security @hellosurgeai. formerly headway, dbt labs, dell tech capital, mit, stanford.

San Francisco, CA
My newsletter, Frankly Speaking, is back! I'm launching a freemium version but with more consistent articles and hot takes on my experience as an engineer and former VC working in cybersecurity: franklyspeaking.substack.com… Subscribe here: franklyspeaking.substack.com…
1
10
Does a CISO need to ship code? I’ve argued that AI will favor technical, hands-on security leaders. But technical work becoming more important doesn’t guarantee the person doing it gets the CISO job. Engineering could absorb more security work. A risk-focused CISO could remain useful alongside a strong engineering leader. That would challenge part of my argument, and I should be willing to admit it. Where I could be wrong: franklyspeaking.substack.com… How technical does the CISO personally need to be?
163
lol
OpenAI talking about rogue AIs communicating through fancy temperature side channels, when they can’t even install a recent Linux kernel on their sandboxes. 🙄
1
157
Frank Wang retweeted
OpenAI and Anthropic need to buy themselves some better security teams ASAP.
24
18
284
25,747
it's hard to be strategic in security or even any other part of engineering without being hands on, but it's easier than ever to be hands on. it'll expose people who aren't strong technically. if you don't know what's technically possible, how can you be strategic?
3
99
Top-down security strategy is dead. The future belongs to the technical doer. 🧵 Ten months of autonomous coding tools have completely broken enterprise annual planning. If you spent Q4 drafting a 2026 roadmap, it was obsolete by February. Here is how the fundamental risk calculus in security has permanently shifted: 1️⃣ The Compressed Timeline: When software moves at machine speed, the luxury of finding a flaw, filing a ticket, and waiting three months for a fix is gone. Latent architectural debt compounds instantly. 2️⃣ Minimal Disruption Fixes: Historically, fixing structural security issues required high developer friction. Today, AI flips that trade-off. Armed with terminal coding agents, security can generate patches, validate against test harnesses, and draft PRs in minutes without disrupting product teams. 3️⃣ Drop the Boundaries: Security cannot be an arm's-length auditing committee. Having rigid boundaries doesn't help. Security must be part of the engineering team, taking direct ownership of code fixes. 4️⃣ Sprints Are Dumb: Tying security to rigid two-week sprints or quarterly epics is broken. Teams must be dynamic and ready to pivot monthly or weekly as models and threats evolve. 5️⃣ How Leaders Stay Technical: Stop reading executive summaries. Read systems architecture docs. Use AI coding agents to submit real PRs. Shadow how your product engineers actually prompt and build. If you can't read the code, you can't calculate the risk. Full analysis on the practitioner's edge: franklyspeaking.substack.com…
2
6
271
Enterprise cybersecurity is no longer one market. 🧵 The biggest takeaway from @blackhatevents US 2026 is that the industry has permanently split in two: 1️⃣ The Infrastructure Divergence: When everyone had on-prem servers and corporate laptops, security was predictable. Today, an AI-native company deploying code at machine speed has completely different risks than a legacy firm managing physical infrastructure. 2️⃣ Dashboards vs. Platforms: Risk managers at legacy firms want visual dashboards and compliance reports. Technical leaders at AI companies want programmable APIs and open context layers that integrate directly into their CI/CD pipelines. One product cannot serve both. 3️⃣ The GTM Mismatch: Sales reps running 2010s playbooks (headcount qualification, 8-week procurement cycles, gated pricing) fall flat with AI startups that want a 3-day self-serve PoC. 4️⃣ The Booth Illusion: Spending $100k+ on trade show booths made sense when software required in-person installations. Today, pipeline moves over Zoom and Slack via API keys. The opportunity cost of booth spend is massive compared to investing in product velocity. 5️⃣ The Rise of Specialized Events: Catch-all conferences are losing relevance. High-signal, practitioner-driven events (like @unpromptedconf and @defcon villages) are replacing monolithic trade shows. Stop trying to build security products for "everyone." The future belongs to specialized architectures. Full analysis on the fragmentation of defense: franklyspeaking.substack.com… #Cybersecurity #Infosec #SecurityEngineering #AI #Startups #TechStrategy #DevSecOps
2
143
Frank Wang retweeted
Has anyone from Anthropic commented on how common of a sentiment this is?
this is largely the sentiment in the company slack
19
3
879
137,262
Frank Wang retweeted
1/ Stripe has signed an agreement to acquire OpenRouter. OpenRouter will continue to operate as it is: same name, same product, same roadmap, same mission. But now, we will do it faster, and with Stripe's unparalleled excellence and reach.
OpenRouter is joining Stripe: stripe.com/newsroom/news/str…. As anyone who uses it knows, @OpenRouter is a truly delightful developer tool. It is by far the best way to use new models and manage multiple inference providers. OpenRouter is also playing an increasingly important role: in the future, every business will have to manage both revenue flows and token flows. OpenRouter is the world's leading token marketplace, helping businesses effectively allocate the new currency of intelligence capital. We think that there's a lot to build together.
222
73
1,495
537,115
Field notes from Hacker Summer Camp 2026. 🧵 After surviving Black Hat and DEF CON, here are eight takeaways on where enterprise security is actually heading: 1️⃣ The Dinners vs. Keynotes: The vendor floor was talking about high-level "strategy." Private dinners with AI security leaders were focused on tactical execution and runtime code. Traditional leadership is out of touch due to a lack of hands-on doing. 2️⃣ The CISO Split: Boards have unrealistic expectations of CISOs (engineer + big org leader + risk manager). The role is splitting into peer positions: a Trust/Compliance Officer and a true Head of Security Engineering. 3️⃣ Cost vs. Workflow: The vendor obsession with raw LLM compute costs is misplaced. The real issue is misuse, untrusted sources, and process design. 4️⃣ The Dashboard Trap: Most tools on the floor are still stuck selling 2010s dashboards. Winning products will eliminate UI friction entirely. 5️⃣ The End of "One Size Fits All": Black Hat used to be one conference for everyone. Today, security is fragmenting into specialized markets for different customer personas. 6️⃣ The Agent Maintenance Reality: Autonomous agents are software. They require continuous tuning, context pruning, and maintenance. 7️⃣ Expensive GTM: Startup marketing remains noisy and expensive, but real thought leadership is rare. 8️⃣ Talking vs. Doing: Black Hat is a lot of talking; DEF CON is a lot of doing. AI security problems will be solved by practitioners in the runtime, not by executives building slides. Full debrief and field notes here: franklyspeaking.substack.com…
1
4
337
i'm going to write a longer post or several of course, but my main learning is from blackhat/defcon, if your security leader/CISO and team aren't effective at using AI for defense, your org has a problem.
1
3
236
totally agree. anyone who can't be hands on, i.e. pure people managers, only create more friction at an org, esp. for eng and security.
re: hiring right now it's a huge bull market for AI-native IC's/player-coaches it's a huge bear market for "heads of X" managers never seen such furious bifurcation. to oversimplify: 1 year experience managing 10 agents > 10 years experience managing 10-100 people
1
393
Security's instinctual fear of AI is actively giving adversaries the upper hand. 🧵 In a recent position paper, Anthropic CEO Dario Amodei noted that broad access to open-weights models doesn't inherently favor defenders because guardrails can be stripped away by malicious actors at machine speed. There's a vital lesson here for enterprise CISOs: 1️⃣ Adversaries don't care about your internal LLM policy. They are using uncensored, unconstrained AI right now to speed up vulnerability discovery and social engineering. 2️⃣ When security blocks developers or delays model adoption out of abstract fear, you don't stop attackers. You just force internal engineers into shadow workflows while keeping your security analysts operating at slow, human speed. 3️⃣ The primary risk isn't the model vendor—it's the adversary using those model capabilities against you. Depending on your risk profile, use enterprise providers with strict privacy terms (Anthropic, OpenAI, Cursor) or host open-weights models locally. 4️⃣ Security teams should be demanding UNLIMITED AI leverage inside their orgs. Defenders need frontier reasoning models and autonomous analysis agents just to maintain a level playing field. Stop viewing AI as a threat surface to restrict. Start using it as the core engine of defense. Full field preview before Vegas: open.substack.com/pub/frankl…
122
Heading to Vegas for Black Hat and DEF CON next week. 🧵 I haven't done the full dual-conference marathon since my VC days, but this year feels different. We are in the middle of a massive structural shift: the rise of the technical practitioner. Here is what I'm tracking across the strip: 1️⃣ The Tooling Test: I don't care if an AI tool is a "wrapper" as long as it delivers an elite product experience. The real test at Black Hat is whether a vendor eliminates administrative friction. If I still have to log into a bloated 2010 dashboard every morning instead of querying an agent, it's a pass. 2️⃣ The "Day-One" Security Hire: High-growth AI startups are hiring their first security engineer earlier than ever. A 10-person team using Cursor or Claude Code ships the code volume of a 50-person team. Technical debt compounds at machine speed—waiting until Series B is suicide. 3️⃣ The Builder Profile: Early startups don't need a compliance officer managing spreadsheets; they need a technical generalist who can write code, configure IAM, and build context files alongside developers. 4️⃣ The Executive Reset: Non-technical security leaders who manage from a distance are becoming operational bottlenecks. The industry is returning to technical CISOs who can read code and evaluate platform architecture. Full preview of the Vegas paradigm shift: open.substack.com/pub/frankl…
1
2
275
AI has made enterprise security significantly harder, but not for the reasons you think. 🧵 It's easy to complain about prompt injection or data slop. The reality is much more dangerous: AI is a force multiplier for your organization's existing bad habits. Think of an LLM as a high-speed calculator. If you input the wrong numbers, it will give you the wrong answer instantly. It doesn't judge quality. If your team has messy cloud configurations or loose IAM boundaries, an agent will replicate that flaw across thousands of endpoints in seconds. This compounds the "Asymmetry of Failure." A product team builds an agent that works 90% of the time and celebrates it as a massive velocity win. But to a CISO, that 10% non-deterministic variance is an absolute structural nightmare. Security requires 100% prevention. Attackers only have to be right once to win. This friction is triggering a brutal reorganization of the security org chart. The traditional CISO role is splitting in two: 1️⃣ The Compliance CISO: Handles brutal external audits, but faces shrinking internal leverage and fewer resources. 2️⃣ The Engineering CISO: An architecture-first leader building the automated buffer between compliance and the developer pipeline. This creates a massive startup opportunity. The market is flooded with tools trying to help elite engineering security teams build faster. The real gold mine? Building a platform that helps compliance-focused teams use AI to transform into an engineering unit. The founder who builds that bridge will unlock a massive pool of enterprise spend, mimicking what Snyk did for DevOps and Wiz did for the cloud. Full analysis on the hidden friction of force multipliers: open.substack.com/pub/frankl…
3
1
3
263
Security organizations have some important decisions to make in this new AI-world. Are they going to continue being compliance-focused, or are they going to be product/eng-focused? I find it hard to believe that a security org can be both. Of course, they can have both, but they have a "vibe." Otherwise, they will just be irrelevant.
1
96
you can’t stop a good builder from building. that’s real leadership!
1
92
The era of the lazy security gatekeeper is dead. It's a well-kept secret in tech that a lot of security teams don't actually do much. They run a scanner, export a 400-page report of raw alerts, dump it over the fence to the engineering team, and call it "risk management." AI is completely eliminating this comfortable hiding spot. My past newsletters focused on how to make engineers and security teams not hate each other. This week, I’m looking at a much more cynical operational reality. Compliance reporting, user access audits, and dependency bumps are entering a rapid race to the bottom, fully automated out of existence by background LLM jobs that run for pennies. The real budget is shifting to intense, outcome-driven Security Engineering. With terminal agents like Claude Code, security practitioners can no longer just find flaws and file Jiras. You are now expected to step directly into the repo, write the code patch, and submit the completed PR yourself. But this creates a brutal culture shock: most security people suck at product and can't code. Because AI has made writing syntax trivial, software engineers are spending their cycles on high-level system design and crafting exceptional user experiences. If security keeps building clunky, bureaucratic guardrails that add user friction, developers will simply write a script to bypass you entirely. This opens up a massive market opportunity for an entirely new software category: Security Development Tooling, i.e., platforms engineered to turn traditional analysts into automated code contributors. How to survive the shift: 👉 Stop building controls for yourself. Shadow your developers and design for the user experience. 👉 Ditch legacy vanity metrics. Track engineering-level ownership (Change Failure Rates, Lead Time for Secure Changes). 👉 Be highly opinionated. Don't hand teams a checklist; build the gold-standard secure pathway and sell it as an elite internal experience. If security doesn't upskill into a builder mindset, software engineers will use AI to absorb the security function themselves. open.substack.com/pub/frankl…
3
4
195
Terminal-native agents like Claude Code are completely collapsing the time-to-remediate (TTR) for software vulnerabilities. Historically, security engineers found a bug, wrote a report, assigned a Jira ticket, and waited weeks for a developer to fix it. Today, a security engineer can use an agent to auto-generate, test, and submit the PR directly from their terminal. But this structural shift creates a brutal talent filter. It heavily favors security professionals who actually know software engineering. If you can't read code, debug architectures, or manage pipelines, you cannot guide an autonomous agent to safely patch a repository. Because AI-assisted tools make generating modular Terraform code faster than clicking through cloud UI wizards, there is no longer any valid reason for product developers to have admin access to the cloud console. Permissions should be revoked entirely, forcing all configurations through a git-driven workflow. This frees up platform infrastructure teams to build automated AI audit agents to review code in the CI/CD pipeline. Organizations face a clear fork in the road: 1️⃣ Actively upskill your security team to possess true engineering-level ownership and manage programmable "context codebases" alongside developers. 2️⃣ Watch security become completely obsolete as software engineers use AI to absorb the defensive function themselves. The administrative security gatekeeper is dead. Software engineering literacy is now a baseline survival requirement for defense. Full deep dive on the agentic coding shift: open.substack.com/pub/frankl…
1
504
Your security startup is chasing the wrong customer profile. Most founders still define a "Tier 1" enterprise buyer by employee headcount. They are completely ghosting the real money. Next-gen AI-native companies are flat, lean, and hold massive budgets that rival legacy enterprise giants. If your software can’t survive the scrutiny of an AI-native customer, it won’t survive the decade. Here is why the frontier buyer is your ultimate product crucible: 1️⃣ The Build vs. Buy Threshold: AI-forward companies can build internal tools at machine speed. If your product is just a surface-level UI wrapper or solves a purely bureaucratic organizational problem, they will disintermediate you with a homegrown script over the weekend. They only buy when you act as an infrastructure partner toward a complex outcome. 2️⃣ The Return of Forward-Deployed Engineering: Founders are obsessed with building pure SaaS companies from day one. But frontier tools are still highly complex. Organizations don't understand model nuances or how changing a prompt taxonomy alters a security outcome. To win, you need forward-deployed engineers to embed context directly into the customer’s runtime. 3️⃣ The Palantir Playbook: When you eventually take an AI-native security product down-market to legacy enterprises, a SaaS login isn’t enough. You have to deploy services to actively transform their outdated workflows. Look at Palantir—they dominated legacy industries by using elite services to bridge the architectural chasm until their software became foundational. Focusing on the AI-native segment forces you to skate where the puck is going. As legacy enterprises are forced to flatten their orgs to compete, they will inevitably adopt the exact tools you built for the frontier. Full breakdown: open.substack.com/pub/frankl…
4
6
323
The "AI SOC Analyst" is a band-aid on a broken leg. A ton of security startups are dropping autonomous agents into legacy SOC queues to speed up triage. It’s a waste of budget. You are just optimizing a workflow that shouldn't exist in an AI-native world. Think about factory electrification in the 1920s. Early factories just swapped massive steam engines for large electric motors and saw zero productivity gains. It was only when they threw out the blueprints, put tiny motors at individual workstations, and changed the floor layout that productivity skyrocketed. Cybersecurity is stuck in the steam era. Legacy SIEMs force you to pay an insane markup on basic data storage while your team wastes finite engineering cycles tuning noisy alerts. The future isn't a faster SOC. It's a decentralized security data lake. New platforms like @RunReveal and @scanner_dev are cutting out the middleman by running directly on top of cheap infrastructure like S3 and ClickHouse. Meanwhile, tools like @cotoolai are perfecting the AI blue-team application layer. The real win here isn't autonomous code remediation; it's fixing the tuning loop. Most alerts are false positives. When an alert hits, tools like RunReveal can run an immediate background investigation, auto-close the noise, and hand the human generalist the exact context needed to tune the rule in seconds. You don't need a dedicated SOC or an army of analysts anymore. You need elite data infrastructure and software that lets a single generalist focus on outcomes, not implementation details. open.substack.com/pub/frankl…
1
4
13
1,128