Thought Leadership

The Risk Isn’t What You Prompt, It’s What You Built
Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…

AI Proves the Real Bottleneck Was Never Finding Vulnerabilities
Let this sink in: finding security vulnerabilities was never the bottleneck, vulnerability prioritization was. AI-scale discovery is about to make that impossible to ignore, and the teams that see it coming will pull ahead of the rest. Here's what kept me up this week. Anthropic ran a frontier model against some of the world's most…

Security AI Needs an Honest Scoreboard: What It’s Superhuman At, and Where It Comes Up Short
If you follow AI at all, you know the leaderboards. Every few weeks a model takes the top spot, and we all check where our favorite landed. But a leaderboard only tells you who's ahead, and it stays quiet about where any of those models still come up short. Which, conveniently, is the part that…

The Pyramid of Agents Is Also a Pyramid of Identities
Key Takeaways When Anthropic published its piece on recursive self-improvement, the line that traveled was the efficiency one. A 100-person company doing the work of a much larger one, because each person sits atop a pyramid of agents. It's a striking image, and it's probably right. But there's a second diagram hiding inside the first…

Trust Is Full-Duplex
Key Takeaways A few weeks ago, Mira Murati's lab, Thinking Machines, put out a research preview of something they're calling interaction models. If you haven't seen it, it's worth your time. This is a serious effort from serious people, the kind of lab that trains a 276-billion-parameter model from scratch and stands up a whole…

Is your AI governance actually governing anything?
Key Takeaways Most organizations believe they have AI governance because they have policies, risk classifications, even responsible AI principles documented and approved. What they do not have, in most cases, is the ability to answer a basic question: what is every AI agent in our environment doing right now, and should it be doing that?…

Why Cloud Security UX Is Broken, and How We’re Fixing It
As a design team, we spend a lot of time watching where users slow down, where they hesitate, and where the product makes them work harder than it should. In cloud security, one pattern shows up again and again: A security engineer starts their day by opening the platform and scanning a long list of…

Who’s watching the code AI writes?
It’s probably no shocker that most of the code shipping into production this year wasn't written by a person. The real question isn't whether it's any good, but who's watching what it does once it's running, because no human ever held the context for it in the first place. Here's a startling number that may…

API Security Is a Cloud Runtime Problem: Why Endpoint-Only Approaches Fail in Modern Environments
TL;DR: API security was designed for a world where APIs were stable, documented endpoints sitting in front of monolithic applications. In cloud-native environments, APIs are dynamic connective tissue between workloads, identities, and data stores and securing them requires runtime visibility across the full cloud stack, not endpoint-level controls alone. Introduction API security has received significant…

Field CISO Work is More like Courtship than Sales
Field CISO work is closer to courtship than sales. And what I mean by that is, by the time a CISO has an urgent project, the field of trusted vendors has already been chosen, which means the year before the buying moment is the entire game. The most underused word in cybersecurity is courtship. We…

Thanks to GlassWorm, your developer’s laptop is now the most dangerous device in your company. You’re Welcome.
Key Takeaways We've spent the last decade hardening the perimeter. Using firewalls, Zero Trust and EDR on every endpoint. SOC analysts surviving on cold brew and adrenaline just to keep us safe. And then GlassWorm walked straight through the front door. Like taking candy from a baby. If you haven't been following this one, here's…

Upwind Researcher Spotlight: Dan Gansel
"You have to map the core logic and syntax of the system before you can find the interesting primitives." This June 1st, Dan Gansel will walk on stage at fwd:cloudsec 2026 in North America to demonstrate a fully functional command-and-control channel that operates inside the AWS Data Perimeter, the cloud-native gold standard for keeping sensitive…