# Risk and Cyber

Risk and Cyber

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Cybersecurity Benchmarking: Why, Why Not, When and How

DevFeed: [Cybersecurity Benchmarking: Why, Why Not, When and How](<https://devfeed.tech/articles/cybersecurity-benchmarking-why-why-not-when-and-how-39487.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/cybersecurity-benchmarking-why-why-not-when-and-how>)

Author: Phil Venables

Published: 2026-09-05T15:27:39Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [performance](<https://devfeed.tech/tags/performance.md>), [risk](<https://devfeed.tech/tags/risk.md>)

### AI overview

The article argues that cybersecurity benchmarking is unhelpful when it focuses only on inputs such as budgets instead of outcomes such as control effectiveness. It recommends comparing leading indicators and examining how they influence lagging performance indicators, while noting that budget comparisons may not be meaningfully comparable.

### Source excerpt

tl;dr Benchmarking is a waste of time when focused solely on inputs (e.g. budgets) rather than outcomes (e.g. effectiveness of controls). The budget comparisons are never "apples for apples" and may often end up setting risk tolerance only marginally ahead of others who may be in a bad state to begin with. Instead, we need to decouple this and compare leading not lagging indicators of performance to show (i) how those leading indicators drive the lagging indicators in the right direction and...

## Rolling with the Punches: Why Cybersecurity is Backgammon, Not Chess

DevFeed: [Rolling with the Punches: Why Cybersecurity is Backgammon, Not Chess](<https://devfeed.tech/articles/rolling-with-the-punches-why-cybersecurity-is-backgammon-not-chess-39493.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/rolling-with-the-punches-why-cybersecurity-is-backgammon-not-chess>)

Author: phil7672

Published: 2026-08-22T16:49:47Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-day](<https://devfeed.tech/tags/zero-day.md>)

### AI overview

The article argues that cybersecurity is better understood as backgammon than chess because organizations must prepare for many possible outcomes amid complex dependencies, supply chains, changing technology platforms, and unpredictable attackers. It also argues that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than inputs such as budgets.

### Source excerpt

It is tempting to compare cybersecurity to a chess game. Two adversaries facing each other, plotting strategy and tactics. Move and counter move, anticipating actions and grinding out a win. In reality, in our complex world of dependencies, supply chains, constantly shifting technology platforms and unpredictable attackers, this is all way more haphazard. Indeed, a better analogy is backgammon, where you position yourself for many different possible outcomes to maximize your chance of...

## Whether Rising Vulnerabilities Will Cause a Cybersecurity Incident Crisis

DevFeed: [Whether Rising Vulnerabilities Will Cause a Cybersecurity Incident Crisis](<https://devfeed.tech/articles/a-coming-incident-crisis-39484.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/a-coming-incident-crisis>)

Author: phil7672

Published: 2026-08-08T14:58:15Z

Content type: article

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-day](<https://devfeed.tech/tags/zero-day.md>)

### AI overview

The article examines whether increasing software vulnerabilities will lead to more cybersecurity incidents. It argues that security breaches often result from ineffective controls rather than exceptionally capable attackers or sophisticated zero-day exploits, and that benchmarking should focus on control effectiveness instead of inputs such as budgets.

### Source excerpt

We're all talking about the tidal wave of vulnerabilities that is upon us, with repeated waves likely coming. As I've covered here, we can respond to this in various ways including ramping up speed across our entire defensive stack, which is as much about structural defense-in-depth than just faster patching. I've covered that here as well. But, there's a question as to whether the leading indicator of increasing vulnerabilities will in fact result in an increase in the lagging indicator of...

## Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls

DevFeed: [Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls](<https://devfeed.tech/articles/control-reliability-engineering-cre-applying-sre-principles-to-cybersecurity-controls-39486.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/control-reliability-engineering-cre-applying-sre-principles-to-cybersecurity-controls>)

Author: phil7672

Published: 2026-07-25T05:52:21Z

Content type: article

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [SRE](<https://devfeed.tech/topics/sre.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [reliability](<https://devfeed.tech/topics/reliability.md>), [plotting](<https://devfeed.tech/topics/plotting.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [reliability-engineering](<https://devfeed.tech/tags/reliability-engineering.md>), [risk](<https://devfeed.tech/tags/risk.md>), [sre](<https://devfeed.tech/tags/sre.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

This article applies SRE principles to cybersecurity controls, arguing that control effectiveness matters more than input-focused budget comparisons. It highlights continuous control monitoring to detect controls that are broken, misconfigured, or incomplete when needed.

### Source excerpt

Security breaches are often not the result of awesome attacker capabilities or the sudden emergence of sophisticated zero-day exploits. Instead, what we usually find are the controls designed to stop the attack were believed to be operational but were actually broken or misconfigured at the moment when they were needed. Sometimes they were never fully in place to meet the security team's original intent. So, continuous control monitoring is needed to counter the natural decay that occurs to...

## Technology Waves and Security - Is This Time Really Different?

DevFeed: [Technology Waves and Security - Is This Time Really Different?](<https://devfeed.tech/articles/technology-waves-and-security-is-this-time-really-different-39498.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/technology-waves-and-security-is-this-time-really-different>)

Author: phil7672

Published: 2026-07-11T15:52:48Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [architectures](<https://devfeed.tech/tags/architectures.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>), [transformation](<https://devfeed.tech/tags/transformation.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This commentary examines whether current technology waves are fundamentally different for security. It argues that benchmarking should focus on control effectiveness and outcomes rather than budgets, while discussing recurring waves of vulnerabilities and possible responses including increased speed.

### Source excerpt

Most people have been through at least one wave of technology transformation. Some of us have been through a few and all carry the wisdom and scars from these. When you've experienced these changes you learn to appreciate, as the adage goes, that history might not repeat but it certainly does rhyme. In my working lifetime I caught the tail end of the mainframe to PC transition, the proliferation of client/server and distributed system architectures, wide-spread Internet adoption, mobile...

## Cybersecurity Benchmarking Should Focus on Control Effectiveness, Not Budgets

DevFeed: [Cybersecurity Benchmarking Should Focus on Control Effectiveness, Not Budgets](<https://devfeed.tech/articles/sorry-cyber-you-aren-t-the-only-ones-saving-the-company-from-itself-39497.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/sorry-cyber-you-aren-t-the-only-ones-saving-the-company-from-itself>)

Author: Phil Venables

Published: 2026-06-27T12:52:02Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that cybersecurity benchmarking should assess the effectiveness of security controls and their outcomes rather than compare budgets, which are not reliably comparable. It also places cybersecurity work within the broader responsibilities shared by organizational functions.

### Source excerpt

There's still a bit of a tone in some security circles that we're somehow unique in constantly having to push back against ill-advised moves, or even outright craziness, from our business, operations, or technology colleagues. But, when you pause and think about all the many functions in your or other organizations you realize this is not so. You quickly see that while great security teams are true enablers of business and reducers of friction, most teams still have to (and are expected to...

## CISO Version 2.0

DevFeed: [CISO Version 2.0](<https://devfeed.tech/articles/ciso-version-2-0-39485.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/ciso-version-2-0>)

Author: Phil Venables

Published: 2026-06-12T13:05:15Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [version](<https://devfeed.tech/topics/version.md>), [Security](<https://devfeed.tech/topics/security.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [opinion](<https://devfeed.tech/tags/opinion.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>), [version](<https://devfeed.tech/tags/version.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that the CISO role has evolved from an IT security manager into roles including cyber-defense leader, compliance director, and technology risk manager. It also argues that cybersecurity benchmarking is unhelpful when it focuses on inputs such as budgets rather than control effectiveness.

### Source excerpt

Everyone, no doubt, has an opinion on how many versions of the CISO role we have gone through since its inception. There has been a constant evolution from what was essentially an IT security manager, to cyber-defense leader, compliance director, technology risk manager, and beyond. However, I would argue the incarnation of the CISO role up until recently has been CISO Version 1.0 albeit with some "point releases" on the way. This is simply because version 1 of the role is a mode where most...

## Why Cybersecurity Benchmarking Should Focus on Control Effectiveness and Outcomes

DevFeed: [Why Cybersecurity Benchmarking Should Focus on Control Effectiveness and Outcomes](<https://devfeed.tech/articles/do-you-really-know-what-s-going-on-39489.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/do-you-really-know-what-s-going-on>)

Author: phil7672

Published: 2026-05-16T15:56:56Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [effectiveness](<https://devfeed.tech/tags/effectiveness.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This commentary argues that cybersecurity benchmarking should emphasize the effectiveness of security controls and outcomes rather than inputs such as budgets. It also discusses the continuing waves of vulnerabilities and possible responses.

### Source excerpt

At some point every leader needs to ask themselves: Do I really know what is going on in my company? Do I even know what is really going on in my own organization? Most leaders do not know the actual truth of what is happening. This is not because people are overtly hiding things or that leaders are ineffective, although sometimes it is both of those, but rather this is because of the "thermocline of truth" that I covered in this post. Organizations are full of cultural, structural, process,...

## High Frequency Trading and Lessons for Agentic AI

DevFeed: [High Frequency Trading and Lessons for Agentic AI](<https://devfeed.tech/articles/high-frequency-trading-and-lessons-for-agentic-ai-39490.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/high-frequency-trading-and-lessons-for-agentic-ai>)

Author: Phil Venables

Published: 2026-05-02T12:45:05Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [systems](<https://devfeed.tech/topics/systems.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [automated](<https://devfeed.tech/tags/automated.md>), [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [financial](<https://devfeed.tech/tags/financial.md>), [guardrails](<https://devfeed.tech/tags/guardrails.md>), [risk](<https://devfeed.tech/tags/risk.md>)

### AI overview

The article argues that lessons from high-frequency and algorithmic trading controls can inform deterministic guardrails for mostly non-deterministic agentic AI systems as they evolve from chatbots into systems that act. It also argues that benchmarking should focus on outcomes such as control effectiveness rather than input budgets alone.

### Source excerpt

I suspect I'm not the only former or current financial markets technologist that sees parallels between the world of high frequency / algorithmic trading controls and what is needed for appropriate deterministic guardrails around our, mostly, non-deterministic agentic AI systems. As we transition from chatbots to systems of agents, that don't just talk but act, we are entering a regime of automated risk that the financial markets have navigated, mostly successfully, for decades....

## Maintenance of Everything : A Review

DevFeed: [Maintenance of Everything : A Review](<https://devfeed.tech/articles/maintenance-of-everything-a-review-39491.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/maintenance-of-everything-a-review>)

Author: Phil Venables

Published: 2026-04-18T10:45:19Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [maintenance](<https://devfeed.tech/topics/maintenance.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [reliability](<https://devfeed.tech/topics/reliability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [review](<https://devfeed.tech/tags/review.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

A review of Stewart Brand's book Maintenance of Everything, discussing the importance of maintenance in technology risk management, security, and reliability. It also questions cybersecurity benchmarking that focuses on inputs such as budgets instead of outcomes such as control effectiveness.

### Source excerpt

I haven't done a book review for a while and there's no better way to get back to this than a look at Stewart Brand's Maintenance of Everything . Stewart developed a lot of this book in an open editing process and so the final delivery of what is Part 1 of a forthcoming series was all the more anticipated. I've long been obsessed with the need for maintenance in the context of technology risk management, security and reliability. A big part of technical debt build up and the security...

## The Real Role of the Field CISO

DevFeed: [The Real Role of the Field CISO](<https://devfeed.tech/articles/the-real-role-of-the-field-ciso-39501.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/the-real-role-of-the-field-ciso>)

Author: phil7672

Published: 2026-04-04T13:32:43Z

Content type: article

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [reliability](<https://devfeed.tech/topics/reliability.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [ciso](<https://devfeed.tech/tags/ciso.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article discusses the role of Field CISOs and argues that security and reliability increasingly support sustainable, long-term customer success.

### Source excerpt

We all need to advance our businesses and that is in many respects about selling. We also need to recognize that security and reliability are increasingly the path to sustainable long term customer success - which is your success. This is where the Field CISOs come in. There are many more people that are becoming, so called, Field CISOs and many more organizations that are creating Field CISO teams under a variety of structures and names. Let's look at what Field CISOs are, why they exist,...

## Organizational Politics & The Security Program

DevFeed: [Organizational Politics & The Security Program](<https://devfeed.tech/articles/organizational-politics-the-security-program-39492.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/organizational-politics-the-security-program>)

Author: phil7672

Published: 2026-03-21T11:29:27Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article revisits organizational politics in security programs and argues that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than budgets alone. It also discusses the continuing waves of vulnerabilities and possible responses.

### Source excerpt

I first wrote the original of this post over 4 years ago. Having seen a new spurt of discussion about organization politics in various on-line and in-person forums I thought it was time for an update. At every stage in your career and in every part of your role you are going to have to deal with organizational politics. People often construe such politics as inherently negative. Yes, there are some organizations that have toxic cultures where organizational politics looks more like chicanery...

## Cybersecurity's Need for Speed & Where To Find It

DevFeed: [Cybersecurity's Need for Speed & Where To Find It](<https://devfeed.tech/articles/cybersecurity-s-need-for-speed-where-to-find-it-39488.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/cybersecurity-s-need-for-speed-where-to-find-it>)

Author: phil7672

Published: 2026-03-07T15:08:59Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that cybersecurity organizations should increase their speed in adapting to change and responding to evolving threats. It also argues that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than inputs such as budgets.

### Source excerpt

As we talked about in the last post , a world going through a massive AI-driven transition means speed becomes vital. This is the speed of adapting to change and the speed of dealing with a world of threats, who are themselves moving ever faster. It's easy to say go faster but this has to be more than just wishful thinking or a line in a strategy document. You actually have to go do some things. You also have to push back against some of the defeatism that permeates a lot of the security...

## AI Is Reorienting Cybersecurity and Increasing Its Negative Impact

DevFeed: [AI Is Reorienting Cybersecurity and Increasing Its Negative Impact](<https://devfeed.tech/articles/things-are-getting-wild-re-tool-everything-for-speed-39502.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/things-are-getting-wild-re-tool-everything-for-speed>)

Author: Phil Venables

Published: 2026-02-21T16:08:46Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

The article argues that AI is rapidly reshaping cybersecurity and may have a more negative impact than previously assumed. It also questions cybersecurity benchmarking based only on inputs such as budgets rather than outcomes such as control effectiveness.

### Source excerpt

It's not often that a force appears that totally re-orients everything in security. This is what we are facing with AI. 12 months ago I had an incrementalist view of the cybersecurity impact of AI. Specifically, that it will be very significant but things will change progressively and we'll adapt to adversarial use while also using it to improve defenses. Now, I'm coming to a view that this will have a bigger negative impact than even our worst assumptions. But at the same time, it...

## Security Implications of DORA AI Capabilities Model

DevFeed: [Security Implications of DORA AI Capabilities Model](<https://devfeed.tech/articles/security-implications-of-dora-ai-capabilities-model-39494.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/security-implications-of-dora-ai-capabilities-model>)

Author: phil7672

Published: 2026-02-07T13:23:17Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [ai](<https://devfeed.tech/tags/ai.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

This opinion article summarizes security implications identified in the DORA AI Capabilities Model, focusing on data protection, access control, and evaluating cybersecurity controls by their effectiveness rather than by budget alone.

### Source excerpt

The DORA AI Capabilities Model (DevOps Research and Asssesment, not the EU Digital Operational Resilience Act) report is well worth a read not just to get a perspective from the developer community but to look at the many security implications it uncovers. This post is a summary of the explicit findings and some of broader implications from reading between the lines of the report. 1. Data Protection and Access Control A primary security concern is ensuring AI tools respect existing...

## The CISO's Craft: Watchmaker or Gardener?

DevFeed: [The CISO's Craft: Watchmaker or Gardener?](<https://devfeed.tech/articles/the-ciso-s-craft-watchmaker-or-gardener-39499.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/the-ciso-s-craft-watchmaker-or-gardener>)

Author: Phil Venables

Published: 2026-01-24T16:39:53Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [ciso](<https://devfeed.tech/tags/ciso.md>), [craft](<https://devfeed.tech/tags/craft.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [precision](<https://devfeed.tech/tags/precision.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article considers whether security leaders should operate more like precise watchmakers, adaptive gardeners, or both when leading organizational transformations. It also argues that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than inputs such as budgets.

### Source excerpt

Some time ago I saw a comment about the distinction between acting like a "watchmaker" or a "gardener" when undertaking organization transformations. I misplaced the original reference so, unfortunately, I can't credit appropriately. But, I've been thinking a lot about what this would mean in the context of security leadership. Specifically, should the CISO be a watchmaker or a gardener, or both? The Watchmaker CISO: Precision and Control Imagine a master watchmaker, meticulously crafting...

## 2025 Year in Review - Top 10

DevFeed: [2025 Year in Review - Top 10](<https://devfeed.tech/articles/2025-year-in-review-top-10-39483.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/2025-year-in-review-top-10>)

Author: Phil Venables

Published: 2026-01-10T14:36:22Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [execution](<https://devfeed.tech/tags/execution.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [technology](<https://devfeed.tech/tags/technology.md>), [transformation](<https://devfeed.tech/tags/transformation.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [year-in-review](<https://devfeed.tech/tags/year-in-review.md>)

### AI overview

A 2025 year-in-review highlighting posts about cybersecurity as a business leadership, strategic design, and sustainable execution function. It emphasizes moving from reactive security practices toward scalable, proactive systems and cautions against benchmarking based only on inputs such as budgets rather than control effectiveness.

### Source excerpt

The most read posts in 2025 coalesced around the concept that successful cybersecurity is fundamentally a function of business leadership, strategic design, and sustainable execution . The unifying themes across the top posts emphasize shifting security from an artisanal, reactive craft to an industrial-scale, proactive capability focused on building scalable, self-reinforcing systems (flywheels). Transformation requires leaders to manage stakeholder expectations carefully, particularly by...

## Security Leadership Master Class 7 : Contrarian takes

DevFeed: [Security Leadership Master Class 7 : Contrarian takes](<https://devfeed.tech/articles/security-leadership-master-class-7-contrarian-takes-39496.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/security-leadership-master-class-7-contrarian-takes>)

Author: Phil Venables

Published: 2025-12-27T15:12:43Z

Content type: article

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article's final installment discusses contrarian perspectives on security leadership, arguing that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than inputs such as budgets. It also considers adversarial strategy and responses to recurring waves of vulnerabilities.

### Source excerpt

This is the final of the series grouping together sets of prior posts into a particular theme. Security Leadership Master Class 1 : Leveling up your leadership Security Leadership Master Class 2 : Dealing with the board and other executives Security Leadership Master Class 3 : Building a security program Security Leadership Master Class 4 : Enhancing/refreshing a security program Security Leadership Master Class 5 : Getting hired and doing hiring Security Leadership Master Class 6 : When...

## Security Leadership Master Class 6 : When disaster strikes

DevFeed: [Security Leadership Master Class 6 : When disaster strikes](<https://devfeed.tech/articles/security-leadership-master-class-6-when-disaster-strikes-39495.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/security-leadership-master-class-6-when-disaster-strikes>)

Author: Phil Venables

Published: 2025-12-13T16:15:34Z

Content type: article

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Part 6 of a security leadership series argues that cybersecurity benchmarking should focus on outcomes, such as control effectiveness, rather than inputs such as budgets. It also discusses responding to recurring waves of vulnerabilities.

### Source excerpt

This is part 6 of a 7 part series grouping together sets of prior posts into a particular theme. Security Leadership Master Class 1 : Leveling up your leadership Security Leadership Master Class 2 : Dealing with the board and other executives Security Leadership Master Class 3 : Building a security program Security Leadership Master Class 4 : Enhancing/refreshing a security program Security Leadership Master Class 5 : Getting hired and doing hiring Security Leadership Master Class 6 : When...