-and-ssl-errors/</guid><description>Veeam Known Issues: Error Observed by Underlying BIO Issue Discontinuous network failures may occur when communicating with the VMware host. This is accompanied by errors such as: “Error observed by…</description><pubDate>Sun, 17 Nov 2024 00:00:00 GMT</pubDate><category>Infrastructure</category></item><item><title>Simplifying Access Control: Introducing Temporary Access Passes in Azure</title><link>https://www.shihansuhail.com/writing/simplifying-access-control-introducing-temporary-access-passes-in-azur/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/simplifying-access-control-introducing-temporary-access-passes-in-azur/</guid><description>Overview In today’s ever changing business environment, it is often necessary to grant temporary access to resources within the Azure platform. Whether it be for a brief project, contractor involvement,…</description><pubDate>Wed, 20 Sep 2023 00:00:00 GMT</pubDate><category>Azure</category><category>Security</category></item><item><title>Configure Front Door For An Azure App</title><link>https://www.shihansuhail.com/writing/configure-front-door-for-an-azure-app/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/configure-front-door-for-an-azure-app/</guid><description>For content and apps, Azure Front Door is a cutting edge cloud content delivery network CDN service that offers high performance, scalability, and secure user experiences. This can be set…</description><pubDate>Wed, 05 Jul 2023 00:00:00 GMT</pubDate><category>Azure</category></item><item><title>Monitoring on premises devices with Sentinel using Azure ARC</title><link>https://www.shihansuhail.com/writing/monitoring-on-premise-devices-with-sentinel-using-azure-arc/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/monitoring-on-premise-devices-with-sentinel-using-azure-arc/</guid><description>When talking about Hybrid clouds &amp; multi cloud environments the main requirement is to monitor on premise devices. And yes when it comes to Azure cloud the monitoring is way…</description><pubDate>Wed, 05 Jul 2023 00:00:00 GMT</pubDate><category>Azure</category><category>Security</category><category>Automation</category></item><item><title>Using mTLS for your Organization</title><link>https://www.shihansuhail.com/writing/using-mtls-for-your-organization/</link><guid isPermaLink="true">https://www.shihansuhail.com/writing/using-mtls-for-your-organization/</guid><description>We used to do secure communication over the internet using TLS. After attacks such as POODLE made SSL 3.0 unsafe, mTLS (Mutual Transport Layer Security) was introduced to make client and server connections secure and trusted…</description><pubDate>Mon, 30 Aug 2021 00:00:00 GMT</pubDate><category>Security</category><category>Infrastructure</category></item></channel></rss>