# Risk

Published articles for Risk.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Match Software Quality Controls to Customer Impact and Technical Risk

DevFeed: [Match Software Quality Controls to Customer Impact and Technical Risk](<https://devfeed.tech/articles/quality-controls-storytelling-reps-and-weekly-readings-39824.md>)

Original publisher: [Read original article](<https://refactoring.fm/p/quality-controls-storytelling-reps>)

Author: Luca Rossi

Published: 2026-09-07T07:03:38Z

Content type: opinion

Language: en

Sources: [Refactoring](<https://devfeed.tech/sources/refactoring.md>)

Topics: [Risk](<https://devfeed.tech/topics/risk.md>), [Software](<https://devfeed.tech/topics/software.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [essay](<https://devfeed.tech/tags/essay.md>), [risk](<https://devfeed.tech/tags/risk.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

This commentary argues that software quality controls should reflect a change's customer impact and technical risk. It describes a maturity path from individual quality advocacy to team-wide principles and processes.

### Source excerpt

Monday Ideas -- Edition #224

## Cybersecurity Benchmarking: Why, Why Not, When and How

DevFeed: [Cybersecurity Benchmarking: Why, Why Not, When and How](<https://devfeed.tech/articles/cybersecurity-benchmarking-why-why-not-when-and-how-39487.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/cybersecurity-benchmarking-why-why-not-when-and-how>)

Author: Phil Venables

Published: 2026-09-05T15:27:39Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [performance](<https://devfeed.tech/tags/performance.md>), [risk](<https://devfeed.tech/tags/risk.md>)

### AI overview

The article argues that cybersecurity benchmarking is unhelpful when it focuses only on inputs such as budgets instead of outcomes such as control effectiveness. It recommends comparing leading indicators and examining how they influence lagging performance indicators, while noting that budget comparisons may not be meaningfully comparable.

### Source excerpt

tl;dr Benchmarking is a waste of time when focused solely on inputs (e.g. budgets) rather than outcomes (e.g. effectiveness of controls). The budget comparisons are never "apples for apples" and may often end up setting risk tolerance only marginally ahead of others who may be in a bad state to begin with. Instead, we need to decouple this and compare leading not lagging indicators of performance to show (i) how those leading indicators drive the lagging indicators in the right direction and...

## NFR Brain: challenging the status quo of risk management with data

DevFeed: [NFR Brain: challenging the status quo of risk management with data](<https://devfeed.tech/articles/nfr-brain-challenging-the-status-quo-of-risk-management-with-data-38852.md>)

Original publisher: [Read original article](<https://building.nubank.com/nfr-brain-challenging-the-status-quo-of-risk-management-with-data/>)

Author: Nubank Editorial

Published: 2026-09-04T14:18:41Z

Content type: article

Language: en

Sources: [Nubank](<https://devfeed.tech/sources/nubank.md>)

Topics: [risk-management](<https://devfeed.tech/topics/risk-management.md>), [data](<https://devfeed.tech/topics/data.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [business](<https://devfeed.tech/tags/business.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [data](<https://devfeed.tech/tags/data.md>), [data-analytics](<https://devfeed.tech/tags/data-analytics.md>), [data-science-machine-learning](<https://devfeed.tech/tags/data-science-machine-learning.md>), [management](<https://devfeed.tech/tags/management.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [risk](<https://devfeed.tech/tags/risk.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [service](<https://devfeed.tech/tags/service.md>)

### AI overview

Nubank is building NFR Brain, a platform that combines data, modelling and expert judgement to create a comparable and actionable view of non-financial risk. The article explains how the platform is intended to support clearer, more consistent prioritization across operational failures, customer complaints, third-party dependencies and other risk signals.

### Source excerpt

Author : Mayara Zenati At Nubank, we believe the most meaningful problems for customers and for the business rarely come with ready-made answers. That is why we challenge the status quo: not to innovate for innovation's sake, but to remove complexity and build solutions that make important decisions simpler, faster and better. This mindset also [...] The post NFR Brain: challenging the status quo of risk management with data appeared first on Building Nubank.

## Generating scenarios for extreme events, without extreme data

DevFeed: [Generating scenarios for extreme events, without extreme data](<https://devfeed.tech/articles/generating-scenarios-for-extreme-events-without-extreme-data-37953.md>)

Original publisher: [Read original article](<https://news.mit.edu/2026/generating-scenarios-extreme-events-without-extreme-data-0824>)

Author: Jennifer Chu | MIT News

Published: 2026-08-24T18:00:00Z

Content type: news

Language: en

Sources: [MIT AI News](<https://devfeed.tech/sources/mit-ai-news.md>)

Topics: [Machine learning](<https://devfeed.tech/topics/machine-learning.md>), [Algorithms](<https://devfeed.tech/topics/algorithms.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [algorithm](<https://devfeed.tech/tags/algorithm.md>), [algorithms](<https://devfeed.tech/tags/algorithms.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [center-for-computational-science-and-engineering](<https://devfeed.tech/tags/center-for-computational-science-and-engineering.md>), [climate](<https://devfeed.tech/tags/climate.md>), [climate-risk-assessment](<https://devfeed.tech/tags/climate-risk-assessment.md>), [computer-modeling](<https://devfeed.tech/tags/computer-modeling.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [data](<https://devfeed.tech/tags/data.md>), [extreme-event-aware](<https://devfeed.tech/tags/extreme-event-aware.md>), [extreme-weather](<https://devfeed.tech/tags/extreme-weather.md>), [fire](<https://devfeed.tech/tags/fire.md>), [heat](<https://devfeed.tech/tags/heat.md>), [idss](<https://devfeed.tech/tags/idss.md>), [kai-chang](<https://devfeed.tech/tags/kai-chang.md>), [learning-fefb62e9fa83](<https://devfeed.tech/tags/learning-fefb62e9fa83.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [mechanical-engineering](<https://devfeed.tech/tags/mechanical-engineering.md>), [mit-meche](<https://devfeed.tech/tags/mit-meche.md>), [mit-schwarzman-college-of-computing](<https://devfeed.tech/tags/mit-schwarzman-college-of-computing.md>), [natural-disasters](<https://devfeed.tech/tags/natural-disasters.md>), [research](<https://devfeed.tech/tags/research.md>), [risk](<https://devfeed.tech/tags/risk.md>), [school-of-engineering](<https://devfeed.tech/tags/school-of-engineering.md>), [storm](<https://devfeed.tech/tags/storm.md>), [sustainability](<https://devfeed.tech/tags/sustainability.md>), [themis-sapsis](<https://devfeed.tech/tags/themis-sapsis.md>), [weather](<https://devfeed.tech/tags/weather.md>), [weather-prediction](<https://devfeed.tech/tags/weather-prediction.md>)

### AI overview

MIT engineers developed a machine-learning algorithm that generates plausible future extreme-event scenarios without requiring past extreme events in the training data. It learns from available records, filters out implausible weather scenarios, and estimates events' frequency, size, intensity, duration, and area of impact to help planners prepare.

### Source excerpt

A new algorithm learns to anticipate the unprecedented scenarios that critical infrastructure and global supply chains are least prepared for.

## Rolling with the Punches: Why Cybersecurity is Backgammon, Not Chess

DevFeed: [Rolling with the Punches: Why Cybersecurity is Backgammon, Not Chess](<https://devfeed.tech/articles/rolling-with-the-punches-why-cybersecurity-is-backgammon-not-chess-39493.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/rolling-with-the-punches-why-cybersecurity-is-backgammon-not-chess>)

Author: phil7672

Published: 2026-08-22T16:49:47Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-day](<https://devfeed.tech/tags/zero-day.md>)

### AI overview

The article argues that cybersecurity is better understood as backgammon than chess because organizations must prepare for many possible outcomes amid complex dependencies, supply chains, changing technology platforms, and unpredictable attackers. It also argues that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than inputs such as budgets.

### Source excerpt

It is tempting to compare cybersecurity to a chess game. Two adversaries facing each other, plotting strategy and tactics. Move and counter move, anticipating actions and grinding out a win. In reality, in our complex world of dependencies, supply chains, constantly shifting technology platforms and unpredictable attackers, this is all way more haphazard. Indeed, a better analogy is backgammon, where you position yourself for many different possible outcomes to maximize your chance of...

## Whether Rising Vulnerabilities Will Cause a Cybersecurity Incident Crisis

DevFeed: [Whether Rising Vulnerabilities Will Cause a Cybersecurity Incident Crisis](<https://devfeed.tech/articles/a-coming-incident-crisis-39484.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/a-coming-incident-crisis>)

Author: phil7672

Published: 2026-08-08T14:58:15Z

Content type: article

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [zero-day](<https://devfeed.tech/tags/zero-day.md>)

### AI overview

The article examines whether increasing software vulnerabilities will lead to more cybersecurity incidents. It argues that security breaches often result from ineffective controls rather than exceptionally capable attackers or sophisticated zero-day exploits, and that benchmarking should focus on control effectiveness instead of inputs such as budgets.

### Source excerpt

We're all talking about the tidal wave of vulnerabilities that is upon us, with repeated waves likely coming. As I've covered here, we can respond to this in various ways including ramping up speed across our entire defensive stack, which is as much about structural defense-in-depth than just faster patching. I've covered that here as well. But, there's a question as to whether the leading indicator of increasing vulnerabilities will in fact result in an increase in the lagging indicator of...

## Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls

DevFeed: [Control Reliability Engineering (CRE): Applying SRE Principles to Cybersecurity Controls](<https://devfeed.tech/articles/control-reliability-engineering-cre-applying-sre-principles-to-cybersecurity-controls-39486.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/control-reliability-engineering-cre-applying-sre-principles-to-cybersecurity-controls>)

Author: phil7672

Published: 2026-07-25T05:52:21Z

Content type: article

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [SRE](<https://devfeed.tech/topics/sre.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [reliability](<https://devfeed.tech/topics/reliability.md>), [plotting](<https://devfeed.tech/topics/plotting.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [reliability-engineering](<https://devfeed.tech/tags/reliability-engineering.md>), [risk](<https://devfeed.tech/tags/risk.md>), [sre](<https://devfeed.tech/tags/sre.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

This article applies SRE principles to cybersecurity controls, arguing that control effectiveness matters more than input-focused budget comparisons. It highlights continuous control monitoring to detect controls that are broken, misconfigured, or incomplete when needed.

### Source excerpt

Security breaches are often not the result of awesome attacker capabilities or the sudden emergence of sophisticated zero-day exploits. Instead, what we usually find are the controls designed to stop the attack were believed to be operational but were actually broken or misconfigured at the moment when they were needed. Sometimes they were never fully in place to meet the security team's original intent. So, continuous control monitoring is needed to counter the natural decay that occurs to...

## Product Discovery for Product Managers in 2026

DevFeed: [Product Discovery for Product Managers in 2026](<https://devfeed.tech/articles/what-is-product-discovery-the-ultimate-guide-for-pms-2026-edition-39183.md>)

Original publisher: [Read original article](<https://www.productcompass.pm/p/product-discovery-2026>)

Author: Paweł Huryn

Published: 2026-07-22T20:01:35Z

Content type: tutorial

Language: en

Sources: [The Product Compass](<https://devfeed.tech/sources/the-product-compass.md>)

Topics: [Product Management](<https://devfeed.tech/topics/product-management.md>), [Usability](<https://devfeed.tech/topics/usability.md>), [Users](<https://devfeed.tech/topics/users.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [discovery](<https://devfeed.tech/tags/discovery.md>), [guide](<https://devfeed.tech/tags/guide.md>), [product-management](<https://devfeed.tech/tags/product-management.md>), [risk](<https://devfeed.tech/tags/risk.md>)

### AI overview

This guide explains why product discovery remains important for product managers in 2026, even as shipping becomes faster and cheaper. It focuses on validating ideas, managing product risks, and deciding what to build before committing resources.

### Source excerpt

You can ship an idea the same day you have it. That's why discovery matters more, not less. What changed, what didn't, and what to learn.

## A Model for Understanding AI Success in Organizations

DevFeed: [A Model for Understanding AI Success in Organizations](<https://devfeed.tech/articles/tbm-431-the-denominator-that-matters-40057.md>)

Original publisher: [Read original article](<https://cutlefish.substack.com/p/tbm-431-the-denominator-that-matters>)

Author: John Cutler

Published: 2026-07-19T15:21:27Z

Content type: opinion

Language: en

Sources: [The Beautiful Mess](<https://devfeed.tech/sources/the-beautiful-mess.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [context](<https://devfeed.tech/topics/context.md>), [domain](<https://devfeed.tech/topics/domain.md>), [iteration](<https://devfeed.tech/topics/iteration.md>), [Risk](<https://devfeed.tech/topics/risk.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [context](<https://devfeed.tech/tags/context.md>), [domain](<https://devfeed.tech/tags/domain.md>), [iteration](<https://devfeed.tech/tags/iteration.md>), [risk](<https://devfeed.tech/tags/risk.md>)

### AI overview

The article presents a multiplicative model for AI success based on technology understanding, problem understanding, practice evolution, and an organizational social contract. It argues that missing any essential factor can undermine the outcome, while resistance to AI mandates may reflect rational self-preservation and insufficient evidence.

### Source excerpt

Here's a simple model for thinking about AI success in organizations.

## How Nubank uses causality, machine learning and Python to support credit limit increase decisions

DevFeed: [How Nubank uses causality, machine learning and Python to support credit limit increase decisions](<https://devfeed.tech/articles/how-nubank-uses-causality-machine-learning-and-python-to-support-credit-limit-increase-decisions-38849.md>)

Original publisher: [Read original article](<https://building.nubank.com/how-nubank-uses-causality-machine-learning-and-python-to-support-credit-limit-increase-decisions/>)

Author: Nubank Editorial

Published: 2026-07-01T16:16:31Z

Content type: article

Language: en

Sources: [Nubank](<https://devfeed.tech/sources/nubank.md>)

Topics: [Data Science](<https://devfeed.tech/topics/data-science.md>), [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>), [Python](<https://devfeed.tech/topics/python.md>), [risk-management](<https://devfeed.tech/topics/risk-management.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Optimization](<https://devfeed.tech/topics/optimization.md>)

Tags: [causality](<https://devfeed.tech/tags/causality.md>), [data-science](<https://devfeed.tech/tags/data-science.md>), [life-at-nu](<https://devfeed.tech/tags/life-at-nu.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [python](<https://devfeed.tech/tags/python.md>), [risk](<https://devfeed.tech/tags/risk.md>), [scalability](<https://devfeed.tech/tags/scalability.md>)

### AI overview

A high-level technical overview of how Nubank applies data science, predictive modeling, causality, optimization, and monitoring to support credit limit increase decisions. It discusses balancing customer experience, risk management, operational sustainability, interpretability, computational cost, and scalability.

### Source excerpt

A technical, high-level view of how data science helps build more responsible and scalable credit decisions The post How Nubank uses causality, machine learning and Python to support credit limit increase decisions appeared first on Building Nubank.

## Cybersecurity Benchmarking Should Focus on Control Effectiveness, Not Budgets

DevFeed: [Cybersecurity Benchmarking Should Focus on Control Effectiveness, Not Budgets](<https://devfeed.tech/articles/sorry-cyber-you-aren-t-the-only-ones-saving-the-company-from-itself-39497.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/sorry-cyber-you-aren-t-the-only-ones-saving-the-company-from-itself>)

Author: Phil Venables

Published: 2026-06-27T12:52:02Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article argues that cybersecurity benchmarking should assess the effectiveness of security controls and their outcomes rather than compare budgets, which are not reliably comparable. It also places cybersecurity work within the broader responsibilities shared by organizational functions.

### Source excerpt

There's still a bit of a tone in some security circles that we're somehow unique in constantly having to push back against ill-advised moves, or even outright craziness, from our business, operations, or technology colleagues. But, when you pause and think about all the many functions in your or other organizations you realize this is not so. You quickly see that while great security teams are true enablers of business and reducers of friction, most teams still have to (and are expected to...

## CISO Version 2.0

DevFeed: [CISO Version 2.0](<https://devfeed.tech/articles/ciso-version-2-0-39485.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/ciso-version-2-0>)

Author: Phil Venables

Published: 2026-06-12T13:05:15Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [version](<https://devfeed.tech/topics/version.md>), [Security](<https://devfeed.tech/topics/security.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [opinion](<https://devfeed.tech/tags/opinion.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>), [version](<https://devfeed.tech/tags/version.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that the CISO role has evolved from an IT security manager into roles including cyber-defense leader, compliance director, and technology risk manager. It also argues that cybersecurity benchmarking is unhelpful when it focuses on inputs such as budgets rather than control effectiveness.

### Source excerpt

Everyone, no doubt, has an opinion on how many versions of the CISO role we have gone through since its inception. There has been a constant evolution from what was essentially an IT security manager, to cyber-defense leader, compliance director, technology risk manager, and beyond. However, I would argue the incarnation of the CISO role up until recently has been CISO Version 1.0 albeit with some "point releases" on the way. This is simply because version 1 of the role is a mode where most...

## Why Cybersecurity Benchmarking Should Focus on Control Effectiveness and Outcomes

DevFeed: [Why Cybersecurity Benchmarking Should Focus on Control Effectiveness and Outcomes](<https://devfeed.tech/articles/do-you-really-know-what-s-going-on-39489.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/do-you-really-know-what-s-going-on>)

Author: phil7672

Published: 2026-05-16T15:56:56Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [benchmarking](<https://devfeed.tech/topics/benchmarking.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [effectiveness](<https://devfeed.tech/tags/effectiveness.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [strategy](<https://devfeed.tech/tags/strategy.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This commentary argues that cybersecurity benchmarking should emphasize the effectiveness of security controls and outcomes rather than inputs such as budgets. It also discusses the continuing waves of vulnerabilities and possible responses.

### Source excerpt

At some point every leader needs to ask themselves: Do I really know what is going on in my company? Do I even know what is really going on in my own organization? Most leaders do not know the actual truth of what is happening. This is not because people are overtly hiding things or that leaders are ineffective, although sometimes it is both of those, but rather this is because of the "thermocline of truth" that I covered in this post. Organizations are full of cultural, structural, process,...

## High Frequency Trading and Lessons for Agentic AI

DevFeed: [High Frequency Trading and Lessons for Agentic AI](<https://devfeed.tech/articles/high-frequency-trading-and-lessons-for-agentic-ai-39490.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/high-frequency-trading-and-lessons-for-agentic-ai>)

Author: Phil Venables

Published: 2026-05-02T12:45:05Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [systems](<https://devfeed.tech/topics/systems.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [automated](<https://devfeed.tech/tags/automated.md>), [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [financial](<https://devfeed.tech/tags/financial.md>), [guardrails](<https://devfeed.tech/tags/guardrails.md>), [risk](<https://devfeed.tech/tags/risk.md>)

### AI overview

The article argues that lessons from high-frequency and algorithmic trading controls can inform deterministic guardrails for mostly non-deterministic agentic AI systems as they evolve from chatbots into systems that act. It also argues that benchmarking should focus on outcomes such as control effectiveness rather than input budgets alone.

### Source excerpt

I suspect I'm not the only former or current financial markets technologist that sees parallels between the world of high frequency / algorithmic trading controls and what is needed for appropriate deterministic guardrails around our, mostly, non-deterministic agentic AI systems. As we transition from chatbots to systems of agents, that don't just talk but act, we are entering a regime of automated risk that the financial markets have navigated, mostly successfully, for decades....

## AI Code Generation Is Fueling Disposable Software Projects

DevFeed: [AI Code Generation Is Fueling Disposable Software Projects](<https://devfeed.tech/articles/the-rise-of-abandonware-38755.md>)

Original publisher: [Read original article](<https://www.paleblueapps.com/rockandnull/the-rise-of-abandonware/>)

Author: Mike Yerou

Published: 2026-04-21T14:10:12Z

Content type: opinion

Language: en

Sources: [Rock and Null](<https://devfeed.tech/sources/rock-and-null.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [Software](<https://devfeed.tech/topics/software.md>), [Library](<https://devfeed.tech/topics/library.md>), [Tool](<https://devfeed.tech/topics/tool.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [code-generation](<https://devfeed.tech/tags/code-generation.md>), [disposable-software](<https://devfeed.tech/tags/disposable-software.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [repositories](<https://devfeed.tech/tags/repositories.md>), [risk](<https://devfeed.tech/tags/risk.md>), [software-engineering](<https://devfeed.tech/tags/software-engineering.md>), [thoughts](<https://devfeed.tech/tags/thoughts.md>)

### AI overview

AI code generation makes it possible to turn ideas into software quickly, but it may also encourage projects that are abandoned soon after creation. The article argues that maintainers' track records should be considered when evaluating libraries and tools.

### Source excerpt

AI allows us to ship software instantly, but it's also fueling a surge of "disposable" projects. The team behind the code matters more than the code itself in the age of AI generation.

## Big tech clouds worden niet veiliger met stapels papier

DevFeed: [Big tech clouds worden niet veiliger met stapels papier](<https://devfeed.tech/articles/big-tech-clouds-worden-niet-veiliger-met-stapels-papier-36267.md>)

Original publisher: [Read original article](<https://berthub.eu/articles/posts/big-tech-clouds-niet-veiliger-met-papier/>)

Published: 2026-04-19T19:00:00Z

Content type: opinion

Language: nl

Sources: [Bert Hubert's writings](<https://devfeed.tech/sources/bert-hubert-s-writings.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [data-privacy](<https://devfeed.tech/tags/data-privacy.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [risk](<https://devfeed.tech/tags/risk.md>), [tech](<https://devfeed.tech/tags/tech.md>)

### AI overview

The article argues that relying on American cloud providers creates risks for European societies and governments because U.S. law can affect access to services and data even when servers are located in Europe. It criticizes privacy assessments, transfer assessments, compliance documents, and risk registers as paperwork that can be used to justify accepting those risks instead of pursuing greater digital autonomy and European technology.

### Source excerpt

Je samenleving, overheid en maatschappij overlaten aan Amerikaanse servers komt met twee problemen: Alles werkt alleen zolang ze het in Amerika goed vinden. Met een enkel briefje op Whitehouse.gov lig je uit hun cloud. Via minstens drie wetsinstrumenten gunt Amerika zich toegang tot onze data en communicatie, ook al staan de Microsoftservers in Europa. Dit is allemaal heel vervelend, en er is ook weinig aan te doen. Geen enkele "speciale" afspraak heft de realiteit van Amerikaanse wetgeving op.

## Organizational Politics & The Security Program

DevFeed: [Organizational Politics & The Security Program](<https://devfeed.tech/articles/organizational-politics-the-security-program-39492.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/organizational-politics-the-security-program>)

Author: phil7672

Published: 2026-03-21T11:29:27Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article revisits organizational politics in security programs and argues that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than budgets alone. It also discusses the continuing waves of vulnerabilities and possible responses.

### Source excerpt

I first wrote the original of this post over 4 years ago. Having seen a new spurt of discussion about organization politics in various on-line and in-person forums I thought it was time for an update. At every stage in your career and in every part of your role you are going to have to deal with organizational politics. People often construe such politics as inherently negative. Yes, there are some organizations that have toxic cultures where organizational politics looks more like chicanery...

## Cybersecurity's Need for Speed & Where To Find It

DevFeed: [Cybersecurity's Need for Speed & Where To Find It](<https://devfeed.tech/articles/cybersecurity-s-need-for-speed-where-to-find-it-39488.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/cybersecurity-s-need-for-speed-where-to-find-it>)

Author: phil7672

Published: 2026-03-07T15:08:59Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [benchmarking](<https://devfeed.tech/topics/benchmarking.md>)

Tags: [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that cybersecurity organizations should increase their speed in adapting to change and responding to evolving threats. It also argues that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than inputs such as budgets.

### Source excerpt

As we talked about in the last post , a world going through a massive AI-driven transition means speed becomes vital. This is the speed of adapting to change and the speed of dealing with a world of threats, who are themselves moving ever faster. It's easy to say go faster but this has to be more than just wishful thinking or a line in a strategy document. You actually have to go do some things. You also have to push back against some of the defeatism that permeates a lot of the security...

## AI Is Reorienting Cybersecurity and Increasing Its Negative Impact

DevFeed: [AI Is Reorienting Cybersecurity and Increasing Its Negative Impact](<https://devfeed.tech/articles/things-are-getting-wild-re-tool-everything-for-speed-39502.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/things-are-getting-wild-re-tool-everything-for-speed>)

Author: Phil Venables

Published: 2026-02-21T16:08:46Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

The article argues that AI is rapidly reshaping cybersecurity and may have a more negative impact than previously assumed. It also questions cybersecurity benchmarking based only on inputs such as budgets rather than outcomes such as control effectiveness.

### Source excerpt

It's not often that a force appears that totally re-orients everything in security. This is what we are facing with AI. 12 months ago I had an incrementalist view of the cybersecurity impact of AI. Specifically, that it will be very significant but things will change progressively and we'll adapt to adversarial use while also using it to improve defenses. Now, I'm coming to a view that this will have a bigger negative impact than even our worst assumptions. But at the same time, it...

## The 5 Processes Every Business Should Automate First

DevFeed: [The 5 Processes Every Business Should Automate First](<https://devfeed.tech/articles/the-5-processes-every-business-should-automate-first-39942.md>)

Original publisher: [Read original article](<https://mende.io/blog/the-5-processes-every-business-should-automate-first/>)

Author: tobi@techunicorn.builders (Tobias Mende)

Published: 2026-01-30T05:00:00Z

Content type: article

Language: en

Sources: [Tobias Mende](<https://devfeed.tech/sources/tobias-mende.md>)

Topics: [Automation](<https://devfeed.tech/topics/automation.md>), [n8n](<https://devfeed.tech/topics/n8n.md>), [Processes](<https://devfeed.tech/topics/processes.md>)

Tags: [automate](<https://devfeed.tech/tags/automate.md>), [automation](<https://devfeed.tech/tags/automation.md>), [automation-productivity-n8n-business-process-efficiency](<https://devfeed.tech/tags/automation-productivity-n8n-business-process-efficiency.md>), [crm](<https://devfeed.tech/tags/crm.md>), [email](<https://devfeed.tech/tags/email.md>), [incremental](<https://devfeed.tech/tags/incremental.md>), [n8n](<https://devfeed.tech/tags/n8n.md>), [risk](<https://devfeed.tech/tags/risk.md>), [slack](<https://devfeed.tech/tags/slack.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This article recommends starting business automation with small, frequent, rule-based, low-risk processes rather than a large transformation project. It presents five candidate processes and illustrates lead response automation using a contact form, CRM, confirmation email, and Slack or email notification.

### Source excerpt

The 5 Processes Every Business Should Automate First Most businesses I work with know they should automate more. They have heard the promises. They might even have an n8n instance running somewhere with one or two small workflows that someone set up a while ago.

## Trusting AI agents: A reinsurance case study

DevFeed: [Trusting AI agents: A reinsurance case study](<https://devfeed.tech/articles/trusting-ai-agents-a-reinsurance-case-study-36082.md>)

Original publisher: [Read original article](<https://temporal.io/blog/trusting-ai-agents-a-reinsurance-case-study>)

Author: Sophia Barnes

Published: 2026-01-22T00:00:00Z

Content type: article

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [data-processing](<https://devfeed.tech/topics/data-processing.md>), [datasets](<https://devfeed.tech/topics/datasets.md>), [decision-making](<https://devfeed.tech/topics/decision-making.md>), [parallel](<https://devfeed.tech/topics/parallel.md>), [file](<https://devfeed.tech/topics/file.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [automate](<https://devfeed.tech/tags/automate.md>), [case-study](<https://devfeed.tech/tags/case-study.md>), [data-processing](<https://devfeed.tech/tags/data-processing.md>), [excel](<https://devfeed.tech/tags/excel.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [insurance](<https://devfeed.tech/tags/insurance.md>), [multi-agent](<https://devfeed.tech/tags/multi-agent.md>), [pricing](<https://devfeed.tech/tags/pricing.md>), [risk](<https://devfeed.tech/tags/risk.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This case study explains how a multi-agent AI system with human-in-the-loop safeguards automates reinsurance data workflows. The system parses unstandardized Excel submission packs, matches catastrophe events with historical records, creates cedant loss records, and flags changes to existing data.

### Source excerpt

Learn how to build a reliable multi-agent AI system with human-in-the-loop safeguards using Temporal. A detailed case study on automating complex reinsurance data workflows.

## 2025 Year in Review - Top 10

DevFeed: [2025 Year in Review - Top 10](<https://devfeed.tech/articles/2025-year-in-review-top-10-39483.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/2025-year-in-review-top-10>)

Author: Phil Venables

Published: 2026-01-10T14:36:22Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [benchmarking](<https://devfeed.tech/tags/benchmarking.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [execution](<https://devfeed.tech/tags/execution.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [risk](<https://devfeed.tech/tags/risk.md>), [technology](<https://devfeed.tech/tags/technology.md>), [transformation](<https://devfeed.tech/tags/transformation.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [year-in-review](<https://devfeed.tech/tags/year-in-review.md>)

### AI overview

A 2025 year-in-review highlighting posts about cybersecurity as a business leadership, strategic design, and sustainable execution function. It emphasizes moving from reactive security practices toward scalable, proactive systems and cautions against benchmarking based only on inputs such as budgets rather than control effectiveness.

### Source excerpt

The most read posts in 2025 coalesced around the concept that successful cybersecurity is fundamentally a function of business leadership, strategic design, and sustainable execution . The unifying themes across the top posts emphasize shifting security from an artisanal, reactive craft to an industrial-scale, proactive capability focused on building scalable, self-reinforcing systems (flywheels). Transformation requires leaders to manage stakeholder expectations carefully, particularly by...

## Individual contributors vs. decision makers: Same systems, different realities

DevFeed: [Individual contributors vs. decision makers: Same systems, different realities](<https://devfeed.tech/articles/individual-contributors-vs-decision-makers-same-systems-different-realities-35884.md>)

Original publisher: [Read original article](<https://temporal.io/blog/individual-contributors-vs-decision-makers-same-systems-different-realities>)

Author: Lauren Bennett

Published: 2025-09-23T00:00:00Z

Content type: article

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [reliability](<https://devfeed.tech/topics/reliability.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [community](<https://devfeed.tech/tags/community.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [development](<https://devfeed.tech/tags/development.md>), [observability](<https://devfeed.tech/tags/observability.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [performance](<https://devfeed.tech/tags/performance.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [risk](<https://devfeed.tech/tags/risk.md>), [scaling](<https://devfeed.tech/tags/scaling.md>)

### AI overview

The State of Development 2025 survey compares how individual contributors and decision makers perceive operational problems. Contributors emphasize latency, fragile workflows, observability gaps, and manual recovery, while decision makers focus on security, complexity, integration, cost, scaling, and reliability. The article argues that both perspectives point toward greater reliability and less manual effort, and that tooling decisions vary by company size.

### Source excerpt

ICs feel daily friction. DMs see business risk. State of Development 2025 puts both views on one page so teams share facts, cut toil, and raise reliability.

## Upsides and Downsides

DevFeed: [Upsides and Downsides](<https://devfeed.tech/articles/upsides-and-downsides-37190.md>)

Original publisher: [Read original article](<https://calv.info/upsides-and-downsides>)

Author: Calvin French-Owen

Published: 2025-02-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Calvin French-Owen](<https://devfeed.tech/sources/calvin-french-owen.md>)

Topics: [Requirements](<https://devfeed.tech/topics/requirements.md>), [Security](<https://devfeed.tech/topics/security.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [churn](<https://devfeed.tech/tags/churn.md>), [latency](<https://devfeed.tech/tags/latency.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>), [startups](<https://devfeed.tech/tags/startups.md>), [velocity](<https://devfeed.tech/tags/velocity.md>)

### AI overview

This opinion article presents a framework for understanding how startup priorities change as a company matures. Early-stage startups benefit from pursuing high-upside opportunities and accepting variance, while later-stage companies must reduce downside risks such as security issues, access-control gaps, audit requirements, uptime problems, and cost or performance concerns. The article also argues that this shift helps explain why AI demos often fail to become strong products.

### Source excerpt

When to shift mentality from upsides to downsides. And why most AI demos don't make great products.

[Next page](<https://devfeed.tech/tags/risk.md?cursor=WyIyMDI1LTAyLTI3VDAwOjAwOjAwKzAwOjAwIiwgImM5NmE2MDg0LWFiOWItNDI0Ni04ZjE2LTg2NTUxNjBkMTQ3NCJd>)