Writing
RockCyber Blog
RockCyber Musings is where I think out loud about AI security, governance, and the risk calls executives have to make. It's plain-language and written for the people who own the outcome.
Latest from the blog
Latest from RockCyber Musings
- Broken Object Level Authorization Is Now an AI Agent ProblemAugust 2026
- AI Risk Assessment: Anthropic’s 186-Page Blind SpotAugust 2026
- Weekly Musings Top 10 AI Security Wrapup: Issue 49 August 7 -August 13, 2026August 2026
- The 2026 OWASP LLM Top 10 Landed. Its #1 Risk Nearly Didn’t Make the Cut.August 2026
- AI Agent Capability Confinement: No Escape RequiredAugust 2026
- Weekly Musings Top 10 AI Security Wrapup: Issue 48 July 24 -July 30, 2026July 2026
What I write about
- AI and agentic security: the threat models and controls that hold up in production.
- Governance that speeds teams up instead of becoming the thing they route around.
- Risk quantification: putting a number on AI exposure so a board can act on it.
Subscribe to the newsletter
Get RockCyber Musings in your inbox. It is free, and you can leave whenever you want.
