HUMAN REQUIRED / EST. 2026
AI is everywhere.
Knowing what to trust is the new superpower.
Sharp, intelligent, evidence-based writing on AI, cybersecurity, hacking, and the technology that shapes how we live and work.
Mission
The hype is loud. The fear is louder. We cut through the noise with practical, evidence-based writing for people who want to think clearly about technology, especially when the technology is trying to think for us.
THE LATEST / 20 ARTICLES / UPDATED SEP 11
What we are writing about right now.
See the full Index →The OWASP Top 10 Hasn’t Kept Up
The OWASP Top 10, the canonical list of web application security risks, has been a foundational reference for 20 years. The 2021 edition added four new categories. The 2025…
READ →The ‘AI in Security’ Vendor Pitch Is Not the Same as AI in Security
Every security vendor now says they use AI. The phrase, in the security context, is even more inflated than the broader ‘we use AI’ problem. The products that actually use…
READ →Your Threat Intelligence Feed Is Mostly Noise
Every enterprise in 2026 subscribes to one or more commercial threat intelligence feeds. The feeds promise context about who is attacking, what they want, and how they operate.…
READ →The Cyber Insurance Market Is Breaking
Cyber insurance used to be a hedge. Premiums are up 200 to 400% over the last 4 years. Coverage is down. Exclusions are everywhere. The insurers are pulling out of the market. The…
READ →The Password Is Dying. The Passkey Is Not Winning.
Every year for the last 10 years has been the year the password was going to die. The year has not arrived. The password is still the dominant authentication mechanism. The…
READ →Your SaaS Sprawl Is Your Biggest Breach Surface
The average enterprise in 2026 uses somewhere between 100 and 300 SaaS applications. The enterprise has direct visibility into maybe 20% of them. The other 80% is shadow SaaS,…
READ →The Zero Trust Marketing Has Eaten Zero Trust
Zero trust was a security architecture model. Zero trust is now a marketing term. The original model, articulated by John Kindervag at Forrester in 2010, was a specific approach…
READ →A Field Guide to the Endpoint Detection and Response in 2026
The EDR the enterprise has been deploying has finally matured into the tool the security team has been waiting for, the tool that catches the breach the SIEM missed, the tool that…
READ →The CISO Month in Review: August 2026
The CISO month in review for August 2026 has been the month the breach disclosure, the regulator, the AI agent compromise all lined up in a way that the CISO had been quietly…
READ →The CISO Job Market Has Fundamentally Changed
The CISO job market of 2026 is not the CISO job market of 2018. The skills, the compensation, the reporting structure, the board relationship, the budget authority, the legal…
READ →AI Coding: The Cost of the Extra Context Window in 2026
The extra context window the AI vendor has been promoting has become the cost the developer has been quietly paying, the cost the AI bill has been showing for three months, the…
READ →AI Music and the Derivative Work Question in 2026
The AI music derivative work question has become the question the musician, the platform, the regulator have all been quietly watching, the question the next lawsuit will turn on.
READ →The Honest State of the CISO Turnover in 2026
The CISO turnover number has been the metric the board has been reading about for five years, the metric that has finally crossed the threshold the recruiter said was…
READ →The State of the Cloud in Q3 2026
The cloud market in Q3 2026 has settled into a shape that the analyst has been predicting for two years, the shape that the executive team has been delaying the strategy decision…
READ →The Platform Team and the Incident Response in 2026
The platform team has become the team the incident response depends on, the team the CISO has been quietly relying on, the team the breach response will land on before the…
READ →The Data Residency Question in 2026
The data residency question has become the question the enterprise has been quietly trying to answer, the question the procurement team has been asking, the question the regulator…
READ →A Field Guide to the Runtime Application Self Protection in 2026
The RASP the security team has been postponing has finally become the layer the breach disclosure will name as the layer the enterprise should have had, the layer that the modern…
READ →The Platform Team as a Product in 2026
The platform team that the enterprise has been building has been quietly developing into a product, the product the developer consumes, the product the developer has been treating…
READ →AI Music and the Harms of the Default in 2026
The AI music default the platform has been shipping has become the default the working musician has been quietly grieving, the default that ships the AI generated track on the…
READ →The CISO and the Acquisition Due Diligence in 2026
The acquisition due diligence the CISO has been involved in has become the diligence the CISO has been quietly dreading, the diligence that decides whether the enterprise buys the…
READ →FOLLOW / HUMAN VERIFIED / NO TRACKING
Read what we publish, in the order we publish it.
No newsletter. No algorithm. Subscribe directly through RSS and the next article lands when it lands.