HUMAN REQUIRED / EST. 2026
AI is everywhere.
Knowing what to trust is the new superpower.
Sharp, intelligent, evidence-based writing on AI, cybersecurity, hacking, and the technology that shapes how we live and work.
Mission
The hype is loud. The fear is louder. We cut through the noise with practical, evidence-based writing for people who want to think clearly about technology, especially when the technology is trying to think for us.
THE LATEST / 21 ARTICLES / UPDATED SEP 20
What we are writing about right now.
See the full Index →The End of the Pentest Report
Cinematic cyan-and-black editorial frame for the piece on continuous offensive testing and the death of the annual pentest report. By Editorial Desk | September 20, 2026 The pentest report has not changed format…
READ →The Cyber Insurance Carrier Wants Your Logs Now
The cyber insurance carriers, in 2026, are not just raising premiums and narrowing coverage. They are also demanding more from the buyers as a condition of coverage. The new demand is operational visibility,…
READ →Your DLP Is Not Stopping Data Exfiltration
Data loss prevention, DLP, has been a security control category for 20 years. DLP, in most deployments, catches accidental data exposure. DLP does not, in most deployments, stop intentional data exfiltration. The gap…
READ →The OWASP Top 10 Hasn’t Kept Up
The OWASP Top 10, the canonical list of web application security risks, has been a foundational reference for 20 years. The 2021 edition added four new categories. The 2025 edition is overdue. The categories do not…
READ →The ‘AI in Security’ Vendor Pitch Is Not the Same as AI in Security
Every security vendor now says they use AI. The phrase, in the security context, is even more inflated than the broader ‘we use AI’ problem. The products that actually use AI in security, in ways that…
READ →Your Threat Intelligence Feed Is Mostly Noise
Every enterprise in 2026 subscribes to one or more commercial threat intelligence feeds. The feeds promise context about who is attacking, what they want, and how they operate. The feeds deliver, in most cases, a…
READ →The Cyber Insurance Market Is Breaking
Cyber insurance used to be a hedge. Premiums are up 200 to 400% over the last 4 years. Coverage is down. Exclusions are everywhere. The insurers are pulling out of the market. The market is breaking, and the breaking…
READ →The Password Is Dying. The Passkey Is Not Winning.
Every year for the last 10 years has been the year the password was going to die. The year has not arrived. The password is still the dominant authentication mechanism. The passkey, the technology that was supposed…
READ →Your SaaS Sprawl Is Your Biggest Breach Surface
The average enterprise in 2026 uses somewhere between 100 and 300 SaaS applications. The enterprise has direct visibility into maybe 20% of them. The other 80% is shadow SaaS, signed up by individual employees or…
READ →The Zero Trust Marketing Has Eaten Zero Trust
Zero trust was a security architecture model. Zero trust is now a marketing term. The original model, articulated by John Kindervag at Forrester in 2010, was a specific approach to security. The marketing co-opted…
READ →A Field Guide to the Endpoint Detection and Response in 2026
The EDR the enterprise has been deploying has finally matured into the tool the security team has been waiting for, the tool that catches the breach the SIEM missed, the tool that the postmortem will describe as the…
READ →AI Music and the Derivative Work Question in 2026
The AI music derivative work question has become the question the musician, the platform, the regulator have all been quietly watching, the question the next lawsuit will turn on.
READ →The Platform Team and the Incident Response in 2026
The platform team has become the team the incident response depends on, the team the CISO has been quietly relying on, the team the breach response will land on before the security team has even opened the runbook.
READ →The Platform Team as a Product in 2026
The platform team that the enterprise has been building has been quietly developing into a product, the product the developer consumes, the product the developer has been treating as the internal vendor.
READ →A Field Guide to the Data Loss Prevention Rule in 2026
The DLP rule the security team has been writing has become the rule the privacy team has been asking for, the rule the regulator has been citing, the rule the breach disclosure will describe as the rule the…
READ →Building the Home Network Monitor in 2026
The home network monitor the user has been quietly wanting has become the tool the privacy conscious household can actually run, the tool the smart home, the work from home, the small business has been needing.
READ →A Field Guide to the Cloud Detection Rule in 2026
The cloud detection rule has become the rule the SOC analyst has been writing, the rule the cloud architect has been reviewing, the rule the breach disclosure will reference when the rule fired but the SOC missed the…
READ →Hardware Firmware Vulnerability Disclosure in 2026
Firmware disclosure in 2026 is a slower animal than software disclosure. The CVE drops, but the patch is months away, the affected devices are still in production, and someone has to decide who is going to coordinate…
READ →The Honest State of the VPN in 2026
The VPN in 2026 has become the security control the enterprise has been questioning, the control the Zero Trust pitch has been promising to replace, the control the recent breach has been quietly exposing as the…
READ →Building a Detect and Respond Team in 2026
The detect and respond team the enterprise has been building has finally become the team the breach response depends on, the team the executive team has been quietly asking for, the team the CISO has been struggling…
READ →A Field Guide to the Public Key Infrastructure
The public key infrastructure the enterprise has been quietly depending on sits as the infrastructure the audit will quietly test, the infrastructure the post quantum deadline is quietly trying to replace, and the…
READ →FOLLOW / HUMAN VERIFIED / NO TRACKING
Read what we publish, in the order we publish it.
No newsletter. No algorithm. Subscribe directly through RSS and the next article lands when it lands.