Curator of Chaos Security Weekly Director of Operations (Studio Mom).

AI may make developers faster. For security teams, the real metric is different: Does it help reduce risk faster? That's the conversation leaders should be having. 👇
Everyone talks about AI making developers 10x more productive. But cybersecurity doesn't work the same way. Success isn't measured by writing more code—it's measured by finding and reducing risk faster. That changes how AI should be evaluated inside security teams. Will AI ever create a true productivity breakthrough for cybersecurity professionals? #Cybersecurity #ArtificialIntelligence #CISO
1
87
Cyber insurance is evolving beyond financial protection. As insurers become security providers, leaders need to ask a new question: Are we reducing risk—or centralizing it? 👇
What happens when your cyber insurer also runs your security? For many small businesses, it's an attractive option. But if thousands of customers rely on the same managed security service and tools, a single weakness could have far-reaching consequences. Does convenience outweigh the risk of a security monoculture? #CyberSecurity #CyberInsurance #MSSP
1
70
Quarterly patch cycles made sense when attackers moved slower. Do they still make sense when AI can accelerate exploit development? Thought-provoking discussion from @secweekly.
The old approach to patch management is being challenged. As AI accelerates vulnerability discovery and exploitation, waiting 60 or 90 days for the next maintenance window may leave organizations exposed. The conversation is shifting from scheduled patching to responding based on real-time risk. Is your patching strategy built for today's threat landscape—or yesterday's? #CyberSecurity #PatchManagement #AI
1
96
The question isn't whether AI needs an identity. It's whether your IAM strategy is ready for thousands of non-human identities making business decisions at machine speed. Thought-provoking conversation from @secweekly.
AI isn't just helping identity management—it also needs identity management itself. As AI agents gain access to corporate data and execute business workflows, they require the same oversight, auditing, and accountability as human users. At the same time, AI can automate many of the manual tasks that have long challenged identity teams. How should organizations govern AI agents as they become part of the workforce? #IdentitySecurity #AI #Cybersecurity
1
120
The biggest workforce challenge may not be replacing jobs. It may be replacing the experience those jobs create. A fascinating leadership discussion from @secweekly.
AI's impact may go far beyond entry-level jobs. If organizations need fewer junior employees and fewer managers, they could also reduce the pool of future directors and executives. The biggest challenge may not be today's workforce—but tomorrow's leadership pipeline. How should companies prepare future leaders in an AI-driven workplace? #AI #Leadership #FutureOfWork
1
116
Most security controls try to keep attackers out. Deception assumes they'll get in and gives them nowhere to hide. Strong conversation from @secweekly.
Attackers expect firewalls and patches. What they don't want to find is a properly placed honeypot. In this clip, a professional red teamer explains why even basic deception technology can expose an attacker during their very first reconnaissance steps—even in networks with known vulnerabilities. Would you prioritize another security control before deploying honeypots? #CyberSecurity #Honeypots #RedTeam
1
65
Developers have spent decades building software for people. The next generation may be building software that sells itself to AI agents. That's a future worth thinking about. @secweekly
AI agents may soon become your next customer—and your next decision-maker. Instead of humans comparing vendors, agents could evaluate pricing, security, and MCP support automatically before choosing where to execute tasks. That shift could change how companies design pricing pages and APIs. If AI agents start making purchasing decisions, what should businesses optimize for first? #AI #MCP #AgenticAI
1
103
Your employees don't learn your values from the mission statement. They learn them by watching what leadership does when the stakes are high. A conversation every executive should hear. @secweekly
Company values only matter if they're true. Saying "people first" means nothing when everyday decisions tell a different story. Honest leadership starts by defining what your organization actually values—and acting accordingly. Do your company's actions reinforce its stated values, or contradict them? #Leadership #CompanyCulture #Trust
1
68
You can pass every security scan... ...and still expose sensitive business data through perfectly "working" application logic. A fascinating RSAC conversation on where AppSec is headed. @secweekly👇
Some security vulnerabilities happen even when the software works exactly as designed. This clip explains business logic vulnerabilities using a payroll example: who should — and shouldn’t — be allowed to see salary data. The challenge is not just authentication. It’s making sure applications understand roles, context, and real-world business rules correctly. How many “working” applications are quietly exposing sensitive information? #AppSec #Cybersecurity #BusinessLogic
115
Attackers only have to be right once. Defenders have to be right every. single. day. AI isn't changing that. It's making it harder. @secweekly
Defense is becoming the harder side of cybersecurity. AI is rapidly accelerating vulnerability discovery and exploit creation. That makes offensive security faster, cheaper, and more “exciting.” But defense doesn’t get that luxury. Detection and patching must be correct every time. One mistake can break security posture entirely. Is cybersecurity innovation drifting too far toward offense while defense struggles to keep up? #Cybersecurity #AI #BlueTeam
1
1
150
The best time to prepare for a technology shift is before it changes your risk profile. Quantum computing isn't a 2035 conversation anymore. It's becoming a strategic planning conversation. Watch the discussion from @secweekly
Quantum computers aren't mainstream yet. That doesn't mean organizations should wait. Just as early computers evolved into everyday technology, quantum computing could arrive faster than many expect—and policy decisions made today will determine how prepared organizations are. When should companies start planning for quantum security? #QuantumComputing #Cybersecurity #Technology
2
135
Everyone talks about prompt injection. Far fewer are talking about what happens after an AI agent gets permission to act. Great conversation from @secweekly. 👇
Everyone worries about what AI says. The bigger security problem is what AI is allowed to do. As AI agents gain access to systems and identities, prompt filtering alone won't stop real-world damage. Where should security teams focus first: controlling AI responses or controlling AI permissions? #AI #Cybersecurity #IdentitySecurity
1
68
The fastest way to ship bad code? Stop questioning AI output. Great conversation from @secweekly on why critical thinking remains a competitive advantage. 👇
AI coding tools can speed up development — but they can also speed up bad decisions. This clip explains why critical thinking still matters when engineers use AI-generated code. Without experienced developers questioning what the AI produces, teams risk entering endless loops of buggy code, failed fixes, and automated rewrites. AI may write code faster than humans. That doesn’t mean it understands what it wrote. #AI #SoftwareEngineering #Cybersecurity
1
49
The next major breach may begin with a company you've never heard of. That's the reality of supply chain risk. Great conversation from @secweekly. 👇
Sometimes attackers don't target your company at all. They target the software, supplier, or service that dozens of organizations rely on. This conversation explains "cascading breaches" and why a single successful compromise can rapidly spread across an entire ecosystem. How much of your organization's security depends on someone else's? #CyberSecurity #SupplyChainSecurity #DataBreach
1
86
Technology gets smarter. Does it also get harder to secure, govern, and recover when things break? Strong discussion from @secweekly. 👇
AI is adding new features everywhere. But every new layer of complexity can also introduce new points of failure. This clip explores the tradeoff between rapid AI-driven innovation and operational stability. As vendors race to integrate AI into products and platforms, the systems underneath may become harder to manage, maintain, and secure. Could AI adoption unintentionally make critical technology more fragile? Now booking interviews at Black Hat 2026. Early access pricing is open. Message us for details! #ArtificialIntelligence #Cybersecurity #Technology
1
73
The biggest AI risk may not be the technology. It may be the AI systems operating outside your visibility and control. Great conversation from @secweekly. 👇
Most companies already have shadow AI. Employees are deploying AI agents, LLMs, and AI tools faster than security teams can track them. The real problem isn’t just the tools — it’s that many organizations don’t even know they exist. If your company can’t see its AI systems, how can it secure them? #Cybersecurity #AI #ShadowAI
1
56
AI agents don’t just answer questions. They can take actions, use tools, and pursue objectives across systems. Interesting @secweekly discussion on what that means for security. 👇
AI agents don't behave like chatbots. They can pursue goals, use tools, remember information, and act independently across systems. This clip explores why traditional security controls may fail against autonomous agents—and why friction-based defenses like SMS codes and rate limits may not hold up for long. Does your security actually stop attacks, or just slow them down? #AIAgents #CyberSecurity #AISecurity
1
114
The hardest part of post-quantum cryptography may not be the math. It may be the deployment. Great @secweekly conversation on readiness and operational risk. 👇
Post-quantum cryptography is coming — but deployment won’t be smooth. This clip breaks down the uneven readiness between client software and enterprise systems, and why organizations are concerned about breaking production environments during rollout. While some systems can be updated immediately when inactive, the real challenge is managing live infrastructure without disruption. Is security modernization worth the operational risk it introduces? #Cybersecurity #PostQuantum #Cryptography
1
97
AI is moving faster than most governance frameworks can adapt. Strong @secweekly discussion on DSPM, data context, and securing agent-driven environments. 👇
AI systems are moving faster than traditional governance models can handle. This clip explores how agentic AI shifts security thinking away from traditional perimeters and toward the data itself. By focusing on lineage, contextualization, and DSPM, organizations try to build trust and resilience at machine speed. But human processes are struggling to keep up. What happens when decision-making speed outpaces human governance entirely? #AI #Cybersecurity #DataSecurity
1
67
AI isn’t just changing defense. It’s lowering the barrier to entry for attackers too. Interesting @secweekly discussion on how the threat landscape is evolving. 👇
AI isn’t just helping defenders. According to this clip, it’s rapidly increasing the effectiveness of low-level and mid-tier cyber attackers too. Tasks that once required deep expertise are becoming faster, cheaper, and easier to scale. The result? Security teams may need to rethink response times, staffing, and overall defense posture much sooner than expected. Are organizations underestimating how quickly AI changes the threat landscape? #Cybersecurity #AI #InfoSec
1
54