Gourav Nagar

Risk

The Risk Isn’t What You Prompt, It’s What You Built

Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…
AI Governance

Is your AI governance actually governing anything?

Key Takeaways Most organizations believe they have AI governance because they have policies, risk classifications, even responsible AI principles documented and approved. What they do not have, in most cases, is the ability to answer a basic question: what is every AI agent in our environment doing right now, and should it be doing that?…
API Security Is a Cloud Runtime Problem: Why Endpoint-Only Approaches Fail in Modern Environments
API Security Is a Cloud Runtime Problem: Why Endpoint-Only Approaches Fail in Modern Environments

API Security Is a Cloud Runtime Problem: Why Endpoint-Only Approaches Fail in Modern Environments

TL;DR: API security was designed for a world where APIs were stable, documented endpoints sitting in front of monolithic applications. In cloud-native environments, APIs are dynamic connective tissue between workloads, identities, and data stores and securing them requires runtime visibility across the full cloud stack, not endpoint-level controls alone. Introduction API security has received significant…
GlassWorm

Thanks to GlassWorm, your developer’s laptop is now the most dangerous device in your company. You’re Welcome.

Key Takeaways We've spent the last decade hardening the perimeter. Using firewalls, Zero Trust and EDR on every endpoint. SOC analysts surviving on cold brew and adrenaline just to keep us safe.  And then GlassWorm walked straight through the front door. Like taking candy from a baby.  If you haven't been following this one, here's…
Agentic Security is Here
Agentic Security Accountability & Human Oversight

Agentic Security Is Here — But Who Is Accountable When the AI Acts Alone?

TL;DR: Agentic security is the use of autonomous AI systems that detect, triage, and respond to threats without human intervention, which introduces a new category of operational risk. The most valuable security skill in 2026 is not prompt engineering or AI fluency. It’s consequence engineering: the ability to anticipate what happens when an autonomous system…
fedramp

Upwind Pursues FedRAMP Certification to Power Trusted Federal Cloud Solutions

Upwind is advancing federal cloud security with the pursuit of FedRAMP Moderate Equivalency, in partnership with Coalfire, the leading FedRAMP advisor and assessor. This milestone clears the way for the enterprises, integrators, and software vendors that serve government agencies to deliver live runtime protection with the compliance assurances their customers demand. By working with Coalfire…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS