New quiz In-house vs on-demand: 10 questions to save you $500k+ in hiring mistakes and lost time10 questions to save you $500k+ Take the quiz

Blog

Takeaways worth writing down.

What we're learning from client work and from the practitioners on The Security Podcast of Silicon Valley — pulled apart and put into practice.

Jul 14, 2026 AI Readiness Assessment: The Pre-Flight Check Before You Deploy an Agent More than 60% of AI implementations never reach meaningful ROI — usually because the enterprise was never ready to feed the agent what it needed. Run the check before you sign. Jun 30, 2026 Enterprise Browser Security: Why the Browser Is the New Control Point Users spend most of their day in SaaS and AI tools, on encrypted connections your network appliances can't see into. The browser, not the network, is where the last mile of control now lives. Jun 30, 2026 Shadow AI: The Risks, and How to Govern It Without Blocking AI Data you can't see is data you can't protect. When staff feed company information into unsanctioned AI tools, it can be stored, logged, or trained on far beyond your control. Jun 19, 2026 AI Penetration Testing: Can Autonomous Agents Replace Human Pentesters? A scanner flags an open door. An AI agent walks through it, finds your keys on the counter, and opens the safe. Here's what autonomous offensive testing can and can't do yet. Jun 19, 2026 AI Cyberattacks Are Going Autonomous: When the Hacker Is a Machine For a while, AI just wrote cleaner phishing emails. The newest tools run the whole attack — finding weaknesses, exploiting them, and moving deeper with little human input. Jun 3, 2026 Harvest Now, Decrypt Later: Why Today's Encrypted Data Is Tomorrow's Breach An adversary captures your encrypted traffic today, stores it, and waits for a quantum computer to break it. The attack works against data you already sent. Jun 3, 2026 What Is Deep Tech? Why the Hardest Startups Can't Be Built in a Weekend Deep tech is built on a hard scientific breakthrough, not on assembling parts that already exist. The core advance has to be invented and proven before there's a product to sell. May 19, 2026 AI Data Bill of Materials (DBOM): Why AI Security Needs a Data Supply Chain An SBOM tells you what code is in your software. It can't tell you which customer records ended up in your latest fine-tune. A DBOM makes the data supply chain explicit. May 19, 2026 Stop Saying No: Enable AI With Data Governance, Not a Blanket Block The fastest way to lose influence as a security leader is to be the person who says no every time the business proposes an AI use case. The fix is visibility, not courage. May 7, 2026 IoT Device Security: Why Forgotten Devices Are Your Biggest Risk Printers, cameras, badge readers, sensors — the devices that get attacked first are the ones nobody put in the security org chart. Most IoT failures are governance failures with technical symptoms. May 7, 2026 Printer Security: How One Unsecured Printer Becomes Your Weakest Link About 20% of enterprise endpoints are printers. Roughly 99% sit at factory defaults — storing credentials for your email server, file shares, and directory at admin level. Apr 23, 2026 Neuro-Symbolic AI: Why Enterprises Need More Than Large Language Models LLMs handle the fuzzy parts — language, perception, pattern. Symbolic systems handle the parts that must be correct. The enterprises getting AI right are composing both. Apr 23, 2026 Why 95% of Enterprise AI Projects Fail — and the Scoping Discipline That Beats the Odds MIT found 95% of integrated enterprise AI pilots delivered zero measurable P&L impact. The problem isn't the technology. It's how enterprises decide what to build, in what order, and with which tool. Apr 7, 2026 Deepfake Attacks Keep Working Because We Keep Detecting Instead of Proving Detection is a classification problem, and its error rate grows as the adversary improves. Cryptographic identity proof doesn't care how realistic the fake is — it never relies on what someone looks or sounds like. Apr 7, 2026 Why Passwords Still Get Stolen: The Case for Device-Bound Credentials 88% of web app breaches involve stolen credentials. The security industry responds with more MFA and shorter tokens. Those are mitigations. The real problem is that the secret moves at all. Mar 25, 2026 Vibe Coding Security: How to Stop AI Agents From Shipping Vulnerable Code AI coding agents trust what they find — in the registry, on the machine, in the context window — often without verifying any of it. That trust is the new attack surface. Mar 25, 2026 Why Shift-Left Security Keeps Failing (and What Actually Works) Shift-left sounds right: find bugs earlier, fix them cheaper. It keeps failing because security teams push findings to developers who lack the context to prioritize them. Mar 10, 2026 Counter-Drone Technology: The Biggest Gap in National Security A $500 drone can destroy a $10 million tank. Small drone swarms reshaped warfare overnight, and Western nations don't yet have adequate defenses against them. Mar 10, 2026 How to Build a Defense Tech Startup: Lessons From the Tactical Edge Defense tech raised $125 billion from 2020 to 2024. Reveal Technology won military contracts by inverting the playbook — building for the corporal on the ground, not the program manager at a desk. Mar 5, 2026 Agentic AI Security: Why Agents Need Least Privilege More Than Humans Ever Did Agents get the same broad permissions humans built up over years — without the judgment or self-control that made those permissions safe enough for people. RBAC was built for humans. It breaks for agents. Mar 5, 2026 Authorization Is the Last Layer Companies Still Build From Scratch Authentication got outsourced a decade ago. Authorization — the logic that decides what a user can see, edit, or delete — is still built in-house at most companies. AI agents make that unsustainable. Feb 18, 2026 Building a Cybersecurity Startup: Lessons From Illumio CEO Andrew Rubin In 2013, Rubin and PJ Kirner founded Illumio on a thesis the industry wasn't ready to hear: perimeter security alone wouldn't be enough, breaches would be inevitable, and containment needed a different approach. Feb 17, 2026 Immutable Backups and Ransomware Recovery: Why 3-2-1 Isn't Enough Anymore Ransomware operators go after your backups first. The 3-2-1 rule was built for hardware failures, not for adversaries who study your infrastructure before they strike.
Most of these started as podcast conversations

Hear them firsthand.