For the longest time cybersecurity was always a fringe and misunderstood phenomenon.
Since 2020, cybersecurity has become more and more mainstream, so much so that I would hear about cybersecurity in mainstream news at least weekly, and as of the last few years just about daily.
Now, since Mythos was announced earlier in 2026 cybersecurity has taken center stage.
Disclaimer, for the uninitiated, cybersecurity has often had a theatrical side to it. Partly due to movies, partly due to the sheer mystery of it, and in large part due to the industry itself. As such, cybersecurity vendors (including frontier labs) have taken advantage of the theatrical side of things. Hopefully reading these essays helps you discern theater from reality, although to be honest… reality is catching up to theatrical. 🦾
With AI becoming so powerful where on one side agents are independently hacking at lightning speed and on the other side, attackers are uplifted using AI maliciously to achieve their goals at 10-100x speed and/or impact, cybersecurity is center stage in almost every AI discussion.
Panel Discussion on AI - Cybersecurity Came up in 4 minutes
I attended a panel recently with both practitioners and founders discussing the future of AI. I was expecting a general discussion on AI and the industry, but almost immediately the discussion turned to cybersecurity!
My spidey sense perked up, sat up in my chair, and started taking some notes. There were some good nuggets that came out of it.
Below are some quotes from the panel, with some personal commentary, where applicable.
“Never worked with security so much” and “Never thought I would get along with them”
I found this hitting close to home! One of the challenges I generally face when entering a new organization is whether they had friction with the security at their prior job and if that has caused any PTSD that will show up with me. Pretty soon they learn that my approach is Guardrails, not gatekeeping.
This kind of goes towards my philosophy of running lean security at a company. It involves a few parts:
Meeting people where they are
Being approachable
Building culture - security is everyone’s job
Being solution oriented
I could do a whole essay or video on just this. Lmk in the comments if that’s something you’d like to see.
“Our security is built assuming it’s a human on the other side.”
This was such a profound statement!
Our defenses are built to protect and detect humans and semi-automatic bots on the other side.
This has changed.
We now have self-correcting, highly intelligent, trained, and tooled AUTONOMOUS agents on the other side.
It’s like when the agents in the Matrix started drilling toward Zion. It was only a matter of time before they go through.
We need to change our mentality and defenses in such an era, otherwise we will lose.
“There is not enough inference in the world to secure all the software.”
This did seem like a hot take, but I think it’s kinda true (for now).
Take a look at BSD, Microsoft, or other giant repos of software. How much compute has been used to secure them?
“The future would not have npm. The model will write it itself.”
This was my FAVORITE quote of the evening. I’ve had to deal with supply chain attacks most of my career as a CISO and this year they have become so frequent and common.
What a great idea… instead of relying on a library to do a thing.. Just build it!
Why not!
Yes, it means more compute, but you know that library will ALWAYS be secure and you will never hear a dependabot nag again.
I like that personally and can really get behind that!
Cool Things I’ve come Across
Harness Engineering
This past week I went to down a big rabbit hole to level up my AI workflow. As such, YouTube was my go to. It was hard to find videos that discuss advanced coding practices, but was lucky to find some really high value low fluff channels and videos.
Notable YouTube Channels
If you are new to Harness Engineering, then I would start with this channel, and this video. It’s simply a mindset shift.
He even has his own OSS harness builder!
His videos are quite relevant and approachable.
This guy’s workflow is off the hook. Nothing better than a real engineer and engineering manager fully embracing AI. Who better else to do this.
This video is chock full of nuggets and hacks.
If you don’t watch the video (which you should if you code), his Github is full of tons of tools.
Automic Vault
The creator of Homebrew (Max Howell) created this a new tool. Automic Vault hardens supported CLI tools on macOS.
https://github.com/automic-vault/automic-vault
Honesetly, there is a lot that needs to be done in the Agentic-Credentials space. Tools like Wardn for example. https://github.com/rohansx/wardn
Claude Code Now Supports Mods!
Ever since Deepseek released it’s OSS harness where EVERYTHING was a plugin and customizable I was interested in the trying out a new harness (change is hard lol).
Seems like Anthropic listened, and has opened it up a bit.
My friend Daniel Miessler shared his mod for Claude Code.
After watching Kun Chen, I was pondering with the idea of taking all his tools and integrating them into OMP/Pi. But with CC open to mods, I might stay on CC for a little bit.
This week I hope to continue experimentation in leveling up my software workflow.
SOC 2 Workshop
I’ve been getting a lot of questions lately about SOC 2, so I decided to put together a LIVE workshop to go over all the details and questions. It will include an AMA where you can ask your specific questions.
Sign up here:
Unrelated Links
I love learning about tons of topics, but sometimes I could use a break from the usual (cybersecurity, psychology, productivity). So why not learn about quantum physics and mechanics. 😎
I found this discussion about Dark Matter and Anti-Matter wholly fascinating to calm my brain on a long drive when I didn’t want to think.
As always, all my essays are 100% organic and handwritten. Nothing beyond google docs spellcheck is run prior to publishing. Not submitted to AI at all. Enjoy!





