Demo  Arrow | GitHub | Docs | API reference | Contact | Blog
tirreno - Open-source security framework Home Use cases How it works Pricing About
Arrow Download

tirreno » .com/bat » Platform security is not what you think it is






.com/bat
blog




Platform security is not what you think it is

July 31, 2025 · 3 min read

Traditional platform security focuses on familiar territory: code vulnerabilities, OWASP Top 10 threats, supply chain risks, and application architecture challenges.

It's the right moment to shift our perception and think not about how we develop but how applications are used by end users, no matter if they are internal workforces, external customers, or even non-human identities. We call this approach Security Analytics. It's based on the concept of aggregating and analyzing user events to identify risks based on their identities, behavioural irregularities, or specific metrics based on individual application functions. We can think about this like having SIEM but at the application level.

The main problem with this new security thinking is that it falls between classic disciplines such as development, security, and risk management. It is not straightforward development, as applications should have users to analyze and be in production. It's not only about security, because this approach is not related to endpoints, networks, or perimeters as we usually think. Moreover, from the standpoint of classic cybersecurity thinking, all events that could be considered risky are perfectly legitimate. Finally, it's not purely a risk management, since interpreting many data points requires deep cybersecurity expertise to recognize threat patterns.

We're seeing a new category of threats. For example, impersonation of platforms to perform personalized phishing attacks, or scammers that misuse legitimate platforms to obtain elements to use them to commit fraud or social engineering. There are many cases of insider threats or hacking attacks that use internal platforms as targets instead of hacking databases or file systems directly, as it's more valuable.

The same way that at some point a new profession like DevOps emerged, our times require creating a new job that will understand platform architecture, risks related to organizational operations relying on these applications, and cybersecurity aspects of the environment to bring Security Analytics together.

't'







tirreno is an open-source security
framework that embeds protection
into your product against threats,
fraud and abuse.

—  Security framework

—  Use cases

—  How it works

—  Pricing

—  About

—  Download

—  Live demo

—  GitHub

—  Dockerhub

—  Documentation

—  Blog

General team@tirreno.com
Support ping@tirreno.com
Security atdt@tirreno.com

Terms & conditions
Privacy policy
Imprint | Contact

Rue Galilée 7
1400 Yverdon-les-Bains
Switzerland Switzerland

©2026, tirreno




Open-source security framework