Thoughts on application security, AI-assisted testing, DevSecOps, and the gap between what vendors promise and what practitioners actually need.
Most organisations test their security posture once or twice a year. Their attack surface changes every day. That gap isn't a resource problem — it's a mental model problem. The shift every CISO needs to make isn't in tool selection; it's in expectation.
Read on LinkedIn →GPT-5.5 is now part of XBOW's production stack — and the reactions split cleanly into two camps, both missing the point. A better model is necessary. It's not sufficient. Here's what actually changes, and what practitioners need to care about.
Read on LinkedIn →The last few weeks have been loud. Anthropic's research found thousands of unknown vulnerabilities in weeks. The hype cycle is in full swing. But before you rip out your SAST tooling and replace it with an AI model, there are three questions the conversation keeps skipping — and they matter more than the headlines.
Read on LinkedIn →Anthropic recently launched Claude Code Security — an AI-powered vulnerability scanner that can analyse your codebase, trace data flows across files, find bugs, and even propose patches. It represents a meaningful advance in how developers can get security insights earlier in the development process. But does a smart scanner replace an AppSec programme?
Read on LinkedIn →