Live webinar The Wrong Security Hire Burns Your B2B GTM Pipeline. A fireside chat for founders · Oct 6, 9:30am PTThe wrong security hire · Oct 6 Save your seat

Blog

Takeaways worth writing down.

What we're learning from client work and from the practitioners on The Security Podcast of Silicon Valley — pulled apart and put into practice.

Sep 23, 2026 The Human in the Loop Is Going Away Yash Kosaraju, the Chief Information Security Officer of a16z, told me nobody reads the third permission prompt. The numbers say he's being generous. The vendors are retiring the approve button, and your engineers clicked "don't ask again" months ago. Here's where the human goes next, and a scorecard for what your agents can reach. Sep 20, 2026 Too Fancy: When Your Agent Costs You $50,000 an Hour to Operate A ledger-reconciliation agent at a global financial services firm met one corrupted value, looped more than 15,000 times in under an hour, ran up about $50,000 and locked the billing database while it did it. Sasha Sinkevich traces the same failure back through a decade of surprise cloud bills and forward through the deleted-database confessions of 2025 and 2026, listens to the people on X, Reddit and Hacker News asking for a cap that actually stops execution, and lays out the boring controls that turn an agent's budget from a surprise into a number you chose. Sep 18, 2026 "We Need SOC 2 Soon, But We're Not Ready to Hire": What We Heard at Twin Cities Startup Week One founder put her hand up and asked it out loud. "Where can I get a security team that I don't have to hire in house?" Most of the room was sitting on the same question. Here's what she asked, what it costs to answer it either way, and how to tell which side of it you're on. Sep 17, 2026 The Art and Zen of Adopting AI Established organizations read every incident report and wait. Startups try everything and buy the demo. Both are failures of practice rather than of enthusiasm. Sasha Sinkevich takes the ten good reasons the first group waits on their own terms, walks through the grandiose claims that cost the second group its scarcest asset, lays out a Middle Way you can actually test, and argues that security maturity has become the litmus test for whether a company is real. Sep 10, 2026 It's Like a Self-Driving Car: Agentic Code Review and Your SOC 2 Type 2 Audit Agents now write most of the code at AI-native companies and review a growing share of it. The first thing every auditor and every customer security team says is the same: an agent is not a human. Correct. Paddy Roberts, who leads governance, risk and compliance at Augment Code, on what SOC 2 CC8.1 actually requires, how Augment Code and Anthropic run agentic code review, why it lands like a self-driving car, and how the same control reads under FedRAMP, CMMC, ITAR, ISO 27001 and ISO 42001. Sep 8, 2026 Your Zero Trust Stops at the Sticker on the Box Zero trust verifies every user, device and request. Then it runs on a switch you trust because a label says who made it. Roei Ganzarski of Alitheon on hardware provenance, the fake-paperwork aircraft parts that flew for years, and the six-step intake pipeline a startup can run this quarter. Sep 1, 2026 What Even Is a SOC 2? A Founder's Plain-English Guide to SOC 2 Reports Every enterprise buyer asks for one. Most founders nod along the first time and look it up afterward. Here's the plain-English version: what a SOC 2 actually is, what's in the report, Type 1 versus Type 2, and how fast a startup can realistically get one. Aug 29, 2026 Are You Actually Going to Give the Agent Write Access? Chris Kirschke has enabled write access on a production system exactly once in 27 years. The outage took seven minutes. His question for every autonomous-remediation pitch should be yours too. Aug 29, 2026 AI Agents Are Now on Both Sides of the Breach OpenAI's own agents breached Hugging Face, a ransomware crew talked Cursor into assisting real intrusions, and 100+ companies say the window to prepare is closing. The hypothetical era of AI attacks is over. Aug 16, 2026 In-House, On-Demand, or YOLO? How Startups Should Staff Security There are only three ways a startup can handle security. Most are doing the third one right now, some of them correctly. Here's how to tell which one fits the work you have, and when the answer changes. Jul 14, 2026 AI Agent Governance Starts at Onboarding, Not Runtime Most governance tools watch agents that are already deployed and already have access. The bigger opportunity is making agents declare what they need before they ever run, then holding them to it. Jul 14, 2026 AI Readiness Assessment: The Pre-Flight Check Before You Deploy an Agent Most agent deployments that stall were never ready to begin with: the data wasn't there, the dependencies were hidden, and nobody asked before the contract was signed. Here is the pre-flight check that returns an honest go, fix first, or not yet. Jun 30, 2026 Enterprise Browser Security: Why the Browser Is the New Control Point Users spend most of their day in SaaS and AI tools, on encrypted connections your network appliances can't see into. The browser, not the network, is where the last mile of control now lives. Jun 30, 2026 Shadow AI: The Risks, and How to Govern It Without Blocking AI Data you can't see is data you can't protect. Your team is already using AI tools nobody approved, mostly on personal accounts. Here's what shadow AI looks like, why a flat ban makes it worse, and the policy plus point-of-use guardrails that let you say yes to AI and still know where your data went. Jun 19, 2026 AI Penetration Testing: Can Autonomous Agents Replace Human Pentesters? A scanner flags an open door. An AI agent walks through it, finds your keys on the counter, and opens the safe. Here's what autonomous offensive testing does well, where human pentesters still earn their fee, and how a startup should buy a pentest in 2026. Jun 19, 2026 AI Cyberattacks Are Going Autonomous: When the Hacker Is a Machine For a while, AI just wrote cleaner phishing emails. The newest tools run the whole attack: finding weaknesses, exploiting them, chaining web to IoT to physical systems, and moving deeper with little human input. Here is what the documented cases show, and what changes for defenders when the attacker never sleeps. Jun 3, 2026 Harvest Now, Decrypt Later: Why Today's Encrypted Data Is Tomorrow's Breach An adversary captures your encrypted traffic today, stores it, and waits for a quantum computer to break it. The attack works against data you already sent. Here is which data is exposed first, what the standards say, and the four-step migration a startup can start this quarter. Jun 3, 2026 What Is Deep Tech? Why the Hardest Startups Can't Be Built in a Weekend Deep tech is built on a hard scientific breakthrough, not on assembling parts that already exist. The core advance has to be invented and proven before there's a product to sell. Here's how the companies that do it actually work: the timeline, the capital, the proof, and where the moat comes from. May 19, 2026 AI Data Bill of Materials (DBOM): Why AI Security Needs a Data Supply Chain An SBOM tells you what code is in your software. It can't tell you which customer records ended up in your latest fine-tune. A DBOM makes the data supply chain explicit: every dataset behind a model, where it came from, how it was processed, and who owns it. May 19, 2026 Stop Saying No: Enable AI With Data Governance, Not a Blanket Block The fastest way to lose influence as a security leader is to be the person who says no every time the business proposes an AI use case. The fix is visibility, not courage: know your data, put the guardrails where the work happens, and you get to say yes. May 7, 2026 IoT Device Security: Why Forgotten Devices Are Your Biggest Risk Printers, cameras, badge readers, sensors: the devices that get attacked first are the ones nobody put in the security org chart. Most IoT failures are governance failures with technical symptoms, which is good news, because governance is cheap to fix. May 7, 2026 Printer Security: How One Unsecured Printer Becomes Your Weakest Link About 20% of enterprise endpoints are printers, and roughly 99% sit at factory defaults, holding admin-level credentials for your email server, file shares and directory. Here is what a printer really stores, how one device took down 11,000, and the checklist that fixes it. Apr 23, 2026 Neuro-Symbolic AI: Why Enterprises Need More Than Large Language Models LLMs handle the fuzzy parts: language, perception, pattern. Symbolic systems handle the parts that must be correct. The enterprises getting AI right are composing both. Here is what that stack looks like: where each half is strong, how the routing pattern works, and which tasks belong to which. Apr 23, 2026 Why 95% of Enterprise AI Projects Fail: The Scoping Discipline That Beats the Odds MIT found 95% of integrated enterprise AI pilots delivered no measurable P&L impact. The models were rarely the reason. What separated the 5% was how they decided what to build, in what order, and with which tool. Apr 7, 2026 Deepfake Attacks Keep Working Because We Keep Detecting Instead of Proving Detection is a classification problem, and its error rate grows as the adversary improves. Cryptographic identity proof doesn't care how realistic the fake is, because it never relies on what someone looks or sounds like. Apr 7, 2026 Why Passwords Still Get Stolen: The Case for Device-Bound Credentials In Verizon's 2025 DBIR, 88% of basic web application attacks involved stolen credentials. The industry answers with more MFA prompts and shorter tokens. Those are mitigations. The real problem is that the secret moves at all. Mar 25, 2026 Vibe Coding Security: How to Stop AI Agents From Shipping Vulnerable Code AI coding agents trust what they find (in the registry, on the machine, in the context window) and rarely verify any of it. That trust is the new attack surface. Here's how to close it, and how to put the same agents to work fixing what they find. Mar 25, 2026 Why Shift-Left Security Keeps Failing (and What Actually Works) Shift-left sounds right: find bugs earlier, fix them cheaper. It keeps failing because security teams push every scanner finding to developers who have no way to tell which ones matter. Here is what reachability and business context change, and what a startup should do instead. Mar 10, 2026 Counter-Drone Technology: Closing the Biggest Gap in National Security A $500 drone can destroy a $10 million tank. Small drones reshaped warfare in a few short years, and the defenses against them are still being built. Here's how counter-drone technology works, from detection to defeat, why it's a national-security priority, and where the openings are for founders. Mar 10, 2026 How to Build a Defense Tech Startup: Lessons From the Tactical Edge Defense tech raised $125 billion from 2020 to 2024. Reveal Technology won military contracts by inverting the playbook: building for the corporal on the ground, not the program manager at a desk. Here is the company-building version of that story, from bottom-up product design to the ATO ladder to why compliance ends up being the moat. Mar 5, 2026 Agentic AI Security: Why Agents Need Least Privilege More Than Humans Ever Did Agents inherit the broad permissions humans built up over years, without the judgment or self-control that made those permissions safe enough for people. Roles were built for humans. Here is what least privilege looks like when the user is an agent. Mar 5, 2026 Authorization Is the Last Layer Companies Still Build From Scratch Authentication got outsourced a decade ago. Authorization, the logic that decides what a user can see, edit, or delete, is still built in-house at most companies. Here's why that's changing, what RBAC, ReBAC and ABAC actually mean, and how fine-grained permissions turn into enterprise revenue. Feb 18, 2026 Building a Cybersecurity Startup: Lessons From Illumio CEO Andrew Rubin In 2013, Rubin and PJ Kirner founded Illumio on a thesis the industry wasn't ready to hear: perimeter security alone wouldn't be enough, breaches would be inevitable, and containment needed a different approach. Thirteen years later, here is what the bet taught him about building a company, and what it should teach you about building a system. Feb 17, 2026 Immutable Backups and Ransomware Recovery: Why 3-2-1 Isn't Enough Anymore Ransomware operators go after your backups first. The 3-2-1 rule was built for hardware failures, not for adversaries who study your infrastructure before they strike. Here is what 3-2-1-1-0 adds, what immutability does and doesn't solve, and how to know you can restore before anyone asks.
Most of these started as podcast conversations

Hear them firsthand.