Skip to main content
Stephanie Domas

Stephanie Domas

9 posts

A CISO’s preview of open source and cybersecurity trends in 2026 and beyond

Where is open source going next? What’s in store for open source in the coming years, particularly in relation to security? Here’s a CISO’s reflection on the state of open source, and the trends that you can expect to have an impact going into 2026. 

Beyond ‘whack-a-mole’ and insecticide

Designing a new, robust, sustainable, and truly holistic approach to cybersecurity Talk to any cybersecurity expert or IT security manager, and they’ll tell you they’re sick of alerts and issues. For a while now, the industry has slowly been realizing that there’s a better way to improve cybersecurity and resolve security issues in IT wit

A CISO’s guide to Application Security best practices

Effective AppSec is not a one-time fix but a continuous journey across every facet of your application’s lifecycle. By embracing a Secure Software Development Lifecycle (SSDLC) from the outset, diligently uncovering potential risks, and mastering your cybersecurity fundamentals, you lay a robust foundation for resilient applications.

CRA compliance: Things IoT manufacturers can no longer do under the CRA (and what to do instead)

In this blog, I’ll give you a thorough overview of common IoT manufacturer and PDE developer practices that need immediate attention, and how to change or improve these practices so that you can pass CRA compliance.

Extra Factor Authentication: how to create zero trust IAM with third-party IdPs

In this article, I’ll explore an original and robust method for using third-party IdPs that allows you to maintain a zero trust security posture, thanks to Extra Factor Authentication. Find it on our Charm hub!

What is Application Security (AppSec)?

Application security (or AppSec, for short) is a broad term that refers to all of the tools, actions, and processes that an organization uses to protect its applications against vulnerabilities across the entirety of its life cycle. Application security has one objective: to find weaknesses in your applications and systems that could be a

EU Cyber Resilience Act compliance: best practices for IoT manufacturers

The EU Cyber Resilience Act has considerable repercussions for the IoT device manufacturers. In this blog, we explore these new regulatory requirements and give our blueprint for compliant, market-ready devices.

A CISO’s comprehensive breakdown of the EU’s Cyber Resilience Act (EU CRA)

The CRA is coming, and you need to be prepared. Depending on the Class your product falls into, there could be additional assessment, security, documentation, patching, compliance and reporting requirements on you and your teams. Find out how your digital product or service is categorised, reexamine your cybersecurity practices and design

The Cyber Resilience Act: What it means for open source

Canonical CISO Stephanie Domas outlines the community response to the EU Cyber Resilience Act and explores how it will affect enterprises using open source software.